guigcs 0 Denunciar post Postado Março 19, 2010 Aqui vai o Log file do Hijack This. Não sei o q faço, esse vírus está atormentando minha vida. rs Agradeço a colaboração! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:28:55, on 19/3/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\csrcs.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\VM_STI.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\MessengerPlus\wmplayer.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Microsoft Office\OFFICE11\WINWORD.EXE C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe C:\Arquivos de programas\Microsoft\Office Live\OfficeLiveSignIn.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\net.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: flvdirect - {2e7929b5-b903-340d-eb69-96c8e83d402c} - C:\WINDOWS\system32\RQVvIO.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\MessengerPlus\IEBrowserEvents.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\All Users\Dados de aplicativos\Winthkill.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [TaskServ.exe] C:\Documents and Settings\All Users\Dados de aplicativos\TaskServ.exe O4 - HKCU\..\Run: [wmplayer] C:\MessengerPlus\wmplayer.exe O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: http://www.flvdirect.com O15 - ESC Trusted Zone: http://www.flvdirect.com O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 8923 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 19, 2010 *Baixe o MalwareBytes Anti-malware e salve-o no desktop: *Instale o programa *Se alguma atualização existir,o download será automático. Aguarde... *O programa será aberto automaticamente. *Na aba [Verificação], selecione a opção [Verificação completa] *Clique em [Verificar] e selecione as unidades (C:\ e D:\) a serem examinadas *Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados] *Clique em [Remover Selecionados] *Um relatório (mbam-log-ano-mês-data.txt) será apresentado. *Cole-o na sua próxima resposta e novo log do hijack Compartilhar este post Link para o post Compartilhar em outros sites
guigcs 0 Denunciar post Postado Março 19, 2010 Aí vão os resultados do Malwarebytes' e do novo log do hijack. Valeu pela ajuda!!! Malwarebytes' Anti-Malware 1.44 Versão do banco de dados: 3885 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 19/3/2010 18:07:48 mbam-log-2010-03-19 (18-07-46).txt Tipo de Verificação: Completa (C:\|D:\|) Objetos verificados: 165174 Tempo decorrido: 2 hour(s), 26 minute(s), 13 second(s) Processos da Memória infectados: 2 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 12 Valores do Registro infectados: 4 Ítens do Registro infectados: 4 Pastas infectadas: 9 Arquivos infectados: 49 Processos da Memória infectados: C:\MessengerPlus\wmplayer.exe (Trojan.VB) -> Unloaded process successfully. C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Unloaded process successfully. Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.BHO.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.BHO.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax5-314cca322142} (Generic.Bot.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.Banker) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ef34404a-747c-81d8-843a-d938e181273d} (Adware.BHO.FL) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax5-314cca322142} (Worm.AutoRun) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\s7eho-nia_6 (Adware.LoudMo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\flv direct player (Adware.BHO.FL) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty (Worm.Autorun) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e7929b5-b903-340d-eb69-96c8e83d402c} (Adware.AdRotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2e7929b5-b903-340d-eb69-96c8e83d402c} (Adware.AdRotator) -> Quarantined and deleted successfully. Valores do Registro infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wmplayer (Trojan.VB) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\explorer (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\csrcs (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\taskserv.exe (Trojan.Banker) -> Quarantined and deleted successfully. Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully. Pastas infectadas: C:\Arquivos de programas\FLV Direct Player (Adware.BHO.FL) -> Delete on reboot. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player (Adware.FLVPlayer) -> Quarantined and deleted successfully. Arquivos infectados: C:\MessengerPlus\IEBrowserEvents.dll (Trojan.BHO.H) -> Quarantined and deleted successfully. C:\MessengerPlus\wmplayer.exe (Trojan.VB) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{3F3BB39D-29BA-4782-ABA0-87EC32C7B760}\RP337\A0087997.exe (Trojan.Banker) -> Quarantined and deleted successfully. C:\WINDOWS\system32\s7EhO-nIA_6.exe (Adware.LoudMo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\FLVDirect.exe (Adware.MediaPass) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\downloading.swf (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\dskinliteu.dll (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\FLVPlayer.exe (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\player.dat (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\preload.swf (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\uninstall.exe (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin.xml (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_default.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_disable.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_normal.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonDown.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonHot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonNor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\edit_back.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menubg.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_arrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_check.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuitem_select.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_seperator.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\BottomBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\downarrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\LeftBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\Logo.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\main.ico (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\RightBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\TitlePattern.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player\FLV Direct Player.lnk (Adware.FLVPlayer) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player\Uninstall FLV Direct Player.lnk (Adware.FLVPlayer) -> Quarantined and deleted successfully. C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\RQVvIO.dll (Adware.AdRotator) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:20:41, on 19/3/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\VM_STI.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: http://www.flvdirect.com O15 - ESC Trusted Zone: http://www.flvdirect.com O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 8171 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 19, 2010 *Baixe o AD-Remover e salve-o no desktop *Duplo clique em AD-R.exe *Clique em [Clean]...aguarde o término *Cole o relatório criado em C:\Ad-Report-CLEAN.log e novo log do hijack Compartilhar este post Link para o post Compartilhar em outros sites
guigcs 0 Denunciar post Postado Março 19, 2010 . ======= AD-REMOVER 2.0.0.0,BREPORT | ONLY XP/VISTA/7 ======= . Updated by C_XX on 19/03/10 à 20:40 Contact: AdRemover.contact@gmail.com Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html . Started: 19:42:33 le 19/03/2010 | Normal boot | Option: CLEAN Executed from: C:\Ad-Remover\ADR.exe OS: Microsoft® Windows XP™ Service Pack 2 - X86 Computer name: ASDF-8BFEDC562E | Current user: usuario (Administrator) . ============== FIXED ELEMENTS ============== . . C:\Arquivos de programas\AskBarDis C:\Arquivos de programas\PokerStars C:\Documents and Settings\usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\4u2vjo6r.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} (!) -- Deleted temporary files. . HKCU\Software\AppDataLow\AskBarDis HKCU\Software\AskBarDis HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201f27d4-3704-41d6-89c1-aa35e39143ed} HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041d03e-fd4b-44e0-b742-2d9b88305f98} HKLM\Software\AskBarDis HKLM\Software\Classes\AskIBar.PopSwatterBarButton HKLM\Software\Classes\AskIBar.PopSwatterBarButton.1 HKLM\Software\Classes\AskIBar.PopSwatterSettingsControl HKLM\Software\Classes\AskIBar.PopSwatterSettingsControl.1 HKLM\Software\Classes\AskToolBar.SettingsPlugin HKLM\Software\Classes\AskToolBar.SettingsPlugin.1 HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f} HKLM\Software\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2} HKLM\Software\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E} HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed} HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98} HKLM\Software\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60} HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf} HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b} HKLM\Software\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362} HKLM\Software\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA} HKLM\Software\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9} HKLM\Software\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742} HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150} HKLM\Software\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2} HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1 HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98} HKLM\Software\Microsoft\Internet Explorer\Toolbar|{3041D03E-FD4B-44E0-B742-2D9B88305F98} . ============== ADDITIONNAL SCAN ============== . * Mozilla FireFox Version 3.5.8 (pt-BR) * . C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.download.dir: C:\\Documents and Settings\\usuario\\Desktop C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.download.lastDir: C:\\Documents and Settings\\usuario\\Desktop C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.search.defaultenginename: Search C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.search.defaulturl: hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search= C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.startup.homepage: hxxp://www.google.com.br/ C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.1.8 C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - keyword.URL: hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search= . . * Internet Explorer Version 6.0.2900.2180 * . [HKCU\Software\Microsoft\Internet Explorer\Main] . Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Do404Search: 0x01000000 Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 Show_ToolBar: yes Start Page: hxxp://fr.msn.com/ Use Search Asst: no . [HKLM\Software\Microsoft\Internet Explorer\Main] . Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Delete_Temp_Files_On_Exit: yes Local Page: %SystemRoot%\system32\blank.htm Search bar: hxxp://search.msn.com/spbasic.htm Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page: hxxp://fr.msn.com/ . [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] . Tabs: res://ieframe.dll/tabswelcome.htm Blank: res://mshtml.dll/blank.htm . ======================================== . C:\DOCUME~1\usuario\CONFIG~1\Temp: 2 Files, 22 Folders C:\WINDOWS\temp: 2 Files, 6 Folders Temporary Internet Files: 0 Files, 10 Folders . C:\Ad-Remover\Quarantine: 0 Files C:\Ad-Remover\Backup: 14 Files . C:\Ad-Report-CLEAN[1].txt - 5333 Byte(s) . End at:19:53:20, 19/03/2010 . ============== E.O.F - CLEAN[1] ============== Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:02:21, on 19/3/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\VM_STI.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: http://www.flvdirect.com O15 - ESC Trusted Zone: http://www.flvdirect.com O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 8065 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 19, 2010 1. *Execute novamente o AD-Remover *Clique em [uninstall] 2. *Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Remover tudo] *Clique na aba [Logs], selecione o relatório e clique em [Remover] 3. *Desative temporariamente seu antivírus Iniciar > Programas > AVG Abra a Interface do usuário do AVG Clique duas vezes na Proteção Residente Desmarque a opção "Proteção Residente ativa" Salve as alterações *Baixe o ComboFix e salve-o no desktop *Duplo-clique no arquivo Combofix.exe *Aceite o contrato *Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso não esteja, uma janela conforme abaixo será aberta. Clique em [sIM] para aceitar a instalação do mesmo. *Após a instalação, clique em [sIM] para continuar. *Aguarde a conclusão de todas as etapas *Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER. *O programa será fechado automaticamente *Cole o relatório criado em C:\combofix.txt Compartilhar este post Link para o post Compartilhar em outros sites
guigcs 0 Denunciar post Postado Março 20, 2010 ComboFix 10-03-19.06 - usuario 19/03/2010 20:41:59.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.223.7 [GMT -3:00] Executando de: c:\documents and settings\usuario\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Dados de aplicativos\UpApp32.dll c:\driver\Files\Desktop.ini C:\MessengerPlus c:\messengerplus\a01campos@ig.com.br1.log c:\messengerplus\acmottavilela@hotmail.com1.log c:\messengerplus\adeliagb@hotmail.com1.log c:\messengerplus\adeliamagal@hotmail.com1.log c:\messengerplus\alan_hilario@hotmail.com1.log c:\messengerplus\alepachecosvm@hotmail.com1.log c:\messengerplus\alexandrasvm@hotmail.com1.log c:\messengerplus\alexcamposfisco@hotmail.com1.log c:\messengerplus\alicealmeidaferreira@hotmail.com1.log c:\messengerplus\aline_sasso@hotmail.com1.log c:\messengerplus\alinejuste@gmail.com1.log c:\messengerplus\alinejuste@hotmail.com1.log c:\messengerplus\alinnecaneschi@hotmail.com1.log c:\messengerplus\alyne402@hotmail.com1.log c:\messengerplus\amanda_mg@msn.com1.log c:\messengerplus\amandadias_britto@hotmail.com1.log c:\messengerplus\anacondutta@hotmail.com1.log c:\messengerplus\anakrol_santos@hotmail.com1.log c:\messengerplus\analuisarleite@hotmail.com1.log c:\messengerplus\anapaulacamppos@hotmail.com1.log c:\messengerplus\anatereza007@hotmail.com1.log c:\messengerplus\andinhaloks@hotmail.com1.log c:\messengerplus\andre-fperon@hotmail.com1.log c:\messengerplus\andressacretha@hotmail.com1.log c:\messengerplus\anepotter_67@hotmail.com1.log c:\messengerplus\aninha_ksb@hotmail.com1.log c:\messengerplus\annapaulaguida@hotmail.com1.log c:\messengerplus\anninha.souza@hotmail.com1.log c:\messengerplus\annybruno@yahoo.com.br1.log c:\messengerplus\apruma@yahoo.com.br1.log c:\messengerplus\arcanjinhu@hotmail.com1.log c:\messengerplus\asmoxinhas@hotmail.com1.log c:\messengerplus\aspiranteapsicologa_joca@yahoo.com.br1.log c:\messengerplus\avirgilioferreira@yahoo.com.br1.log c:\messengerplus\baixinha141@hotmail.com1.log c:\messengerplus\bardock_lf@hotmail.com1.log c:\messengerplus\barreto279@hotmail.com1.log c:\messengerplus\baxandre@hotmail.com1.log c:\messengerplus\bebel-bela@hotmail.com1.log c:\messengerplus\bebeporto@hotmail.com1.log c:\messengerplus\belissimais@hotmail.com1.log c:\messengerplus\bethania_fm@hotmail.com1.log c:\messengerplus\bianca_012@hotmail.com1.log c:\messengerplus\biancas_rossi@hotmail.com1.log c:\messengerplus\bibifileh@hotmail.com1.log c:\messengerplus\bigtaycosta@hotmail.com1.log c:\messengerplus\bininhatavares@hotmail.com1.log c:\messengerplus\bmflipper@hotmail.com1.log c:\messengerplus\botelho963@hotmail.com1.log c:\messengerplus\bovareto@terra.com.br1.log c:\messengerplus\brauliomarciano@yahoo.com.br1.log c:\messengerplus\bruninha_bsv@hotmail.com1.log c:\messengerplus\bruninha_zampier@msn.com1.log c:\messengerplus\brunninh@hotmail.com1.log c:\messengerplus\bruno_uba@hotmail.com1.log c:\messengerplus\brunoazeve8@hotmail.com1.log c:\messengerplus\brunodasilvamiranda@gmail.com1.log c:\messengerplus\brunompboia@hotmail.com1.log c:\messengerplus\bulu_mirai@hotmail.com1.log c:\messengerplus\caiolreboucas@hotmail.com1.log c:\messengerplus\caiom_moreira@hotmail.com1.log c:\messengerplus\camilacalsavara@hotmail.com1.log c:\messengerplus\carla_ppzinha@hotmail.com1.log c:\messengerplus\carloseduardo_tuc@hotmail.com1.log c:\messengerplus\carolinapiva@hotmail.com1.log c:\messengerplus\carolugs@hotmail.com1.log c:\messengerplus\carolzinha.tur@hotmail.com1.log c:\messengerplus\carolzinhapaes@hotmail.com1.log c:\messengerplus\celsi.campos@hotmail.com1.log c:\messengerplus\celsiane.souza@fazenda.mg.gov.br1.log c:\messengerplus\celsicampos@hotmail.com1.log c:\messengerplus\celsosouzauba@hotmail.com1.log c:\messengerplus\ciceromaia@hotmail.com1.log c:\messengerplus\cinthia-ufjf@hotmail.com1.log c:\messengerplus\cintyaufv@hotmail.com1.log c:\messengerplus\claudinein@snv.com.br1.log c:\messengerplus\clebergomides@hotmail.com1.log c:\messengerplus\cleo_mariacoelho@hotmail.com1.log c:\messengerplus\clown-adm@hotmail.com1.log c:\messengerplus\colleman7@hotmail.com1.log c:\messengerplus\conradotgs@hotmail.com1.log c:\messengerplus\cpanalise1@intermedium.com.br1.log c:\messengerplus\cpanalise2@intermedium.com.br1.log c:\messengerplus\creonice_21@hotmail.com1.log c:\messengerplus\cristiane_alves_456@hotmail.com1.log c:\messengerplus\cupidopammachado@hotmail.com1.log c:\messengerplus\dalvinha.teixeira@hotmail.com1.log c:\messengerplus\danicoelhojf@hotmail.com1.log c:\messengerplus\daniele@intermedium.com.br1.log c:\messengerplus\daniloamedina@hotmail.com1.log c:\messengerplus\danizinha_guimaraes@hotmail.com1.log c:\messengerplus\dannyzimmermann@hotmail.com1.log c:\messengerplus\dayana_ribeirojf@hotmail.com1.log c:\messengerplus\deboraheloli@hotmail.com1.log c:\messengerplus\denisematipo@hotmail.com1.log c:\messengerplus\dennerskiter@hotmail.com1.log c:\messengerplus\deus_hades@hotmail.com1.log c:\messengerplus\diego_bianchi_@hotmail.com1.log c:\messengerplus\diogo_moreira82@hotmail.com1.log c:\messengerplus\distribuidoraakitem@hotmail.com1.log c:\messengerplus\djcka@hotmail.com1.log c:\messengerplus\djcka@yahoo.com.br1.log c:\messengerplus\drigommachado@hotmail.com1.log c:\messengerplus\du_152@hotmail.com1.log c:\messengerplus\dudaduda_888@hotmail.com1.log c:\messengerplus\dudinkka@hotmail.com1.log c:\messengerplus\ecila.vieira@hotmail.com1.log c:\messengerplus\edite80@hotmail.com1.log c:\messengerplus\eduardocpp@hotmail.com1.log c:\messengerplus\ehdementirinha@hotmail.com1.log c:\messengerplus\elainepatriciacm@hotmail.com1.log c:\messengerplus\eliermelo@yahoo.com.br1.log c:\messengerplus\elisaprocopio01@hotmail.com1.log c:\messengerplus\elton_me@hotmail.com1.log c:\messengerplus\emmanuel_costa@hotmail.com1.log c:\messengerplus\enviado.flg c:\messengerplus\estevaocruz@hotmail.com1.log c:\messengerplus\evelynalbuquerque@hotmail.com1.log c:\messengerplus\evezinha_maia@hotmail.com1.log c:\messengerplus\extra_cred@hotmail.com1.log c:\messengerplus\f.rbraga@hotmail.com1.log c:\messengerplus\fabin_magrin@hotmail.com1.log c:\messengerplus\fastdel@hotmail.com1.log c:\messengerplus\fefe_thebest_vip@hotmail.com1.log c:\messengerplus\feiterer@hotmail.com1.log c:\messengerplus\felipecogu@hotmail.com1.log c:\messengerplus\felipepiva@hotmail.com1.log c:\messengerplus\feliperodriguestokio@hotmail.com1.log c:\messengerplus\felippe_cr7@hotmail.com1.log c:\messengerplus\felippebalbi@msn.com1.log c:\messengerplus\fernanda_salomao@hotmail.com1.log c:\messengerplus\fernandinha_cp2@hotmail.com1.log c:\messengerplus\feuzinho4@hotmail.com1.log c:\messengerplus\filippemoreira@msn.com1.log c:\messengerplus\fiuza_@hotmail.com1.log c:\messengerplus\flaviajunqueira@msn.com1.log c:\messengerplus\fotoiris@yahoo.com.br1.log c:\messengerplus\francielecasal@hotmail.com1.log c:\messengerplus\frbilheri@hotmail.com1.log c:\messengerplus\g735@hotmail.com1.log c:\messengerplus\gabih_kuwabara@hotmail.com1.log c:\messengerplus\gabimehri@hotmail.com1.log c:\messengerplus\gabrielamello_01@hotmail.com1.log c:\messengerplus\gabriellaramos@hotmail.com1.log c:\messengerplus\gabrielmcampos@msn.com1.log c:\messengerplus\gabrielmcampos@yahoo.com.br1.log c:\messengerplus\gaofernandes@hotmail.com1.log c:\messengerplus\gatas_groppo@hotmail.com1.log c:\messengerplus\gerfisio@hotmail.com1.log c:\messengerplus\gestor.cadastro@intermedium.com.br1.log c:\messengerplus\gestor.operacional@intermedium.com.br1.log c:\messengerplus\gi_htinha666@hotmail.com1.log c:\messengerplus\gianinigandhi@yahoo.com1.log c:\messengerplus\gipcardoso@hotmail.com1.log c:\messengerplus\gisellerq@hotmail.com1.log c:\messengerplus\gisiane-lopes@hotmail.com1.log c:\messengerplus\gmvalverde@hotmail.com1.log c:\messengerplus\graziroberti@hotmail.com1.log c:\messengerplus\grazitrevenzoli@hotmail.com1.log c:\messengerplus\guigcs@gmail.com1.log c:\messengerplus\guilherme.c.toledo@hotmail.com1.log c:\messengerplus\guilhermegravina@hotmail.com1.log c:\messengerplus\guilhermesreis10@hotmail.com1.log c:\messengerplus\guimaraes_araujo@hotmail.com1.log c:\messengerplus\gustavocamposalmeida@hotmail.com1.log c:\messengerplus\guytruta@hotmail.com1.log c:\messengerplus\gvcasado@hotmail.com1.log c:\messengerplus\hbovareto@hotmail.com1.log c:\messengerplus\helves@intermedium.com.br1.log c:\messengerplus\henrao@hotmail.com1.log c:\messengerplus\heronfchagas@hotmail.com1.log c:\messengerplus\hugomn@gmail.com1.log c:\messengerplus\huguin_moreira@hotmail.com1.log c:\messengerplus\humbertindocoracao@hotmail.com1.log c:\messengerplus\igor_mdvm@hotmail.com1.log c:\messengerplus\ikaroteixeira@hotmail.com1.log c:\messengerplus\iki.almeida@hotmail.com1.log c:\messengerplus\isabelamariadeoliveira@hotmail.com1.log c:\messengerplus\isabella_limaoliveira@hotmail.com1.log c:\messengerplus\isagily@hotmail.com1.log c:\messengerplus\isianedurso1@hotmail.com1.log c:\messengerplus\ivsgyn@hotmail.com1.log c:\messengerplus\jannyso@hotmail.com1.log c:\messengerplus\jaop_sol@hotmail.com1.log c:\messengerplus\jardelhc@hotmail.com1.log c:\messengerplus\jayme_ab@hotmail.com1.log c:\messengerplus\jessiquinha_tdb@hotmail.com1.log c:\messengerplus\jlcarpolminastex@hotmail.com1.log c:\messengerplus\jmarepre@yahoo.com.br1.log c:\messengerplus\jmoreira102@hotmail.com1.log c:\messengerplus\joanna.dantas@hotmail.com1.log c:\messengerplus\jonedebruce@hotmail.com1.log c:\messengerplus\jordanamarques@uol.com.br1.log c:\messengerplus\joseanedoa@hotmail.com1.log c:\messengerplus\josi.real@hotmail.com1.log c:\messengerplus\jositavares21@hotmail.com1.log c:\messengerplus\joyce_af@hotmail.com1.log c:\messengerplus\ju_filezinha@hotmail.com1.log c:\messengerplus\jubcastro1@hotmail.com1.log c:\messengerplus\jujubinha_mag@hotmail.com1.log c:\messengerplus\julia_furiati@hotmail.com1.log c:\messengerplus\juliana-cretha@hotmail.com1.log c:\messengerplus\julianaphonseca@hotmail.com1.log c:\messengerplus\julianasalimena@terra.com.br1.log c:\messengerplus\julibressan@hotmail.com1.log c:\messengerplus\julis_jacob@hotmail.com1.log c:\messengerplus\julisjacob@hotmail.com1.log c:\messengerplus\july_kt@hotmail.com1.log c:\messengerplus\juniabretas@hotmail.com1.log c:\messengerplus\juninho2501@hotmail.com1.log c:\messengerplus\jussara_mag@hotmail.com1.log c:\messengerplus\juupdate18.log c:\messengerplus\kaizinhaaa@hotmail.com1.log c:\messengerplus\kaka_rp16@hotmail.com1.log c:\messengerplus\kamilacrp@hotmail.com1.log c:\messengerplus\karolcaputo@hotmail.com1.log c:\messengerplus\kezinhah@hotmail.com1.log c:\messengerplus\kikamcg@hotmail.com1.log c:\messengerplus\kk.soares@hotmail.com1.log c:\messengerplus\kley_2005@hotmail.com1.log c:\messengerplus\kulla_botelho@hotmail.com1.log c:\messengerplus\kynhacarvalho@hotmail.com1.log c:\messengerplus\lailacfp@hotmail.com1.log c:\messengerplus\lailapiva@hotmail.com1.log c:\messengerplus\lais_fonseca@hotmail.com1.log c:\messengerplus\laisbalbi@hotmail.com1.log c:\messengerplus\laiscruzp@hotmail.com1.log c:\messengerplus\laisfonseca_@hotmail.com1.log c:\messengerplus\laizmn@hotmail.com1.log c:\messengerplus\lala_nteixeira@hotmail.com1.log c:\messengerplus\laramnogueira@hotmail.com1.log c:\messengerplus\larinha3@yahoo.com.br1.log c:\messengerplus\larinhafeital@hotmail.com1.log c:\messengerplus\larissa_cotta@hotmail.com1.log c:\messengerplus\lauragprata@hotmail.com1.log c:\messengerplus\laurobombinha@hotmail.com1.log c:\messengerplus\laysecohen@live.com1.log c:\messengerplus\leandrouba@hotmail.com1.log c:\messengerplus\leila-_-@hotmail.com1.log c:\messengerplus\leliudes@hotmail.com1.log c:\messengerplus\lenasouza02@hotmail.com1.log c:\messengerplus\leofaki@hotmail.com.br1.log c:\messengerplus\lialilida@hotmail.com1.log c:\messengerplus\liamaradruda@hotmail.com1.log c:\messengerplus\lidao1@msn.com1.log c:\messengerplus\lili_stp@hotmail.com1.log c:\messengerplus\lilianetolomelli@hotmail.com1.log c:\messengerplus\liviacurty@hotmail.com1.log c:\messengerplus\livinhamsb@hotmail.com1.log c:\messengerplus\livinhasimoes@yahoo.com.br1.log c:\messengerplus\lorraine.cso@hotmail.com1.log c:\messengerplus\luanacb2000@yahoo.com.br1.log c:\messengerplus\luanamc6@hotmail.com1.log c:\messengerplus\luanaribeiro2006@hotmail.com1.log c:\messengerplus\luanatoledo7_9@hotmail.com1.log c:\messengerplus\luannalexandre@hotmail.com1.log c:\messengerplus\lucaspiersanti@hotmail.com1.log c:\messengerplus\luciana_gravina@hotmail.com1.log c:\messengerplus\lucyassef29@hotmail.com1.log c:\messengerplus\lud_werneque@hotmail.com1.log c:\messengerplus\ludmila555@hotmail.com1.log c:\messengerplus\luga_brandao@hotmail.com1.log c:\messengerplus\luis_o_bom@hotmail.com1.log c:\messengerplus\luiza_sansao@hotmail.com1.log c:\messengerplus\luizabethlopes@hotmail.com1.log c:\messengerplus\luizabranches@hotmail.com1.log c:\messengerplus\luizapabranches@hotmail.com1.log c:\messengerplus\luizinhoff@msn.com1.log c:\messengerplus\lunna_vc@hotmail.com1.log c:\messengerplus\lusaiki@hotmail.com1.log c:\messengerplus\maira_rosa85@hotmail.com1.log c:\messengerplus\mapalmas@hotmail.com1.log c:\messengerplus\marcelabaiao2@hotmail.com1.log c:\messengerplus\marcelacretha@hotmail.com1.log c:\messengerplus\marcelinhamf15@hotmail.com1.log c:\messengerplus\marcelo_ramos@hotmail.com1.log c:\messengerplus\marcioartesanato@hotmail.com1.log c:\messengerplus\marcobonoto@hotmail.com1.log c:\messengerplus\mari_vieirajf@hotmail.com1.log c:\messengerplus\mariana_teixeira_44@hotmail.com1.log c:\messengerplus\marianacampos_88@hotmail.com1.log c:\messengerplus\marianacasella27@hotmail.com1.log c:\messengerplus\marianepena@yahoo.com.br1.log c:\messengerplus\marinabitarello@hotmail.com1.log c:\messengerplus\marinaflautista@hotmail.com1.log c:\messengerplus\marinafusaro@yahoo.com.br1.log c:\messengerplus\mariviannatop@hotmail.com1.log c:\messengerplus\mary-inha@hotmail.com1.log c:\messengerplus\maryrossinjf@hotmail.com1.log c:\messengerplus\massai_tr@hotmail.com1.log c:\messengerplus\mathiasagostini@yahoo.com.br1.log c:\messengerplus\meirepaivamoreira@hotmail.com1.log c:\messengerplus\meiretmpaiva@hotmail.com1.log c:\messengerplus\meli_mschmid@hotmail.com1.log c:\messengerplus\mfernandacls@hotmail.com1.log c:\messengerplus\micheleangel_79@hotmail.com1.log c:\messengerplus\migamali@hotmail.com1.log c:\messengerplus\milamoises@hotmail.com1.log c:\messengerplus\millasiv@hotmail.com1.log c:\messengerplus\mimilamarinho@hotmail.com1.log c:\messengerplus\mississippi_brazilian@hotmail.com1.log c:\messengerplus\mo_jf@hotmail.com1.log c:\messengerplus\morais_881@hotmail.com1.log c:\messengerplus\moraleida@oi.com.br1.log c:\messengerplus\moygori@hotmail.com1.log c:\messengerplus\mpsjf@hotmail.com1.log c:\messengerplus\myller666@hotmail.com1.log c:\messengerplus\myndocrym@msn.com1.log c:\messengerplus\nadja_ganda@hotmail.com1.log c:\messengerplus\nandalimasd@hotmail.com1.log c:\messengerplus\nandavicosa@hotmail.com1.log c:\messengerplus\nandopovoa@hotmail.com1.log c:\messengerplus\nataliaparma@hotmail.com1.log c:\messengerplus\natashatgs@hotmail.com1.log c:\messengerplus\nathaliabonissatto@hotmail.com1.log c:\messengerplus\nathaliagm@hotmail.com1.log c:\messengerplus\nathcb@hotmail.com1.log c:\messengerplus\nathypa@hotmail.com1.log c:\messengerplus\nati_az@hotmail.com1.log c:\messengerplus\naty_camposp@hotmail.com1.log c:\messengerplus\nayracoelho@hotmail.com1.log c:\messengerplus\nebailarocca@hotmail.com1.log c:\messengerplus\nessafreis@hotmail.com1.log c:\messengerplus\nicoletolomelli@hotmail.com1.log c:\messengerplus\nina-sousa@hotmail.com1.log c:\messengerplus\nina_apocalypse@hotmail.com1.log c:\messengerplus\odilontokio@hotmail.com1.log c:\messengerplus\olaninola@hotmail.com1.log c:\messengerplus\olinda-chaves@hotmail.com1.log c:\messengerplus\oliviamoreira_oli@hotmail.com1.log c:\messengerplus\oscarwgbressan@hotmail.com1.log c:\messengerplus\pamellamachadomadagascar@hotmail.com1.log c:\messengerplus\pat_uba@hotmail.com1.log c:\messengerplus\patmontesi@msn.com1.log c:\messengerplus\patriciagomes@intermedium.com.br1.log c:\messengerplus\paty_sanna@hotmail.com1.log c:\messengerplus\paulacorbelli@gmail.com1.log c:\messengerplus\paulatmarques@hotmail.com1.log c:\messengerplus\paulo.cadastro@intermedium.com.br1.log c:\messengerplus\pc_mantikeira@hotmail.com1.log c:\messengerplus\pf_relacionamento1@intermedium.com.br1.log c:\messengerplus\pf_relacionamento2@intermedium.com.br1.log c:\messengerplus\pf_relacionamento4@intermedium.com.br1.log c:\messengerplus\pf_relacionamento5@intermedium.com.br1.log c:\messengerplus\pilarzinhamc@hotmail.com1.log c:\messengerplus\pimentinhajf@hotmail.com1.log c:\messengerplus\poetajf@hotmail.com1.log c:\messengerplus\poliaps@hotmail.com1.log c:\messengerplus\pollyanaalbuquerque@hotmail.com1.log c:\messengerplus\polyanapsoares@hotmail.com1.log c:\messengerplus\prigp_87@hotmail.com1.log c:\messengerplus\priprilla21@hotmail.com1.log c:\messengerplus\prock2001@msn.com1.log c:\messengerplus\quel-mmonteiro@hotmail.com1.log c:\messengerplus\rafael_defaria@hotmail.com1.log c:\messengerplus\rafaleviana@hotmail.com1.log c:\messengerplus\rafitxacastelloes@hotmail.com1.log c:\messengerplus\ramfmg@hotmail.com1.log c:\messengerplus\raphaela2807@hotmail.com1.log c:\messengerplus\raphaelaqueiroz@hotmail.com1.log c:\messengerplus\raphinhapx@hotmail.com1.log c:\messengerplus\raquelcardosojf@hotmail.com1.log c:\messengerplus\raulzitah@hotmail.com1.log c:\messengerplus\re_cheaps@hotmail.com1.log c:\messengerplus\rebsbeca@hotmail.com1.log c:\messengerplus\recarvalho16@hotmail.com1.log c:\messengerplus\ree_camarano@hotmail.com1.log c:\messengerplus\regina.remonteiro@gmail.com1.log c:\messengerplus\renata_campomizzi@hotmail.com1.log c:\messengerplus\renata_s_souza@hotmail.com1.log c:\messengerplus\renatatokio@hotmail.com1.log c:\messengerplus\renatinhabperes@hotmail.com1.log c:\messengerplus\ricardo_muranga@hotmail.com1.log c:\messengerplus\robertafeital@hotmail.com1.log c:\messengerplus\rodney.quirino@hotmail.com1.log c:\messengerplus\rodrigolima_159@hotmail.com1.log c:\messengerplus\ronanbahia@hotmail.com1.log c:\messengerplus\rosane-sf@hotmail.com1.log c:\messengerplus\rosane_fernandes@bol.com.br1.log c:\messengerplus\rpcorbelli@hotmail.com1.log c:\messengerplus\ruivavp@hotmail.com1.log c:\messengerplus\sa_caio@hotmail.com1.log c:\messengerplus\sammycardoso17@hotmail.com1.log c:\messengerplus\samuca_do_mau@hotmail.com1.log c:\messengerplus\samuel_chaves@hotmail.com1.log c:\messengerplus\samyaiasbeck@gmail.com1.log c:\messengerplus\sanpam_10@hotmail.com1.log c:\messengerplus\sapi@intermedium.com.br1.log c:\messengerplus\sapi1@intermedium.com.br1.log c:\messengerplus\sapi2@intermedium.com.br1.log c:\messengerplus\sapi3@intermedium.com.br1.log c:\messengerplus\sapi5@intermedium.com.br1.log c:\messengerplus\sapi6@intermedium.com.br1.log c:\messengerplus\sapi7@intermedium.com.br1.log c:\messengerplus\saradtb@hotmail.com1.log c:\messengerplus\sazaneti@hotmail.com1.log c:\messengerplus\sde_dudzzz@hotmail.com1.log c:\messengerplus\sheilasperandio@hotmail.com1.log c:\messengerplus\sillasesacol@yahoo.com.br1.log c:\messengerplus\skiterd2@hotmail.com1.log c:\messengerplus\ssminasgerais@hotmail.com1.log c:\messengerplus\stephanemeirelesmarques@hotmail.com1.log c:\messengerplus\stksf@hotmail.com1.log c:\messengerplus\studio1fot@hotmail.com1.log c:\messengerplus\sylvianecascata@hotmail.com1.log c:\messengerplus\sylvinho_caxambu@hotmail.com1.log c:\messengerplus\sylvinho69@hotmail.com1.log c:\messengerplus\taci.lee@hotmail.com1.log c:\messengerplus\taci_lee@hotmail.com1.log c:\messengerplus\talise_machado@hotmail.com1.log c:\messengerplus\tataqp@hotmail.com1.log c:\messengerplus\tatiass@hotmail.com1.log c:\messengerplus\tattinha_pimenta85@hotmail.com1.log c:\messengerplus\teoniliof@snv.com.br1.log c:\messengerplus\terracred@yahoo.com.br1.log c:\messengerplus\tete_nejaim@hotmail.com1.log c:\messengerplus\thabatasofia@hotmail.com1.log c:\messengerplus\thais_minnie@hotmail.com1.log c:\messengerplus\thaiscostaamaral@hotmail.com1.log c:\messengerplus\thaismatosdeassis@hotmail.com1.log c:\messengerplus\thalytaqueiroz1@hotmail.com1.log c:\messengerplus\thatalentosa@hotmail.com1.log c:\messengerplus\thati_magalhaes@hotmail.com1.log c:\messengerplus\theresasingulani@hotmail.com1.log c:\messengerplus\thety_zotta@hotmail.com1.log c:\messengerplus\thiarama@hotmail.com1.log c:\messengerplus\thielytavares@hotmail.com1.log c:\messengerplus\tiagodutra31@hotmail.com1.log c:\messengerplus\tianinhabento@yahoo.com.br1.log c:\messengerplus\toniana_gc@hotmail.com1.log c:\messengerplus\tovalente@gmail.com1.log c:\messengerplus\trinca_jf@hotmail.com1.log c:\messengerplus\triplicerepresentacoes@hotmail.com1.log c:\messengerplus\uba_mg@hotmail.com1.log c:\messengerplus\ubacred@hotmail.com1.log c:\messengerplus\ubacreduba@yahoo.com.br1.log c:\messengerplus\ubahisufv@yahoo.com.br1.log c:\messengerplus\ubashop@msn.com1.log c:\messengerplus\valeriabraga25@hotmail.com1.log c:\messengerplus\valeriabragacb@hotmail.com1.log c:\messengerplus\valtaglia@hotmail.com1.log c:\messengerplus\vanessasabioni@hotmail.com1.log c:\messengerplus\vanessasterk@hotmail.com1.log c:\messengerplus\veninasilveira@hotmail.com1.log c:\messengerplus\victoragroufv@hotmail.com1.log c:\messengerplus\virginia@intermedium.com.br1.log c:\messengerplus\virginiacancado@terra.com.br1.log c:\messengerplus\viror3000@hotmail.com1.log c:\messengerplus\vitougaloucura@hotmail.com1.log c:\messengerplus\vivialevato_11@hotmail.com1.log c:\messengerplus\vrbcred@konet.com.br1.log c:\messengerplus\walaceame@yahoo.com.br1.log c:\messengerplus\wanessacampos@yahoo.com.br1.log c:\messengerplus\waniaalmeidaa@uol.com.br1.log c:\messengerplus\weimarbcjunior@yahoo.com.br1.log c:\messengerplus\weimarbraga@yahoo.com.br1.log c:\messengerplus\william.guidini@hotmail.com1.log c:\messengerplus\wilmabcs@hotmail.com1.log c:\messengerplus\wilmarjuniocm@hotmail.com1.log c:\messengerplus\xavier1357@hotmail.com1.log c:\messengerplus\xgnomax@tayrine.com1.log c:\messengerplus\yahoo c:\messengerplus\yohanabraga10@hotmail.com1.log c:\messengerplus\yvini@hotmail.com1.log c:\messengerplus\zoommiag@hotmail.com1.log c:\windows\system32\AutoRun.inf . (((((((((((((((( Arquivos/Ficheiros criados de 2010-02-19 to 2010-03-19 )))))))))))))))))))))))))))) . 2010-03-19 18:04 . 2010-03-19 18:04 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Malwarebytes 2010-03-19 18:04 . 2010-01-07 19:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-19 18:03 . 2010-03-19 18:03 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2010-03-19 18:03 . 2010-01-07 19:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-19 18:03 . 2010-03-19 18:04 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2010-03-19 14:50 . 2010-03-19 21:12 -------- d-----w- c:\windows\SxsCaPendDel 2010-03-19 13:06 . 2010-03-18 23:12 1111320 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgssie.dll 2010-03-18 23:16 . 2010-03-18 19:13 90632 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgtdix.sys 2010-03-18 23:16 . 2010-03-18 19:13 98440 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgldx86.sys 2010-03-18 23:15 . 2010-03-18 19:13 10520 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgrsstx.dll 2010-03-18 23:15 . 2010-03-18 19:13 287000 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgrsx.exe 2010-03-18 23:15 . 2010-03-18 19:13 26824 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmfx86.sys 2010-03-18 22:37 . 2010-03-18 22:36 1126168 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgupd.exe 2010-03-18 22:37 . 2010-03-18 22:36 1471768 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgupd.dll 2010-03-18 22:37 . 2010-03-18 22:36 587032 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgiproxy.exe 2010-03-18 22:37 . 2010-03-18 22:36 758040 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avginet.dll 2010-03-18 22:13 . 2010-03-19 18:26 -------- d-----w- C:\$AVG8.VAULT$ 2010-03-18 19:13 . 2010-03-18 23:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2010-03-18 19:13 . 2010-03-18 23:13 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-03-18 19:13 . 2010-03-18 23:13 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-03-18 19:13 . 2010-03-18 23:13 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-03-18 19:13 . 2010-03-19 13:12 -------- d-----w- c:\windows\system32\drivers\Avg 2010-03-07 16:16 . 2010-03-07 16:16 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype 2010-03-06 13:18 . 2010-03-06 13:18 -------- d-----r- C:\Driver . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-19 00:16 . 2008-09-24 11:05 -------- d-----w- c:\arquivos de programas\LHSP 2010-03-18 23:16 . 2008-12-01 18:27 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avg8 2010-03-18 23:13 . 2010-03-19 13:07 693016 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcsrvx.exe 2010-03-18 23:13 . 2010-03-19 13:07 390424 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgclitx.dll 2010-03-18 23:13 . 2010-03-19 13:07 70424 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcrlpx.dll 2010-03-18 23:13 . 2010-03-19 13:07 418072 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcclix.dll 2010-03-18 23:13 . 2010-03-19 13:07 2061592 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcorex.dll 2010-03-18 23:13 . 2010-03-19 13:07 2308888 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avguiadv.dll 2010-03-18 23:13 . 2010-03-19 13:07 2808600 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avguires.dll 2010-03-18 23:13 . 2010-03-19 13:07 3476760 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgui.exe 2010-03-18 23:13 . 2010-03-19 13:07 2000152 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgtray.exe 2010-03-18 23:13 . 2010-03-19 13:07 1213720 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgfrw.exe 2010-03-18 23:13 . 2010-03-19 13:07 1209112 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgabout.dll 2010-03-18 23:13 . 2010-03-19 13:07 3299608 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\setup.exe 2010-03-18 23:11 . 2010-03-19 13:06 339736 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgscanx.dll 2010-03-18 23:11 . 2010-03-19 13:06 305944 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmvflx.dll 2010-03-18 23:11 . 2010-03-19 13:06 177432 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmail.dll 2010-03-18 23:11 . 2010-03-19 13:06 310552 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avglngx.dll 2010-03-18 23:11 . 2010-03-19 13:06 836888 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcfgx.dll 2010-03-18 19:13 . 2010-03-19 13:07 2075416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgresf.dll 2010-03-07 16:38 . 2009-11-24 00:15 79488 ----a-w- c:\documents and settings\usuario\Dados de aplicativos\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-07 16:26 . 2008-10-27 13:38 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Skype 2010-03-07 16:18 . 2008-10-27 13:42 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\skypePM 2010-03-07 16:16 . 2009-09-06 16:34 -------- d-----r- c:\arquivos de programas\Skype 2010-03-07 16:16 . 2008-10-27 13:32 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Skype 2010-02-19 11:46 . 2001-10-28 13:07 68408 ----a-w- c:\windows\system32\perfc016.dat 2010-02-19 11:46 . 2001-10-28 13:07 428340 ----a-w- c:\windows\system32\perfh016.dat 2010-02-10 14:35 . 2010-02-04 13:26 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Youtube Downloader HD 2010-02-05 15:12 . 2010-02-05 15:12 -------- d-----w- c:\arquivos de programas\MSECache 2010-02-04 13:26 . 2010-02-04 13:26 -------- d-----w- c:\arquivos de programas\Youtube Downloader HD 2010-01-24 14:50 . 2010-01-24 14:50 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Foxit 2010-01-24 14:50 . 2010-01-24 14:50 -------- d-----w- c:\arquivos de programas\Foxit Software 2010-01-19 22:10 . 2008-09-25 21:32 -------- d-----w- c:\arquivos de programas\FlashGet . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360] "swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-09 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "BigDogPath"="c:\windows\VM_STI.EXE" [2003-01-22 40960] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-21 136600] "PCSuiteTrayApplication"="c:\arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] "Nokia.PCSync"="c:\arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-03-18 23:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\FlashGet\\FlashGet.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\RkSoft\\Xadrez\\xadrez.exe"= "c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"= "c:\\Arquivos de programas\\NetMeeting\\conf.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/3/2010 16:13 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/3/2010 16:13 108552] R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [10/1/2010 14:02 19064] R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [18/3/2010 20:12 297752] . . ------- Scan Suplementar ------- . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Descarregar tudo com o FlashGet - c:\arquivos de programas\FlashGet\jc_all.htm IE: &Descarregar utilizando o FlashGet - c:\arquivos de programas\FlashGet\jc_link.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html Trusted Zone: flvdirect.com\www DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\4u2vjo6r.default\ FF - prefs.js: browser.search.defaulturl - hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search= FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/ FF - prefs.js: keyword.URL - hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search= FF - component: c:\arquivos de programas\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\{347f6522-829d-3f64-db77-001c59f0aa68}\components\4wNzgJ9l-JALh.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . - - - - ORFÃOS REMOVIDOS - - - - HKCU-Run-MsnMsgr - c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-19 20:53 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-1275210071-1993962763-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C45B8DE4-45A6-3F60-9886-8E844345BAC7}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) "abpecplbnoajdiialjgnkjpmbagmplplig"=hex:69,61,61,65,61,6d,6b,6d,6f,61,61,63, 63,66,61,6a,65,6b,00,00 "maoennbnmkegmoimmpkpnjmpok"=hex:6f,61,6c,6b,62,6e,65,69,61,69,62,66,6c,64,61, 67,68,65,6a,66,61,6e,6c,61,6d,6a,6f,63,6b,70,00,00 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Òw*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . Tempo para conclusão: 2010-03-19 20:59:33 ComboFix-quarantined-files.txt 2010-03-19 23:59 Pré-execução: 2.927.632.384 bytes disponíveis Pós execução: 2.908.372.992 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - 844738871136205603DDB38DC40DBD8C Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 20, 2010 Por favor..... Novo log do hijack. Compartilhar este post Link para o post Compartilhar em outros sites
guigcs 0 Denunciar post Postado Março 20, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:40:13, on 20/3/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\VM_STI.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: http://www.flvdirect.com O15 - ESC Trusted Zone: http://www.flvdirect.com O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 7906 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 20, 2010 OK...o PC está limpo. :) *Clique em [iniciar] > [Executar] > digite: Combofix /uninstall *Clique [OK] *Clique em [Executar] *Aguarde até surgir a mensagem: "ComboFix está desinstalado" *Clique [OK] Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
guigcs 0 Denunciar post Postado Março 20, 2010 Muito obrigado, deu tudo certo. Só mais uma dúvida. Eu reparei q apareceu a lista das pessoas do meu msn. E tb enquanto estava com vírus ficava acusando a pasta messenger plus. Inclusive nesse meio tempo eu desinstalei o windows live. Hoje, durante a instalação do messenger eu precisei cancelá-la e agora quando fui instalar de novo não tá dando de jeito nenhum. tá dando erro. você sabe me explicar porquê disso? E o q devo fazer? Novamente, muito obrigado! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 20, 2010 Não entendi bem o seu problema.... Mas, dê uma lida neste tutorial: http://www.baixaki.com.br/info/2278-aprenda-a-corrigir-os-erros-do-seu-msn.htm Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Março 22, 2010 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites