Luizfc_ 0 Denunciar post Postado Maio 8, 2011 Toda vez que ligo meu pc esse Erro de aplicativo "avgwdsvc.exe" aparece 2 vezes Fiz um log com o Hijackthis. Segue o Log! Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:47:42, on 8/5/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe C:\WINDOWS\system32\sistray.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe C:\Arquivos de programas\AVG\AVG9\avgnsx.exe C:\Arquivos de programas\AVG\AVG9\avgchsvx.exe C:\Arquivos de programas\AVG\AVG9\avgrsx.exe C:\Arquivos de programas\AVG\AVG9\avgcsrvx.exe C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tangosearch.com/?useie5=1&q= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing) O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Arquivos de programas\ConduitEngine\prxConduitEngine.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Tango - {9C398D3F-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing) O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing) O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O3 - Toolbar: Tango - {9C398D3E-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing) O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Arquivos de programas\ConduitEngine\prxConduitEngine.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing) O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: QuestBrowser Service - Unknown owner - C:\Documents and Settings\All Users\Dados de aplicativos\QuestBrowser\questbrowser117.exe (file missing) O23 - Service: STSService - Unknown owner - C:\Arquivos de programas\SoundTaxi Media Suite\STSService.exe (file missing) -- End of file - 13541 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 8, 2011 :) Olá Luizfc_! :seta: Vá no menu: Iniciar > Painel de Controle > Adicionar ou remover programas > clique no Avg e clique em Remover > aí é só ir seguindo os passos que o desinstalador do Avg vai lhe passando para desinstalar ele. Depois de desinstalar o Avg, sugiro que você o troque pelo Avira ou outro antivirus gratuito de sua preferência, pois o Avg está tendo problemas ultimamente. Caso queira trocá-lo pelo Avira, é só seguir as dicas destes tutoriais para instalá-lo, configurá-lo e utilizá-lo corretamente: Tutorial do Avira AntiVir Personal Edition Classic (Instalação e Configuração) Tutorial do Avira AntiVir Personal Edition Classic (como usá-lo corretamente) ________________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylo....19&affID=17159 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....19&affID=17159 O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Tango - {9C398D3F-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing) O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing) O3 - Toolbar: Tango - {9C398D3E-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing) O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing) ______________________ :seta: Siga também estas dicas: Tutorial do Ad-Remover Tutorial do Malwarebytes Anti-Malware _______________________ :seta: Na sua próxima resposta poste o log do Malwarebytes juntamente com um novo log do Hijackthis, o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log e nos diga como está o seu PC após estes procedimentos. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 9, 2011 Boa Noite, obrigado pela ajuda, Segue Logs.: Ad-Remover ======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 20:50:37 on 08/05/2011, Normal boot Microsoft Windows XP Professional Service Pack 3 (X86) Luizinho@CASA-72A2ETXOUB ( ) ============== ACTION(S) ============== File deleted: C:\WINDOWS\system32\ConduitEngine.tmp Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\conduit File deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\searchplugins\conduit.xml Folder deleted: C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Conduit Folder deleted: C:\Arquivos de programas\Conduit Folder deleted: C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\ConduitEngine Folder deleted: C:\Arquivos de programas\ConduitEngine Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\GabPath Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Toolbar4 (!) -- Temporary files deleted. -- File opened: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\Prefs.js -- Line deleted: user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&Sea... -- File closed -- Key deleted: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D} Key deleted: HKLM\Software\Classes\CLSID\{65B3F26E-13AE-418E-AC22-ECDB8D9FD6D3} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{65B3F26E-13AE-418E-AC22-ECDB8D9FD6D3} Key deleted: HKLM\Software\Classes\Conduit.Engine Key deleted: HKLM\Software\Classes\Toolbar.CT2737658 Key deleted: HKLM\Software\Conduit Key deleted: HKLM\Software\conduitEngine Key deleted: HKCU\Software\Conduit Key deleted: HKCU\Software\conduitEngine Key deleted: HKCU\Software\IEBarProperties Key deleted: HKCU\Software\MarketPrecision Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Adparatus Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5} Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{213DD725-3D40-4EEF-AAEE-7A48A1070CFA} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine Key deleted: HKLM\Software\Microsoft\ESENT\Process\Adparatus Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [4.0.1 (pt-BR)] **** Plugins\libdivx.dll (The OpenSSL Project, http://www.openssl.org/) Plugins\npdivx32.dll (DivX,Inc.) Plugins\npDivxPlayerPlugin.dll (DivX, Inc) Plugins\NpFv501.dll (1 mal 1 Software GmbH) Plugins\npganymedenet.dll ( ) Plugins\npwachk.dll (Nullsoft, Inc.) Plugins\ssldivx.dll (The OpenSSL Project, http://www.openssl.org/) HKCU_MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0 (x) HKCU_MozillaPlugins\electronicarts.com/GameFacePlugin (x) Searchplugins\babylon.xml (hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159/) Searchplugins\buscape.xml (hxxp://busca.buscape.com.br/cprocura) Searchplugins\mercadolivre.xml (hxxp://pmstrk.mercadolivre.com.br/jm/PmsTrk) Searchplugins\wikipedia-br.xml (hxxp://pt.wikipedia.org/wiki/Especial:Busca) Searchplugins\yahoo-br.xml (hxxp://br.search.yahoo.com/search) Components\browsercomps.dll (Mozilla Foundation) Extensions\{B13721C7-F507-4982-B2E5-502A71474FED} (Skype extension for Firefox ) Extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6} (QuestBrowser) HKLM_Extensions|{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}\ -- C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default -- Extensions\newtaburl@sogame.cat (NewTabURL) Extensions\SkipScreen@SkipScreen (SkipScreen) Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} (Flagfox) Extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66} (Charles Autoconfiguration) Extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C} (Módulo de Segurança - Banco do Brasil) Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} (DVDVideoSoft Menu) Extensions\{cc409fe8-42b4-405b-a9fa-02dfcffbedde} (OMusic) Searchplugins\search-the-web.xml (?) Searchplugins\winamp-search.xml (?) Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Luizinho\\Desktop Prefs.js - browser.search.defaultenginename, Prefs.js - browser.startup.homepage, hxxp://www.google.com.br/ Prefs.js - browser.startup.homepage_override.buildID, 20110413222027 Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1 Prefs.js - keyword.URL, hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&instlRef=ss... ======================================== **** Google Chrome Version [11.0.696.60] **** Extension\dhkplhfnhceodhffomolpfigojocbpcb (C:\Arquivos de programas\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbar.crx) (x) -- C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default -- Preferences - default_search_provider: "Oryte Games Brazil Customized Web Search" (Enabled: true) (hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2444516&SearchSource=3&q={searchTerms}) Preferences - homepage: hxxp://www.google.com.br/ Preferences - homepage_is_newtabpage: false Plugin - Flatcast Viewer Plugin 5.0.225 (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\NpFv501.dll) Plugin - Office Genuine Advantage (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll) Plugin - Microsoft DRM (Enabled: true) (C:\Arquivos de programas\Windows Media Player\npdrmv2.dll) Plugin - Microsoft DRM (Enabled: true) (C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll) Plugin - Unity Player (Enabled: true) (C:\Documents and Settings\Luizinho\Configuraes locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll) (x) Plugin - "Flatcast Viewer Plugin 5.0.225" (Enabled: true) Plugin - "DivX Player" (Enabled: true) Plugin - "DivX Player Netscape Plugin" (Enabled: true) Plugin - "Office Genuine Advantage" (Enabled: true) Plugin - "Unity Player" (Enabled: true) Plugin - "Microsoft DRM" (Enabled: true) Plugin - "GanymedeNet.Detector" (Enabled: true) Plugin - "Winamp Application Detector" (Enabled: true) ======================================== **** Internet Explorer Version [8.0.6001.18702] **** HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896 HKCU_Main|Start Page - hxxp://fr.msn.com/ HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Start Page - hxxp://fr.msn.com/ HKCU_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll) HKCU_URLSearchHooks|{f999a48b-1950-4d81-9971-79018f807b4b} - "FreeOnlineRadioPlayerRecorder Toolbar" (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll) HKLM_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll) HKLM_URLSearchHooks|{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} (x) HKCU_SearchScopes\{41A30F3E-E976-40CC-B5E5-1BBFFDA94D9A} - "Search" (hxxp://www.tangosearch.com/?q={searchTerms}&a=SEARCH) HKCU_SearchScopes\{B576BAFD-FED1-4474-A7D6-CB89D2E13B5D} - "SpeedBit Search" (hxxp://search.speedbit.com/searchresults.asp?src=default&q={searchTerms}) HKLM_SearchScopes\{41A30F3E-E976-40CC-B5E5-1BBFFDA94D9A} - "Search" (hxxp://www.tangosearch.com/?q={searchTerms}&a=SEARCH) HKCU_Toolbar\WebBrowser|{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll) HKCU_Toolbar\WebBrowser|{F999A48B-1950-4D81-9971-79018F807B4B} (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll) HKCU_Toolbar\WebBrowser|{9C398D3E-95C3-49AB-A00E-3C4089ECD048} (C:\WINDOWS\system32\e178.dll) (x) HKLM_Toolbar|{0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll) HKLM_Toolbar|{f999a48b-1950-4d81-9971-79018f807b4b} (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll) HKCU_ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953} - C:\Arquivos de programas\SpeedBit Video Downloader\Converter.exe (x) HKLM_ElevationPolicy\11f8c830-530a-4313-886a-2b0b4415c22a - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper.exe (?) HKLM_ElevationPolicy\75645006-7c35-42d5-8fe8-608475805c58 - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper.exe (?) HKLM_ElevationPolicy\{1ACB6FDD-83AF-424C-8164-23197A94AC36} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper1.exe (?) HKLM_ElevationPolicy\{1F949079-DC18-40B2-A3D4-45545FA02DE0} - C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Conduit\CT2737658\FreeOnlineRadioPlayerRecorderAutoUpdaterHelper.exe (x) HKLM_ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953} - C:\Arquivos de programas\SpeedBit Video Downloader\Converter.exe (x) HKLM_ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} - C:\Arquivos de programas\IMinent Toolbar\TbHelper2.exe (x) HKLM_ElevationPolicy\{ADADAEE2-457A-4984-A57C-E01C3A2BA612} - c:\arquivos de programas\shoutcast radio toolbar\SHOUTcastTbServer.exe (AOL LLC) HKLM_ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} - C:\Arquivos de programas\Iminent\MMServer\Iminent.MMServer.exe (x) HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?) BHO\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - "Adobe PDF Reader Link Helper" (C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll) BHO\{21A88CB9-84D2-4020-A2D1-B25A21034884} - "HistoryTriggerBHO Class" (C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll) BHO\{9030D464-4C02-4ABF-8ECC-5164760863C6} - "Auxiliar de Conexão do Windows Live" (C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll) BHO\{C41A1C0E-EA6C-11D4-B1B8-444553540000} - "GbIehObj Class" (C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll) BHO\{ccec60fc-2608-4e58-9659-3ffc159e8ea9} - "SHOUTcast Loader" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll) BHO\{f999a48b-1950-4d81-9971-79018f807b4b} - "FreeOnlineRadioPlayerRecorder Toolbar" (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll) ======================================== C:\Arquivos de programas\Ad-Remover\Quarantine: 88 File(s) C:\Arquivos de programas\Ad-Remover\Backup: 14 File(s) C:\Ad-Report-CLEAN[1].txt - 08/05/2011 20:51:27 (10120 Byte(s)) End at: 20:52:41, 08/05/2011 ============== E.O.F ============== Malwarebytes Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Versão da Base de Dados: 6534 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 8/5/2011 22:28:33 mbam-log-2011-05-08 (22-28-32).txt Tipo de Verificação: Verificação Completa (C:\|) Objetos escaneados: 221623 Tempo decorrido: 1 hora(s), 14 minuto(s), 44 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 1 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 1 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully. Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: c:\arquivos de programas\questbrowser\uninstall.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully. hijackthis Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 22:34:17, on 8/5/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe C:\WINDOWS\system32\sistray.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll (file missing) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: QuestBrowser Service - Unknown owner - C:\Documents and Settings\All Users\Dados de aplicativos\QuestBrowser\questbrowser117.exe (file missing) O23 - Service: STSService - Unknown owner - C:\Arquivos de programas\SoundTaxi Media Suite\STSService.exe (file missing) -- End of file - 11952 bytes O problema desapareceu, reiniciei o pc mais de 3x e não apareceu mais o erro. Obrigado pela ajuda! Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 9, 2011 :) Vários problemas foram removidos pelo Ad-Remover e Malwarebytes. ___________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked: O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll (file missing) ___________________ :seta: No seu log está constando que seu PC está sem antivirus. Sugiro que você instale o antivirus de sua preferência, atualize ele (faça um update), depois disto faça um escaneamento completo do computador com seu antivírus e à medida em que forem sendo achados vírus e programas espiões escolha a opção de desinfectar estes arquivos contaminados ou vá enviando eles para a quarentena. E no caso dos arquivos terem sido enviados para a quarentena, depois de algumas semanas, se o seu computador estiver funcionando normalmente sem estes arquivos que foram para a quarentena, você pode ir na quarentena e excluí-los definitivamente. ___________________ :seta: Há muitas toolbars (barras de ferramentas) desnecessárias e que acabam deixando a navegação mais lenta e podem causar travamentos e algumas ainda podem ficar monitorando seus hábitos de navegação. Sugiro que desinstale-as (como a SHOUTcast Toolbar, FreeOnlineRadioPlayerRecorder Toolbar e Winamp Toolbar. ___________________ :seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho): http://swandog46.geekstogo.com/avenger2/download.php *Selecione e copie (Ctrl+C) todo o texto destacado em vermelho abaixo: Drivers to disable: QuestBrowser Service STSService Drivers to delete: QuestBrowser Service STSService *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *O relatório será criado em C:\avenger.txt ______________________ :seta: Siga, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis, o log do Avenger que estará em C:\avenger.txt e nos diga, por gentileza, se algum virus foi removido pelo seu antivirus que você instalar e como está o seu PC após seguir estes procedimentos. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 11, 2011 Obrigado pela ajuda, vou poder fazer isso somente no sábado, não tenho tempo de semana... Se puder aguardar até sábado eu agradeço! Até mais. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 11, 2011 Obrigado pela ajuda, vou poder fazer isso somente no sábado, não tenho tempo de semana... Se puder aguardar até sábado eu agradeço! Até mais. :thumbsup: Tranquilo, ficamos na espera. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 14, 2011 Boa Noite, Segue o log do Nod32 Online: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=5ca7444cd5dd0e46a392d6cf01e05c80 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-05-14 02:13:14 # local_time=2011-05-13 11:13:14 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 47282394 47282394 0 0 # compatibility_mode=1797 16775125 100 93 0 38087324 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=105140 # found=12 # cleaned=0 # scan_time=5712 C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\Cheat Engine\dbk32.dll a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\Cheat Engine\dbk32.sys a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe a variant of Win32/HackTool.SystemCall.AA application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe a variant of Win32/HackTool.SystemCall.AA application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\DSE\AKV.exe a variant of Win32/KeyLogger.Ardamax.NAX application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\DSE\DSE.001 probably a variant of Win32/KeyLogger.Ardamax.NAY application (unable to clean) 00000000000000000000000000000000 I C:\Arquivos de programas\NEL\NEL.002 a variant of Win32/KeyLogger.Ardamax application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll probably a variant of Win32/TrojanDropper.Agent.HJOVFDD trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll probably a variant of Win32/TrojanDropper.Agent.HJOVFDD trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini probably unknown SCRIPT virus (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe probably a variant of Win32/Spy.Agent.KUUKBEW trojan (unable to clean) 00000000000000000000000000000000 I log do Hijackthis: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:16:47, on 13/5/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe C:\WINDOWS\system32\sistray.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\System32\alg.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\System32\dllhost.exe C:\WINDOWS\System32\msdtc.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Arquivos de programas\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 11635 bytes log do Avenger; Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Driver "QuestBrowser Service" disabled successfully. Driver "STSService" disabled successfully. Driver "QuestBrowser Service" deleted successfully. Driver "STSService" deleted successfully. Completed script processing. ******************* Finished! Terminate. Bom, eu instalei o Avira, ele moveu 25 arquivos para a quarentena. Não excluiu nenhum. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 14, 2011 :seta: Exclua o log do Avenger que está em C:\avenger.txt *Selecione e copie (Ctrl+C) todo o texto destacado em vermelho abaixo: Files to delete: C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe C:\Arquivos de programas\Cheat Engine\dbk32.dll C:\Arquivos de programas\Cheat Engine\dbk32.sys C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe C:\Arquivos de programas\DSE\AKV.exe C:\Arquivos de programas\DSE\DSE.001 C:\Arquivos de programas\NEL\NEL.002 C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *O relatório será criado em C:\avenger.txt ___________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing) O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ______________________ :seta: 1. Baixe o ERUNT e salve-o no desktop *Crie uma pasta em C:\ chamada ERUNT e extraia para ela *Execute o arquivo C:\ERUNT\ERUNT.exe *Clique [OK] > [OK] > [sim] > [OK] 2. Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download do ComboFix Salve-o no Desktop (área de trabalho). * Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! ) * Feche todas as janelas e execute a ferramenta. * Ps: A execução, por comando, também é possível: * Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall * Clique em Ok. * Na solicitação: "Negação de garantia de software" --> Clique em Sim. * Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo. * Terminando,clique Sim ou Yes. --> Aguarde. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX :!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download. * Salve-a no Desktop,renomeada como: Kombo.exe * Ps: Nomeie durante o salvamento,e não após salvá-la! * Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link! * Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação: * Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos. * Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! * Ps: Para evitar problemas, siga todas as recomendações propostas. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX * Abrir-se-á a janela Auto Scan. --> Aguarde! * Para finalizar remoções, o ComboFix poderá reiniciar o computador. * Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! * Durante o scan, evite manusear o mouse ou teclado! <-- Importante! * Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter. <><><><><><><><><><><><> Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis e o novo log do Avenger que estará em C:\avenger.txt em sua próxima resposta e nos diga como está o seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 15, 2011 Log do ComboFix: ComboFix 11-05-14.01 - Luizinho 14/05/2011 22:45:08.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.3055.2573 [GMT -3:00] Executando de: c:\documents and settings\Luizinho\desktop\Combofix.exe Comandos utilizados :: /killall AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} * Criado um novo ponto de restauração . ADS - system32: deleted 2 bytes in 1 streams. ADS - drivers: deleted 204 bytes in 1 streams. ADS - WINDOWS: deleted 0 bytes in 1 streams. . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6} c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\chrome.manifest c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\chrome\questbrowser.jar c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\defaults\preferences\prefs.js c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\install.rdf c:\arquivos de programas\QuestBrowser c:\brasfoot2009\Brasfoot2009.exe c:\brasfoot2010\Brasfoot2010.exe C:\cleanup.exe c:\documents and settings\All Users\Dados de aplicativos\QuestBrowser c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Help.lnk c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Log Viewer.lnk c:\documents and settings\Luizinho\Recent\Thumbs.db c:\documents and settings\Luizinho\WINDOWS c:\windows\system32\Thumbs.db c:\windows\XSxS C:\zip.exe . . (((((((((((((((( Arquivos/Ficheiros criados de 2011-04-15 to 2011-05-15 )))))))))))))))))))))))))))) . . 2011-05-15 01:33 . 2011-05-15 01:36 -------- d-----w- C:\ERUNT 2011-05-14 00:20 . 2011-05-14 00:20 -------- d-----w- c:\arquivos de programas\ESET 2011-05-14 00:09 . 2011-05-14 00:09 7144 ----a-w- C:\backup.reg 2011-05-14 00:09 . 2011-05-15 01:24 574 ----a-w- C:\cleanup.bat 2011-05-09 01:59 . 2011-05-14 01:49 -------- d-----w- c:\windows\system32\NtmsData 2011-05-09 01:49 . 2011-05-09 01:49 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\Avira 2011-05-09 01:44 . 2011-05-13 07:40 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-05-09 01:44 . 2011-02-04 15:11 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-05-09 01:44 . 2010-06-17 17:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2011-05-09 01:44 . 2010-06-17 17:29 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2011-05-09 01:44 . 2011-05-09 01:44 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira 2011-05-09 01:44 . 2011-05-09 01:44 -------- d-----w- c:\arquivos de programas\Avira 2011-05-08 23:50 . 2011-05-08 23:50 -------- d-----w- c:\arquivos de programas\Ad-Remover 2011-05-08 20:53 . 2011-05-08 20:53 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\Electronic Arts 2011-05-08 00:18 . 2011-05-08 00:33 -------- d-----w- c:\arquivos de programas\eMule 2011-05-01 15:52 . 2011-04-14 16:59 142296 ----a-w- c:\arquivos de programas\Mozilla Firefox\components\browsercomps.dll 2011-05-01 15:52 . 2011-04-14 16:59 781272 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozsqlite3.dll 2011-05-01 15:52 . 2011-04-14 16:59 1874904 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozjs.dll 2011-05-01 15:52 . 2011-04-14 16:59 89048 ----a-w- c:\arquivos de programas\Mozilla Firefox\libEGL.dll 2011-05-01 15:52 . 2011-04-14 16:59 465880 ----a-w- c:\arquivos de programas\Mozilla Firefox\libGLESv2.dll 2011-05-01 15:52 . 2011-04-14 16:59 15832 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozalloc.dll 2011-05-01 15:52 . 2010-01-01 08:00 1974616 ----a-w- c:\arquivos de programas\Mozilla Firefox\D3DCompiler_42.dll 2011-05-01 15:52 . 2010-01-01 08:00 1892184 ----a-w- c:\arquivos de programas\Mozilla Firefox\d3dx9_42.dll 2011-04-17 17:46 . 2011-04-17 17:46 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\BabylonToolbar 2011-04-16 19:43 . 2011-04-16 19:43 -------- d-----w- c:\arquivos de programas\Yuna Software . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-20 14:14 . 2010-08-28 04:21 46600 ----a-w- c:\windows\system32\drivers\gbpkm.sys 2011-03-07 05:33 . 2009-11-01 18:38 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:36 . 2002-09-09 17:08 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:53 . 2002-09-09 16:44 1858048 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:08 . 2002-09-09 17:08 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:08 . 2002-09-09 17:08 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 23:08 . 2002-09-09 17:07 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-02-22 11:43 . 2009-11-01 21:41 385024 ----a-w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2002-08-29 04:59 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2001-10-28 18:07 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2001-10-28 18:06 290432 ----a-w- c:\windows\system32\atmfd.dll 2011-02-14 05:42 . 2011-04-08 01:00 20864 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys 2011-02-14 05:42 . 2011-04-08 01:00 25216 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys 2011-02-14 05:42 . 2011-04-08 01:00 13056 ----a-w- c:\windows\system32\drivers\lgusbbus.sys 2009-08-28 21:42 . 2009-08-28 21:42 1044480 ----a-w- c:\arquivos de programas\mozilla firefox\plugins\libdivx.dll 2009-08-28 21:42 . 2009-08-28 21:42 200704 ----a-w- c:\arquivos de programas\mozilla firefox\plugins\ssldivx.dll 2011-04-14 16:59 . 2011-05-01 15:52 142296 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SiSPower"="SiSPower.dll" [2009-02-12 53248] "RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864] "SMSERIAL"="c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-21 630784] "SynTPStart"="c:\arquivos de programas\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368] "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2010-11-29 421888] "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-10-29 249064] "AdobeAAMUpdater-1.0"="c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-26 500208] "AdobeCS5ServiceManager"="c:\arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432] "avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2011-02-04 281768] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360] . c:\documents and settings\Luizinho\Menu Iniciar\Programas\Inicializar\ Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-11-7 110592] Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-11-1 262144] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2011-04-20 14:11 505736 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1080:TCP"= 1080:TCP:messenger "4660:TCP"= 4660:TCP:eMule - Porta TCP "4670:TCP"= 4670:TCP:eMule - Porta UDP . R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [28/8/2010 01:21 46600] R2 AntiVirSchedulerService;Avira AntiVir Agendamento;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [8/5/2011 22:44 136360] R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [28/8/2010 01:21 56712] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [1/11/2009 15:51 113504] R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/9/2009 08:11 12160] R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/9/2009 08:11 10496] R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/9/2009 08:11 12928] R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [1/11/2009 16:50 340096] S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [24/4/2010 16:29 136176] S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [7/4/2011 22:00 14336] S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [7/4/2011 22:00 20736] S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [7/4/2011 22:00 20096] S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [7/4/2011 22:00 25088] S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUSB.sys [21/8/2010 14:40 16896] S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [24/4/2010 16:29 136176] S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] . Conteúdo da pasta 'Tarefas Agendadas' . 2011-04-13 c:\windows\Tasks\AdobeAAMUpdater-1.0-CASA-72A2ETXOUB-Luizinho.job - c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-26 21:52] . 2009-12-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 14:34] . 2011-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-04-24 19:29] . 2011-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-04-24 19:29] . . ------- Scan Suplementar ------- . uInternet Settings,ProxyServer = socks= uInternet Settings,ProxyOverride = local IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Free YouTube Download - c:\documents and settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm IE: Free YouTube to Mp3 Converter - c:\documents and settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm IE: LG Air Sync (R-Click) - Save as Mobile Image - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 IE: LG Air Sync (R-Click) - Save as Mobile Memo - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 IE: LG Air Sync (R-Click) - Save as Mobile Text file - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 IE: LG Air Sync (R-Click) - Set as Mobile Wallpaper - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 IE: LG Air Sync Option - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 Trusted Zone: bancobrasil.com.br\www Trusted Zone: bancobrasil.com.br\www14 Trusted Zone: bancobrasil.com.br\www2 Trusted Zone: bb.com.br\www DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Luizinho\Dados de aplicativos\Mozilla\Firefox\Profiles\dzuv881t.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/ FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&instlRef=sst&affID=17159&q= FF - prefs.js: network.proxy.gopher - FF - prefs.js: network.proxy.gopher_port - 0 FF - prefs.js: network.proxy.type - 0 FF - user.js: network.proxy.type - 0 FF - user.js: network.proxy.http - FF - user.js: network.proxy.http_port - 0 FF - user.js: network.proxy.ssl - FF - user.js: network.proxy.ssl_port - 0 FF - user.js: network.proxy.ftp - FF - user.js: network.proxy.ftp_port - 0 FF - user.js: network.proxy.gopher - FF - user.js: network.proxy.gopher_port - 0 FF - user.js: network.proxy.socks_version - 5 FF - user.js: network.proxy.socks - FF - user.js: network.proxy.socks_port - 0 . - - - - ORFÃOS REMOVIDOS - - - - . WebBrowser-{F999A48B-1950-4D81-9971-79018F807B4B} - (no file) WebBrowser-{9C398D3E-95C3-49AB-A00E-3C4089ECD048} - c:\windows\system32\e178.dll AddRemove-FreeOnlineRadioPlayerRecorder Toolbar - c:\arquivos de programas\FreeOnlineRadioPlayerRecorder\uninstall.exe AddRemove-GabPath - c:\documents and settings\Luizinho\Dados de aplicativos\GabPath\GPUninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-05-14 22:54 Windows 5.1.2600 Service Pack 3 NTFS . Procurando processos ocultos ... . Procurando entradas auto inicializáveis ocultas ... . Procurando ficheiros/arquivos ocultos ... . Varredura completada com sucesso arquivos/ficheiros ocultos: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- . - - - - - - - > 'winlogon.exe'(720) c:\arquivos de programas\GBPLUGIN\gbieh.dll . - - - - - - - > 'explorer.exe'(4064) c:\windows\system32\WININET.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\arquivos de programas\GBPLUGIN\gbieh.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\CDBurnerXP\NMSAccessU.exe c:\arquivos de programas\Avira\AntiVir Desktop\avshadow.exe c:\windows\System32\wbem\wmiapsrv.exe c:\windows\RTHDCPL.EXE c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe c:\arquivos de programas\Synaptics\SynTP\SynTPEnh.exe c:\arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe c:\arquivos de programas\Windows Live\Contacts\wlcomm.exe . ************************************************************************** . Tempo para conclusão: 2011-05-14 23:02:39 - Máquina reiniciou ComboFix-quarantined-files.txt 2011-05-15 02:02 ComboFix2.txt 2010-05-31 00:29 . Pré-execução: 19 pasta(s) 241.647.796.224 bytes disponíveis Pós execução: 20 pasta(s) 242.674.200.576 bytes disponíveis . - - End Of File - - A94036290ADFA4206BF56E584051B205 log do Hijackthis: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:11:00, on 14/5/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\sistray.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 10166 bytes log do Avenger: Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe" deleted successfully. File "C:\Arquivos de programas\Cheat Engine\dbk32.dll" deleted successfully. File "C:\Arquivos de programas\Cheat Engine\dbk32.sys" deleted successfully. File "C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe" deleted successfully. File "C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe" deleted successfully. File "C:\Arquivos de programas\DSE\AKV.exe" deleted successfully. File "C:\Arquivos de programas\DSE\DSE.001" deleted successfully. File "C:\Arquivos de programas\NEL\NEL.002" deleted successfully. File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll" deleted successfully. File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll" deleted successfully. File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini" deleted successfully. File "C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe" deleted successfully. Completed script processing. ******************* Finished! Terminate. Sinto que meu PC está um pouco mais rápido. Não tive problemas até agora. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 15, 2011 :) Muitos outros problemas foram removidos. _________________ :seta: Siga também esta dica: Tutorial do Norman Malware Cleaner Na sua próxima resposta poste o conteúdo do log do Norman Malware Cleaner juntamente com um novo log do Hijackthis e nos diga como está o seu PC depois disto. Ficamos na espera. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 15, 2011 log do Norman Malware: Norman Malware Cleaner v2.00.05 Copyright © 1990 - 2011, Norman ASA. Norman Scanner Engine Version: 6.07.07 nvcbin.def: Version: 6.07.00, Date: 2011/05/14 22:23:07, Variants: 11989707 nvcmacro.def: Version: 6.07.00, Date: 2011/02/01 12:21:31, Variants: 20465 Operating System: Windows XP Service Pack 3 Switches: /iagree Running without NSAK Scan started: 2011/05/15 15:47:29 Running pre-scan cleanup routine... Modified registry value: HKCR\.com --> (null) from 'ComFile' to 'comfile' Modified registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows --> AppInit_DLLs from '(null)' to '' Deleted registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System --> DisableRegistryTools = 0x00000000 Deleted registry value: HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer --> NoDrives = 0x00000000 Deleted registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer --> NoDrives = 0x00000000 Scanning time: 1s Scanning system for active rootkit activity... Scanning time: 0s Scanning running processes and process memory... Number of objects found: 462 Number of objects scanned: 462 Number of objects not scanned: 0 Number of malicious memory objects found: 0 Scanning time: 29s Running custom scan... C:\Arquivos de programas\Gravity\Ragnarok Online\directx10.dll: File infected with W32/Obfuscated.T Deleted file: C:\Arquivos de programas\Gravity\Ragnarok Online\directx10.dll C:\Arquivos de programas\Gravity\Ragnarok Online\GameGuard\GameMon.des: File infected with Packed_TheMida.B Deleted file: C:\Arquivos de programas\Gravity\Ragnarok Online\GameGuard\GameMon.des C:\Arquivos de programas\WinRAR\Default.SFX: File infected with W32/Smalltroj.YWRV Deleted file: C:\Arquivos de programas\WinRAR\Default.SFX C:\Documents and Settings\Luizinho\NTUSER.DAT: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\ntuser.dat.LOG: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Configurações locais\Temporary Internet Files\Content.Word\~WRS{90399EED-CF76-4242-92B3-B6ED1C9C9AF9}.tmp: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Configurações locais\Temporary Internet Files\Content.Word\~WRS{AC2A3A7C-B8C8-48B9-9C7A-1DEAE78D57AC}.tmp: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Dados de aplicativos\Microsoft\Modelos\Normal.dotm: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0/Main.class C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf: Archive infected C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf/Main.class: File infected with JAVA/DLoader.B Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf/Main.class C:\Documents and Settings\Luizinho\Desktop\Faça o download do Norman Malware Cleaner e renomeie.docx: Error opening file for read: 0x00000020 C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip/wiSdOmBOTv43.exe Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip/wiSdOmBOTv43.exe Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\CyberScript.exe: File infected with W32/Suspicious_Gen2.CSAJZ Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\CyberScript.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\wiSdOmBOTv43.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe: File infected with W32/Suspicious_Gen2.AGKME Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe: File infected with W32/Suspicious_Gen2.AGKME Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/CyberScript.exe: File infected with W32/Suspicious_Gen2.CSAJZ Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/CyberScript.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/sistema/dlls/nHTMLn.dll: File infected with W32/Suspicious_Gen2.IYCS Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/sistema/dlls/nHTMLn.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/wiSdOmBOTv43.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar/FutNew3\mirc.exe: File infected with Suspicious_Gen2.VMSE Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar/FutNew3\mirc.exe C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\mooold.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip: Archive infected C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/moo.dll: File infected with W32/Suspicious_Gen2.JOHX Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/moo.dll C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/mooold.dll: File infected with W32/Smalltroj.CXEP Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/mooold.dll C:\Documents and Settings\NetworkService\NTUSER.DAT: Error opening file for read: 0x00000020 C:\Documents and Settings\NetworkService\ntuser.dat.LOG: Error opening file for read: 0x00000020 C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020 C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020 C:\GMouse20\Gmouse.exe: File infected with W32/Suspicious_Gen2.CRFM Deleted file: C:\GMouse20\Gmouse.exe C:\Qoobox\Quarantine\C\cleanup.exe.vir: File infected with W32/Zapchast.CTP Deleted file: C:\Qoobox\Quarantine\C\cleanup.exe.vir C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk.vir: File infected with LNK/Keylogger.B Deleted file: C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk.vir C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002654.exe: File infected with W32/Zapchast.CTP Deleted file: C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002654.exe C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002655.lnk: File infected with LNK/Keylogger.B Deleted file: C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002655.lnk C:\WINDOWS\Installer\10e838.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\16bcf7.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\1ddd97.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\1e5f50f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\1e5f51b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\203cd9.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\203cc3.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\20c4f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\20c65.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\2251b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\245ae.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\251e8.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d25.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d3b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d52.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d68.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d80.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25d98.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25db0.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25dc7.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\25de2.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\26198.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\26cdd.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\26cf3.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\26d0f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\26d25.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\286de.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\286f4.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\2870a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\30c0a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\31962b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\319642.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\319658.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\31966e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\319684.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\33133.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34ead.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34eb5.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34ec8.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34ed2.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34f06.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\34f0c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\35eb79.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\3d374c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\42244.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4225a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\42270.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\428a32.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\45518f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4551a5.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4551bb.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4768d9.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\49980.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4a5a8.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4dd80.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4f5ba.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\4fc52.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\5583e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\56aeb.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\56b01.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\5753da.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\5753ef.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\575406.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\575432.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\57541c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\599b0b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\599b8a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\64aad9.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\662e17.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\662e01.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\662e36.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69c25b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\662e37.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69c27b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e363.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e364.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e365.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e366.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e367.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e368.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e369.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e36a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\69e36b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b391.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b39b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b3a4.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b3ab.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b3b5.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6b3c4.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba966.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba967.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba968.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba969.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96b.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96d.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6ba96f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f00.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f01.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f02.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f03.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f04.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f14.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f15.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f17.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f16.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f18.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f19.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f1a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f2e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f38.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6d5f43.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\6f4129.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\79071f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\790726.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7ace8e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7ace99.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7aceb0.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acebb.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acebc.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7aceca.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acee0.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acef6.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf0c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf27.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf28.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf3f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf64.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7acf4e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7f385f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\7f386a.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\84116.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\8b48e.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\aad186.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\aad19c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7b56.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7b6c.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7b82.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7baa.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7bc5.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7bda.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7bf2.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c09.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c1f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c39.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c4f.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c67.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c7d.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7c93.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\ad7ca9.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\c53fbe.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\d0322.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\d0338.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\d0352.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\d800c9.msp: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\APEX.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\APEX.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ASPECT.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ASPECT.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CIVIC.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CIVIC.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONCOURSE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONCOURSE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EQUITY.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EQUITY.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FLOW.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FLOW.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FOUNDRY.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FOUNDRY.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDIAN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDIAN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\METRO.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\METRO.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MODULE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MODULE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OPULENT.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OPULENT.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIEL.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIEL.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIGIN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIGIN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PAPER.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PAPER.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOLSTICE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOLSTICE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TECHNIC.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TECHNIC.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TREK.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TREK.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\URBAN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\URBAN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VERVE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VERVE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\APEX.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\APEX.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ASPECT.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ASPECT.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CIVIC.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CIVIC.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CONCOURSE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\EQUITY.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\EQUITY.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FLOW.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FLOW.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FOUNDRY.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MEDIAN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MEDIAN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\METRO.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\METRO.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MODULE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MODULE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\OPULENT.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\OPULENT.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIEL.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIGIN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIGIN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\PAPER.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\PAPER.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\SOLSTICE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\SOLSTICE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TECHNIC.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TECHNIC.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TREK.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TREK.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\URBAN.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\URBAN.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\VERVE.EFTX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\VERVE.THMX: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK01.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK03.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK04.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK05.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK06.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK07.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK10.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK11.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\ONGUIDE.ONEPKG_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109E60061400000000000F01FEC\12.0.4518\XLATE_COMPLETE.XSN_1046: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D\3.5.30729\Chrome_jar.3643236F_FC70_11D3_A536_0090278A1BB8: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\{26A24AE4-039D-4CA4-87B4-2F83216017FF}\sp1033.MST: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\1046.MST: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\ShellUI.MST: Error opening file for read: 0x00000005 C:\WINDOWS\Installer\{90120000-0051-0000-0000-0000000FF1CE}\ShellUI.MST: Error opening file for read: 0x00000005 C:\WINDOWS\system32\config\default: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\default.LOG: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\SAM: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\SAM.LOG: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\SECURITY: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\SECURITY.LOG: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\software: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\software.LOG: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\system: Error opening file for read: 0x00000020 C:\WINDOWS\system32\config\system.LOG: Error opening file for read: 0x00000020 Number of files found: 91473 Number of archives unpacked: 4943 Number of objects found: 329080 Number of objects scanned: 328820 Number of objects not scanned: 273 Number of malicious objects found: 41 Number of malicious objects cleaned: 41 Number of malicious files found: 25 Number of malicious files cleaned: 25 Scanning time: 2h 18m 29s Running post-scan cleanup routine... Modified registry value: HKCR\.com --> (null) from 'ComFile' to 'comfile' Scanning time: 0s Results: Total number of files found: 91473 Total number of archives unpacked: 4943 Total number of objects found: 329542 Total number of objects scanned: 329282 Total number of objects not scanned: 273 Total number of malicious objects found: 47 Total number of malicious objects cleaned: 47 Total number of malicious files found: 25 Total number of malicious files cleaned: 25 Total scanning time: 2h 18m 59s log do Hijackthis: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:10:04, on 15/5/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\sistray.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208 O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210 O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205 O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 10423 bytes Meu pc está normal, não deu erro ainda. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 15, 2011 :) 25 problemas foram removidos pelo Norman. _____________________ :seta: Siga também esta dica: Tutorial do SUPERAntispyware (instalação e utilização) ____________________ :seta: Na sua próxima resposta poste o log do SuperAntispyware, nos diga se os problemas encontrados por ele foram removidos e nos diga como está seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Luizfc_ 0 Denunciar post Postado Maio 16, 2011 Segue log do SuperAntispyware: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 05/15/2011 at 09:42 PM Application Version : 4.52.1000 Core Rules Database Version : 7062 Trace Rules Database Version: 4874 Scan type : Complete Scan Total Scan Time : 01:19:39 Memory items scanned : 566 Memory threats detected : 0 Registry items scanned : 7636 Registry threats detected : 10 File items scanned : 92850 File threats detected : 82 Browser Hijacker.Internet Explorer Zone Hijack HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www#* HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www14 HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www14#* HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www2 HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www2#* HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br\www HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br\www#* Adware.Tracking Cookie C:\Documents and Settings\Luizinho\Cookies\luizinho@eaeacom.112.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@myroitracking[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@doubleclick[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@content.yieldmanager[3].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@ad.yieldmanager[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@msnportal.112.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@atdmt.combing[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@cofidis2.solution.weborama[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@bs.serving-sys[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@media-player-classic.softonic.com[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@terra.112.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@boursoramabanque.solution.weborama[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@smileycentral[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@portalclaro.ad.adnetwork.com[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@eset.122.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@apmebf[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@atdmt[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@microsoftwllivemkt.112.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@cms.trafficmp[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@smartadserver[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@mediaplex[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@vivo.ad.adnetwork.com[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@advertising[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@azjmp[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@avgtechnologies.112.2o7[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@content.yieldmanager[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[3].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@weborama[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@ads.lzjl[1].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[5].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@serving-sys[3].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@fastclick[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@clicksor[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@247realmedia[2].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[6].txt C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[4].txt bc.you---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] cdn-www.---hub.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] cdn4.specificclick.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] content3.---kolt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] ec.atdmt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] findel.scene7.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] ia.media-imdb.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] images.indieclick.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] latam-media.disneyinternational.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.buto.tv [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.ign.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.movieweb.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.mtvnservices.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.mtvu.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.scanscout.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media.shufuni.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media01.kyte.tv [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media1.break.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media1.shopto.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] media1.shufuni.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] naiadsystems.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] objects.tremormedia.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] ---otube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] rmd.atdmt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] s0.2mdn.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] secure-us.imrworldwide.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] static.cineclick.uol.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] swf.portal---o.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] vhss-a.oddcast.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] vhss-d.oddcast.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] vidii.hardsextube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.adult-im.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.hornypharaoh.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.mestredosexo.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.naiadsystems.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.----star.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.---hub.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.---obis.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.---otube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.---tube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.sexopop.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.sextvx.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.twelvefifteen.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] www.user---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] wwwstatic.mega---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ] 92 Arquivos foram para quarentena e excluidos. Meu PC está um pouco mais rápido, por enquanto sem erros. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Maio 16, 2011 92 Arquivos foram para quarentena e excluidos. Meu PC está um pouco mais rápido, por enquanto sem erros. :seta: Siga, por gentileza, esta dica: Tutorial do Ad-Aware Free Internet Security 9 (Instalação e utilização) Depois disto poste o log do Ad-Aware junto com novo log do Hijackthis e nos diga como está o PC depois disto. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 15, 2011 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites