Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

juniorzin

[Resolvido] &nbspProblema com Anti-Virus

Recommended Posts

Boa tarde , estou com um problema no meu pc , que ele simplismente não executa os anti - virus , creio eu que seja malware , ja vi problemas semelhantes ao meu que era virus ,

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 13:27:32, on 17/8/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.17080)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

C:\Documents and Settings\Administrador\system.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\Documents and Settings\Administrador\Meus documentos\Downloads\SoftonicDownloader_para_hijackthis.exe

C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.minilua.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.minilua.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.minilua.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.minilua.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.minilua.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.minilua.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.minilua.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.minilua.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.minilua.com/q/%s

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ww4.freeurlset.com:8083/connect.dat

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {D1763781-8374-40BD-836A-F2E1F2600B2F}836A-F2E1F2600B2F} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [MSC] "c:\Arquivos de programas\Microsoft Security Client\msseces.exe" -hide -runkey

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Policies\Explorer\Run: [internet] "C:\Documents and Settings\Administrador\system.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{43116D85-F7AE-4142-A8E1-38C709F5A91C}: NameServer = 200.204.0.10 200.204.0.138

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Arquivos de programas\Arquivos comuns\Adobe\SwitchBoard\SwitchBoard.exe

 

--

End of file - 9772 bytes

 

 

Grato

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá juniorzin

 

*Baixe o MalwareBytes e salve-o no desktop

*Instale o programa e aguarde a atualização

*O programa será aberto automaticamente

*Na aba [Verificação], selecione [Verificação completa]

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

oii descupa , postei e fui pra academia terminei agr de fazer ^^ segue ai o log

 

 

Malwarebytes' Anti-Malware 1.51.1.1800

www.malwarebytes.org

 

Versão da Base de Dados: 7491

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 7.0.5730.13

 

17/8/2011 18:00:10

mbam-log-2011-08-17 (18-00-10).txt

 

Tipo de Verificação: Verificação Completa (C:\|)

Objetos escaneados: 225854

Tempo decorrido: 29 minuto(s), 55 segundo(s)

 

Processos de Memória Infectados: 1

Módulos de Memória Infectados: 2

Chaves de Registro Infectadas: 5

Valores de Registro Infectados: 2

Itens de Dados no Registro Infectados: 4

Pastas Infectadas: 1

Arquivos Infectados: 44

 

Processos de Memória Infectados:

c:\documents and settings\administrador\system.exe (Trojan.Agent) -> 1948 -> Unloaded process successfully.

 

Módulos de Memória Infectados:

c:\WINDOWS\ksef1541.dll (Trojan.BHO) -> Delete on reboot.

c:\documents and settings\administrador\engine.dll (Trojan.Agent) -> Delete on reboot.

 

Chaves de Registro Infectadas:

HKEY_CLASSES_ROOT\CLSID\{D1763781-8374-40BD-836A-F2E1F2600B2F} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{C5C53AD7-957B-40C0-9886-B3CA26A51BD1} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{46AF773E-50A3-4347-A6EC-BEEA0CF115CD} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Center.CenterPlus (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1763781-8374-40BD-836A-F2E1F2600B2F} (Trojan.BHO) -> Quarantined and deleted successfully.

 

Valores de Registro Infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Internet (Trojan.Agent) -> Value: Internet -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Value: ForceClassicControlPanel -> Quarantined and deleted successfully.

 

Itens de Dados no Registro Infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

 

Pastas Infectadas:

c:\WINDOWS\winarquivos (Trojan.Banker) -> Quarantined and deleted successfully.

 

Arquivos Infectados:

c:\WINDOWS\ksef1541.dll (Trojan.BHO) -> Delete on reboot.

c:\documents and settings\administrador\system.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\documents and settings\administrador\engine.dll (Trojan.Agent) -> Quarantined and deleted successfully.

c:\documents and settings\administrador\configurações locais\Temp\Rar$EX00.406\diablo2_kg.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

c:\documents and settings\administrador\configurações locais\Temp\Rar$EX06.188\keygen ps cs5.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.

c:\WINDOWS\system32\ebyhed.dll (Worm.Downadup) -> Delete on reboot.

c:\WINDOWS\system32\igfxrenuz.dll (Heuristics.Shuriken) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\500a (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\500b (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\500c (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\loga.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\logb.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\logc.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\logaa.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\logbb.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\messenge\logcc.dll (Malware.Trace) -> Quarantined and deleted successfully.

c:\arquivos de programas\windows media player\silkscrenn500.ini (Malware.Trace) -> Quarantined and deleted successfully.

c:\documents and settings\administrador\connect32.dll (Trojan.Banker) -> Quarantined and deleted successfully.

c:\documents and settings\administrador\dados de aplicativos\google talk\googletalk.exe (Trojan.Agent) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003aba1ac3fa8 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003aba1ac508a (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003aba1ac6859 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abd450960f (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abd450fb92 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abd4511537 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abe04803f4 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abe0484231 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\000003abe0488ff8 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod01.mp3 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod02.mp3 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod03.mp3 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod1-400 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod1-500 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod1-600 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod1-700 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod2-400 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod2-500 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod2-600 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod2-700 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod3-400 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod3-500 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod3-600 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\mod3-700 (Trojan.Banker) -> Quarantined and deleted successfully.

c:\WINDOWS\winarquivos\NewIcon.ico (Trojan.Banker) -> Quarantined and deleted successfully.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue o Log

 

 

RogueKiller V5.3.1 [08/06/2011] by Tigzy

contact at http://www.sur-la-toile.com

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

 

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Administrador [Admin rights]

Mode: Scan -- Date : 08/17/2011 18:30:46

 

Bad processes: 0

 

Registry Entries: 3

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

[HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

[HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

 

HOSTS File:

127.0.0.1 localhost

0.0.0.0 gtcc1.acecounter.com

0.0.0.0 gtp1.acecounter.com

0.0.0.0 acestats.com

0.0.0.0 www.acestats.com

0.0.0.0 www.activesearch.com #[Adware.ActiveSearch]

0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames]

0.0.0.0 www.actualnames.com

0.0.0.0 ad-up.com

0.0.0.0 www.ad-up.com

0.0.0.0 adatom.com

0.0.0.0 aesp.adatom.com

0.0.0.0 adbest.com #[iE-SpyAd]

0.0.0.0 www.adcipta.net #[W32/Malware]

0.0.0.0 adserv.adbonus.com #[iE-SpyAd]

0.0.0.0 www.adbonus.com

0.0.0.0 media.adcentriconline.com #[iE-SpyAd]

0.0.0.0 ad2.adcept.net

0.0.0.0 ad3.adcept.net

0.0.0.0 www.adcept.net #[iE-SpyAd]

[...]

 

 

Finished : << RKreport[1].txt >>

RKreport[1].txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Execute novamente o RogueKiller e tecle 2 > [ENTER]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Feito

 

 

RogueKiller V5.3.1 [08/06/2011] by Tigzy

contact at http://www.sur-la-toile.com

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

 

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Administrador [Admin rights]

Mode: Remove -- Date : 08/17/2011 18:38:58

 

Bad processes: 0

 

Registry Entries: 3

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

[HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

[HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

 

HOSTS File:

127.0.0.1 localhost

0.0.0.0 gtcc1.acecounter.com

0.0.0.0 gtp1.acecounter.com

0.0.0.0 acestats.com

0.0.0.0 www.acestats.com

0.0.0.0 www.activesearch.com #[Adware.ActiveSearch]

0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames]

0.0.0.0 www.actualnames.com

0.0.0.0 ad-up.com

0.0.0.0 www.ad-up.com

0.0.0.0 adatom.com

0.0.0.0 aesp.adatom.com

0.0.0.0 adbest.com #[iE-SpyAd]

0.0.0.0 www.adcipta.net #[W32/Malware]

0.0.0.0 adserv.adbonus.com #[iE-SpyAd]

0.0.0.0 www.adbonus.com

0.0.0.0 media.adcentriconline.com #[iE-SpyAd]

0.0.0.0 ad2.adcept.net

0.0.0.0 ad3.adcept.net

0.0.0.0 www.adcept.net #[iE-SpyAd]

[...]

 

 

Finished : << RKreport[2].txt >>

RKreport[1].txt ; RKreport[2].txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Execute novamente o RogueKiller e tecle 3 > [ENTER]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

RogueKiller V5.3.1 [08/06/2011] by Tigzy

contact at http://www.sur-la-toile.com

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

 

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Administrador [Admin rights]

Mode: HOSTSFix -- Date : 08/17/2011 18:43:29

 

Bad processes: 0

 

HOSTS File:

127.0.0.1 localhost

0.0.0.0 gtcc1.acecounter.com

0.0.0.0 gtp1.acecounter.com

0.0.0.0 acestats.com

0.0.0.0 www.acestats.com

0.0.0.0 www.activesearch.com #[Adware.ActiveSearch]

0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames]

0.0.0.0 www.actualnames.com

0.0.0.0 ad-up.com

0.0.0.0 www.ad-up.com

0.0.0.0 adatom.com

0.0.0.0 aesp.adatom.com

0.0.0.0 adbest.com #[iE-SpyAd]

0.0.0.0 www.adcipta.net #[W32/Malware]

0.0.0.0 adserv.adbonus.com #[iE-SpyAd]

0.0.0.0 www.adbonus.com

0.0.0.0 media.adcentriconline.com #[iE-SpyAd]

0.0.0.0 ad2.adcept.net

0.0.0.0 ad3.adcept.net

0.0.0.0 www.adcept.net #[iE-SpyAd]

[...]

 

 

Resetted HOSTS:

127.0.0.1 localhost

 

Finished : << RKreport[3].txt >>

RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Execute novamente o RogueKiller e tecle 4 > [ENTER]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

RogueKiller V5.3.1 [08/06/2011] by Tigzy

contact at http://www.sur-la-toile.com

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

 

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

Started in : Normal mode

User: Administrador [Admin rights]

Mode: ProxyFix -- Date : 08/17/2011 18:46:28

 

Bad processes: 0

 

Registry Entries: 0

 

Finished : << RKreport[4].txt >>

RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o ProxyFix e salve-o no desktop

*Tecle [A] > [ENTER]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

ProxyFix v 2.0 © by Maxstar

qua 17/08/2011 - 18:49:53,09

 

 

----------Internet Explorer----------

"ProxyEnable"=dword:00000000

 

----------Firefox----------

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.socks_port", 80);

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat");

user_pref("network.proxy.type", 2);

 

----------E.O.F----------

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Execute o ProxyFix

*Tecle [C] > [ENTER]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

ProxyFix v 2.0 © by Maxstar

qua 17/08/2011 - 18:51:47,23

 

 

----------Internet Explorer----------

"ProxyEnable"=dword:00000000

 

----------Firefox----------

 

----------E.O.F----------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Feito ^^

 

All Processes Killed

[Registry - Safe List]

Registry value HKEY_USERS\S-1-5-21-1547161642-1177238915-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable deleted successfully.

Registry value HKEY_USERS\S-1-5-21-1547161642-1177238915-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL deleted successfully.

HOSTS file reset successfully!

[Empty Temp Folders]

 

 

User: Administrador

->Temp folder emptied: 3533205541 bytes

->Temporary Internet Files folder emptied: 194233895 bytes

->Java cache emptied: 16381954 bytes

->FireFox cache emptied: 114225926 bytes

->Google Chrome cache emptied: 361905567 bytes

->Flash cache emptied: 16991681 bytes

 

User: All Users

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 41620 bytes

 

User: LocalService

->Temp folder emptied: 82513 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: NetworkService

->Temp folder emptied: 70164 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 2134162 bytes

%systemroot%\System32 .tmp files removed: 4001689 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 10503849 bytes

RecycleBin emptied: 91878 bytes

 

Total Files Cleaned = 4.057,00 mb

 

< End of fix log >

OTS by OldTimer - Version 3.1.44.3 fix logfile created on 08172011_204528

 

Files\Folders moved on Reboot...

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\0XeICnCPrcmGGTHylZmidjdgRUg= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\4ERV5Nyw7sDjpa0ScL3IGgX7J+o= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\8llsebuHnuOSrOErjDvF+c9V+uM= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\927OuiEo6rZBVJLSQPp43pMO8G8= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\9BDO5sMRePi0HzivGVRtm9QbEMw= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\AOr+f1P9H6ox0y8JuA1xyI0Oz6U= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\AS6CEVGUGOi1yXvIs9Z4SfW5jBc= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\bJxAmXUJdRjK82FNq1ijFIPnrfIQ= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\Bz0JZpJ7DBLYziOfoh02f52BUPU= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\DEOT0GuEd5eXECxrgdbHkUUr1Kk= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\dKFsvRTOaXAfsl2qvy3qGG2FArXA= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\Ea0di6m+VXwJh4F0uoW5JSfAvy4= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\GwFVkX5H4AWmPYYXYuXKYpUa3Cc= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\HMIJx6bmeU58f2FmT00vuEv3Ki4c= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\I255B+e+wcicZ7HXrKsdvmhd+Sw= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\lb2LpajsxqWH0g54KmVpXpjuOgI= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\O33F9dstf8rcwFXly4RFGHVxYFA= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\PlBHD2FY2FNR93kVl3upb2FF7yem4g= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\RZW585t5UbA8LqXWQVoT8nYbOYA= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\T0DYZ5w+VKpKCyaOU2sKL8GAMRM= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tjwi8qUGjvtGz1CF6C7xC7ACBGM= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tNtLmM7NNqjL6RCf2QwvF5tC4hY= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tQcjmhlmOBX3SbS8BivYOpQmTNI= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\UDWs4bM0B3o3oytOPpvlFzlcjms= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\UqaDSqeECpBMI0RCX+gmamShsd0= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\wJZBV6DQrx6U1mJ6RgbZLdkv+Lg= moved successfully.

C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\YwBxho7KqCFsFk+kPMJDhjVk22A= moved successfully.

File\Folder C:\Documents and Settings\Administrador\Configurações locais\Temporary Internet Files\Content.IE5\SC825DNQ\01[1].htm not found!

File\Folder C:\Documents and Settings\Administrador\Configurações locais\Temporary Internet Files\Content.IE5\SC825DNQ\ADSAdClient31[4].htm not found!

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Baixe o AD-Remover e salve-o no desktop

*Execute-o, clique [Clean] > [sim] > [OK] > [sim]

*Cole o relatório C:\Ad-Report-CLEAN[1].txt

 

2.

*Baixe o USBFix e salve-o no desktop

*Conecte e mantenha o pen drive no PC

*Execute o UsbFix e clique [supressão]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

nem pra avisa ein @_@

ta aqui

 

 

======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 12/04/11

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 20:56:46 on 17/08/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 3 (X86)

Administrador@DAS-86CB343315C ( )

 

============== ACTION(S) ==============

 

 

Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\conduit

Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\ConduitEngine

Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\extensions\engine@conduit.com

File deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\searchplugins\web-search.xml

Folder deleted: C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Conduit

 

(!) -- Temporary files deleted.

 

 

-- File opened: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\Prefs.js --

Line deleted: user_pref("CT2905346.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT290...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1297271/1292942/BR", "\"0\"...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2905346", ...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.5...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3....

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2905346",...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2905346&octid=...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/minimize.gif...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/play.gif", "...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/stop.gif", "...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/stopped.GIF"...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/vol.gif", "\...

Line deleted: user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pt-br", "\"...

Line deleted: user_pref("CommunityToolbar.EngineOwner", "CT2905346");

Line deleted: user_pref("CommunityToolbar.EngineOwnerGuid", "{1d80d668-2160-46a2-b3a7-e166795b0b28}");

Line deleted: user_pref("CommunityToolbar.EngineOwnerToolbarId", "messenger_plus_br");

Line deleted: user_pref("CommunityToolbar.IsEngineShown", true);

Line deleted: user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);

Line deleted: user_pref("CommunityToolbar.OriginalEngineOwner", "CT2905346");

Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{1d80d668-2160-46a2-b3a7-e166795b0b28}");

Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "messenger_plus_br");

Line deleted: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://radiobar.toolbarhome.com/search.a...

Line deleted: user_pref("CommunityToolbar.ToolbarsList", "CT2905346,ConduitEngine");

Line deleted: user_pref("CommunityToolbar.ToolbarsList2", "CT2905346");

Line deleted: user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Aug 08 2011 16:13:58 GMT-03...

Line deleted: user_pref("CommunityToolbar.alert.alertInfoInterval", 60);

Line deleted: user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Aug 08 2011 16:14:06 GMT-0300 (Hora ...

Line deleted: user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");

Line deleted: user_pref("CommunityToolbar.alert.locale", "en");

Line deleted: user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);

Line deleted: user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon Aug 08 2011 16:13:52 GMT-0300 (Hora ofic...

Line deleted: user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");

Line deleted: user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);

Line deleted: user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");

Line deleted: user_pref("CommunityToolbar.alert.showTrayIcon", false);

Line deleted: user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);

Line deleted: user_pref("CommunityToolbar.alert.userId", "facce56c-07ac-4735-a661-512bbf1c50b6");

Line deleted: user_pref("CommunityToolbar.globalUserId", "9e060dca-4b2d-4ee1-97b1-1a1dd014d5f1");

Line deleted: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);

Line deleted: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);

Line deleted: user_pref("ConduitEngine.AppTrackingLastCheckTime", "Mon Aug 08 2011 16:14:05 GMT-0300 (Hora oficial...

Line deleted: user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Mon Aug 08 2011 16:13:56 GMT-0300 (Hora ofici...

Line deleted: user_pref("ConduitEngine.FirstServerDate", "08/08/2011 22");

Line deleted: user_pref("ConduitEngine.FirstTime", true);

Line deleted: user_pref("ConduitEngine.FirstTimeFF3", true);

Line deleted: user_pref("ConduitEngine.HasUserGlobalKeys", true);

Line deleted: user_pref("ConduitEngine.HideEngineAfterRestart", true);

Line deleted: user_pref("ConduitEngine.Initialize", true);

Line deleted: user_pref("ConduitEngine.InitializeCommonPrefs", true);

Line deleted: user_pref("ConduitEngine.InstalledDate", "Mon Aug 08 2011 16:13:58 GMT-0300 (Hora oficial do Brasil)...

Line deleted: user_pref("ConduitEngine.IsOpenThankYouPage", false);

Line deleted: user_pref("ConduitEngine.IsOpenUninstallPage", true);

Line deleted: user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora oficia...

Line deleted: user_pref("ConduitEngine.LastLogin_3.3.5.1", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora oficial do Bra...

Line deleted: user_pref("ConduitEngine.PublisherContainerWidth", 0);

Line deleted: user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);

Line deleted: user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Aug 08 2011 16:13:53 GMT-0300 (Hora oficial do...

Line deleted: user_pref("ConduitEngine.UserID", "UN85648893958021042");

Line deleted: user_pref("ConduitEngine.engineLocale", "pt-BR");

Line deleted: user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora ...

Line deleted: user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Aug 08 2011 16:13:59 GMT-0300 (Hora...

Line deleted: user_pref("ConduitEngine.initDone", true);

Line deleted: user_pref("ConduitEngine.isAppTrackingManagerOn", true);

-- File closed --

 

 

Key deleted: HKLM\Software\Classes\Conduit.Engine

Key deleted: HKLM\Software\Classes\Toolbar.CT2905346

Key deleted: HKLM\Software\Conduit

Key deleted: HKLM\Software\aMSN\OpenCandy

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

 

 

============== ADDITIONNAL SCAN ==============

 

**** Mozilla Firefox Version [3.6.8 (pt-BR)] ****

 

HKLM_MozillaPlugins\@pandonetworks.com/PandoWebPlugin (x)

HKLM_MozillaPlugins\Adobe Reader (x)

Searchplugins\buscape.xml (hxxp://busca.buscape.com.br/cprocura)

Searchplugins\mercadolivre.xml (hxxp://pmstrk.mercadolivre.com.br/jm/PmsTrk)

Searchplugins\wikipedia-br.xml (hxxp://pt.wikipedia.org/wiki/Especial:Busca)

Searchplugins\yahoo-br.xml (hxxp://br.search.yahoo.com/search)

 

-- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default --

Extensions\radiobar@toolbar (RadioBar Toolbar)

Extensions\YoutubeDownloader@PeterOlayev.com (1-Click YouTube Video Downloader)

Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} (FlashGot)

Extensions\{1d80d668-2160-46a2-b3a7-e166795b0b28} (Messenger Plus BR Community Toolbar)

Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Administrador\\Meus documentos\\Minhas imagens

Prefs.js - browser.search.defaultenginename, Web Search...

Prefs.js - browser.startup.homepage, hxxp://www.google.com.br/

Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.8

Prefs.js - keyword.URL, hxxp://radiobar.toolbarhome.com/search.aspx?srch=ku&q=

Prefs.js - browser.startup.homepage,

Prefs.js - browser.search.selectedEngine,

Prefs.js - browser.search.defaultenginename,

Prefs.js - browser.startup.homepage,

Prefs.js - browser.search.selectedEngine,

Prefs.js - browser.search.defaultenginename,

 

========================================

 

**** Google Chrome Version [13.0.782.112] ****

 

Extension - jfmjfhklogoienhpfnppmbcbjfjnkonk (x)

Extension\ohhbldejoecoecfngibhhhfgilhhoilo (C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\ohhbldejoecoecfngibhhhfgilhhoilo.crx) (x)

 

-- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default --

Preferences - default_search_provider: "Google" (Enabled: true) (?)

Preferences - homepage: hxxp://www.google.com.br/

Preferences - homepage_is_newtabpage: false

Plugin - RealJukebox NS Plugin (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\nprjplug.dll)

Plugin - Pando Web Plugin (Enabled: true) (C:\Arquivos de programas\Pando Networks\Media Booster\npPandoWebPlugin.dll) (x)

Plugin - "Pando Web Plugin" (Enabled: true)

Plugin - "RealJukebox NS Plugin" (Enabled: true)

Preferences - urls_to_restore_on_startup: hxxp://search.conduit.com/?ctid=ct2905346&SearchSource=48

 

========================================

 

**** Internet Explorer Version [7.0.5730.13] ****

 

HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896

HKCU_Main|Start Page - hxxp://fr.msn.com/

HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896

HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm

HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Start Page - hxxp://fr.msn.com/

HKLM_ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} - C:\Arquivos de programas\Iminent\MMServer\Iminent.MMServer.exe (x)

HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)

BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

BHO\{9030D464-4C02-4ABF-8ECC-5164760863C6} - "Auxiliar de Conexão do Windows Live" (C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll)

BHO\{D1763781-8374-40BD-836A-F2E1F2600B2F}836A-F2E1F2600B2F} (?)

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 105 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 13 File(s)

 

C:\Ad-Report-CLEAN[1].txt - 17/08/2011 20:57:04 (10743 Byte(s))

 

End at: 20:57:28, 17/08/2011

 

============== E.O.F ==============

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.