juniorzin 0 Denunciar post Postado Agosto 17, 2011 Boa tarde , estou com um problema no meu pc , que ele simplismente não executa os anti - virus , creio eu que seja malware , ja vi problemas semelhantes ao meu que era virus , Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:27:32, on 17/8/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.17080) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe C:\Documents and Settings\Administrador\system.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Windows Media Player\wmplayer.exe C:\Documents and Settings\Administrador\Meus documentos\Downloads\SoftonicDownloader_para_hijackthis.exe C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.minilua.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.minilua.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.minilua.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.minilua.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.minilua.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.minilua.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.minilua.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.minilua.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.minilua.com/q/%s R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ww4.freeurlset.com:8083/connect.dat O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {D1763781-8374-40BD-836A-F2E1F2600B2F}836A-F2E1F2600B2F} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [MSC] "c:\Arquivos de programas\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Policies\Explorer\Run: [internet] "C:\Documents and Settings\Administrador\system.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{43116D85-F7AE-4142-A8E1-38C709F5A91C}: NameServer = 200.204.0.10 200.204.0.138 O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Arquivos de programas\Arquivos comuns\Adobe\SwitchBoard\SwitchBoard.exe -- End of file - 9772 bytes Grato Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 Olá juniorzin *Baixe o MalwareBytes e salve-o no desktop *Instale o programa e aguarde a atualização *O programa será aberto automaticamente *Na aba [Verificação], selecione [Verificação completa] *Clique [Verificar] e selecione a partição onde o Windows está instalado *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 oii descupa , postei e fui pra academia terminei agr de fazer ^^ segue ai o log Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Versão da Base de Dados: 7491 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 17/8/2011 18:00:10 mbam-log-2011-08-17 (18-00-10).txt Tipo de Verificação: Verificação Completa (C:\|) Objetos escaneados: 225854 Tempo decorrido: 29 minuto(s), 55 segundo(s) Processos de Memória Infectados: 1 Módulos de Memória Infectados: 2 Chaves de Registro Infectadas: 5 Valores de Registro Infectados: 2 Itens de Dados no Registro Infectados: 4 Pastas Infectadas: 1 Arquivos Infectados: 44 Processos de Memória Infectados: c:\documents and settings\administrador\system.exe (Trojan.Agent) -> 1948 -> Unloaded process successfully. Módulos de Memória Infectados: c:\WINDOWS\ksef1541.dll (Trojan.BHO) -> Delete on reboot. c:\documents and settings\administrador\engine.dll (Trojan.Agent) -> Delete on reboot. Chaves de Registro Infectadas: HKEY_CLASSES_ROOT\CLSID\{D1763781-8374-40BD-836A-F2E1F2600B2F} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{C5C53AD7-957B-40C0-9886-B3CA26A51BD1} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{46AF773E-50A3-4347-A6EC-BEEA0CF115CD} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Center.CenterPlus (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1763781-8374-40BD-836A-F2E1F2600B2F} (Trojan.BHO) -> Quarantined and deleted successfully. Valores de Registro Infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Internet (Trojan.Agent) -> Value: Internet -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Value: ForceClassicControlPanel -> Quarantined and deleted successfully. Itens de Dados no Registro Infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Pastas Infectadas: c:\WINDOWS\winarquivos (Trojan.Banker) -> Quarantined and deleted successfully. Arquivos Infectados: c:\WINDOWS\ksef1541.dll (Trojan.BHO) -> Delete on reboot. c:\documents and settings\administrador\system.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\administrador\engine.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\administrador\configurações locais\Temp\Rar$EX00.406\diablo2_kg.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. c:\documents and settings\administrador\configurações locais\Temp\Rar$EX06.188\keygen ps cs5.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully. c:\WINDOWS\system32\ebyhed.dll (Worm.Downadup) -> Delete on reboot. c:\WINDOWS\system32\igfxrenuz.dll (Heuristics.Shuriken) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\500a (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\500b (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\500c (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\loga.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\logb.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\logc.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\logaa.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\logbb.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\messenge\logcc.dll (Malware.Trace) -> Quarantined and deleted successfully. c:\arquivos de programas\windows media player\silkscrenn500.ini (Malware.Trace) -> Quarantined and deleted successfully. c:\documents and settings\administrador\connect32.dll (Trojan.Banker) -> Quarantined and deleted successfully. c:\documents and settings\administrador\dados de aplicativos\google talk\googletalk.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003aba1ac3fa8 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003aba1ac508a (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003aba1ac6859 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abd450960f (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abd450fb92 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abd4511537 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abe04803f4 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abe0484231 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\000003abe0488ff8 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod01.mp3 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod02.mp3 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod03.mp3 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod1-400 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod1-500 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod1-600 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod1-700 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod2-400 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod2-500 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod2-600 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod2-700 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod3-400 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod3-500 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod3-600 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\mod3-700 (Trojan.Banker) -> Quarantined and deleted successfully. c:\WINDOWS\winarquivos\NewIcon.ico (Trojan.Banker) -> Quarantined and deleted successfully. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Baixe o RogueKiller e salve-o no desktop *Execute-o e tecle 1 > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 Segue o Log RogueKiller V5.3.1 [08/06/2011] by Tigzy contact at http://www.sur-la-toile.com mail: tigzyRK<at>gmail<dot>com Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: Administrador [Admin rights] Mode: Scan -- Date : 08/17/2011 18:30:46 Bad processes: 0 Registry Entries: 3 [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND [HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND [HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND HOSTS File: 127.0.0.1 localhost 0.0.0.0 gtcc1.acecounter.com 0.0.0.0 gtp1.acecounter.com 0.0.0.0 acestats.com 0.0.0.0 www.acestats.com 0.0.0.0 www.activesearch.com #[Adware.ActiveSearch] 0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames] 0.0.0.0 www.actualnames.com 0.0.0.0 ad-up.com 0.0.0.0 www.ad-up.com 0.0.0.0 adatom.com 0.0.0.0 aesp.adatom.com 0.0.0.0 adbest.com #[iE-SpyAd] 0.0.0.0 www.adcipta.net #[W32/Malware] 0.0.0.0 adserv.adbonus.com #[iE-SpyAd] 0.0.0.0 www.adbonus.com 0.0.0.0 media.adcentriconline.com #[iE-SpyAd] 0.0.0.0 ad2.adcept.net 0.0.0.0 ad3.adcept.net 0.0.0.0 www.adcept.net #[iE-SpyAd] [...] Finished : << RKreport[1].txt >> RKreport[1].txt Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Execute novamente o RogueKiller e tecle 2 > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 Feito RogueKiller V5.3.1 [08/06/2011] by Tigzy contact at http://www.sur-la-toile.com mail: tigzyRK<at>gmail<dot>com Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: Administrador [Admin rights] Mode: Remove -- Date : 08/17/2011 18:38:58 Bad processes: 0 Registry Entries: 3 [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0) [HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0) [HJ] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0) HOSTS File: 127.0.0.1 localhost 0.0.0.0 gtcc1.acecounter.com 0.0.0.0 gtp1.acecounter.com 0.0.0.0 acestats.com 0.0.0.0 www.acestats.com 0.0.0.0 www.activesearch.com #[Adware.ActiveSearch] 0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames] 0.0.0.0 www.actualnames.com 0.0.0.0 ad-up.com 0.0.0.0 www.ad-up.com 0.0.0.0 adatom.com 0.0.0.0 aesp.adatom.com 0.0.0.0 adbest.com #[iE-SpyAd] 0.0.0.0 www.adcipta.net #[W32/Malware] 0.0.0.0 adserv.adbonus.com #[iE-SpyAd] 0.0.0.0 www.adbonus.com 0.0.0.0 media.adcentriconline.com #[iE-SpyAd] 0.0.0.0 ad2.adcept.net 0.0.0.0 ad3.adcept.net 0.0.0.0 www.adcept.net #[iE-SpyAd] [...] Finished : << RKreport[2].txt >> RKreport[1].txt ; RKreport[2].txt Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Execute novamente o RogueKiller e tecle 3 > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 RogueKiller V5.3.1 [08/06/2011] by Tigzy contact at http://www.sur-la-toile.com mail: tigzyRK<at>gmail<dot>com Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: Administrador [Admin rights] Mode: HOSTSFix -- Date : 08/17/2011 18:43:29 Bad processes: 0 HOSTS File: 127.0.0.1 localhost 0.0.0.0 gtcc1.acecounter.com 0.0.0.0 gtp1.acecounter.com 0.0.0.0 acestats.com 0.0.0.0 www.acestats.com 0.0.0.0 www.activesearch.com #[Adware.ActiveSearch] 0.0.0.0 actualnames.com #[Parasite.ActualNames][spyware.ActualNames] 0.0.0.0 www.actualnames.com 0.0.0.0 ad-up.com 0.0.0.0 www.ad-up.com 0.0.0.0 adatom.com 0.0.0.0 aesp.adatom.com 0.0.0.0 adbest.com #[iE-SpyAd] 0.0.0.0 www.adcipta.net #[W32/Malware] 0.0.0.0 adserv.adbonus.com #[iE-SpyAd] 0.0.0.0 www.adbonus.com 0.0.0.0 media.adcentriconline.com #[iE-SpyAd] 0.0.0.0 ad2.adcept.net 0.0.0.0 ad3.adcept.net 0.0.0.0 www.adcept.net #[iE-SpyAd] [...] Resetted HOSTS: 127.0.0.1 localhost Finished : << RKreport[3].txt >> RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Execute novamente o RogueKiller e tecle 4 > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 RogueKiller V5.3.1 [08/06/2011] by Tigzy contact at http://www.sur-la-toile.com mail: tigzyRK<at>gmail<dot>com Feedback: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User: Administrador [Admin rights] Mode: ProxyFix -- Date : 08/17/2011 18:46:28 Bad processes: 0 Registry Entries: 0 Finished : << RKreport[4].txt >> RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Baixe o ProxyFix e salve-o no desktop *Tecle [A] > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 ProxyFix v 2.0 © by Maxstar qua 17/08/2011 - 18:49:53,09 ----------Internet Explorer---------- "ProxyEnable"=dword:00000000 ----------Firefox---------- user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.socks_port", 80); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); user_pref("network.proxy.autoconfig_url", "http://ww4.freeurlset.com:8083/connect.dat"); user_pref("network.proxy.type", 2); ----------E.O.F---------- Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 *Execute o ProxyFix *Tecle [C] > [ENTER] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 ProxyFix v 2.0 © by Maxstar qua 17/08/2011 - 18:51:47,23 ----------Internet Explorer---------- "ProxyEnable"=dword:00000000 ----------Firefox---------- ----------E.O.F---------- Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 Feito ^^ All Processes Killed [Registry - Safe List] Registry value HKEY_USERS\S-1-5-21-1547161642-1177238915-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable deleted successfully. Registry value HKEY_USERS\S-1-5-21-1547161642-1177238915-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL deleted successfully. HOSTS file reset successfully! [Empty Temp Folders] User: Administrador ->Temp folder emptied: 3533205541 bytes ->Temporary Internet Files folder emptied: 194233895 bytes ->Java cache emptied: 16381954 bytes ->FireFox cache emptied: 114225926 bytes ->Google Chrome cache emptied: 361905567 bytes ->Flash cache emptied: 16991681 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41620 bytes User: LocalService ->Temp folder emptied: 82513 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 70164 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2134162 bytes %systemroot%\System32 .tmp files removed: 4001689 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 10503849 bytes RecycleBin emptied: 91878 bytes Total Files Cleaned = 4.057,00 mb < End of fix log > OTS by OldTimer - Version 3.1.44.3 fix logfile created on 08172011_204528 Files\Folders moved on Reboot... C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\0XeICnCPrcmGGTHylZmidjdgRUg= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\4ERV5Nyw7sDjpa0ScL3IGgX7J+o= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\8llsebuHnuOSrOErjDvF+c9V+uM= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\927OuiEo6rZBVJLSQPp43pMO8G8= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\9BDO5sMRePi0HzivGVRtm9QbEMw= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\AOr+f1P9H6ox0y8JuA1xyI0Oz6U= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\AS6CEVGUGOi1yXvIs9Z4SfW5jBc= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\bJxAmXUJdRjK82FNq1ijFIPnrfIQ= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\Bz0JZpJ7DBLYziOfoh02f52BUPU= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\DEOT0GuEd5eXECxrgdbHkUUr1Kk= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\dKFsvRTOaXAfsl2qvy3qGG2FArXA= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\Ea0di6m+VXwJh4F0uoW5JSfAvy4= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\GwFVkX5H4AWmPYYXYuXKYpUa3Cc= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\HMIJx6bmeU58f2FmT00vuEv3Ki4c= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\I255B+e+wcicZ7HXrKsdvmhd+Sw= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\lb2LpajsxqWH0g54KmVpXpjuOgI= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\O33F9dstf8rcwFXly4RFGHVxYFA= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\PlBHD2FY2FNR93kVl3upb2FF7yem4g= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\RZW585t5UbA8LqXWQVoT8nYbOYA= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\T0DYZ5w+VKpKCyaOU2sKL8GAMRM= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tjwi8qUGjvtGz1CF6C7xC7ACBGM= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tNtLmM7NNqjL6RCf2QwvF5tC4hY= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\tQcjmhlmOBX3SbS8BivYOpQmTNI= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\UDWs4bM0B3o3oytOPpvlFzlcjms= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\UqaDSqeECpBMI0RCX+gmamShsd0= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\wJZBV6DQrx6U1mJ6RgbZLdkv+Lg= moved successfully. C:\Documents and Settings\Administrador\Configurações locais\Temp\MessengerCache\YwBxho7KqCFsFk+kPMJDhjVk22A= moved successfully. File\Folder C:\Documents and Settings\Administrador\Configurações locais\Temporary Internet Files\Content.IE5\SC825DNQ\01[1].htm not found! File\Folder C:\Documents and Settings\Administrador\Configurações locais\Temporary Internet Files\Content.IE5\SC825DNQ\ADSAdClient31[4].htm not found! Registry entries deleted on Reboot... Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 17, 2011 1. *Baixe o AD-Remover e salve-o no desktop *Execute-o, clique [Clean] > [sim] > [OK] > [sim] *Cole o relatório C:\Ad-Report-CLEAN[1].txt 2. *Baixe o USBFix e salve-o no desktop *Conecte e mantenha o pen drive no PC *Execute o UsbFix e clique [supressão] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 17, 2011 meu pc reinicio sozin no meio do processo do ad o.o Medo kkk vo fazer dnv Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 18, 2011 Ele pode reiniciar para remover. Veja se há o relatório. Compartilhar este post Link para o post Compartilhar em outros sites
juniorzin 0 Denunciar post Postado Agosto 18, 2011 nem pra avisa ein @_@ ta aqui ======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 12/04/11 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 20:56:46 on 17/08/2011, Normal boot Microsoft Windows XP Professional Service Pack 3 (X86) Administrador@DAS-86CB343315C ( ) ============== ACTION(S) ============== Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\conduit Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\ConduitEngine Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\extensions\engine@conduit.com File deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\searchplugins\web-search.xml Folder deleted: C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Conduit (!) -- Temporary files deleted. -- File opened: C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default\Prefs.js -- Line deleted: user_pref("CT2905346.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT290... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1297271/1292942/BR", "\"0\"... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2905346", ... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-services.com/DLG.pkg?ver=3.3.5... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2905346",... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?browser=FF&lut=0", "63... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2905346&octid=... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/minimize.gif... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/play.gif", "... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/stop.gif", "... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/stopped.GIF"... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Funky/vol.gif", "\... Line deleted: user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pt-br", "\"... Line deleted: user_pref("CommunityToolbar.EngineOwner", "CT2905346"); Line deleted: user_pref("CommunityToolbar.EngineOwnerGuid", "{1d80d668-2160-46a2-b3a7-e166795b0b28}"); Line deleted: user_pref("CommunityToolbar.EngineOwnerToolbarId", "messenger_plus_br"); Line deleted: user_pref("CommunityToolbar.IsEngineShown", true); Line deleted: user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true); Line deleted: user_pref("CommunityToolbar.OriginalEngineOwner", "CT2905346"); Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{1d80d668-2160-46a2-b3a7-e166795b0b28}"); Line deleted: user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "messenger_plus_br"); Line deleted: user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://radiobar.toolbarhome.com/search.a... Line deleted: user_pref("CommunityToolbar.ToolbarsList", "CT2905346,ConduitEngine"); Line deleted: user_pref("CommunityToolbar.ToolbarsList2", "CT2905346"); Line deleted: user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Mon Aug 08 2011 16:13:58 GMT-03... Line deleted: user_pref("CommunityToolbar.alert.alertInfoInterval", 60); Line deleted: user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Mon Aug 08 2011 16:14:06 GMT-0300 (Hora ... Line deleted: user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com"); Line deleted: user_pref("CommunityToolbar.alert.locale", "en"); Line deleted: user_pref("CommunityToolbar.alert.loginIntervalMin", 1440); Line deleted: user_pref("CommunityToolbar.alert.loginLastCheckTime", "Mon Aug 08 2011 16:13:52 GMT-0300 (Hora ofic... Line deleted: user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559"); Line deleted: user_pref("CommunityToolbar.alert.messageShowTimeSec", 20); Line deleted: user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com"); Line deleted: user_pref("CommunityToolbar.alert.showTrayIcon", false); Line deleted: user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300); Line deleted: user_pref("CommunityToolbar.alert.userId", "facce56c-07ac-4735-a661-512bbf1c50b6"); Line deleted: user_pref("CommunityToolbar.globalUserId", "9e060dca-4b2d-4ee1-97b1-1a1dd014d5f1"); Line deleted: user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Line deleted: user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Line deleted: user_pref("ConduitEngine.AppTrackingLastCheckTime", "Mon Aug 08 2011 16:14:05 GMT-0300 (Hora oficial... Line deleted: user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Mon Aug 08 2011 16:13:56 GMT-0300 (Hora ofici... Line deleted: user_pref("ConduitEngine.FirstServerDate", "08/08/2011 22"); Line deleted: user_pref("ConduitEngine.FirstTime", true); Line deleted: user_pref("ConduitEngine.FirstTimeFF3", true); Line deleted: user_pref("ConduitEngine.HasUserGlobalKeys", true); Line deleted: user_pref("ConduitEngine.HideEngineAfterRestart", true); Line deleted: user_pref("ConduitEngine.Initialize", true); Line deleted: user_pref("ConduitEngine.InitializeCommonPrefs", true); Line deleted: user_pref("ConduitEngine.InstalledDate", "Mon Aug 08 2011 16:13:58 GMT-0300 (Hora oficial do Brasil)... Line deleted: user_pref("ConduitEngine.IsOpenThankYouPage", false); Line deleted: user_pref("ConduitEngine.IsOpenUninstallPage", true); Line deleted: user_pref("ConduitEngine.LanguagePackLastCheckTime", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora oficia... Line deleted: user_pref("ConduitEngine.LastLogin_3.3.5.1", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora oficial do Bra... Line deleted: user_pref("ConduitEngine.PublisherContainerWidth", 0); Line deleted: user_pref("ConduitEngine.SearchFromAddressBarIsInit", true); Line deleted: user_pref("ConduitEngine.SettingsLastCheckTime", "Mon Aug 08 2011 16:13:53 GMT-0300 (Hora oficial do... Line deleted: user_pref("ConduitEngine.UserID", "UN85648893958021042"); Line deleted: user_pref("ConduitEngine.engineLocale", "pt-BR"); Line deleted: user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Mon Aug 08 2011 16:13:55 GMT-0300 (Hora ... Line deleted: user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Mon Aug 08 2011 16:13:59 GMT-0300 (Hora... Line deleted: user_pref("ConduitEngine.initDone", true); Line deleted: user_pref("ConduitEngine.isAppTrackingManagerOn", true); -- File closed -- Key deleted: HKLM\Software\Classes\Conduit.Engine Key deleted: HKLM\Software\Classes\Toolbar.CT2905346 Key deleted: HKLM\Software\Conduit Key deleted: HKLM\Software\aMSN\OpenCandy Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} ============== ADDITIONNAL SCAN ============== **** Mozilla Firefox Version [3.6.8 (pt-BR)] **** HKLM_MozillaPlugins\@pandonetworks.com/PandoWebPlugin (x) HKLM_MozillaPlugins\Adobe Reader (x) Searchplugins\buscape.xml (hxxp://busca.buscape.com.br/cprocura) Searchplugins\mercadolivre.xml (hxxp://pmstrk.mercadolivre.com.br/jm/PmsTrk) Searchplugins\wikipedia-br.xml (hxxp://pt.wikipedia.org/wiki/Especial:Busca) Searchplugins\yahoo-br.xml (hxxp://br.search.yahoo.com/search) -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\06ihivk5.default -- Extensions\radiobar@toolbar (RadioBar Toolbar) Extensions\YoutubeDownloader@PeterOlayev.com (1-Click YouTube Video Downloader) Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34} (FlashGot) Extensions\{1d80d668-2160-46a2-b3a7-e166795b0b28} (Messenger Plus BR Community Toolbar) Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Administrador\\Meus documentos\\Minhas imagens Prefs.js - browser.search.defaultenginename, Web Search... Prefs.js - browser.startup.homepage, hxxp://www.google.com.br/ Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.8 Prefs.js - keyword.URL, hxxp://radiobar.toolbarhome.com/search.aspx?srch=ku&q= Prefs.js - browser.startup.homepage, Prefs.js - browser.search.selectedEngine, Prefs.js - browser.search.defaultenginename, Prefs.js - browser.startup.homepage, Prefs.js - browser.search.selectedEngine, Prefs.js - browser.search.defaultenginename, ======================================== **** Google Chrome Version [13.0.782.112] **** Extension - jfmjfhklogoienhpfnppmbcbjfjnkonk (x) Extension\ohhbldejoecoecfngibhhhfgilhhoilo (C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\ohhbldejoecoecfngibhhhfgilhhoilo.crx) (x) -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default -- Preferences - default_search_provider: "Google" (Enabled: true) (?) Preferences - homepage: hxxp://www.google.com.br/ Preferences - homepage_is_newtabpage: false Plugin - RealJukebox NS Plugin (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\nprjplug.dll) Plugin - Pando Web Plugin (Enabled: true) (C:\Arquivos de programas\Pando Networks\Media Booster\npPandoWebPlugin.dll) (x) Plugin - "Pando Web Plugin" (Enabled: true) Plugin - "RealJukebox NS Plugin" (Enabled: true) Preferences - urls_to_restore_on_startup: hxxp://search.conduit.com/?ctid=ct2905346&SearchSource=48 ======================================== **** Internet Explorer Version [7.0.5730.13] **** HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896 HKCU_Main|Start Page - hxxp://fr.msn.com/ HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896 HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM_Main|Start Page - hxxp://fr.msn.com/ HKLM_ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} - C:\Arquivos de programas\Iminent\MMServer\Iminent.MMServer.exe (x) HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?) BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?) BHO\{9030D464-4C02-4ABF-8ECC-5164760863C6} - "Auxiliar de Conexão do Windows Live" (C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll) BHO\{D1763781-8374-40BD-836A-F2E1F2600B2F}836A-F2E1F2600B2F} (?) ======================================== C:\Arquivos de programas\Ad-Remover\Quarantine: 105 File(s) C:\Arquivos de programas\Ad-Remover\Backup: 13 File(s) C:\Ad-Report-CLEAN[1].txt - 17/08/2011 20:57:04 (10743 Byte(s)) End at: 20:57:28, 17/08/2011 ============== E.O.F ============== Compartilhar este post Link para o post Compartilhar em outros sites