FórumGdH

Página Inicial do Guia do Hardware

Registrar FAQ Calendário Pesquisar Mensagens de Hoje Marcar Fóruns Como Lidos

Voltar   FórumGdH > Software, Segurança e Mac (Apple) > Segurança: discussões, dúvidas e informações
Bem-vindo ao FórumGdH
Não se esqueça de se registrar, é grátis . Nós temos 759.317 usuários, convidamos você fazer parte de nossa comunidade também! Se ainda não encontrou o que procura use nossa pesquisa. Esperamos que aprecie nosso trabalho.

Resposta
 
Opções do Tópico
Antigo 23-12-2009, 18:07   #1 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão Problema no IE8 e Firefox 3,5

meu pc ta com o seguinte problema, no IE 8 por exemplo entro no login do Orkut e qdo digito meu nome e senha a tela fica apagadinha e abre uma caixa dizendo q a pagina precisa ser restaurada, clico em restaurar e simplesmente cai a pagina, nao entra o Orkut de jeito nenhum...
Ja no Firefox 3.5.6 navego normal por todos os sites inclusive entra o Orkut, so que dentro de um site qualquer eu mudando de uma pagina pra outra algumas vezes td normal mais derrepente abre uma caixa q diz o seguinte > A PROGRAM NEEDS PERMISSION TO CONTINUE >>> IF YOU STARTET THIS PROGRAM, CONTINUE >>> JAVA(TM) SE RUMTIME ENVIRONMENT 6 UPDATE 17 SUM MICROSYSTEMS INC. >>> C:\PROGRAM FILE\JAVA\JRE6\BIN\JQSNOTFLY.EXE...
Eh indiferente se clico em continue ou cancel pois o resultado eh o mesmo, ele libera pra acessar a pg mais abre um outro site na hora com propagandas que fica na barrinha la em baixo, isso ta acontecendo direto, ja fui no site da java e baixei o mais atual, ja passei o Antivir em modo normal e modo de segurança, ja passei o Ccleaner tb em modo normal e de segurança e ja passei o CHKDSK no prompt, o relogio do pc ta certo, alguem poderia me ajudar?
Estou usando o Vista Home Edition
will77 está offline   Responder com Quote
Antigo 23-12-2009, 18:32   #2 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Olá will77


Vamos ver se é algo relacionado a virus.


Faça o download do HijackThis aqui

Crie uma pasta, e nomeia-a de Hijackthis..
Extraia o conteúdo do arquivo .zip baixado dentro da pasta criada por você
Execute o programa...
Aceite o contrato...
Aparecerá uma janela clique em Do a system scan and save a log file..
Não marque nada...simplismente copie o Log que aparecerá num bloco de notas e poste aqui....

Aguardo o seu poste...



T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 23-12-2009, 18:59   #3 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão Feito Diogo

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:16:17 PM, on 12/23/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Users\JcBonG\Desktop\ver virus\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion &pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion &pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...lion &pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5290\ACEIEAddOn.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files\Scpad\scpsssh2.dll
O2 - BHO: Customized Platform Advancer - {42C7C39F-3128-4a17-BDB7-91C46032B5B9} - C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPAIEAddOn.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\s wg.dll
O2 - BHO: Content Management Wizard - {B72681C0-A222-4b21-A0E2-53A5A5CA3D41} - C:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll
O2 - BHO: Textual Content Provider - {CAC89FF9-34A9-4431-8CFE-292A47F843BC} - C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Web Search Operator - {EB4A577D-BCAD-4b1c-8AF2-9A74B8DD3431} - C:\Program Files\Web Search Operator\4.1.0.2080\wso.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMen u.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Dealio Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [Internet Today Task] "C:\Program Files\Internet Today\1.1.0.1260\InternetToday.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Super Screen Capture] C:\Program Files\Zeallsoft\Super Screen Capture\SSCapture.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\JcBonG\AppData\Local\Google\Update\Googl eUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_6.0;_en-US)_AppleWebKit/532.0_(KHTML,_like_Gecko)_Chrome/3.0.195.38_Safari/532.0" -"http://www.cyberjogos.com/box/jugar_...no&room=bbb_01"
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6 097707281E79.dll/cmsidewiki.html
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: Justin.tv Publisher - http://pt-br.justin.tv/plugins/justintv_publisher.CAB
O16 - DPF: Ustream Publisher - http://static.ustream.tv/plugin/3.1...._publisher.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite....x/qtplugin.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn...Detection2.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll
O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: scpVista - Scopus Tecnologia Ltda - C:\Program Files\Scpad\scpVista.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 13685 bytes
will77 está offline   Responder com Quote
Antigo 23-12-2009, 19:16   #4 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Olá will77


Faça o download do Ad-Remover
Dê duplo clique em AD-R.exe...
Aparecerá uma janela, clique então emSIM
Logo após, clique em Suivant para instalar
Ao término clique em Quitter
Um ícone no Desktop será criado...
Dê duplo clique em Ad Remover.exe e depois clique em Oui...
Tecle A e depois ENTER para fazer o scan...
O scan pode demorar, aguarde o processo terminar...
Um log será criado em C:\Ad-Report-SCAN.log
Copie e cole esse log aqui...


Aguardo


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 23-12-2009, 19:33   #5 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

Ta dando erro pra fazer o download.
will77 está offline   Responder com Quote
Antigo 23-12-2009, 22:16   #6 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Bem o link funciona.

mas tente esse então:

http://rapidshare.com/files/325081978/AD-R.exe.html

E siga com os procedimentos.


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 24-12-2009, 0:16   #7 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

cliquei em SIM, abre uma caixa C:\Administrador: AD-REMOVER C_XX e em seguida abre uma outra caixa dizendo "the user account is enable in this conditions, the program cannot continue...Please speak about this to the person who help you" e OK, clico em OK e nao prossegue...
will77 está offline   Responder com Quote
Antigo 24-12-2009, 1:34   #8 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Olá will77


Faça o download do ToolBar S&D e salve do Desktop
Reinicie o micro em Modo se Segurança...
Após isso, execute o aplicativo, tecle P depois Enter e depois em OK...
Logo depois, aperte a tecla 2 e depois Enter...
Aguarde o processo...
Depois que terminar será gerado um log em C:\ToolBar SD\TB_1.txt ...
Abra o documento copie e cole o resultado aqui...



T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 24-12-2009, 15:06   #9 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

Oi Diogo, nossos horarios estao diferente, pois to nos EUA 3 horas a menos dai...


-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft® Windows Vista™ Home Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Pentium(R) Dual-Core CPU T4200 @ 2.00GHz )
BIOS : Default System BIOS
USER : will ( Administrator )
BOOT : Fail-safe boot
C:\ (Local Disk) - NTFS - Total:287 Go (Free:209 Go)
D:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
E:\ (CD or DVD) - CDFS - Total:2 Go (Free:0 Go)
F:\ (USB) - FAT - Total:486 Mo (Free:0 Go)
"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( Thu 12/24/2009|10:33 )
[ UAC => 1 ]
-----------\\ REMOVIDOS
Deletado! - C:\Users\will\Desktop\BitLord.lnk
Deletado! - C:\Users\will\AppData\Roaming\MICROS~1\Windows\STA RTM~1\Programs\BitLord
Deletado! - C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Bit Lord
Deletado! - C:\Program Files\Bit Lord 1.1\BitLord.exe
Deletado! - C:\Program Files\Bit Lord 1.1\BitLord.url
Deletado! - C:\Program Files\Bit Lord 1.1\BitLord_Win9x.exe
Deletado! - C:\Program Files\Bit Lord 1.1\lang
Deletado! - C:\Program Files\Bit Lord 1.1\License.txt
Deletado! - C:\Program Files\Bit Lord 1.1\rules
Deletado! - C:\Program Files\Bit Lord 1.1\uninst.exe
Deletado! - C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
Deletado! - C:\Program Files\VVSN\URL2
Deletado! - C:\Program Files\VVSN\vvsn.cfg
Deletado! - C:\Program Files\Bit Lord 1.1
Deletado! - C:\Program Files\VVSN
-----------\\ Procura por Arquivos / Ficheiros ...

-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com.br/"
"Default_Page_URL"="http://ie.redirect.hp.com/svs/rdr?TY...lion &pf=cnnb"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68929"
"Url"="http://go.microsoft.com/fwlink/?LinkId=44406"
"Url"="http://go.microsoft.com/fwlink/?LinkId=68928"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://ie.redirect.hp.com/svs/rdr?TY...lion &pf=cnnb"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\Windows\\System32\\blank.htm"

--------------------\\ Procurando por outras infecções
--------------------\\ Cracks & Keygens ..
C:\Users\will\Desktop\Xilisoft_Video_Converter_Ult imate_5.1.26.0904_Portable\Xilisoft Video Converter Ultimate\%Personal%\Xilisoft Corporation\Video Converter Ultimate\crack.js
C:\Users\will\Favorites\Downloads em geral\CrackDB.com.url
C:\Users\will\Favorites\Downloads em geral\Ta de Gra‡a DateCrack + Crack.url

[ UAC => 1 ]

1 - "C:\ToolBar SD\TB_1.txt" - Thu 12/24/2009|10:34 - Option : [2]
-----------\\ Verificação completa em 10:34:57.66
will77 está offline   Responder com Quote
Antigo 24-12-2009, 22:30   #10 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Olá will77

Citação:
Oi Diogo, nossos horarios estao diferente, pois to nos EUA 3 horas a menos dai...
Heeheehe....

------------------------------------------------------------------

1.

Delete o arquivo ToolBarSd.exe que está no seu Desktop e delete a pasta que estará em C:\ToolBar SD

2.

Citação:
Clique em Iniciar > Painel de Controle > Contas de Usuários > Ativar ou Desativar Contas de Usuários > Confirme > Continuar > Desmarque "Utilizar o Controle de Conta de Usuário (UAC) para ajudar a proteger o computador" > OK > Confirme > Reinicie o PC
3.

Vamos tentar a ultima vez a utilização do Ad-Remover ok.

Citação:
Execute o AD-R.exe <--- Duplo clique em AD-R.exe...
Aparecerá uma janela, clique então emSIM
Logo após, clique em Suivant para instalar
Ao término clique em Quitter
Um ícone no Desktop será criado...
Dê duplo clique em Ad Remover.exe e depois clique em Oui...
Tecle A e depois ENTER para fazer o scan...
O scan pode demorar, aguarde o processo terminar...
Um log será criado em C:\Ad-Report-SCAN.log
Copie e cole esse log aqui...

Aguardo


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 25-12-2009, 21:55   #11 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

Desculpa a demora, festaaaaa....

.
======= LOGFILE OF AD-REMOVER 1.1.4.5_Y | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 11.10.2009 at 13:06
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 18:39:15, Fri 12/25/2009 | Normal Boot | Option: SCAN
Executed from: C:\Program Files\Ad-Remover\
Operating system: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
Computer Name: Will-PC | Current user: Will
.
============== FOUND ELEMENT(S) ==============
.
HKCU\Software\AppDataLow\Software\Dealio
HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uni nstall\{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
HKU\S-1-5-21-2205956746-275866889-86147075-1000\Software\Appdatalow\Software\Dealio
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
.
C:\Users\Will\AppData\LocalLow\Dealio
C:\Users\Will\AppData\LocalLow\Search Settings
C:\Program Files\Dealio Toolbar
C:\Program Files\Mozilla FireFox\Components\AskSearch.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
C:\Windows\Installer\31218b.msi
C:\Users\Will\AppData\Roaming\MICROS~1\Windows\Coo kies\Will@cfg.crawler[2].txt
C:\Users\Will\AppData\Roaming\MICROS~1\Windows\Coo kies\Will@crawler[2].txt
.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.5.6 [pt-BR] *
.
ProfilePath: hfliptg5.default (Will)
.
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.com.br");
(Prefs.js) user_pref("browser.startup.homepage_override.mston e", "rv:1.9.1.6");
.
.
* Internet Explorer Version 8.0.6001.18865 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page: hxxp://www.google.com.br/
Default_Page_URL: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion &pf=cnnb
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Start Page: hxxp://www.msn.com/
Default_Page_URL: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion &pf=cnnb
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Users\Will\Favorites\SerialBay.url
C:\Users\Will\Favorites\Downloads em geral\CrackDB.com.url
C:\Users\Will\Favorites\Downloads em geral\Ta de Gra‡a DateCrack + Crack.url
.
===================================
.
2988 Byte(s) - C:\Ad-Report-SCAN[1].log
.
643 File(s) - C:\Users\Will\AppData\Local\Temp
47 File(s) - C:\Windows\Temp
.
1 File(s) - C:\Program Files\Ad-Remover\BACKUP
0 File(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
End at: 18:45:09 | Fri 12/25/2009 - SCAN[1]
.
============== E.O.F ==============
.
will77 está offline   Responder com Quote
Antigo 26-12-2009, 0:33   #12 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Olá will77


1.

Execute o Ad Remover...
Logo após, tecle --> L <--e depois ENTER <------------
Durante o processo de remoção será perguntado se deseja remover, Tecle [O]
Será gerado um Log em C:\Ad-Report-CLEAN.log
Copie e cole esse log aqui...

2.

Citação:
C:\Users\will\Desktop\Xilisoft_Video_Converter_Ult imate_5.1.26.0904_Portable\Xilisoft Video Converter Ultimate\%Personal%\Xilisoft Corporation\Video Converter Ultimate\crack.js
C:\Users\will\Favorites\Downloads em geral\CrackDB.com.url
C:\Users\will\Favorites\Downloads em geral\Ta de Gra‡a DateCrack + Crack.url
C:\Users\Will\Favorites\SerialBay.url
C:\Users\Will\Favorites\Downloads em geral\CrackDB.com.url
C:\Users\Will\Favorites\Downloads em geral\Ta de Gra‡a DateCrack + Crack.url
Foram detectados, Cracks ou Keygens em seu pc, é importante a remoção dos mesmos, pois muitos desses aplicativos carregam malware sem a percebição do usuário, portante eles, podem ser a fonte de contaminação.


3.

Faça o download do Dr.WebCureit e salve-o no desktop
Duplo clique em launch.exe
Clique em [Opções] e altere o idioma para "Português"
Selecione a opção [Verificação completa] e clique na seta para iniciar o scan
Ao término, clique em [Ficheiro] e selecione a opção [Guardar lista de relatórios] e salve-o no desktop
Cole o relatório criado


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 26-12-2009, 1:10   #13 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

.
======= LOGFILE OF AD-REMOVER 1.1.4.5_Y | ONLY XP/VISTA/7 =======
.
Updated by C_XX on 11.10.2009 at 13:06
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launch at: 21:48:40, Fri 12/25/2009 | Normal Boot | Option: CLEAN
Executed from: C:\Program Files\Ad-Remover\
Operating system: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
Computer Name: will-PC | Current user: will
.
============== NEUTRALIZED ELEMENT(S) ==============
.
HKCU\Software\AppDataLow\Software\Dealio
HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uni nstall\{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
.
C:\Users\will\AppData\LocalLow\Dealio\res
C:\Users\will\AppData\LocalLow\Dealio\temp
C:\Users\will\AppData\LocalLow\Dealio\temp\http___ www_dealio_com_rss_coupons-deals_dotd_.xml
C:\Users\will\AppData\LocalLow\Dealio\temp\WTFF-14604.log
C:\Users\will\AppData\LocalLow\Dealio
C:\Users\will\AppData\LocalLow\Search Settings\kb128
C:\Users\will\AppData\LocalLow\Search Settings\kb128\temp
C:\Users\will\AppData\LocalLow\Search Settings\kb128\temp\ws-14598.log
C:\Users\will\AppData\LocalLow\Search Settings\kb128\temp\ws-14600.log
C:\Users\will\AppData\LocalLow\Search Settings
C:\Program Files\Dealio Toolbar\config.ini
C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
C:\Program Files\Dealio Toolbar\Res
C:\Program Files\Dealio Toolbar\SearchSettings.dll
C:\Program Files\Dealio Toolbar\SearchSettings.exe
C:\Program Files\Dealio Toolbar\SearchSettingsRes409.dll
C:\Program Files\Dealio Toolbar\sscfg.ini
C:\Program Files\Dealio Toolbar\WidgiHelper.exe
C:\Program Files\Dealio Toolbar\Res\amazon.gif
C:\Program Files\Dealio Toolbar\Res\apple.gif
C:\Program Files\Dealio Toolbar\Res\barnes.gif
C:\Program Files\Dealio Toolbar\Res\bestbuy.gif
C:\Program Files\Dealio Toolbar\Res\dealio_logo.gif
C:\Program Files\Dealio Toolbar\Res\dealio_logo_hover.gif
C:\Program Files\Dealio Toolbar\Res\ebay.gif
C:\Program Files\Dealio Toolbar\Res\icon_settings.gif
C:\Program Files\Dealio Toolbar\Res\macys.gif
C:\Program Files\Dealio Toolbar\Res\newegg.gif
C:\Program Files\Dealio Toolbar\Res\overstock.gif
C:\Program Files\Dealio Toolbar\Res\search-button-hover.gif
C:\Program Files\Dealio Toolbar\Res\search-button.gif
C:\Program Files\Dealio Toolbar\Res\search-chevron-hover.gif
C:\Program Files\Dealio Toolbar\Res\search-chevron.gif
C:\Program Files\Dealio Toolbar\Res\search_amazon.gif
C:\Program Files\Dealio Toolbar\Res\search_dealio.gif
C:\Program Files\Dealio Toolbar\Res\search_ebay.gif
C:\Program Files\Dealio Toolbar\Res\search_yahoo.gif
C:\Program Files\Dealio Toolbar\Res\separator.gif
C:\Program Files\Dealio Toolbar\Res\target.gif
C:\Program Files\Dealio Toolbar\Res\walmart.gif
C:\Program Files\Dealio Toolbar\Res\widgets.xml
C:\Program Files\Dealio Toolbar
C:\Program Files\Mozilla FireFox\Components\AskSearch.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome.manifest
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\install.rdf
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\chevron.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\chevron.xul
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\login.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\login.xul
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\parser.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\RssTickerWidget.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\searchbox.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\searchbox.xul
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgichevron.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgicomm.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgihandling.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgilisteners.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgitoolbarplugin.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgitoolbarplugin.xu l
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\content\widgiui.js
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale\EN-US
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale\EN-US\searchbox.dtd
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale\EN-US\widgitoolbarplugin.dtd
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale\EN-US\widgitoolbarplugin.properties
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\locale\EN-US\yahoo-search.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\amazon.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\apple.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\barnes.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\bestbuy.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\chevron.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\dealio_logo.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\dealio_logo_hover.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\ebay.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\icon_settings.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\macys.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\newegg.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\overstock.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search-button-hover.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search-button.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search-chevron-hover.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search-chevron.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\searchbox.css
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search_amazon.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search_dealio.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search_ebay.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\search_yahoo.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\separator.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\target.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\walmart.gif
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\chrome\skin\widgitoolbarplugin.css
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\config.ini
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\IFBHOHelperWidgiToolbar.x pt
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\IFBHOWidgiToolbar.xpt
C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
C:\Windows\Installer\31218b.msi
C:\Users\will\AppData\Roaming\MICROS~1\Windows\Coo kies\will@cfg.crawler[2].txt
C:\Users\will\AppData\Roaming\MICROS~1\Windows\Coo kies\will@crawler[2].txt

(!) -- Temp files deleted.

.
============== Added scan ==============
.
.
* Mozilla FireFox Version 3.5.6 [pt-BR] *
.
ProfilePath: hfliptg5.default (will)
.
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.com.br");
(Prefs.js) user_pref("browser.startup.homepage_override.mston e", "rv:1.9.1.6");
.
.
* Internet Explorer Version 8.0.6001.18865 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page: hxxp://fr.msn.com/
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Start Page: hxxp://fr.msn.com/
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Users\will\Favorites\SerialBay.url
C:\Users\will\Favorites\Downloads em geral\CrackDB.com.url
C:\Users\will\Favorites\Downloads em geral\Ta de Gra‡a DateCrack + Crack.url
.
===================================
.
11526 Byte(s) - C:\Ad-Report-CLEAN[1].log
3284 Byte(s) - C:\Ad-Report-SCAN[1].log
.
16 File(s) - C:\Users\will\AppData\Local\Temp
0 File(s) - C:\Windows\Temp
.
20 File(s) - C:\Program Files\Ad-Remover\BACKUP
42 File(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
End at: 21:54:19 | Fri 12/25/2009 - CLEAN[1]
.
============== E.O.F ==============
.

Última edição por will77 : 26-12-2009 às 2:16.
will77 está offline   Responder com Quote
Antigo 26-12-2009, 15:44   #14 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Ok.

1.

Execute o Ad Remover
Clique em Oui
Tecle D depois ENTER


2.

Faça os procedimentos do Dr. Web Curent

Citação:
Faça o download do Dr.WebCureit e salve-o no desktop
Duplo clique em launch.exe
Clique em [Opções] e altere o idioma para "Português"
Selecione a opção [Verificação completa] e clique na seta para iniciar o scan
Ao término, clique em [Ficheiro] e selecione a opção [Guardar lista de relatórios] e salve-o no desktop
Cole o relatório criado

Aguardo



T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 26-12-2009, 15:49   #15 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

Fiz todo processo no Launch, detectou e removeu 6 virus e toda hora abria o Antivir tb achando virus e eu jogava pra quarentena, no final do processo fiz com vc falou mais nao salvou o relatorio nao e o problemas continuam, so houve uma alteraçao, no FIREFOX nao abre mais a caixa A PROGRAM NEEDS PERMISSION TO CONTINUE >>> IF YOU STARTET THIS PROGRAM, CONTINUE >>> JAVA(TM) SE RUMTIME ENVIRONMENT 6 UPDATE 17 SUM MICROSYSTEMS INC. >>> C:\PROGRAM FILE\JAVA\JRE6\BIN\JQSNOTFLY.EXE... agora entra direto outro site na barrinha abaixo da tela e no IE 8 os problemas continuam os mesmos, nesse momento estou passando o Launch novamente e ja detectou e removeu 2 virus...
will77 está offline   Responder com Quote
Antigo 26-12-2009, 15:58   #16 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Ok.


Ao final do procedimento poste o LOG!


Caso ainda não ache, siga com um novo procedimento abaixo:

Faça o download do ComboFix


Desative temporariamente o seu antivirus
Dê um duplo clique no ícone combofix.exe para iniciar o scaniamento...
Aceita o contrato para continuar....
Tecle 1 e logo após, tecle Enter...
Irá abrir uma janela do Console de Recuperação, clique em Sim, se aparecer outra janela, clique em OK, e depois em Sim...
Aguarde o ComboFix com seu scan...
Se ocorrer algum problema durante o scan, reinicie o micro em Modo de Segurança e faça novamente o processo...
Não utilize nem o mouse nem o teclado...se isso acontecer seu desktop ficará branco...
Caso queira sair ou cancelar o ComboFix, tecle N;
Quando terminar, o computador será reiniciado, após isso, a ferramenta executará novamente, então aguarde...
Será gerado um log em C:\ComboFix.txt ...
Cole este log em sua próxima resposta...

Aguardo seu poste...


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 26-12-2009, 16:46   #17 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

ComboFix 09-12-25.05 - will 12/26/2009 13:23:48.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1948 [GMT -6:00]
Running from: c:\users\will\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2205956746-275866889-86147075-500
c:\$recycle.bin\S-1-5-21-2819002435-850761837-2018973860-500
c:\program files\Web Search Operator\4.1.0.2080\wso.dll------
.
((((((((((((((((((((((((( Files Created from 2009-11-26 to 2009-12-26 )))))))))))))))))))))))))))))))
.
2009-12-26 19:29 . 2009-12-26 19:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-26 15:33 . 2009-12-26 15:33 -------- d-----w- c:\users\will\AppData\Roaming\Template
2009-12-26 04:13 . 2009-12-26 05:52 -------- d-----w- c:\users\will\DoctorWeb
2009-12-26 00:36 . 2009-12-26 00:36 -------- d-----w- c:\users\will\AppData\Local\Textual Content Provider
2009-12-26 00:35 . 2009-12-26 00:35 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-25 04:00 . 2009-12-25 04:00 658184 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlig ht\MCESpotlight\SpotlightResources.dll
2009-12-24 03:24 . 2009-12-26 03:54 -------- d-----w- c:\program files\Ad-Remover
2009-12-21 20:31 . 2009-12-22 17:17 -------- d-----w- c:\program files\Zeallsoft
2009-12-21 19:53 . 2009-12-22 17:11 -------- d-----w- c:\program files\ZD Soft
2009-12-20 05:39 . 2009-06-30 15:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-12-20 05:36 . 2009-12-20 05:36 -------- d-----w- c:\program files\Panda Security
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\programdata\QuestService
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\QuestService
2009-12-19 15:01 . 2009-12-09 13:00 58744 ----a-w- c:\programdata\QuestService\questservice110.exe
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Textual Content Provider
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Content Management Wizard
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\users\will\AppData\Local\Internet Today
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Internet Today
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Customized Platform Advancer
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Automated Content Enhancer
2009-12-19 15:01 . 2009-12-19 15:01 -------- d-----w- c:\program files\Web Search Operator
2009-12-19 15:01 . 2009-12-19 18:52 -------- d-----w- c:\program files\HottieStar Toolbar
2009-12-11 01:43 . 2008-10-02 21:58 2014208 ----a-w- c:\users\will\AppData\Roaming\Mozilla\Firefox\Prof iles\hfliptg5.default\extensions\ustreampublisher@ ustream.tv\platform\WINNT_x86-msvc\plugins\npustreampublisher.dll
2009-12-09 09:02 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-09 09:02 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 09:02 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-05 18:30 . 2009-12-05 18:30 -------- d-----w- c:\users\will\AppData\Roaming\Xilisoft Corporation
2009-12-05 17:19 . 2009-12-05 17:19 -------- d-----w- c:\programdata\Apple Computer
2009-12-03 16:48 . 2009-12-03 16:48 680 ----a-w- c:\users\will\AppData\Local\d3d9caps.dat
2009-11-30 22:58 . 2009-12-22 17:38 -------- d-----w- c:\programdata\boost_interprocess
2009-11-30 22:58 . 2009-12-22 17:35 -------- d-----w- c:\users\will\AppData\Roaming\Multi File Downloader
2009-11-30 07:42 . 2009-12-21 01:02 -------- d-----w- c:\users\will\AppData\Local\The Weather Channel
2009-11-28 09:18 . 2009-11-28 09:18 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-28 09:01 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-27 04:46 . 2009-11-27 04:46 -------- d-----w- c:\windows\system32\ca-ES
2009-11-27 04:46 . 2009-11-27 04:46 -------- d-----w- c:\windows\system32\eu-ES
2009-11-27 04:46 . 2009-11-27 04:46 -------- d-----w- c:\windows\system32\vi-VN
2009-11-27 04:33 . 2009-11-27 04:33 -------- d-----w- c:\windows\system32\EventProviders
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-12-26 19:15 . 2009-09-22 01:45 -------- d-----w- c:\users\will\AppData\Roaming\Skype
2009-12-26 19:15 . 2009-05-09 07:04 -------- d-----w- c:\users\will\AppData\Roaming\Orbit
2009-12-26 19:15 . 2009-09-22 01:52 -------- d-----w- c:\users\will\AppData\Roaming\skypePM
2009-12-26 15:33 . 2009-12-26 15:33 0 ----a-w- c:\users\will\AppData\Roaming\wklnhst.dat
2009-12-21 19:24 . 2009-05-02 04:43 75264 ----a-w- c:\users\will\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-21 01:55 . 2008-10-23 09:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-21 01:11 . 2008-10-23 09:57 -------- d-----w- c:\programdata\WildTangent
2009-12-21 01:11 . 2008-10-23 09:57 -------- d-----w- c:\program files\HP Games
2009-12-21 00:57 . 2009-05-17 18:03 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-21 00:40 . 2009-05-15 17:22 -------- d-----w- c:\users\will\AppData\Roaming\vlc
2009-12-21 00:40 . 2009-09-22 01:45 -------- d-----w- c:\program files\Common Files\Skype
2009-12-21 00:40 . 2008-10-23 10:25 -------- d-----w- c:\program files\Microsoft Works
2009-12-20 20:10 . 2008-10-23 10:53 -------- d-----w- c:\program files\Java
2009-12-19 19:00 . 2008-10-23 10:43 -------- d-----w- c:\program files\CyberLink
2009-12-09 09:19 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-09 09:02 . 2008-10-23 10:38 -------- d-----w- c:\programdata\Microsoft Help
2009-12-07 16:30 . 2009-05-08 15:21 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-28 09:18 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-28 09:18 . 2009-11-28 09:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_ 07_00.Wdf
2009-11-28 09:18 . 2009-11-28 09:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_ 00.Wdf
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-11-27 04:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-11-26 13:19 . 2009-11-26 13:19 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb3394.tmp.exe
2009-11-24 20:35 . 2009-07-08 10:17 -------- d-----w- c:\users\will\AppData\Roaming\gtk-2.0
2009-11-23 02:28 . 2009-11-23 01:57 -------- d-----w- c:\users\will\AppData\Roaming\Photo DVD Slideshow
2009-11-23 01:57 . 2009-11-23 01:57 -------- d-----w- c:\programdata\Anvsoft
2009-11-21 06:40 . 2009-12-08 23:49 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-08 23:49 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-08 23:49 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-08 23:49 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-14 17:39 . 2009-05-24 17:21 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-11-14 17:39 . 2009-05-24 17:21 -------- d-----w- c:\program files\DVDVideoSoft
2009-11-03 02:42 . 2009-10-27 02:02 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 01:23 . 2009-10-30 17:10 -------- d-----w- c:\users\will\AppData\Roaming\dvdcss
2009-10-29 09:17 . 2009-11-26 09:01 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-28 03:49 . 2009-10-28 03:49 -------- d-----w- c:\program files\Panopreter
2009-10-20 02:30 . 2009-10-20 02:30 3584 ----a-r- c:\users\will\AppData\Roaming\Microsoft\Installer\ {121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-10-08 21:08 . 2009-11-28 09:01 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-28 09:01 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-28 09:01 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-07 11:36 . 2009-12-08 23:49 243712 ----a-w- c:\windows\system32\rastls.dll
2009-10-01 01:02 . 2009-11-28 09:01 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-28 09:01 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-28 09:01 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-28 09:01 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-28 09:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-28 09:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-28 09:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-28 09:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-28 09:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-28 09:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.d ll
2009-10-01 01:01 . 2009-11-28 09:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-11-28 09:01 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-11-28 09:01 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-11-28 09:01 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-11-28 09:01 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-29 02:45 . 2009-09-29 02:18 81920 ----a-w- c:\users\will\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\acaddin\connecthook.dll
2009-09-29 02:45 . 2009-09-29 02:18 190976 ----a-w- c:\users\will\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\acaddin\connectsprd.dll
2009-09-29 02:18 . 2009-09-29 02:18 4183224 ----a-w- c:\users\will\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\acaddin\acaddin.exe
2008-10-23 10:05 . 2008-10-23 09:55 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Update"="c:\users\will\AppData\Local\Google\Update \GoogleUpdate.exe" [2009-09-17 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2009-09-19 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-10 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-10 170520]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2008-07-10 145944]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMen u.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-19 122368]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-21 149280]
"Super Screen Capture"="c:\program files\Zeallsoft\Super Screen Capture\SSCapture.exe" [2007-03-09 3025920]
c:\users\will\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-5-9 1719496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 22:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
2009-03-02 17:08 209153 ----a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 14:58 75008 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2008-09-30 23:56 972080 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 17:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-08-01 23:14 202032 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2008-09-24 00:21 468264 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-04-17 18:05 1049896 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-06-14 01:11 210216 ------w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu. exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-06-14 01:11 210216 ------w- c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStart Menu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):4b,8f,12,75,1d,6f,ca,01
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboo t.sys [12/19/2009 11:39 PM 28552]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/8/2009 9:21 AM 108289]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [10/23/2008 4:56 AM 365952]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [6/29/2008 8:52 AM 112128]
S2 scpVista;scpVista;c:\program files\Scpad\scpVista.exe [5/11/2009 9:30 AM 136448]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [10/23/2008 3:55 AM 193840]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:23 PM 21504]
S3 vgadrv;vgadrv;c:\windows\System32\drivers\vgadrv.s ys [6/10/2006 3:41 AM 8078]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.br/
mWindow Title =
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6 097707281E79.dll/cmsidewiki.html
DPF: Justin.tv Publisher - hxxp://pt-br.justin.tv/plugins/justintv_publisher.CAB
DPF: Ustream Publisher - hxxp://static.ustream.tv/plugin/3.1.5.2/ustream_publisher.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\users\will\AppData\Roaming\Mozilla\Firefox\Prof iles\hfliptg5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br
FF - component: c:\program files\Automated Content Enhancer\4.1.0.5290\FF\components\ACEFFAddOn.dll
FF - component: c:\program files\Customized Platform Advancer\4.1.0.1960\FF\components\CPAFFAddOn.dll
FF - component: c:\program files\Web Search Operator\4.1.0.2080\FF\components\WSOFFAddOn.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\will\AppData\Local\Google\Update\1.2.183. 13\npGoogleOneClick8.dll
FF - plugin: c:\users\will\AppData\Roaming\Mozilla\Firefox\Prof iles\hfliptg5.default\extensions\ustreampublisher@ ustream.tv\platform\WINNT_x86-msvc\plugins\npustreampublisher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.
- - - - ORPHANS REMOVED - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKLM-Run-Internet Today Task - c:\program files\Internet Today\1.1.0.1260\InternetToday.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_07\bin\jusched.exe
MSConfigStartUp-VVSN - c:\program files\VVSN\VVSN.exe

************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-26 13:31
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(660)
c:\program files\Scpad\scpLIB.dll
c:\program files\Scpad\scpMIB.dll
c:\program files\Scpad\sshib.dll
.
Completion time: 2009-12-26 13:33:12
ComboFix-quarantined-files.txt 2009-12-26 19:33
Pre-Run: 222,950,760,448 bytes free
Post-Run: 222,931,730,432 bytes free
- - End Of File - - F6195F7DBC8735B125AE01F6A92956B6
will77 está offline   Responder com Quote
Antigo 26-12-2009, 18:30   #18 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

No IE parece q ta resolvido, pois consigo logar no Orkut e outros sites q precisa logar, mais o Firefox continua abrindo paginas desenfreadamente,,,,rssss
will77 está offline   Responder com Quote
Antigo 27-12-2009, 11:47   #19 (permalink)
Diogo R.
Zumbi
 
Avatar de Diogo R.
 
Registrado em: Jul 2008
Localização: Brasil; MG; Região Metropolitana de BH
Idade: 4
Mensagens: 6.508
Reputação: 3732 Diogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputaçãoDiogo R. tem uma fabulosa reputação
Enviar mensagem via MSN para Diogo R.
Padrão

Ok.

Baixe o Malwarebytes Anti-Malware


Inicie a instalação clicando em "mbam-setup.exe"...
Marque "Atualizar Malwarebytes Anti-Malware" e clique em concluir...
Execute o programa MalwareBytes Anti Malware...
Clique na aba: "Verificação", selecione a opção "Verificação completa"....
Clique então em "Verificar"...
Selecione tudo que deseja escanear.....
Clique então em "Verificar"....
Quando o scan terminar, clique em Ok e em "Mostrar Resultados" para ver o log...
Se algo for detectado, veja se tudo está marcado e clique em "Remover"....
Se perguntar se você deseja remover objetos da memória, clica em Sim...
O log é automaticamente gravado e pode ser consultado clicando em "Logs" do menu principal...
Copie e cole esse log aqui...

Aguardo seu poste...


T+
__________________

Visite nosso FAQ










Diogo R. está offline   Responder com Quote
Antigo 27-12-2009, 21:00   #20 (permalink)
will77
Newbie
 
Registrado em: Jan 2008
Mensagens: 45
Reputação: 0 will77 está indo no caminho certo
Padrão

Diogo, Resolvido...
Fiz varios testes com o Firefox e nenhum site abriu sem que eu tivesse
solicitado, antes era uma verdadeira baderna...
Te agradeço a paciencia, me ajudou mto...
Muito Obrigado, e aproveito pra te desejar um Feliz 2010, td de bom pra vc e pra sua familia...
Mais uma vez, muito obrigado...
Segue ai o Log...

Malwarebytes' Anti-Malware 1.42
Versão do banco de dados: 3441
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865
12/27/2009 3:15:25 PM
mbam-log-2009-12-27 (15-15-25).txt
Tipo de Verificação: Completa (C:\|)
Objetos verificados: 259240
Tempo decorrido: 48 minute(s), 35 second(s)
Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 14
Valores do Registro infectados: 3
Ítens do Registro infectados: 0
Pastas infectadas: 35
Arquivos infectados: 73
Processos da Memória infectados:
(Nenhum ítem malicioso foi detectado)
Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)
Chaves do Registro infectadas:
HKEY_CLASSES_ROOT\Interface\{6160f76a-1992-4b17-a32d-0c706d159105} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3de88beb-f271-484a-ba71-01d30f439f0c} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{50ad41d2-b1f0-47cc-9ea7-395355eaeebd} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8ceb185e-81a5-46d3-bc20-c555d605afbd} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a72522ba-9ff3-4c83-abc6-9b476728a396} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5762628-ae15-4ca6-96c4-b00dd17f3419} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d062e03e-65ca-49e4-9b15-31938ba98922} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Explorer\Bars \{cac89ff9-34a9-4431-8cfe-292a47f843bc} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Explorer\Bars \{b72681c0-a222-4b21-a0e2-53a5a5ca3d411} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\{D45817B8-3EAD-4d1d-8FCA-EC63A8E35DE2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AppDataLow\SOFTWARE\In ternet Today (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\QuestService (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Web Search Operator (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Media Access Startup (Adware.DoubleD) -> Quarantined and deleted successfully.
Valores do Registro infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extens ions\{8141440e-08f0-4339-9959-5c31c6a69f23} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extens ions\{e63605fc-d583-4c81-867f-9457bdb3ea1b} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extens ions\{e889f097-b0be-471b-89ad-b86b6f04b506} (Adware.DoubleD) -> Quarantined and deleted successfully.
Ítens do Registro infectados:
(Nenhum ítem malicioso foi detectado)
Pastas infectadas:
C:\Program Files\Internet Today (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\Data (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome\content (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\components (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\Data (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome\content (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\components (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\Data (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome\content (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\components (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990 (Adware.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\QuestService (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\QuestService (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Program Files\HottieStar Toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Internet Today (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810 (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
Arquivos infectados:
C:\Program Files\Internet Today\1.1.0.1260\InternetToday.ico (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\InternetToday.skf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\mfc80.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\Microsoft.VC80.MFC.manifest (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\SkinCrafterDll.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Today\1.1.0.1260\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\lri.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\WSO.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\WSOCommon.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\Data\config.md (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome.manifest (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\install.rdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome\WSOAddOn.jar (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome\content\WSOAddOn.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\chrome\content\WSOAddOn.xul (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\components\WSOFFAddOn.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\components\WSOFFAddOn.xpt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Web Search Operator\4.1.0.2080\FF\components\WSOFFHelperCompo nent.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\TCPIE.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\pxtmpdata.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\TP_Config.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\TP_Data.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\TP_DomainExcludeList.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\TP_DomainInterval.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Textual Content Provider\1.1.0.1810\data\TP_KeywordInterval.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\ACECommon.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\ACEIEAddOn.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\lri.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\Data\config.md (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome.manifest (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\install.rdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome\ACEAddOn.jar (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome\content\ACEAddOn.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\chrome\content\ACEAddOn.xul (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\components\ACEFFAddOn.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\components\ACEFFAddOn.xpt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Automated Content Enhancer\4.1.0.5290\FF\components\ACEFFHelperCompo nent.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPACommon.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\CPAIEAddOn.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\lri.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\Data\config.md (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome.manifest (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\install.rdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome\CPAAddOn.jar (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome\content\CPAAddOn.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\chrome\content\CPAAddOn.xul (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\components\CPAFFAddOn.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\components\CPAFFAddOn.xpt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Customized Platform Advancer\4.1.0.1960\FF\components\CPAFFHelperCompo nent.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\CMWIE.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\cmwsh.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\config.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\data.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\exclude.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\LRI.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\MatchingData.zd5 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\pxtmpdata.mx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\unins000.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Content Management Wizard\1.1.0.1990\unins000.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\ProgramData\QuestService\questservice110.exe (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810\Data\TP_Config.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810\Data\TP_Data.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810\Data\TP_DomainExcludeList.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
C:\Users\will\Local Settings\Application Data\Textual Content Provider\1.1.0.1810\Data\TP_DomainInterval.mx (Adware.DoubleD) -> Quarantined and deleted successfully.

Última edição por will77 : 27-12-2009 às 21:16.
will77 está offline   Responder com Quote
Resposta


Opções do Tópico

Regras de Mensagens
Você não pode criar tópicos
Você não pode postar respostas
Você não pode anexar arquivos
Você não pode editar suas mensagens

Código vB está Ligado
Smiles estão Ligado
Código [IMG] está Ligado
Código HTML está Desligado
Ir para...


Horários baseados na GMT -3. Agora são 3:22.