Fórum SecSecurity

Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Fórum SecSecurity

Implementando Limpeza e Seguranca em seu computador!

Palavras-chaves

Últimos assuntos

» OpenTip (...by Kaspersky.com)
Pc infectado, pop up de propaganda aparecendo. EmptySáb Mar 23, 2024 10:28 am por joram

» KpRm ( ... by Kernel-panik )
Pc infectado, pop up de propaganda aparecendo. EmptyTer Ago 11, 2020 9:47 pm por joram

» ESET Rogue Applications Remover ( ... by Eset.com )
Pc infectado, pop up de propaganda aparecendo. EmptySáb Ago 01, 2020 7:49 am por joram

» PW Clean 2.7 ( ... by Doutor PW )
Pc infectado, pop up de propaganda aparecendo. EmptyTer maio 15, 2018 9:27 am por joram

» CKScanner ( ... by askey127 )
Pc infectado, pop up de propaganda aparecendo. EmptySáb maio 05, 2018 1:12 pm por joram

» AdwCleaner ( ... by XPlode )
Pc infectado, pop up de propaganda aparecendo. EmptySeg Abr 16, 2018 8:47 am por joram

» ZHPDiag ( ... de Nicolas Coolman )
Pc infectado, pop up de propaganda aparecendo. EmptySáb Abr 14, 2018 8:56 am por joram

» Argente - Registry Cleaner ( ... by Argente Software )
Pc infectado, pop up de propaganda aparecendo. EmptyDom Nov 19, 2017 4:36 pm por joram

» ListChkdskResult ( ... by SleepyDude )
Pc infectado, pop up de propaganda aparecendo. EmptyDom Set 24, 2017 1:39 pm por joram

abril 2024

SegTerQuaQuiSexSábDom
1234567
891011121314
15161718192021
22232425262728
2930     

Calendário Calendário

Parceiros

Fórum grátis

Os membros mais mencionados

Nenhum usuário

2 participantes

    Pc infectado, pop up de propaganda aparecendo.

    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 43
    Localização : Natal/RN

    Pc infectado, pop up de propaganda aparecendo. Empty Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan Qui Jul 11, 2013 10:03 pm

    Log para analise [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

     Passei no pc ontem essas ferramentas logo abaixo:

    # AdwCleaner v2.304 - Relatório criado em 10/07/2013 às 16:30:54
    # Atualizado em 03/07/2013 por Xplode
    # Sistema Operacional : Microsoft Windows XP Service Pack 3 (32 bits)
    # Usuário : f000847 - FUN0066
    # Modo de Boot : Normal
    # Executado de : C:\Documents and Settings\f000847\Meus documentos\Downloads\adwcleaner.exe
    # Opção [Remover]


    ***** [Serviços] *****


    ***** [Arquivos/Pastas] *****

    Arquivo Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\HelperFramework@ZoneMedia.com.xpi
    Arquivo Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\searchplugins\Babylon.xml
    Pasta Removido : C:\Documents and Settings\All Users\Dados de aplicativos\Babylon
    Pasta Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Babylon
    Removido Durante o reboot : C:\Documents and Settings\All Users\Dados de aplicativos\BrowserDefender

    ***** [Registro] *****

    Chave Removida : HKCU\Software\BabSolution
    Chave Removida : HKCU\Software\DataMngr
    Chave Removida : HKCU\Software\DataMngr_Toolbar
    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
    Chave Removida : HKLM\SOFTWARE\5c55dcdce26dea48
    Chave Removida : HKLM\Software\Babylon
    Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
    Chave Removida : HKLM\SOFTWARE\Classes\Prod.cap
    Chave Removida : HKLM\Software\DataMngr
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PricePeep

    ***** [Navegadores] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registro está limpo.

    -\\ Mozilla Firefox v21.0 (pt-BR)

    Arquivo : C:\Documents and Settings\Fun0131\Dados de aplicativos\Mozilla\Firefox\Profiles\z4e8s4wm.default\prefs.js

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\itaqxty1.default\prefs.js

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\prefs.js

    C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\user.js ... Removido !

    Removida : user_pref("extensions.BabylonToolbar.admin", false);
    Removida : user_pref("extensions.BabylonToolbar.aflt", "babsst");
    Removida : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
    Removida : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
    Removida : user_pref("extensions.BabylonToolbar.dfltLng", "en");
    Removida : user_pref("extensions.BabylonToolbar.excTlbr", false);
    Removida : user_pref("extensions.BabylonToolbar.ffxUnstlRst", true);
    Removida : user_pref("extensions.BabylonToolbar.id", "7c25fa6900000000000014dae96ecb3d");
    Removida : user_pref("extensions.BabylonToolbar.instlDay", "15874");
    Removida : user_pref("extensions.BabylonToolbar.instlRef", "sst");
    Removida : user_pref("extensions.BabylonToolbar.newTab", false);
    Removida : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
    Removida : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
    Removida : user_pref("extensions.BabylonToolbar.rvrt", "false");
    Removida : user_pref("extensions.BabylonToolbar.smplGrp", "none");
    Removida : user_pref("extensions.BabylonToolbar.tlbrId", "base");
    Removida : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]
    Removida : user_pref("extensions.BabylonToolbar.vrsn", "1.8.11.10");
    Removida : user_pref("extensions.BabylonToolbar.vrsni", "1.8.11.10");
    Removida : user_pref("extensions.BabylonToolbar.vrsnTs", "1.8.11.108:37:58");
    Removida : user_pref("extensions.BabylonToolbar_i.babExt", "");
    Removida : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=122793");
    Removida : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");

    -\\ Google Chrome v27.0.1453.116

    Arquivo : C:\Documents and Settings\f000847\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

    [OK] Arquivo está limpo.

    *************************

    AdwCleaner[S1].txt - [4573 octets] - [10/07/2013 16:30:54]

    ########## EOF - C:\AdwCleaner[S1].txt - [4633 octets] ##########




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 4.9.2 (04.29.2013:1)
    OS: Microsoft Windows XP x86
    Ran by f000847 on 10/07/2013 at 16:33:31,87
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



    ~~~ Registry Keys



    ~~~ Files

    Successfully deleted: [File] C:\WINDOWS\prefetch\BABYLONTOOLBARSRV.EXE-289CB403.pf



    ~~~ Folders





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 10/07/2013 at 16:36:13,03
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 43
    Localização : Natal/RN

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan Qui Jul 11, 2013 10:05 pm

     Continuação:

    ComboFix 13-07-09.01 - f000847 10/07/2013  16:48:18.1.2 - x86
    Microsoft Windows XP Professional  5.1.2600.3.1252.55.1046.18.2013.1545 [GMT -3:00]
    Executando de: c:\documents and settings\f000847\Desktop\Ferramentas para remoção de virus\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ADS - system32: deleted 2 bytes in 1 streams.
    ADS - drivers: deleted 412 bytes in 1 streams.
    .
    (((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Dados de aplicativos\TEMP
    .
    .
    ((((((((((((((((   Arquivos/Ficheiros criados de 2013-06-10 to 2013-07-10  ))))))))))))))))))))))))))))
    .
    .
    2013-07-10 19:44 . 2013-07-10 19:44 512 ----a-w- C:\PhysicalDisk0_MBR.bin
    2013-07-10 19:42 . 2013-07-10 19:44 -------- d-----w- C:\ZHP
    2013-07-10 19:42 . 2013-07-10 19:44 -------- d-----w- c:\arquivos de programas\ZHPDiag
    2013-07-10 19:41 . 2013-07-10 19:41 144896 ----a-w- c:\windows\system32\javacpl.cpl
    2013-07-10 19:41 . 2013-07-10 19:41 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-07-10 19:41 . 2013-07-10 19:41 -------- d-----w- c:\arquivos de programas\Java
    2013-07-10 19:33 . 2013-07-10 19:33 -------- d-----w- C:\JRT
    2013-06-27 11:53 . 2013-07-10 19:26 -------- d-----w- c:\documents and settings\f000847\Dados de aplicativos\Thunderbird
    2013-06-18 12:28 . 2013-06-21 17:19 -------- d-----w- c:\documents and settings\f000847\Dados de aplicativos\IE Addon
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-07-10 19:48 . 2012-01-09 12:39 31088 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys
    2013-07-10 19:41 . 2013-04-11 13:20 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
    2013-07-10 19:41 . 2011-11-24 13:45 789416 ----a-w- c:\windows\system32\deployJava1.dll
    2013-06-27 19:41 . 2013-05-16 14:01 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2013-06-27 19:41 . 2011-11-24 13:28 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2013-06-27 19:41 . 2011-11-29 10:37 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2013-06-12 14:55 . 2013-01-22 11:13 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-06-12 14:55 . 2011-11-24 14:10 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-05-09 08:59 . 2013-05-16 14:01 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2013-05-09 08:59 . 2011-11-24 13:28 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2013-05-09 08:59 . 2013-05-16 14:01 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2013-05-09 08:59 . 2011-11-24 13:28 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2013-05-09 08:59 . 2011-11-24 13:28 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2013-05-09 08:58 . 2011-11-29 10:37 41664 ----a-w- c:\windows\avastSS.scr
    2013-05-09 08:58 . 2011-11-24 13:27 229648 ----a-w- c:\windows\system32\aswBoot.exe
    2013-05-08 12:52 . 2011-12-01 18:50 49536 ----a-w- c:\windows\system32\drivers\gbpkm.sys
    .
    .
    ((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* entradas vazias e legítimas por padrão não são apresentadas. 
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2013-05-09 08:58 121968 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2013-05-09 4858968]
    "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
    "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2013-03-12 253816]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{E37CB5F0-51F5-4395-A808-5FA49E399014}"= "c:\arquivos de programas\GbPlugin\gbiehbnb.dll" [2012-11-06 643008]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
    2013-05-23 13:47 1389096 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBnb]
    2012-11-06 12:26 643008 ------w- c:\arquivos de programas\GbPlugin\gbiehbnb.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
    2012-12-26 16:03 1652584 ------w- c:\arquivos de programas\GbPlugin\gbiehcef.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Serviço Scheduler2]
    2011-02-03 06:49 358808 ----a-w- c:\arquivos de programas\Arquivos comuns\Acronis\Schedule2\schedhlp.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2013-04-04 21:06 958576 ----a-w- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2007-06-27 22:03 152872 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
    2009-11-18 02:55 33697792 ----a-r- c:\arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2009-06-25 04:51 166912 ----a-r- c:\windows\system32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2009-06-25 04:52 134656 ----a-r- c:\windows\system32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2007-03-01 18:57 153136 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
    2009-06-25 04:51 136192 ----a-r- c:\windows\system32\igfxpers.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2013-03-12 10:32 253816 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
    2011-02-03 06:49 5149840 ----a-w- c:\arquivos de programas\Acronis\TrueImageHome\TrueImageMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    .
    R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [16/05/2013 11:01 49376]
    R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [16/05/2013 11:01 175176]
    R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [01/12/2011 15:50 49536]
    R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [24/11/2011 11:11 752128]
    R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [03/04/2012 09:31 24408]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29/11/2011 07:37 770344]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24/11/2011 10:28 369584]
    R2 afcdpsrv;Serviço de Acronis Nonstop Backup;c:\arquivos de programas\Arquivos comuns\Acronis\CDP\afcdpsrv.exe [24/11/2011 11:11 3246040]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24/11/2011 10:28 29816]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [16/05/2013 11:01 66336]
    R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [01/12/2011 15:50 410152]
    R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [24/11/2011 11:11 167968]
    R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [09/01/2012 09:39 31088]
    R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [24/11/2011 10:11 1425280]
    S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [09/01/2012 09:39 31088]
    .
    --- =Outros Serviços/Drivers Na Memória ---
    .
    *NewlyCreated* - JAVAQUICKSTARTERSERVICE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-06-21 15:39 1165776 ----a-w- c:\arquivos de programas\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
    .
    Conteúdo da pasta 'Tarefas Agendadas'
    .
    2013-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-22 14:55]
    .
    2013-07-10 c:\windows\Tasks\avast! Emergency Update.job
    - c:\arquivos de programas\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-20 08:58]
    .
    2013-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-04-11 10:24]
    .
    2013-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-04-11 10:24]
    .
    .
    ------- Scan Suplementar -------
    .
    uStart Page = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    mSearch Bar = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Trusted Zone: bancobrasil.com.br\www
    Trusted Zone: bancobrasil.com.br\www14
    Trusted Zone: bancobrasil.com.br\www2
    Trusted Zone: bb.com.br\www
    Trusted Zone: caixa.gov.br\imagem
    Trusted Zone: caixa.gov.br\internetbanking
    Trusted Zone: caixa.gov.br\www
    TCP: DhcpNameServer = 10.4.65.16
    FF - ProfilePath - c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\
    FF - prefs.js: browser.startup.homepage - 
    FF - ExtSQL: 2013-06-18 08:37; [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]; c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\helperframework@zonemedia.com.xpi
    FF - ExtSQL: 2013-06-18 08:38; [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]; c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\ffxtlbr@babylon.com
    .
    - - - - ORFÃOS REMOVIDOS - - - -
    .
    HKLM-Run-update_apc - c:\arquivos de programas\Internet Explorer\Updater.exe
    AddRemove-Cartoon Maker1.7 - c:\documents and settings\f000847\Meus documentos\Nova pasta\uninstall.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Rootkit scan 2013-07-10 16:51
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Procurando processos ocultos ... 
    .
    Procurando entradas auto inicializáveis ocultas ... 
    .
    Procurando ficheiros/arquivos ocultos ... 
    .
    Varredura completada com sucesso
    arquivos/ficheiros ocultos: 0
    .
    **************************************************************************
    .
    --------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\1FDE42FC632E233438BCC407A1B9BC0F\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "107"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\2451D69CF585D214C8A52004DB1A469B\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "106"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\256917180E811B74A9218FB20F574DBD\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "105"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\484CA1D2615EC8048852CA1B3C65CAA7\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "101"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\4C9878626E35BDD4F833D8F0E900B0AE\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "100"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\5E903427217EC6249BD46B4B52112CF9\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "104"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\7A7FFB02FB4E7E4488243D1990374C9B\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="Microsoft's Silverlight Installation [1]"
    "100"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\82B28DCEEB84C6245BB5E60C22162658\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "108"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\BE7C28545F39D804F992A5B51E7E8654\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "103"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\DE6BA3F2C1597EC4A89C5864DFFCF1A5\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "102"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\46EAC7482DC4D2B4FA0079F85F340164\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";"
    "2"=";"
    "3"=";"
    "4"=";"
    "5"=";"
    "6"=";"
    "7"=";"
    "8"=";"
    "9"=";"
    "10"=";"
    "11"=";"
    "12"=";"
    "13"=";"
    "14"=";"
    "15"=";"
    "16"=";"
    "17"=";"
    "18"=";"
    "19"=";"
    "20"=";"
    "21"=";"
    "22"=";"
    "23"=";"
    "24"=";"
    "25"=";"
    "26"=";"
    "27"=";"
    "28"=";"
    "29"=";"
    "30"=";"
    "31"=";"
    "32"=";"
    "33"=";"
    "34"=";"
    "35"=";"
    "36"=";"
    "37"=";"
    "38"=";"
    "39"=";"
    "40"=";"
    "41"=";"
    "42"=";"
    "43"=";"
    "44"=";"
    "45"=";"
    "46"=";"
    "47"=";"
    "48"=";"
    "49"=";"
    "50"=";"
    "51"=";"
    "52"=";"
    "53"=";"
    "54"=";"
    "55"=";"
    "56"=";"
    "57"=";"
    "58"=";"
    "59"=";"
    "60"=";"
    "61"=";"
    "62"=";"
    "63"=";"
    "64"=";"
    "65"=";"
    "66"=";"
    "67"=";"
    "68"=";"
    "69"=";"
    "70"=";"
    "71"=";"
    "72"=";"
    "73"=";"
    "74"=";"
    "75"=";"
    "76"=";"
    "77"=";"
    "78"=";"
    "79"=";"
    "80"=";"
    "81"=";"
    "82"=";"
    "83"=";"
    "84"=";"
    "85"=";"
    "86"=";"
    "87"=";"
    "88"=";"
    "89"=";"
    "90"=";"
    "91"=";"
    "92"=";"
    "93"=";"
    "94"=";"
    "95"=";"
    "96"=";"
    "97"=";"
    "98"=";"
    "99"=";"
    "100"=";"
    "101"=";"
    "102"=";"
    "103"=";"
    "104"=";"
    "105"=";"
    "106"=";"
    "107"=";"
    "108"=";"
    "109"=";"
    "110"=";"
    "111"=";"
    "112"=";"
    "113"=";"
    "114"=";"
    "115"=";"
    "116"=";"
    "117"=";"
    "118"=";"
    "119"=";"
    "120"=";"
    "121"=";"
    "122"=";"
    "123"=";"
    "124"=";"
    "125"=";"
    "126"=";"
    "127"=";"
    "128"=";"
    "129"=";"
    "130"=";"
    "131"=";"
    "132"=";"
    "133"=";"
    "134"=";"
    "135"=";"
    "136"=";"
    "137"=";"
    "138"=";"
    "139"=";"
    "140"=";"
    "141"=";"
    "142"=";"
    "143"=";"
    "144"=";"
    "145"=";"
    "146"=";"
    "147"=";"
    "148"=";"
    "149"=";"
    "150"=";"
    "151"=";"
    "152"=";"
    "153"=";"
    "154"=";"
    "155"=";"
    "156"=";"
    "157"=";"
    "158"=";"
    "159"=";"
    "160"=";"
    "161"=";"
    "162"=";"
    "163"=";"
    "164"=";"
    "165"=";"
    "166"=";"
    "167"=";"
    "168"=";"
    "169"=";"
    "170"=";"
    "171"=";"
    "172"=";"
    "173"=";"
    "174"=";"
    "175"=";"
    "176"=";"
    "177"=";"
    "178"=";"
    "179"=";"
    "180"=";"
    "181"=";"
    "182"=";"
    "183"=";"
    "184"=";"
    "185"=";"
    "186"=";"
    "187"=";"
    "188"=";"
    "189"=";"
    "190"=";"
    "191"=";"
    "192"=";"
    "193"=";"
    "194"=";"
    "195"=";"
    "196"=";"
    "197"=";"
    "198"=";"
    "199"=";"
    "200"=";"
    "201"=";"
    "202"=";"
    "203"=";"
    "204"=";"
    "205"=";"
    "206"=";"
    "207"=";"
    "208"=";"
    "209"=";"
    "210"=";"
    "211"=";"
    "212"=";"
    "213"=";"
    "214"=";"
    "215"=";"
    "216"=";"
    "217"=";"
    "218"=";"
    "219"=";"
    "220"=";"
    "221"=";"
    "222"=";"
    "223"=";"
    "224"=";"
    "225"=";"
    "226"=";"
    "227"=";"
    "228"=";"
    "229"=";"
    "230"=";"
    "231"=";"
    "232"=";"
    "233"=";"
    "234"=";"
    "235"=";"
    "236"=";"
    "237"=";"
    "238"=";"
    "239"=";"
    "240"=";"
    "241"=";"
    "242"=";"
    "243"=";"
    "244"=";"
    "245"=";"
    "246"=";"
    "247"=";"
    "248"=";"
    "249"=";"
    "250"=";"
    "251"=";"
    "252"=";"
    "253"=";"
    "254"=";"
    "255"=";"
    "256"=";"
    "257"=";"
    "258"=";"
    "259"=";"
    "260"=";"
    "261"=";"
    "262"=";"
    "263"=";"
    "264"=";"
    "265"=";"
    "266"=";"
    "267"=";"
    "268"=";"
    "269"=";"
    "270"=";"
    "271"=";"
    "272"=";"
    "273"=";"
    "274"=";"
    "275"=";"
    "276"=";"
    "277"=";"
    "278"=";"
    "279"=";"
    "280"=";"
    "281"=";"
    "282"=";"
    "283"=";"
    "284"=";"
    "285"=";"
    "286"=";"
    "287"=";"
    "288"=";"
    "289"=";"
    "290"=";"
    "291"=";"
    "292"=";"
    "293"=";"
    "294"=";"
    "295"=";"
    "296"=";"
    "297"=";"
    "298"=";"
    "299"=";"
    "300"=";"
    "301"=";"
    "302"=";"
    "303"=";"
    "304"=";"
    "305"=";"
    "306"=";"
    "307"=";"
    "308"=";"
    "309"=";"
    "310"=";"
    "311"=";"
    "312"=";"
    "313"=";"
    "314"=";"
    "315"=";"
    "316"=";"
    "317"=";"
    "318"=";"
    "319"=";"
    "320"=";"
    "321"=";"
    "322"=";"
    "323"=";"
    "324"=";"
    "325"=";"
    "326"=";"
    "327"=";"
    "328"=";"
    "329"=";"
    "330"=";"
    "331"=";"
    "332"=";"
    "333"=";"
    "334"=";"
    "335"=";"
    "336"=";"
    "337"=";"
    "338"=";"
    "339"=";"
    "340"=";"
    "341"=";"
    "342"=";"
    "343"=";"
    "344"=";"
    "345"=";"
    "346"=";"
    "347"=";"
    "348"=";"
    "349"=";"
    "350"=";"
    "351"=";"
    "352"=";"
    "353"=";"
    "354"=";"
    "355"=";"
    "356"=";"
    "357"=";"
    "358"=";"
    "359"=";"
    "360"=";"
    "361"=";"
    "362"=";"
    "363"=";"
    "364"=";"
    "365"=";"
    "366"=";"
    "367"=";"
    "368"=";"
    "369"=";"
    "370"=";"
    "371"=";"
    "372"=";"
    "373"=";"
    "374"=";"
    "375"=";"
    "376"=";"
    "377"=";"
    "378"=";"
    "379"=";"
    "380"=";"
    "381"=";"
    "382"=";"
    "383"=";"
    "384"=";"
    "385"=";"
    "386"=";"
    "387"=";"
    "388"=";"
    "389"=";"
    "390"=";"
    "391"=";"
    "392"=";"
    "393"=";"
    "394"=";"
    "395"=";"
    "396"=";"
    "397"=";"
    "398"=";"
    "399"=";"
    "400"=";"
    "401"=";"
    "402"=";"
    "403"=";"
    "404"=";"
    "405"=";"
    "406"=";"
    "407"=";"
    "408"=";"
    "409"=";"
    "410"=";"
    "411"=";"
    "412"=";"
    "413"=";"
    "414"=";"
    "415"=";"
    "416"=";"
    "417"=";"
    "418"=";"
    "419"=";"
    "420"=";"
    "421"=";"
    "422"=";"
    "423"=";"
    "424"=";"
    "425"=";"
    "426"=";"
    "427"=";"
    "428"=";"
    "429"=";"
    "430"=";"
    "431"=";"
    "432"=";"
    "433"=";"
    "434"=";"
    "435"=";"
    "436"=";"
    "437"=";"
    "438"=";"
    "439"=";"
    "440"=";"
    "441"=";"
    "442"=";"
    "443"=";"
    "444"=";"
    "445"=";"
    "446"=";"
    "447"=";"
    "448"=";"
    "449"=";"
    "450"=";"
    "451"=";"
    "452"=";"
    "453"=";"
    "454"=";"
    "455"=";"
    "456"=";"
    "457"=";"
    "458"=";"
    "459"=";"
    "460"=";"
    "461"=";"
    "462"=";"
    "463"=";"
    "464"=";"
    "465"=";"
    "466"=";"
    "467"=";"
    "468"=";"
    "469"=";"
    "470"=";"
    "471"=";"
    "472"=";"
    "473"=";"
    "474"=";"
    "475"=";"
    "476"=";"
    "477"=";"
    "478"=";"
    "479"=";"
    "480"=";"
    "481"=";"
    "482"=";"
    "483"=";"
    "484"=";"
    "485"=";"
    "486"=";"
    "487"=";"
    "488"=";"
    "489"=";"
    "490"=";"
    "491"=";"
    "492"=";"
    "493"=";"
    "494"=";"
    "495"=";"
    "496"=";"
    "497"=";"
    "498"=";"
    "499"=";"
    "500"=";"
    "501"=";"
    "502"=";"
    "503"=";"
    "504"=";"
    "505"=";"
    "506"=";"
    "507"=";"
    "508"=";"
    "509"=";"
    "510"=";"
    "511"=";"
    "512"=";"
    "513"=";"
    "514"=";"
    "515"=";"
    "516"=";"
    "517"=";"
    "518"=";"
    "519"=";"
    "520"=";"
    "521"=";"
    "522"=";"
    "523"=";"
    "524"=";"
    "525"=";"
    "526"=";"
    "527"=";"
    "528"=";"
    "529"=";"
    "530"=";"
    "531"=";"
    "532"=";"
    "533"=";"
    "534"=";"
    "535"=";"
    "536"=";"
    "537"=";"
    "538"=";"
    "539"=";"
    "540"=";"
    "541"=";"
    "542"=";"
    "543"=";"
    "544"=";"
    "545"=";"
    "546"=";"
    "547"=";"
    "548"=";"
    "549"=";"
    "550"=";"
    "551"=";"
    "552"=";"
    "553"=";"
    "554"=";"
    "555"=";"
    "556"=";"
    "557"=";"
    "558"=";"
    "559"=";"
    "560"=";"
    "561"=";"
    "562"=";"
    "563"=";"
    "564"=";"
    "565"=";"
    "566"=";"
    "567"=";"
    "568"=";"
    "569"=";"
    "570"=";"
    "571"=";"
    "572"=";"
    "573"=";"
    "574"=";"
    "575"=";"
    "576"=";"
    "577"=";"
    "578"=";"
    "579"=";"
    "580"=";"
    "581"=";"
    "582"=";"
    "583"=";"
    "584"=";"
    "585"=";"
    "586"=";"
    "587"=";"
    "588"=";"
    "589"=";"
    "590"=";"
    "591"=";"
    "592"=";"
    "593"=";"
    "594"=";"
    "595"=";"
    "596"=";"
    "597"=";"
    "598"=";"
    "599"=";"
    "600"=";"
    "601"=";"
    "602"=";"
    "603"=";"
    "604"=";"
    "605"=";"
    "606"=";"
    "607"=";"
    "608"=";"
    "609"=";"
    "610"=";"
    "611"=";"
    "612"=";"
    "613"=";"
    "614"=";"
    "615"=";"
    "616"=";"
    "617"=";"
    "618"=";"
    "619"=";"
    "620"=";"
    "621"=";"
    "622"=";"
    "623"=";"
    "624"=";"
    "625"=";"
    "626"=";"
    "627"=";"
    "628"=";"
    "629"=";"
    "630"=";"
    "631"=";"
    "632"=";"
    "633"=";"
    "634"=";"
    "635"=";"
    "636"=";"
    "637"=";"
    "638"=";"
    "639"=";"
    "640"=";"
    "641"=";"
    "642"=";"
    "643"=";"
    "644"=";"
    "645"=";"
    "646"=";"
    "647"=";"
    "648"=";"
    "649"=";"
    "650"=";"
    "651"=";"
    "652"=";"
    "653"=";"
    "654"=";"
    "655"=";"
    "656"=";"
    "657"=";"
    "658"=";"
    "659"=";"
    "660"=";"
    "661"=";"
    "662"=";"
    "663"=";"
    "664"=";"
    "665"=";"
    "666"=";"
    "667"=";"
    "668"=";"
    "669"=";"
    "670"=";"
    "671"=";"
    "672"=";"
    "673"=";"
    "674"=";"
    "675"=";"
    "676"=";"
    "677"=";"
    "678"=";"
    "679"=";"
    "680"=";"
    "681"=";"
    "682"=";"
    "683"=";"
    "684"=";"
    "685"=";"
    "686"=";"
    "687"=";"
    "688"=";"
    "689"=";"
    "690"=";"
    "691"=";"
    "692"=";"
    "693"=";"
    "694"=";"
    "695"=";"
    "696"=";"
    "697"=";"
    "698"=";"
    "699"=";"
    "700"=";"
    "701"=";"
    "702"=";"
    "703"=";"
    "704"=";"
    "705"=";"
    "706"=";"
    "707"=";"
    "708"=";"
    "709"=";"
    "710"=";"
    "711"=";"
    "712"=";"
    "713"=";"
    "714"=";"
    "715"=";"
    "716"=";"
    "717"=";"
    "718"=";"
    "719"=";"
    "720"=";"
    "721"=";"
    "722"=";"
    "723"=";"
    "724"=";"
    "725"=";"
    "726"=";"
    "727"=";"
    "728"=";"
    "729"=";"
    "730"=";"
    "731"=";"
    "732"=";"
    "733"=";"
    "734"=";"
    "735"=";"
    "736"=";"
    "737"=";"
    "738"=";"
    "739"=";"
    "740"=";"
    "741"=";"
    "742"=";"
    "743"=";"
    "744"=";"
    "745"=";"
    "746"=";"
    "747"=";"
    "748"=";"
    "749"=";"
    "750"=";"
    "751"=";"
    "752"=";"
    "753"=";"
    "754"=";"
    "755"=";"
    "756"=";"
    "757"=";"
    "758"=";"
    "759"=";"
    "760"=";"
    "761"=";"
    "762"=";"
    "763"=";"
    "764"=";"
    "765"=";"
    "766"=";"
    "767"=";"
    "768"=";"
    "769"=";"
    "770"=";"
    "771"=";"
    "772"=";"
    "773"=";"
    "774"=";"
    "775"=";"
    "776"=";"
    "777"=";"
    "778"=";"
    "779"=";"
    "780"=";"
    "781"=";"
    "782"=";"
    "783"=";"
    "784"=";"
    "785"=";"
    "786"=";"
    "787"=";"
    "788"=";"
    "789"=";"
    "790"=";"
    "791"=";"
    "792"=";"
    "793"=";"
    "794"=";"
    "795"=";"
    "796"=";"
    "797"=";"
    "798"=";"
    "799"=";"
    "800"=";"
    "801"=";"
    "802"=";"
    "803"=";"
    "804"=";"
    "805"=";"
    "806"=";"
    "807"=";"
    "808"=";"
    "809"=";"
    "810"=";"
    "811"=";"
    "812"=";"
    "813"=";"
    "814"=";"
    "815"=";"
    "816"=";"
    "817"=";"
    "818"=";"
    "819"=";"
    "820"=";"
    "821"=";"
    "822"=";"
    "823"=";"
    "824"=";"
    "825"=";"
    "826"=";"
    "827"=";"
    "828"=";"
    "829"=";"
    "830"=";"
    "831"=";"
    "832"=";"
    "833"=";"
    "834"=";"
    "835"=";"
    "836"=";"
    "837"=";"
    "838"=";"
    "839"=";"
    "840"=";"
    "841"=";"
    "842"=";"
    "843"=";"
    "844"=";"
    "845"=";"
    "846"=";"
    "847"=";"
    "848"=";"
    "849"=";"
    "850"=";"
    "851"=";"
    "852"=";"
    "853"=";"
    "854"=";"
    "855"=";"
    "856"=";"
    "857"=";"
    "858"=";"
    "859"=";"
    "860"=";"
    "861"=";"
    "862"=";"
    "863"=";"
    "864"=";"
    "865"=";"
    "866"=";"
    "867"=";"
    "868"=";"
    "869"=";"
    "870"=";"
    "871"=";"
    "872"=";"
    "873"=";"
    "874"=";"
    "875"=";"
    "876"=";"
    "877"=";"
    "878"=";"
    "879"=";"
    "880"=";"
    "881"=";"
    "882"=";"
    "883"=";"
    "884"=";"
    "885"=";"
    "886"=";"
    "887"=";"
    "888"=";"
    "889"=";"
    "890"=";"
    "891"=";"
    "892"=";"
    "893"=";"
    "894"=";"
    "895"=";"
    "896"=";"
    "897"=";"
    "898"=";"
    "899"=";"
    "900"=";"
    "901"=";"
    "902"=";"
    "903"=";"
    "904"=";"
    "905"=";"
    "906"=";"
    "907"=";"
    "908"=";"
    "909"=";"
    "910"=";"
    "911"=";"
    "912"=";"
    "913"=";"
    "914"=";"
    "915"=";"
    "916"=";"
    "917"=";"
    "918"=";"
    "919"=";"
    "920"=";"
    "921"=";"
    "922"=";"
    "923"=";"
    "924"=";"
    "925"=";"
    "926"=";"
    "927"=";"
    "928"=";"
    "929"=";"
    "930"=";"
    "931"=";"
    "932"=";"
    "933"=";"
    "934"=";"
    "935"=";"
    "936"=";"
    "937"=";"
    "938"=";"
    "939"=";"
    "940"=";"
    "941"=";"
    "942"=";"
    "943"=";"
    "944"=";"
    "945"=";"
    "946"=";"
    "947"=";"
    "948"=";"
    "949"=";"
    "950"=";"
    "951"=";"
    "952"=";"
    "953"=";"
    "954"=";"
    "955"=";"
    "956"=";"
    "957"=";"
    "958"=";"
    "959"=";"
    "960"=";"
    "961"=";"
    "962"=";"
    "963"=";"
    "964"=";"
    "965"=";"
    "966"=";"
    "967"=";"
    "968"=";"
    "969"=";"
    "970"=";"
    "971"=";"
    "972"=";"
    "973"=";"
    "974"=";"
    "975"=";"
    "976"=";"
    "977"=";"
    "978"=";"
    "979"=";"
    "980"=";"
    "981"=";"
    "982"=";"
    "983"=";"
    "984"=";"
    "985"=";"
    "986"=";"
    "987"=";"
    "988"=";"
    "989"=";"
    "990"=";"
    "991"=";"
    "992"=";"
    "993"=";"
    "994"=";"
    "995"=";"
    "996"=";"
    "997"=";"
    "998"=";"
    "999"=";"
    "1000"=";"
    "1001"=";"
    "1002"=";"
    "1003"=";"
    "1004"=";"
    "1005"=";"
    "1006"=";"
    "1007"=";"
    "1008"=";"
    "1009"=";"
    "1010"=";"
    "1011"=";"
    "1012"=";"
    "1013"=";"
    "1014"=";"
    "1015"=";"
    "1016"=";"
    "1017"=";"
    "1018"=";"
    "1019"=";"
    "1020"=";"
    "1021"=";"
    "1022"=";"
    "1023"=";"
    "1024"=";"
    "1025"=";"
    "1026"=";"
    "1027"=";"
    "1028"=";"
    "1029"=";"
    "1030"=";"
    "1031"=";"
    "1032"=";"
    "1033"=";"
    "1034"=";"
    "1035"=";"
    "1036"=";"
    "1037"=";"
    "1038"=";"
    "1039"=";"
    "1040"=";"
    "1041"=";"
    "1042"=";"
    "1043"=";"
    "1044"=";"
    "1045"=";"
    "1046"=";"
    "1047"=";"
    "1048"=";"
    "1049"=";"
    "1050"=";"
    "1051"=";"
    "1052"=";"
    "1053"=";"
    "1054"=";"
    "1055"=";"
    "1056"=";"
    "1057"=";"
    "1058"=";"
    "1059"=";"
    "1060"=";"
    "1061"=";"
    "1062"=";"
    "1063"=";"
    "1064"=";"
    "1065"=";"
    "1066"=";"
    "1067"=";"
    "1068"=";"
    "1069"=";"
    "1070"=";"
    "1071"=";"
    "1072"=";"
    "1073"=";"
    "1074"=";"
    "1075"=";"
    "1076"=";"
    "1077"=";"
    "1078"=";"
    "1079"=";"
    "1080"=";"
    "1081"=";"
    "1082"=";"
    "1083"=";"
    "1084"=";"
    "1085"=";"
    "1086"=";"
    "1087"=";"
    "1088"=";"
    "1089"=";"
    "1090"=";"
    "1091"=";"
    "1092"=";"
    "1093"=";"
    "1094"=";"
    "1095"=";"
    "1096"=";"
    "1097"=";"
    "1098"=";"
    "1099"=";"
    "1100"=";"
    "1101"=";"
    "1102"=";"
    "1103"=";"
    "1104"=";"
    "1105"=";"
    "1106"=";"
    "1107"=";"
    "1108"=";"
    "1109"=";"
    "1110"=";"
    "1111"=";"
    "1112"=";"
    "1113"=";"
    "1114"=";"
    "1115"=";"
    "1116"=";"
    "1117"=";"
    "1118"=";"
    "1119"=";"
    "1120"=";"
    "1121"=";"
    "1122"=";"
    "1123"=";"
    "1124"=";"
    "1125"=";"
    "1126"=";"
    "1127"=";"
    "1128"=";"
    "1129"=";"
    "1130"=";"
    "1131"=";"
    "1132"=";"
    "1133"=";"
    "1134"=";"
    "1135"=";"
    "1136"=";"
    "1137"=";"
    "1138"=";"
    "1139"=";"
    "1140"=";"
    "1141"=";"
    "1142"=";"
    "1143"=";"
    "1144"=";"
    "1145"=";"
    "1146"=";"
    "1147"=";"
    "1148"=";"
    "1149"=";"
    "1150"=";"
    "1151"=";"
    "1152"=";"
    "1153"=";"
    "1154"=";"
    "1155"=";"
    "1156"=";"
    "1157"=";"
    "1158"=";"
    "1159"=";"
    "1160"=";"
    "1161"=";"
    "1162"=";"
    "1163"=";"
    "1164"=";"
    "1165"=";"
    "1166"=";"
    "1167"=";"
    "1168"=";"
    "1169"=";"
    "1170"=";"
    "1171"=";"
    "1172"=";"
    "1173"=";"
    "1174"=";"
    "1175"=";"
    "1176"=";"
    "1177"=";"
    "1178"=";"
    "1179"=";"
    "1180"=";"
    "1181"=";"
    "1182"=";"
    "1183"=";"
    "1184"=";"
    "1185"=";"
    "1186"=";"
    "1187"=";"
    "1188"=";"
    "1189"=";"
    "1190"=";"
    "1191"=";"
    "1192"=";"
    "1193"=";"
    "1194"=";"
    "1195"=";"
    "1196"=";"
    "1197"=";"
    "1198"=";"
    "1199"=";"
    "1200"=";"
    "1201"=";"
    "1202"=";"
    "1203"=";"
    "1204"=";"
    "1205"=";"
    "1206"=";"
    "1207"=";"
    "1208"=";"
    "1209"=";"
    "1210"=";"
    "1211"=";"
    "1212"=";"
    "1213"=";"
    "1214"=";"
    "1215"=";"
    "1216"=";"
    "1217"=";"
    "1218"=";"
    "1219"=";"
    "1220"=";"
    "1221"=";"
    "1222"=";"
    "1223"=";"
    "1224"=";"
    "1225"=";"
    "1226"=";"
    "1227"=";"
    "1228"=";"
    "1229"=";"
    "1230"=";"
    "1231"=";"
    "1232"=";"
    "1233"=";"
    "1234"=";"
    "1235"=";"
    "1236"=";"
    "1237"=";"
    "1238"=";"
    "1239"=";"
    "1240"=";"
    "1241"=";"
    "1242"=";"
    "1243"=";"
    "1244"=";"
    "1245"=";"
    "1246"=";"
    "1247"=";"
    "1248"=";"
    "1249"=";"
    "1250"=";"
    "1251"=";"
    "1252"=";"
    "1253"=";"
    "1254"=";"
    "1255"=";"
    "1256"=";"
    "1257"=";"
    "1258"=";"
    "1259"=";"
    "1260"=";"
    "1261"=";"
    "1262"=";"
    "1263"=";"
    "1264"=";"
    "1265"=";"
    "1266"=";"
    "1267"=";"
    "1268"=";"
    "1269"=";"
    "1270"=";"
    "1271"=";"
    "1272"=";"
    "1273"=";"
    "1274"=";"
    "1275"=";"
    "1276"=";"
    "1277"=";"
    "1278"=";"
    "1279"=";"
    "1280"=";"
    "1281"=";"
    "1282"=";"
    "1283"=";"
    "1284"=";"
    "1285"=";"
    "1286"=";"
    "1287"=";"
    "1288"=";"
    "1289"=";"
    "1290"=";"
    "1291"=";"
    "1292"=";"
    "1293"=";"
    "1294"=";"
    "1295"=";"
    "1296"=";"
    "1297"=";"
    "1298"=";"
    "1299"=";"
    "1300"=";"
    "1301"=";"
    "1302"=";"
    "1303"=";"
    "1304"=";"
    "1305"=";"
    "1306"=";"
    "1307"=";"
    "1308"=";"
    "1309"=";"
    "1310"=";"
    "1311"=";"
    "1312"=";"
    "1313"=";"
    "1314"=";"
    "1315"=";"
    "1316"=";"
    "1317"=";"
    "1318"=";"
    "1319"=";"
    "1320"=";"
    "1321"=";"
    "1322"=";"
    "1323"=";"
    "1324"=";"
    "1325"=";"
    "1326"=";"
    "1327"=";"
    "1328"=";"
    "1329"=";"
    "1330"=";"
    "1331"=";"
    "1332"=";"
    "1333"=";"
    "1334"=";"
    "1335"=";"
    "1336"=";"
    "1337"=";"
    "1338"=";"
    "1339"=";"
    "1340"=";"
    "1341"=";"
    "1342"=";"
    "1343"=";"
    "1344"=";"
    "1345"=";"
    "1346"=";"
    "1347"=";"
    "1348"=";"
    "1349"=";"
    "1350"=";"
    "1351"=";"
    "1352"=";"
    "1353"=";"
    "1354"=";"
    "1355"=";"
    "1356"=";"
    "1357"=";"
    "1358"=";"
    "1359"=";"
    "1360"=";"
    "1361"=";"
    "1362"=";"
    "1363"=";"
    "1364"=";"
    "1365"=";"
    "1366"=";"
    "1367"=";"
    "1368"=";"
    "1369"=";"
    "1370"=";"
    "1371"=";"
    "1372"=";"
    "1373"=";"
    "1374"=";"
    "1375"=";"
    "1376"=";"
    "1377"=";"
    "1378"=";"
    "1379"=";"
    "1380"=";"
    "1381"=";"
    "1382"=";"
    "1383"=";"
    "1384"=";"
    "1385"=";"
    "1386"=";"
    "1387"=";"
    "1388"=";"
    "1389"=";"
    "1390"=";"
    "1391"=";"
    "1392"=";"
    "1393"=";"
    "1394"=";"
    "1395"=";"
    "1396"=";"
    "1397"=";"
    "1398"=";"
    "1399"=";"
    "1400"=";"
    "1401"=";"
    "1402"=";"
    "1403"=";"
    "1404"=";"
    "1405"=";"
    "1406"=";"
    "1407"=";"
    "1408"=";"
    "1409"=";"
    "1410"=";"
    "1411"=";"
    "1412"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"="READER8;[1]"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D7314F9862C648A4DB8BE2A5B47BE100\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="Microsoft's Silverlight Installation [1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\DC3BF90CC0D3D2F398A9A6D1762F70F3\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";"
    "100"=";"
    "101"=";"
    "102"=";"
    "103"=";"
    "104"=";"
    "105"=";"
    "106"=";"
    "107"=";"
    "108"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
    .
    - - - - - - - > 'winlogon.exe'(1076)
    c:\arquivos de programas\GBPLUGIN\gbieh.dll
    c:\arquivos de programas\GbPlugin\gbiehBnb.dll
    c:\arquivos de programas\GbPlugin\gbiehCef.dll
    .
    - - - - - - - > 'explorer.exe'(1472)
    c:\windows\system32\ieframe.dll
    c:\arquivos de programas\GbPlugin\gbiehBnb.dll
    c:\windows\system32\webcheck.dll
    c:\arquivos de programas\GBPLUGIN\gbieh.dll
    c:\arquivos de programas\GbPlugin\gbiehCef.dll
    .
    Tempo para conclusão: 2013-07-10  16:52:37
    ComboFix-quarantined-files.txt  2013-07-10 19:52
    .
    Pré-execução: 12 pasta(s) 74.985.631.744 bytes disponíveis
    Pós execução: 13 pasta(s) 74.998.796.288 bytes disponíveis
    .
    - - End Of File - - F3789C676E1F5486AFF52186A2CD8FC6
    239FC8B1C26D5286165A956F5A98D8D7
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 70
    Localização : Rio de Janeiro

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram Sex Jul 12, 2013 10:26 am

    Bom Dia! Edvan

    |- Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( ... by Smeenk )

    |- Ou aqui! < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] >

    |- Salve-o no desktop!
    |- Desabilite seu antivírus!
    |- Para Windows 7,execute zoek.exe como administrador.

    autoclean;
    emptyalltemp;


    |- Copie e cole estas informações,em vermelho,no campo da ferramenta.
    |- Clique "Run Script".

    Zoek.exe is running now.
    Do not start any browser windows, they will be closed automatically.
    Please wait! This window will close when finished.
    A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log
    |- Surgirão estas informações,pedindo-lhe que aguarde o relatório.

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

    |- Aceite e/ou confirme o reboot!

    zoek.hta failed by unknown error.
    Restart computer, and try again.
    |- Ps: Ao obter algum erro,reinicie o PC e execute,novamente,a ferramenta.
    |- Poste o relatório,que estará em C:\zoek-results.txt <<

    A+
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 43
    Localização : Natal/RN

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan Sex Jul 12, 2013 4:58 pm

    Zoek.exe Version 4.0.0.4 Updated 10-July-2013
    Tool run by f000847 on 12/07/2013 at 17:49:47,10.
    Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
    Running in: Normal Mode Internet Access Detected

    ==== System Restore Info ======================

    12/07/2013 17:50:12 Zoek.exe System Restore Point Created Succesfully.

    ==== Deleting CLSID Registry Keys ======================


    ==== Deleting CLSID Registry Values ======================


    ==== Deleting Services ======================


    ==== Deleting Files \ Folders ======================

    "C:\Documents and Settings\f000847\Dados de aplicativos\desktop.ini" deleted
    "C:\WINDOWS\002702_.tmp" deleted
    "C:\WINDOWS\SET25.tmp" deleted
    "C:\WINDOWS\SET3.tmp" deleted
    "C:\WINDOWS\SET4.tmp" deleted
    "C:\WINDOWS\SET8.tmp" deleted
    "C:\WINDOWS\System32\SET1C4.tmp" deleted
    "C:\WINDOWS\System32\SET1CD.tmp" deleted
    "C:\WINDOWS\System32\SET1CE.tmp" deleted
    "C:\WINDOWS\System32\SET1CF.tmp" deleted
    "C:\WINDOWS\System32\SET1D0.tmp" deleted
    "C:\WINDOWS\System32\SET1D1.tmp" deleted
    "C:\WINDOWS\System32\SET1D2.tmp" deleted
    "C:\WINDOWS\System32\SET1D3.tmp" deleted
    "C:\WINDOWS\System32\SET1D4.tmp" deleted
    "C:\WINDOWS\System32\SET1D5.tmp" deleted
    "C:\WINDOWS\System32\SET1D6.tmp" deleted
    "C:\WINDOWS\System32\SET1D7.tmp" deleted
    "C:\WINDOWS\System32\SET1D8.tmp" deleted
    "C:\WINDOWS\System32\SET1D9.tmp" deleted
    "C:\WINDOWS\System32\SET1DA.tmp" deleted
    "C:\WINDOWS\System32\SET1E9.tmp" deleted
    "C:\WINDOWS\System32\SET1F2.tmp" deleted
    "C:\WINDOWS\System32\SET1F3.tmp" deleted
    "C:\WINDOWS\System32\SET1F4.tmp" deleted
    "C:\WINDOWS\System32\SET1F5.tmp" deleted
    "C:\WINDOWS\System32\SET1F6.tmp" deleted
    "C:\WINDOWS\System32\SET1F7.tmp" deleted
    "C:\WINDOWS\System32\SET1F8.tmp" deleted
    "C:\WINDOWS\System32\SET1F9.tmp" deleted
    "C:\WINDOWS\System32\SET1FA.tmp" deleted
    "C:\WINDOWS\System32\SET1FB.tmp" deleted
    "C:\WINDOWS\System32\SET1FC.tmp" deleted
    "C:\WINDOWS\System32\SET1FD.tmp" deleted
    "C:\WINDOWS\System32\SET1FE.tmp" deleted
    "C:\WINDOWS\System32\SET1FF.tmp" deleted
    "C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\searchplugins\BrowserDefender.xml" deleted
    "C:\Arquivos de programas\MyPC Backup" deleted

    ==== Firefox Extensions ======================

    ProfilePath: C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default
    - Undetermined - %ProfilePath%\extensions\data
    - Modulo de Seguranca - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}
    - Adicional de Seguranca CAIXA - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886D}

    ProfilePath: C:\Documents and Settings\Fun0131\Dados de aplicativos\Mozilla\Firefox\Profiles\z4e8s4wm.default
    - Modulo de Seguranca - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

    ==== Firefox Plugins ======================

    Profilepath: C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default
    ABCB4A6EAB701C629378255ABCB308E5 - C:\Arquivos de programas\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
    D7324EB1EDCB8990F8522DE0311359E9 - C:\WINDOWS\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
    02C317A415A91112EDEF07AAC78AF6D5 - C:\Arquivos de programas\Google\Update\1.3.21.149\npGoogleUpdate3.dll - Google Update
    3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
    F833DD5D8F959819F44BC98F47B1B6BB - C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
    65D09D8BC91D74C8800725EB33D1EE1B - C:\Arquivos de programas\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
    36A0F250C766D27BFE5A953C1A65B696 - C:\Arquivos de programas\Microsoft Silverlight\5.0.61118.0\npctrl.dll - Silverlight Plug-In
    CF4ABE599858E10EEB911E16FBCFD87D - C:\Arquivos de programas\Windows Media Player\npdrmv2.dll - Microsoft® DRM
    76E34EA1089E92709C5725407B565DA1 - C:\Arquivos de programas\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
    02A4A41FAC9BF96155B3E8068D1DF4B6 - C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
    64CE864482A941C006AC430640DE4DB3 - C:\Arquivos de programas\Microsoft Silverlight\5.0.61118.0\npctrlui.dll - Microsoft® Silverlight
    F9174E52953C2EDB35E4E634F6228F66 - C:\WINDOWS\system32\npptools.dll - Sistema operacional Microsoft® Windows®


    ==== Set IE to Default ======================

    Old Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.google.com/"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"="http://www.google.com/"

    New Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.google.com/"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
    {483830EE-A4CD-4b71-B0A3-3D82E62A6909} Unknown  Url="Not_Found"
    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21082\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} deleted successfully

    ==== Deleting CLSID Registry Values ======================


    ==== Empty IE Cache ======================

    C:\Documents and Settings\f000847\Meus documentos\Outros arquivos\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\Documents and Settings\f000847\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
    C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\itaqxty1.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    C:\Documents and Settings\f000847\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\WINDOWS\Temp successfully emptied
    C:\DOCUME~1\f000847\CONFIG~1\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\RECYCLER successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Documents and Settings\f000847\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted
    "C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted

    ==== EOF on 12/07/2013 at 17:56:48,89 ======================
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 70
    Localização : Rio de Janeiro

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram Sáb Jul 13, 2013 8:19 am

    Bom Dia! Edvan

    c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    ######

    |- Vá a pasta do Mozilla e,em "extensions",procure estes destaques e delete-as

    -/-

    |- Baixe: |[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]| ( ... de Xplode )

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

    |- Estando na página,clique na seta verde para o download
    |- Salve-a em um local conveniente! ( desktop! )
    |- Feche aplicativos que estejam abertos.

    [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    |- Execute-a!
    |- Com as duas checkbox marcadas! 
    |- Clique "Run".
    |- Caso queira,poste o log.

    A+
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 43
    Localização : Natal/RN

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan Seg Jul 15, 2013 4:57 pm

    Pronto amigo, mais um pc limpo.hehe



    # DelFix v10.3 - Logfile created 15/07/2013 at 17:56:45
    # Updated 08/06/2013 by Xplode
    # Username : f000847 - FUN0066
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

    ~ Removing disinfection tools ...

    Deleted : C:\Qoobox
    Deleted : C:\JRT
    Deleted : C:\ZHP
    Deleted : C:\Arquivos de programas\ZHPDiag
    Deleted : C:\AdwCleaner[S1].txt
    Deleted : C:\ComboFix.txt
    Deleted : C:\PhysicalDisk0_MBR.bin
    Deleted : C:\zoek-results.log
    Deleted : C:\Documents and Settings\f000847\Desktop\ComboFix.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\JRT.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\MBRCheck.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPDiag.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPDiag2.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPFix.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\zoek.exe
    Deleted : C:\Documents and Settings\f000847\Meus documentos\Downloads\adwcleaner.exe
    Deleted : C:\WINDOWS\grep.exe
    Deleted : C:\WINDOWS\PEV.exe
    Deleted : C:\WINDOWS\NIRCMD.exe
    Deleted : C:\WINDOWS\MBR.exe
    Deleted : C:\WINDOWS\SED.exe
    Deleted : C:\WINDOWS\SWREG.exe
    Deleted : C:\WINDOWS\SWSC.exe
    Deleted : C:\WINDOWS\SWXCACLS.exe
    Deleted : C:\WINDOWS\Zip.exe
    Deleted : HKLM\SOFTWARE\AdwCleaner
    Deleted : HKLM\SOFTWARE\Swearware
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

    ~ Cleaning system restore ...

    Deleted : RP #213 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #214 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #215 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #216 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #217 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #218 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #219 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #220 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #221 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #222 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #223 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #224 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #225 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #226 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #227 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #228 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #229 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #230 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #231 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #232 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #233 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #234 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #235 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #236 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #237 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #238 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #239 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #240 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #241 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #242 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #243 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #244 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #245 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #246 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #247 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #248 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #249 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #250 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #251 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #252 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #253 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #254 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #255 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #256 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #257 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #258 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #259 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #260 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #261 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #262 [P | 05/20/2013 13:00:46]
    Deleted : RP #263 [End of disinfection | 05/20/2013 13:00:46]
    Deleted : RP #264 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #265 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #266 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #267 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #268 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #269 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #270 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #271 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #272 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #273 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #274 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #275 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #276 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #277 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #278 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #279 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #280 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #281 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #282 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #283 [Ponto de verificação do sistema | 05/20/2013 13:00:49]
    Deleted : RP #284 [Ponto de verificação do sistema | 05/20/2013 13:00:49]
    Deleted : RP #285 [Instalado Java 7 Update 17 | 05/20/2013 13:00:50]
    Deleted : RP #286 [Ponto de verificação do sistema | 05/20/2013 13:00:50]
    Deleted : RP #287 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #288 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #289 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #290 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #291 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #292 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #293 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #294 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #295 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #296 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #297 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #298 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #299 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #300 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #301 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #302 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #303 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #304 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #305 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #306 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #307 [Instalado Java 7 Update 21 | 05/20/2013 13:00:53]
    Deleted : RP #308 [P | 05/20/2013 13:00:53]
    Deleted : RP #309 [Windows Internet Explorer 8 Instalado. | 05/20/2013 13:00:53]
    Deleted : RP #310 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #311 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #312 [Removido Java(TM) 6 Update 31 | 05/20/2013 13:00:53]
    Deleted : RP #313 [Removido Java 7 Update 17 | 05/20/2013 13:00:53]
    Deleted : RP #314 [Removido Adobe Reader 8.1.0 - Português | 05/20/2013 13:00:54]
    Deleted : RP #315 [End of disinfection | 05/20/2013 13:00:57]
    Deleted : RP #316 [Instalado Java 7 Update 21 | 05/20/2013 13:03:17]
    Deleted : RP #317 [Ponto de verificação do sistema | 05/21/2013 14:17:53]
    Deleted : RP #318 [Ponto de verificação do sistema | 05/22/2013 15:18:23]
    Deleted : RP #319 [Ponto de verificação do sistema | 05/23/2013 15:20:11]
    Deleted : RP #320 [Ponto de verificação do sistema | 05/24/2013 19:02:11]
    Deleted : RP #321 [Ponto de verificação do sistema | 05/27/2013 15:15:16]
    Deleted : RP #322 [Ponto de verificação do sistema | 05/28/2013 15:17:03]
    Deleted : RP #323 [Ponto de verificação do sistema | 05/29/2013 15:17:39]
    Deleted : RP #324 [Ponto de verificação do sistema | 05/31/2013 10:50:06]
    Deleted : RP #325 [Ponto de verificação do sistema | 06/03/2013 10:47:26]
    Deleted : RP #326 [Ponto de verificação do sistema | 06/04/2013 13:39:37]
    Deleted : RP #327 [Ponto de verificação do sistema | 06/05/2013 15:16:59]
    Deleted : RP #328 [Ponto de verificação do sistema | 06/06/2013 15:50:55]
    Deleted : RP #329 [Ponto de verificação do sistema | 06/07/2013 16:23:59]
    Deleted : RP #330 [Ponto de verificação do sistema | 06/10/2013 11:27:45]
    Deleted : RP #331 [Ponto de verificação do sistema | 06/11/2013 13:09:04]
    Deleted : RP #332 [Ponto de verificação do sistema | 06/12/2013 13:12:18]
    Deleted : RP #333 [Ponto de verificação do sistema | 06/13/2013 15:19:30]
    Deleted : RP #334 [Ponto de verificação do sistema | 06/17/2013 11:40:48]
    Deleted : RP #335 [Ponto de verificação do sistema | 06/18/2013 12:57:35]
    Deleted : RP #336 [Ponto de verificação do sistema | 06/19/2013 13:18:03]
    Deleted : RP #337 [Ponto de verificação do sistema | 06/20/2013 15:49:44]
    Deleted : RP #338 [Ponto de verificação do sistema | 06/21/2013 16:16:45]
    Deleted : RP #339 [Ponto de verificação do sistema | 06/25/2013 11:23:02]
    Deleted : RP #340 [Removido Microsoft .NET Framework 2.0 Service Pack 2 | 06/26/2013 10:52:21]
    Deleted : RP #341 [Ponto de verificação do sistema | 06/27/2013 11:12:26]
    Deleted : RP #342 [Ponto de verificação do sistema | 06/28/2013 15:16:16]
    Deleted : RP #343 [Ponto de verificação do sistema | 07/01/2013 10:52:18]
    Deleted : RP #344 [Ponto de verificação do sistema | 07/02/2013 14:13:02]
    Deleted : RP #345 [Ponto de verificação do sistema | 07/03/2013 15:15:09]
    Deleted : RP #346 [Ponto de verificação do sistema | 07/04/2013 15:15:20]
    Deleted : RP #347 [Ponto de verificação do sistema | 07/05/2013 19:46:05]
    Deleted : RP #348 [Ponto de verificação do sistema | 07/08/2013 11:06:50]
    Deleted : RP #349 [Ponto de verificação do sistema | 07/09/2013 12:09:42]
    Deleted : RP #350 [Ponto de verificação do sistema | 07/10/2013 15:18:29]
    Deleted : RP #351 [Removido Java 7 Update 21 | 07/10/2013 19:40:56]
    Deleted : RP #352 [Instalado Java 7 Update 25 | 07/10/2013 19:41:28]
    Deleted : RP #353 [Ponto de verificação do sistema | 07/12/2013 15:16:08]
    Deleted : RP #354 [zoek.exe restore point | 07/12/2013 20:50:12]
    Deleted : RP #355 [Ponto de verificação do sistema | 07/15/2013 10:39:58]

    New restore point created !

    ########## - EOF - ##########
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 70
    Localização : Rio de Janeiro

    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram Seg Jul 15, 2013 8:46 pm

    CASO RESOLVIDO!

    Necessitando novo auxílio para este computador,basta abrir "Novo Tópico" e relatar o problema.

    Conteúdo patrocinado


    Pc infectado, pop up de propaganda aparecendo. Empty Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Conteúdo patrocinado


      Data/hora atual: Sex Abr 26, 2024 9:16 am