Fórum SecSecurity

Implementando Limpeza e Seguranca em seu computador!

Palavras chave

Últimos assuntos

» ResetBrowser ( ... de Nicolas Coolman )
Ter Maio 31, 2016 5:58 am por joram

» herdProtectScan ( ... by herdprotect.com )
Seg Mar 07, 2016 10:58 pm por joram

» Emsisoft Emergency Kit ( ... by Emsisoft.com )
Dom Fev 28, 2016 5:40 am por joram

» Dr.WEB Link Checker ( ... by Doctor Web.Ltd )
Qui Fev 11, 2016 9:51 am por joram

» Computador com erros no navegador
Sab Ago 29, 2015 8:04 pm por joram

» Justiça determina que PSafe retire alertas desleais
Qua Ago 19, 2015 6:58 am por joram

» Google vai fazer buscas offline internas no desktop do seu PC
Ter Ago 18, 2015 8:19 am por joram

» Baidu lança buscador no Brasil!
Seg Ago 17, 2015 12:25 pm por joram

» Kaspersky é acusada de inventar vírus!
Sex Ago 14, 2015 3:32 pm por joram

Dezembro 2016

SegTerQuaQuiSexSabDom
   1234
567891011
12131415161718
19202122232425
262728293031 

Calendário Calendário

Parceiros

Fórum grátis

Os membros mais marcados


    Pc infectado, pop up de propaganda aparecendo.

    Compartilhe

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan em Qui Jul 11, 2013 10:03 pm

    Log para analise [Você precisa estar registrado e conectado para ver este link.]

     Passei no pc ontem essas ferramentas logo abaixo:

    # AdwCleaner v2.304 - Relatório criado em 10/07/2013 às 16:30:54
    # Atualizado em 03/07/2013 por Xplode
    # Sistema Operacional : Microsoft Windows XP Service Pack 3 (32 bits)
    # Usuário : f000847 - FUN0066
    # Modo de Boot : Normal
    # Executado de : C:\Documents and Settings\f000847\Meus documentos\Downloads\adwcleaner.exe
    # Opção [Remover]


    ***** [Serviços] *****


    ***** [Arquivos/Pastas] *****

    Arquivo Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\HelperFramework@ZoneMedia.com.xpi
    Arquivo Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\searchplugins\Babylon.xml
    Pasta Removido : C:\Documents and Settings\All Users\Dados de aplicativos\Babylon
    Pasta Removido : C:\Documents and Settings\f000847\Dados de aplicativos\Babylon
    Removido Durante o reboot : C:\Documents and Settings\All Users\Dados de aplicativos\BrowserDefender

    ***** [Registro] *****

    Chave Removida : HKCU\Software\BabSolution
    Chave Removida : HKCU\Software\DataMngr
    Chave Removida : HKCU\Software\DataMngr_Toolbar
    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}
    Chave Removida : HKLM\SOFTWARE\5c55dcdce26dea48
    Chave Removida : HKLM\Software\Babylon
    Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
    Chave Removida : HKLM\SOFTWARE\Classes\Prod.cap
    Chave Removida : HKLM\Software\DataMngr
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BabylonToolbar
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PricePeep

    ***** [Navegadores] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registro está limpo.

    -\\ Mozilla Firefox v21.0 (pt-BR)

    Arquivo : C:\Documents and Settings\Fun0131\Dados de aplicativos\Mozilla\Firefox\Profiles\z4e8s4wm.default\prefs.js

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\itaqxty1.default\prefs.js

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\prefs.js

    C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\user.js ... Removido !

    Removida : user_pref("extensions.BabylonToolbar.admin", false);
    Removida : user_pref("extensions.BabylonToolbar.aflt", "babsst");
    Removida : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
    Removida : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
    Removida : user_pref("extensions.BabylonToolbar.dfltLng", "en");
    Removida : user_pref("extensions.BabylonToolbar.excTlbr", false);
    Removida : user_pref("extensions.BabylonToolbar.ffxUnstlRst", true);
    Removida : user_pref("extensions.BabylonToolbar.id", "7c25fa6900000000000014dae96ecb3d");
    Removida : user_pref("extensions.BabylonToolbar.instlDay", "15874");
    Removida : user_pref("extensions.BabylonToolbar.instlRef", "sst");
    Removida : user_pref("extensions.BabylonToolbar.newTab", false);
    Removida : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
    Removida : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
    Removida : user_pref("extensions.BabylonToolbar.rvrt", "false");
    Removida : user_pref("extensions.BabylonToolbar.smplGrp", "none");
    Removida : user_pref("extensions.BabylonToolbar.tlbrId", "base");
    Removida : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[...]
    Removida : user_pref("extensions.BabylonToolbar.vrsn", "1.8.11.10");
    Removida : user_pref("extensions.BabylonToolbar.vrsni", "1.8.11.10");
    Removida : user_pref("extensions.BabylonToolbar.vrsnTs", "1.8.11.108:37:58");
    Removida : user_pref("extensions.BabylonToolbar_i.babExt", "");
    Removida : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=122793");
    Removida : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");

    -\\ Google Chrome v27.0.1453.116

    Arquivo : C:\Documents and Settings\f000847\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

    [OK] Arquivo está limpo.

    *************************

    AdwCleaner[S1].txt - [4573 octets] - [10/07/2013 16:30:54]

    ########## EOF - C:\AdwCleaner[S1].txt - [4633 octets] ##########




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 4.9.2 (04.29.2013:1)
    OS: Microsoft Windows XP x86
    Ran by f000847 on 10/07/2013 at 16:33:31,87
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



    ~~~ Registry Keys



    ~~~ Files

    Successfully deleted: [File] C:\WINDOWS\prefetch\BABYLONTOOLBARSRV.EXE-289CB403.pf



    ~~~ Folders





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 10/07/2013 at 16:36:13,03
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan em Qui Jul 11, 2013 10:05 pm

     Continuação:

    ComboFix 13-07-09.01 - f000847 10/07/2013  16:48:18.1.2 - x86
    Microsoft Windows XP Professional  5.1.2600.3.1252.55.1046.18.2013.1545 [GMT -3:00]
    Executando de: c:\documents and settings\f000847\Desktop\Ferramentas para remoção de virus\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ADS - system32: deleted 2 bytes in 1 streams.
    ADS - drivers: deleted 412 bytes in 1 streams.
    .
    (((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\Dados de aplicativos\TEMP
    .
    .
    ((((((((((((((((   Arquivos/Ficheiros criados de 2013-06-10 to 2013-07-10  ))))))))))))))))))))))))))))
    .
    .
    2013-07-10 19:44 . 2013-07-10 19:44 512 ----a-w- C:\PhysicalDisk0_MBR.bin
    2013-07-10 19:42 . 2013-07-10 19:44 -------- d-----w- C:\ZHP
    2013-07-10 19:42 . 2013-07-10 19:44 -------- d-----w- c:\arquivos de programas\ZHPDiag
    2013-07-10 19:41 . 2013-07-10 19:41 144896 ----a-w- c:\windows\system32\javacpl.cpl
    2013-07-10 19:41 . 2013-07-10 19:41 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-07-10 19:41 . 2013-07-10 19:41 -------- d-----w- c:\arquivos de programas\Java
    2013-07-10 19:33 . 2013-07-10 19:33 -------- d-----w- C:\JRT
    2013-06-27 11:53 . 2013-07-10 19:26 -------- d-----w- c:\documents and settings\f000847\Dados de aplicativos\Thunderbird
    2013-06-18 12:28 . 2013-06-21 17:19 -------- d-----w- c:\documents and settings\f000847\Dados de aplicativos\IE Addon
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-07-10 19:48 . 2012-01-09 12:39 31088 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys
    2013-07-10 19:41 . 2013-04-11 13:20 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
    2013-07-10 19:41 . 2011-11-24 13:45 789416 ----a-w- c:\windows\system32\deployJava1.dll
    2013-06-27 19:41 . 2013-05-16 14:01 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2013-06-27 19:41 . 2011-11-24 13:28 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2013-06-27 19:41 . 2011-11-29 10:37 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2013-06-12 14:55 . 2013-01-22 11:13 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-06-12 14:55 . 2011-11-24 14:10 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-05-09 08:59 . 2013-05-16 14:01 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2013-05-09 08:59 . 2011-11-24 13:28 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2013-05-09 08:59 . 2013-05-16 14:01 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2013-05-09 08:59 . 2011-11-24 13:28 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2013-05-09 08:59 . 2011-11-24 13:28 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2013-05-09 08:58 . 2011-11-29 10:37 41664 ----a-w- c:\windows\avastSS.scr
    2013-05-09 08:58 . 2011-11-24 13:27 229648 ----a-w- c:\windows\system32\aswBoot.exe
    2013-05-08 12:52 . 2011-12-01 18:50 49536 ----a-w- c:\windows\system32\drivers\gbpkm.sys
    .
    .
    ((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* entradas vazias e legítimas por padrão não são apresentadas. 
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2013-05-09 08:58 121968 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2013-05-09 4858968]
    "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
    "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2013-03-12 253816]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{E37CB5F0-51F5-4395-A808-5FA49E399014}"= "c:\arquivos de programas\GbPlugin\gbiehbnb.dll" [2012-11-06 643008]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
    2013-05-23 13:47 1389096 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBnb]
    2012-11-06 12:26 643008 ------w- c:\arquivos de programas\GbPlugin\gbiehbnb.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
    2012-12-26 16:03 1652584 ------w- c:\arquivos de programas\GbPlugin\gbiehcef.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Serviço Scheduler2]
    2011-02-03 06:49 358808 ----a-w- c:\arquivos de programas\Arquivos comuns\Acronis\Schedule2\schedhlp.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2013-04-04 21:06 958576 ----a-w- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2007-06-27 22:03 152872 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
    2009-11-18 02:55 33697792 ----a-r- c:\arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2009-06-25 04:51 166912 ----a-r- c:\windows\system32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2009-06-25 04:52 134656 ----a-r- c:\windows\system32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2007-03-01 18:57 153136 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
    2009-06-25 04:51 136192 ----a-r- c:\windows\system32\igfxpers.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2013-03-12 10:32 253816 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
    2011-02-03 06:49 5149840 ----a-w- c:\arquivos de programas\Acronis\TrueImageHome\TrueImageMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    .
    R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [16/05/2013 11:01 49376]
    R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [16/05/2013 11:01 175176]
    R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [01/12/2011 15:50 49536]
    R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [24/11/2011 11:11 752128]
    R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [03/04/2012 09:31 24408]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [29/11/2011 07:37 770344]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24/11/2011 10:28 369584]
    R2 afcdpsrv;Serviço de Acronis Nonstop Backup;c:\arquivos de programas\Arquivos comuns\Acronis\CDP\afcdpsrv.exe [24/11/2011 11:11 3246040]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24/11/2011 10:28 29816]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [16/05/2013 11:01 66336]
    R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [01/12/2011 15:50 410152]
    R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [24/11/2011 11:11 167968]
    R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [09/01/2012 09:39 31088]
    R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [24/11/2011 10:11 1425280]
    S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [09/01/2012 09:39 31088]
    .
    --- =Outros Serviços/Drivers Na Memória ---
    .
    *NewlyCreated* - JAVAQUICKSTARTERSERVICE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-06-21 15:39 1165776 ----a-w- c:\arquivos de programas\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
    .
    Conteúdo da pasta 'Tarefas Agendadas'
    .
    2013-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-22 14:55]
    .
    2013-07-10 c:\windows\Tasks\avast! Emergency Update.job
    - c:\arquivos de programas\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-20 08:58]
    .
    2013-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-04-11 10:24]
    .
    2013-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-04-11 10:24]
    .
    .
    ------- Scan Suplementar -------
    .
    uStart Page = [Você precisa estar registrado e conectado para ver este link.]
    mSearch Bar = [Você precisa estar registrado e conectado para ver este link.]
    Trusted Zone: bancobrasil.com.br\www
    Trusted Zone: bancobrasil.com.br\www14
    Trusted Zone: bancobrasil.com.br\www2
    Trusted Zone: bb.com.br\www
    Trusted Zone: caixa.gov.br\imagem
    Trusted Zone: caixa.gov.br\internetbanking
    Trusted Zone: caixa.gov.br\www
    TCP: DhcpNameServer = 10.4.65.16
    FF - ProfilePath - c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\
    FF - prefs.js: browser.startup.homepage - 
    FF - ExtSQL: 2013-06-18 08:37; [Você precisa estar registrado e conectado para ver este link.]; c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\helperframework@zonemedia.com.xpi
    FF - ExtSQL: 2013-06-18 08:38; [Você precisa estar registrado e conectado para ver este link.]; c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\ffxtlbr@babylon.com
    .
    - - - - ORFÃOS REMOVIDOS - - - -
    .
    HKLM-Run-update_apc - c:\arquivos de programas\Internet Explorer\Updater.exe
    AddRemove-Cartoon Maker1.7 - c:\documents and settings\f000847\Meus documentos\Nova pasta\uninstall.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Você precisa estar registrado e conectado para ver este link.]
    Rootkit scan 2013-07-10 16:51
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Procurando processos ocultos ... 
    .
    Procurando entradas auto inicializáveis ocultas ... 
    .
    Procurando ficheiros/arquivos ocultos ... 
    .
    Varredura completada com sucesso
    arquivos/ficheiros ocultos: 0
    .
    **************************************************************************
    .
    --------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\1FDE42FC632E233438BCC407A1B9BC0F\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "107"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\2451D69CF585D214C8A52004DB1A469B\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "106"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\256917180E811B74A9218FB20F574DBD\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "105"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\484CA1D2615EC8048852CA1B3C65CAA7\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "101"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\4C9878626E35BDD4F833D8F0E900B0AE\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "100"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\5E903427217EC6249BD46B4B52112CF9\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "104"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\7A7FFB02FB4E7E4488243D1990374C9B\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="Microsoft's Silverlight Installation [1]"
    "100"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\82B28DCEEB84C6245BB5E60C22162658\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "108"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\BE7C28545F39D804F992A5B51E7E8654\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "103"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\DE6BA3F2C1597EC4A89C5864DFFCF1A5\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "102"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\46EAC7482DC4D2B4FA0079F85F340164\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";"
    "2"=";"
    "3"=";"
    "4"=";"
    "5"=";"
    "6"=";"
    "7"=";"
    "8"=";"
    "9"=";"
    "10"=";"
    "11"=";"
    "12"=";"
    "13"=";"
    "14"=";"
    "15"=";"
    "16"=";"
    "17"=";"
    "18"=";"
    "19"=";"
    "20"=";"
    "21"=";"
    "22"=";"
    "23"=";"
    "24"=";"
    "25"=";"
    "26"=";"
    "27"=";"
    "28"=";"
    "29"=";"
    "30"=";"
    "31"=";"
    "32"=";"
    "33"=";"
    "34"=";"
    "35"=";"
    "36"=";"
    "37"=";"
    "38"=";"
    "39"=";"
    "40"=";"
    "41"=";"
    "42"=";"
    "43"=";"
    "44"=";"
    "45"=";"
    "46"=";"
    "47"=";"
    "48"=";"
    "49"=";"
    "50"=";"
    "51"=";"
    "52"=";"
    "53"=";"
    "54"=";"
    "55"=";"
    "56"=";"
    "57"=";"
    "58"=";"
    "59"=";"
    "60"=";"
    "61"=";"
    "62"=";"
    "63"=";"
    "64"=";"
    "65"=";"
    "66"=";"
    "67"=";"
    "68"=";"
    "69"=";"
    "70"=";"
    "71"=";"
    "72"=";"
    "73"=";"
    "74"=";"
    "75"=";"
    "76"=";"
    "77"=";"
    "78"=";"
    "79"=";"
    "80"=";"
    "81"=";"
    "82"=";"
    "83"=";"
    "84"=";"
    "85"=";"
    "86"=";"
    "87"=";"
    "88"=";"
    "89"=";"
    "90"=";"
    "91"=";"
    "92"=";"
    "93"=";"
    "94"=";"
    "95"=";"
    "96"=";"
    "97"=";"
    "98"=";"
    "99"=";"
    "100"=";"
    "101"=";"
    "102"=";"
    "103"=";"
    "104"=";"
    "105"=";"
    "106"=";"
    "107"=";"
    "108"=";"
    "109"=";"
    "110"=";"
    "111"=";"
    "112"=";"
    "113"=";"
    "114"=";"
    "115"=";"
    "116"=";"
    "117"=";"
    "118"=";"
    "119"=";"
    "120"=";"
    "121"=";"
    "122"=";"
    "123"=";"
    "124"=";"
    "125"=";"
    "126"=";"
    "127"=";"
    "128"=";"
    "129"=";"
    "130"=";"
    "131"=";"
    "132"=";"
    "133"=";"
    "134"=";"
    "135"=";"
    "136"=";"
    "137"=";"
    "138"=";"
    "139"=";"
    "140"=";"
    "141"=";"
    "142"=";"
    "143"=";"
    "144"=";"
    "145"=";"
    "146"=";"
    "147"=";"
    "148"=";"
    "149"=";"
    "150"=";"
    "151"=";"
    "152"=";"
    "153"=";"
    "154"=";"
    "155"=";"
    "156"=";"
    "157"=";"
    "158"=";"
    "159"=";"
    "160"=";"
    "161"=";"
    "162"=";"
    "163"=";"
    "164"=";"
    "165"=";"
    "166"=";"
    "167"=";"
    "168"=";"
    "169"=";"
    "170"=";"
    "171"=";"
    "172"=";"
    "173"=";"
    "174"=";"
    "175"=";"
    "176"=";"
    "177"=";"
    "178"=";"
    "179"=";"
    "180"=";"
    "181"=";"
    "182"=";"
    "183"=";"
    "184"=";"
    "185"=";"
    "186"=";"
    "187"=";"
    "188"=";"
    "189"=";"
    "190"=";"
    "191"=";"
    "192"=";"
    "193"=";"
    "194"=";"
    "195"=";"
    "196"=";"
    "197"=";"
    "198"=";"
    "199"=";"
    "200"=";"
    "201"=";"
    "202"=";"
    "203"=";"
    "204"=";"
    "205"=";"
    "206"=";"
    "207"=";"
    "208"=";"
    "209"=";"
    "210"=";"
    "211"=";"
    "212"=";"
    "213"=";"
    "214"=";"
    "215"=";"
    "216"=";"
    "217"=";"
    "218"=";"
    "219"=";"
    "220"=";"
    "221"=";"
    "222"=";"
    "223"=";"
    "224"=";"
    "225"=";"
    "226"=";"
    "227"=";"
    "228"=";"
    "229"=";"
    "230"=";"
    "231"=";"
    "232"=";"
    "233"=";"
    "234"=";"
    "235"=";"
    "236"=";"
    "237"=";"
    "238"=";"
    "239"=";"
    "240"=";"
    "241"=";"
    "242"=";"
    "243"=";"
    "244"=";"
    "245"=";"
    "246"=";"
    "247"=";"
    "248"=";"
    "249"=";"
    "250"=";"
    "251"=";"
    "252"=";"
    "253"=";"
    "254"=";"
    "255"=";"
    "256"=";"
    "257"=";"
    "258"=";"
    "259"=";"
    "260"=";"
    "261"=";"
    "262"=";"
    "263"=";"
    "264"=";"
    "265"=";"
    "266"=";"
    "267"=";"
    "268"=";"
    "269"=";"
    "270"=";"
    "271"=";"
    "272"=";"
    "273"=";"
    "274"=";"
    "275"=";"
    "276"=";"
    "277"=";"
    "278"=";"
    "279"=";"
    "280"=";"
    "281"=";"
    "282"=";"
    "283"=";"
    "284"=";"
    "285"=";"
    "286"=";"
    "287"=";"
    "288"=";"
    "289"=";"
    "290"=";"
    "291"=";"
    "292"=";"
    "293"=";"
    "294"=";"
    "295"=";"
    "296"=";"
    "297"=";"
    "298"=";"
    "299"=";"
    "300"=";"
    "301"=";"
    "302"=";"
    "303"=";"
    "304"=";"
    "305"=";"
    "306"=";"
    "307"=";"
    "308"=";"
    "309"=";"
    "310"=";"
    "311"=";"
    "312"=";"
    "313"=";"
    "314"=";"
    "315"=";"
    "316"=";"
    "317"=";"
    "318"=";"
    "319"=";"
    "320"=";"
    "321"=";"
    "322"=";"
    "323"=";"
    "324"=";"
    "325"=";"
    "326"=";"
    "327"=";"
    "328"=";"
    "329"=";"
    "330"=";"
    "331"=";"
    "332"=";"
    "333"=";"
    "334"=";"
    "335"=";"
    "336"=";"
    "337"=";"
    "338"=";"
    "339"=";"
    "340"=";"
    "341"=";"
    "342"=";"
    "343"=";"
    "344"=";"
    "345"=";"
    "346"=";"
    "347"=";"
    "348"=";"
    "349"=";"
    "350"=";"
    "351"=";"
    "352"=";"
    "353"=";"
    "354"=";"
    "355"=";"
    "356"=";"
    "357"=";"
    "358"=";"
    "359"=";"
    "360"=";"
    "361"=";"
    "362"=";"
    "363"=";"
    "364"=";"
    "365"=";"
    "366"=";"
    "367"=";"
    "368"=";"
    "369"=";"
    "370"=";"
    "371"=";"
    "372"=";"
    "373"=";"
    "374"=";"
    "375"=";"
    "376"=";"
    "377"=";"
    "378"=";"
    "379"=";"
    "380"=";"
    "381"=";"
    "382"=";"
    "383"=";"
    "384"=";"
    "385"=";"
    "386"=";"
    "387"=";"
    "388"=";"
    "389"=";"
    "390"=";"
    "391"=";"
    "392"=";"
    "393"=";"
    "394"=";"
    "395"=";"
    "396"=";"
    "397"=";"
    "398"=";"
    "399"=";"
    "400"=";"
    "401"=";"
    "402"=";"
    "403"=";"
    "404"=";"
    "405"=";"
    "406"=";"
    "407"=";"
    "408"=";"
    "409"=";"
    "410"=";"
    "411"=";"
    "412"=";"
    "413"=";"
    "414"=";"
    "415"=";"
    "416"=";"
    "417"=";"
    "418"=";"
    "419"=";"
    "420"=";"
    "421"=";"
    "422"=";"
    "423"=";"
    "424"=";"
    "425"=";"
    "426"=";"
    "427"=";"
    "428"=";"
    "429"=";"
    "430"=";"
    "431"=";"
    "432"=";"
    "433"=";"
    "434"=";"
    "435"=";"
    "436"=";"
    "437"=";"
    "438"=";"
    "439"=";"
    "440"=";"
    "441"=";"
    "442"=";"
    "443"=";"
    "444"=";"
    "445"=";"
    "446"=";"
    "447"=";"
    "448"=";"
    "449"=";"
    "450"=";"
    "451"=";"
    "452"=";"
    "453"=";"
    "454"=";"
    "455"=";"
    "456"=";"
    "457"=";"
    "458"=";"
    "459"=";"
    "460"=";"
    "461"=";"
    "462"=";"
    "463"=";"
    "464"=";"
    "465"=";"
    "466"=";"
    "467"=";"
    "468"=";"
    "469"=";"
    "470"=";"
    "471"=";"
    "472"=";"
    "473"=";"
    "474"=";"
    "475"=";"
    "476"=";"
    "477"=";"
    "478"=";"
    "479"=";"
    "480"=";"
    "481"=";"
    "482"=";"
    "483"=";"
    "484"=";"
    "485"=";"
    "486"=";"
    "487"=";"
    "488"=";"
    "489"=";"
    "490"=";"
    "491"=";"
    "492"=";"
    "493"=";"
    "494"=";"
    "495"=";"
    "496"=";"
    "497"=";"
    "498"=";"
    "499"=";"
    "500"=";"
    "501"=";"
    "502"=";"
    "503"=";"
    "504"=";"
    "505"=";"
    "506"=";"
    "507"=";"
    "508"=";"
    "509"=";"
    "510"=";"
    "511"=";"
    "512"=";"
    "513"=";"
    "514"=";"
    "515"=";"
    "516"=";"
    "517"=";"
    "518"=";"
    "519"=";"
    "520"=";"
    "521"=";"
    "522"=";"
    "523"=";"
    "524"=";"
    "525"=";"
    "526"=";"
    "527"=";"
    "528"=";"
    "529"=";"
    "530"=";"
    "531"=";"
    "532"=";"
    "533"=";"
    "534"=";"
    "535"=";"
    "536"=";"
    "537"=";"
    "538"=";"
    "539"=";"
    "540"=";"
    "541"=";"
    "542"=";"
    "543"=";"
    "544"=";"
    "545"=";"
    "546"=";"
    "547"=";"
    "548"=";"
    "549"=";"
    "550"=";"
    "551"=";"
    "552"=";"
    "553"=";"
    "554"=";"
    "555"=";"
    "556"=";"
    "557"=";"
    "558"=";"
    "559"=";"
    "560"=";"
    "561"=";"
    "562"=";"
    "563"=";"
    "564"=";"
    "565"=";"
    "566"=";"
    "567"=";"
    "568"=";"
    "569"=";"
    "570"=";"
    "571"=";"
    "572"=";"
    "573"=";"
    "574"=";"
    "575"=";"
    "576"=";"
    "577"=";"
    "578"=";"
    "579"=";"
    "580"=";"
    "581"=";"
    "582"=";"
    "583"=";"
    "584"=";"
    "585"=";"
    "586"=";"
    "587"=";"
    "588"=";"
    "589"=";"
    "590"=";"
    "591"=";"
    "592"=";"
    "593"=";"
    "594"=";"
    "595"=";"
    "596"=";"
    "597"=";"
    "598"=";"
    "599"=";"
    "600"=";"
    "601"=";"
    "602"=";"
    "603"=";"
    "604"=";"
    "605"=";"
    "606"=";"
    "607"=";"
    "608"=";"
    "609"=";"
    "610"=";"
    "611"=";"
    "612"=";"
    "613"=";"
    "614"=";"
    "615"=";"
    "616"=";"
    "617"=";"
    "618"=";"
    "619"=";"
    "620"=";"
    "621"=";"
    "622"=";"
    "623"=";"
    "624"=";"
    "625"=";"
    "626"=";"
    "627"=";"
    "628"=";"
    "629"=";"
    "630"=";"
    "631"=";"
    "632"=";"
    "633"=";"
    "634"=";"
    "635"=";"
    "636"=";"
    "637"=";"
    "638"=";"
    "639"=";"
    "640"=";"
    "641"=";"
    "642"=";"
    "643"=";"
    "644"=";"
    "645"=";"
    "646"=";"
    "647"=";"
    "648"=";"
    "649"=";"
    "650"=";"
    "651"=";"
    "652"=";"
    "653"=";"
    "654"=";"
    "655"=";"
    "656"=";"
    "657"=";"
    "658"=";"
    "659"=";"
    "660"=";"
    "661"=";"
    "662"=";"
    "663"=";"
    "664"=";"
    "665"=";"
    "666"=";"
    "667"=";"
    "668"=";"
    "669"=";"
    "670"=";"
    "671"=";"
    "672"=";"
    "673"=";"
    "674"=";"
    "675"=";"
    "676"=";"
    "677"=";"
    "678"=";"
    "679"=";"
    "680"=";"
    "681"=";"
    "682"=";"
    "683"=";"
    "684"=";"
    "685"=";"
    "686"=";"
    "687"=";"
    "688"=";"
    "689"=";"
    "690"=";"
    "691"=";"
    "692"=";"
    "693"=";"
    "694"=";"
    "695"=";"
    "696"=";"
    "697"=";"
    "698"=";"
    "699"=";"
    "700"=";"
    "701"=";"
    "702"=";"
    "703"=";"
    "704"=";"
    "705"=";"
    "706"=";"
    "707"=";"
    "708"=";"
    "709"=";"
    "710"=";"
    "711"=";"
    "712"=";"
    "713"=";"
    "714"=";"
    "715"=";"
    "716"=";"
    "717"=";"
    "718"=";"
    "719"=";"
    "720"=";"
    "721"=";"
    "722"=";"
    "723"=";"
    "724"=";"
    "725"=";"
    "726"=";"
    "727"=";"
    "728"=";"
    "729"=";"
    "730"=";"
    "731"=";"
    "732"=";"
    "733"=";"
    "734"=";"
    "735"=";"
    "736"=";"
    "737"=";"
    "738"=";"
    "739"=";"
    "740"=";"
    "741"=";"
    "742"=";"
    "743"=";"
    "744"=";"
    "745"=";"
    "746"=";"
    "747"=";"
    "748"=";"
    "749"=";"
    "750"=";"
    "751"=";"
    "752"=";"
    "753"=";"
    "754"=";"
    "755"=";"
    "756"=";"
    "757"=";"
    "758"=";"
    "759"=";"
    "760"=";"
    "761"=";"
    "762"=";"
    "763"=";"
    "764"=";"
    "765"=";"
    "766"=";"
    "767"=";"
    "768"=";"
    "769"=";"
    "770"=";"
    "771"=";"
    "772"=";"
    "773"=";"
    "774"=";"
    "775"=";"
    "776"=";"
    "777"=";"
    "778"=";"
    "779"=";"
    "780"=";"
    "781"=";"
    "782"=";"
    "783"=";"
    "784"=";"
    "785"=";"
    "786"=";"
    "787"=";"
    "788"=";"
    "789"=";"
    "790"=";"
    "791"=";"
    "792"=";"
    "793"=";"
    "794"=";"
    "795"=";"
    "796"=";"
    "797"=";"
    "798"=";"
    "799"=";"
    "800"=";"
    "801"=";"
    "802"=";"
    "803"=";"
    "804"=";"
    "805"=";"
    "806"=";"
    "807"=";"
    "808"=";"
    "809"=";"
    "810"=";"
    "811"=";"
    "812"=";"
    "813"=";"
    "814"=";"
    "815"=";"
    "816"=";"
    "817"=";"
    "818"=";"
    "819"=";"
    "820"=";"
    "821"=";"
    "822"=";"
    "823"=";"
    "824"=";"
    "825"=";"
    "826"=";"
    "827"=";"
    "828"=";"
    "829"=";"
    "830"=";"
    "831"=";"
    "832"=";"
    "833"=";"
    "834"=";"
    "835"=";"
    "836"=";"
    "837"=";"
    "838"=";"
    "839"=";"
    "840"=";"
    "841"=";"
    "842"=";"
    "843"=";"
    "844"=";"
    "845"=";"
    "846"=";"
    "847"=";"
    "848"=";"
    "849"=";"
    "850"=";"
    "851"=";"
    "852"=";"
    "853"=";"
    "854"=";"
    "855"=";"
    "856"=";"
    "857"=";"
    "858"=";"
    "859"=";"
    "860"=";"
    "861"=";"
    "862"=";"
    "863"=";"
    "864"=";"
    "865"=";"
    "866"=";"
    "867"=";"
    "868"=";"
    "869"=";"
    "870"=";"
    "871"=";"
    "872"=";"
    "873"=";"
    "874"=";"
    "875"=";"
    "876"=";"
    "877"=";"
    "878"=";"
    "879"=";"
    "880"=";"
    "881"=";"
    "882"=";"
    "883"=";"
    "884"=";"
    "885"=";"
    "886"=";"
    "887"=";"
    "888"=";"
    "889"=";"
    "890"=";"
    "891"=";"
    "892"=";"
    "893"=";"
    "894"=";"
    "895"=";"
    "896"=";"
    "897"=";"
    "898"=";"
    "899"=";"
    "900"=";"
    "901"=";"
    "902"=";"
    "903"=";"
    "904"=";"
    "905"=";"
    "906"=";"
    "907"=";"
    "908"=";"
    "909"=";"
    "910"=";"
    "911"=";"
    "912"=";"
    "913"=";"
    "914"=";"
    "915"=";"
    "916"=";"
    "917"=";"
    "918"=";"
    "919"=";"
    "920"=";"
    "921"=";"
    "922"=";"
    "923"=";"
    "924"=";"
    "925"=";"
    "926"=";"
    "927"=";"
    "928"=";"
    "929"=";"
    "930"=";"
    "931"=";"
    "932"=";"
    "933"=";"
    "934"=";"
    "935"=";"
    "936"=";"
    "937"=";"
    "938"=";"
    "939"=";"
    "940"=";"
    "941"=";"
    "942"=";"
    "943"=";"
    "944"=";"
    "945"=";"
    "946"=";"
    "947"=";"
    "948"=";"
    "949"=";"
    "950"=";"
    "951"=";"
    "952"=";"
    "953"=";"
    "954"=";"
    "955"=";"
    "956"=";"
    "957"=";"
    "958"=";"
    "959"=";"
    "960"=";"
    "961"=";"
    "962"=";"
    "963"=";"
    "964"=";"
    "965"=";"
    "966"=";"
    "967"=";"
    "968"=";"
    "969"=";"
    "970"=";"
    "971"=";"
    "972"=";"
    "973"=";"
    "974"=";"
    "975"=";"
    "976"=";"
    "977"=";"
    "978"=";"
    "979"=";"
    "980"=";"
    "981"=";"
    "982"=";"
    "983"=";"
    "984"=";"
    "985"=";"
    "986"=";"
    "987"=";"
    "988"=";"
    "989"=";"
    "990"=";"
    "991"=";"
    "992"=";"
    "993"=";"
    "994"=";"
    "995"=";"
    "996"=";"
    "997"=";"
    "998"=";"
    "999"=";"
    "1000"=";"
    "1001"=";"
    "1002"=";"
    "1003"=";"
    "1004"=";"
    "1005"=";"
    "1006"=";"
    "1007"=";"
    "1008"=";"
    "1009"=";"
    "1010"=";"
    "1011"=";"
    "1012"=";"
    "1013"=";"
    "1014"=";"
    "1015"=";"
    "1016"=";"
    "1017"=";"
    "1018"=";"
    "1019"=";"
    "1020"=";"
    "1021"=";"
    "1022"=";"
    "1023"=";"
    "1024"=";"
    "1025"=";"
    "1026"=";"
    "1027"=";"
    "1028"=";"
    "1029"=";"
    "1030"=";"
    "1031"=";"
    "1032"=";"
    "1033"=";"
    "1034"=";"
    "1035"=";"
    "1036"=";"
    "1037"=";"
    "1038"=";"
    "1039"=";"
    "1040"=";"
    "1041"=";"
    "1042"=";"
    "1043"=";"
    "1044"=";"
    "1045"=";"
    "1046"=";"
    "1047"=";"
    "1048"=";"
    "1049"=";"
    "1050"=";"
    "1051"=";"
    "1052"=";"
    "1053"=";"
    "1054"=";"
    "1055"=";"
    "1056"=";"
    "1057"=";"
    "1058"=";"
    "1059"=";"
    "1060"=";"
    "1061"=";"
    "1062"=";"
    "1063"=";"
    "1064"=";"
    "1065"=";"
    "1066"=";"
    "1067"=";"
    "1068"=";"
    "1069"=";"
    "1070"=";"
    "1071"=";"
    "1072"=";"
    "1073"=";"
    "1074"=";"
    "1075"=";"
    "1076"=";"
    "1077"=";"
    "1078"=";"
    "1079"=";"
    "1080"=";"
    "1081"=";"
    "1082"=";"
    "1083"=";"
    "1084"=";"
    "1085"=";"
    "1086"=";"
    "1087"=";"
    "1088"=";"
    "1089"=";"
    "1090"=";"
    "1091"=";"
    "1092"=";"
    "1093"=";"
    "1094"=";"
    "1095"=";"
    "1096"=";"
    "1097"=";"
    "1098"=";"
    "1099"=";"
    "1100"=";"
    "1101"=";"
    "1102"=";"
    "1103"=";"
    "1104"=";"
    "1105"=";"
    "1106"=";"
    "1107"=";"
    "1108"=";"
    "1109"=";"
    "1110"=";"
    "1111"=";"
    "1112"=";"
    "1113"=";"
    "1114"=";"
    "1115"=";"
    "1116"=";"
    "1117"=";"
    "1118"=";"
    "1119"=";"
    "1120"=";"
    "1121"=";"
    "1122"=";"
    "1123"=";"
    "1124"=";"
    "1125"=";"
    "1126"=";"
    "1127"=";"
    "1128"=";"
    "1129"=";"
    "1130"=";"
    "1131"=";"
    "1132"=";"
    "1133"=";"
    "1134"=";"
    "1135"=";"
    "1136"=";"
    "1137"=";"
    "1138"=";"
    "1139"=";"
    "1140"=";"
    "1141"=";"
    "1142"=";"
    "1143"=";"
    "1144"=";"
    "1145"=";"
    "1146"=";"
    "1147"=";"
    "1148"=";"
    "1149"=";"
    "1150"=";"
    "1151"=";"
    "1152"=";"
    "1153"=";"
    "1154"=";"
    "1155"=";"
    "1156"=";"
    "1157"=";"
    "1158"=";"
    "1159"=";"
    "1160"=";"
    "1161"=";"
    "1162"=";"
    "1163"=";"
    "1164"=";"
    "1165"=";"
    "1166"=";"
    "1167"=";"
    "1168"=";"
    "1169"=";"
    "1170"=";"
    "1171"=";"
    "1172"=";"
    "1173"=";"
    "1174"=";"
    "1175"=";"
    "1176"=";"
    "1177"=";"
    "1178"=";"
    "1179"=";"
    "1180"=";"
    "1181"=";"
    "1182"=";"
    "1183"=";"
    "1184"=";"
    "1185"=";"
    "1186"=";"
    "1187"=";"
    "1188"=";"
    "1189"=";"
    "1190"=";"
    "1191"=";"
    "1192"=";"
    "1193"=";"
    "1194"=";"
    "1195"=";"
    "1196"=";"
    "1197"=";"
    "1198"=";"
    "1199"=";"
    "1200"=";"
    "1201"=";"
    "1202"=";"
    "1203"=";"
    "1204"=";"
    "1205"=";"
    "1206"=";"
    "1207"=";"
    "1208"=";"
    "1209"=";"
    "1210"=";"
    "1211"=";"
    "1212"=";"
    "1213"=";"
    "1214"=";"
    "1215"=";"
    "1216"=";"
    "1217"=";"
    "1218"=";"
    "1219"=";"
    "1220"=";"
    "1221"=";"
    "1222"=";"
    "1223"=";"
    "1224"=";"
    "1225"=";"
    "1226"=";"
    "1227"=";"
    "1228"=";"
    "1229"=";"
    "1230"=";"
    "1231"=";"
    "1232"=";"
    "1233"=";"
    "1234"=";"
    "1235"=";"
    "1236"=";"
    "1237"=";"
    "1238"=";"
    "1239"=";"
    "1240"=";"
    "1241"=";"
    "1242"=";"
    "1243"=";"
    "1244"=";"
    "1245"=";"
    "1246"=";"
    "1247"=";"
    "1248"=";"
    "1249"=";"
    "1250"=";"
    "1251"=";"
    "1252"=";"
    "1253"=";"
    "1254"=";"
    "1255"=";"
    "1256"=";"
    "1257"=";"
    "1258"=";"
    "1259"=";"
    "1260"=";"
    "1261"=";"
    "1262"=";"
    "1263"=";"
    "1264"=";"
    "1265"=";"
    "1266"=";"
    "1267"=";"
    "1268"=";"
    "1269"=";"
    "1270"=";"
    "1271"=";"
    "1272"=";"
    "1273"=";"
    "1274"=";"
    "1275"=";"
    "1276"=";"
    "1277"=";"
    "1278"=";"
    "1279"=";"
    "1280"=";"
    "1281"=";"
    "1282"=";"
    "1283"=";"
    "1284"=";"
    "1285"=";"
    "1286"=";"
    "1287"=";"
    "1288"=";"
    "1289"=";"
    "1290"=";"
    "1291"=";"
    "1292"=";"
    "1293"=";"
    "1294"=";"
    "1295"=";"
    "1296"=";"
    "1297"=";"
    "1298"=";"
    "1299"=";"
    "1300"=";"
    "1301"=";"
    "1302"=";"
    "1303"=";"
    "1304"=";"
    "1305"=";"
    "1306"=";"
    "1307"=";"
    "1308"=";"
    "1309"=";"
    "1310"=";"
    "1311"=";"
    "1312"=";"
    "1313"=";"
    "1314"=";"
    "1315"=";"
    "1316"=";"
    "1317"=";"
    "1318"=";"
    "1319"=";"
    "1320"=";"
    "1321"=";"
    "1322"=";"
    "1323"=";"
    "1324"=";"
    "1325"=";"
    "1326"=";"
    "1327"=";"
    "1328"=";"
    "1329"=";"
    "1330"=";"
    "1331"=";"
    "1332"=";"
    "1333"=";"
    "1334"=";"
    "1335"=";"
    "1336"=";"
    "1337"=";"
    "1338"=";"
    "1339"=";"
    "1340"=";"
    "1341"=";"
    "1342"=";"
    "1343"=";"
    "1344"=";"
    "1345"=";"
    "1346"=";"
    "1347"=";"
    "1348"=";"
    "1349"=";"
    "1350"=";"
    "1351"=";"
    "1352"=";"
    "1353"=";"
    "1354"=";"
    "1355"=";"
    "1356"=";"
    "1357"=";"
    "1358"=";"
    "1359"=";"
    "1360"=";"
    "1361"=";"
    "1362"=";"
    "1363"=";"
    "1364"=";"
    "1365"=";"
    "1366"=";"
    "1367"=";"
    "1368"=";"
    "1369"=";"
    "1370"=";"
    "1371"=";"
    "1372"=";"
    "1373"=";"
    "1374"=";"
    "1375"=";"
    "1376"=";"
    "1377"=";"
    "1378"=";"
    "1379"=";"
    "1380"=";"
    "1381"=";"
    "1382"=";"
    "1383"=";"
    "1384"=";"
    "1385"=";"
    "1386"=";"
    "1387"=";"
    "1388"=";"
    "1389"=";"
    "1390"=";"
    "1391"=";"
    "1392"=";"
    "1393"=";"
    "1394"=";"
    "1395"=";"
    "1396"=";"
    "1397"=";"
    "1398"=";"
    "1399"=";"
    "1400"=";"
    "1401"=";"
    "1402"=";"
    "1403"=";"
    "1404"=";"
    "1405"=";"
    "1406"=";"
    "1407"=";"
    "1408"=";"
    "1409"=";"
    "1410"=";"
    "1411"=";"
    "1412"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"="READER8;[1]"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D7314F9862C648A4DB8BE2A5B47BE100\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="Microsoft's Silverlight Installation [1]"
    "1"=";1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\DC3BF90CC0D3D2F398A9A6D1762F70F3\SourceList\Media]
    @DACL=(02 0000)
    "DiskPrompt"="[1]"
    "1"=";"
    "100"=";"
    "101"=";"
    "102"=";"
    "103"=";"
    "104"=";"
    "105"=";"
    "106"=";"
    "107"=";"
    "108"=";"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
    .
    - - - - - - - > 'winlogon.exe'(1076)
    c:\arquivos de programas\GBPLUGIN\gbieh.dll
    c:\arquivos de programas\GbPlugin\gbiehBnb.dll
    c:\arquivos de programas\GbPlugin\gbiehCef.dll
    .
    - - - - - - - > 'explorer.exe'(1472)
    c:\windows\system32\ieframe.dll
    c:\arquivos de programas\GbPlugin\gbiehBnb.dll
    c:\windows\system32\webcheck.dll
    c:\arquivos de programas\GBPLUGIN\gbieh.dll
    c:\arquivos de programas\GbPlugin\gbiehCef.dll
    .
    Tempo para conclusão: 2013-07-10  16:52:37
    ComboFix-quarantined-files.txt  2013-07-10 19:52
    .
    Pré-execução: 12 pasta(s) 74.985.631.744 bytes disponíveis
    Pós execução: 13 pasta(s) 74.998.796.288 bytes disponíveis
    .
    - - End Of File - - F3789C676E1F5486AFF52186A2CD8FC6
    239FC8B1C26D5286165A956F5A98D8D7

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram em Sex Jul 12, 2013 10:26 am

    Bom Dia! Edvan

    |- Baixe: < [Você precisa estar registrado e conectado para ver este link.] > ( ... by Smeenk )

    |- Ou aqui! < [Você precisa estar registrado e conectado para ver este link.] >

    |- Salve-o no desktop!
    |- Desabilite seu antivírus!
    |- Para Windows 7,execute zoek.exe como administrador.

    autoclean;
    emptyalltemp;


    |- Copie e cole estas informações,em vermelho,no campo da ferramenta.
    |- Clique "Run Script".

    Zoek.exe is running now.
    Do not start any browser windows, they will be closed automatically.
    Please wait! This window will close when finished.
    A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log
    |- Surgirão estas informações,pedindo-lhe que aguarde o relatório.

    [Você precisa estar registrado e conectado para ver esta imagem.]

    |- Aceite e/ou confirme o reboot!

    zoek.hta failed by unknown error.
    Restart computer, and try again.
    |- Ps: Ao obter algum erro,reinicie o PC e execute,novamente,a ferramenta.
    |- Poste o relatório,que estará em C:\zoek-results.txt <<

    A+

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan em Sex Jul 12, 2013 4:58 pm

    Zoek.exe Version 4.0.0.4 Updated 10-July-2013
    Tool run by f000847 on 12/07/2013 at 17:49:47,10.
    Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
    Running in: Normal Mode Internet Access Detected

    ==== System Restore Info ======================

    12/07/2013 17:50:12 Zoek.exe System Restore Point Created Succesfully.

    ==== Deleting CLSID Registry Keys ======================


    ==== Deleting CLSID Registry Values ======================


    ==== Deleting Services ======================


    ==== Deleting Files \ Folders ======================

    "C:\Documents and Settings\f000847\Dados de aplicativos\desktop.ini" deleted
    "C:\WINDOWS\002702_.tmp" deleted
    "C:\WINDOWS\SET25.tmp" deleted
    "C:\WINDOWS\SET3.tmp" deleted
    "C:\WINDOWS\SET4.tmp" deleted
    "C:\WINDOWS\SET8.tmp" deleted
    "C:\WINDOWS\System32\SET1C4.tmp" deleted
    "C:\WINDOWS\System32\SET1CD.tmp" deleted
    "C:\WINDOWS\System32\SET1CE.tmp" deleted
    "C:\WINDOWS\System32\SET1CF.tmp" deleted
    "C:\WINDOWS\System32\SET1D0.tmp" deleted
    "C:\WINDOWS\System32\SET1D1.tmp" deleted
    "C:\WINDOWS\System32\SET1D2.tmp" deleted
    "C:\WINDOWS\System32\SET1D3.tmp" deleted
    "C:\WINDOWS\System32\SET1D4.tmp" deleted
    "C:\WINDOWS\System32\SET1D5.tmp" deleted
    "C:\WINDOWS\System32\SET1D6.tmp" deleted
    "C:\WINDOWS\System32\SET1D7.tmp" deleted
    "C:\WINDOWS\System32\SET1D8.tmp" deleted
    "C:\WINDOWS\System32\SET1D9.tmp" deleted
    "C:\WINDOWS\System32\SET1DA.tmp" deleted
    "C:\WINDOWS\System32\SET1E9.tmp" deleted
    "C:\WINDOWS\System32\SET1F2.tmp" deleted
    "C:\WINDOWS\System32\SET1F3.tmp" deleted
    "C:\WINDOWS\System32\SET1F4.tmp" deleted
    "C:\WINDOWS\System32\SET1F5.tmp" deleted
    "C:\WINDOWS\System32\SET1F6.tmp" deleted
    "C:\WINDOWS\System32\SET1F7.tmp" deleted
    "C:\WINDOWS\System32\SET1F8.tmp" deleted
    "C:\WINDOWS\System32\SET1F9.tmp" deleted
    "C:\WINDOWS\System32\SET1FA.tmp" deleted
    "C:\WINDOWS\System32\SET1FB.tmp" deleted
    "C:\WINDOWS\System32\SET1FC.tmp" deleted
    "C:\WINDOWS\System32\SET1FD.tmp" deleted
    "C:\WINDOWS\System32\SET1FE.tmp" deleted
    "C:\WINDOWS\System32\SET1FF.tmp" deleted
    "C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\searchplugins\BrowserDefender.xml" deleted
    "C:\Arquivos de programas\MyPC Backup" deleted

    ==== Firefox Extensions ======================

    ProfilePath: C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default
    - Undetermined - %ProfilePath%\extensions\data
    - Modulo de Seguranca - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}
    - Adicional de Seguranca CAIXA - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886D}

    ProfilePath: C:\Documents and Settings\Fun0131\Dados de aplicativos\Mozilla\Firefox\Profiles\z4e8s4wm.default
    - Modulo de Seguranca - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

    ==== Firefox Plugins ======================

    Profilepath: C:\Documents and Settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default
    ABCB4A6EAB701C629378255ABCB308E5 - C:\Arquivos de programas\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
    D7324EB1EDCB8990F8522DE0311359E9 - C:\WINDOWS\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
    02C317A415A91112EDEF07AAC78AF6D5 - C:\Arquivos de programas\Google\Update\1.3.21.149\npGoogleUpdate3.dll - Google Update
    3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
    F833DD5D8F959819F44BC98F47B1B6BB - C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
    65D09D8BC91D74C8800725EB33D1EE1B - C:\Arquivos de programas\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
    36A0F250C766D27BFE5A953C1A65B696 - C:\Arquivos de programas\Microsoft Silverlight\5.0.61118.0\npctrl.dll - Silverlight Plug-In
    CF4ABE599858E10EEB911E16FBCFD87D - C:\Arquivos de programas\Windows Media Player\npdrmv2.dll - Microsoft® DRM
    76E34EA1089E92709C5725407B565DA1 - C:\Arquivos de programas\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
    02A4A41FAC9BF96155B3E8068D1DF4B6 - C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
    64CE864482A941C006AC430640DE4DB3 - C:\Arquivos de programas\Microsoft Silverlight\5.0.61118.0\npctrlui.dll - Microsoft® Silverlight
    F9174E52953C2EDB35E4E634F6228F66 - C:\WINDOWS\system32\npptools.dll - Sistema operacional Microsoft® Windows®


    ==== Set IE to Default ======================

    Old Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.google.com/"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"="http://www.google.com/"

    New Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.google.com/"
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
    {483830EE-A4CD-4b71-B0A3-3D82E62A6909} Unknown  Url="Not_Found"
    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21082\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} deleted successfully

    ==== Deleting CLSID Registry Values ======================


    ==== Empty IE Cache ======================

    C:\Documents and Settings\f000847\Meus documentos\Outros arquivos\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\Documents and Settings\f000847\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
    C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\itaqxty1.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    C:\Documents and Settings\f000847\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\WINDOWS\Temp successfully emptied
    C:\DOCUME~1\f000847\CONFIG~1\Temp successfully emptied

    ==== Empty Recycle Bin ======================

    C:\RECYCLER successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Documents and Settings\f000847\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted
    "C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted

    ==== EOF on 12/07/2013 at 17:56:48,89 ======================

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram em Sab Jul 13, 2013 8:19 am

    Bom Dia! Edvan

    c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\[Você precisa estar registrado e conectado para ver este link.]
    c:\documents and settings\f000847\Dados de aplicativos\Mozilla\Firefox\Profiles\vc3ld4n3.default\extensions\[Você precisa estar registrado e conectado para ver este link.]

    ######

    |- Vá a pasta do Mozilla e,em "extensions",procure estes destaques e delete-as

    -/-

    |- Baixe: |[Você precisa estar registrado e conectado para ver este link.]| ( ... de Xplode )

    [Você precisa estar registrado e conectado para ver esta imagem.]

    |- Estando na página,clique na seta verde para o download
    |- Salve-a em um local conveniente! ( desktop! )
    |- Feche aplicativos que estejam abertos.

    [Você precisa estar registrado e conectado para ver este link.]

    |- Execute-a!
    |- Com as duas checkbox marcadas! 
    |- Clique "Run".
    |- Caso queira,poste o log.

    A+

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Edvan em Seg Jul 15, 2013 4:57 pm

    Pronto amigo, mais um pc limpo.hehe



    # DelFix v10.3 - Logfile created 15/07/2013 at 17:56:45
    # Updated 08/06/2013 by Xplode
    # Username : f000847 - FUN0066
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

    ~ Removing disinfection tools ...

    Deleted : C:\Qoobox
    Deleted : C:\JRT
    Deleted : C:\ZHP
    Deleted : C:\Arquivos de programas\ZHPDiag
    Deleted : C:\AdwCleaner[S1].txt
    Deleted : C:\ComboFix.txt
    Deleted : C:\PhysicalDisk0_MBR.bin
    Deleted : C:\zoek-results.log
    Deleted : C:\Documents and Settings\f000847\Desktop\ComboFix.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\JRT.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\MBRCheck.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPDiag.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPDiag2.exe
    Deleted : C:\Documents and Settings\f000847\Desktop\ZHPFix.lnk
    Deleted : C:\Documents and Settings\f000847\Desktop\zoek.exe
    Deleted : C:\Documents and Settings\f000847\Meus documentos\Downloads\adwcleaner.exe
    Deleted : C:\WINDOWS\grep.exe
    Deleted : C:\WINDOWS\PEV.exe
    Deleted : C:\WINDOWS\NIRCMD.exe
    Deleted : C:\WINDOWS\MBR.exe
    Deleted : C:\WINDOWS\SED.exe
    Deleted : C:\WINDOWS\SWREG.exe
    Deleted : C:\WINDOWS\SWSC.exe
    Deleted : C:\WINDOWS\SWXCACLS.exe
    Deleted : C:\WINDOWS\Zip.exe
    Deleted : HKLM\SOFTWARE\AdwCleaner
    Deleted : HKLM\SOFTWARE\Swearware
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

    ~ Cleaning system restore ...

    Deleted : RP #213 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #214 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #215 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #216 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #217 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #218 [Ponto de verificação do sistema | 05/20/2013 13:00:45]
    Deleted : RP #219 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #220 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #221 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #222 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #223 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #224 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #225 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #226 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #227 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #228 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #229 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #230 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #231 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #232 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #233 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #234 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #235 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #236 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #237 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #238 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #239 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #240 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #241 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #242 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #243 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #244 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #245 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #246 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #247 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #248 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #249 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #250 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #251 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #252 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #253 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #254 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #255 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #256 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #257 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #258 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #259 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #260 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #261 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #262 [P | 05/20/2013 13:00:46]
    Deleted : RP #263 [End of disinfection | 05/20/2013 13:00:46]
    Deleted : RP #264 [Ponto de verificação do sistema | 05/20/2013 13:00:46]
    Deleted : RP #265 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #266 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #267 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #268 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #269 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #270 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #271 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #272 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #273 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #274 [Ponto de verificação do sistema | 05/20/2013 13:00:47]
    Deleted : RP #275 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #276 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #277 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #278 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #279 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #280 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #281 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #282 [Ponto de verificação do sistema | 05/20/2013 13:00:48]
    Deleted : RP #283 [Ponto de verificação do sistema | 05/20/2013 13:00:49]
    Deleted : RP #284 [Ponto de verificação do sistema | 05/20/2013 13:00:49]
    Deleted : RP #285 [Instalado Java 7 Update 17 | 05/20/2013 13:00:50]
    Deleted : RP #286 [Ponto de verificação do sistema | 05/20/2013 13:00:50]
    Deleted : RP #287 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #288 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #289 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #290 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #291 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #292 [Ponto de verificação do sistema | 05/20/2013 13:00:51]
    Deleted : RP #293 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #294 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #295 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #296 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #297 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #298 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #299 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #300 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #301 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #302 [Ponto de verificação do sistema | 05/20/2013 13:00:52]
    Deleted : RP #303 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #304 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #305 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #306 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #307 [Instalado Java 7 Update 21 | 05/20/2013 13:00:53]
    Deleted : RP #308 [P | 05/20/2013 13:00:53]
    Deleted : RP #309 [Windows Internet Explorer 8 Instalado. | 05/20/2013 13:00:53]
    Deleted : RP #310 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #311 [Ponto de verificação do sistema | 05/20/2013 13:00:53]
    Deleted : RP #312 [Removido Java(TM) 6 Update 31 | 05/20/2013 13:00:53]
    Deleted : RP #313 [Removido Java 7 Update 17 | 05/20/2013 13:00:53]
    Deleted : RP #314 [Removido Adobe Reader 8.1.0 - Português | 05/20/2013 13:00:54]
    Deleted : RP #315 [End of disinfection | 05/20/2013 13:00:57]
    Deleted : RP #316 [Instalado Java 7 Update 21 | 05/20/2013 13:03:17]
    Deleted : RP #317 [Ponto de verificação do sistema | 05/21/2013 14:17:53]
    Deleted : RP #318 [Ponto de verificação do sistema | 05/22/2013 15:18:23]
    Deleted : RP #319 [Ponto de verificação do sistema | 05/23/2013 15:20:11]
    Deleted : RP #320 [Ponto de verificação do sistema | 05/24/2013 19:02:11]
    Deleted : RP #321 [Ponto de verificação do sistema | 05/27/2013 15:15:16]
    Deleted : RP #322 [Ponto de verificação do sistema | 05/28/2013 15:17:03]
    Deleted : RP #323 [Ponto de verificação do sistema | 05/29/2013 15:17:39]
    Deleted : RP #324 [Ponto de verificação do sistema | 05/31/2013 10:50:06]
    Deleted : RP #325 [Ponto de verificação do sistema | 06/03/2013 10:47:26]
    Deleted : RP #326 [Ponto de verificação do sistema | 06/04/2013 13:39:37]
    Deleted : RP #327 [Ponto de verificação do sistema | 06/05/2013 15:16:59]
    Deleted : RP #328 [Ponto de verificação do sistema | 06/06/2013 15:50:55]
    Deleted : RP #329 [Ponto de verificação do sistema | 06/07/2013 16:23:59]
    Deleted : RP #330 [Ponto de verificação do sistema | 06/10/2013 11:27:45]
    Deleted : RP #331 [Ponto de verificação do sistema | 06/11/2013 13:09:04]
    Deleted : RP #332 [Ponto de verificação do sistema | 06/12/2013 13:12:18]
    Deleted : RP #333 [Ponto de verificação do sistema | 06/13/2013 15:19:30]
    Deleted : RP #334 [Ponto de verificação do sistema | 06/17/2013 11:40:48]
    Deleted : RP #335 [Ponto de verificação do sistema | 06/18/2013 12:57:35]
    Deleted : RP #336 [Ponto de verificação do sistema | 06/19/2013 13:18:03]
    Deleted : RP #337 [Ponto de verificação do sistema | 06/20/2013 15:49:44]
    Deleted : RP #338 [Ponto de verificação do sistema | 06/21/2013 16:16:45]
    Deleted : RP #339 [Ponto de verificação do sistema | 06/25/2013 11:23:02]
    Deleted : RP #340 [Removido Microsoft .NET Framework 2.0 Service Pack 2 | 06/26/2013 10:52:21]
    Deleted : RP #341 [Ponto de verificação do sistema | 06/27/2013 11:12:26]
    Deleted : RP #342 [Ponto de verificação do sistema | 06/28/2013 15:16:16]
    Deleted : RP #343 [Ponto de verificação do sistema | 07/01/2013 10:52:18]
    Deleted : RP #344 [Ponto de verificação do sistema | 07/02/2013 14:13:02]
    Deleted : RP #345 [Ponto de verificação do sistema | 07/03/2013 15:15:09]
    Deleted : RP #346 [Ponto de verificação do sistema | 07/04/2013 15:15:20]
    Deleted : RP #347 [Ponto de verificação do sistema | 07/05/2013 19:46:05]
    Deleted : RP #348 [Ponto de verificação do sistema | 07/08/2013 11:06:50]
    Deleted : RP #349 [Ponto de verificação do sistema | 07/09/2013 12:09:42]
    Deleted : RP #350 [Ponto de verificação do sistema | 07/10/2013 15:18:29]
    Deleted : RP #351 [Removido Java 7 Update 21 | 07/10/2013 19:40:56]
    Deleted : RP #352 [Instalado Java 7 Update 25 | 07/10/2013 19:41:28]
    Deleted : RP #353 [Ponto de verificação do sistema | 07/12/2013 15:16:08]
    Deleted : RP #354 [zoek.exe restore point | 07/12/2013 20:50:12]
    Deleted : RP #355 [Ponto de verificação do sistema | 07/15/2013 10:39:58]

    New restore point created !

    ########## - EOF - ##########

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por joram em Seg Jul 15, 2013 8:46 pm

    CASO RESOLVIDO!

    Necessitando novo auxílio para este computador,basta abrir "Novo Tópico" e relatar o problema.

    Conteúdo patrocinado

    Re: Pc infectado, pop up de propaganda aparecendo.

    Mensagem por Conteúdo patrocinado Hoje à(s) 8:35 am


      Data/hora atual: Sab Dez 03, 2016 8:35 am