![]() |
| |||||||
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| oi. soo meu computador está infectado. tem pop up a dizer que alguém está tentando atacar o meu sistema, através do envio de vírus e, em seguida, theres estes programas recomendados vírus popping up para mim instalar. Então, meu papel vai mudar para vermelho com um símbolo. Estou usando atualmente Spybot Search and Destroy e ad adware para varrer o meu computador, todos os dias. ela vai embora e volta algumas horas lters. Portanto, estou pensando como livrar-se da mesma forma que ele vai voltar. Logfile do HijackThis v1.99.1 Scan guardado em 4:20:15, em 12/24/2007 Plataforma: Windows XP SP2 (WinNT 5/01/2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Executando processos: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe c: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe C: \ WINDOWS \ system32 \ VTTimer.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ LVCOMSX.EXE C: \ Program Files \ Logitech \ Video \ LogiTray.exe C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ jusched.exe C: \ Program Files \ HP \ hpcoretech \ hpcmpmgr.exe C: \ WINDOWS \ system32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb1 0.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ MSN Messenger \ msnmsgr.exe C: \ Program Files \ AIM \ aim.exe C: \ Program Files \ Logitech \ Video \ FxSvr2.exe C: \ Program Files \ Logitech \ Desktop Messenger \ 8876480 \ Program \ LogitechDesktopMessenger. Exe C: \ Program Files \ Yahoo! \ Messenger \ ymsgr_tray.exe C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ jucheck.exe C: \ Program Files \ MSN Messenger \ usnsvc.exe C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ Arquivos de Programas \ Internet Explorer \ iexplore.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ HijackThis \ HijackThis.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, ProxyOverride = localhost O2 - BHO: (no name) - (0180A7AF-7449-4632-A705-09CB76186F0D) - (no arquivo) O2 - BHO: (no name) - (02478D38-C3F9-4efb-9B51-7695ECA05670) - (no arquivo) O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: (no name) - (1D4B1AF0-833A-AFE9-4B66-888DBA2582CD) - (no arquivo) O2 - BHO: (no name) - (3f711da5-eed1-496b-9ac7-870af3236ef5) - (no arquivo) O2 - BHO: (no name) - (56125AE0-2785-4E21-A200-6646C4FFB7FC) - \ O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ ssv.dll O2 - BHO: (no name) - (7A8D213D-2998-4DC2-A09F-4B91903292EF) - \ O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no arquivo) O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 2.1.615.5858 \ sw g.dll O2 - BHO: (no name) - (EAA38E9A-A84D-467A-9DFB-34CFEAC54F02) - \ O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe" O4 - HKLM \ .. \ Run: [PHIME2002ASync] C: \ WINDOWS \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / SYNC O4 - HKLM \ .. \ Run: [PHIME2002A] C: \ WINDOWS \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / IMEName O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe O4 - HKLM \ .. \ Run: [Symantec NetDriver Monitor] C: \ PROGRA ~ 1 \ SYMNET ~ 1 \ SNDMon.exe / Enterprise O4 - HKLM \ .. \ Run: [VTTimer] VTTimer.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [LVCOMSX] C: \ WINDOWS \ system32 \ LVCOMSX.EXE O4 - HKLM \ .. \ Run: [LogitechVideoRepair] C: \ Program Files \ Logitech \ Video \ ISStart.exe O4 - HKLM \ .. \ Run: [LogitechVideoTray] C: \ Program Files \ Logitech \ Video \ LogiTray.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [MP10_EnsureFileVer] C: \ WINDOWS \ inf \ Unregmp2.exe / EnsureFileVersions O4 - HKLM \ .. \ Run: [HP Component Manager] "C: \ Program Files \ HP \ hpcoretech \ hpcmpmgr.exe" O4 - HKLM \ .. \ Run: [HPDJ Taskbar Utility] C: \ WINDOWS \ system32 \ spool \ drivers \ w32x86 \ 3 \ hpztsb1 0.exe O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [msnmsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / background O4 - HKCU \ .. \ Run: [AIM] C: \ Program Files \ AIM \ aim.exe-cnetwait.odl O4 - HKCU \ .. \ Run: [LogitechSoftwareUpdate] "C: \ Program Files \ Logitech \ Video \ ManifestEngine.exe" boot O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet O4 - HKCU \ .. \ Run: [LDM] C: \ Program Files \ Logitech \ Desktop Messenger \ 8876480 \ Program \ BackWeb-8876480.exe O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Arquivos de Programas \ Spybot - Search & Destroy \ TeaTimer.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C: \ Program Files \ Logitech \ Desktop Messenger \ 8876480 \ Program \ LogitechDesktopMessenger. Exe O4 - Global Startup: Microsoft Office.lnk = C: \ Arquivos de Programas \ Microsoft Office \ Office10 \ Osa.exe O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_02 \ bin \ ssv.dll O9 - Extra button: Yahoo! Serviços - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll O9 - Extra button: AIM - (AC9E2541-2814-11d5-BC6D-00B0D0A1DE45) - C: \ Program Files \ AIM \ aim.exe O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ SpyBot ~ 1 \ SDHelper.dll O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @ Xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing) O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O11 - Options group: [INTERNATIONAL] International * O16 - DPF: (0742B9EF-8C83-41CA-BFBA-830A59E23533) (Microsoft Data Collection Control) -- https: / / support.microsoft.com / OAS / ActiveX / MSDcode.cab O16 - DPF: (1EF9F042-C2EB-4293-8213-474CAEEF531D) (TmHcmsX Controle) -- http://www.trendsecure.com/framework...ex/TmHcmsX.CAB O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O18 - Protocol: bwfile-8876480 - (9462A756-7B47-47BC-8C80-C34B9B80B32B) - C: \ Program Files \ Logitech \ Desktop Messenger \ 8876480 \ Program \ GAPlugProtocol-8876480.dll O18 - Protocol: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ MSNMES ~ 1 \ MSGRAP ~ 1.DLL O18 - Protocol: msnim - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ MSNMES ~ 1 \ MSGRAP ~ 1.DLL O20 - Winlogon Notify: gebaxxv - gebaxxv.dll (arquivo ausente) O20 - Winlogon Notify: igfxcui - C: \ WINDOWS \ SYSTEM32 \ igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C: \ WINDOWS \ system32 \ NavLogon.dll O20 - Winlogon Notify: pmkjh - C: \ WINDOWS \ system32 \ pmkjh.dll (arquivo ausente) O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ system32 \ WgaLogon.dll O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj.dll O21 - SSODL: mssql - (24D6EB4C-3C8C-4355-9CD5-4948138645A3) - C: \ WINDOWS \ mssql.dll O21 - SSODL: syscore - (372F9833-A2A9-4597-967D-9C4B6EC4121D) - C: \ WINDOWS \ syscore.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c: \ Program Files \ Common Files \ Symantec Shared \ Security Center \ SymWSC.exe Pls help. obrigado. |
|
#2
| |||
| |||
| obter um bom antivírus como o McAfee, que abrange spam, adawre, vírus, hackers, etc todos de uma vez, dissconnect da intetnet, desinstale todos os seus actuais protecção programas, instale o seu bom antivírus de escolha, atualização através da Internet (ele deve estar segura agora mcafee está instalado), faça uma varredura completa do sistema. |
|
#4
| ||||||||||||
| ||||||||||||
| que nunca que você não faça o download do programa recomendado Eu tive esse vírus antes, mas não tão grave, I didn't get a fixação ronda-lo como timed-lo apenas direita quando eu comprei meu computador novo anti virus que tens no momento? Avast Home Edition livre é bom
__________________
__________________
A temperatura dentro deste apple pie é superior a 1000 graus. Se eu apertar ele, um jacto de líquido Bramley maçã garoto vai para fora. Poderia ir à sua maneira, poderia ir mina. De qualquer forma, um de nós está a descer! Meu Sistema: Meu
|
|
#5
| |||
| |||
| O2 - BHO: (no name) - (0180A7AF-7449-4632-A705-09CB76186F0D) - (no arquivo) R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant = R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, CustomizeSearch = O2 - BHO: (no name) - (1D4B1AF0-833A-AFE9-4B66-888DBA2582CD) - (no arquivo) O2 - BHO: (no name) - (3f711da5-eed1-496b-9ac7-870af3236ef5) - (no arquivo) O2 - BHO: (no name) - (56125AE0-2785-4E21-A200-6646C4FFB7FC) - \ O2 - BHO: (no name) - (7A8D213D-2998-4DC2-A09F-4B91903292EF) - \ O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no arquivo) O2 - BHO: (no name) - (EAA38E9A-A84D-467A-9DFB-34CFEAC54F02) - \ O20 - Winlogon Notify: gebaxxv - gebaxxv.dll (arquivo ausente) Aqueles todos suspiscious olhar e deve ser removido (mas confirme com evilfantasy ou howardhopkinson primeiro) O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ system32 \ WgaLogon.dll <<<É o seu Windows Geniune? Como é que é exibida apenas quando quando uma cópia do Windows não é genuína. |
|
#6
| |||
| |||
| Olá ct122592. Se você ainda estão buscando ajuda, em seguida, siga estas instruções. Abrir HijackThis e selecione Fazer um sistema de verificação só então colocar uma marca de verificação ao lado: R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 O2 - BHO: (no name) - (0180A7AF-7449-4632-A705-09CB76186F0D) - (no arquivo) O2 - BHO: (no name) - (02478D38-C3F9-4efb-9B51-7695ECA05670) - (no arquivo) O2 - BHO: (no name) - (1D4B1AF0-833A-AFE9-4B66-888DBA2582CD) - (no arquivo) O2 - BHO: (no name) - (3f711da5-eed1-496b-9ac7-870af3236ef5) - (no arquivo) O2 - BHO: (no name) - (56125AE0-2785-4E21-A200-6646C4FFB7FC) - \ O2 - BHO: (no name) - (7A8D213D-2998-4DC2-A09F-4B91903292EF) - \ O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (no arquivo) O2 - BHO: (no name) - (EAA38E9A-A84D-467A-9DFB-34CFEAC54F02) - \ O20 - Winlogon Notify: gebaxxv - gebaxxv.dll (arquivo ausente) O20 - Winlogon Notify: pmkjh - C: \ WINDOWS \ system32 \ pmkjh.dll (arquivo ausente) Agora feche todas as janelas exceto para HijackThis e clique em Fix Checked. ---------- Faça o download CCleaner
Baixar SUPERAntiSpyware Free Edition (SAS)
Por favor, desinstalar / apagar a cópia do HijackThis que tem e fazer o download da nova versão e executar uma varredura com ele e postar o log. Download e renomear HijackThis (HJT)
---------- Próximo post adicione SUPERAntiSpyware log Nova HijackThis log |
|
#7
| |||
| |||
| Graças EvilFantasy para ajudar. SUPERAntiSpyware scan log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Produzido em 01/12/2008 às 00:51 Aplicação Versão: 3/9/1008 Core Rules Database Version: 3259 Trace Rules Database Version: 1270 Scan type: Complete Scan Total Scan Time: 00:37:53 Memória itens digitalizados: 537 Memória ameaças detectadas: 0 Secretaria itens digitalizados: 6842 Secretaria ameaças detectadas: 19 Arquivo itens digitalizados: 6768 Arquivo ameaças detectadas: 67 Adware.Tracking Cookie C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ colectivo-media [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ partner2profit [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ ad [2]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ atwola [2]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ xiti [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner@adopt.specificc lamber [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ html [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner@ar.atwola [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner@bridge.admarket local [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ windowsmedia [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner@ads.healthcare [1]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner@ads.adbrite [2]. Txt C: \ Documents and Settings \ HP_Owner \ Cookies \ hp_owner @ atdmt [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@a.websponso rs [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@ad.admarket lugar [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@ad.reunion [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ adknowledge [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@adopt.hbmed iapro [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@adopt.hotba r [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@ads.cc21414 2 [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@ath.belnk [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ atwola [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ banners [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ belnk [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ bigbanners [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@btg.btgrab [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@cts.metrics directo [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@dist.belnk [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ emarketmake rs [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@hits.clicka ndtrack [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ hurricanedi gitalmedia [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ nextag [2]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez @ offeroptimi Zer [1]. Txt C: \ Documents and Settings \ CatherineZ \ Cookies \ catherinez@server.cpms alcatrão [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@a.websponsors [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ adknowledge [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@adopt.hbmediapro [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@adopt.hotbar [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@ads.us.e-planning [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@ar.atwola [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@ath.belnk [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ atwola [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ azjmp [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@banner3.inet-traffic [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ banner [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ belnk [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ bigbanners [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@btg.btgrab [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ cassava [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@cts.metricsdirect [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@dist.belnk [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ emarketmakers [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ exitexchange [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ interclick [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ leadgenetwork [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ linkstattrack [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ nextag [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ offeroptimizer [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@partypoker.touchc larity [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@sav.coolsavings [1]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ web-nexus [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez @ WinFixer [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@www.azoogleads [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@www.riverbelle [2]. Txt C: \ Documents and Settings \ CatherineZ \ Local Settings \ Temp \ Cookies \ catherinez@www.tagworld [1]. Txt Trojan.WinAntiSpyware / WinAntiVirus 2006/2007 C: \ UWA7P \ quar C: \ WINDOWS \ .. \ UWA7P Trojan.VideoCach / Gen HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) \ 1.0 HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) \ 1.0 \ 0 HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) \ 1.0 \ 0 \ win32 HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) \ 1.0 \ FLAGS HKCR \ TypeLib \ (A8954909-1F0F-41A5-A7FA-3B376D69E226) \ 1.0 \ HELPDIR HKCR \ Interface \ (967A494A-6AEC-4555-9CAF-FA6EB00ACF91) HKCR \ Interface \ (967A494A-6AEC-4555-9CAF-FA6EB00ACF91) \ ProxyStubClsid HKCR \ Interface \ (967A494A-6AEC-4555-9CAF-FA6EB00ACF91) \ ProxyStubClsid32 HKCR \ Interface \ (967A494A-6AEC-4555-9CAF-FA6EB00ACF91) \ TypeLib HKCR \ Interface \ (967A494A-6AEC-4555-9CAF-FA6EB00ACF91) \ TypeLib # Version HKCR \ Interface \ (9692BE2F-EB8F-49D9-A11C-C24C1EF734D5) HKCR \ Interface \ (9692BE2F-EB8F-49D9-A11C-C24C1EF734D5) \ ProxyStubClsid HKCR \ Interface \ (9692BE2F-EB8F-49D9-A11C-C24C1EF734D5) \ ProxyStubClsid32 HKCR \ Interface \ (9692BE2F-EB8F-49D9-A11C-C24C1EF734D5) \ TypeLib HKCR \ Interface \ (9692BE2F-EB8F-49D9-A11C-C24C1EF734D5) \ TypeLib # Version Trojan.Net-MSV/VPS HKCR \ MSVPS.MSVPSApp HKCR \ MSVPS.MSVPSApp \ CLSID HKCR \ MSVPS.MSVPSApp \ Curvatura r i cant find hijackthis.exe, então eu não sei como fazer o último passo. Tudo que eu tenho é a nova versão do HJT instalado. |
|
#8
| |||
| |||
| Desinstalar / apagar HijackThis. É uma versão desatualizada. Em seguida, use as instruções que dei para instalar a nova versão. |
|
#9
| |||
| |||
| Ok thanks. |
|
#10
| |||
| |||
| E postar um novo log do HijackThis novo. |
![]() |
|
| Marcadores |
Similar Threads | ||||
| Fio | Thread Starter | Fórum | Respostas | Última postagem |
| Search Engine Redireciona para Anúncios, Cabo USB Causa CPU Shutdown, vírus Aviso Popups | Jacko2983 | Vírus, spyware e Segurança | 25 | 18. De agosto de 2009 18:16 |
| Cid popups | lazj | Vírus, spyware e Segurança | 8 | 15. De outubro de 2008 10:31 |
| Movendo Antecedentes XP | ashmehta | General Chat Software | 5 | 8. De maio de 2008 13:59 |
| Popups | shig | Vírus, spyware e Segurança | 1 | 18. De dezembro de 2007 08:42 |
| Thread Tools | |
| |