Remoção de vírus

Olá,

Estive retirando uns virus dos computadores da Lan House e tinha um worm chamado Brontok.p num deles e começou a detonar os arquivos no meu pendrive.

O Avira não conseguiu dar um jeito nele, e parece que o Antivirus da Microsoft conseguiu.

Fazia tempo que eu não via um virus infectando arquivos como esse.
 
win32.sality/AA e Win32.comficker

Bom novamente tive problemas com esses 2 "maledetos" e infelizmente os antivirus abaixo nao limpam decentemente esses danados, alguns nem detectam corretamente, alguns deletam outros so avisam !!

Avira
Avast File server
Panda security
Rising internet security

Bom como disse acima nenhum desses citados resolveu meus problemas nos 2 servidores w2003, foi entao que para minha surpresa que aquele Av guardado na gaveta (EZ etrust antivirus 2005) resolveu meus problemas, simplesmente limpou os arquivos infectados !!!


35536642.jpg



Antes que digam alguma coisa, os servidores estavam com AV atualizado, firewall e todos as atualizações !!!

Notei que o servidor web estava infectado graças ao meu linux (mandriva) com ClamAV mas esse tambem nao limpa ! ! ! O w32sality para quem nao conhece e uma verdadeira dor de cabeça, ele infecta os executaveis, desabilita o firewall, altera alguns serviços do windows, prejudica o funcionamento da maquina, altera o registro incluindo algumas chaves para dificultar sua remoção, se propaga rapidamente pela rede etc.. etc... Muita gente pode estar infectada e nem sabe !!!

mais informações sobre ele LINK


Olá,

Estive retirando uns virus dos computadores da Lan House e tinha um worm chamado Brontok.p num deles e começou a detonar os arquivos no meu pendrive.

O Avira não conseguiu dar um jeito nele, e parece que o Antivirus da Microsoft conseguiu.

Fazia tempo que eu não via um virus infectando arquivos como esse.

bom como tens lan creio que o USB disk security seria bem interessante pra ti !! programinha simples, leve e eficiente !! Com ele podes desativar o autorun (claro que podes fazer isso de outras varias formas tb), e tem outras opcoes interessantes !!!


aqui um cap dele !


71915816.jpg


antes que falem desse tema "argh" to no pc da minha noiva !

abs
 
Última edição:
ola Mr. Wolf!
Obrigado por me atender!!
ai vai o log do Mban!
Malwarebytes' Anti-Malware 1.41
Versão do banco de dados: 3100
Windows 5.1.2600 Service Pack 3

13/11/2009 09:56:50
mbam-log-2009-11-13 (09-56-45).txt

Tipo de Verificação: Completa (C:\|)
Objetos verificados: 217223
Tempo decorrido: 1 hour(s), 17 minute(s), 31 second(s)

Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 3
Valores do Registro infectados: 0
Ítens do Registro infectados: 0
Pastas infectadas: 13
Arquivos infectados: 636

Processos da Memória infectados:
(Nenhum ítem malicioso foi detectado)

Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)

Chaves do Registro infectadas:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> No action taken.

Valores do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Ítens do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Pastas infectadas:
C:\Arquivos de programas\Windows (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\_tmpEmblem (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\_tmpEmblem (Backdoor.Bot) -> Files: 761 -> No action taken.

Arquivos infectados:
C:\Arquivos de programas\Windows\Thumbs.db (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15Bgm10_3_br (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15Bgm10_3_br.rgz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15Data10_3_br.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15DataAI_br (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15DataAI_br.rgz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2007-01-15Ragexe10_3_br.rgz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-07-09DifData_bz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-07-09newdata_bz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-07-09_difdata_bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-07-09_newdata_bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-08-15Ragexe_Bz.rgz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-12-22Bgm_Bz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-12-22data_01_Bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-12-22data_02_Bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-12-22data_03_Bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2008-8-15scdata_Bz.gpf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\2009-01-30ro_ep12_br.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\binkw32.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\bRO_PatchNameless.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\cps.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\data.grf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\dbghelp.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\event.grf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\granny2.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\ijl15.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\image003.emz (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\licence.txt (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Mp3dec.asi (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Mss32.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Mssfast.m3d (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkcrypt.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkcrypt.sys (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkcrypt.vxd (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkcusb.sys (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkeysdk.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\npkpdb.dll (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\OnePatch.dat (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\patch.inf (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\patch2.txt (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\patch_allow.txt (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Ragexe.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Ragnarok.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\RagnarokBR.ini (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Ragnarok_Completo.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\ragnarush.bin (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\ragnarush.ini (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\RagnaRush_Install.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\server.dat (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\Setup.exe (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI\AI.lua (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI\ai_m.lua (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI\Const.lua (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI\Util.lua (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\AI\È£¹®Å¬·ç½º ÀΰøÁö´É ½ºÅ©¸³Æ® ¼³¸í¼*.htm (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\01.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\01_01.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\01_02.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\01_03.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\02.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\03.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\04.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\05.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\06.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\07.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\08.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\09.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\10.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\100.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\101.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\102.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\103.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\104.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\105.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\106.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\107.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\108.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\109.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\11.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\110.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\111.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\112.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\113.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\114.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\115.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\116.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\117.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\118.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\119.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\12.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\120.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\121.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\122.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\123.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\124.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\125.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\126.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\127.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\128.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\129.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\13.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\130.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\131.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\132.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\133.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\134.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\135.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\14.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\15.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\16.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\17.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\18.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\19.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\20.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\21.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\22.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\23.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\24.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\25.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\26.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\27.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\28.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\29.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\30.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\31.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\33.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\34.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\35.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\36.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\37.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\38.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\39.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\40.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\41.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\42.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\43.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\44.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\45.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\46.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\47.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\48.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\49.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\50.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\51.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\52.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\53.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\54.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\55.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\56.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\57.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\58.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\59.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\60.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\61.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\62.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\63.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\64.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\65.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\66.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\67.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\68.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\69.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\70.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\71.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\72.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\73.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\74.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\75.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\76.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\77.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\78.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\79.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\80.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\81.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\82.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\83.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\84.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\85.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\86.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\87.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\88.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\89.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\90.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\91.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\92.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\93.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\94.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\95.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\96.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\97.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\98.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\BGM\99.mp3 (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\dump_wmimmc.sys (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\GameGuard.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\GameGuard.ver (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\GameMon.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\ggerror.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\ggscan.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgg.erl (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgg9x.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npggNT.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgl.erl (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgm.erl (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgmup.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgmup.des.new (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npgmup.erl (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npsc.des (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\npsc.erl (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\NPSCAN.DES (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\RagnarokBR.ini (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\GameGuard\Splash.jpg (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\beginner.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\button.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\button_npc.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\center.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\exit.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\home.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\skin.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\start.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\Thumbs.db (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\PatchClient\withgm.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_BACK.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_back_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_back_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_BUY.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_buy_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_buy_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_cancel.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_cancel_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_cancel_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_close.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_close_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_close_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_edit.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_edit_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_edit_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_exchange.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_exchange_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_exchange_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_exchange_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_NEXT.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_next_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_next_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_OK.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_OK_A.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_OK_B.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_ok_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_resize.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_SELL.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_sell_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_sell_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_send.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_send_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_send_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_use.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_use_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\BTN_use_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_view.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_view_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\btn_view_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\chat_close.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\chat_open.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\checkbox_0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\checkbox_1.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\colorchip.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_01a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_01b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_01c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_02a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_02b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_02c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_03a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_03b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_03c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_04a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_04b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\esc_04c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\radiobtn_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\radiobtn_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0bar_down.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0bar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0bar_up.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0down.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll0up.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1bar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1bar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1bar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\scroll1right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\shop.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_arr_l.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_arr_r.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_ld.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_lm.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_lu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_md.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_mu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_rd.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_rm.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\sysbox_ru.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\win_msgbox.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ARW_DOWN.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ARW_LEFT.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\arw_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\arw_right_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ARW_UP.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\basewin_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\basewin_mini.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_left2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_mid2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btnbar_right2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_cartoff.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_comm_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_comm_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_comm_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_equip_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_equip_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_equip_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_friend_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_friend_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_friend_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_items_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_items_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_items_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_map_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_map_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_map_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_option_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_option_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_option_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_skill_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_skill_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_skill_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_status_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_status_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\btn_status_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\chatwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\chatwin1_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\chatwin1_line.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\chatwin1_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\chatwin1_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\collection_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\cutline_0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_btn0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_btn1.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_btn2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\dialog_resize.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\equipwin_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\exchange_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\grp_leader.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\grp_offline.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\grp_online.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\GRP_STUN.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzeblue_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzeblue_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzeblue_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzered_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzered_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\gzered_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\GZE_BG.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_confusion.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_curse.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_frozen.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_poison.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_silence.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\ico_stone.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\itemwin_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\itemwin_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\itemwin_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\item_invert.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\lv_up_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\LV_UP_ON.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_01.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_01_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_01_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_02.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_02_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_02_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_03.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_03_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_03_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_04.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_04_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_04_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_05.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_05_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_05_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\mesbtn_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\optwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\optwin1_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\shortitem_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\shortitem_btn.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\skillcollection.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\skill_up_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\skill_up_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\skill_up_c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\statwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\statwin1_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sysboxs_ld.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sysboxs_lu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sysboxs_rd.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sysboxs_ru.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_base_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_base_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_close_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_close_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_mini_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\sys_mini_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\tab_itm_01.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\tab_itm_02.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\tab_itm_03.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\titlebar_fix.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\titlebar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\titlebar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\titlebar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\txtbox_btn_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\txtbox_btn_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\default\basic_interface\txtbox_btn_c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_BACK.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_back_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_back_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_BUY.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_buy_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_buy_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_cancel.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_cancel_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_cancel_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_close.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_close_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_close_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_edit.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_edit_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_edit_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_exchange.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_exchange_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_exchange_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_exchange_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_NEXT.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_next_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_next_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_OK.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_OK_A.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_OK_B.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_ok_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_resize.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_SELL.BMP (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_sell_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_sell_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_send.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_send_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_send_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_use.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_use_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\BTN_use_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_view.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_view_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\btn_view_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\chat_close.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\chat_open.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\checkbox_0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\checkbox_1.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\colorchip.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_01a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_01b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_01c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_02a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_02b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_02c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_03a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_03b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_03c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_04a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_04b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\esc_04c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\radiobtn_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\radiobtn_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0bar_down.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0bar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0bar_up.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0down.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll0up.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1bar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1bar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1bar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\scroll1right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\shop.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_arr_l.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_arr_r.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_ld.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_lm.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_lu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_md.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_mu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_rd.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_rm.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\sysbox_ru.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\win_msgbox.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ARW_DOWN.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ARW_LEFT.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\arw_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\arw_right_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ARW_UP.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\basewin_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\basewin_mini.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_left2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_mid2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btnbar_right2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_cartoff.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_comm_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_comm_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_comm_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_equip_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_equip_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_equip_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_friend_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_friend_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_friend_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_items_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_items_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_items_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_map_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_map_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_map_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_option_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_option_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_option_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_skill_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_skill_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_skill_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_status_dis.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_status_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\btn_status_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\chatwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\chatwin1_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\chatwin1_line.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\chatwin1_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\chatwin1_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\collection_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\cutline_0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_btn0.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_btn1.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_btn2.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\dialog_resize.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\equipwin_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\exchange_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\grp_leader.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\grp_offline.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\grp_online.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\GRP_STUN.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzeblue_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzeblue_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzeblue_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzered_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzered_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\gzered_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\GZE_BG.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_confusion.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_curse.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_frozen.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_poison.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_silence.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\ico_stone.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\itemwin_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\itemwin_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\itemwin_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\item_invert.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\LV_UP_OFF.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\LV_UP_ON.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_01.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_01_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_01_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_02.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_02_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_02_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_03.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_03_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_03_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_04.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_04_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_04_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_05.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_05_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_05_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\mesbtn_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\optwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\optwin1_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\shortitem_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\shortitem_btn.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\skillcollection.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\skill_up_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\skill_up_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\skill_up_c.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\statwin0_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\statwin1_bg.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sysboxs_ld.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sysboxs_lu.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sysboxs_rd.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sysboxs_ru.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_base_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_base_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_close_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_close_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_mini_off.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\sys_mini_on.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\tab_itm_01.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\tab_itm_02.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\tab_itm_03.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\titlebar_fix.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\titlebar_left.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\titlebar_mid.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\titlebar_right.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\txtbox_btn_a.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\txtbox_btn_b.bmp (Backdoor.Bot) -> No action taken.
C:\Arquivos de programas\Windows\Gravity\skin\Scribbling Kid\basic_interface\txtbox_btn_c.bmp (Backdoor.Bot) -> No action taken.
no aguardo !!
obrigado!!!!
 
Amigo GVSPFC, seus logs estão limpos. Poste apenas um log do HijackThis para analisarmos a situação atual, por gentileza.

Quanto ao autorun do Windows, tente desativá-lo usando este programinha: AutoPlayConfig. Me diga se o recurso foi devidamente desativado.

Meu grande amigo Mestre Wolf.

Muito grato pela indicação deste programinha para desabilitar o autorun, simples, rápido e prático, funcionou corretamente.

Pergunta, é compatível com o Windows 7 será este programa??

Baixei um programa que vi indicarem em outros fóruns, ThreatFire, que dizem trabalhar em conjunto com o antivírus. Aconselha usá-lo Mr. Wolf?

Mr. Wolf, segue o log do HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:48:09, on 13/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\ThreatFire\TFService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Arquivos de programas\BOINC\boinctray.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\Arquivos de programas\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
C:\Arquivos de programas\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Arquivos de programas\ThreatFire\TFTray.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\svchost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.7.16.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Arquivos de programas\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Arquivos de programas\Arquivos comuns\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Arquivos de programas\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Arquivos de programas\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Arquivos de programas\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Dados de aplicativos\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [boincmgr] "C:\Arquivos de programas\BOINC\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "C:\Arquivos de programas\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Arquivos de programas\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Arquivos de programas\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [ThreatFire] C:\Arquivos de programas\ThreatFire\TFTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Arquivos de programas\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: &B&aixar &com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &B&aixar todos os vídeos com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &B&aixar tudo usando o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converter destino de link em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converter destino de link em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converter em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converter links selecionados em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{80F6107E-C9EB-4DF2-9313-8577A920056F}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\..\{EF2CCA6F-33AF-478D-B11F-077990963C34}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Arquivos de programas\Arquivos comuns\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Dolby Digital Live Pack Licensing Service - Creative Labs - C:\Arquivos de programas\Arquivos comuns\Creative Labs Shared\Service\DDLLicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Arquivos de programas\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Arquivos de programas\ThreatFire\TFService.exe

--
End of file - 11212 bytes

Mais uma vez, não sei nem como agradecer esta ajuda Mr. Wolf. Parabéns por este trabalho, quem sem dúvidas é o mais importante aqui no fórum.:thumbs_up
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:37:05, on 13/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Windows\tsnp325.exe
C:\Windows\vsnp325.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\ALADIA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.positivoinformatica.com.br
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.positivoinformatica.com.br
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [tsnp325] C:\Windows\tsnp325.exe
O4 - HKLM\..\Run: [snp325] C:\Windows\vsnp325.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: Monitor.lnk = ?
O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: Estatísticas do Antivírus da Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\kasper~1\kasper~1.0\r3hook.dll
O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe

--
End of file - 8316 bytes

Mas esse log não é o da mesma máquina dos logs anteriores. Postarei um dela amanhã ou domingo.

Valeu, Mr. Wolf!
 
Boa tarde pessoal!



qeuzinha, não tem perigo algum em pegar o código. Mesmo que você leia o e-mail, você não corre risco de ser infectada por um vírus, somente se abrir ou baixar algum arquivo malicioso anexado no e-mail. Para colocar a mensagem em spoiler (ocultar), é só seguir o que eu passei ao origom neste link.

Bem, qeuzinha, o e-mail é realmente malicioso. Ele redireciona você a uma página de um host falso, onde, automaticamente, um trojan será instalado em seu sistema. O trojan é um downloader que baixará um rootkit -- malware muito perigoso. Inclusive, foi bom eu ter pego este código-fonte, pois descobri um novo rootkit e já foi adicionado ao MBAM e já mandei as assinaturas às empresas antivirus. Se tiverem outros e-mail do gênero, poste os códigos deles também, por gentileza.

A conta da sua irmã foi comprometida qeuzinha.

Veja se alterando a senha os e-mails param de ser enviados. Caso não parem, talvez a única solução para a sua irmã será criar uma outra conta de e-mail e cancelar esta atual. No entanto, se isto já está ocorrendo à bastante tempo, o mais recomendado e seguro para a sua irmã é que troque mesmo o endereço de e-mail.

_______________________________


Tello, seus dados do internet banking, de e-mails, de MSN, e etc... não são capturadas por este novo trojan. Com relação à isto, pode se despreocupar. Porém, é aconselhável que após qualquer infecção no computador, independetemente do tipo, trocar todas as senhas que foram digitadas.
Mas falando do trojan em si, ele não faz nada com seus dados.

Entretanto, encontramos o primeiro empecilho dele com o OTL. O problema deste trojan é que ele usa o padrão de PID igual ao svchost.exe, legítmo do Windows.

Siga abaixo:

- Faça o download do AVZ4 e salve-o no desktop;

- Extraia os arquivos do WinZip para o desktop, onde será criada uma pasta chamada avz4 no mesmo local;
- Entre nesta pasta e dê um duplo clique sobre o arquivo AVZ.exe para rodar a ferramenta;
- Ao abrir a janela do programa, clique no menu File > Database Update. Ou clique no botão
AVZupdate.jpg
no canto direito do painel da ferramenta, e clique no botão Start para atualizar a ferramenta;
- Clique no menu File > Standard scripts e marque a opção "2. Advanced System Analysis";
- Clique então no botão Execute selected scripts e clique em Yes na próxima mensagem. Aguarde a análise;
- Quando a análise terminar, clique em OK na mensagem. Voltando à janela Standard scripts, clique em Close para fechá-la. E feche também a janela do AVZ4;
- Vá até a pasta avz4 no desktop, e abra a pasta LOG que está dentro dela;
- Nesta estará os logs e uma pasta zipada denominada: virusinfo_syscheck.zip.

Anexe esta pasta em sua próxima resposta.
_______________________________


RodrigoFL, sei que os arquivos detectados pelo MBAM são referentes ao Ragnarok. Mas por que a criação da pasta Windows em:

C:\Arquivos de programas\Windows\Gravity

Pois com certeza foi por isso que o MBAM detectou os arquivos. Foi você quem criou a pasta Windows? Se foi você mesmo, foi um falso positivo do MBAM.

Porém, veja bem: somente os arquivos do jogo que talvez sejam falsos positivos. Os outros arquivos e entradas que o MBAM detectou são infecções reais, inclusive, até o adware.trojan MyWebSearch foi encontrado.

Refaça o scan com o MBAM e remova estas entradas ao término do scan Rodrigo:

Chaves do Registro infectadas:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Backdoor.Bot) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> No action taken.
Todos são malwares.

_______________________________


Grande amigo GVSPFC, não precisa agradecer! Sempre que precisar estarei à disposição aqui :)

De acordo com o site do AutoPlayConfig, a ferramenta só é compatível com: Windows 95/98/ME e XP. Agora não saberei lhe responder se a afirmação é atual. Posso verificar no 7 do meu computador pessoal quando chegar em casa, caso prefira.

Porém, você pode desativar manualmente, tanto no XP quanto no 7. Veja como no spoiler:

Para o XP: Vá em Iniciar -> Executar, digite gpedit.msc e dê um OK. No diretivas caminhe em Configuração do computador -> Modelos Administrativos -> Sistema.
Ao lado direito do painel, dê um duplo clique no item Desativar AutoExecutar.
Marque a opção Ativado e mais abaixo coloque "Todas as unidades" -> OK.

Para o 7 ou Vista: Clique em Start e na caixa de pesquisa digite gpedit.msc para abrir o group policy (diretivas de grupo).
Expanda as chaves Administrative Templates -> Windows Components -> Autoplay Policies. Ao lado direito do painel, dê um duplo clique em "Turn off AutoPlay". Marque a opção Enable e embaixo marque a opção "All drives" -> OK.
Quanto ao ThreatFire, ele é um behaviour blocker - excelente por sinal. Ótimo para ficar em conjunto com seu antivirus sim. Entretanto, acho que um behaviour blocker hoje é essencial. Visto que, malwares e vírus estão surgindo muito mais rápidos do que o normal hoje em dia, e os antivirus não estão conseguindo acompanhar; um behaviour blocker, que tem a função de detectar vírus/malwares novos que os antivirus ainda não possuem assinatura, pode barrá-los/detectá-los.

Totalmente recomendado GVSPFC.

Bem, seu log do HijackThis está limpo caro amigo.

Caso as ferramentas que utilizamos estiverem ainda em seu PC, pode deletá-las: AVZ4, Avenger e para o ComboFix é só ir em Iniciar > Executar, digite ComboFix /u e dê um OK. As outras pode deletar normalmente (shift + delete).

Algum problema em que eu possa ajudá-lo ainda amigo GVSPFC?

_______________________________


Johnn Y, limpo.
 
Eu também penso da mesma forma que você Mr. Wolf, tanto que assim que li a notícia, desinstalei imediatamente o software da IOBit que eu costumava usar "Advanced Systemcare".

Com relação a situação da Comodo, essa vc me surpreendeu, não sabia disso. E olha que esse era o firewall mais recomendado por vc a uns tempos atrás... que coisa hein :eek:

Essa ação da Comodo é de propósito ou é uma falha no software? Se for de propósito, qual seria o objetivo dela com isso?
Por que eu entendo que se a finalidade do software é essa - dar controle total ao user sobre oq pode ou não pode liberar - e o firewall não está fazendo isso deliberadamente, então pra que existe então? :wacko:
Então |St1ng3r|, a Comodo está pisando na bola mesmo. E muito bem lembrado, tempo atrás eu realmente recomendava 100% o Comodo Firewall.

Infelizmente, não é uma falha da empresa, é propositalmente. O fato é o seguinte. A Comodo já vinha se aliando à uma empresa adware chamada Ask.com - empresa esta, aliada também à empresas como Foxit, Zone Labs (Zone Alarm), Piriform (CCleaner), dentre outras - e vinha regredindo, colocando instaladores de crapwares (toolbars, barra de ferramentas, home page) em seu produto. O que antes bastava desmarcar a opção para não instalar estas toolbars, passou a ser instaladas mesmo com o usuário recusando. Com o passar do tempo, descobrimos que a Comodo estava deliberadamente permitindo o tráfego de sites e IPs maliciosos em seus certificados, o que é um absurdo para uma empresa de segurança privilegiada e de alto nível como a Comodo Groups.
relatos comprovados de que a própria Comodo Groups estaria liberando este tráfego malicioso.

Recomendo que dê uma lida neste tópico feito no fórum Linha Defensiva |St1ng3r|:
http://www.linhadefensiva.org/forum/index.php?showtopic=96881

PS: Agora que vc falou isso, eu lembro que antigamente vc estava analisando o Comodo Firewall pois o mesmo para funcionar 100% obrigava o user a instalar um programinha (esqueci o nome), e esse programa acho que era um adware se não me falha a memória.
Lembro que vc recomendava muito esse firewall, mas sempre alertando sobre esse detalhe, e que isso estava sendo investigado.
Por acaso tem alguma coisa a ver com isso ?
Exatamente. SafeSurf é o nome do adware, que ainda está presente na instalação do firewall. Na verdade, isto tem e não tem a ver ao mesmo tempo.

Já é um antiprofissionalismo de uma empresa de segurança colocar o instalador de um adware (um malware) justamente em um software que tende a proteger nosso sistema. Mas infelizmente não há o que discutir, vendo que, eles lucram colocando esses adwares em seus softwares. OK. Mas, como qualquer software que possua crapwares (esses adwares da instalação), basta desmarcar a opção e pronto! Porém, o Comodo Firewall passou a instalar mesmo desmarcando a opção. Esse foi o primeiro erro da empresa.

Depois, obviamente com suspeitas desta instalação forçada do programa, passamos a analisar o tráfego que a Comodo estava liberando, pois não era normal a instalação insistir mesmo desmarcada. Foi então que descobrimos o malicioso tráfego que a empresa está permitindo.
O tráfego redireciona nitidamente para os sites maliciosos destas empresas: SafeSurf e Ask.com. E até mesmo de sites falsos, e sites que foram hackeados.

Em virtude dos fatos, pessoalmente, não recomendo mais a ninguém os produtos da Comodo Groups.

A Comodo tentou se defender em um post em seu fórum:
http://forums.comodo.com/general_di...e_certificates_to_known_malware-t39564.0.html

Porém, mesmo assim, Comodo Firewall não recomendo mais!
 
Ola, tenho sempre que te agradecer. Já troquei a senha dela, espero que resolva.

Encontrei os seguintes :
[]
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html style="overflow:hidden;">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>


<base href="http://sn116w.snt116.mail.live.com/mail/TodayLight.aspx?layout=TodayDefault&rru=&n=1430690404" />

<script type="text/javascript">


var isPersistenceInline = false, redirectUrl = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3d\x26n\x3d1430690404';


var domainLoweringIsDown = false;
document.domain = "live.com";

if (window.top != self)
{
var hostname = "";
try
{
hostname = window.top.location.hostname;
}
catch(e)
{
hostname = "";
}

var mailUrlDomain = "mail.live.com";
var peopleUrlDomain = "people.live.com";
var hasMailUrl = (hostname != "") &&
(hostname.indexOf(mailUrlDomain) != -1) &&
((hostname.indexOf(mailUrlDomain) + mailUrlDomain.length) == hostname.length);
var hasPeopleUrl = (hostname != "") &&
(hostname.indexOf(peopleUrlDomain) != -1) &&
((hostname.indexOf(peopleUrlDomain) + peopleUrlDomain.length) == hostname.length);
if (!hasMailUrl && !hasPeopleUrl)
{
window.top.location.href = self.location.href;
}
else
{
self.location.href = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3d\x26n\x3d1430690404';
}
}
else if (domainLoweringIsDown)
{
if (self.location.hostname.indexOf("mail.live.com") <= 0)
{
document.cookie = "afu=" + escape('http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3d\x26n\x3d1430690404') + ";path=/;domain=.mail.live.com;";
self.location.href = 'sn116w.snt116.mail.live.com';
}
}


var gLoadIM = true,
gUIFrameBaseUrl = "";
function loadIM(q)
{
if (gLoadIM &&
(!q || q.indexOf('nwi=1') < 0))
{
gLoadIM = false;
var win = getUiWindow(), loc = win.location;
gUIFrameBaseUrl = loc.host;
var imFrame = document.getElementById("IMFrame");
if (imFrame)
{
imFrame.src = [loc.protocol, "//", gUIFrameBaseUrl, "/im/pages/im.aspx"].join("");
}
imFrame = null;
}
}


function uiFrameLoad()
{
//
try
{
if(!isPersistenceInline)
{
document.title = window.frames[0].document.title;
}

if (gLoadIM)
{
loadIM(getUiWindow().location.search);
}

}
catch(e)
{
}
}
function beforeUnloadHandler()
{
try
{
var frameUrl = getUiWindow().document.location.href;
document.cookie = "afu=" + escape(frameUrl) + ";path=/;domain=.mail.live.com;";
}
catch(e)
{
}
}
function getUiFrame()
{
return document.getElementById("UIFrame");
}
function getUiFrameOrBody()
{
return isPersistenceInline ? document.body : getUiFrame();
}
function getUiWindow()
{
return isPersistenceInline ? window : getUiFrame().contentWindow;
}
function makePersistenceStandalone()
{
isPersistenceInline = false;

var imFrame = document.getElementById("IMFrame");
if(imFrame && imFrame.contentWindow.updateUIFrameRef)
{
imFrame.contentWindow.updateUIFrameRef();
}

}
function redirectToLandingPage()
{
if(!isPersistenceInline)
{
getUiFrame().src = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3d\x26n\x3d1430690404';
}
}
</script>

</head>
<body style="padding:0;margin:0;overflow:visible;height:100%;width:100%;position:absolute;" onbeforeunload="beforeUnloadHandler()">

<div id="appDiv" style="position:absolute;height:100%;width:100%;">

<iframe id="UIFrame" name="UIFrame" src="http://sn116w.snt116.mail.live.com/mail/TodayLight.aspx?layout=TodayDefault&rru=&n=1430690404" onload="uiFrameLoad();"
frameborder="0"
width="100%"
height="100%"
marginheight="0"
marginwidth="0">
</iframe>

<iframe id="IMFrame" frameborder="0" width="0" height="0" src=""></iframe>

</div>

</body>
</html>
[/]
 
Segue mais um: Não tem como descobrir que fez isso:

Estou mandando tudo o que estou encontrando. Espero que tambem possa te ajudar.

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html dir="ltr" class="Unmanaged BottomUnmanaged">
<head><title>
Windows Live Hotmail
</title>

<base href="http://sn116w.snt116.mail.live.com/mail/TodayLight.aspx?n=418425526" />

<script type="text/javascript">


var isPersistenceInline = true, redirectUrl = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d418425526';


var domainLoweringIsDown = false;
document.domain = "live.com";

if (window.top != self)
{
var hostname = "";
try
{
hostname = window.top.location.hostname;
}
catch(e)
{
hostname = "";
}

var mailUrlDomain = "mail.live.com";
var peopleUrlDomain = "people.live.com";
var hasMailUrl = (hostname != "") &&
(hostname.indexOf(mailUrlDomain) != -1) &&
((hostname.indexOf(mailUrlDomain) + mailUrlDomain.length) == hostname.length);
var hasPeopleUrl = (hostname != "") &&
(hostname.indexOf(peopleUrlDomain) != -1) &&
((hostname.indexOf(peopleUrlDomain) + peopleUrlDomain.length) == hostname.length);
if (!hasMailUrl && !hasPeopleUrl)
{
window.top.location.href = self.location.href;
}
else
{
self.location.href = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d418425526';
}
}
else if (domainLoweringIsDown)
{
if (self.location.hostname.indexOf("mail.live.com") <= 0)
{
document.cookie = "afu=" + escape('http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d418425526') + ";path=/;domain=.mail.live.com;";
self.location.href = 'sn116w.snt116.mail.live.com';
}
}


var gLoadIM = true,
gUIFrameBaseUrl = "";
function loadIM(q)
{
if (gLoadIM &&
(!q || q.indexOf('nwi=1') < 0))
{
gLoadIM = false;
var win = getUiWindow(), loc = win.location;
gUIFrameBaseUrl = loc.host;
var imFrame = document.getElementById("IMFrame");
if (imFrame)
{
imFrame.src = [loc.protocol, "//", gUIFrameBaseUrl, "/im/pages/im.aspx"].join("");
}
imFrame = null;
}
}


function uiFrameLoad()
{
//
try
{
if(!isPersistenceInline)
{
document.title = window.frames[0].document.title;
}

if (gLoadIM)
{
loadIM(getUiWindow().location.search);
}

}
catch(e)
{
}
}
function beforeUnloadHandler()
{
try
{
var frameUrl = getUiWindow().document.location.href;
document.cookie = "afu=" + escape(frameUrl) + ";path=/;domain=.mail.live.com;";
}
catch(e)
{
}
}
function getUiFrame()
{
return document.getElementById("UIFrame");
}
function getUiFrameOrBody()
{
return isPersistenceInline ? document.body : getUiFrame();
}
function getUiWindow()
{
return isPersistenceInline ? window : getUiFrame().contentWindow;
}
function makePersistenceStandalone()
{
isPersistenceInline = false;

var imFrame = document.getElementById("IMFrame");
if(imFrame && imFrame.contentWindow.updateUIFrameRef)
{
imFrame.contentWindow.updateUIFrameRef();
}

}
function redirectToLandingPage()
{
if(!isPersistenceInline)
{
getUiFrame().src = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d418425526';
}
}
</script>
<script>window._ttgTs = 0;function setTtgTs(eventName){window._ttgTs = Math.max(window._ttgTs, new Date().getTime());}</script><link rel="stylesheet" href="http://gfx8.hotmail.com/mail/15.1.3028.1103/styles/base/hig.css" type="text/css" onload="if(window.setTtgTs){setTtgTs('css-onload');}"/>
<style type="text/css">
.DefaultFont, BODY, BODY.IE_M7, BODY.IE_M8, BODY.Win6, TEXTAREA, SELECT, INPUT, .c_hf INPUT, BUTTON,
.c_h .signOut, .EditArea, .ExternalClass {font-family:Tahoma,Verdana,Arial,sans-serif;line-height:normal;}BODY{font-size:83%;}A{text-decoration:nenhum;}.EditArea, .ExternalClass{font-size:10pt;}B, STRONG, .BoldText,.cSubsectionSubtitle {font-weight: bold;}I, EM, .TextItalic{font-style: italic;}.button_rest, .yl_sdi, .rd_sdi, .i_importance_low_large, .i_importance_high_large, .pr_sdi, .bl_sdi, .gr_sdi, .pi_sdi, .expand_right, .collapse_left{border:none;overflow:hidden;background-repeat:no-repeat;background-image:url(http://gfx2.hotmail.com/mail/w4/pr01/ltr/ics_1.gif);height:16px;width:17px;}.i_cancel, .mr_accept, .i_next, .i_warn, .i_previous, .i_print, .i_info, .i_reply, .i_read, .i_importance_high, .i_forward, .i_importance_low, .i_new, .i_prev_page_disable, .i_nextpage, .i_previouspage, .glyph_close_rest, .i_next_page, .i_previouspage_disable, .i_attach, .i_nextpage_disable, .descend_rest_dark, .ascend_rest_dark{border:none;overflow:hidden;background-repeat:no-repeat;background-image:url(http://gfx1.hotmail.com/mail/w4/pr01/ltr/ics_2.gif);height:10px;width:9px;}.TableHeaderGradient{background-image: url('http://gfx1.hotmail.com/mail/w4/pr01/ltr/table_header_gradient.png');}
</style>


<link rel="stylesheet" href="http://gfx8.hotmail.com/mail/15.1.3028.1103/styles/base/TodayAll.css" type="text/css" onload="if(window.setTtgTs){setTtgTs('css-onload');}"/>

<script type="text/javascript">


document.domain = "live.com";


var mailUrlDomain = "mail.live.com";
var hostname = "";
try
{

hostname = window.top.location.hostname;
}
catch(e)
{
hostname = "";
}

var doReframe = false;
var hasMailUrl = (hostname != "") &&
(hostname.indexOf(mailUrlDomain) != -1) &&
((hostname.indexOf(mailUrlDomain) + mailUrlDomain.length) == hostname.length);


if (!hasMailUrl)
{
var peopleUrlDomain = "people.live.com";
var hasPeopleUrl = (hostname != "") &&
(hostname.indexOf(peopleUrlDomain) != -1) &&
((hostname.indexOf(peopleUrlDomain) + peopleUrlDomain.length) == hostname.length);

if (!hasPeopleUrl)
{
doReframe = true;
}
}


else if (window == top)
{

doReframe = true;
}

if (doReframe)
{
document.cookie = "afu=" + escape(window.location.href) + ";path=/;domain=.mail.live.com;";

}

</script>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta http-equiv="x-dns-prefetch-control" value="off" /><script>Browser={isFF:true,isFF2:false,isFF3:true};</script>
<script src="http://gfx6.hotmail.com/mail/15.1.3028.1103/cmpt0.js"></script>

<script>
Control = {};Control.invoke=Control.invokeStatic=Control.getAncestorByAttr=Control.lookup=function(){};PerfRecorder = {};PerfRecorder.startTimer=PerfRecorder.stopPageTimer=PerfRecorder.sendTransaction=function(){};AutoRefresh = {}; AutoRefresh.config = {isDown: false, delay: 60};
</script>
<link rel="icon" href="http://gfx2.hotmail.com/mail/w4/pr01/ltr/favicon.ico" />
<link rel="shortcut icon" href="http://gfx2.hotmail.com/mail/w4/pr01/ltr/favicon.ico" />
</head>

<body onload="if(typeof(Page)!='undefined'){Page.isPageLoaded=true;};uiFrameLoad()" layout="BottomUnmanaged" class="ltr SignedIn Firefox FF_Win FF_M3 FF_D5 Full RE_Gecko TodayPage">



<div id="PageElt" class="App Unmanaged BottomUnmanaged">
<script>

DoHelp=function (){};
var g_wlmMainFormId = "aspnetForm", g_helpPaneMarket = "pt-br", g_helpPaneProject = "MailClassic", g_helpBaseUrl = "http://help.live.com", g_adsToFire=[], g_isRtl = false, g_confirmEmptyFolder = "Tem certeza de que deseja esvaziar a pasta\x3f";
if (!document.cookie || (document.cookie.indexOf("KSC")==-1) && (document.cookie.length!=0) )
{

var mailDomain = "mail.live.com";
if (window.location.hostname.indexOf(mailDomain) != -1)
{
window.location=document.location.href+'&n=2033220202';
}
}
</script>
<div class="AppInner">
<div id="HeaderContainer" onresize="return Control.invokeStatic('Resize', '_headerResize', event);"><s ns="rs"></s>
<img style="display:none" src="http://accountservices.msn.com/loginmsn.srf?lc=1031&ct=1258128980&rver=6.0.5285.0&id=64855&MSNPPAuth=CccGrhElTdXyiKzx4YIzINCzEiR6T2*coEBTwLOr4MxA3mNhtD8FcEmQz4Bsy!BxT!21is!3wZDQaUqXdjQidFY8ZlbsmdTpBqyuPYcXgeHSFbuPXYlU3H*W7ykeytOGtp4FPLFE!DuxxLplB4jSs6UX3zdXSrLboy51I1rXIzRoCWvkjBqrHzFy4w5JpGCQpjD!S4uLVZfLpT1hdwbRno1Mgv38brTMvMwzRdMMi!1omVeJbHE6TIkW1FnjekJH5L649Y*9FI2Q9pCDRdIJHbak6G13Ef3aErlwgtvtYZmrgBcG5E3dm1vfRYWvtyQiu5nHEw9ehnIQlRq*6psnP8cWtkWMh!XA09JUpjryekFTYrwg5ZMC2EsVOw48EyCXispEn6Ps8J5uQ8oPOiQVuUnCCxduwfwgZdpTUUi9LNXipn3eZkF0rQQbMuk9gjGZq20MAJtDQPrdfvk6ea3RfLOBsl24wsKqCpegOwS7aq4TsjPtVMXzr0zB3iLs"/><script type="text/javascript">function $c_TreatTile(a,e){a.style.display=e;var d=a.width,c=a.height,b=19;if(d>=c||c<b)a.height=b;if(d<c||d<b)a.width=b}</script>
<div id="c_header" class="c_hb" style="min-width:987px;"><div class="c_hta"><div class="c_hg" style="background-image:url(http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/g.png);padding-bottom:7px;"><div class="c_h" style=""><div class="c_hl" style="top:12px;"><a class="c_hlp c_nootl" href="http://g.live.com/9uxp9pt-br/hdr_main1??su=http://shared.live.com/" target="_top"><span class="c_is" style="padding-left:18px;font-size:17px;line-height:17px;vertical-align:middle;margin-right:3px;"><span style="clip: rect(0px 18px 17px 0px);left:0px;top:0px;"><img src="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/s3.png" alt="Windows Live" /></span></span><span class='c_hbrnd'>Windows Live<span class="c_tm">&trade;</span></span></a></div><div class="c_hc"><div class="inCenter" style="margin-right:4,5em;;"><ul class="c_ht"><li><a href="http://g.live.com/9uxp9pt-br/hdr_main1??su=http://shared.live.com/Live.Mail" target="_top">Início</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_main2??su=http://shared.live.com/Live.Mail" target="_top">Perfil</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_main3??su=http://shared.live.com/Live.Mail" target="_self">Contatos</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_main4??su=http://shared.live.com/Live.Mail" target="_self">Email</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_main5??su=http://shared.live.com/Live.Mail" target="_top">Fotos</a></li><li><a href="#" onclick="try{$menu.bind(event,0,3,1);}catch(e){};return false;;return false;return false" class=" uxfa_ml c_ml" target="_top"><span class="c_mlu">Mais</span><span class="c_chev"> ▼</span></a><ul class=" uxfa_m c_m"><li><a href="http://g.live.com/9uxp9pt-br/hdr_main6??su=http://shared.live.com/Live.Mail" target="_top">Calendário</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more12??su=http://shared.live.com/Live.Mail" target="_top">Eventos</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more1??su=http://shared.live.com/Live.Mail" target="_top">Grupos</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more11??su=http://shared.live.com/Live.Mail" target="_top">Spaces</a><div class="c_ms"></div></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more2??su=http://shared.live.com/Live.Mail" target="_top">SkyDrive</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more4??su=http://shared.live.com/Live.Mail" target="_top">Proteção para a Família</a><div class="c_ms"></div></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more6??su=http://shared.live.com/Live.Mail" target="_top">Celular</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more5??su=http://shared.live.com/Live.Mail" target="_top">Downloads</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_more13??su=http://shared.live.com/Live.Mail" target="_top">Todos os serviços</a></li></ul></li><li><a href="#" onclick="try{$menu.bind(event,0,3,1);}catch(e){};return false;;return false;return false" class=" uxfa_ml c_ml" target="_top"><span class="c_mlu">MSN</span><span class="c_chev"> ▼</span></a><ul class=" uxfa_m c_m"><li><a href="http://g.live.com/9uxp9msn/mhm-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Início</a><div class="c_ms"></div></li><li><a href="http://g.live.com/9uxp9msn/mau-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Automóvel</a></li><li><a href="http://g.live.com/9uxp9msn/mga-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Jogos</a></li><li><a href="http://g.live.com/9uxp9msn/mmo-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Dinheiro</a></li><li><a href="http://g.live.com/9uxp9msn/mmv-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Filmes</a></li><li><a href="http://g.live.com/9uxp9msn/mmu-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Música</a></li><li><a href="http://g.live.com/9uxp9msn/mnw-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Notícias</a></li><li><a href="http://g.live.com/9uxp9msn/msp-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Esportes</a></li><li><a href="http://g.live.com/9uxp9msn/mwe-pt-br??su=http://shared.live.com/Live.Mail" target="_top">Tempo</a></li></ul></li></ul><script type="text/javascript">
function $clrDT(){var t=document.getElementById('c_hsv');if(t.value=="Pesquisar na Web"){t.value='';}return t;}
function searchTheWeb(){$clrDT();document.getElementById('c_search').submit();}
</script><div class="c_hf" style="background-image:url(http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/sl1.png);background-position:center right;background-repeat:no-repeat;"><form id="c_search" action="http://www.bing.com/search" method="GET" target="_top"><label for="c_hsv" style="display:none;">Pesquisar na Web</label><input id='c_hsv' class="c_ml TextItalic" value="Pesquisar na Web" autoComplete="Off" type="text" name="q"
onfocus="if(this.s!='t'){this.value='';this.className = 'c_ml c_fia';this.s='t';this.parentNode.parentNode.style.backgroundImage = '';}"
onblur="if(this.value ==''){this.value='Pesquisar na Web';this.className = 'c_ml TextItalic';this.s='';this.parentNode.parentNode.style.backgroundImage = 'url(http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/sl1.png)';}" /><input name="form" value="WLMLQB" type="hidden"/><input name="mkt" value="pt-br" type="hidden"/><a id='c_hsbt' href="#" onclick="document.getElementById('c_sbt').click()" class="c_nootl glyph"><span><img src="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/s3.png" alt="Pesquisar" title="Pesquisar" /></span></a><input id="c_sbt" style="display:none" type="button" onclick="searchTheWeb()"/></form></div></div></div><div id="c_me" class="c_me c_mcp"><a id="c_melink" href="#" class="TextSizeLarge c_un c_ml c_nootl" onclick="try{return $menu.bind(event,1,0,1);}catch(e){};return false;" style="vertical-align:top;zoom:1;" target="_top">

Selma<span class="c_chev">&nbsp;▼</span><span class="c_is" style="padding-left:31px;font-size:31px;line-height:31px;;"><span style="clip: rect(17px 31px 48px 0px);top: -17px;left:0px;"><span id="c_metile" class="c_utw"><img class="c_ut" src="http://5d5ef9da01061fdd.users.storage.live.com/MyData/MyProfile/GeneralProfile/ProfilePhoto:UserTileSmall,Thumbnail?fofoff=1&ex=24&ck=633937317347514306" onload="$c_TreatTile(this,'block');" style="-ms-interpolation-mode:bicubic;" alt=""/></span><img src="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/s3.png" style="position:absolute;" alt=""/></span></span>
</a><ul class="c_m"><li><a href="http://g.live.com/9uxp9pt-br/hdr_mectrl3?ru=http%3a%2f%2fsn116w.snt116.mail.live.com%2fdefault.aspx%3fwa%3dwsignin1.0&&su=http://shared.live.com/Live.Mail" target="_top">Alterar imagem</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_mectrl4?ru=http%3a%2f%2fsn116w.snt116.mail.live.com%2fdefault.aspx%3fwa%3dwsignin1.0&&su=http://shared.live.com/Live.Mail" target="_top">Alterar nome</a><div class="c_ms"></div></li><li><a id="c_hli" href="http://g.live.com/9uxp9pt-br/hdr_mectrl1??su=http://shared.live.com/Live.Mail" target="_top">Exibir sua conta</a></li><li><a href="http://g.live.com/9uxp9pt-br/hdr_mectrl2??su=http://shared.live.com/Live.Mail" target="_top">Vincular outras contas</a></li></ul><a id="c_signout" class="signOut TextSizeXSmall" onclick="event.cancelBubble=true" href="/mail/logout.aspx" target="_top">sair</a></div>
</div></div></div></div>


</div>

<div class="Middle" id="Middle">
<div class="ContentLeft" id="contentLeft">
<div class="ProductNameContainer"><h1 class="ProductName">Hotmail</h1></div>
<div class="EmailName DisplayBlock">selmacesar@hotmail.com</div>
<div class="ContentFolderList" style="bottom:15.3762493em">



<ul id="folderList" fid="00000000-0000-0000-0000-000000000000" fst="NONE" ft="c" srchKw="" class="List FolderList LeftNav" onclick="PerfRecorder.startTimer(false, 'VI-LN');"><li class=" BoldText" id="00000000-0000-0000-0000-000000000001" count="2" d="1"><a href="InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000001&InboxSortAscending=False&InboxSortBy=Date&n=435427812" title="Caixa de Entrada (2)"><span class="Caption">Caixa de Entrada <span style="display:inline;">(<span>2</span>)</span></span></a></li><li class=" BoldText" id="00000000-0000-0000-0000-000000000005" count="3" d="1"><a href="InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000005&InboxSortAscending=False&InboxSortBy=Date&n=851894944" title="Lixo (3)"><span class="Caption">Lixo <span style="display:inline;">(<span>3</span>)</span></span></a></li><li class=" BoldText" id="00000000-0000-0000-0000-000000000004" count="0" d="1"><a href="InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000004&InboxSortAscending=False&InboxSortBy=Date&n=1098197368" title="Rascunhos"><span class="Caption">Rascunhos <span style="display:none;">(<span></span>)</span></span></a></li><li id="00000000-0000-0000-0000-000000000003" count="0" d="1"><a href="InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000003&InboxSortAscending=False&InboxSortBy=Date&n=1210613288" title="Enviados"><span class="Caption">Enviados <span style="display:none;">(<span></span>)</span></span></a></li><li class=" BoldText" id="00000000-0000-0000-0000-000000000002" count="2" d="1"><a href="InboxLight.aspx?FolderID=00000000-0000-0000-0000-000000000002&InboxSortAscending=False&InboxSortBy=Date&n=417949100" title="Excluídos (2)"><span class="Caption">Excluídos <span style="display:inline;">(<span>2</span>)</span></span></a></li><li id="1bfd1986-7fd1-4a2f-af93-bf62d34b3f61" count="0" d="1"><a href="InboxLight.aspx?FolderID=1bfd1986-7fd1-4a2f-af93-bf62d34b3f61&InboxSortAscending=False&InboxSortBy=Date&n=571100605" title="memorias"><span class="Caption">memorias <span style="display:none;">(<span></span>)</span></span></a></li><li id="5b076194-b020-41a9-9e97-7ef4cf1b90b4" count="0" d="1"><a href="InboxLight.aspx?FolderID=5b076194-b020-41a9-9e97-7ef4cf1b90b4&InboxSortAscending=False&InboxSortBy=Date&n=346359899" title="SELMA RK"><span class="Caption">SELMA RK <span style="display:none;">(<span></span>)</span></span></a></li></ul><a class="ManageLink LinkColor TextDecorationUnderline" href="ManageFoldersLight.aspx?n=398387919"><span class="Caption" title="Gerenciar pastas">Gerenciar pastas</span></a>



<span class="DisplayBlock AddAccount">
<a style="white-space:normal" href="AggregationSetupBasic.aspx?ext=PAS&SEP=Inbox&n=794171322" target="_top">Adicione uma conta de email</a>
</span>

</div>
<div class="Bottom">


<div class="LeftNavHeading DisplayBlock">Locais relacionados</div>
<ul id="RelatedPlaces" class="List LeftNav RelatedPlaces">
<li>
<a href="TodayLight.aspx?n=2121654879" title="Ir para a página do Hoje" onclick="PerfRecorder.startTimer(false, 'VI-SC');" >Hoje</a>
</li><li>

<a href="ContactMainLight.aspx?n=996248612" title="Ir para a lista de contatos" >Lista de contatos</a>
</li><li>
<a href="/mail/calendar.aspx" title="Ir para a agenda" >Calendário</a>
</li>
</ul>


<div id="CustComm_120x60" class="Crm120Container" style="height:60px !important;">
<script defer="defer" type="text/javascript">
g_adsToFire[g_adsToFire.length] = ["CustComm_120x60", "&AP=1026&PG=WLMBRC&UC=127", "120", "60", false];
</script>

</div>


</div>
</div>
<div class="MasterSplitter" id="masterSplitter"></div>
<div class="ContentRight" id="contentRight">

<form name="aspnetForm" method="post" action="mail/TodayLight.aspx?n=386717109" id="aspnetForm" enctype="multipart/form-data" target="_self" onsubmit="var btn=window.document.getElementById('psbtn');if(this.s &amp;&amp; btn){btn.click(); return false;}">
<div>
<input type="hidden" name="__VIEWSTATE" id="
__VIEWSTATE" value="" />
</div>

<input type="hidden" id="mt" name="mt" value="" />

<div class="Toolbar" style="border-bottom-width:1px;border-bottom-style:solid;" id="toolbarContainer" >
<ul>

<script defer="defer" type="text/javascript">g_helpKey="PIM_WhatsNew";</script>

<li aId="NewMessage" class="ToolbarItem ToolbarItemFirst" ><a title="Escrever uma nova mensagem (Ctrl+N)" href="javascript:;" id="NewMessage" onclick="Control.invokeStatic('TodaySmcActions', 'newMsg', event);">
<span class="Label">Novo</span></a></li>
<li id="__Page" class="ToolbarItem"><span class="ToolbarPipe">|</span></li>
<li class="ToolbarItem"><a href="http://newsletters.msn.com/hm/gomarket.asp?L=BR&C=BR&P=WCMaintenance&Brand=WL&RU=http%3a%2f%2fmail.live.com" target="_blank">Gerencie os boletins informativos</a></li>





<li class="ToolbarItem c_mcp ToolbarHelpLink FloatRight">
<a href="javascript:;" class="c_ml" onclick="try{$menu.bind(event,1, 0, 1)}catch(e){};return false;"><img alt="Ajuda" src="http://gfx2.hotmail.com/mail/w4/pr01/ltr/i_help.gif" title="Ajuda"/><span></span>&nbsp;<span class="c_chev">▼</span></a>
<ul class="c_m" onclick="$menu.closeCurrent();"><li ><a href="javascript:;" onclick="DoHelp();"><span>Ajuda</span></a></li><li aId="HelpSupport" style="display: none;"><a id="HelpSupport" href="http://www.windowslivehelp.com" target="_top"><span>Suporte</span></a></li><li aId="HelpFeedback" class="BorderTop" ><a id="HelpFeedback" href="http://g.live.com/9uxp9pt-br/ftr4?productkey=wlmail&build=15.1.3028.1103&cluster=sn116w.snt116.mail.live.com" target="_top" onclick="Page.addFeedbackData(this);"><span>Comentários</span></a></li><li aId="HelpWhatsNew" ><a id="HelpWhatsNew" href="WhatsNew.aspx"><span>Novidades</span></a></li><li aId="HelpAbout" class="BorderTop" ><a id="HelpAbout" href="About.aspx"><span>Sobre</span></a></li><li aId="IBrokenheartDogfacePizza" style="display: none;"><a id="IBrokenheartDogfacePizza" href="javascript:;" onclick="TakeMeOutOfDogfood();"><span></span><img alt="Dude! This build doesn't work for me!" src="http://gfx1.hotmail.com/mail/w4/pr01/ltr/../IBrokenheartDogfacePizza.gif" /></a></li></ul>
</li>



<li class="ToolbarItem ToolbarOptionsLink FloatRight">


<!-- Options Menu Start -->
<span class="c_omcntrl c_mcp" >

<a id="_button" href="#null" onclick="try{$menu_themes(this,'_menu_themes','http://gfx1.hotmail.com/mail/15.1.3028.1103/Live.Controls.V2/',0);return $menu.bind(event,1);}catch(e){return false;}" class="c_ml">Opções<span class="c_chev">&nbsp;▼</span></a>
<div id="_menu" class="c_om c_m noresize" style="display:none;">
<div class="c_clr"></div>
<ul class="c_oblock" id="_menu_language">
<li>
<span class="gt">Idioma</span>

</li>
<li>
<a href="options.aspx?subsection=12&n=812388964" rel="nofollow">Português (Brasil)</a>
</li>
</ul>

<div class="lp"><div class="line"></div></div>
<ul class="c_oblock c_ot" id="_menu_themes" serviceurl="http://ssw.live.com/lfe/Live.Gateway.Themes/themewriter.aspx?canary=dZ6FNb1HO6oyeOAkwXAhGdpy4bwZlzwE0AewuviYnMc%3d9">

<li>
<span class="gt">Temas</span>
</li>
<li class="c_omti"><a href='#' onclick='return false;' info='Base|thumbnail.jpg|15.1.2055' class='c_thmb' title='Windows Live'></a><a href='#' onclick='return false;' info='X_3_Robot|thumbnail.gif|15.1.2055' class='c_thmb' title='Robôs'></a><a href='#' onclick='return false;' info='Remix_FloLight_12|Thumbnail.gif|15.1.2055' class='c_thmb' title='Violeta Primavera'></a><a href='#' onclick='return false;' info='OOB_3_Cherry|thumbnail.jpg|15.1.2055' class='c_thmb' title='Cerejeiras em Flor'></a><div style="clear:both"></div></li><li class="c_omti"><a href='#' onclick='return false;' info='X_4_Prairie|Prairie_32x32.gif|15.1.2055' class='c_thmb' title='Pradaria'></a><a href='#' onclick='return false;' info='X_1_Daisy|DaisyHill_32x32.gif|15.1.2055' class='c_thmb' title='Margaridas'></a><a href='#' onclick='return false;' info='Remix_CirqueDark_7|Thumbnail.gif|15.1.2055' class='c_thmb' title='Marrom Hipnótico'></a><a href='#' onclick='return false;' info='OOB_51_Carbon|Thumbnail.gif|15.1.2055' class='c_thmb' title='Carbono'></a><div style="clear:both"></div></li>
<li>
<a href="http://g.live.com/9uxp9pt-br/op_1" rel="nofollow">Mais temas</a>
</li>

</ul>

<div class="c_clr"></div>
<div class="lp"><div class="line"></div></div>
<ul class="c_oblock" id="_menu_more">
<li>
<a href="options.aspx?subsection=1&n=1490965966" rel="nofollow">Mais opções</a>
</li>
</ul>


</div>
<div class="c_shad" style="position:absolute;display:none;"></div><script type="text/javascript">var _d=document,_dh=_d.getElementsByTagName("head")[0];function $newScript(c,d,b){var a=_d.createElement("script");a.id=d||"";a.src=c;if(!b)_dh.appendChild(a);return a}</script>
</span>
<!-- Options Menu End -->


</li>

<li id="WebIMSeparator" class="ToolbarItem FloatRight">
<span class="ToolbarPipe">|</span>
</li>



<li class="ToolbarItem c_mcp ToolbarItem FloatRight c_mcp" id="WebIMMenu">
<a href="javascript:;" class="c_ml" onclick="try{$menu.bind(event,0, 0, 1)}catch(e){};return false;"><span>Messenger</span>&nbsp;<span class="c_chev">▼</span></a>
<ul class="c_m"><li ><a href="javascript:;" onclick="$menu.closeCurrent();return false;"><span>Carregando...</span></a></li></ul>
</li>


</ul>
<input type="hidden" id="ToolbarActionItem" name="ToolbarActionItem" value=""/>
</div>
<div id="infoPaneContainer" class="InfoPaneContainer BorderTop BorderBottom" style="display:none;" onresize="return Control.invokeStatic('Resize', '_ipaneResize', event);"><s ns="rs"></s>


<div id="error">
<div id="ctl00_InfoPane_infoPri" class="InfoPaneInner">
</div>

<input type="hidden" id="InfoPaneActionItem" name="InfoPaneActionItem" value="" />
</div>

</div>
<div id="ManagedContentWrapper">
<div id="MainContent">

<input type="hidden" size="" id="folderCache" name="folderCache" maxFolders="12"></input>

<table width="100%" cellpadding="0" cellspacing="0"><tr valign="top"><td>
<div class="TodayContentContainer">
<div class="TodayContentModule">

<div class="WelcomeText">
<div><h1 class="DisplayInline">Olá, Selma!</h1>&nbsp;<span class="WelcomeDate SecondaryTextColor">sábado, 14 novembro</span></div>
<div class="WelcomeStorageText">Você possui armazenamento em contínuo crescimento.&nbsp;<a href="#" onclick="DoHelp('egarots_detimilnu');return false;">Saiba mais</a></div>

</div>


<iframe id="ttgFrame" src="about:blank" onload="setTtgTs('iframe-onload');" style="display:none;"></iframe><div class="Upsell"><div class="UpsellIcon"><img src="http://gfx1.hotmail.com/mail/w4/pr01/ltr/i_info.gif" alt="Para suas informações" title="Para suas informações" width="15" height="16"/></div>
<span>Use os <a href="http://g.live.com/9wc9pt-br/sell21">atalhos de teclado</a> para navegar pelos seus emails rapidamente sem usar um mouse.</span><img alt="" width="1" height="1" src="http://h.msn.com/c.gif?RF=&PI=44280&DI=5709&PS=97922"/></div>
</div><div class="ATNWNTable WNZ">
<h2>Novidades na sua rede</h2><div id="WNControl" class="WNContainer">
<div class="WNSelector"><a href="TodayLight.aspx?sf=True&n=1178110423">Favoritos</a><span class="WNSelectorSpliter">|</span><span class="WNSelectItemSelected">Surpreenda-me</span></div>

<table width="100%" cellpadding="0" cellspacing="0">
<colgroup>
<col class="WNColICDB" />
</colgroup>
<tr>
<td>
<div class="WNICContainer">
<script type="text/javascript">function ic_onTileErr(a){try{a.onerror=null;a.onload=null;a.className="cxp_ic_tile";a.src=a.getAttribute("errsrc");a.style.visibility=""}catch(b){}}function ic_onTileLoad(a){try{var c=a.width,b=a.height;a.className="cxp_ic_tile";var k=a.width,j=a.height,g,d,l=0,m=0;if(c==0&&b==0){var i=new Image;i.src=a.src;c=i.width;b=i.height}var h=a.currentStyle;if(c==1&&b==1||h&&h.width=="1px"&&h.height=="1px"){ic_onTileErr(a);return}var f=Math.round;if(c&&b&&c!=b)if(c>b){d=j;g=f(j*(c/b));l=-f((g-k)/2)}else{g=k;d=f(k*(b/c));m=-f((d-j)/2)}var e=a.style;if(d&&d){e.width=g+"px";e.height=d+"px";e.left=l+"px";e.top=m+"px"}a.style.visibility=""}catch(n){}}</script>

<div id="ICc0" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc0_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc0_frame_clip" title="Imagem de kofnatpret@yahoo.com.br" class="cxp_ic_frame_clip" target="_top" href="http://cid-60d992da60cdcc76.profile.live.com/" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';">

<img id="ICc0_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de kofnatpret@yahoo.com.br" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc0_usertile" srcTo="http://60d992da60cdcc76.users.storage.live.com/users/6978770564211919990/MyProfile/ExpressionProfile/ProfilePhoto:UserTileStatic?fofoff=1&ex=48&ck=1" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de kofnatpret@yahoo.com.br" />
</div>

</div>


<div id="ICc0_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc0_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="kofnatpret@yahoo.com.br" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">kofnatpret​@yahoo.com.​br</span>

</div>

<div id="ICc0_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>


</div>

</div>
<div class="WNDBContainer">

<script type="text/javascript">function $db_TreatImg(i,a,ml,l,mt,b,sh,kw,kh){setTimeout(function(){if(i.getAttribute('treated')==null){try{var m=Math;var r=0.01745*(a>=0?a:360+a);var c=m.cos(r);var s=m.sin(r);var v=document.createElement('canvas');var w=kw||i.width;var h=kh||i.height;if(w>=h&&w>l){i.width=l;}if(w<h&&h>l){i.height=l;}if(kw){i.width=kw};if(kh){i.height=kh};var wb=i.width+b*2;var hb=i.height+b*2; if(!sh && b>0){v.style.position="absolute";}i.style.visibility="visible";if(b==0&&!sh){return;}a!=0||b==0?v.oImage=i:v=i;v.style.width=v.width=m.abs(c*wb)+m.abs(s*hb);v.style.height=v.height=m.abs(c*hb)+m.abs(s*wb);if(ml!=0){v.style.marginLeft=ml+"px";v.style.marginTop=mt+"px";}v.style.verticalAlign="middle";if(v.oImage){var x=v.getContext('2d');x.save();if(r<=m.PI/2){x.translate(s*hb,0);}else if(r<=m.PI){x.translate(v.width,-c*hb);}else if(r<=1.5*m.PI){x.translate(-c*wb,v.height);}else{x.translate(0,-s*wb);}x.rotate(r);if(b>0){x.fillStyle="#fff";x.fillRect(0,0,wb,hb);}b?x.drawImage(v.oImage,0,0,w,h,b,b,i.width,i.height):x.drawImage(v.oImage,0,2,i.width,i.height);x.restore();i.parentNode.replaceChild(v,i);}if(!sh & b>0){var s=new Image();s.src="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/all/photoShadow.png";s.className='c_db_imgBorder';s.style.display="none";v.parentNode.appendChild(s); i.style.display="none";s.addEventListener("load", function(){i.style.display="";$db_TreatImg(s, a, ml, l, mt, 0, 1, wb * 1.075, hb * 1.075);},false);}}catch(e){}i.treated = true;}});}</script>

<div class="c_db c_db_noUt " >

<div class='c_db_i' n="Katia" >
<div class="c_db_ut">

</div>


<div class="c_db_itb " style="margin-bottom:13px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">4 dias atrás</span>

<div class="c_db_itc">
<span ><span dir='ltr' style='zoom: 1;'>Katia</span></span>: <span dir='ltr' style='zoom: 1;'>O QUE É BOM DURA POUCO!!!</span> | <a target='_top' href='http://cid-60d992da60cdcc76.profile.live.com/notes/'>Postar uma observação</a>

</div>
</div>

</div>

</div>

<div class='c_db_i' n="Katia" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:0px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">5 dias atrás</span>

<div class="c_db_itc">

<span ><span dir='ltr' style='zoom: 1;'>Katia</span></span>: <span dir='ltr' style='zoom: 1;'>FÉRIAS ACABANDO!!!!!!</span> | <a target='_top' href='http://cid-60d992da60cdcc76.profile.live.com/notes/'>Postar uma observação</a>
</div>
</div>

</div>

</div>


</div>

</div>
</td>
</tr>
<tr>
<td>
<div class="WNICContainer">

<div id="ICc1" class="cxp_ic cxp_ic_h_m_t">


<div id="ICc1_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc1_frame_clip" title="Imagem de deni-66@hotmail.com" class="cxp_ic_frame_clip" target="_top" href="http://cid-f722d6f8bb5b4c50.profile.live.com/" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';">

<img id="ICc1_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de deni-66@hotmail.com" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc1_usertile" srcTo="http://f722d6f8bb5b4c50.users.storage.live.com/users/-638711833349632944/MyProfile/ExpressionProfile/ProfilePhoto:UserTileStatic?fofoff=1&ex=48&ck=1" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de deni-66@hotmail.com" />
</div>

</div>

<div id="ICc1_text" class="cxp_ic_text_h cxp_ic_text_h_m">


<div>
<span id="ICc1_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="deni-66@hotmail.com" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">deni-66@ho​tmail.com</span>

</div>

<div id="ICc1_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>

</div>

</div>
<div class="WNDBContainer">

<div class="c_db c_db_noUt " >

<div class='c_db_i' n="Denise" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:13px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">5 dias atrás</span>

<div class="c_db_itc">

<span ><span dir='ltr' style='zoom: 1;'>Denise</span></span> possui uma nova imagem no Messenger
</div>
</div>

<div class="c_db_ib">
<a target='_top' class='c_db_imgLink' href='http://cid-f722d6f8bb5b4c50.profile.live.com/'><img class='c_db_imgFloat c_db_imgBorder' srcTo='http://byfiles.storage.msn.com/y1pm-h_Qk7KbGV5TqnFvBuLDOcZUwliiWzwrr1eA3As2dJiW6q_-NslC-dH8JvqAHkfKhni699o9as' alt='' onload='$db_TreatImg(this, 0, 0,75,0,1);' onerror="this.style.display='none';"/></a> | <a target='_top' href='http://cid-f722d6f8bb5b4c50.profile.live.com/notes/'>Postar uma observação</a>
<span class='c_db_clear'></span>
</div>

</div>

</div>


<div class='c_db_i' n="Denise" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:0px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">21 Set.</span>

<div class="c_db_itc">
<span ><span dir='ltr' style='zoom: 1;'>Denise</span></span> ingressou na rede de <a target='_top' style='-moz-outline-style: none;' href='http://cid-3C629BAB8640C568.profile.live.com'><span dir='ltr' style='zoom: 1;'>joni rogerio</span></a>

</div>
</div>

</div>

</div>

</div>

</div>
</td>
</tr>
<tr>

<td>
<div class="WNICContainer">

<div id="ICc2" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc2_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc2_frame_clip" title="Imagem de nathsalgueiro@hotmail.com" class="cxp_ic_frame_clip" target="_top" href="http://cid-29d591045fd54ded.profile.live.com/" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';">

<img id="ICc2_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de nathsalgueiro@hotmail.com" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc2_usertile" srcTo="http://29d591045fd54ded.users.storage.live.com/users/3014474973568126445/MyProfile/ExpressionProfile/ProfilePhoto:UserTileStatic?fofoff=1&ex=48&ck=1" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de nathsalgueiro@hotmail.com" />

</div>

</div>

<div id="ICc2_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc2_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="nathsalgueiro@hotmail.com" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">nathsalgue​iro@hotmail​.com</span>

</div>

<div id="ICc2_psm" class="cxp_ic_psm cxp_ic_hide" ></div>


</div>

<div class="c_clr"></div>

</div>

</div>
<div class="WNDBContainer">

<div class="c_db c_db_noUt " >

<div class='c_db_i' n="Nath" >
<div class="c_db_ut">


</div>

<div class="c_db_itb " style="margin-bottom:13px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">26 Out.</span>

<div class="c_db_itc">
<span ><span dir='ltr' style='zoom: 1;'>Nath</span></span>: <span dir='ltr' style='zoom: 1;'>o que se leva da vida é a vida que se leva!;P</span> | <a target='_top' href='http://cid-29d591045fd54ded.profile.live.com/notes/'>Postar uma observação</a>

</div>
</div>

</div>

</div>

<div class='c_db_i' n="Nath" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:0px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">18 Out.</span>

<div class="c_db_itc">

<span ><span dir='ltr' style='zoom: 1;'>Nath</span></span> possui uma nova imagem no Messenger
</div>
</div>

<div class="c_db_ib">
<a target='_top' class='c_db_imgLink' href='http://cid-29d591045fd54ded.profile.live.com/'><img class='c_db_imgFloat c_db_imgBorder' srcTo='http://byfiles.storage.msn.com/y1pAKgRYxq7phIh35byyfeLlxQNlqKzCpte5aOiyWDdb7IW6vR1_9jSOoc8pgJ49eN9RQQieRzGjqQ' alt='' onload='$db_TreatImg(this, 0, 0,75,0,1);' onerror="this.style.display='none';"/></a> | <a target='_top' href='http://cid-29d591045fd54ded.profile.live.com/notes/'>Postar uma observação</a>
<span class='c_db_clear'></span>
</div>

</div>

</div>


</div>

</div>
</td>
</tr>
<tr>
<td>
<div class="WNICContainer">

<div id="ICc3" class="cxp_ic cxp_ic_h_m_t">


<div id="ICc3_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc3_frame_clip" title="Imagem de wesley_dossantos@hotmail.com" class="cxp_ic_frame_clip" target="_top" href="http://cid-5a9067561e87371d.profile.live.com/" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';">

<img id="ICc3_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de wesley_dossantos@hotmail.com" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc3_usertile" srcTo="http://5a9067561e87371d.users.storage.live.com/users/6525829479636875037/MyProfile/ExpressionProfile/ProfilePhoto:UserTileStatic?fofoff=1&ex=48&ck=1" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de wesley_dossantos@hotmail.com" />
</div>

</div>

<div id="ICc3_text" class="cxp_ic_text_h cxp_ic_text_h_m">


<div>
<span id="ICc3_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="wesley_dossantos@hotmail.com" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">wesley_dos​santos@hotm​ail.com</span>

</div>

<div id="ICc3_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>


</div>

</div>
<div class="WNDBContainer">

<div class="c_db c_db_noUt " >

<div class='c_db_i' n="wesley" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:13px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">15 Out.</span>

<div class="c_db_itc">

<span ><span dir='ltr' style='zoom: 1;'>wesley</span></span>: <span dir='ltr' style='zoom: 1;'>' Amanha tem prova ieu no shoOp rS ' </span> | <a target='_top' href='http://cid-5a9067561e87371d.profile.live.com/notes/'>Postar uma observação</a>
</div>
</div>


</div>

</div>

<div class='c_db_i' n="wesley" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:0px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">14 Out.</span>

<div class="c_db_itc">
<span ><span dir='ltr' style='zoom: 1;'>wesley</span></span>: <span dir='ltr' style='zoom: 1;'>' Cada vez mais saindo daquela vidinhã --' | Amanhã *---* | SaindO cada vez mais daquela vidinhã--' </span> | <a target='_top' href='http://cid-5a9067561e87371d.profile.live.com/notes/'>Postar uma observação</a>

</div>
</div>

</div>

</div>

</div>

</div>
</td>
</tr>
<tr>

<td>
<div class="WNICContainer">

<div id="ICc4" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc4_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc4_frame_clip" title="Imagem de nana_mng@hotmail.com" class="cxp_ic_frame_clip" target="_top" href="http://cid-0daef2ea286fb5fa.profile.live.com/" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';">

<img id="ICc4_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de nana_mng@hotmail.com" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc4_usertile" srcTo="http://0daef2ea286fb5fa.users.storage.live.com/users/985992455955396090/MyProfile/ExpressionProfile/ProfilePhoto:UserTileStatic?fofoff=1&ex=48&ck=1" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de nana_mng@hotmail.com" />

</div>

</div>

<div id="ICc4_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc4_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="nana_mng@hotmail.com" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">nana_mng@h​otmail.com</span>

</div>

<div id="ICc4_psm" class="cxp_ic_psm cxp_ic_hide" ></div>


</div>

<div class="c_clr"></div>

</div>

</div>
<div class="WNDBContainer">

<div class="c_db c_db_noUt " >

<div class='c_db_i' n="Mariana" >
<div class="c_db_ut">


</div>

<div class="c_db_itb " style="margin-bottom:13px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">14 Out.</span>

<div class="c_db_itc">
<span ><span dir='ltr' style='zoom: 1;'>Mariana</span></span>: <span dir='ltr' style='zoom: 1;'> (On <a href="http://www.ebuddy.com" target="_blank">www.ebuddy.com</a> Web Messenger)</span> | <a target='_top' href='http://cid-0daef2ea286fb5fa.profile.live.com/notes/'>Postar uma observação</a>

</div>
</div>

</div>

</div>

<div class='c_db_i' n="Mariana" >
<div class="c_db_ut">

</div>

<div class="c_db_itb " style="margin-bottom:0px;">
<div class="c_db_it c_mcp">
<span class="c_db_i_age">27 Ago.</span>

<div class="c_db_itc">

<span ><span dir='ltr' style='zoom: 1;'>Mariana</span></span>: <span dir='ltr' style='zoom: 1;'>...meu milagre está chegando, enfim Deus está agindo...agora é só ser feliz!!!</span> | <a target='_top' href='http://cid-0daef2ea286fb5fa.profile.live.com/notes/'>Postar uma observação</a>

</div>
</div>

</div>

</div>

</div>

</div>
</td>
</tr>
<tr>

<td>
<div class="WNDBContainer">
<a href="http://g.live.com/9wc9pt-br/WN6 " target="_top">Mais...</a>
</div>
</td>
</tr>
</table>
</div></div><div class="ATNWNTable ATNZ">
<!-- Add to network Module -->

<h2>Sugestões para a sua rede</h2>
<span class="ATNSubHeader">Essas são as pessoas da sua lista de contatos. Se adicioná-las à sua rede, você terá novas maneiras de manter contato. <a href="http://g.live.com/9wc9pt-br/add2" target="_blank">Saiba mais</a></span>
<script type="text/javascript" defer="defer">
var atncheckedState = [true, true, true, true];
var atnUrl = 'http\x3a\x2f\x2fcid-5d5ef9da01061fdd.profile.live.com\x2fconnect\x2fselect.aspx';
var atnReturnUrl = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d448679727';
var atnInviteParams = [
['denise','0','denise.moreira\x40pop.com.br','89f8b0aa-8ca7-47b0-907e-a95cc40dbec3','denise',''],
['selma','0','selmacesar\x40ig.com.br','33844a15-ad1c-478a-8303-94ad52da830a','selma',''],
['selma','0','selmacesar\x40ig.com','7cbeb15e-662c-4b31-97f1-14db66c80f68','selma',''],
['\x210000\x21','0','alerta-virus\x40x.com.br','dd7906e6-45ae-419d-8331-ea98cc9b7f8a','\x210000\x21','']
];
function onCheckBoxClickedATN(elt, id)
{
if (elt == null)
{
return;
}

var addButton = $('AddToNetworkBtn');
if (addButton == null)
{
return;
}

var checkedStateLength = atncheckedState.length;
var newState = elt.checked;
atncheckedState[id] = newState;


if (newState)
{
if (addButton.disabled == true)
{
addButton.disabled = false;
}
}
else
{
var on = 0;
for (var i = checkedStateLength; i--;)
{
(atncheckedState == true ? on += 1 : on);
}
if (!on)
{
addButton.disabled = true;
}
}
}

function createAndSubmitAddToNetworkForm(method, target, action)
{
if (!action)
{
return;
}

var _method = (method || "GET");
var _target = (target || "_top");
var _action = action;

var _form = document.createElement("FORM");
if (_form)
{
_form.method = _method;
_form.target = _target;
_form.action = _action;
_form = createAndAppendParams(_form, atnInviteParams);
document.body.appendChild(_form);

_form.submit();
}
}
function createAndAppendParams(formElt, params)
{
if (!formElt || !params)
{
return;
}
// do ru first
var _ruParam = document.createElement("input");
_ruParam.type = "hidden";
_ruParam.name = "ru";
_ruParam.value = atnReturnUrl;
formElt.appendChild(_ruParam);

var length = atncheckedState.length;
for (var i = length; i--; )
{
if (atncheckedState)
{
var _snInviteParam = document.createElement("input");
_snInviteParam.type = "hidden";
_snInviteParam.name = "sn_invitee";
_snInviteParam.value = [
params[0], // name
params[1], // cid
"", // email, we no longer send this per request of the invite team
params[3], // contactID (GUID)
params[4], // first name
params[5] // last name
].join(',');

formElt.appendChild(_snInviteParam);
}
}

return formElt;
}
</script>
<div id="ATNControl" class="ATNContainer">
<table width="100%" cellpadding="0" cellspacing="0">
<colgroup>
<col class="ATNColCheckBox" />
<col class="ATNColContent" />

</colgroup>

<tr>
<td>

<input class=""
checked="checked"
name=""
onclick="onCheckBoxClickedATN(this, 0)"
type="checkbox"
value="0"
/>

</td>
<td>
<div class="ATNICContainer">

<div id="ICc5" class="cxp_ic cxp_ic_h_m_t">


<div id="ICc5_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc5_frame_clip" title="Imagem de denise" class="cxp_ic_frame_clip" target="_top" href="#" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';return false;">

<img id="ICc5_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de denise" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc5_usertile" srcTo="http://gfx1.hotmail.com/mail/w4/pr01/ltr/abUserTile.gif" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de denise" />
</div>

</div>

<div id="ICc5_text" class="cxp_ic_text_h cxp_ic_text_h_m">


<div>
<span id="ICc5_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="denise" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">denise</span>

</div>

<div id="ICc5_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>

</div>

</div>

</td>
</tr>

<tr>
<td>

<input class=""
checked="checked"
name=""
onclick="onCheckBoxClickedATN(this, 1)"
type="checkbox"
value="1"
/>

</td>
<td>
<div class="ATNICContainer">


<div id="ICc6" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc6_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc6_frame_clip" title="Imagem de selma" class="cxp_ic_frame_clip" target="_top" href="#" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';return false;">

<img id="ICc6_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de selma" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc6_usertile" srcTo="http://gfx1.hotmail.com/mail/w4/pr01/ltr/abUserTile.gif" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de selma" />
</div>

</div>


<div id="ICc6_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc6_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="selma" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">selma</span>

</div>

<div id="ICc6_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>

</div>

</div>
</td>
</tr>

<tr>
<td>

<input class=""
checked="checked"
name=""
onclick="onCheckBoxClickedATN(this, 2)"
type="checkbox"
value="2"
/>

</td>
<td>

<div class="ATNICContainer">

<div id="ICc7" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc7_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc7_frame_clip" title="Imagem de selma" class="cxp_ic_frame_clip" target="_top" href="#" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';return false;">

<img id="ICc7_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de selma" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc7_usertile" srcTo="http://gfx1.hotmail.com/mail/w4/pr01/ltr/abUserTile.gif" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de selma" />
</div>


</div>

<div id="ICc7_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc7_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="selma" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">selma</span>

</div>

<div id="ICc7_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>

<div class="c_clr"></div>


</div>

</div>
</td>
</tr>

<tr>
<td>

<input class=""
checked="checked"
name=""
onclick="onCheckBoxClickedATN(this, 3)"
type="checkbox"
value="3"
/>

</td>

<td>
<div class="ATNICContainer">

<div id="ICc8" class="cxp_ic cxp_ic_h_m_t">

<div id="ICc8_usertilecontainer" class="cxp_ic_img_h cxp_ic_img_m">
<a id="ICc8_frame_clip" title="Imagem de !0000!" class="cxp_ic_frame_clip" target="_top" href="#" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_ut??su=http://shared.live.com/Live.Mail';return false;">

<img id="ICc8_frame" srcTo="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/iciconmap24.png" class="cxp_ic_blueframe" alt="Imagem de !0000!" />

</a>
<div class="cxp_ic_tile_clip">
<img id="ICc8_usertile" srcTo="http://gfx1.hotmail.com/mail/w4/pr01/ltr/abUserTile.gif" errsrc="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/ic/bluemann.png" onload="ic_onTileLoad(this)" onerror="ic_onTileErr(this)" style="visibility:hidden;" alt="Imagem de !0000!" />

</div>

</div>

<div id="ICc8_text" class="cxp_ic_text_h cxp_ic_text_h_m">

<div>
<span id="ICc8_name" class="cxp_ic_name cxp_ic_name_m" target="_self" href="#" title="!0000!" onclick="i = new Image(); i.src = 'http://g.live.com/_9uxp9pt-br/ic_dn??su=http://shared.live.com/Live.Mail';return false;">!0000!</span>

</div>

<div id="ICc8_psm" class="cxp_ic_psm cxp_ic_hide" ></div>

</div>


<div class="c_clr"></div>

</div>

</div>
</td>
</tr>

</table>
</div>

<div class="ANTIButton">

<input class="UiButton" type="button" value="Adicionar à sua rede" onclick="createAndSubmitAddToNetworkForm('POST', '_top', atnUrl);" id="AddToNetworkBtn" />
</div>

<!-- Add to network module End -->
</div><div class="ATNWNTable ATCLZ"></div><div class="OptOut"><div class="TodayOptOut BorderTop">Deseja iniciar com sua caixa de entrada? Para ignorar a página Hoje ao entrar, <a href="TodayPageOptOut.aspx?n=682977255" target="_self">altere suas configurações</a>.</div></div>
</div>
</td>
<td class="SideAdCol">
<div class="TodayRightContentContainer">

<div class="ProductSearchBox TodayContentModule">

<script type="text/javascript" defer="defer">

SearchBox = {};
SearchBox.setValue = function SearchBox$updateSearchValue(value)
{
var elt = document.getElementById("productSearchTerms"); elt.value = value; elt.className = "c_ml c_fia"; elt.s="t"; // not empty string
}
SearchBox.resetValue = function SearchBox$resetValue()
{
var elt = document.getElementById("productSearchTerms"); elt.value = elt.getAttribute("r"); elt.className = "c_ml TextItalic"; elt.s="";
}

</script>
<div class="c_hf">
<span class="c_search">
<input id="productSearchTerms" type="text" class="c_ml TextItalic"
onblur="if(''==this.value){SearchBox.resetValue();};this.form.s=false;"
onfocus="if(this.s!='t'){SearchBox.setValue('');}this.form.s=true;" onkeydown="var kc = event.keyCode; if (kc == 3 || kc == 13) { document.getElementById('psbtn').click(); event.cancelBubble = true; return false; }" autocomplete="Off" value="Pesquisar no email" r="Pesquisar no email" title="Pesquisar no email (/)"/>
<a class="c_nootl glyph" onclick="document.getElementById('psbtn').click(); event.cancelBubble = true; return false;" href="#" id="c_hsbt">
<span>
<img title="Pesquisar" alt="Pesquisar" src="http://gfx1.hotmail.com/mail/uxp/w4/m1/pr06/h/strip.png"/>
</span>

</a>
</span>
</div>
<input id="psbtn" type="button" onclick="var t = $('productSearchTerms');if($containsClass(t, 'c_fia') && '' != t.value.trim()){SearchInbox();}" style="display: none;" />
</div>
<div class="SideAds TodayContentModule">

<div id="RadAd_Today300" class="" style="">
<script defer="defer" type="text/javascript">
g_adsToFire[g_adsToFire.length] = ["RadAd_Today300", "&AP=1089&PG=WLMBR1&UC=127", "300", "250", false];
</script>
</div>


</div><div class="Birthdays TodayContentModule">


<div class="TodayContent Narrow">
<h2 style="padding-bottom: 4px;">Aniversários</h2>

<div><a href='http://g.live.com/9wc9pt-br/bday1'>Adicione seu aniversário</a> para que possamos lembrar todas as pessoas da sua rede quando é o grande dia.</div>

</div></div><div class="MsnContent TodayContentModule"><div class="TodayContent Narrow">
<h2>Manchetes</h2>

<div>
<div id="edtab" class="parent chrome6 hexa0">
<div class="MsnContent">
<h3>'2012'</h3>
<div class="NewsImages"><a target="_blank" target="_blank" href="http://video.msn.com/video.aspx?mkt=pt-br&amp;brand=&amp;vid=a1d598cb-9523-45f5-9831-e93e41b61005&amp;from=&amp;fg=rss"><img border="0" width="40" src="http://col.stb.s-msn.com/i/22/5FA8BE6B8D3CF58EF891B49FCD6D7B.jpg"></a></div>
<div class="NewsItems WithImage">
<ul>
<li class="BoldText"><a target="_blank" href="http://video.msn.com/video.aspx?mkt=pt-br&amp;brand=&amp;vid=a1d598cb-9523-45f5-9831-e93e41b61005&amp;from=&amp;fg=rss" target="_blank">Trecho do filme '2012', dirigido por Roland Emmerich</a></li></ul>
</div>
</div>
<div class="MsnContent">
<h3>Fique por dentro</h3>
<div class="NewsItems">

<ul>
<li class="BoldText"><a target="_blank" href="http://noticias.br.msn.com/mundo/artigo-bbc.aspx?cp-documentid=22600501" target="_blank">Nasa anuncia descoberta de grande quantidade de água na Lua</a></li><li><a target="_blank" href="http://noticias.br.msn.com/mundo/artigo.aspx?cp-documentid=22602430" target="_blank">Obama propõe maior envolvimento dos EUA com a Ásia</a></li><li><a target="_blank" href="http://entretenimento.br.msn.com/famosidades/noticias-artigo.aspx?cp-documentid=22601648" target="_blank">Madonna sobe morro, beija bandeira de escola de samba e esbanja simpatia no Rio</a></li><li><a target="_blank" href="http://dinheiro.br.msn.com/financaspessoais/noticia.aspx?cp-documentid=22600490" target="_blank">Ibovespa avança 1,36% e fecha segunda semana de alta; dólar é cotado a R$ 1,723</a></li></ul>
</div>
</div>
</div>
</div>
</div></div><div class="SideAds">

<div id="CustComm_300x125_TodayPage" class="" style="">
<script defer="defer" type="text/javascript">
g_adsToFire[g_adsToFire.length] = ["CustComm_300x125_TodayPage", "&AP=1419&PG=WLMBRA&UC=127", "300", "125", false];
</script>

</div>

</div>
</div>
</td>
</tr></table>
<div id="cxp_ic_usertiles" style="display:none"></div>
<script type="text/javascript" defer="defer">
window.cxp_ic_common_data = {
imgbaseurl:'http\x3a\x2f\x2fgfx1.hotmail.com\x2fmail\x2fuxp\x2fw4\x2fm1\x2fpr06\x2fic\x2f',
showpresence:'1',
webpresence:'1',
socialcontext:'0',
vcid:'5d5ef9da01061fdd',
p_av:'\x28Dispon\u00edvel\x29',
p_b:'\x28Ocupado\x29',
p_aw:'\x28Ausente\x29',
p_off:'\x28Offline\x29',
max_name:'20',
tp_no_name:'Exibir fotos desta pessoa',
ru:'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3fn\x3d448679727'};
window.cxp_ic_menu_data = {
ut:['','','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_ut\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
dn:['','','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_dn\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
ps:['','','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_ps\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
ev:['Exibir evento','http\x3a\x2f\x2fcid-\x7bcid\x7d.events.live.com\x2f','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_ev\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
gr:['Exibir grupo','http\x3a\x2f\x2fcid-\x7bcid\x7d.groups.live.com\x2f','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_gr\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
pr:['Exibir perfil','http\x3a\x2f\x2fcid-\x7bcid\x7d.profile.live.com\x2f','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_pr\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
se:['Enviar email','\x2fmail\x2f\x3frru\x3dcompose\x253faction\x253dcompose\x2526to\x253d\x7baddress\x7d\x26ru\x3d\x7bru\x7d','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_se\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
sm:['Enviar uma mensagem particular','http\x3a\x2f\x2fspaces.live.com\x2fapi.aspx\x3fwx_action\x3dsendMessage\x26wxp_toCid\x3d\x7baddress\x7d\x26wx_ru\x3d\x7bru\x7d\x26mkt\x3dpt-br','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_sm\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
si:['Enviar uma mensagem instant\u00e2nea','','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_si\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
mc:['','','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_mc\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
c1:['Adicionar a sua rede','http\x3a\x2f\x2fcid-\x7bvcid\x7d.profile.live.com\x2fconnect\x2fsend.aspx\x3fname\x3d\x7bname\x7d\x26scontext\x3d\x7bscxt\x7d\x26ru\x3d\x7bru\x7d\x26mkt\x3dpt-br','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_c1\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
c4:['Reenviar convite','http\x3a\x2f\x2fcid-\x7bvcid\x7d.profile.live.com\x2fconnect\x2fsend.aspx\x3fname\x3d\x7bname\x7d\x26scontext\x3d\x7bscxt\x7d\x26ru\x3d\x7bru\x7d\x26mkt\x3dpt-br','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_c4\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
c2:['Adicionar ao Messenger','http\x3a\x2f\x2fcid-\x7bvcid\x7d.profile.live.com\x2fconnect\x2fsend.aspx\x3fname\x3d\x7bname\x7d\x26scontext\x3d\x7bscxt\x7d\x26ru\x3d\x7bru\x7d\x26mkt\x3dpt-br','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_c2\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
c3:['Adicionar ao perfil','http\x3a\x2f\x2fcid-\x7bvcid\x7d.profile.live.com\x2fconnect\x2fsend.aspx\x3fname\x3d\x7bname\x7d\x26scontext\x3d\x7bscxt\x7d\x26ru\x3d\x7bru\x7d\x26mkt\x3dpt-br','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_c3\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
ph:['Exibir fotos','http\x3a\x2f\x2fcid-\x7bcid\x7d.skydrive.live.com\x2falbums.aspx','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_ph\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
tp:['Exibir fotos de \x7bname\x7d','http\x3a\x2f\x2fcid-\x7bcid\x7d.skydrive.live.com\x2fpeopletags.aspx','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_tp\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail'],
ct:['Exibir informa\u00e7\u00f5es de contato','\x2fmail\x2f\x3frru\x3dcontacts\x253fcontact\x253d\x7bcontactid\x7d','http\x3a\x2f\x2fg.live.com\x2f_9uxp9pt-br\x2fic_ct\x3f\x3fsu\x3dhttp\x3a\x2f\x2fshared.live.com\x2fLive.Mail']};
window.cxp_ic_control_data = {
ICc0:['60d992da60cdcc76','1',['se','sm','si','ct'],'kofnatpret\x26\x2364\x3byahoo.com.br','943aadcb-f525-4c3a-a67a-3769807fbad3','6978770564211919990','kofnatpret\x40yahoo.com.br','kofnatpret\x40yahoo.com.br','','1'],
ICc1:['f722d6f8bb5b4c50','1',['se','sm','si','ct'],'deni-66\x26\x2364\x3bhotmail.com','70607dbb-d9e1-46eb-a9b3-15468c002b3d','-638711833349632944','deni-66\x40hotmail.com','deni-66\x40hotmail.com','','1'],
ICc2:['29d591045fd54ded','1',['se','sm','si','ct'],'nathsalgueiro\x26\x2364\x3bhotmail.com','d53ca174-bd67-4086-ad55-32822f3690e6','3014474973568126445','nathsalgueiro\x40hotmail.com','nathsalgueiro\x40hotmail.com','','1'],
ICc3:['5a9067561e87371d','1',['se','sm','si','ct'],'wesley_dossantos\x26\x2364\x3bhotmail.com','c32e4520-e57a-4c04-9b33-6bdc482059c3','6525829479636875037','wesley_dossantos\x40hotmail.com','wesley_dossantos\x40hotmail.com','','1'],
ICc4:['0daef2ea286fb5fa','1',['se','sm','si','ct'],'nana_mng\x26\x2364\x3bhotmail.com','dc074c84-f1fe-4584-b60e-16cea7c89aee','985992455955396090','nana_mng\x40hotmail.com','nana_mng\x40hotmail.com','','1'],
ICc5:['0000000000000000','1',['se','ct'],'denise','89f8b0aa-8ca7-47b0-907e-a95cc40dbec3','0','denise.moreira\x40pop.com.br','cid\x3a0','','1'],
ICc6:['0000000000000000','1',['se','ct'],'selma','33844a15-ad1c-478a-8303-94ad52da830a','0','selmacesar\x40ig.com.br','cid\x3a0','','1'],
ICc7:['0000000000000000','1',['se','ct'],'selma','7cbeb15e-662c-4b31-97f1-14db66c80f68','0','selmacesar\x40ig.com','cid\x3a0','','1'],
ICc8:['0000000000000000','1',['se','ct'],'\x26\x2333\x3b0000\x26\x2333\x3b','dd7906e6-45ae-419d-8331-ea98cc9b7f8a','0','alerta-virus\x40x.com.br','cid\x3a0','','1']};
if(typeof($cxp_ic)!='undefined'&&typeof($cxp_ic.ic)!='undefined'){$cxp_ic.ic.init();}
</script>


</div>



</div>
</form>
</div>
</div>
<div id="FooterContainer" class="FooterContainer">
<table id="uxp_ftr_control" cellpadding="0" cellspacing="0">
<tr>
<td id="uxp_ftr_left">
<ul>

<li><a id="uxp_ftr_link_trademark" target="_top" href="http://g.live.com/9uxp9pt-br/ftr1">&copy; 2009 Microsoft</a></li>

<li><a id="uxp_ftr_link_privacy" target="_top" href="http://go.microsoft.com/fwlink/?LinkId=74170">Privacidade</a></li>
<li class="uxp_ftr_item_last"><a id="uxp_ftr_link_legal" target="_top" href="http://g.msn.com/0TO_/ptbr">Termos de uso</a></li>

</ul>
</td>
<td id="uxp_ftr_right">
<table id="uxp_ftr_right_nest" cellpadding="0" cellspacing="0">
<tr>

<td>
<ul>

<li><a id="uxp_ftr_link_custom1" target="_top" href="https://support.live.com/default.aspx?productkey=wlpeopleabuse">Relatar abuso</a></li>

<li><a id="uxp_ftr_link_account" target="_top" href="http://g.live.com/9uxp9pt-br/ftr3">Conta</a></li>
<li class="uxp_ftr_item_last"><a id="uxp_ftr_link_feedback" target="_top" href="http://g.live.com/9uxp9pt-br/ftr4?productkey=wlmail">Comentários</a></li>
</ul>

</td>
</tr>
</table>
</td>
</tr>
</table>
</div>
</div>
</div>
<div id="PageBottomElt">


<img style="display:none;" id="cleargif" width="1" height="1" alt="" name="http://h.msn.com/c.gif?RF=&PI=44280&DI=5709&PS="/>

<script>
var PS = "96753";
</script>

<div style="display:none">

<div id="tmpl_infopane" style="display:none">

<div class="InfoPane">
<div class="InfoPaneInner ErrorPriMedium">
<img src="./clear.gif" class="i_warn ErrorImg" id="infoImg" title="Aviso" alt="Aviso"/>
<span>{0}</span>


</div>
</div>

</div>

</div>
<div style="overflow: hidden; height: 1em; width: 1em; z-index: -100; position: absolute; top:0em; left: 0em;">
<div id="EM2PX" style="width: 1000em;" onresize="return Control.invokeStatic('Resize', '_OnEMChange', event);"><s ns="rs" doFirst="doFirst">&nbsp;</s></div>
<div id="THEME_FL_HOVER" class="THEME_FL_HOVER"></div>
<div id="THEME_FL_IDLE" class="THEME_FL_IDLE"></div>
</div>


</div>


<iframe id="mergedLoginHistoryFrame" src="MergedLoginHistoryFrame_15.1.3028.1103.html?dl=dl#" style="display:none;"></iframe>


<div id="appDiv" style="height:0px;width:0px">
<iframe id="UIFrame" name="UIFrame" style="display:none;" src="javascript:;"
frameborder="0"
width="100%"
height="100%"
marginheight="0"
marginwidth="0">
</iframe>

<iframe id="IMFrame" frameborder="0" width="0" height="0" src=""></iframe>

</div>


</body>
<div id="PageAfterElt">

<script type="text/javascript">
PerfRecorder = {
config:{allowInstrumentation :true,
market:'pt-br',
reportMode:'2',
sendTransactionsByImage:true,
sampleFrequency:'100',
delimiter:'\x26',
cookieName:'prc',
pltImg:'plx2.gif',
pltTransList:'L\x3aI, L\x3aT, L\x3aML',
transactionLimit:'50',
maxSessionDuration:'240',
privateDomain:'.mail.live.com',
sharedDomain:'.live.com'},
GT1Param:"",
page:{landingPageName:"", timeStamp:""},
stopPageTimer:function(){},
startTimer:function(){},
sendTransaction:function(){}
};
</script>

<img id="3rdPartyOmniture" style="display:none;" width="1" height="1" alt="" name="http://msnportal.112.2o7.net/b/ss/msnportalhotmail/1/H.1-pdv-2/" />


<script>PerfRecorder.page.landingPageName = "T";</script>

<script>
Loc = {isBidi : false,LEFT : "left",RIGHT : "right",LRM : "\u200e",RLM : "\u200f"};Res = {strings : {browserJSError: "O Windows Live Hotmail n%c3%a3o p%c3%b4de concluir esta solicita%c3%a7%c3%a3o. A Microsoft poder%c3%a1 contatar voc%c3%aa sobre os problemas informados.",loading: "Carregando...",noconnectivity:"N%c3%a3o %c3%a9 poss%c3%advel se conectar ao Windows Live Hotmail agora. Verifique se voc%c3%aa est%c3%a1 conectado %c3%a0 Internet e tente novamente",fppTimeout: "N%c3%a3o foi poss%c3%advel concluir a tarefa. Tente novamente.",fppInternalErr: "N%c3%a3o %c3%a9 poss%c3%advel se conectar ao Windows Live Hotmail agora. Tente novamente mais tarde."}};App = { BUILD : "15.1.3028.1103",config : {adsMinInterval: "2", adsMinActions : "1",cookieDomain: ".mail.live.com",imgSvrUrl : "http://gfx2.hotmail.com/mail/w4/pr01/ltr/"}};Page = {addFeedbackData : function(){},pageComplete : function(){},fppPending : function(){},FORM_ID:'aspnetForm',fppCfg : { RequestHandler:"mail.fpp",FppVersion:1,SessionId:"f4%2bVVgU7ONgTuOquSKSFEg%3d%3d",AuthUser:"2763942204",CanaryToken:"mt",Version:"1",PartnerID:""},SELF_PATH : '\x2fdefault.aspx',queryString : {nonce : '386717109',newNonce : '1022365543'}};Resize = {};
KbdShortcuts = {timeout : 1000,hasSeenUi : false,hasSeenUiText : "Voc%c3%aa usou um atalho de teclado. Caso isso n%c3%a3o tenha sido intencional%2c clique em Cancelar. Para desativar os atalhos ou alternar o seu modo de atalho%2c v%c3%a1 para Op%c3%a7%c3%b5es.",uiSeenUrl : '\x2fmail\x2fOptionsWriter.aspx\x3fn\x3d1376107468\x26mt\x3d01_31b39308f7e8def7c272de26f667e33806cb3c2e70d3b4ae7611333aa402d26e\x257cb69e0715e383bd0f\x26kuis\x3dtrue'};
</script>



<script defer="defer" src="http://gfx6.hotmail.com/mail/15.1.3028.1103/l0a.mozilla.js"></script>


<script>
PersistenceMerge = {cfg : {bodyStyle : "padding:0;margin:0;overflow:visible;height:100%;width:100%;position:absolute;",htmlStyle : "overflow:hidden;",appDivStyle : "position:absolute;height:100%;width:100%;",uiFrameOnloadFunc : uiFrameLoad,beforeUnloadFunc : beforeUnloadHandler,historyFrameId : "mergedLoginHistoryFrame"}};
</script>


<script defer="defer" src="http://gfx6.hotmail.com/mail/15.1.3028.1103/pfm.js"></script>


<script>

TodaySmcPage = {sysFldrs : {inboxFid : "00000000-0000-0000-0000-000000000001",sentFid : "00000000-0000-0000-0000-000000000003",draftsFid : "00000000-0000-0000-0000-000000000004" },pdCookie : "pd-2763942204",kbdShortcuts : {"CTRL78":"newMsg","191":"searchMail","70":{"73":"goToInbox","83":"goToSent","68":"goToDrafts"}}};
</script>

<script defer="defer" src="http://gfx6.hotmail.com/mail/15.1.3028.1103/ts0a.js"></script>




<script defer="defer" src="http://gfx6.hotmail.com/mail/15.1.3028.1103/shared.js"></script>



<script defer="defer" src="http://gfx6.hotmail.com/mail/15.1.3028.1103/ic.js"></script>


<FONT size="1">[AD]</FONT>



<script defer="defer" type="text/javascript" src="http://help.live.com/resources/neutral/launchhelp.js"></script>

<img style="display:none" src="http://gfx1.hotmail.com/mail/w4/pr01/ltr/plx.gif" />


<script defer="defer" type="text/javascript">
if(null==window["$Config"])
window["$Config"] = {};
window.$Config.Themes =
{
baseUrl:'http\x3a\x2f\x2fgfx8.hotmail.com\x2fmail\x2f15.1.3028.1103\x2fstyles\x2f',
current:'base',
version:'',
url:'http\x3a\x2f\x2fgfx8.hotmail.com\x2fmail\x2f15.1.3028.1103\x2fstyles\x2f\x2fbase\x2f',
hmtwUrl:'\x2fmail\x2fOptionsWriter.aspx\x3fn\x3d1526808054\x26mt\x3d01_31b39308f7e8def7c272de26f667e33806cb3c2e70d3b4ae7611333aa402d26e\x257cb69e0715e383bd0f\x26themeId\x3d'
}
</script>



</div>
</html>
 
Desculpe tenho que mandar um de cada vez, pois eles são grandes.
Este ela recebeu, o estranho e que o destinatario são todos para hotmail com nome dela so mudando complemento (ex. fulanacheri@hotmail, fulanacasa@hotmail ...)


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html style="overflow:hidden;">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>


<base href="http://sn116w.snt116.mail.live.com/mail/TodayLight.aspx?layout=TodayDefault&rru=inbox&n=554505890" />

<script type="text/javascript">


var isPersistenceInline = false, redirectUrl = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3dinbox\x26n\x3d554505890';


var domainLoweringIsDown = false;
document.domain = "live.com";

if (window.top != self)
{
var hostname = "";
try
{
hostname = window.top.location.hostname;
}
catch(e)
{
hostname = "";
}

var mailUrlDomain = "mail.live.com";
var peopleUrlDomain = "people.live.com";
var hasMailUrl = (hostname != "") &&
(hostname.indexOf(mailUrlDomain) != -1) &&
((hostname.indexOf(mailUrlDomain) + mailUrlDomain.length) == hostname.length);
var hasPeopleUrl = (hostname != "") &&
(hostname.indexOf(peopleUrlDomain) != -1) &&
((hostname.indexOf(peopleUrlDomain) + peopleUrlDomain.length) == hostname.length);
if (!hasMailUrl && !hasPeopleUrl)
{
window.top.location.href = self.location.href;
}
else
{
self.location.href = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3dinbox\x26n\x3d554505890';
}
}
else if (domainLoweringIsDown)
{
if (self.location.hostname.indexOf("mail.live.com") <= 0)
{
document.cookie = "afu=" + escape('http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3dinbox\x26n\x3d554505890') + ";path=/;domain=.mail.live.com;";
self.location.href = 'sn116w.snt116.mail.live.com';
}
}


var gLoadIM = true,
gUIFrameBaseUrl = "";
function loadIM(q)
{
if (gLoadIM &&
(!q || q.indexOf('nwi=1') < 0))
{
gLoadIM = false;
var win = getUiWindow(), loc = win.location;
gUIFrameBaseUrl = loc.host;
var imFrame = document.getElementById("IMFrame");
if (imFrame)
{
imFrame.src = [loc.protocol, "//", gUIFrameBaseUrl, "/im/pages/im.aspx"].join("");
}
imFrame = null;
}
}


function uiFrameLoad()
{
//
try
{
if(!isPersistenceInline)
{
document.title = window.frames[0].document.title;
}

if (gLoadIM)
{
loadIM(getUiWindow().location.search);
}

}
catch(e)
{
}
}
function beforeUnloadHandler()
{
try
{
var frameUrl = getUiWindow().document.location.href;
document.cookie = "afu=" + escape(frameUrl) + ";path=/;domain=.mail.live.com;";
}
catch(e)
{
}
}
function getUiFrame()
{
return document.getElementById("UIFrame");
}
function getUiFrameOrBody()
{
return isPersistenceInline ? document.body : getUiFrame();
}
function getUiWindow()
{
return isPersistenceInline ? window : getUiFrame().contentWindow;
}
function makePersistenceStandalone()
{
isPersistenceInline = false;

var imFrame = document.getElementById("IMFrame");
if(imFrame && imFrame.contentWindow.updateUIFrameRef)
{
imFrame.contentWindow.updateUIFrameRef();
}

}
function redirectToLandingPage()
{
if(!isPersistenceInline)
{
getUiFrame().src = 'http\x3a\x2f\x2fsn116w.snt116.mail.live.com\x2fmail\x2fTodayLight.aspx\x3flayout\x3dTodayDefault\x26rru\x3dinbox\x26n\x3d554505890';
}
}
</script>

</head>
<body style="padding:0;margin:0;overflow:visible;height:100%;width:100%;position:absolute;" onbeforeunload="beforeUnloadHandler()">

<div id="appDiv" style="position:absolute;height:100%;width:100%;">

<iframe id="UIFrame" name="UIFrame" src="http://sn116w.snt116.mail.live.com/mail/TodayLight.aspx?layout=TodayDefault&rru=inbox&n=554505890" onload="uiFrameLoad();"
frameborder="0"
width="100%"
height="100%"
marginheight="0"
marginwidth="0">
</iframe>

<iframe id="IMFrame" frameborder="0" width="0" height="0" src=""></iframe>

</div>

</body>
</html>
 
Olá Mr Wolf,
Quanto tempo hein?!
Tudo bem com vc? Muito trabalho aqui no fórum né?!
Só passando pra ver se esse log tem alguma entrada maliciosa ainda?
Muitíssimo Obrigado Mr Wolf,
Forte abraço!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:16:58, on 14/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\TBridge\FLATBED.EXE
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Messenger\msmsgs.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Arquivos de programas\Windows Live\Toolbar\wltuser.exe
C:\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer do Windows fornecido por Yahoo! Brasil
F3 - REG:win.ini: load=C:\TBridge\FLATBED.EXE
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (MSN Games – Matchmaking) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (MSN Games – Game Chat) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {86D33886-21AC-11D7-B475-0080AD750764} (Midiocx Control) - http://www.somaceio.com.br/karaoke/midiocx.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: GbPluginBb - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8311 bytes

P.S.: Posso remover essas seguintes entradas desse log?

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (MSN Games – Matchmaking) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (MSN Games – Game Chat) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {86D33886-21AC-11D7-B475-0080AD750764} (Midiocx Control) - http://www.somaceio.com.br/karaoke/midiocx.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL
 
Última edição:
Sdfix log

SDFix: Version 1.240
Run by Felipe on 14/11/2009 at 09:33

Microsoft Windows XP [versÆo 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\csrcs.exe - Deleted
C:\WINDOWS\system32\msvcrt2.dll - Deleted
C:\WINDOWS\system32\SysMgr.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-11-14 10:03:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\bb4abb33cac5]
"0022b48deaa7"=hex:48,db,38,7c,1c,1f,1f,07,e2,83,73,34,a2,76,7f,92
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ypebp]
"DisplayName"="Windows Image"
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs"
"ObjectName"="LocalSystem"
"Description"="Provides system and desktop level support to the NVIDIA display driver"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ypebp\Parameters]
"ServiceDll"=str(2):"C:\WINDOWS\system32\mdpgn.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\bb4abb33cac5]
"0022b48deaa7"=hex:48,db,38,7c,1c,1f,1f,07,e2,83,73,34,a2,76,7f,92
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Arquivos de programas\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:7c,bb,68,8b,86,d0,05,f2,f4,e7,c2,c6,76,28,3a,05,58,be,81,d1,15,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,92,9a,89,b9,2d,a7,7a,ff,6e,ac,23,cc,d2,70,9e,ea,24,..
"hdf12"=hex:d8,db,4d,6e,8c,5e,c7,3a,1f,c6,08,7d,88,2b,88,b3,08,e4,45,59,84,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:10,84,da,83,3e,82,8a,ac,0b,71,39,a7,be,a7,f4,16,8d,ee,7a,ba,e0,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ypebp]
"DisplayName"="Windows Image"
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs"
"ObjectName"="LocalSystem"
"Description"="Provides system and desktop level support to the NVIDIA display driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ypebp\Parameters]
"ServiceDll"=str(2):"C:\WINDOWS\system32\mdpgn.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\bb4abb33cac5]
"0022b48deaa7"=hex:48,db,38,7c,1c,1f,1f,07,e2,83,73,34,a2,76,7f,92
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Arquivos de programas\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:7c,bb,68,8b,86,d0,05,f2,f4,e7,c2,c6,76,28,3a,05,58,be,81,d1,15,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,92,9a,89,b9,2d,a7,7a,ff,6e,ac,23,cc,d2,70,9e,ea,24,..
"hdf12"=hex:d8,db,4d,6e,8c,5e,c7,3a,1f,c6,08,7d,88,2b,88,b3,08,e4,45,59,84,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:10,84,da,83,3e,82,8a,ac,0b,71,39,a7,be,a7,f4,16,8d,ee,7a,ba,e0,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ypebp]
"DisplayName"="Windows Image"
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000000
"ImagePath"=str(2):"%SystemRoot%\system32\svchost.exe -k netsvcs"
"ObjectName"="LocalSystem"
"Description"="Provides system and desktop level support to the NVIDIA display driver"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\ypebp\Parameters]
"ServiceDll"=str(2):"C:\WINDOWS\system32\mdpgn.dll"

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000043b

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
"C:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"="C:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbit"
"C:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"="C:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orbit"
"C:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Arquivos de programas\\uTorrent\\uTorrent.exe"="C:\\Arquivos de programas\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
"C:\\WINDOWS\\Temp\\~os7.tmp\\pmropn.exe"="C:\\WINDOWS\\Temp\\~os7.tmp\\pmropn.exe:*:Enabled:pmropn.exe"
"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Arquivos de programas\\Spotify\\spotify.exe"="C:\\Arquivos de programas\\Spotify\\spotify.exe:*:Enabled:Spotify"
"c:\\arquivos de programas\\premieropinion\\pmropn.exe"="c:\\arquivos de programas\\premieropinion\\pmropn.exe:*:Enabled:pmropn.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
"C:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Arquivos de programas\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Arquivos de programas\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 13 Apr 2009 140,707 ...H. --- "C:\Arquivos de programas\Windows Sidebar\uninst.exe"
Mon 24 Aug 2009 848 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Wed 22 Dec 2004 76,568 ..SHR --- "C:\Arquivos de programas\Autodesk\Autodesk DWF Viewer\Setup.exe"
Thu 13 Jan 2005 11,360 A.SHR --- "C:\Arquivos de programas\Autodesk\Autodesk DWF Viewer\_Setupx.dll"
Sat 18 Feb 2006 73,728 A..H. --- "C:\Coord\Instrutores\Reuniäes\~WRL0071.tmp"
Thu 30 Dec 2004 343,040 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL0056.tmp"
Mon 13 Dec 2004 342,016 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL0163.tmp"
Mon 13 Dec 2004 338,944 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL0804.tmp"
Mon 13 Dec 2004 343,040 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL0814.tmp"
Tue 14 Dec 2004 205,824 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL0898.tmp"
Thu 30 Dec 2004 343,552 A..H. --- "C:\Coord\Alunos\Aula & Planejamento\Exerc¡cios\Caderno de Exerc¡cio Atualizado\SOS NET\~WRL3433.tmp"

Finished!
 
cssrs.exe é uma arquivo do sistema

Passe o Malwarebytes Antimalware aí.
Não tem nada no seu log, mas se o virus está voltando, é porque algo escondido está baixando o mesmo.

Obrigado ae Lyraal! :thumbs_up
 
Ola Mr. Wolf
Realmente eu tinha criado aquela pasta (Windows), tirei o jogo de la e acabou o problema!!:D
Passei o scan do Mban denovo, agora eu acho q eu estou limpo :yes:
Malwarebytes' Anti-Malware 1.41
Versão do banco de dados: 3100
Windows 5.1.2600 Service Pack 3

14/11/2009 15:06:15
mbam-log-2009-11-14 (15-06-15).txt

Tipo de Verificação: Completa (C:\|)
Objetos verificados: 215131
Tempo decorrido: 1 hour(s), 18 minute(s), 0 second(s)

Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 2
Valores do Registro infectados: 0
Ítens do Registro infectados: 0
Pastas infectadas: 0
Arquivos infectados: 0

Processos da Memória infectados:
(Nenhum ítem malicioso foi detectado)

Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)

Chaves do Registro infectadas:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\poprock (Trojan.Downloader) -> Quarantined and deleted successfully.

Valores do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Ítens do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Pastas infectadas:
(Nenhum ítem malicioso foi detectado)

Arquivos infectados:
(Nenhum ítem malicioso foi detectado)
Estou colocando o log do hijackthis tb!!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:13:21, on 14/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\Spyware Doctor\pctsAuxs.exe
C:\Arquivos de programas\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\alg.exe
C:\Arquivos de programas\Spyware Doctor\pctsTray.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
C:\Arquivos de programas\Realtek\RTL8185 Wireless LAN Utility\RtWLan.exe
C:\Arquivos de programas\internet explorer\iexplore.exe
C:\Arquivos de programas\internet explorer\iexplore.exe
C:\Arquivos de programas\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbiehcef.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SmartDefrag] "C:\Arquivos de programas\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ISTray] "C:\Arquivos de programas\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: REALTEK RTL8185 Wireless LAN Utility.lnk = C:\Arquivos de programas\Realtek\RTL8185 Wireless LAN Utility\RtWLan.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Arquivos de programas\Arquivos comuns\SolidWorks Shared\Service\SolidWorksLicensing.exe

--
End of file - 6571 bytes
Vlw Mr. Wolf!!!!!!!
 
Ola Mr Wolf
Tudo joia
E o seguinte? estava navegando na net qnd de repente uma mensagem do eset smart security: win32/agent trojan (esse java que saco, era um .jar que executou na pasta bin do java).
O eset finalizou como "connection terminated - quarentined"
O source era um HTTP filter.
Por favor, podes dar uma olhada no log do HijackThis
Obrigado e um grande abraço
Juliano =)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:29:06, on 14/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Juliano\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI" TRANSFORMS="C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST" WISE_SETUP_EXE_PATH="c:\nvidia\displaydriver\190.62\english\PhysX_9.09.0814_SystemSoftware.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1255322457901
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6514 bytes
 
Valeu mesmo, Mr. Wolf :)

Esses dois são de outra máquina, queria que desse uma olhada.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:15, on 14/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
C:\Arquivos de programas\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\DAP\DAP.EXE
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe
c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe
c:\ARQUIV~1\ARQUIV~1\mcafee\mcproxy\mcproxy.exe
C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Last.fm\LastFM.exe
C:\Arquivos de programas\iTunes\iTunes.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\Documents and Settings\usuario\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SBCONVERT - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - C:\Arquivos de programas\SpeedBit Video Downloader\TBUDC\tbcore3.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Arquivos de programas\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\ARQUIV~1\DAP\DAPIEL~1.DLL
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\ARQUIV~1\SPEEDB~1\TBUDC\grabber.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Arquivos de programas\SpeedBit Video Downloader\TBUDC\tbcore3.dll
O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Arquivos de programas\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Arquivos de programas\DAP\DAP.EXE" /STARTUP
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm
O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm
O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm
O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm
O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F42911F-1B92-4CB2-9FB7-2210EFC0D097}: NameServer = 200.149.55.140 200.165.132.147
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Arquivos de programas\WinPcap\rpcapd.exe

--
End of file - 9824 bytes

ComboFix 09-11-15.01 - usuario 14/11/2009 22:45.2.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1023.652 [GMT -2:00]
Executando de: c:\documents and settings\usuario\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* AV residente está ativo

.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\arquivos de programas\SpeedBit Toolbar\Toolbar\tbhelper.dll
c:\arquivos de programas\SpeedBit Video Downloader\Toolbar\tbhelper.dll

.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-10-15 to 2009-11-15 ))))))))))))))))))))))))))))
.

2009-11-06 01:10 . 2009-11-06 01:10 91648 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit\DAP\SDCondition.dll
2009-11-06 01:03 . 2009-11-06 01:03 -------- d-----w- c:\arquivos de programas\SpeedBit Toolbar
2009-11-06 00:55 . 2009-11-06 00:52 251392 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit\DAP\Temp\dapop.dll
2009-11-06 00:55 . 2009-11-06 00:55 3317784 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit\DAP\Offers\VA3_DapSo.exe
2009-11-06 00:52 . 2009-11-14 20:32 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP
2009-11-06 00:52 . 2009-11-06 00:52 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit
2009-11-06 00:52 . 2009-11-06 01:03 -------- d-----w- c:\arquivos de programas\DAP
2009-11-06 00:52 . 2009-11-06 01:02 -------- d-----w- c:\arquivos de programas\SpeedBit Video Downloader
2009-11-01 20:19 . 2009-11-01 20:19 -------- d-----w- c:\arquivos de programas\WinPcap
2009-10-27 00:38 . 2009-10-27 00:37 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-27 00:37 . 2009-10-27 00:51 -------- d-----w- c:\documents and settings\usuario\.housecall6.6
2009-10-26 01:32 . 2009-10-26 01:32 -------- d-----w- c:\temp\installtemped
2009-10-26 01:32 . 2009-10-26 01:32 -------- d-----w- C:\Temp
2009-10-24 23:15 . 2009-10-24 23:16 -------- d-----w- C:\!KillBox
2009-10-20 22:59 . 2008-05-09 10:55 90112 -c----w- c:\windows\system32\dllcache\wshext.dll
2009-10-20 22:59 . 2008-05-09 10:55 180224 -c----w- c:\windows\system32\dllcache\scrobj.dll
2009-10-20 22:59 . 2008-05-09 10:55 172032 -c----w- c:\windows\system32\dllcache\scrrun.dll
2009-10-20 22:59 . 2008-05-09 08:45 135168 -c----w- c:\windows\system32\dllcache\cscript.exe
2009-10-20 22:59 . 2008-05-08 11:24 155648 -c----w- c:\windows\system32\dllcache\wscript.exe
2009-10-20 00:26 . 2009-10-20 00:26 -------- d-----w- c:\windows\l2schemas
2009-10-20 00:26 . 2009-10-20 00:26 -------- d-----w- c:\windows\system32\bits
2009-10-18 21:19 . 2009-10-18 21:19 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-18 21:19 . 2009-10-18 21:19 -------- d-----w- c:\arquivos de programas\MSBuild
2009-10-18 21:19 . 2009-10-18 21:19 -------- d-----w- c:\arquivos de programas\Reference Assemblies
2009-10-18 21:19 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-18 21:19 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-18 21:19 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-10-18 21:19 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-18 21:19 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-10-18 21:19 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-10-18 21:19 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-18 21:19 . 2009-10-18 21:19 -------- d-----w- C:\357990c6e19be66f345fde91b3b5
2009-10-18 21:16 . 2009-10-18 21:16 -------- d-----w- c:\arquivos de programas\MSXML 6.0
2009-10-18 21:12 . 2009-10-18 21:13 -------- d-----w- C:\LinhaDefensiva
2009-10-18 21:04 . 2009-10-18 21:04 -------- d-----w- C:\MSNCleaner
2009-10-18 19:33 . 2004-08-04 01:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2009-10-18 16:14 . 2009-10-18 16:14 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Malwarebytes
2009-10-18 16:14 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-18 16:14 . 2009-10-18 16:14 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2009-10-18 16:14 . 2009-10-18 16:14 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2009-10-18 16:14 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-18 15:57 . 2008-06-19 19:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-18 15:53 . 2009-10-18 15:53 -------- d-----w- c:\arquivos de programas\Panda Security
2009-10-18 15:31 . 2009-10-18 15:31 -------- d-----w- c:\arquivos de programas\AxBx
2009-10-18 15:23 . 2009-10-18 15:23 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-18 15:13 . 2009-10-18 15:14 344576 --sh--w- c:\documents and settings\All Users\Dados de aplicativos\orkuthreat.exe
2009-10-18 15:12 . 2009-10-18 15:15 351 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\UpApp32.dll
2009-10-18 15:11 . 2009-10-18 15:13 763 ----a-w- c:\windows\apsou.vbs
2009-10-17 17:16 . 2009-10-17 17:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-17 13:27 . 2009-10-17 13:27 -------- d-sh--w- c:\documents and settings\usuario\IECompatCache
2009-10-17 13:26 . 2009-10-17 13:26 -------- d-sh--w- c:\documents and settings\usuario\PrivacIE
2009-10-17 13:22 . 2009-10-17 13:22 -------- d-sh--w- c:\documents and settings\usuario\IETldCache
2009-10-17 13:18 . 2009-10-18 06:00 -------- d-----w- c:\windows\ie8updates
2009-10-17 13:15 . 2009-10-17 13:16 -------- dc-h--w- c:\windows\ie8

.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-14 20:52 . 2009-09-27 05:50 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Free Download Manager
2009-11-14 20:36 . 2001-10-28 18:07 80198 ----a-w- c:\windows\system32\perfc016.dat
2009-11-14 20:36 . 2001-10-28 18:07 471376 ----a-w- c:\windows\system32\perfh016.dat
2009-11-14 17:24 . 2009-09-27 04:53 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\uTorrent
2009-11-14 05:17 . 2009-09-26 22:44 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Skype
2009-11-13 18:06 . 2009-09-26 22:45 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\skypePM
2009-11-13 00:50 . 2007-10-06 00:44 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\BSplayer Pro
2009-10-23 21:13 . 2009-10-11 02:38 -------- d-----w- c:\arquivos de programas\McAfee
2009-10-23 01:18 . 2009-09-27 05:50 -------- d-----w- c:\arquivos de programas\Free Download Manager
2009-10-18 20:06 . 2009-10-05 02:36 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Symantec Shared
2009-10-17 13:24 . 2007-09-01 02:36 -------- d-----w- c:\arquivos de programas\iTunes
2009-10-15 23:19 . 2009-10-09 01:36 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\HPAppData
2009-10-15 01:41 . 2009-10-15 01:38 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Autodesk Shared
2009-10-15 01:37 . 2009-10-15 01:37 -------- d-----w- c:\arquivos de programas\Autodesk
2009-10-13 22:04 . 2009-10-13 22:04 -------- d-----w- c:\arquivos de programas\MSXML 4.0
2009-10-12 16:27 . 2002-02-15 16:13 -------- d-----w- c:\arquivos de programas\Warcraft III
2009-10-12 15:41 . 2008-08-09 18:12 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Vso
2009-10-12 15:41 . 2007-08-11 14:49 -------- d-----w- c:\arquivos de programas\Windows Media Connect 2
2009-10-12 15:38 . 2009-09-27 02:33 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\IObit
2009-10-11 05:40 . 2009-09-27 02:34 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\McAfee
2009-10-11 02:39 . 2009-10-11 02:38 -------- d-----w- c:\arquivos de programas\Arquivos comuns\McAfee
2009-10-11 02:39 . 2009-10-11 02:38 -------- d-----w- c:\arquivos de programas\McAfee.com
2009-10-09 01:29 . 2009-10-09 01:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\WEBREG
2009-10-09 01:28 . 2009-10-09 01:22 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\HP
2009-10-09 01:28 . 2009-10-09 01:17 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\HP
2009-10-09 01:22 . 2009-10-08 23:45 168001 ----a-w- c:\windows\hpoins28.dat
2009-10-09 01:21 . 2009-10-09 01:21 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Hewlett-Packard
2009-10-09 01:17 . 2009-10-09 01:17 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\HP Product Assistant
2009-10-09 01:17 . 2009-10-09 01:15 -------- d-----w- c:\arquivos de programas\HP
2009-10-09 01:17 . 2009-10-09 01:17 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Hewlett-Packard
2009-10-09 01:17 . 2009-10-09 01:17 -------- d-----w- c:\arquivos de programas\Arquivos comuns\HP
2009-10-04 22:40 . 2009-10-04 22:39 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Norton
2009-10-04 22:39 . 2009-10-04 22:39 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Symantec
2009-10-04 22:39 . 2009-10-04 22:39 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\NortonInstaller
2009-10-04 00:28 . 2009-09-27 04:52 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!
2009-09-29 16:27 . 2007-08-11 14:54 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe
2009-09-27 05:50 . 2009-09-27 05:50 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\FreeDownloadManager.ORG
2009-09-27 04:55 . 2009-09-27 04:55 -------- d-----w- c:\arquivos de programas\uTorrent
2009-09-27 02:37 . 2009-09-27 02:37 -------- d-----w- c:\arquivos de programas\Messenger Plus! Live
2009-09-27 02:33 . 2009-09-27 02:33 -------- d-----w- c:\arquivos de programas\IObit
2009-09-27 02:33 . 2009-09-27 02:33 -------- d-----w- c:\arquivos de programas\CCleaner
2009-09-27 01:42 . 2007-08-11 14:10 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information
2009-09-26 22:45 . 2009-09-26 22:45 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-09-26 22:44 . 2009-09-26 22:42 -------- d-----r- c:\arquivos de programas\Skype
2009-09-26 22:42 . 2009-09-26 22:42 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype
2009-09-26 22:42 . 2009-09-26 22:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Skype
2009-09-26 22:27 . 2009-09-26 22:26 287 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Last.fm\Client\uninst2.bat
2009-09-26 22:27 . 2009-09-26 22:27 683801 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Last.fm\Client\UninstWMP\unins000.exe
2009-09-26 22:27 . 2009-09-26 22:27 683801 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Last.fm\Client\UninstWA\unins000.exe
2009-09-26 22:26 . 2009-09-26 22:26 683801 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Last.fm\Client\UninstITW\unins000.exe
2009-09-26 22:26 . 2009-09-26 22:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Last.fm
2009-09-26 22:26 . 2009-09-26 22:26 -------- d-----w- c:\arquivos de programas\Last.fm
2009-09-26 20:14 . 2009-09-26 20:14 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight
2009-09-26 20:13 . 2009-09-26 20:10 -------- d-----w- c:\arquivos de programas\Microsoft
2009-09-26 20:13 . 2009-09-26 20:13 -------- d-----w- c:\arquivos de programas\Microsoft Office Outlook Connector
2009-09-26 20:13 . 2009-09-26 20:09 -------- d-----w- c:\arquivos de programas\Windows Live
2009-09-26 20:13 . 2009-09-26 20:13 -------- d-----w- c:\arquivos de programas\Microsoft Sync Framework
2009-09-26 20:12 . 2009-09-26 20:12 -------- d-----w- c:\arquivos de programas\Microsoft SQL Server Compact Edition
2009-09-26 20:10 . 2009-09-26 20:10 -------- d-----w- c:\arquivos de programas\Windows Live SkyDrive
2009-09-26 19:21 . 2009-09-26 19:21 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live
2009-09-26 12:42 . 2009-09-25 21:33 -------- d-----w- c:\arquivos de programas\Oi Velox
2009-09-16 12:22 . 2009-10-11 02:40 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 12:22 . 2009-10-11 02:40 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 12:22 . 2009-10-11 02:40 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 12:22 . 2009-07-08 16:44 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 12:22 . 2009-10-11 02:24 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:19 . 2004-08-04 02:45 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:04 . 2004-08-04 02:45 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:57 . 2004-08-04 02:45 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:15 . 2004-08-04 02:45 247326 ----a-w- c:\windows\system32\strmdll.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-10-31_23.06.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-16 17:09 . 2009-08-06 21:24 44768 c:\windows\system32\wups2.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 35552 c:\windows\system32\wups.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 53472 c:\windows\system32\wuauclt.exe
+ 2007-11-06 20:22 . 2007-11-06 20:22 68224 c:\windows\system32\WanPacket.dll
+ 2009-11-04 00:55 . 2009-08-06 21:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2009-11-04 00:55 . 2009-08-06 21:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2007-11-06 20:19 . 2007-11-06 20:19 53299 c:\windows\system32\pthreadVC.dll
+ 2001-10-28 18:07 . 2009-11-14 20:36 68292 c:\windows\system32\perfc009.dat
- 2001-10-28 18:07 . 2009-10-31 21:28 68292 c:\windows\system32\perfc009.dat
+ 2007-11-06 20:22 . 2007-11-06 20:22 88696 c:\windows\system32\Packet.dll
+ 2007-11-06 20:22 . 2007-11-06 20:22 34064 c:\windows\system32\drivers\npf.sys
+ 2007-08-11 13:00 . 2009-08-06 21:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-04 02:45 . 2009-08-06 21:24 96480 c:\windows\system32\dllcache\cdm.dll
- 2007-08-11 13:07 . 2009-10-31 21:22 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-11-01 02:15 . 2009-11-14 20:59 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-08-11 13:07 . 2009-11-14 20:59 32768 c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-11 13:07 . 2009-10-31 21:22 32768 c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-11 13:07 . 2009-10-31 21:22 32768 c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat
+ 2007-08-11 13:07 . 2009-11-14 20:59 32768 c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat
+ 2004-08-04 02:45 . 2009-08-06 21:24 96480 c:\windows\system32\cdm.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 209632 c:\windows\system32\wuweb.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 327896 c:\windows\system32\wucltui.dll
+ 2007-08-11 13:00 . 2009-08-06 21:23 575704 c:\windows\system32\wuapi.dll
+ 2007-11-06 20:23 . 2007-11-06 20:23 240248 c:\windows\system32\wpcap.dll
- 2001-10-28 18:07 . 2009-10-31 21:28 435396 c:\windows\system32\perfh009.dat
+ 2001-10-28 18:07 . 2009-11-14 20:36 435396 c:\windows\system32\perfh009.dat
+ 2007-08-11 09:48 . 2009-11-12 02:18 356952 c:\windows\system32\FNTCACHE.DAT
- 2007-08-11 09:48 . 2009-10-20 22:45 356952 c:\windows\system32\FNTCACHE.DAT
+ 2007-08-11 13:00 . 2009-08-06 21:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2007-08-11 13:00 . 2009-08-06 21:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2007-08-11 13:00 . 2009-08-06 21:23 575704 c:\windows\system32\dllcache\wuapi.dll
- 2009-09-29 16:28 . 2009-09-29 16:28 295606 c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe
+ 2009-09-29 16:28 . 2009-11-12 23:42 295606 c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe
+ 2009-11-03 23:19 . 2008-07-08 12:58 395128 c:\windows\ie8updates\KB976749-IE8\spuninst\updspapi.dll
+ 2009-11-03 23:19 . 2008-07-08 12:58 233336 c:\windows\ie8updates\KB976749-IE8\spuninst\spuninst.exe
+ 2007-08-11 13:00 . 2009-08-06 21:23 1929952 c:\windows\system32\wuaueng.dll
+ 2004-08-04 02:38 . 2009-08-14 15:15 1850752 c:\windows\system32\win32k.sys
+ 2004-08-04 02:45 . 2009-10-22 09:17 5939712 c:\windows\system32\mshtml.dll
+ 2007-08-11 13:00 . 2009-08-06 21:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2009-04-19 19:50 . 2009-08-14 15:15 1850752 c:\windows\system32\dllcache\win32k.sys
+ 2004-08-04 02:45 . 2009-10-22 09:17 5939712 c:\windows\system32\dllcache\mshtml.dll
+ 2009-10-07 01:32 . 2009-10-07 01:32 4733440 c:\windows\Installer\1f288.msp
+ 2009-11-12 23:42 . 2009-11-12 23:42 1711616 c:\windows\Installer\11753d.msp
+ 2009-11-03 23:19 . 2009-08-29 07:57 5940224 c:\windows\ie8updates\KB976749-IE8\mshtml.dll
+ 2009-10-15 23:29 . 2009-11-05 17:36 26768832 c:\windows\system32\MRT.exe
+ 2008-10-15 03:42 . 2008-10-15 03:42 13219184 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76401B7448A3100000030\8.1.3\AcroRd32.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B}]
2009-11-06 01:02 2655736 ----a-w- c:\arquivos de programas\SpeedBit Video Downloader\TBUDC\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\arquivos de programas\DAP\DAP.EXE" [2009-11-06 2803200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"desp2k"="c:\arquivos de programas\Oi Velox\Manager\desp2k.exe" [2006-08-03 65536]
"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"mcagent_exe"="c:\arquivos de programas\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"Malwarebytes Anti-Malware (reboot)"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"QuickTime Task"="c:\arquivos de programas\K-Lite Codec Pack\QuickTime\qttask.exe" [2007-06-29 286720]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^usuario^Menu Iniciar^Programas^Inicializar^Reboot.exe]
path=c:\documents and settings\usuario\Menu Iniciar\Programas\Inicializar\Reboot.exe
backup=c:\windows\pss\Reboot.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\StepMania CVS\\Program\\StepMania.exe"=
"c:\\Arquivos de programas\\Warcraft III\\Warcraft III.exe"=
"c:\\Arquivos de programas\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\Arquivos comuns\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [18/10/2009 13:57 28544]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [6/11/2007 18:22 34064]

--- =Outros Serviços/Drivers Na Memória ---

*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Conteúdo da pasta 'Tarefas Agendadas'

2007-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2007-06-03 16:42]

2009-10-11 c:\windows\Tasks\McDefragTask.job
- c:\arquiv~1\mcafee\mqc\QcConsol.exe [2009-10-11 14:22]

2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\arquiv~1\mcafee\mqc\QcConsol.exe [2009-10-11 14:22]

2009-11-14 c:\windows\Tasks\User_Feed_Synchronization-{549ECE67-9207-4B6E-A3D6-95D0D8D36602}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 07:31]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://search.speedbit.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Clean Traces - c:\arquivos de programas\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\arquivos de programas\DAP\dapextie.htm
IE: Baixar com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dllink.htm
IE: Baixar tudo com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlall.htm
IE: Baixar vídeo com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlfvideo.htm
IE: Download &all with DAP - c:\arquivos de programas\DAP\dapextie2.htm
IE: Download selecionado pelo Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlselected.htm
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {8F42911F-1B92-4CB2-9FB7-2210EFC0D097} = 200.149.55.140 200.165.132.147
FF - ProfilePath - c:\documents and settings\usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\29y57njr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (pt)
FF - prefs.js: browser.startup.homepage - hxxp://pt-BR.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pt-BR:eek:fficial
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q=
FF - component: c:\arquivos de programas\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: c:\arquivos de programas\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-11-14 22:52
Windows 5.1.2600 Service Pack 3 NTFS

Procurando processos ocultos ...

Procurando entradas auto inicializáveis ocultas ...

Procurando ficheiros/arquivos ocultos ...

Varredura completada com sucesso
arquivos/ficheiros ocultos: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, GMER - Rootkit Detector and Remover

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x86F808AC]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, GMER - Rootkit Detector and Remover

atapi.sys @ 0x0 0x0 bytes

\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7246B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7246B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7246B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF7246B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7246B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7246B40 atapi.sys
\Driver\atapi IRP hooks detected !

**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

[HKEY_USERS\S-1-5-21-606747145-1965331169-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:de,19,41,fc,8d,01,94,91,41,57,2c,9e,28,cc,91,5b,91,8e,9b,17,6c,23,df,
1c,1e,be,92,cc,05,2a,91,85,44,a8,aa,de,39,f3,d4,23,df,bc,90,cc,93,1d,72,99,\
"??"=hex:ba,fd,0f,63,1b,2b,94,42,db,fd,dc,03,2e,1d,d9,bc

[HKEY_USERS\S-1-5-21-606747145-1965331169-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:af,17,2b,11,f3,d9,65,97,1e,5d,57,e5,de,1e,91,6f,c0,73,95,da,aa,
9b,28,74,55,53,3e,22,20,8d,f2,10,68,e7,55,d2,15,25,dc,f8,c1,2b,55,c4,ba,6a,\
"rkeysecu"=hex:45,68,f7,54,53,7e,35,5d,30,41,1e,43,d3,9b,8a,d6
.
Tempo para conclusão: 2009-11-14 22:54
ComboFix-quarantined-files.txt 2009-11-15 00:54
ComboFix2.txt 2009-10-31 23:09

Pré-execução: 2.401.062.912 bytes disponíveis
Pós execução: 2.362.212.352 bytes disponíveis

- - End Of File - - 7EFBE9A9AD44B389EDD11FCC48F96EE2
 
Está aí Mr.
Só umas observações... nesse meio tempo instalei o AVAST!. Mas creio q isso não interfira...
Outra coisa, eu vi q o processo WinDefense32 está running. Cara, esse não é o Windows Defender? Eu já desativei-o lá no painel de controle...

Abraços! Obrigado
 

Attachments

  • virusinfo_syscheck.zip
    64.8 KB · Visitas: 58
Mr. Wolf da uma olhada no meu log do combofix por favor
e me diga se tem alguma entrada suspeita
grato desde já
abraço
ComboFix 09-11-16.01 - Administrador 15/11/2009 18:04.6.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1023.665 [GMT -3:00]
Executando de: c:\documents and settings\Administrador\Desktop\Anti-virus\ComboFix.exe
* AV residente está ativo

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-10-15 to 2009-11-15 ))))))))))))))))))))))))))))
.

2009-11-09 16:25 . 2009-11-09 16:25 -------- dc----w- c:\arquivos de programas\VID_0E8F&PID_0003
2009-11-08 02:16 . 2007-12-26 20:30 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
2009-11-08 02:16 . 2007-12-26 20:30 1970176 ----a-w- c:\windows\system32\d3dx9.dll
2009-11-08 02:15 . 2009-11-08 02:16 -------- dc----w- c:\arquivos de programas\Cheat Engine
2009-11-05 23:36 . 2009-11-06 00:36 -------- dc----w- c:\arquivos de programas\Realtek AC97
2009-11-05 04:49 . 2009-11-05 04:49 -------- dc----w- c:\arquivos de programas\GameHi_USA
2009-11-05 04:39 . 2009-11-05 04:39 12862 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{0E2B767B-EA6A-489B-BF83-8083FE1DB661}\_1EEFFF72773535163E4216.exe
2009-11-05 04:39 . 2009-11-05 04:39 -------- dc----w- c:\arquivos de programas\Pcsx2
2009-11-04 22:04 . 2009-03-09 18:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-11-04 22:04 . 2009-03-09 18:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-11-04 22:04 . 2009-03-09 18:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-11-04 22:03 . 2009-03-16 17:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-11-04 22:03 . 2009-03-16 17:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-11-04 22:03 . 2009-03-16 17:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-11-04 22:03 . 2009-03-16 17:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-11-04 22:02 . 2008-10-15 09:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-11-04 22:02 . 2008-10-15 09:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-11-04 22:02 . 2008-10-15 09:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2009-11-04 22:02 . 2008-10-15 10:03 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2009-11-04 22:02 . 2008-10-15 10:03 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2009-11-04 22:01 . 2008-10-15 10:03 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2009-11-04 22:01 . 2008-10-15 10:03 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2009-11-04 22:01 . 2008-07-30 09:20 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2009-11-04 22:01 . 2008-07-30 09:20 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2009-11-04 22:01 . 2008-07-30 09:20 238088 ----a-w- c:\windows\system32\xactengine3_2.dll
2009-11-04 22:00 . 2008-07-10 14:01 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2009-11-04 22:00 . 2008-07-10 14:00 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2009-11-04 22:00 . 2008-07-10 14:00 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2009-11-04 22:00 . 2008-05-30 17:19 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2009-11-04 22:00 . 2008-05-30 17:17 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2009-11-04 21:59 . 2008-05-30 17:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2009-11-04 21:59 . 2008-05-30 17:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2009-11-04 21:59 . 2008-05-30 17:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2009-11-04 21:59 . 2008-05-30 17:11 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2009-11-04 21:59 . 2008-05-30 17:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2009-11-04 21:58 . 2008-03-05 19:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-11-04 21:58 . 2008-03-05 19:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2009-11-04 21:58 . 2008-03-05 19:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2009-11-04 21:57 . 2008-03-05 18:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-11-04 21:57 . 2008-02-06 02:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-11-04 21:57 . 2008-03-05 18:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-11-04 21:57 . 2007-10-22 06:39 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
2009-11-04 21:57 . 2007-10-12 18:14 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2009-11-04 21:57 . 2007-10-02 12:56 444776 ----a-w- c:\windows\system32\d3dx10_36.dll
2009-11-04 21:56 . 2007-10-12 18:14 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
2009-11-04 21:56 . 2007-07-20 03:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
2009-11-04 21:56 . 2007-07-19 21:14 444776 ----a-w- c:\windows\system32\d3dx10_35.dll
2009-11-04 21:56 . 2007-07-19 21:14 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll
2009-11-04 21:56 . 2007-07-19 21:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-11-04 21:56 . 2007-10-22 06:37 17928 ----a-w- c:\windows\system32\X3DAudio1_2.dll
2009-11-04 21:56 . 2007-06-20 23:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2009-11-04 21:55 . 2007-05-16 19:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2009-11-04 21:55 . 2007-05-16 19:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2009-11-04 21:55 . 2007-05-16 19:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2009-11-04 21:55 . 2007-04-04 21:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2009-11-04 21:55 . 2007-04-04 21:55 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
2009-11-04 21:55 . 2007-03-15 19:57 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
2009-11-04 21:55 . 2007-03-12 19:42 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
2009-11-04 21:54 . 2007-03-12 19:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2009-11-04 21:54 . 2007-01-24 18:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll
2009-11-04 21:54 . 2006-12-08 15:02 251672 ----a-w- c:\windows\system32\xactengine2_5.dll
2009-11-04 21:54 . 2006-11-29 16:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-04 21:54 . 2007-03-05 15:42 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
2009-11-04 21:54 . 2006-09-28 19:05 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2009-11-04 21:54 . 2006-09-28 19:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-11-04 21:53 . 2006-07-28 12:30 236824 ----a-w- c:\windows\system32\xactengine2_3.dll
2009-11-04 21:53 . 2006-07-28 12:30 62744 ----a-w- c:\windows\system32\xinput1_2.dll
2009-11-04 21:51 . 2005-05-26 18:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-11-04 21:48 . 2009-11-04 21:48 -------- d-----w- c:\windows\Logs
2009-11-04 15:26 . 2009-11-05 04:49 -------- dc----w- C:\Download
2009-11-01 17:43 . 2009-07-16 19:32 139264 ----a-w- c:\windows\NeoUninstall.exe
2009-11-01 03:25 . 2009-11-01 03:25 -------- d-----w- c:\windows\system32\Te_mp_B_S!!
2009-10-28 04:35 . 2009-10-28 04:35 -------- dc----w- C:\VertigoGames
2009-10-28 00:55 . 2009-10-28 00:55 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AA2DeployClient
2009-10-27 23:54 . 2009-10-27 23:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AA3DeployClient
2009-10-25 07:22 . 2009-10-25 07:22 -------- dc----w- C:\Brasfoo2009

.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-15 18:18 . 2009-09-25 00:20 -------- dc----w- c:\arquivos de programas\sXe Injected
2009-11-15 17:51 . 2009-05-26 01:31 -------- d-----w- c:\arquivos de programas\VALVe
2009-11-09 17:53 . 2009-08-25 16:05 -------- dc----w- c:\arquivos de programas\Messenger Plus! Live
2009-11-07 16:27 . 2009-06-14 15:34 -------- dc-h--w- c:\arquivos de programas\InstallShield Installation Information
2009-11-07 01:03 . 2009-05-25 19:50 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\uTorrent
2009-11-05 02:58 . 2009-07-04 16:08 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\FMZilla
2009-10-16 04:06 . 2009-10-16 04:06 71152 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\NewShortcut21_C207166A39DE4B35B3CE8F35C423973B.exe
2009-10-16 04:06 . 2009-10-16 04:06 71152 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\NewShortcut2_8D2B9DEE2E7249CEB360F463F3370804.exe
2009-10-16 04:06 . 2009-10-16 04:06 71152 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\NewShortcut11_9D70A61FD7214BC585565549793FFA8A.exe
2009-10-16 04:06 . 2009-10-16 04:06 71152 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\NewShortcut1_9F88E99FAF234356849120C5725C6B5F.exe
2009-10-16 04:06 . 2009-10-16 04:06 58864 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\ARPPRODUCTICON.exe
2009-10-16 04:06 . 2009-10-16 04:06 54768 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}\UNINST_Uninstall_F_CF49ABBD814F419BA60B0CCC15F0A1F0.exe
2009-10-14 20:02 . 2008-04-14 12:00 73154 ----a-w- c:\windows\system32\perfc016.dat
2009-10-14 20:02 . 2008-04-14 12:00 452534 ----a-w- c:\windows\system32\perfh016.dat
2009-09-20 18:23 . 2009-02-19 21:41 2516 -csha-w- c:\documents and settings\All Users\Dados de aplicativos\KGyGaAvL.sys
2009-09-20 18:23 . 2009-02-19 21:41 2516 -csha-w- c:\documents and settings\All Users\Dados de aplicativos\KGyGaAvL.sys
2009-09-19 15:24 . 2009-09-19 15:24 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\SmartFTP
2009-09-19 15:10 . 2009-09-19 15:07 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\FileZilla
2009-09-18 14:01 . 2009-09-18 14:01 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\FLEXnet
2009-09-17 22:01 . 2009-05-18 17:00 -------- dc----w- c:\arquivos de programas\Arquivos comuns\Adobe
2009-09-17 21:51 . 2009-09-17 21:51 -------- dc----w- c:\arquivos de programas\Adobe Media Player
2009-09-17 21:43 . 2009-09-17 21:43 -------- dc----w- c:\arquivos de programas\Arquivos comuns\Adobe AIR
2009-09-17 21:24 . 2009-09-17 21:24 -------- dc----w- c:\arquivos de programas\Arquivos comuns\Macrovision Shared
2009-09-17 21:15 . 2009-09-17 21:04 -------- dc----w- c:\arquivos de programas\AdobeFlash
2009-09-17 18:50 . 2009-09-17 16:12 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Download Manager
2009-09-11 14:19 . 2008-04-14 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:43 . 2009-09-04 21:43 152576 ----a-w- c:\documents and settings\Administrador\Dados de aplicativos\Sun\Java\jre1.6.0_15\lzma.dll
2009-09-04 21:04 . 2008-04-14 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:57 . 2008-04-14 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:01 . 2008-04-14 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-24 22:32 . 2009-08-24 22:32 68296 ----a-w- c:\windows\system32\drivers\GRD.sys
2009-08-24 22:24 . 2009-08-24 22:24 50888 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2009-08-24 22:24 . 2009-08-24 22:24 50888 ----a-w- c:\windows\system32\drivers\GDTdiIcpt.sys
2009-08-23 23:17 . 2009-08-23 23:17 3584 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
.

------- Sigcheck -------



[-] 2008-05-05 . 4A242109B08C4355E72860807F151BF4 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll


c:\windows\system32\drivers\beep.sys ... está faltando !!
c:\windows\system32\wscntfy.exe ... está faltando !!
c:\windows\system32\regsvc.dll ... está faltando !!
.
((((((((((((((((((((((((((((( SnapShot@2009-11-13_16.28.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-15 21:01 . 2009-11-15 21:01 16384 c:\windows\temp\Perflib_Perfdata_744.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]
"Steam"="c:\arquivos de programas\Steam\Steam.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"nod32kui"="c:\arquivos de programas\Eset\nod32kui.exe" [2009-08-17 949376]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Sys32V2Contoller"="c:\documents and settings\Administrador\Desktop\mw2mmgr32\mw2mmgr32.exe" [BU]
"HTV Agent"="c:\arquivos de programas\HTV\HTV.exe" [BU]
"AdobeCS4ServiceManager"="c:\arquivos de programas\Arquivos comuns\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Cmaudio"="cmicnfg.cpl" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\Administrador\\Configurações locais\\Dados de aplicativos\\Kamuse\\KCSTrayDownloader\\KCSTrayDownloaderEngine.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56879:TCP"= 56879:TCP:pando Media Booster
"56879:UDP"= 56879:UDP:pando Media Booster
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [17/8/2009 15:30 Igor 15424]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\CONFIG~1\Temp\BTL130F.tmp --> c:\docume~1\ADMINI~1\CONFIG~1\Temp\BTL130F.tmp [?]
S3 vtany;vtany;\??\c:\windows\vtany.sys --> c:\windows\vtany.sys [?]
S3 WallHack;WallHack;\??\c:\documents and settings\Administrador\Desktop\Cheat Cs\WallHack.sys --> c:\documents and settings\Administrador\Desktop\Cheat Cs\WallHack.sys [?]
S3 xhunter1;xhunter1;\??\c:\windows\xhunter1.sys --> c:\windows\xhunter1.sys [?]

--- =Outros Serviços/Drivers Na Memória ---

*Deregistered* - mbr
*Deregistered* - PROCEXP113

NETSVCS PRECISA DE REPAROS - Entradas atuais mostradas
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
Schedule
SENS
Sharedaccess
SRService
Tapisrv
Themes
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
Conteúdo da pasta 'Tarefas Agendadas'

2009-11-15 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 18:07]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\iycytwmq.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com.br/
FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\AvkWebFilterFF.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-11-15 18:11
Windows 5.1.2600 Service Pack 3 NTFS

Procurando processos ocultos ...

Procurando entradas auto inicializáveis ocultas ...

Procurando ficheiros/arquivos ocultos ...

Varredura completada com sucesso
arquivos/ficheiros ocultos: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\CONFIG~1\Temp\BTL130F.tmp"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

[HKEY_USERS\S-1-5-21-1409082233-1682526488-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,71,fe,84,a5,54,64,23,4a,b9,d0,96,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,71,fe,84,a5,54,64,23,4a,b9,d0,96,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

- - - - - - - > 'winlogon.exe'(380)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(436)
c:\windows\system32\imon.dll
c:\arquivos de programas\Eset\pr_imon.dll

- - - - - - - > 'explorer.exe'(416)
c:\windows\system32\WININET.dll
c:\arquivos de programas\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\imon.dll
c:\arquivos de programas\Eset\pr_imon.dll
c:\arquivos de programas\Arquivos comuns\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\arquivos de programas\Microsoft Office\OFFICE11\msohev.dll
.
Tempo para conclusão: 2009-11-15 18:14
ComboFix-quarantined-files.txt 2009-11-15 21:14

Pré-execução: 15 pasta(s) 42.464.219.136 bytes disponíveis
Pós execução: 17 pasta(s) 42.437.099.520 bytes disponíveis

- - End Of File - - DEA587D4ED4E6B9440D55566F113EE0F
 
Então |St1ng3r|, a Comodo está pisando na bola mesmo. E muito bem lembrado, tempo atrás eu realmente recomendava 100% o Comodo Firewall.

Infelizmente, não é uma falha da empresa, é propositalmente. O fato é o seguinte. A Comodo já vinha se aliando à uma empresa adware chamada Ask.com - empresa esta, aliada também à empresas como Foxit, Zone Labs (Zone Alarm), Piriform (CCleaner), dentre outras - e vinha regredindo, colocando instaladores de crapwares (toolbars, barra de ferramentas, home page) em seu produto. O que antes bastava desmarcar a opção para não instalar estas toolbars, passou a ser instaladas mesmo com o usuário recusando. Com o passar do tempo, descobrimos que a Comodo estava deliberadamente permitindo o tráfego de sites e IPs maliciosos em seus certificados, o que é um absurdo para uma empresa de segurança privilegiada e de alto nível como a Comodo Groups.
relatos comprovados de que a própria Comodo Groups estaria liberando este tráfego malicioso.

Recomendo que dê uma lida neste tópico feito no fórum Linha Defensiva |St1ng3r|:
http://www.linhadefensiva.org/forum/index.php?showtopic=96881


Exatamente. SafeSurf é o nome do adware, que ainda está presente na instalação do firewall. Na verdade, isto tem e não tem a ver ao mesmo tempo.

Já é um antiprofissionalismo de uma empresa de segurança colocar o instalador de um adware (um malware) justamente em um software que tende a proteger nosso sistema. Mas infelizmente não há o que discutir, vendo que, eles lucram colocando esses adwares em seus softwares. OK. Mas, como qualquer software que possua crapwares (esses adwares da instalação), basta desmarcar a opção e pronto! Porém, o Comodo Firewall passou a instalar mesmo desmarcando a opção. Esse foi o primeiro erro da empresa.

Depois, obviamente com suspeitas desta instalação forçada do programa, passamos a analisar o tráfego que a Comodo estava liberando, pois não era normal a instalação insistir mesmo desmarcada. Foi então que descobrimos o malicioso tráfego que a empresa está permitindo.
O tráfego redireciona nitidamente para os sites maliciosos destas empresas: SafeSurf e Ask.com. E até mesmo de sites falsos, e sites que foram hackeados.

Em virtude dos fatos, pessoalmente, não recomendo mais a ninguém os produtos da Comodo Groups.

A Comodo tentou se defender em um post em seu fórum:
http://forums.comodo.com/general_di...e_certificates_to_known_malware-t39564.0.html

Porém, mesmo assim, Comodo Firewall não recomendo mais!

Li o tópico todo Mr. Wolf..

É o cúmulo uma empresa que desenvolve um software de segurança, que tem o propósito a obrigação de nos proteger, se prestar a fazer uma coisa dessas, pensando única e exclusivamente nos seus lucros.


Tá difícil a situação...
se não estamos podemos confiar mais nem nos protetores.. oq dirá o resto dos softwares.. :no:
 
Amigo, passei o HijackThis e o log é esse... pode ajudar? Obrigado.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:03:23, on 16/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\WINDOWS\system32\SupportAppXL\cdrom_mon.exe
C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
C:\ARQUIV~1\AVG\AVG8\avgrsx.exe
C:\Arquivos de programas\iolo\common\lib\ioloServiceManager.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\O2Micro Oz128 Driver\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\ARQUIV~1\SpeedBit Video Accelerator\VideoAcceleratorService.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\ARQUIV~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\ARQUIV~1\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\ARQUIV~1\AVG\AVG8\avgtray.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Pedro\CONFIG~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\DAP\DAP.EXE
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Arquivos de programas\Arquivos comuns\XoftSpySE\6\xoftspyservice.exe
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Arquivos de programas\XoftSpySE6\XoftSpySE.exe
C:\Arquivos de programas\AVG\AVG8\avgui.exe
C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Pedro\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\ARQUIV~1\DAP\dapieloader.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [avast!] "C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [XoftSpySE] "C:\Arquivos de programas\XoftSpySE6\XoftSpySE.exe" -NM -hidesplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enviar para Dispositivo &Bluetooth... - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedbit video accelerator\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedbit video accelerator\sblsp.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autorun CDROM Monitor - Unknown owner - C:\WINDOWS\system32\SupportAppXL\cdrom_mon.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Arquivos de programas\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Arquivos de programas\iolo\common\lib\ioloServiceManager.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Arquivos de programas\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SpeedBit Video Accelerator\VideoAcceleratorService.exe
O23 - Service: XoftSpyService - ParetoLogic Inc. - C:\Arquivos de programas\Arquivos comuns\XoftSpySE\6\xoftspyservice.exe

--
End of file - 8826 bytes
 
Boa tarde pessoal!

Grande amigo GVSPFC, não precisa agradecer! Sempre que precisar estarei à disposição aqui :)

De acordo com o site do AutoPlayConfig, a ferramenta só é compatível com: Windows 95/98/ME e XP. Agora não saberei lhe responder se a afirmação é atual. Posso verificar no 7 do meu computador pessoal quando chegar em casa, caso prefira.

Porém, você pode desativar manualmente, tanto no XP quanto no 7. Veja como no spoiler:

Para o XP: Vá em Iniciar -> Executar, digite gpedit.msc e dê um OK. No diretivas caminhe em Configuração do computador -> Modelos Administrativos -> Sistema.
Ao lado direito do painel, dê um duplo clique no item Desativar AutoExecutar.
Marque a opção Ativado e mais abaixo coloque "Todas as unidades" -> OK.

Para o 7 ou Vista: Clique em Start e na caixa de pesquisa digite gpedit.msc para abrir o group policy (diretivas de grupo).
Expanda as chaves Administrative Templates -> Windows Components -> Autoplay Policies. Ao lado direito do painel, dê um duplo clique em "Turn off AutoPlay". Marque a opção Enable e embaixo marque a opção "All drives" -> OK.
Quanto ao ThreatFire, ele é um behaviour blocker - excelente por sinal. Ótimo para ficar em conjunto com seu antivirus sim. Entretanto, acho que um behaviour blocker hoje é essencial. Visto que, malwares e vírus estão surgindo muito mais rápidos do que o normal hoje em dia, e os antivirus não estão conseguindo acompanhar; um behaviour blocker, que tem a função de detectar vírus/malwares novos que os antivirus ainda não possuem assinatura, pode barrá-los/detectá-los.

Totalmente recomendado GVSPFC.

Bem, seu log do HijackThis está limpo caro amigo.

Caso as ferramentas que utilizamos estiverem ainda em seu PC, pode deletá-las: AVZ4, Avenger e para o ComboFix é só ir em Iniciar > Executar, digite ComboFix /u e dê um OK. As outras pode deletar normalmente (shift + delete).

Algum problema em que eu possa ajudá-lo ainda amigo GVSPFC?
.

Maravilha Mr. Wolf, obrigado mais uma vez pela grande ajuda e dicas valiosas.

Desejo tudo do melhor pra você Mr. Wolf pois merece.

Grande abraço.
 
aki vai o tag... aguardo resposta, brigadão!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:44:23, on 16/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Arquivos de programas\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
C:\Arquivos de programas\Microsoft Security Essentials\msseces.exe
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Ares\Ares.exe
C:\Arquivos de programas\ManyCam 2.3\ManyCam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\UltraVNC\WinVNC.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\userinit.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {6EF05952-B48D-4944-AA91-57A6A1A48EF8} - C:\Arquivos de programas\Puxa Rápido\IEBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSSE] "c:\Arquivos de programas\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Arquivos de programas\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [wave amen] C:\DOCUME~1\Bock\DADOSD~1\infomemo\love bags.exe
O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized
O4 - HKCU\..\Run: [ManyCam] "C:\Arquivos de programas\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Arquivos de programas\SolidWorks\swScheduler\swBOEngine.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6901FAF8-5068-4C6B-86F2-F7805D0A84E5}: NameServer = 200.203.109.253,200.180.239.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{6901FAF8-5068-4C6B-86F2-F7805D0A84E5}: NameServer = 200.203.109.253,200.180.239.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{6901FAF8-5068-4C6B-86F2-F7805D0A84E5}: NameServer = 200.203.109.253,200.180.239.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Arquivos de programas\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Arquivos de programas\Arquivos comuns\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Arquivos de programas\UltraVNC\WinVNC.exe

--
End of file - 8578 bytes
 
PC com vírus me ajudem por favor

Oi Pessoal sou novo aki no Adrenaline...gostaria q v6 me dessem dicas do que fazer com o bendito vírus q se acomodou no meu PC...
Vou explicar de onde eu acho q o vírus comessou..
Um certu dia eu peguei um Pen-Drive de um amigo meu para instalar um Game no meu pc o qual todos conhecem como MU(eu não conseguia baixar pela internet pois minha net é ruim) então quando eu abri o pen-drive o avast avisou que havia detectado um vírus eu pensei q poderia ser um arquivo do pen-drive do meu amigo e resolvi não excluir(escolhi a opção "Sem Ação"), + ou - dois dias depois eu fiz um download de músicas pra minha mãe, e no dia seguinte o Computador não queria abrir os seguintes arquivos: Meu Computador, Meus Documentos, Lixeira, Meu Locais de Rede, alguns icones do Menu Iniciar, Painel de Controle, não faz downloads entre outros problemas.
Me recomendaram ver a proteção residente do avast mas quando eu entrava no avast ele ia pro teste de memória e qndo abria um arquivo "cmpe.exe" ele travava já tentei a restauração do sistema mas tambem não abre..

estou desesperado, me desculpem pela ENOORME MENSAGEM e por favor me digam oq devo fazer...

Atenciosamente...:D
 
Boa tarde à todos!



qeuzinha, todos os códigos são maliciosos. Já me encarreguei de enviar as assinaturas dos malwares às empresas antivirus, e à alguns desenvolvedores de ferramentas específicas.

Agradeço sua gentileza e boa vontade de postar os códigos aqui, qeuzinha. Pode excluir todos esses e-mails.

E quanto ao e-mail de sua irmã, o problema foi resolvido ou não alterando a senha?

______________________________


luisednardo, log limpo.

Quanto às entradas: você pode fixar apenas as O16. As demais entradas são legítmas.

Abraços

______________________________


fanatic, novo log do HijackThis.

______________________________


RodrigoFL, log limpo.

Delete o HijackThis, e baixe-o novamente se quiser. O mesmo foi contaminado.

______________________________


JulianoT, aparentemente log limpo. Se puder, ou souber, a página em que o NOD32 gerou o alerta poste-a aqui, por gentileza.

______________________________


Johnn Y, apague este arquivo -> C:\WINDOWS\apsou.vbs.

No mais, ambos os logs estão limpos.

______________________________


Tello, o Windows Defender não tem absolutamente nenhuma relação com o WinDefense32. Este último é um trojan. O principal problema deste trojan é que o mesmo utiliza processos legítmos - no seu caso o svchost.exe -, em outros casos ele usa o firefox.exe, regedit.exe, TASKMAN.exe, dentre outros processos legítmos.

Poste um log atual do AVZ, por favor.

______________________________


erthaped, log limpo. Retire o XoftSpy da inicialização da máquina. Ele às vezes entra em conflito com o antivirus no boot, no seu caso o AVG.

______________________________


Bock, vá em Adicionar ou Remover Programa e desinstale o Ask.com.

Siga abaixo:

- Baixe o Lop Uninstall e salve no desktop.

- Desative temporariamente seu antivirus para não detectar a ferramenta como infecção. Caso o antivirus bloqueie o arquivo na hora em que o download estiver ocorrendo, desative-o e baixe o arquivo novamente.
- Feche todos os programas abertos e execute o uninstall.exe. Clique em OK > OK.
- Na próxima tela "Uninstall verification", digite os números correspondentes à mensagem e clique em UNINSTALL. Vide imagem de demonstração abaixo:

14bi5gz.jpg


- Clique em OK > OK e siga os prompts que aparecerão.
- Ao término, clique em OK e delete a ferramenta do desktop.

Poste um novo log do HijackThis.
______________________________


sandro007, consegue acessar o Modo de Segurança?

Siga abaixo:

Pressione as teclas do Logotipo do Windows + R para abrir o menu Executar. Digite notepad e dê um OK.

No bloco de notas, cole este texto abaixo:

Código:
@echo off
regedit /e C:\cp.reg "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa"
more C:\cp.reg >> C:\Display.txt
notepad C:\Display.txt
del /q c:\cp.reg
del /q C:\Display.txt
Salve no desktop como SearchRoot.bat e dê um duplo clique neste arquivo. Um log abrirá no bloco de notas.

Anexe-o em sua resposta.

OBS: O arquivo é extenso, portanto, repito, anexe-o ao invés de copiar/colar.
 

Users who are viewing this thread

Voltar
Topo