This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Dialers, worms, spyware etc...

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, everyone. Need help. My comp has lots of malware, but Norton cant find it. Ad-aware found lots of things, but it doesnt find others. Panda on-line found stuff but didnt erase them. Even some of my registry keys have been corrupted. Can anyone help me, please? :( there goes my hijackthis log:


Logfile of HijackThis v1.99.1
Scan saved at 23:31:51, on 17/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
C:\Arquivos de programas\NavNT\vptray.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
C:\Arquivos de programas\SpywareGuard\sgmain.exe
C:\Arquivos de programas\SpywareGuard\sgbhp.exe
C:\Arquivos de programas\NavNT\defwatch.exe
C:\Arquivos de programas\NavNT\rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Serginho.AMD-XP2800\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.globo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Arquivos de programas\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Arquivos de programas\NavNT\vptray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Arquivos de programas\SpywareGuard\sgmain.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126566911609
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…400/mcfscan.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAB4575-77AF-422B-8EA1-85183BD14BE7}: NameServer = 200.149.55.143 200.165.132.155
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Arquivos de programas\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Arquivos de programas\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
Hello The Count of Monte Cristo, welcome to the forum.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Hey LDTate. Thnx for helping me out. did what u told me to do. these are the results. ewido first.

+ Criado em: 16:49:49, 24/9/2005
+ Relatório-Checksum: 8467F949

+ Resultado da verificação:

:mozilla.28:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\im6o5m6f.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.52:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\im6o5m6f.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Limpo com backup
:mozilla.7:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Atdmt : Limpo com backup
:mozilla.10:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Doubleclick : Limpo com backup
:mozilla.11:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Addynamix : Limpo com backup
:mozilla.44:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.45:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.46:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.47:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.54:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Ad-logics : Limpo com backup
:mozilla.59:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.60:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.61:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.62:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.78:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.88:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Com : Limpo com backup
:mozilla.89:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Com : Limpo com backup
:mozilla.144:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Paycounter : Limpo com backup
:mozilla.164:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.165:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.166:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.167:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.178:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Limpo com backup
:mozilla.180:C:\Documents and Settings\Sergio.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\3q6rq7tf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@com[2].txt -> Spyware.Cookie.Com : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@com[1].txt -> Spyware.Cookie.Com : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Masterstats : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\[removed][2].txt -> Spyware.Cookie.Clickzs : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Bpath : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\[removed][2].txt -> Spyware.Cookie.Masterstats : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Com : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@com[4].txt -> Spyware.Cookie.Com : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@ivwbox[2].txt -> Spyware.Cookie.Ivwbox : Limpo com backup
C:\Documents and Settings\Serginho.AMD-XP2800\Meus documentos\Documents and Settings\Serginho\Cookies\serginho@2o7[5].txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.6:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.7:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.8:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.9:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.10:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.11:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.23:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.24:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.25:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.29:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.31:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.32:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.33:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.34:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.37:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Burstnet : Limpo com backup
:mozilla.38:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Limpo com backup
:mozilla.39:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Limpo com backup
:mozilla.40:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Limpo com backup
:mozilla.41:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.42:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.43:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.44:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.60:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Ru4 : Limpo com backup
:mozilla.61:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Gator : Limpo com backup
:mozilla.62:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Gator : Limpo com backup
:mozilla.63:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Gator : Limpo com backup
:mozilla.64:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Gator : Limpo com backup
:mozilla.110:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Limpo com backup
:mozilla.118:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.127:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Limpo com backup
:mozilla.137:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.138:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.143:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.163:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Masterstats : Limpo com backup
:mozilla.188:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Gator : Limpo com backup
:mozilla.192:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Burstbeacon : Limpo com backup
:mozilla.201:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Profiles\default\zg4rlelq.slt\cookies.txt -> Spyware.Cookie.Googleadservices : Limpo com backup
:mozilla.152:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Falkag : Limpo com backup
:mozilla.153:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Limpo com backup
:mozilla.154:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Limpo com backup
:mozilla.155:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Limpo com backup
:mozilla.156:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Limpo com backup
:mozilla.184:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.185:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.186:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.187:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.188:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Serving-sys : Limpo com backup
:mozilla.219:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Revenue : Limpo com backup
:mozilla.273:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Burstnet : Limpo com backup
:mozilla.274:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Burstnet : Limpo com backup
:mozilla.281:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Com : Limpo com backup
:mozilla.282:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Com : Limpo com backup
:mozilla.285:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Com : Limpo com backup
:mozilla.342:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.343:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.344:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.345:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.346:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.347:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.348:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.349:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.350:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.351:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.352:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.353:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.354:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.355:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.356:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.357:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Statcounter : Limpo com backup
:mozilla.390:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Liveperson : Limpo com backup
:mozilla.391:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Liveperson : Limpo com backup
:mozilla.419:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Estat : Limpo com backup
:mozilla.530:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Casalemedia : Limpo com backup
:mozilla.531:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Casalemedia : Limpo com backup
:mozilla.597:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Onestat : Limpo com backup
:mozilla.598:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Onestat : Limpo com backup
:mozilla.599:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Onestat : Limpo com backup
:mozilla.600:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Onestat : Limpo com backup
:mozilla.601:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Onestat : Limpo com backup
:mozilla.618:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.619:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.620:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.621:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.622:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.623:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.624:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.625:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.626:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.627:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.628:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.629:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.630:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.2o7 : Limpo com backup
:mozilla.639:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.640:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.641:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Pointroll : Limpo com backup
:mozilla.671:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.672:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Centrport : Limpo com backup
:mozilla.681:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.682:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.683:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.684:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.685:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.686:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.687:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.688:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Sexcounter : Limpo com backup
:mozilla.689:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Clickzs : Limpo com backup
:mozilla.690:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Clickzs : Limpo com backup
:mozilla.816:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Paycounter : Limpo com backup
:mozilla.828:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Questionmarket : Limpo com backup
:mozilla.847:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Specificclick : Limpo com backup
:mozilla.869:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Limpo com backup
:mozilla.902:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.903:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.904:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.905:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.906:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adserver : Limpo com backup
:mozilla.909:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Cqcounter : Limpo com backup
:mozilla.930:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Adition : Limpo com backup
:mozilla.934:C:\Documents and Settings\Serginho.AMD-XP2800\Dados de aplicativos\Mozilla\Firefox\Profiles\36cffp4a.default\cookies.txt -> Spyware.Cookie.Clickhype : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP244\A0035265.exe -> Dialer.Generic : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP250\A0036533.exe -> Dialer.Generic : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP251\A0037576.exe -> Dialer.Generic : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP253\A0038001.exe -> Spyware.ClipGenie : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP253\A0038002.dll -> Spyware.TopSearch : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP253\A0038003.exe -> Spyware.ClipGenie : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP253\A0038010.exe -> Spyware.DownloadWare : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP255\A0038754.exe -> Spyware.DownloadWare : Limpo com backup
C:\System Volume Information\_restore{CEEB1545-535D-4C1E-B715-AB9A105086F0}\RP255\A0038755.exe -> Dialer.Generic : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@com[2].txt -> Spyware.Cookie.Com : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@com[1].txt -> Spyware.Cookie.Com : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Masterstats : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@ivwbox[1].txt -> Spyware.Cookie.Ivwbox : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\[removed][2].txt -> Spyware.Cookie.Clickzs : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Bpath : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\[removed][2].txt -> Spyware.Cookie.Masterstats : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\[removed][1].txt -> Spyware.Cookie.Com : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@com[4].txt -> Spyware.Cookie.Com : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@ivwbox[2].txt -> Spyware.Cookie.Ivwbox : Limpo com backup
C:\BACKUP\Serginho\Documents and Settings\Serginho\Cookies\serginho@2o7[5].txt -> Spyware.Cookie.2o7 : Limpo com backup
C:\BACKUP\Thais\Cookies\thais@com[2].txt -> Spyware.Cookie.Com : Limpo com backup


::Fim do Relatório

now the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 16:51:03, on 24/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Serginho.AMD-XP2800\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.globo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Arquivos de programas\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll
O3 - Toolbar: &R;ádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Arquivos de programas\NavNT\vptray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Arquivos de programas\SpywareGuard\sgmain.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar; para o Microsoft Excel - res://C:\ARQUIV~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126566911609
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…400/mcfscan.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Arquivos de programas\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Arquivos de programas\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe


thnx again. :D
Lets also do this:

click Start> Run> type in Cleanmgr. Tap enter and select C: to clean.


Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Hey LDTate. Done it. About my pc, it actually works perfectly. when i installed adaware se a few days ago it found over a 100 malware files, but i never noticed a thing. when i installed ewido it also found over a 100 malware files. norton also picked up something a few times a few days ago everytime i started the pc and put the thing in quaratine. it was the same malware over and over, but now it finds nothing. anyway, there goes the new log

Logfile of HijackThis v1.99.1
Scan saved at 23:43:39, on 24/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
C:\Arquivos de programas\NavNT\vptray.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
C:\Arquivos de programas\SpywareGuard\sgmain.exe
C:\Arquivos de programas\SpywareGuard\sgbhp.exe
C:\Arquivos de programas\NavNT\defwatch.exe
C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
C:\Arquivos de programas\NavNT\rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Serginho.AMD-XP2800\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.globo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Arquivos de programas\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Arquivos de programas\NavNT\vptray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Arquivos de programas\SpywareGuard\sgmain.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126566911609
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…400/mcfscan.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAB4575-77AF-422B-8EA1-85183BD14BE7}: NameServer = 200.149.55.142 200.165.132.154
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Arquivos de programas\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Arquivos de programas\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

thnx for your help
Good job. :thumbup:

Only a few minor ones left.


I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MI1933~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Hey LDTate. There goes the new log. The PC is just fine, thnx to you. Big thnx for taking time to help me :thumbup: :D :thumbup: .

Logfile of HijackThis v1.99.1
Scan saved at 11:17:13, on 25/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
C:\Arquivos de programas\NavNT\vptray.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
C:\Arquivos de programas\SpywareGuard\sgmain.exe
C:\Arquivos de programas\SpywareGuard\sgbhp.exe
C:\Arquivos de programas\NavNT\defwatch.exe
C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
C:\Arquivos de programas\NavNT\rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Serginho.AMD-XP2800\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.globo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Arquivos de programas\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\WINDOWS\Downloaded Program Files\gbieh.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Arquivos de programas\NavNT\vptray.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Arquivos de programas\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Arquivos de programas\SpywareGuard\sgmain.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Arquivos de programas\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126566911609
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399F83} (GbPluginObj Class) - https://www14.bancobrasil.com.br/plugin/GbPluginBb.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…400/mcfscan.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAB4575-77AF-422B-8EA1-85183BD14BE7}: NameServer = 200.149.55.142 200.165.132.154
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Arquivos de programas\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Arquivos de programas\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\ARQUIV~1\Telemar\Velox\app\pppoeservice.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Arquivos de programas\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe
Good Job :thumbup:

You can also look for and delete the folder named C:\!submit
It's from Ewido scans and not needed anymore.


Log looks good :D

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
YEEEEEAAAAAHHHHHHH :weee: :weee: :weee: !!!!! THANK U VERY MUCH, LDTate!!!!!!! Ur my hero!!! :D :D :D i have everything u suggested, except IESPY AD, which i will download. thank u again!!!
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI