Bem cá está o relatório do ewido e no fim o do hijack this.
---------------------------------------------------------
ewido anti-malware - Relatório de verificação
---------------------------------------------------------
+ Criado em: 1:12:29, 08-03-2006
+ Relatório-Checksum: 9E0F371
+ Resultado da verificação:
:mozilla.34:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Advertising : Ignorado
:mozilla.35:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Revenue : Ignorado
C:\Documents and Settings\Rafaela\Definições locais\Temp\Cookies\
[email protected][2].txt -> TrackingCookie.Pointroll : Limpo com backup
C:\Documents and Settings\Rafaela\Os meus documentos\Icons de instalaçao\Messenger.rar/MDX_Install_1.1.exe -> Adware.VB : Limpo com backup
C:\Documents and Settings\Rafaela\Os meus documentos\Icons de instalaçao\MDX_Install_1.1.exe -> Adware.VB : Limpo com backup
C:\Documents and Settings\Rafaela\Cookies\
[email protected][2].txt -> TrackingCookie.Pointroll : Limpo com backup
C:\Documents and Settings\Rafaela\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Limpo com backup
C:\Documents and Settings\Rafaela\Cookies\
[email protected][2].txt -> TrackingCookie.Realcastmedia : Limpo com backup
C:\Documents and Settings\Rafaela\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Limpo com backup
:mozilla.19:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.20:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.25:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.28:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.30:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.31:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.32:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Fastclick : Limpo com backup
:mozilla.33:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Tribalfusion : Limpo com backup
:mozilla.36:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Revenue : Limpo com backup
:mozilla.37:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Revenue : Limpo com backup
:mozilla.42:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpo com backup
:mozilla.43:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpo com backup
:mozilla.44:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpo com backup
:mozilla.47:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.48:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.49:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.50:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.51:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.52:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Zedo : Limpo com backup
:mozilla.53:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Atdmt : Limpo com backup
:mozilla.54:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Addynamix : Limpo com backup
:mozilla.56:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Doubleclick : Limpo com backup
:mozilla.79:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Hitbox : Limpo com backup
:mozilla.80:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Hitbox : Limpo com backup
:mozilla.81:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Hitbox : Limpo com backup
:mozilla.82:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Hitbox : Limpo com backup
:mozilla.89:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Bfast : Limpo com backup
:mozilla.92:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.93:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.94:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.95:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.96:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.97:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Liveperson : Limpo com backup
:mozilla.99:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Clickbank : Limpo com backup
:mozilla.100:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Googleadservices : Limpo com backup
:mozilla.103:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Googleadservices : Limpo com backup
:mozilla.112:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.2o7 : Limpo com backup
:mozilla.118:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Questionmarket : Limpo com backup
:mozilla.119:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Falkag : Limpo com backup
:mozilla.121:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Pointroll : Limpo com backup
:mozilla.122:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Pointroll : Limpo com backup
:mozilla.123:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Pointroll : Limpo com backup
:mozilla.124:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Pointroll : Limpo com backup
:mozilla.125:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Pointroll : Limpo com backup
:mozilla.146:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Adtech : Limpo com backup
:mozilla.147:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Adtech : Limpo com backup
:mozilla.148:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Estat : Limpo com backup
:mozilla.149:C:\Documents and Settings\Rafaela\Application Data\Mozilla\Firefox\Profiles\jkks6cbz.default\cookies.txt -> TrackingCookie.Weborama : Limpo com backup
C:\Programas\NoAdware4\noadwareutils.dll -> Adware.WebRebates : Limpo com backup
::Fim do Relatório
Logfile of HijackThis v1.99.1
Scan saved at 1:14:07, on 08-03-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\EPSON\EBAPI\eEBSVC.exe
C:\Programas\Ficheiros comuns\EPSON\EBAPI\SAgent2.exe
C:\Programas\ewido anti-malware\ewidoctrl.exe
C:\Programas\ewido anti-malware\ewidoguard.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Programas\Apoint2K\Apoint.exe
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\Programas\Apoint2K\Apntex.exe
C:\Programas\Java\jre1.5.0_06\bin\jusched.exe
C:\Programas\Support.com\bin\tgcmd.exe
C:\Programas\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programas\Logitech\Video\LogiTray.exe
C:\Programas\Ficheiros comuns\PCSuite\DataLayer\DataLayer.exe
C:\Programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PROGRA~1\FICHEI~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Messenger\msmsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Programas\SAPO Messenger\sapoim.exe
C:\Programas\MSN Messenger\msnmsgr.exe
C:\Programas\Logitech\Video\FxSvr2.exe
C:\Programas\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rafaela\Ambiente de trabalho\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sapo.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://global.acer.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://global.acer.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O5 "LPT1:" /M "Stylus CX3200"
O4 - HKLM\..\Run: [EPSON Stylus CX3200 (cópia 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P29 "EPSON Stylus CX3200 (cópia 1)" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB002" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [hcenter] "C:\Programas\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programas\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programas\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programas\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [DataLayer] C:\Programas\Ficheiros comuns\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [cmrss] C:\WINDOWS\system32\cmrss.exe
O4 - HKLM\..\Run: [taskmgr] C:\WINDOWS\system32\msbcs.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programas\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programas\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [SAPO Messenger] "C:\Programas\SAPO Messenger\sapoim.exe" /silent
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Programas\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\MSN Messenger\msnmsgr.exe" /background
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programas\Ficheiros comuns\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programas\Ficheiros comuns\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programas\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programas\ewido anti-malware\ewidoguard.exe