indigoclio
2006-08-15, 00:24
Hello
On the last days, my computer is becoming very slow, for unknown reasons. I thought that it could be virus/malware, and examined it with BitDefender (log below). The online antivirus found some trojans and deleted some of them. But I want to know: is my computer clean?
For some extra information, I received some days ago a really strange popup, telling I had a Virus infection, but it wasn't a Avast popup; rather, it was a Javascript command from the page, or something like that. And on the Tools/System Startup tab on Spybot there are some WinLogon entries with really weird value names, like this:
Located: WinLogon, crypt32chain (DISABLED)
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet (DISABLED)
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll (DISABLED)
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, ScCertProp (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, Schedule (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, sclgntfy (DISABLED)
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, SensLogn (DISABLED)
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, termsrv (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, wlballoon (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Hope it helps
Thanks in Advance!
BitDefender Online Scanner
Scan report generated at: Mon, Aug 14, 2006 - 16:47:45
Scan path: A:\;C:\;D:\;E:\;F:\;
Statistics
Time
02:34:32
Files
422527
Folders
4760
Boot Sectors
2
Archives
9519
Packed Files
34729
Results
Identified Viruses
10
Infected Files
13
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
13
Engines Info
Virus Definitions
444449
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
39
Unpack plugins
5
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Infected with: Trojan.Downloader.Ieax.A
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Infected with: Java.Trojan.Downloader.OpenStream.C
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Infected with: Trojan.Java.Classloader.H
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Infected with: Trojan.Java.Classloader.G
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Infected with: Trojan.Java.Classloader.D
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Infected with: Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Infected with: Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Infected with: Trojan.Java.Classloader.Dummy.A
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Infected with: Java.Trojan.OpenConnection.F
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Deleted
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html
Update failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Deleted
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Deleted
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe
Infected with: Trojan.Downloader.Banload.AOO
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe
Disinfection failed
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe
On the last days, my computer is becoming very slow, for unknown reasons. I thought that it could be virus/malware, and examined it with BitDefender (log below). The online antivirus found some trojans and deleted some of them. But I want to know: is my computer clean?
For some extra information, I received some days ago a really strange popup, telling I had a Virus infection, but it wasn't a Avast popup; rather, it was a Javascript command from the page, or something like that. And on the Tools/System Startup tab on Spybot there are some WinLogon entries with really weird value names, like this:
Located: WinLogon, crypt32chain (DISABLED)
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet (DISABLED)
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll (DISABLED)
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, ScCertProp (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, Schedule (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, sclgntfy (DISABLED)
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, SensLogn (DISABLED)
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, termsrv (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, wlballoon (DISABLED)
command: wlnotify.dll
file: wlnotify.dll
Hope it helps
Thanks in Advance!
BitDefender Online Scanner
Scan report generated at: Mon, Aug 14, 2006 - 16:47:45
Scan path: A:\;C:\;D:\;E:\;F:\;
Statistics
Time
02:34:32
Files
422527
Folders
4760
Boot Sectors
2
Archives
9519
Packed Files
34729
Results
Identified Viruses
10
Infected Files
13
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
13
Engines Info
Virus Definitions
444449
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
39
Unpack plugins
5
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Infected with: Trojan.Downloader.Ieax.A
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip=>javainstaller/InstallerApplet.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3cc46f89-64a0fc63.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Infected with: Java.Trojan.Downloader.OpenStream.C
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Matrix.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Infected with: Trojan.Java.Classloader.H
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Counter.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Infected with: Trojan.Java.Classloader.G
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Dummy.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Infected with: Trojan.Java.Classloader.D
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip=>Parser.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv761.jar-d18bd5b-12a68932.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Infected with: Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>GetAccess.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Infected with: Java.Trojan.Exploit.Bytverify
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>InsecureClassLoader.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Infected with: Trojan.Java.Classloader.Dummy.A
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Dummy.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Infected with: Java.Trojan.OpenConnection.F
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Disinfection failed
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip=>Installer.class
Deleted
C:\Documents and Settings\Gabi\Dados de aplicativos\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-266268dc-61dd15a9.zip
Updated
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html=>(gzip)
Deleted
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\index[1].html
Update failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\09UZCHQZ\navcell-off[1].htm
Deleted
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Infected with: Trojan.Spy.Banker.HQ
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Disinfection failed
C:\Documents and Settings\asd\Configurações locais\Temporary Internet Files\Content.IE5\2TJW14R2\apardetudo.hpg.ig.com[1].htm
Deleted
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe
Infected with: Trojan.Downloader.Banload.AOO
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe
Disinfection failed
C:\System Volume Information\_restore{0E43D19E-22F2-4164-B6FC-BDCFFDB476D5}\RP396\A0104280.exe