Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

walder

[Arquivado]mstds.exe

Recommended Posts

O sistema operacional Windows 2000 estava infectado com o malware mstds.exe. Rodei alguns programas para tentar removê-lo, assim como uma limpeza nos registros. Porém ainda não consigo conectar-me com a Internet e o navegador IE6 fica dando refresh tendando acessar a página http://dns404error.htm e na barra de endereço consta res://C:\WINNT\system32\shdoclc.dll/navcancl.htm.

 

Não consigo localizar mais nada de anormal na máquina.

 

Segue log do HijackThis:

 

Logfile of HijackThis v1.99.1

Scan saved at 10:58:43, on 8/12/2006

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\LEXBCES.EXE

C:\WINNT\system32\spoolsv.exe

C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINNT\System32\svchost.exe

C:\Arquivos de programas\Network Associates\Common Framework\FrameworkService.exe

C:\Arquivos de programas\Network Associates\VirusScan\Mcshield.exe

C:\Arquivos de programas\Network Associates\VirusScan\VsTskMgr.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\Explorer.EXE

C:\Arquivos de programas\Video ActiveX Object\isamonitor.exe

C:\WINNT\System32\sistray.EXE

C:\WINNT\System32\khooker.exe

C:\Arquivos de programas\Video ActiveX Object\isamini.exe

C:\Arquivos de programas\Network Associates\Common Framework\UpdaterUI.exe

C:\Arquivos de programas\Network Associates\VirusScan\SHSTAT.EXE

C:\Arquivos de programas\Arquivos comuns\Network Associates\TalkBack\TBMon.exe

C:\Arquivos de programas\Java\jre1.5.0_06\bin\jusched.exe

C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINNT\system32\internat.exe

C:\Arquivos de programas\Skype\Phone\Skype.exe

C:\Hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.portusinstituto.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.103.5:3128

R3 - URLSearchHook: (no name) - {CE000994-A58C-4441-8938-744CD72AB27F} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Arquivos de programas\Video ActiveX Object\isaddon.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O4 - HKLM\..\Run: [siS Tray] C:\WINNT\System32\sistray.EXE

O4 - HKLM\..\Run: [siS KHooker] C:\WINNT\System32\khooker.exe

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Arquivos de programas\Arquivos comuns\Network Associates\TalkBack\TBMon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [internat.exe] internat.exe

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - Startup: BHODemon 2.0.lnk = C:\Arquivos de programas\BHODemon 2\BHODemon.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Uninstall.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1142448623386

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = portusbr

O17 - HKLM\System\CCS\Services\Tcpip\..\{83269170-29F2-4E23-BCF0-5881033DA6F7}: NameServer = 192.168.103.209,200.196.48.20,200.196.48.21

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = portusbr

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = portusbr

O21 - SSODL: emptins - {588599f4-de26-4c28-ba14-f4eb17e33481} - (no file)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Serviço administrativo do gerenciador de disco lógico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE

O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINNT\system32\LMabcoms.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\Common Framework\FrameworkService.exe

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\VirusScan\Mcshield.exe

O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\VirusScan\VsTskMgr.exe

O23 - Service: OracleClientCache80 - Unknown owner - C:\oracle6i\BIN\ONRSD80.EXE

 

E também do SmitFraud:

 

SmitFraudFix v2.128

 

Scan done at 11:02:31,70, --- 08/12/2006

Run from C:\Documents and Settings\luiz\Desktop\SmitfraudFix

OS: Microsoft Windows 2000 [VersÆo 5.00.2195] - Windows_NT

The filesystem type is NTFS

Fix run in normal mode

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\luiz

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\luiz\Application Data

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\luiz\FAVORI~1

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Arquivos de programas

 

C:\Arquivos de programas\Video ActiveX Object\ FOUND !

 

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]

"Source"="About:Home"

"SubscribedURL"="About:Home"

"FriendlyName"="Minha home page atual"

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, following keys are not inevitably infected!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{588599f4-de26-4c28-ba14-f4eb17e33481}"="emptins"

 

[HKEY_CLASSES_ROOT\CLSID\{588599f4-de26-4c28-ba14-f4eb17e33481}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{588599f4-de26-4c28-ba14-f4eb17e33481}\InProcServer32]

 

 

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, following keys are not inevitably infected!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, following keys are not inevitably infected!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

 

 

»»»»»»»»»»»»»»»»»»»»»»»» End

 

 

Já vasculhei por resostas em vários sites e não consegui resolver ainda...

 

Obrigado pela atenção.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa walder,

 

Baixe o WinsockFix.

 

Execute o WinsockFix.exe e então clique em Fix.

 

O procedimento acima deve resolver o problema relativo à falha na conexão.

 

Bem, agora vamos ao malware...

 

Levando em consideração que você já possui o Smitfraudfix, faça o seguinte:

 

1. Desabilite a proteção do seu antivírus (temporariamente);

 

2. Reinicie em Modo Seguro;

 

3. Execute o SmitfraudFix dando um duplo clique sobre smitfraudfix.cmd --> escolha a Opção 2;

 

4. Responda sim (y) à pergunta sobre a limpeza no registro (Do you want to clean the registry?);

 

5. Aguarde o término do scan e a geração do log;

 

6. Reinicie em Modo Normal;

 

7. Reabilite seu antivírus;

 

8. Poste o log do SmitfraudFix (opção 2) + log HijackThis (gerado em Modo Normal).

 

Aguardo retorno.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Valeu, Jgarcia!!!!

 

WOW :joia: A resposta foi muito rápida XD~~

 

Muitíssimo obrigado. A conexão já está ok (graças ao arquivo que você indicou). Eu tinha pelo menos 2 arquivos na máquina que causaram todo o problema, mtdsm.exe e iptables.exe (esses eu fui removendo na unha mesmo), que provavelmente foram instalados depois do malwarewipe. Mas mesmo depois da remoção deles o problema da conexão persistia.

 

Aqui está o log do HJT (modo normal):

 

Logfile of HijackThis v1.99.1

Scan saved at 14:18:35, on 8/12/2006

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\LEXBCES.EXE

C:\WINNT\system32\spoolsv.exe

C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINNT\System32\svchost.exe

C:\Arquivos de programas\Network Associates\Common Framework\FrameworkService.exe

C:\Arquivos de programas\Network Associates\VirusScan\Mcshield.exe

C:\Arquivos de programas\Network Associates\VirusScan\VsTskMgr.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\Explorer.EXE

C:\WINNT\System32\sistray.EXE

C:\WINNT\System32\khooker.exe

C:\Arquivos de programas\Network Associates\Common Framework\UpdaterUI.exe

C:\Arquivos de programas\Network Associates\VirusScan\SHSTAT.EXE

C:\Arquivos de programas\Arquivos comuns\Network Associates\TalkBack\TBMon.exe

C:\Arquivos de programas\Java\jre1.5.0_06\bin\jusched.exe

C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINNT\system32\internat.exe

C:\winnt\system32\mstds.exe

C:\Hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O4 - HKLM\..\Run: [siS Tray] C:\WINNT\System32\sistray.EXE

O4 - HKLM\..\Run: [siS KHooker] C:\WINNT\System32\khooker.exe

O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey

O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE

O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Arquivos de programas\Arquivos comuns\Network Associates\TalkBack\TBMon.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [mstds.exe] c:\winnt\system32\mstds.exe

O4 - HKCU\..\Run: [internat.exe] internat.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Uninstall.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mswsck32.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1142448623386

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = portusbr

O17 - HKLM\System\CCS\Services\Tcpip\..\{83269170-29F2-4E23-BCF0-5881033DA6F7}: NameServer = 192.168.103.209,200.196.48.20,200.196.48.21

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = portusbr

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = portusbr

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Serviço administrativo do gerenciador de disco lógico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE

O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINNT\system32\LMabcoms.exe

O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\Common Framework\FrameworkService.exe

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\VirusScan\Mcshield.exe

O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Arquivos de programas\Network Associates\VirusScan\VsTskMgr.exe

O23 - Service: OracleClientCache80 - Unknown owner - C:\oracle6i\BIN\ONRSD80.EXE

 

 

Aqui está o log do SmitFraud (modo de segurança):

 

SmitFraudFix v2.128

 

Scan done at 14:08:28,07, --- 08/12/2006

Run from C:\Documents and Settings\luiz\Desktop\SmitfraudFix

OS: Microsoft Windows 2000 [VersÆo 5.00.2195] - Windows_NT

The filesystem type is NTFS

Fix run in safe mode

 

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix

!!!Attention, following keys are not inevitably infected!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{588599f4-de26-4c28-ba14-f4eb17e33481}"="emptins"

 

[HKEY_CLASSES_ROOT\CLSID\{588599f4-de26-4c28-ba14-f4eb17e33481}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{588599f4-de26-4c28-ba14-f4eb17e33481}\InProcServer32]

 

»»»»»»»»»»»»»»»»»»»»»»»» Killing process

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

 

GenericRenosFix by S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

 

C:\Arquivos de programas\Video ActiveX Object\ Deleted

 

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, following keys are not inevitably infected!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

 

Registry Cleaning done.

 

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix

!!!Attention, following keys are not inevitably infected!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» End

 

 

 

BRIGADÃO!!!! Tá tudo ok agora.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa walder,

 

Vamos lá.

 

Habilite o Windows para mostrar todos os arquivos (até ocultos).

 

1ª Etapa

 

Baixe o Killbox em:

Killbox

 

1) Execute o Killbox, clique em Delete on Reboot.

 

2) Copie a lista abaixo em negrito para a área de transferência. Selecione --> Editar --> Copiar.

C:\winnt\system32\mstds.exe

3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files.

 

4. Aperte em "X". Responda "não" à pergunta.

 

É prudente que você faça a impressão deste documento ou salve-o em um lugar de fácil acesso, pois na próxima etapa entraremos em Modo de Seguro e a conexão à internet não será possível.

 

2ª Etapa

 

Reinicie o computador em Modo Seguro.

 

Execute o HijackThis, clique em Do a system scan only e marque:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm

O4 - HKLM\..\Run: [mstds.exe] c:\winnt\system32\mstds.exe

O4 - Global Startup: Uninstall.exe

Clique em Fix Checked.

 

3ª Etapa

 

Ainda em Modo Seguro localize e delete:

 

Uninstall.exe

 

4ª Etapa

 

Reinicie em Modo Normal.

 

Submeta o arquivo abaixo ao site VirusTotal:

 

c:\winnt\system32\mswsck32.dll

 

Retorne com o resultado e um novo log do HijackThis.

 

Aguardo retorno.

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.