Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Heisenberg

[Resolvido!] Como remover o socket error #110004

Recommended Posts

Olá pessoal, sou novo por aqui, mas já notei

que tem muita gente com o mesmo problema

que eu...o famigerado socket error #110004!!!

Aparece um monte de janelas com essa msg

quando ligo o pc. Como não entendo muita coisa

sobre os logs gerados pelo hijackthis, resolvi

pedir ajuda de quem sabe do que se trata.

Aí vai o Log:

 

Logfile of HijackThis v1.99.1

Scan saved at 17:22:09, on 31/03/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\Documents and Settings\Pedagógico\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\System32\RDPSSW32.EXE

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\BeTwinServiceXP.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe

C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe

C:\WINDOWS\system32\JVM0.exe

C:\Arquivos de programas\BeTwin\BeTwinMessages.exe

C:\WINDOWS\system32\nostd.scr

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\JVM0.exe

C:\WINDOWS\system32\sistray.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe

C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe

C:\WINDOWS\system32\JVM0.exe

C:\Arquivos de programas\BeTwin\BeTwinMessages.exe

C:\WINDOWS\system32\nostd.scr

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\JVM0.exe

C:\WINDOWS\system32\sistray.exe

C:\Hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\documents and settings\pedagógico\windows\system32\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.1.1:6588

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar2.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [beTwinAssistant] "C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe"

O4 - HKLM\..\Run: [JVM0] C:\WINDOWS\system32\JVM0.exe

O4 - HKLM\..\Run: [beTwinMessages] "C:\Arquivos de programas\BeTwin\BeTwinMessages.exe"

O4 - HKLM\..\Run: [nostd] C:\WINDOWS\system32\nostd.scr

O4 - HKLM\..\Run: [ ] C:\Documents and Settings\Pedagógico\WINDOWS\Windows64.scr

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr

O4 - Global Startup: JVM0.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O10 - Broken Internet access because of LSP provider 'c:\documents and settings\pedagógico\windows\system32\mswsock.dll' missing

O17 - HKLM\System\CCS\Services\Tcpip\..\{E44B638F-2822-40AD-B821-2BA48D8829A3}: NameServer = 10.0.1.1

O20 - Winlogon Notify: BeTwinNotify - BeTwinNotify.dll (file missing)

O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)

O23 - Service: Serviço 'Gateway de camada de aplicativo' (ALG) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\alg.exe (file missing)

O23 - Service: Gerenciamento de aplicativo (AppMgmt) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Áudio do Windows (AudioSrv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: Serviço de transferência inteligente de plano de fundo (BITS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Localizador de computadores (Browser) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de indexação (CiSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\cisvc.exe (file missing)

O23 - Service: Serviços de criptografia (CryptSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Inicializador de Processo de Servidor DCOM (DcomLaunch) - Unknown owner - C:\Documents.exe (file missing)

O23 - Service: Cliente DHCP (Dhcp) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço administrativo do gerenciador de disco lógico (dmadmin) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\dmadmin.exe (file missing)

O23 - Service: Gerenciador de discos lógicos (dmserver) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente DNS (Dnscache) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Erro ao informar o serviço (ERSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Log de eventos (Eventlog) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\services.exe (file missing)

O23 - Service: Compatibilidade com 'Troca rápida de usuário' (FastUserSwitchingCompatibility) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Ajuda e suporte (helpsvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Servidor (lanmanserver) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Estação de trabalho (lanmanworkstation) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Auxiliar NetBIOS TCP/IP (LmHosts) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Logon de rede (Netlogon) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Conexões de rede (Netman) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Reconhecimento de local da rede (NLA) (Nla) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Fornecedor de suporte de segurança NT LM (NtLmSsp) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Armazenamento removível (NtmsSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\services.exe (file missing)

O23 - Service: Serviços IPSEC (PolicyAgent) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Armazenamento protegido (ProtectedStorage) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Gerenciador de conexão de acesso remoto automático (RasAuto) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Gerenciador de conexão de acesso remoto (RasMan) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: RDPSSW32 - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\RDPSSW32.EXE (file missing)

O23 - Service: Registro remoto (RemoteRegistry) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Alocador Remote Procedure Call (RPC) (RpcLocator) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\locator.exe (file missing)

O23 - Service: Chamada de procedimento remoto (RPC) (RpcSs) - Unknown owner - C:\Documents.exe (file missing)

O23 - Service: QoS RSVP (RSVP) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\rsvp.exe (file missing)

O23 - Service: Gerenciador de contas de segurança (SamSs) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Cartão inteligente (SCardSvr) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\SCardSvr.exe (file missing)

O23 - Service: Agendador de tarefas (Schedule) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Logon secundário (seclogon) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Notificação de eventos de sistema (SENS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Firewall do Windows/Compartilhamento de Conexão com a Internet (ICS) (SharedAccess) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Detecção do hardware do shell (ShellHWDetection) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Spooler de impressão (Spooler) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\spoolsv.exe (file missing)

O23 - Service: Serviço de restauração do sistema (srservice) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de descoberta SSDP (SSDPSRV) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Assistente de aquisição de imagens do Windows (WIA) (stisvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Logs e alertas de desempenho (SysmonLog) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\smlogsvc.exe (file missing)

O23 - Service: Telefonia (TapiSrv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Servidor de Terminal BeTwin (TermService) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\BeTwinServiceXP.exe (file missing)

O23 - Service: Temas (Themes) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente de rastreamento de link distribuído (TrkWks) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Host de dispositivo Plug and Play universal (upnphost) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Sistema de alimentação ininterrupta (UPS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\ups.exe (file missing)

O23 - Service: Cópia de volume em memória (VSS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\vssvc.exe (file missing)

O23 - Service: Horário do Windows (W32Time) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente da Web (WebClient) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Testador de instrumentação de gerenciam. do Windows (winmgmt) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de Número de Série de Mídia Portátil (WmdmPmSN) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Extensões de driver de instrum. gerenc. do Windows (Wmi) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Central de Segurança (wscsvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Atualizações Automáticas (wuauserv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Configuração zero sem fio (WZCSVC) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Serviço de Configuração de Rede (xmlprov) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

 

Agradeço à todos pela atenção.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Heisenberg,

 

1. Baixe o BankerFix.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. Uma mensagem aparecerá avisando que o mesmo será baixado via internet. Clique em Ok -> Ok. Aperte Enter e aguarde o término do scan.

 

4. Terminado o scan, leia a mensagem na tela e aperte Enter novamente.

 

5. Habilite o seu anti-vírus.

 

6. Retorne com um novo log do HijackThis, juntamente com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

7. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

O bankerfix não está executando de forma correta. Ele cria a pasta "LinhaDefensiva", dá a msg que o bankerfix vai ser baixado da internet, clico em ok, mas não acontecenenhuma espécie de escaneamento!! O que pode estar acontecendo?Obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Heisenberg,

 

Poste um novo log do HijackThis.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aí vai outro:

 

Logfile of HijackThis v1.99.1

Scan saved at 20:04:10, on 05/04/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\Documents and Settings\Pedagógico\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\System32\RDPSSW32.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe

C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe

C:\WINDOWS\system32\JVM0.exe

C:\Arquivos de programas\BeTwin\BeTwinMessages.exe

C:\WINDOWS\system32\nostd.scr

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\JVM0.exe

C:\WINDOWS\system32\sistray.exe

C:\WINDOWS\System32\BeTwinServiceXP.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe

C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe

C:\WINDOWS\system32\JVM0.exe

C:\Arquivos de programas\BeTwin\BeTwinMessages.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\nostd.scr

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\JVM0.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Escola\escola.exe

C:\WINDOWS\system32\ntvdm.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\Arquivos de programas\Escola\escola.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\documents and settings\pedagógico\windows\system32\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.1.1:6588

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar2.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [beTwinAssistant] "C:\Arquivos de programas\BeTwin\BeTwinAssistant.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe"

O4 - HKLM\..\Run: [JVM0] C:\WINDOWS\system32\JVM0.exe

O4 - HKLM\..\Run: [beTwinMessages] "C:\Arquivos de programas\BeTwin\BeTwinMessages.exe"

O4 - HKLM\..\Run: [nostd] C:\WINDOWS\system32\nostd.scr

O4 - HKLM\..\Run: [ ] C:\Documents and Settings\Pedagógico\WINDOWS\Windows64.scr

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr

O4 - Global Startup: JVM0.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_11\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O10 - Broken Internet access because of LSP provider 'c:\documents and settings\pedagógico\windows\system32\mswsock.dll' missing

O17 - HKLM\System\CCS\Services\Tcpip\..\{E44B638F-2822-40AD-B821-2BA48D8829A3}: NameServer = 10.0.1.1

O20 - Winlogon Notify: BeTwinNotify - BeTwinNotify.dll (file missing)

O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)

O23 - Service: Serviço 'Gateway de camada de aplicativo' (ALG) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\alg.exe (file missing)

O23 - Service: Gerenciamento de aplicativo (AppMgmt) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Áudio do Windows (AudioSrv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: Serviço de transferência inteligente de plano de fundo (BITS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Localizador de computadores (Browser) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de indexação (CiSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\cisvc.exe (file missing)

O23 - Service: Serviços de criptografia (CryptSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Inicializador de Processo de Servidor DCOM (DcomLaunch) - Unknown owner - C:\Documents.exe (file missing)

O23 - Service: Cliente DHCP (Dhcp) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço administrativo do gerenciador de disco lógico (dmadmin) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\dmadmin.exe (file missing)

O23 - Service: Gerenciador de discos lógicos (dmserver) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente DNS (Dnscache) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Erro ao informar o serviço (ERSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Log de eventos (Eventlog) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\services.exe (file missing)

O23 - Service: Compatibilidade com 'Troca rápida de usuário' (FastUserSwitchingCompatibility) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Ajuda e suporte (helpsvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Servidor (lanmanserver) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Estação de trabalho (lanmanworkstation) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Auxiliar NetBIOS TCP/IP (LmHosts) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Logon de rede (Netlogon) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Conexões de rede (Netman) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Reconhecimento de local da rede (NLA) (Nla) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Fornecedor de suporte de segurança NT LM (NtLmSsp) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Armazenamento removível (NtmsSvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\services.exe (file missing)

O23 - Service: Serviços IPSEC (PolicyAgent) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Armazenamento protegido (ProtectedStorage) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Gerenciador de conexão de acesso remoto automático (RasAuto) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Gerenciador de conexão de acesso remoto (RasMan) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: RDPSSW32 - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\RDPSSW32.EXE (file missing)

O23 - Service: Registro remoto (RemoteRegistry) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Alocador Remote Procedure Call (RPC) (RpcLocator) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\locator.exe (file missing)

O23 - Service: Chamada de procedimento remoto (RPC) (RpcSs) - Unknown owner - C:\Documents.exe (file missing)

O23 - Service: QoS RSVP (RSVP) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\rsvp.exe (file missing)

O23 - Service: Gerenciador de contas de segurança (SamSs) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\lsass.exe (file missing)

O23 - Service: Cartão inteligente (SCardSvr) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\SCardSvr.exe (file missing)

O23 - Service: Agendador de tarefas (Schedule) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Logon secundário (seclogon) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Notificação de eventos de sistema (SENS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Firewall do Windows/Compartilhamento de Conexão com a Internet (ICS) (SharedAccess) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Detecção do hardware do shell (ShellHWDetection) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Spooler de impressão (Spooler) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\spoolsv.exe (file missing)

O23 - Service: Serviço de restauração do sistema (srservice) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de descoberta SSDP (SSDPSRV) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Assistente de aquisição de imagens do Windows (WIA) (stisvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Logs e alertas de desempenho (SysmonLog) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\smlogsvc.exe (file missing)

O23 - Service: Telefonia (TapiSrv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Servidor de Terminal BeTwin (TermService) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\BeTwinServiceXP.exe (file missing)

O23 - Service: Temas (Themes) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente de rastreamento de link distribuído (TrkWks) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Host de dispositivo Plug and Play universal (upnphost) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Sistema de alimentação ininterrupta (UPS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\ups.exe (file missing)

O23 - Service: Cópia de volume em memória (VSS) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\vssvc.exe (file missing)

O23 - Service: Horário do Windows (W32Time) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Cliente da Web (WebClient) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Testador de instrumentação de gerenciam. do Windows (winmgmt) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Serviço de Número de Série de Mídia Portátil (WmdmPmSN) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Extensões de driver de instrum. gerenc. do Windows (Wmi) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Central de Segurança (wscsvc) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Atualizações Automáticas (wuauserv) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\system32\svchost.exe (file missing)

O23 - Service: Configuração zero sem fio (WZCSVC) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

O23 - Service: Serviço de Configuração de Rede (xmlprov) - Unknown owner - C:\Documents and Settings\Pedagógico\WINDOWS\System32\svchost.exe (file missing)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Heisenberg,

 

Vamos lá.

 

Habilite o Windows para mostrar todos os arquivos (até ocultos).

 

1ª Etapa

 

Baixe o Killbox em:

Killbox

 

1. Execute o Killbox, clique em Delete on Reboot.

 

2. Copie a lista abaixo em negrito para a área de transferência. Selecione tudo com o auxílio do mouse --> vá até a aba Editar na barra do navegador --> clique em Copiar.

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\JVM0.exe

C:\Documents and Settings\Pedagógico\WINDOWS\Windows64.scr

C:\WINDOWS\system32\JVM0.exe

C:\WINDOWS\system32\nostd.scr

C:\WINDOWS\system32\hosts.scr

 

3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files.

 

4. Aperte em "X". Responda "não" à pergunta.

 

É prudente que você faça a impressão deste documento ou salve-o em um lugar de fácil acesso, pois na próxima etapa entraremos em Modo de Seguro e a conexão à internet não será possível.

 

2ª Etapa

 

Reinicie o computador em Modo Seguro (ao reiniciar aperte a tecla F8 repetidamente até que apareça uma tela preta em DOS e escolha a opção Modo Seguro).

 

Execute o HijackThis, clique em Do a system scan only e marque:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\documents and settings\pedagógico\windows\system32\blank.htm

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

O4 - HKLM\..\Run: [JVM0] C:\WINDOWS\system32\JVM0.exe

O4 - HKLM\..\Run: [nostd] C:\WINDOWS\system32\nostd.scr

O4 - HKLM\..\Run: [ ] C:\Documents and Settings\Pedagógico\WINDOWS\Windows64.scr

O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr

O4 - Global Startup: JVM0.exe

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

Clique em Fix Checked.

 

3ª Etapa

 

Reinicie em Modo Normal.

 

Retorne com um novo log do HijackThis.

 

Um abraço.

 

PS.: O pessoal da sua rede está clicando em todos os links anexados ao orkut, e-mails, etc... :closedeyes: Sugiro que eles leiam este artigo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Heisenberg,

 

O CCleaner é um excelente programa, mas não possui funções capazes de remover trojans, nem tampouco que corrijam as modificações causadas pelos arquivos maliciosos dos Bankers. Sugiro que poste um novo log do HijackThis, a fim de que eu possa analisá-lo.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto é preciso enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.