Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

FilipeCC

[Arquivado] iexplore.exe na pasta windows

Recommended Posts

Olá! É a primeira vez que posto no iMasters.

 

Meu computador já tá faz algum tempo com um problema: Eu ligo e ele "cria" um arquivo iexplore.exe em algum lugar na pasta C:\Windows e não adianta apagá-lo que ele cria em outro lugar. Ex.: Ligo o computador e ele está em C:\Windows\Media\iexplore.exe, se eu apagar e reiniciar ele cria em C:\Windows\system\iexplore.exe, enfim, qualquer pasta.

 

Já passei o Ad-aware SE inúmeras vezes, ele nunca pegou este vírus, baixei o Ad-aware 2007 e ele trava e reinicia o computador quando ele scan esse arquivo. Tentei o EasySpy Remover também e nada.

 

Ele deixa o computador lento às vezes, como faço pra remover isso?

 

Alguém me ajuda por favor!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá FilipeCC! Baixe > HijackThis

 

Abra uma pasta em C:\ e salve nela.

 

Quando abrir a ferramenta, clique em "Do a system scan and save a logfile". Selecione, copie todo o seu conteúdo e cole na sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ah, tá. às vezes se eu não apago o iexplore.exe ele não abre nenhuma página do explorer (internet; Meus documentos; Meu Computador, etc.). Para apagá-lo uso o AnVir, que uma das únicas coisas que eu consigo rodar quando dá esse problema.

 

Segue o log:

 

Aguardo o póximo passo...

 

 

Logfile of HijackThis v1.99.1

Scan saved at 15:11:42, on 3/7/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

C:\WINDOWS\system32\cisvc.exe

C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

C:\WINDOWS\Cursors\IEXPLORE.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\wamp\apache2\bin\Apache.exe

C:\wamp\mysql\bin\mysqld-nt.exe

C:\wamp\apache2\bin\Apache.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe

C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe

C:\WINDOWS\system32\rmctrl.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopIndex.exe

C:\Arquivos de programas\Comodo\Firewall\CPF.exe

C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe

C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopDisplay.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopCrawl.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\HijackThis\HijackThis.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Arquivos de programas\NewDotNet\newdotnet7_48.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar3.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: Natural Voice Reader - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - (no file)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar3.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [Remote_Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe"

O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe"

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background

O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL

O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

O23 - Service: DirectX Service (DirectSang) - Unknown owner - c:\windows\system32\directx.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: wampapache - Unknown owner - C:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - C:\wamp\mysql\bin\mysqld-nt.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Vamos lá Felipecc,Baixe O WinSockXP FIX ://www.majorgeeks.com/download4372.htmlBaixe, mas não execute ainda.Desinstale o New.Net ou NewDotNet através de Adicionar / Remover programas.Reinicie em Modo Normal.Execute o WinsockFix.exe e então clique em Fix.Poste um novo log do HijackThis.Aguardo retorno.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Seguido os passos, posto o log...

 

 

Logfile of HijackThis v1.99.1

Scan saved at 13:05:18, on 5/7/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

C:\WINDOWS\system32\cisvc.exe

C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe

C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe

C:\WINDOWS\system32\rmctrl.exe

C:\Arquivos de programas\Comodo\Firewall\CPF.exe

C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe

C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopIndex.exe

C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopDisplay.exe

C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopCrawl.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\wamp\apache2\bin\Apache.exe

C:\wamp\mysql\bin\mysqld-nt.exe

C:\wamp\apache2\bin\Apache.exe

C:\HijackThis\HijackThis.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Arquivos de programas\NewDotNet\newdotnet7_48.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar3.dll

O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

O3 - Toolbar: Natural Voice Reader - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - (no file)

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar3.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [Remote_Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe"

O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe"

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background

O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL

O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

O23 - Service: DirectX Service (DirectSang) - Unknown owner - c:\windows\system32\directx.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: wampapache - Unknown owner - C:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - C:\wamp\mysql\bin\mysqld-nt.exe

 

 

 

Aguardo retorno...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Não resolveu ainda. Ele continua criando os arquivos...Ah! o New.Net ele só removeu dos arquivos de programas, pois já tinha sido desinstalado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

EDITADO.

 

Violação das regras Nº 01 e Nº 02.

 

jgarcia

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz o que o Denis Dias mandou e foi editado, seguem os logos, porém não sei se irão atrapalhar o moderados como segue as regras 1 e 2, mas se for simplesmente ignore estes logs...

 

Também achei estranho ele não ser moderador...mas talvez tenha dado certo.

 

COMBO FIX

 

"Filipe" - 2007-07-05 15:40:37 - ComboFix 07-07-04.4 - Service Pack 2 FAT32

 

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\DOCUME~1\Filipe\DADOSD~1.\Starware

C:\DOCUME~1\Filipe\DADOSD~1.\Starware\Manager\ManagerOptions.xml

C:\DOCUME~1\Filipe\DADOSD~1.\Starware\Manager\ManagerOptions.xml.backup

C:\WINDOWS\system32\cfx32.ocx

 

 

((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 )))))))))))))))))))))))))))))))

 

 

2007-07-05 15:39 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-07-05 09:24 <DIR> d-------- C:\Arquivos de programas\Scribus 1.3.3.9

2007-07-05 09:19 <DIR> d-------- C:\Arquivos de programas\Comparatel

2007-07-03 15:11 <DIR> d-------- C:\HijackThis

2007-07-03 14:22 <DIR> d-------- C:\Arquivos de programas\PesquisaBibliaNVI

2007-07-01 17:18 <DIR> d--hs---- C:\FOUND.005

2007-07-01 14:14 <DIR> d--hs---- C:\FOUND.004

2007-07-01 14:00 <DIR> d--hs---- C:\FOUND.003

2007-07-01 13:31 <DIR> d-------- C:\Arquivos de programas\Lavasoft

2007-07-01 13:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Lavasoft

2007-06-28 22:38 <DIR> d--hs---- C:\FOUND.002

2007-06-27 21:43 86,016 --------- C:\WINDOWS\system32\pxwma.dll

2007-06-27 17:42 <DIR> d--hs---- C:\FOUND.001

2007-06-27 14:23 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\Opera

2007-06-26 15:48 <DIR> d-------- C:\Arquivos de programas\WorldCast

2007-06-25 20:33 <DIR> d--hs---- C:\FOUND.000

2007-06-23 20:56 <DIR> d-------- C:\Arquivos de programas\Camtech

2007-06-23 14:43 503,800 --a------ C:\DOCUME~1\Filipe\DADOSD~1\GDIPFONTCACHEV1.DAT

2007-06-23 11:20 <DIR> d-------- C:\Arquivos de programas\Alcohol Soft

2007-06-23 11:17 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2007-06-21 16:41 <DIR> d-------- C:\WINDOWS\Corel

2007-06-21 16:41 <DIR> d-------- C:\Arquivos de programas\KnockOut 2

2007-06-21 15:25 <DIR> d-------- C:\WINDOWS\vbSkinner

2007-06-19 11:44 <DIR> d-------- C:\Arquivos de programas\Soulseek

2007-06-19 10:54 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\pdf995

2007-06-19 09:37 <DIR> d-------- C:\pdf995

2007-06-15 18:37 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\ColorCop

2007-06-15 18:22 7,340,032 --a------ C:\DOCUME~1\Filipe\ntuser.dat

2007-06-15 18:22 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll

2007-06-15 18:22 249,856 --a------ C:\WINDOWS\system32\pdfmona.dll

2007-06-15 18:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\pdf995

2007-06-15 12:39 <DIR> d-------- C:\DOCUME~1\Agnes\DADOSD~1\Skype

2007-06-12 14:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Elaborate Bytes

2007-06-12 14:47 <DIR> d-------- C:\Arquivos de programas\Elaborate Bytes

2007-06-11 11:50 <DIR> d-------- C:\Arquivos de programas\SlySoft

2007-06-08 12:30 <DIR> d-------- C:\RALLYC

2007-06-07 19:40 <DIR> d-------- C:\Arquivos de programas\SopCast

2007-06-06 13:15 <DIR> d-------- C:\WINDOWS\system32\QuickTime

2007-06-05 15:35 <DIR> d-------- C:\Arquivos de programas\DremTeamShare

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-06-21 20:25:22 451 ----a-w C:\WINDOWS\PowerReg.dat

2007-06-11 16:16:24 1,536 ----a-w C:\WINDOWS\system32\TrueSoft.dat

2007-06-04 18:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys

2007-06-04 18:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys

2007-06-04 18:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys

2007-06-03 20:58:46 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Skype

2007-06-03 20:58:28 -------- d-----w C:\Arquivos de programas\Skype

2007-06-03 20:58:28 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Skype

2007-06-03 15:03:50 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Extensis

2007-06-03 15:03:48 -------- d-----w C:\Arquivos de programas\Extensis

2007-06-03 14:52:40 -------- d-----w C:\Arquivos de programas\FLV Player

2007-06-01 14:10:10 -------- d-----w C:\Arquivos de programas\DIFX

2007-06-01 14:09:52 -------- d-----w C:\Arquivos de programas\MSN Messenger

2007-06-01 13:59:48 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared

2007-06-01 02:29:16 512,000 ----a-w C:\WINDOWS\system32\demoMX.scr

2007-06-01 01:49:20 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Comodo

2007-06-01 01:35:04 -------- d-----w C:\Arquivos de programas\Aurora MPEG To DVD Burner

2007-05-31 23:57:20 -------- d-----w C:\Arquivos de programas\Easy SpyRemover

2007-05-31 23:36:16 -------- d-----w C:\Arquivos de programas\Comodo

2007-05-31 22:19:52 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

2007-05-31 18:51:08 -------- d-----w C:\Arquivos de programas\FreshDevices

2007-05-31 14:57:46 -------- d-----w C:\Arquivos de programas\Anvir

2007-05-27 14:40:50 -------- d-----w C:\Arquivos de programas\WinCopyDVD 3.5 Standard Edition

2007-05-18 12:43:56 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Microsoft Games

2007-05-18 12:27:58 -------- d-----w C:\Arquivos de programas\Red Storm Entertainment

2007-04-15 16:08:30 5,413 ----a-w C:\WINDOWS\mozver.dat

2007-04-13 18:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

2006-12-18 04:16 59032 --a------ C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]

2007-05-28 14:52 722472 --a------ C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E3C3651-B19C-4DD9-A979-901EC3E930AF}]

2007-05-19 07:37 124416 --------- C:\Arquivos de programas\Scpad\scpsssh2.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

2007-03-14 03:43 501400 --a------ C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

2007-01-19 23:56 2423872 -ra------ c:\arquivos de programas\google\googletoolbar3.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SiSPower"="SiSPower.dll" [2005-01-04 06:54 C:\WINDOWS\system32\SiSPower.dll]

"SoundMan"="SOUNDMAN.EXE" [2004-12-22 07:09 C:\WINDOWS\SOUNDMAN.EXE]

"Google Desktop Search"="C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" [2006-10-18 15:06]

"Remote_Agent"="C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe" [2004-06-17 14:04]

"Agent"="C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe" [2004-06-17 14:04]

"COMODO Firewall Pro"="C:\Arquivos de programas\Comodo\Firewall\CPF.exe" [2007-05-31 20:36]

"CloneCDTray"="C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 10:47]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

"AVG7_CC"="C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe" [2007-06-27 12:38]

"HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00]

"swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-17 17:22]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{A3717295-941D-416F-9384-ED1736729F1C}"="C:\Arquivos de programas\Scpad\scpLIB.dll" [2007-05-18 13:48]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"{A3717295-941D-416F-9384-ED1736729F1C}"="C:\Arquivos de programas\Scpad\scpLIB.dll" [2007-05-18 13:48]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"appinit_dlls"=C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^HP Digital Imaging Monitor.lnk]

backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Remote Control.lnk]

backup=C:\WINDOWS\pss\Remote Control.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Pércio^Menu Iniciar^Programas^Inicializar^WordWeb.lnk]

backup=C:\WINDOWS\pss\WordWeb.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"wampmysqld"=2 (0x2)

"wampapache"=2 (0x2)

"usnjsvc"=3 (0x3)

 

 

**************************************************************************

 

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-07-05 15:42:30

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\wampmysqld]

"ImagePath"="C:\wamp\mysql\bin\mysqld-nt.exe --defaults-file=c:\wamp\mysql\my.ini wampmysqld"

 

Completion time: 2007-07-05 15:42:59

C:\ComboFix-quarantined-files.txt ... 2007-07-05 15:43

 

--- E O F ---

 

/COMBO FIX

 

 

 

O Banker Fix não encontro erros...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.