FilipeCC 0 Denunciar post Postado Julho 1, 2007 Olá! É a primeira vez que posto no iMasters. Meu computador já tá faz algum tempo com um problema: Eu ligo e ele "cria" um arquivo iexplore.exe em algum lugar na pasta C:\Windows e não adianta apagá-lo que ele cria em outro lugar. Ex.: Ligo o computador e ele está em C:\Windows\Media\iexplore.exe, se eu apagar e reiniciar ele cria em C:\Windows\system\iexplore.exe, enfim, qualquer pasta. Já passei o Ad-aware SE inúmeras vezes, ele nunca pegou este vírus, baixei o Ad-aware 2007 e ele trava e reinicia o computador quando ele scan esse arquivo. Tentei o EasySpy Remover também e nada. Ele deixa o computador lento às vezes, como faço pra remover isso? Alguém me ajuda por favor! Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Julho 3, 2007 Olá FilipeCC! Baixe > HijackThis Abra uma pasta em C:\ e salve nela. Quando abrir a ferramenta, clique em "Do a system scan and save a logfile". Selecione, copie todo o seu conteúdo e cole na sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
FilipeCC 0 Denunciar post Postado Julho 3, 2007 Ah, tá. às vezes se eu não apago o iexplore.exe ele não abre nenhuma página do explorer (internet; Meus documentos; Meu Computador, etc.). Para apagá-lo uso o AnVir, que uma das únicas coisas que eu consigo rodar quando dá esse problema. Segue o log: Aguardo o póximo passo... Logfile of HijackThis v1.99.1 Scan saved at 15:11:42, on 3/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\system32\cisvc.exe C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe C:\WINDOWS\Cursors\IEXPLORE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\wamp\apache2\bin\Apache.exe C:\wamp\mysql\bin\mysqld-nt.exe C:\wamp\apache2\bin\Apache.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe C:\WINDOWS\system32\rmctrl.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Arquivos de programas\Comodo\Firewall\CPF.exe C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\HijackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Arquivos de programas\NewDotNet\newdotnet7_48.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar3.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: Natural Voice Reader - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar3.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Remote_Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe" O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing) O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe O23 - Service: DirectX Service (DirectSang) - Unknown owner - c:\windows\system32\directx.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing) O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: wampapache - Unknown owner - C:\wamp\apache2\bin\Apache.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - C:\wamp\mysql\bin\mysqld-nt.exe Compartilhar este post Link para o post Compartilhar em outros sites
Denis Dias 0 Denunciar post Postado Julho 4, 2007 Vamos lá Felipecc,Baixe O WinSockXP FIX ://www.majorgeeks.com/download4372.htmlBaixe, mas não execute ainda.Desinstale o New.Net ou NewDotNet através de Adicionar / Remover programas.Reinicie em Modo Normal.Execute o WinsockFix.exe e então clique em Fix.Poste um novo log do HijackThis.Aguardo retorno. Compartilhar este post Link para o post Compartilhar em outros sites
FilipeCC 0 Denunciar post Postado Julho 5, 2007 Seguido os passos, posto o log... Logfile of HijackThis v1.99.1 Scan saved at 13:05:18, on 5/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\system32\cisvc.exe C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe C:\WINDOWS\system32\rmctrl.exe C:\Arquivos de programas\Comodo\Firewall\CPF.exe C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\wamp\apache2\bin\Apache.exe C:\wamp\mysql\bin\mysqld-nt.exe C:\wamp\apache2\bin\Apache.exe C:\HijackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Arquivos de programas\NewDotNet\newdotnet7_48.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar3.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: Natural Voice Reader - {BCBF738C-4891-4B9A-959A-C6BF7F608C3A} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar3.dll O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Google Desktop Search] "C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Remote_Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe" O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Agent] "C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: wineil32 - wineil32.dll (file missing) O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe O23 - Service: DirectX Service (DirectSang) - Unknown owner - c:\windows\system32\directx.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe (file missing) O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: wampapache - Unknown owner - C:\wamp\apache2\bin\Apache.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - C:\wamp\mysql\bin\mysqld-nt.exe Aguardo retorno... Compartilhar este post Link para o post Compartilhar em outros sites
FilipeCC 0 Denunciar post Postado Julho 5, 2007 Não resolveu ainda. Ele continua criando os arquivos...Ah! o New.Net ele só removeu dos arquivos de programas, pois já tinha sido desinstalado. Compartilhar este post Link para o post Compartilhar em outros sites
Denis Dias 0 Denunciar post Postado Julho 5, 2007 EDITADO. Violação das regras Nº 01 e Nº 02. jgarcia Compartilhar este post Link para o post Compartilhar em outros sites
FilipeCC 0 Denunciar post Postado Julho 5, 2007 Fiz o que o Denis Dias mandou e foi editado, seguem os logos, porém não sei se irão atrapalhar o moderados como segue as regras 1 e 2, mas se for simplesmente ignore estes logs... Também achei estranho ele não ser moderador...mas talvez tenha dado certo. COMBO FIX "Filipe" - 2007-07-05 15:40:37 - ComboFix 07-07-04.4 - Service Pack 2 FAT32 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\Filipe\DADOSD~1.\Starware C:\DOCUME~1\Filipe\DADOSD~1.\Starware\Manager\ManagerOptions.xml C:\DOCUME~1\Filipe\DADOSD~1.\Starware\Manager\ManagerOptions.xml.backup C:\WINDOWS\system32\cfx32.ocx ((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 ))))))))))))))))))))))))))))))) 2007-07-05 15:39 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-05 09:24 <DIR> d-------- C:\Arquivos de programas\Scribus 1.3.3.9 2007-07-05 09:19 <DIR> d-------- C:\Arquivos de programas\Comparatel 2007-07-03 15:11 <DIR> d-------- C:\HijackThis 2007-07-03 14:22 <DIR> d-------- C:\Arquivos de programas\PesquisaBibliaNVI 2007-07-01 17:18 <DIR> d--hs---- C:\FOUND.005 2007-07-01 14:14 <DIR> d--hs---- C:\FOUND.004 2007-07-01 14:00 <DIR> d--hs---- C:\FOUND.003 2007-07-01 13:31 <DIR> d-------- C:\Arquivos de programas\Lavasoft 2007-07-01 13:16 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Lavasoft 2007-06-28 22:38 <DIR> d--hs---- C:\FOUND.002 2007-06-27 21:43 86,016 --------- C:\WINDOWS\system32\pxwma.dll 2007-06-27 17:42 <DIR> d--hs---- C:\FOUND.001 2007-06-27 14:23 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\Opera 2007-06-26 15:48 <DIR> d-------- C:\Arquivos de programas\WorldCast 2007-06-25 20:33 <DIR> d--hs---- C:\FOUND.000 2007-06-23 20:56 <DIR> d-------- C:\Arquivos de programas\Camtech 2007-06-23 14:43 503,800 --a------ C:\DOCUME~1\Filipe\DADOSD~1\GDIPFONTCACHEV1.DAT 2007-06-23 11:20 <DIR> d-------- C:\Arquivos de programas\Alcohol Soft 2007-06-23 11:17 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-06-21 16:41 <DIR> d-------- C:\WINDOWS\Corel 2007-06-21 16:41 <DIR> d-------- C:\Arquivos de programas\KnockOut 2 2007-06-21 15:25 <DIR> d-------- C:\WINDOWS\vbSkinner 2007-06-19 11:44 <DIR> d-------- C:\Arquivos de programas\Soulseek 2007-06-19 10:54 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\pdf995 2007-06-19 09:37 <DIR> d-------- C:\pdf995 2007-06-15 18:37 <DIR> d-------- C:\DOCUME~1\Filipe\DADOSD~1\ColorCop 2007-06-15 18:22 7,340,032 --a------ C:\DOCUME~1\Filipe\ntuser.dat 2007-06-15 18:22 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll 2007-06-15 18:22 249,856 --a------ C:\WINDOWS\system32\pdfmona.dll 2007-06-15 18:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\pdf995 2007-06-15 12:39 <DIR> d-------- C:\DOCUME~1\Agnes\DADOSD~1\Skype 2007-06-12 14:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Elaborate Bytes 2007-06-12 14:47 <DIR> d-------- C:\Arquivos de programas\Elaborate Bytes 2007-06-11 11:50 <DIR> d-------- C:\Arquivos de programas\SlySoft 2007-06-08 12:30 <DIR> d-------- C:\RALLYC 2007-06-07 19:40 <DIR> d-------- C:\Arquivos de programas\SopCast 2007-06-06 13:15 <DIR> d-------- C:\WINDOWS\system32\QuickTime 2007-06-05 15:35 <DIR> d-------- C:\Arquivos de programas\DremTeamShare (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-21 20:25:22 451 ----a-w C:\WINDOWS\PowerReg.dat 2007-06-11 16:16:24 1,536 ----a-w C:\WINDOWS\system32\TrueSoft.dat 2007-06-04 18:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys 2007-06-04 18:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys 2007-06-04 18:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys 2007-06-03 20:58:46 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Skype 2007-06-03 20:58:28 -------- d-----w C:\Arquivos de programas\Skype 2007-06-03 20:58:28 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Skype 2007-06-03 15:03:50 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Extensis 2007-06-03 15:03:48 -------- d-----w C:\Arquivos de programas\Extensis 2007-06-03 14:52:40 -------- d-----w C:\Arquivos de programas\FLV Player 2007-06-01 14:10:10 -------- d-----w C:\Arquivos de programas\DIFX 2007-06-01 14:09:52 -------- d-----w C:\Arquivos de programas\MSN Messenger 2007-06-01 13:59:48 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared 2007-06-01 02:29:16 512,000 ----a-w C:\WINDOWS\system32\demoMX.scr 2007-06-01 01:49:20 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Comodo 2007-06-01 01:35:04 -------- d-----w C:\Arquivos de programas\Aurora MPEG To DVD Burner 2007-05-31 23:57:20 -------- d-----w C:\Arquivos de programas\Easy SpyRemover 2007-05-31 23:36:16 -------- d-----w C:\Arquivos de programas\Comodo 2007-05-31 22:19:52 -------- d-----w C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard 2007-05-31 18:51:08 -------- d-----w C:\Arquivos de programas\FreshDevices 2007-05-31 14:57:46 -------- d-----w C:\Arquivos de programas\Anvir 2007-05-27 14:40:50 -------- d-----w C:\Arquivos de programas\WinCopyDVD 3.5 Standard Edition 2007-05-18 12:43:56 -------- d-----w C:\DOCUME~1\Filipe\DADOSD~1\Microsoft Games 2007-05-18 12:27:58 -------- d-----w C:\Arquivos de programas\Red Storm Entertainment 2007-04-15 16:08:30 5,413 ----a-w C:\WINDOWS\mozver.dat 2007-04-13 18:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-12-18 04:16 59032 --a------ C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}] 2007-05-28 14:52 722472 --a------ C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E3C3651-B19C-4DD9-A979-901EC3E930AF}] 2007-05-19 07:37 124416 --------- C:\Arquivos de programas\Scpad\scpsssh2.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2007-03-14 03:43 501400 --a------ C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] 2007-01-19 23:56 2423872 -ra------ c:\arquivos de programas\google\googletoolbar3.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SiSPower"="SiSPower.dll" [2005-01-04 06:54 C:\WINDOWS\system32\SiSPower.dll] "SoundMan"="SOUNDMAN.EXE" [2004-12-22 07:09 C:\WINDOWS\SOUNDMAN.EXE] "Google Desktop Search"="C:\Arquivos de programas\Google\Google Desktop Search\GoogleDesktop.exe" [2006-10-18 15:06] "Remote_Agent"="C:\Arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe" [2004-06-17 14:04] "Agent"="C:\Arquivos de programas\CyberLink\PowerVCRII\Agent.exe" [2004-06-17 14:04] "COMODO Firewall Pro"="C:\Arquivos de programas\Comodo\Firewall\CPF.exe" [2007-05-31 20:36] "CloneCDTray"="C:\Arquivos de programas\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 10:47] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43] "AVG7_CC"="C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe" [2007-06-27 12:38] "HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-17 17:22] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{A3717295-941D-416F-9384-ED1736729F1C}"="C:\Arquivos de programas\Scpad\scpLIB.dll" [2007-05-18 13:48] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "{A3717295-941D-416F-9384-ED1736729F1C}"="C:\Arquivos de programas\Scpad\scpLIB.dll" [2007-05-18 13:48] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=C:\ARQUIV~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^HP Digital Imaging Monitor.lnk] backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Remote Control.lnk] backup=C:\WINDOWS\pss\Remote Control.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Pércio^Menu Iniciar^Programas^Inicializar^WordWeb.lnk] backup=C:\WINDOWS\pss\WordWeb.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "wampmysqld"=2 (0x2) "wampapache"=2 (0x2) "usnjsvc"=3 (0x3) ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-05 15:42:30 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet002\Services\wampmysqld] "ImagePath"="C:\wamp\mysql\bin\mysqld-nt.exe --defaults-file=c:\wamp\mysql\my.ini wampmysqld" Completion time: 2007-07-05 15:42:59 C:\ComboFix-quarantined-files.txt ... 2007-07-05 15:43 --- E O F --- /COMBO FIX O Banker Fix não encontro erros... Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Setembro 23, 2008 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites