Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

G_santos

[Resolvido!] Não consigo desligar o computador

Recommended Posts

Logfile of HijackThis v1.99.1

Scan saved at 16:09:04, on 27/7/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\CAVTray.exe

C:\WINDOWS\system\winlogin.cmd

C:\Program Files\CAVRID.exe

C:\WINDOWS\system\winlogin.cmd

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Free Download Manager\fum\fum.exe

C:\Arquivos de programas\Free Download Manager\FUM\fumoei.exe

C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

C:\Program Files\ISafe.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\VetMsg.exe

C:\Arquivos de programas\Free Download Manager\fdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system\msmsgs.cmd

C:\WINDOWS\system\msmsgs.cmd

C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll

O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe"

O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe"

O4 - HKLM\..\Run: [shell] C:\WINDOWS\system\winlogin.cmd

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Free Download Manager] "C:\Arquivos de programas\Free Download Manager\fdm.exe" -autorun

O4 - HKCU\..\Run: [Free Upload Manager] "C:\Arquivos de programas\Free Download Manager\fum\fum.exe" -autorun

O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Arquivos de programas\Free Download Manager\FUM\fumoei.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: Baixar com o FDM - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: Baixar tudo com o FDM - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selecionado pelo FDM - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm

O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Arquivos de programas\Free Download Manager\FUM\fumiebtn.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe

O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe

 

Jà passei o hijackthis ....

 

Alguem pode me ajudar a resolver esse problema

 

obrigado galera!!!!!!!!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

1. Baixe o BankerFix.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. Uma mensagem aparecerá avisando que o mesmo será baixado via internet. Clique em Ok -> Ok. Aperte Enter e aguarde o término do scan.

 

4. Terminado o scan, leia a mensagem na tela e aperte Enter novamente.

 

5. Habilite o seu anti-vírus.

 

6. Retorne com um novo log do HijackThis, juntamente com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

7. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

aqui esta o log

 

Logfile of HijackThis v1.99.1

Scan saved at 17:38:02, on 1/8/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system\winlogin.cmd

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\Program Files\CAVRID.exe

C:\WINDOWS\system\winlogin.cmd

C:\WINDOWS\system32\ctfmon.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

C:\Program Files\ISafe.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\VetMsg.exe

C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe"

O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe

O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe

 

 

 

 

e aqui esta o relatorio

 

BankerFix 2.4 - Removedor de Bankers

Linha Defensiva - http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

Data: 1/8/2007 - 17:21

-------------------------------------------------------

Lista de Definição: 2007-07-28-1

=======================================================

 

Arquivo infectado detectado: C:\WINDOWS\java\aviso.123

Arquivo infectado removido com sucesso!

 

 

Killando arquivos em Help

-----------------------------------

 

Killing '*'

 

Removendo Arquivos em Help

-----------------------------------

 

 

Arquivos ruins restantes

-----------------------------------

 

 

----- Fim -------------------------

 

 

EU NÃO ESTOU CONSEGUINDO DESLIGAR MEU COMPUTADOR

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

Vamos lá.

 

Habilite o Windows para mostrar todos os arquivos (até ocultos).

 

1ª Etapa

 

Baixe o Killbox em:

Killbox

 

1. Execute o Killbox, clique em Delete on Reboot.

 

2. Copie a lista abaixo em negrito para a área de transferência. Selecione tudo com o auxílio do mouse --> vá até a aba Editar na barra do navegador --> clique em Copiar.

 

C:\WINDOWS\system\winlogin.cmd

 

3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files.

 

4. Aperte em "X". Responda "não" à pergunta.

 

É prudente que você faça a impressão deste documento ou salve-o em um lugar de fácil acesso, pois na próxima etapa entraremos em Modo de Seguro e a conexão à internet não será possível.

 

2ª Etapa

 

Reinicie o computador em Modo Seguro (ao reiniciar aperte a tecla F8 repetidamente até que apareça uma tela preta em DOS e escolha a opção Modo Seguro).

 

Execute o HijackThis, clique em Do a system scan only e marque:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd

Clique em Fix Checked.

 

3ª Etapa

 

Reinicie em Modo Normal.

 

Delete o conteúdo da pasta C:\!Killbox.

 

Poste um novo log do HijackThis.

 

Aguardo retorno.

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui está o log

 

Logfile of HijackThis v1.99.1

Scan saved at 23:51:58, on 2/8/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\CAVTray.exe

C:\Program Files\CAVRID.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

C:\Program Files\ISafe.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\VetMsg.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft Office\OFFICE11\WINWORD.EXE

C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe"

O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe

O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

ola Jgarciao computador já esta desligando normalmente masquando eu inicio o computador , na pagina inicial aparece um erro C:\WINDOWS\system\winlogin.cmd na pode ser encontrado verifique a digitação se está correta

Compartilhar este post


Link para o post
Compartilhar em outros sites
ola Jgarcia

 

 

o computador já esta desligando normalmente mas

quando eu inicio o computador , na pagina inicial aparece um erro

 

C:\WINDOWS\system\winlogin.cmd na pode ser encontrado verifique a digitação se está correta

A entrada deve ter ficado na inicialização.

 

Vá em Iniciar -> Executar -> digite msconfig -> dê Ok.

 

Localize a entrada que possui winlogin.cmd e desmarque-a.

 

Caso não encontre a entrada acima citada no registro de inicialização, avise em seu próximo post.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

Baixe o ComboFix em:

ComboFix

 

1) Dê um duplo-clique no combofix.exe e tecle "Y" para prosseguir. O processo vai durar, em média, 10 minutos;

2) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção);

3) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt;

4) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco);

5) Para parar ou sair do ComboFix, tecle "N";

6) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui está

 

 

ComboFix 07-08-04.3 - "User" 2007-08-07 0:46:06.1 [GMT -3:00] - NTFS

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.Verdadeiro

* Created a new restore point

 

 

((((((((((((((((((((((((( Files Created from 2007-07-07 to 2007-08-07 )))))))))))))))))))))))))))))))

 

 

2007-08-07 00:44 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-08-02 22:07 2 --a------ C:\WINDOWS\system\ok.dat

2007-08-02 15:27 81 --a------ C:\WINDOWS\system\msn.dll

2007-08-02 12:05 25,666 --a------ C:\WINDOWS\system\kl.dll

2007-07-28 12:39 <DIR> d-------- C:\WINDOWS\system32\appmgmt

2007-07-26 11:17 <DIR> d-------- C:\Arquivos de programas\MSN Messenger

2007-07-26 09:34 <DIR> d-------- C:\Downloads

2007-07-26 08:11 <DIR> d-------- C:\Arquivos de programas\a-squared Free

2007-07-25 10:45 282 --a------ C:\WINDOWS\system\kvost.dat

2007-07-25 10:44 82 --a------ C:\WINDOWS\system\svchost.dat

2007-07-25 10:44 223,654 --a------ C:\WINDOWS\system\msmsgs.cmd

2007-07-25 10:44 1,220 --a------ C:\WINDOWS\system\msn.dat

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-07-23 11:02 879832 --a------ C:\WINDOWS\system32\drivers\VetEFile.sys

2007-07-23 11:02 108360 --a------ C:\WINDOWS\system32\drivers\VetEBoot.sys

2007-07-12 12:16 --------- d-------- C:\Arquivos de programas\Windows Media Connect 2

2007-07-08 22:59 --------- d-------- C:\DOCUME~1\User\DADOSD~1\AdobeUM

2007-07-04 15:40 --------- d-------- C:\Arquivos de programas\ABSVD

2007-07-02 21:37 4608 --a------ C:\WINDOWS\system32\w95inf32.dll

2007-07-02 21:37 2272 --a------ C:\WINDOWS\system32\w95inf16.dll

2007-07-02 21:37 --------- d--h----- C:\Arquivos de programas\InstallShield Installation Information

2007-07-02 21:37 --------- d-------- C:\Arquivos de programas\ArcSoft

2007-07-02 21:30 --------- d-------- C:\DOCUME~1\User\DADOSD~1\ArcSoft

2007-06-26 23:39 --------- d-------- C:\Arquivos de programas\Apostilas Objetiva

2007-06-16 11:26 --------- d-------- C:\DOCUME~1\User\DADOSD~1\Real

2007-06-16 11:26 --------- d-------- C:\Arquivos de programas\Arquivos comuns\Real

2007-06-16 11:20 --------- d-------- C:\Arquivos de programas\Real

2007-06-10 22:53 --------- d-------- C:\Arquivos de programas\D'Accord Music Software

2007-06-09 14:44 73216 --a------ C:\WINDOWS\ST6UNST.EXE

2007-06-09 14:44 249856 --------- C:\WINDOWS\Setup1.exe

2007-06-03 23:15 74864 --a------ C:\WINDOWS\system32\VetRedir.dll

2007-06-03 23:15 115824 --a------ C:\WINDOWS\UnVet32.exe

2007-06-03 23:15 107632 --a------ C:\WINDOWS\AVShlExt.dll

2007-06-03 22:51 48846 --a------ C:\WINDOWS\system32\perfc016.dat

2007-06-03 22:51 344734 --a------ C:\WINDOWS\system32\perfh016.dat

2007-05-16 12:13 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll

2007-05-16 12:13 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll

2007-05-16 12:13 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll

2007-05-16 12:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll

2007-05-16 12:13 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll

2007-05-16 12:13 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll

2007-05-08 05:56 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CaAvTray"="C:\Program Files\CAVTray.exe" [2007-06-03 23:15]

"CAVRID"="C:\Program Files\CAVRID.exe" [2007-06-03 23:15]

"Emurayden PSX Emulator"="" []

"NWEReboot"="" []

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45]

"updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk

backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Utility Tray.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk

backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]

Mixer.exe /startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]

RunDll32 cmicnfg.cpl,CMICtrlWnd

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

C:\WINDOWS\system32\hkcmd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]

C:\WINDOWS\system32\igfxtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

"C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]

C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]

C:\Arquivos de programas\VIA\RAID\raid_t

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

"C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]

C:\WINDOWS\SiSUSBrg.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes]

VModes 1024 768 32 60

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]

VTTimer.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]

VTtrayp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsTranslator]

C:\ARQUIV~1\MICROP~1\DELTAT~1.0\DWinTrsl.exe

 

R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys

R0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys

R0 uagp35;Filtro Microsoft AGPv3.5;C:\WINDOWS\system32\DRIVERS\uagp35.sys

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys

R3 cmpci;C-Media PCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\cmaudio.sys

R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys

R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys

S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys

S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys

S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys

S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys

S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys

S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys

S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys

S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys

S3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys

S3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys

S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys

S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys

S3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys

S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys

 

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-08-07 00:53:42

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden registry entries ...

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]

"AppData"="C:\Documents and Settings\Default User\Dados de aplicativos"

"Cookies"="C:\Documents and Settings\Default User\Cookies"

"Desktop"="C:\Documents and Settings\Default User\Desktop"

"Favorites"="C:\Documents and Settings\Default User\Favoritos"

"NetHood"="C:\Documents and Settings\Default User\Ambiente de rede"

"Personal"="C:\Documents and Settings\Default User\Meus documentos"

"PrintHood"="C:\Documents and Settings\Default User\Ambiente de impress\xe3o"

"Recent"="C:\Documents and Settings\Default User\Recent"

"SendTo"="C:\Documents and Settings\Default User\SendTo"

"Start Menu"="C:\Documents and Settings\Default User\Menu Iniciar"

"Templates"="C:\Documents and Settings\Default User\Modelos"

"Programs"="C:\Documents and Settings\Default User\Menu Iniciar\Programas"

"Startup"="C:\Documents and Settings\Default User\Menu Iniciar\Programas\Inicializar"

"Local Settings"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais"

"Local AppData"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos"

"Cache"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Temporary Internet Files"

"History"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Hist\xf3rico"

"My Pictures"=""

"My Music"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SmallIcons]

"SmallIcons"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]

"Recent"=str(2):"USERPROFILE\Recent"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"User Agent"="Mozilla/4.0 (compatible; MSIE 6.0; Win32)"

"MigrateProxy"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones]

"DisplayName"="Meu computador"

"Description"="Seu computador"

"1001"=dword:00000000

"1407"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]

"DisplayName"="Intranet local"

"Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o."

"Flags"=dword:000000db

"1407"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]

"DisplayName"="Sites confi\xe1veis"

"Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados."

"1001"=dword:00000000

"1206"=dword:00000000

"1406"=dword:00000000

"1407"=dword:00000000

"1607"=dword:00000000

"1800"=dword:00000000

"1804"=dword:00000000

"1805"=dword:00000000

"1806"=dword:00000000

"1807"=dword:00000000

"1A00"=dword:00000000

"1A05"=dword:00000000

"1A10"=dword:00000000

"1E05"=dword:00030000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]

"Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas."

"1407"=dword:00000000

"1601"=dword:00000001

"1607"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]

"DisplayName"="Sites restritos"

"Description"="Esta zona cont\xe9m sites da Web que podem danificar o computador ou seus dados."

"1604"=dword:00000001

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones]

"DisplayName"="Meu computador"

"Description"="Seu computador"

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]

"Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o."

"CurrentLevel"=dword:00010500

"Flags"=dword:000000db

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]

"DisplayName"="Sites confi\xe1veis"

"Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados."

"CurrentLevel"=dword:00010000

"1001"=dword:00000000

"1004"=dword:00000001

"1201"=dword:00000001

"1206"=dword:00000000

"1406"=dword:00000000

"1407"=dword:00000000

"1607"=dword:00000000

"1800"=dword:00000000

"1804"=dword:00000000

"1805"=dword:00000000

"1806"=dword:00000000

"1809"=dword:00000003

"1A00"=dword:00000000

"1A04"=dword:00000000

"1A05"=dword:00000000

"1C00"=dword:00030000

"1E05"=dword:00030000

"2102"=dword:00000000

"2200"=dword:00000000

"2201"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]

"Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas."

"CurrentLevel"=dword:00011000

"1407"=dword:00000000

"1601"=dword:00000001

"1607"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]

"CurrentLevel"=dword:00012000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme]

"Wallpaper"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]

"C:\WINDOWS\system32\regsvr32.exe"="Servidor de registro Microsoft©"

"C:\WINDOWS\system32\RUNDLL32.exe"="Executa uma DLL como um aplicativo"

"C:\WINDOWS\system32\mshta.exe"="Microsoft ® HTML Application host"

"C:\WINDOWS\system32\fixmapi.exe"="FIXMAPI 1.0 MAPI Repair Tool"

"C:\WINDOWS\system32\odbcconf.exe"="Microsoft Data Access - ODBC Driver Configuration Program"

"C:\WINDOWS\system32\mstinit.exe"="Instala\xe7\xe3o do agendador de tarefas"

"C:\Arquivos de programas\Outlook Express\setup50.exe"="Biblioteca de instala\xe7\xe3o do Outlook Express"

"C:\WINDOWS\system32\logagent.exe"="Windows Media Player Logagent"

"C:\WINDOWS\INF\unregmp2.exe"="Utilit\xe1rio de Instala\xe7\xe3o do Microsoft Windows Media Player"

"C:\WINDOWS\system32\Cmd.exe"="Processador de comandos do Windows"

"C:\WINDOWS\pchealth\uploadlb\binaries\uploadm.exe"="Gerenciador de carregamento do PCHealth"

"C:\Arquivos de programas\Windows Media Player\migrate.exe"="MLS Migrate DLL"

"C:\WINDOWS\system32\grpconv.exe"="Conversor do Grupo de Programas do Windows"

[HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace]

"LocalBase"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.XML"

"DTDFile"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.DTD"

"LocalDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSD.XML"

"RemoteDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSR.XML"

[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"load"=""

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-08-07 0:56:53

 

--- E O F ---

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

Vamos lá.

 

1ª Etapa

 

1. Execute o Killbox, clique em Delete on Reboot.

 

2. Copie a lista abaixo em negrito para a área de transferência. Selecione tudo com o auxílio do mouse --> vá até a aba Editar na barra do navegador --> clique em Copiar.

 

C:\WINDOWS\system\ok.dat

C:\WINDOWS\system\msn.dat

C:\WINDOWS\system\kvost.dat

C:\WINDOWS\system\svchost.dat

C:\WINDOWS\system\msn.dll

C:\WINDOWS\system\kl.dll

C:\WINDOWS\system\msmsgs.cmd

C:\WINDOWS\Setup1.exe

 

3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files.

 

4. Aperte em "X". Responda "não" à pergunta.

 

2ª Etapa

 

Reinicie em Modo Normal.

 

Delete o conteúdo da pasta C:\!Killbox.

 

Poste novos logs do HijackThis e ComboFix.

 

Aguardo retorno.

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Jgarcia

 

Aqui está

 

Logfile of HijackThis v1.99.1

Scan saved at 11:20:41, on 8/8/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16473)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\CAVTray.exe

C:\Program Files\CAVRID.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

C:\Program Files\ISafe.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\VetMsg.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe"

O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe

O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe

O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe

 

 

 

 

 

 

 

 

 

ComboFix 07-08-04.3 - "User" 2007-08-08 11:28:56.2 [GMT -3:00] - NTFS

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.Verdadeiro

 

 

((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 )))))))))))))))))))))))))))))))

 

 

2007-08-08 11:13 <DIR> d-------- C:\!KillBox

2007-08-07 00:44 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-07-28 12:39 <DIR> d-------- C:\WINDOWS\system32\appmgmt

2007-07-26 11:17 <DIR> d-------- C:\Arquivos de programas\MSN Messenger

2007-07-26 09:34 <DIR> d-------- C:\Downloads

2007-07-26 08:11 <DIR> d-------- C:\Arquivos de programas\a-squared Free

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-07-23 11:02 879832 --a------ C:\WINDOWS\system32\drivers\VetEFile.sys

2007-07-23 11:02 108360 --a------ C:\WINDOWS\system32\drivers\VetEBoot.sys

2007-07-12 12:16 --------- d-------- C:\Arquivos de programas\Windows Media Connect 2

2007-07-08 22:59 --------- d-------- C:\DOCUME~1\User\DADOSD~1\AdobeUM

2007-07-04 15:40 --------- d-------- C:\Arquivos de programas\ABSVD

2007-07-02 21:37 4608 --a------ C:\WINDOWS\system32\w95inf32.dll

2007-07-02 21:37 2272 --a------ C:\WINDOWS\system32\w95inf16.dll

2007-07-02 21:37 --------- d--h----- C:\Arquivos de programas\InstallShield Installation Information

2007-07-02 21:37 --------- d-------- C:\Arquivos de programas\ArcSoft

2007-07-02 21:30 --------- d-------- C:\DOCUME~1\User\DADOSD~1\ArcSoft

2007-06-26 23:39 --------- d-------- C:\Arquivos de programas\Apostilas Objetiva

2007-06-16 11:26 --------- d-------- C:\DOCUME~1\User\DADOSD~1\Real

2007-06-16 11:26 --------- d-------- C:\Arquivos de programas\Arquivos comuns\Real

2007-06-16 11:20 --------- d-------- C:\Arquivos de programas\Real

2007-06-10 22:53 --------- d-------- C:\Arquivos de programas\D'Accord Music Software

2007-06-09 14:44 73216 --a------ C:\WINDOWS\ST6UNST.EXE

2007-06-03 23:15 74864 --a------ C:\WINDOWS\system32\VetRedir.dll

2007-06-03 23:15 115824 --a------ C:\WINDOWS\UnVet32.exe

2007-06-03 23:15 107632 --a------ C:\WINDOWS\AVShlExt.dll

2007-06-03 22:51 48846 --a------ C:\WINDOWS\system32\perfc016.dat

2007-06-03 22:51 344734 --a------ C:\WINDOWS\system32\perfh016.dat

2007-05-16 12:13 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll

2007-05-16 12:13 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll

2007-05-16 12:13 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll

2007-05-16 12:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll

2007-05-16 12:13 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll

2007-05-16 12:13 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll

2007-05-08 05:56 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CaAvTray"="C:\Program Files\CAVTray.exe" [2007-06-03 23:15]

"CAVRID"="C:\Program Files\CAVRID.exe" [2007-06-03 23:15]

"Emurayden PSX Emulator"="" []

"NWEReboot"="" []

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45]

"updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk

backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Utility Tray.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk

backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]

C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]

Mixer.exe /startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]

RunDll32 cmicnfg.cpl,CMICtrlWnd

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]

C:\WINDOWS\system32\hkcmd.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]

C:\WINDOWS\system32\igfxtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

"C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]

C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]

C:\Arquivos de programas\VIA\RAID\raid_t

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

"C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]

C:\WINDOWS\SiSUSBrg.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

"C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

SOUNDMAN.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes]

VModes 1024 768 32 60

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]

VTTimer.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]

VTtrayp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsTranslator]

C:\ARQUIV~1\MICROP~1\DELTAT~1.0\DWinTrsl.exe

 

R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys

R0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys

R0 uagp35;Filtro Microsoft AGPv3.5;C:\WINDOWS\system32\DRIVERS\uagp35.sys

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys

R3 cmpci;C-Media PCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\cmaudio.sys

R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys

R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys

S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys

S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys

S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys

S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys

S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys

S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys

S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys

S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys

S3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys

S3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys

S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys

S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys

S3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys

S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys

 

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-08-08 11:34:14

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden registry entries ...

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]

"AppData"="C:\Documents and Settings\Default User\Dados de aplicativos"

"Cookies"="C:\Documents and Settings\Default User\Cookies"

"Desktop"="C:\Documents and Settings\Default User\Desktop"

"Favorites"="C:\Documents and Settings\Default User\Favoritos"

"NetHood"="C:\Documents and Settings\Default User\Ambiente de rede"

"Personal"="C:\Documents and Settings\Default User\Meus documentos"

"PrintHood"="C:\Documents and Settings\Default User\Ambiente de impress\xe3o"

"Recent"="C:\Documents and Settings\Default User\Recent"

"SendTo"="C:\Documents and Settings\Default User\SendTo"

"Start Menu"="C:\Documents and Settings\Default User\Menu Iniciar"

"Templates"="C:\Documents and Settings\Default User\Modelos"

"Programs"="C:\Documents and Settings\Default User\Menu Iniciar\Programas"

"Startup"="C:\Documents and Settings\Default User\Menu Iniciar\Programas\Inicializar"

"Local Settings"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais"

"Local AppData"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos"

"Cache"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Temporary Internet Files"

"History"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Hist\xf3rico"

"My Pictures"=""

"My Music"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SmallIcons]

"SmallIcons"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders]

"Recent"=str(2):"USERPROFILE\Recent"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]

"User Agent"="Mozilla/4.0 (compatible; MSIE 6.0; Win32)"

"MigrateProxy"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones]

"DisplayName"="Meu computador"

"Description"="Seu computador"

"1001"=dword:00000000

"1407"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]

"DisplayName"="Intranet local"

"Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o."

"Flags"=dword:000000db

"1407"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]

"DisplayName"="Sites confi\xe1veis"

"Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados."

"1001"=dword:00000000

"1206"=dword:00000000

"1406"=dword:00000000

"1407"=dword:00000000

"1607"=dword:00000000

"1800"=dword:00000000

"1804"=dword:00000000

"1805"=dword:00000000

"1806"=dword:00000000

"1807"=dword:00000000

"1A00"=dword:00000000

"1A05"=dword:00000000

"1A10"=dword:00000000

"1E05"=dword:00030000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]

"Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas."

"1407"=dword:00000000

"1601"=dword:00000001

"1607"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]

"DisplayName"="Sites restritos"

"Description"="Esta zona cont\xe9m sites da Web que podem danificar o computador ou seus dados."

"1604"=dword:00000001

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones]

"DisplayName"="Meu computador"

"Description"="Seu computador"

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]

"Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o."

"CurrentLevel"=dword:00010500

"Flags"=dword:000000db

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]

"DisplayName"="Sites confi\xe1veis"

"Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados."

"CurrentLevel"=dword:00010000

"1001"=dword:00000000

"1004"=dword:00000001

"1201"=dword:00000001

"1206"=dword:00000000

"1406"=dword:00000000

"1407"=dword:00000000

"1607"=dword:00000000

"1800"=dword:00000000

"1804"=dword:00000000

"1805"=dword:00000000

"1806"=dword:00000000

"1809"=dword:00000003

"1A00"=dword:00000000

"1A04"=dword:00000000

"1A05"=dword:00000000

"1C00"=dword:00030000

"1E05"=dword:00030000

"2102"=dword:00000000

"2200"=dword:00000000

"2201"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]

"Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas."

"CurrentLevel"=dword:00011000

"1407"=dword:00000000

"1601"=dword:00000001

"1607"=dword:00000000

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]

"CurrentLevel"=dword:00012000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]

"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme]

"Wallpaper"=""

[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]

"C:\WINDOWS\system32\regsvr32.exe"="Servidor de registro Microsoft©"

"C:\WINDOWS\system32\RUNDLL32.exe"="Executa uma DLL como um aplicativo"

"C:\WINDOWS\system32\mshta.exe"="Microsoft ® HTML Application host"

"C:\WINDOWS\system32\fixmapi.exe"="FIXMAPI 1.0 MAPI Repair Tool"

"C:\WINDOWS\system32\odbcconf.exe"="Microsoft Data Access - ODBC Driver Configuration Program"

"C:\WINDOWS\system32\mstinit.exe"="Instala\xe7\xe3o do agendador de tarefas"

"C:\Arquivos de programas\Outlook Express\setup50.exe"="Biblioteca de instala\xe7\xe3o do Outlook Express"

"C:\WINDOWS\system32\logagent.exe"="Windows Media Player Logagent"

"C:\WINDOWS\INF\unregmp2.exe"="Utilit\xe1rio de Instala\xe7\xe3o do Microsoft Windows Media Player"

"C:\WINDOWS\system32\Cmd.exe"="Processador de comandos do Windows"

"C:\WINDOWS\pchealth\uploadlb\binaries\uploadm.exe"="Gerenciador de carregamento do PCHealth"

"C:\Arquivos de programas\Windows Media Player\migrate.exe"="MLS Migrate DLL"

"C:\WINDOWS\system32\grpconv.exe"="Conversor do Grupo de Programas do Windows"

[HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace]

"LocalBase"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.XML"

"DTDFile"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.DTD"

"LocalDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSD.XML"

"RemoteDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSR.XML"

[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]

"load"=""

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-08-08 11:37:05

C:\ComboFix2.txt ... 2007-08-07 00:56

 

--- E O F ---

 

 

 

 

continua dando o erro!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

Vá em Iniciar -> Executar -> digite regedit > dê Ok.

 

Selecione a aba Editar -> Localizar -> coloque winlogin.cmd -> Localizar próxima.

 

Caso o sistema encontre alguma entrada, delete-a. Repita a operação, de modo que todas as entradas que contenham winlogin.cmd sejam eliminadas.

 

Saia do Editor do Registro.

 

Reinicie a máquina e verifique se o erro persiste.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa G_santos,

 

Fico feliz por saber que o problema foi resolvido. :thumbsup:

 

Para finalizar siga os procedimentos contidos no Post #6.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.