G_santos 0 Denunciar post Postado Julho 28, 2007 Logfile of HijackThis v1.99.1 Scan saved at 16:09:04, on 27/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CAVTray.exe C:\WINDOWS\system\winlogin.cmd C:\Program Files\CAVRID.exe C:\WINDOWS\system\winlogin.cmd C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Free Download Manager\fum\fum.exe C:\Arquivos de programas\Free Download Manager\FUM\fumoei.exe C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe C:\Arquivos de programas\a-squared Free\a2service.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ISafe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\VetMsg.exe C:\Arquivos de programas\Free Download Manager\fdm.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system\msmsgs.cmd C:\WINDOWS\system\msmsgs.cmd C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe" O4 - HKLM\..\Run: [shell] C:\WINDOWS\system\winlogin.cmd O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Free Download Manager] "C:\Arquivos de programas\Free Download Manager\fdm.exe" -autorun O4 - HKCU\..\Run: [Free Upload Manager] "C:\Arquivos de programas\Free Download Manager\fum\fum.exe" -autorun O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Arquivos de programas\Free Download Manager\FUM\fumoei.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Baixar com o FDM - file://C:\Arquivos de programas\Free Download Manager\dllink.htm O8 - Extra context menu item: Baixar tudo com o FDM - file://C:\Arquivos de programas\Free Download Manager\dlall.htm O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selecionado pelo FDM - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Arquivos de programas\Free Download Manager\FUM\fumiebtn.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe Jà passei o hijackthis .... Alguem pode me ajudar a resolver esse problema obrigado galera!!!!!!!!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 1, 2007 Opa G_santos, 1. Baixe o BankerFix. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. Uma mensagem aparecerá avisando que o mesmo será baixado via internet. Clique em Ok -> Ok. Aperte Enter e aguarde o término do scan. 4. Terminado o scan, leia a mensagem na tela e aperte Enter novamente. 5. Habilite o seu anti-vírus. 6. Retorne com um novo log do HijackThis, juntamente com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 7. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 1, 2007 aqui esta o log Logfile of HijackThis v1.99.1 Scan saved at 17:38:02, on 1/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system\winlogin.cmd C:\Arquivos de programas\a-squared Free\a2service.exe C:\Program Files\CAVRID.exe C:\WINDOWS\system\winlogin.cmd C:\WINDOWS\system32\ctfmon.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ISafe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\VetMsg.exe C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe e aqui esta o relatorio BankerFix 2.4 - Removedor de Bankers Linha Defensiva - http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ Data: 1/8/2007 - 17:21 ------------------------------------------------------- Lista de Definição: 2007-07-28-1 ======================================================= Arquivo infectado detectado: C:\WINDOWS\java\aviso.123 Arquivo infectado removido com sucesso! Killando arquivos em Help ----------------------------------- Killing '*' Removendo Arquivos em Help ----------------------------------- Arquivos ruins restantes ----------------------------------- ----- Fim ------------------------- EU NÃO ESTOU CONSEGUINDO DESLIGAR MEU COMPUTADOR Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 2, 2007 Opa G_santos, Vamos lá. Habilite o Windows para mostrar todos os arquivos (até ocultos). 1ª Etapa Baixe o Killbox em: Killbox 1. Execute o Killbox, clique em Delete on Reboot. 2. Copie a lista abaixo em negrito para a área de transferência. Selecione tudo com o auxílio do mouse --> vá até a aba Editar na barra do navegador --> clique em Copiar. C:\WINDOWS\system\winlogin.cmd 3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files. 4. Aperte em "X". Responda "não" à pergunta. É prudente que você faça a impressão deste documento ou salve-o em um lugar de fácil acesso, pois na próxima etapa entraremos em Modo de Seguro e a conexão à internet não será possível. 2ª Etapa Reinicie o computador em Modo Seguro (ao reiniciar aperte a tecla F8 repetidamente até que apareça uma tela preta em DOS e escolha a opção Modo Seguro). Execute o HijackThis, clique em Do a system scan only e marque: F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system\winlogin.cmd Clique em Fix Checked. 3ª Etapa Reinicie em Modo Normal. Delete o conteúdo da pasta C:\!Killbox. Poste um novo log do HijackThis. Aguardo retorno. Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 3, 2007 Aqui está o log Logfile of HijackThis v1.99.1 Scan saved at 23:51:58, on 2/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CAVTray.exe C:\Program Files\CAVRID.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\a-squared Free\a2service.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ISafe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\VetMsg.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Microsoft Office\OFFICE11\WINWORD.EXE C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 3, 2007 Opa G_santos, O seu log está LIMPO. :thumbsup: Para finalizar: 1. Desabilite e Reabilite a função de Restauração Automática do XP. Clique aqui para ver como; 2. Leia o artigo Cuidados ao navegar na net e saiba como evitar novas infecções. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 3, 2007 ola Jgarciao computador já esta desligando normalmente masquando eu inicio o computador , na pagina inicial aparece um erro C:\WINDOWS\system\winlogin.cmd na pode ser encontrado verifique a digitação se está correta Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 3, 2007 ola Jgarcia o computador já esta desligando normalmente mas quando eu inicio o computador , na pagina inicial aparece um erro C:\WINDOWS\system\winlogin.cmd na pode ser encontrado verifique a digitação se está correta A entrada deve ter ficado na inicialização. Vá em Iniciar -> Executar -> digite msconfig -> dê Ok. Localize a entrada que possui winlogin.cmd e desmarque-a. Caso não encontre a entrada acima citada no registro de inicialização, avise em seu próximo post. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 5, 2007 Ola Jgarcia não consegui encontrar Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 6, 2007 Opa G_santos, Baixe o ComboFix em: ComboFix 1) Dê um duplo-clique no combofix.exe e tecle "Y" para prosseguir. O processo vai durar, em média, 10 minutos; 2) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção); 3) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt; 4) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco); 5) Para parar ou sair do ComboFix, tecle "N"; 6) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 7, 2007 Aqui está ComboFix 07-08-04.3 - "User" 2007-08-07 0:46:06.1 [GMT -3:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.Verdadeiro * Created a new restore point ((((((((((((((((((((((((( Files Created from 2007-07-07 to 2007-08-07 ))))))))))))))))))))))))))))))) 2007-08-07 00:44 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-02 22:07 2 --a------ C:\WINDOWS\system\ok.dat 2007-08-02 15:27 81 --a------ C:\WINDOWS\system\msn.dll 2007-08-02 12:05 25,666 --a------ C:\WINDOWS\system\kl.dll 2007-07-28 12:39 <DIR> d-------- C:\WINDOWS\system32\appmgmt 2007-07-26 11:17 <DIR> d-------- C:\Arquivos de programas\MSN Messenger 2007-07-26 09:34 <DIR> d-------- C:\Downloads 2007-07-26 08:11 <DIR> d-------- C:\Arquivos de programas\a-squared Free 2007-07-25 10:45 282 --a------ C:\WINDOWS\system\kvost.dat 2007-07-25 10:44 82 --a------ C:\WINDOWS\system\svchost.dat 2007-07-25 10:44 223,654 --a------ C:\WINDOWS\system\msmsgs.cmd 2007-07-25 10:44 1,220 --a------ C:\WINDOWS\system\msn.dat (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-23 11:02 879832 --a------ C:\WINDOWS\system32\drivers\VetEFile.sys 2007-07-23 11:02 108360 --a------ C:\WINDOWS\system32\drivers\VetEBoot.sys 2007-07-12 12:16 --------- d-------- C:\Arquivos de programas\Windows Media Connect 2 2007-07-08 22:59 --------- d-------- C:\DOCUME~1\User\DADOSD~1\AdobeUM 2007-07-04 15:40 --------- d-------- C:\Arquivos de programas\ABSVD 2007-07-02 21:37 4608 --a------ C:\WINDOWS\system32\w95inf32.dll 2007-07-02 21:37 2272 --a------ C:\WINDOWS\system32\w95inf16.dll 2007-07-02 21:37 --------- d--h----- C:\Arquivos de programas\InstallShield Installation Information 2007-07-02 21:37 --------- d-------- C:\Arquivos de programas\ArcSoft 2007-07-02 21:30 --------- d-------- C:\DOCUME~1\User\DADOSD~1\ArcSoft 2007-06-26 23:39 --------- d-------- C:\Arquivos de programas\Apostilas Objetiva 2007-06-16 11:26 --------- d-------- C:\DOCUME~1\User\DADOSD~1\Real 2007-06-16 11:26 --------- d-------- C:\Arquivos de programas\Arquivos comuns\Real 2007-06-16 11:20 --------- d-------- C:\Arquivos de programas\Real 2007-06-10 22:53 --------- d-------- C:\Arquivos de programas\D'Accord Music Software 2007-06-09 14:44 73216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-06-09 14:44 249856 --------- C:\WINDOWS\Setup1.exe 2007-06-03 23:15 74864 --a------ C:\WINDOWS\system32\VetRedir.dll 2007-06-03 23:15 115824 --a------ C:\WINDOWS\UnVet32.exe 2007-06-03 23:15 107632 --a------ C:\WINDOWS\AVShlExt.dll 2007-06-03 22:51 48846 --a------ C:\WINDOWS\system32\perfc016.dat 2007-06-03 22:51 344734 --a------ C:\WINDOWS\system32\perfh016.dat 2007-05-16 12:13 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll 2007-05-16 12:13 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll 2007-05-16 12:13 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-05-16 12:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-05-16 12:13 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll 2007-05-16 12:13 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll 2007-05-08 05:56 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CaAvTray"="C:\Program Files\CAVTray.exe" [2007-06-03 23:15] "CAVRID"="C:\Program Files\CAVRID.exe" [2007-06-03 23:15] "Emurayden PSX Emulator"="" [] "NWEReboot"="" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45] "updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Utility Tray.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer] Mixer.exe /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool] C:\Arquivos de programas\VIA\RAID\raid_t [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes] VModes 1024 768 32 60 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer] VTTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp] VTtrayp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsTranslator] C:\ARQUIV~1\MICROP~1\DELTAT~1.0\DWinTrsl.exe R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys R0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys R0 uagp35;Filtro Microsoft AGPv3.5;C:\WINDOWS\system32\DRIVERS\uagp35.sys R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys R3 cmpci;C-Media PCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\cmaudio.sys R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys S3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys S3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys S3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-07 00:53:42 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden registry entries ... [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "AppData"="C:\Documents and Settings\Default User\Dados de aplicativos" "Cookies"="C:\Documents and Settings\Default User\Cookies" "Desktop"="C:\Documents and Settings\Default User\Desktop" "Favorites"="C:\Documents and Settings\Default User\Favoritos" "NetHood"="C:\Documents and Settings\Default User\Ambiente de rede" "Personal"="C:\Documents and Settings\Default User\Meus documentos" "PrintHood"="C:\Documents and Settings\Default User\Ambiente de impress\xe3o" "Recent"="C:\Documents and Settings\Default User\Recent" "SendTo"="C:\Documents and Settings\Default User\SendTo" "Start Menu"="C:\Documents and Settings\Default User\Menu Iniciar" "Templates"="C:\Documents and Settings\Default User\Modelos" "Programs"="C:\Documents and Settings\Default User\Menu Iniciar\Programas" "Startup"="C:\Documents and Settings\Default User\Menu Iniciar\Programas\Inicializar" "Local Settings"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais" "Local AppData"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos" "Cache"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Temporary Internet Files" "History"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Hist\xf3rico" "My Pictures"="" "My Music"="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SmallIcons] "SmallIcons"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "Recent"=str(2):"USERPROFILE\Recent" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "User Agent"="Mozilla/4.0 (compatible; MSIE 6.0; Win32)" "MigrateProxy"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones] "DisplayName"="Meu computador" "Description"="Seu computador" "1001"=dword:00000000 "1407"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1] "DisplayName"="Intranet local" "Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o." "Flags"=dword:000000db "1407"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2] "DisplayName"="Sites confi\xe1veis" "Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados." "1001"=dword:00000000 "1206"=dword:00000000 "1406"=dword:00000000 "1407"=dword:00000000 "1607"=dword:00000000 "1800"=dword:00000000 "1804"=dword:00000000 "1805"=dword:00000000 "1806"=dword:00000000 "1807"=dword:00000000 "1A00"=dword:00000000 "1A05"=dword:00000000 "1A10"=dword:00000000 "1E05"=dword:00030000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3] "Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas." "1407"=dword:00000000 "1601"=dword:00000001 "1607"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4] "DisplayName"="Sites restritos" "Description"="Esta zona cont\xe9m sites da Web que podem danificar o computador ou seus dados." "1604"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] "DisplayName"="Meu computador" "Description"="Seu computador" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] "Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o." "CurrentLevel"=dword:00010500 "Flags"=dword:000000db [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] "DisplayName"="Sites confi\xe1veis" "Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados." "CurrentLevel"=dword:00010000 "1001"=dword:00000000 "1004"=dword:00000001 "1201"=dword:00000001 "1206"=dword:00000000 "1406"=dword:00000000 "1407"=dword:00000000 "1607"=dword:00000000 "1800"=dword:00000000 "1804"=dword:00000000 "1805"=dword:00000000 "1806"=dword:00000000 "1809"=dword:00000003 "1A00"=dword:00000000 "1A04"=dword:00000000 "1A05"=dword:00000000 "1C00"=dword:00030000 "1E05"=dword:00030000 "2102"=dword:00000000 "2200"=dword:00000000 "2201"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] "Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas." "CurrentLevel"=dword:00011000 "1407"=dword:00000000 "1601"=dword:00000001 "1607"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] "CurrentLevel"=dword:00012000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme] "Wallpaper"="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\WINDOWS\system32\regsvr32.exe"="Servidor de registro Microsoft©" "C:\WINDOWS\system32\RUNDLL32.exe"="Executa uma DLL como um aplicativo" "C:\WINDOWS\system32\mshta.exe"="Microsoft ® HTML Application host" "C:\WINDOWS\system32\fixmapi.exe"="FIXMAPI 1.0 MAPI Repair Tool" "C:\WINDOWS\system32\odbcconf.exe"="Microsoft Data Access - ODBC Driver Configuration Program" "C:\WINDOWS\system32\mstinit.exe"="Instala\xe7\xe3o do agendador de tarefas" "C:\Arquivos de programas\Outlook Express\setup50.exe"="Biblioteca de instala\xe7\xe3o do Outlook Express" "C:\WINDOWS\system32\logagent.exe"="Windows Media Player Logagent" "C:\WINDOWS\INF\unregmp2.exe"="Utilit\xe1rio de Instala\xe7\xe3o do Microsoft Windows Media Player" "C:\WINDOWS\system32\Cmd.exe"="Processador de comandos do Windows" "C:\WINDOWS\pchealth\uploadlb\binaries\uploadm.exe"="Gerenciador de carregamento do PCHealth" "C:\Arquivos de programas\Windows Media Player\migrate.exe"="MLS Migrate DLL" "C:\WINDOWS\system32\grpconv.exe"="Conversor do Grupo de Programas do Windows" [HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace] "LocalBase"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.XML" "DTDFile"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.DTD" "LocalDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSD.XML" "RemoteDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSR.XML" [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] "load"="" scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-07 0:56:53 --- E O F --- Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 7, 2007 Opa G_santos, Vamos lá. 1ª Etapa 1. Execute o Killbox, clique em Delete on Reboot. 2. Copie a lista abaixo em negrito para a área de transferência. Selecione tudo com o auxílio do mouse --> vá até a aba Editar na barra do navegador --> clique em Copiar. C:\WINDOWS\system\ok.dat C:\WINDOWS\system\msn.dat C:\WINDOWS\system\kvost.dat C:\WINDOWS\system\svchost.dat C:\WINDOWS\system\msn.dll C:\WINDOWS\system\kl.dll C:\WINDOWS\system\msmsgs.cmd C:\WINDOWS\Setup1.exe 3. Retorne ao Killbox. Clique em File > Paste from clipboard. Clique em All Files. 4. Aperte em "X". Responda "não" à pergunta. 2ª Etapa Reinicie em Modo Normal. Delete o conteúdo da pasta C:\!Killbox. Poste novos logs do HijackThis e ComboFix. Aguardo retorno. Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 8, 2007 Olá Jgarcia Aqui está Logfile of HijackThis v1.99.1 Scan saved at 11:20:41, on 8/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CAVTray.exe C:\Program Files\CAVRID.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Arquivos de programas\a-squared Free\a2service.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ISafe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\VetMsg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\User\Meus documentos\Meus arquivos recebidos\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/GLogin.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CAVRID.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\ISafe.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\VetMsg.exe ComboFix 07-08-04.3 - "User" 2007-08-08 11:28:56.2 [GMT -3:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.Verdadeiro ((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 ))))))))))))))))))))))))))))))) 2007-08-08 11:13 <DIR> d-------- C:\!KillBox 2007-08-07 00:44 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-28 12:39 <DIR> d-------- C:\WINDOWS\system32\appmgmt 2007-07-26 11:17 <DIR> d-------- C:\Arquivos de programas\MSN Messenger 2007-07-26 09:34 <DIR> d-------- C:\Downloads 2007-07-26 08:11 <DIR> d-------- C:\Arquivos de programas\a-squared Free (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-23 11:02 879832 --a------ C:\WINDOWS\system32\drivers\VetEFile.sys 2007-07-23 11:02 108360 --a------ C:\WINDOWS\system32\drivers\VetEBoot.sys 2007-07-12 12:16 --------- d-------- C:\Arquivos de programas\Windows Media Connect 2 2007-07-08 22:59 --------- d-------- C:\DOCUME~1\User\DADOSD~1\AdobeUM 2007-07-04 15:40 --------- d-------- C:\Arquivos de programas\ABSVD 2007-07-02 21:37 4608 --a------ C:\WINDOWS\system32\w95inf32.dll 2007-07-02 21:37 2272 --a------ C:\WINDOWS\system32\w95inf16.dll 2007-07-02 21:37 --------- d--h----- C:\Arquivos de programas\InstallShield Installation Information 2007-07-02 21:37 --------- d-------- C:\Arquivos de programas\ArcSoft 2007-07-02 21:30 --------- d-------- C:\DOCUME~1\User\DADOSD~1\ArcSoft 2007-06-26 23:39 --------- d-------- C:\Arquivos de programas\Apostilas Objetiva 2007-06-16 11:26 --------- d-------- C:\DOCUME~1\User\DADOSD~1\Real 2007-06-16 11:26 --------- d-------- C:\Arquivos de programas\Arquivos comuns\Real 2007-06-16 11:20 --------- d-------- C:\Arquivos de programas\Real 2007-06-10 22:53 --------- d-------- C:\Arquivos de programas\D'Accord Music Software 2007-06-09 14:44 73216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-06-03 23:15 74864 --a------ C:\WINDOWS\system32\VetRedir.dll 2007-06-03 23:15 115824 --a------ C:\WINDOWS\UnVet32.exe 2007-06-03 23:15 107632 --a------ C:\WINDOWS\AVShlExt.dll 2007-06-03 22:51 48846 --a------ C:\WINDOWS\system32\perfc016.dat 2007-06-03 22:51 344734 --a------ C:\WINDOWS\system32\perfh016.dat 2007-05-16 12:13 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll 2007-05-16 12:13 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll 2007-05-16 12:13 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-05-16 12:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-05-16 12:13 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll 2007-05-16 12:13 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll 2007-05-08 05:56 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CaAvTray"="C:\Program Files\CAVTray.exe" [2007-06-03 23:15] "CAVRID"="C:\Program Files\CAVRID.exe" [2007-06-03 23:15] "Emurayden PSX Emulator"="" [] "NWEReboot"="" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45] "updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Utility Tray.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer] Mixer.exe /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool] C:\Arquivos de programas\VIA\RAID\raid_t [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VModes] VModes 1024 768 32 60 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer] VTTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp] VTtrayp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsTranslator] C:\ARQUIV~1\MICROP~1\DELTAT~1.0\DWinTrsl.exe R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys R0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys R0 uagp35;Filtro Microsoft AGPv3.5;C:\WINDOWS\system32\DRIVERS\uagp35.sys R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys R3 cmpci;C-Media PCI Audio Driver (WDM);C:\WINDOWS\system32\drivers\cmaudio.sys R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys R3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys S3 cmuda;C-Media WDM Audio Interface;C:\WINDOWS\system32\drivers\cmuda.sys S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys S3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys S3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys S3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-08 11:34:14 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden registry entries ... [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] "AppData"="C:\Documents and Settings\Default User\Dados de aplicativos" "Cookies"="C:\Documents and Settings\Default User\Cookies" "Desktop"="C:\Documents and Settings\Default User\Desktop" "Favorites"="C:\Documents and Settings\Default User\Favoritos" "NetHood"="C:\Documents and Settings\Default User\Ambiente de rede" "Personal"="C:\Documents and Settings\Default User\Meus documentos" "PrintHood"="C:\Documents and Settings\Default User\Ambiente de impress\xe3o" "Recent"="C:\Documents and Settings\Default User\Recent" "SendTo"="C:\Documents and Settings\Default User\SendTo" "Start Menu"="C:\Documents and Settings\Default User\Menu Iniciar" "Templates"="C:\Documents and Settings\Default User\Modelos" "Programs"="C:\Documents and Settings\Default User\Menu Iniciar\Programas" "Startup"="C:\Documents and Settings\Default User\Menu Iniciar\Programas\Inicializar" "Local Settings"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais" "Local AppData"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos" "Cache"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Temporary Internet Files" "History"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Hist\xf3rico" "My Pictures"="" "My Music"="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SmallIcons] "SmallIcons"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders] "Recent"=str(2):"USERPROFILE\Recent" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "User Agent"="Mozilla/4.0 (compatible; MSIE 6.0; Win32)" "MigrateProxy"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones] "DisplayName"="Meu computador" "Description"="Seu computador" "1001"=dword:00000000 "1407"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1] "DisplayName"="Intranet local" "Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o." "Flags"=dword:000000db "1407"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2] "DisplayName"="Sites confi\xe1veis" "Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados." "1001"=dword:00000000 "1206"=dword:00000000 "1406"=dword:00000000 "1407"=dword:00000000 "1607"=dword:00000000 "1800"=dword:00000000 "1804"=dword:00000000 "1805"=dword:00000000 "1806"=dword:00000000 "1807"=dword:00000000 "1A00"=dword:00000000 "1A05"=dword:00000000 "1A10"=dword:00000000 "1E05"=dword:00030000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3] "Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas." "1407"=dword:00000000 "1601"=dword:00000001 "1607"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4] "DisplayName"="Sites restritos" "Description"="Esta zona cont\xe9m sites da Web que podem danificar o computador ou seus dados." "1604"=dword:00000001 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] "DisplayName"="Meu computador" "Description"="Seu computador" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] "Description"="Esta zona cont\xe9m todos os sites da Web que pertencem \xe0 intranet da sua organiza\xe7\xe3o." "CurrentLevel"=dword:00010500 "Flags"=dword:000000db [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] "DisplayName"="Sites confi\xe1veis" "Description"="Esta zona cont\xe9m os sites da Web que n\xe3o danificar\xe3o o computador nem seus dados." "CurrentLevel"=dword:00010000 "1001"=dword:00000000 "1004"=dword:00000001 "1201"=dword:00000001 "1206"=dword:00000000 "1406"=dword:00000000 "1407"=dword:00000000 "1607"=dword:00000000 "1800"=dword:00000000 "1804"=dword:00000000 "1805"=dword:00000000 "1806"=dword:00000000 "1809"=dword:00000003 "1A00"=dword:00000000 "1A04"=dword:00000000 "1A05"=dword:00000000 "1C00"=dword:00030000 "1E05"=dword:00030000 "2102"=dword:00000000 "2200"=dword:00000000 "2201"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] "Description"="Esta zona cont\xe9m todos os sites da Web que n\xe3o foram colocados em outras zonas." "CurrentLevel"=dword:00011000 "1407"=dword:00000000 "1601"=dword:00000001 "1607"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] "CurrentLevel"=dword:00012000 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\LastTheme] "Wallpaper"="" [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\WINDOWS\system32\regsvr32.exe"="Servidor de registro Microsoft©" "C:\WINDOWS\system32\RUNDLL32.exe"="Executa uma DLL como um aplicativo" "C:\WINDOWS\system32\mshta.exe"="Microsoft ® HTML Application host" "C:\WINDOWS\system32\fixmapi.exe"="FIXMAPI 1.0 MAPI Repair Tool" "C:\WINDOWS\system32\odbcconf.exe"="Microsoft Data Access - ODBC Driver Configuration Program" "C:\WINDOWS\system32\mstinit.exe"="Instala\xe7\xe3o do agendador de tarefas" "C:\Arquivos de programas\Outlook Express\setup50.exe"="Biblioteca de instala\xe7\xe3o do Outlook Express" "C:\WINDOWS\system32\logagent.exe"="Windows Media Player Logagent" "C:\WINDOWS\INF\unregmp2.exe"="Utilit\xe1rio de Instala\xe7\xe3o do Microsoft Windows Media Player" "C:\WINDOWS\system32\Cmd.exe"="Processador de comandos do Windows" "C:\WINDOWS\pchealth\uploadlb\binaries\uploadm.exe"="Gerenciador de carregamento do PCHealth" "C:\Arquivos de programas\Windows Media Player\migrate.exe"="MLS Migrate DLL" "C:\WINDOWS\system32\grpconv.exe"="Conversor do Grupo de Programas do Windows" [HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace] "LocalBase"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.XML" "DTDFile"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNS.DTD" "LocalDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSD.XML" "RemoteDelta"="C:\Documents and Settings\Default User\Configura\xe7\x00f5es locais\Dados de aplicativos\Microsoft\Windows Media\9.0\WMSDKNSR.XML" [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] "load"="" scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-08 11:37:05 C:\ComboFix2.txt ... 2007-08-07 00:56 --- E O F --- continua dando o erro! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 8, 2007 Opa G_santos, Vá em Iniciar -> Executar -> digite regedit > dê Ok. Selecione a aba Editar -> Localizar -> coloque winlogin.cmd -> Localizar próxima. Caso o sistema encontre alguma entrada, delete-a. Repita a operação, de modo que todas as entradas que contenham winlogin.cmd sejam eliminadas. Saia do Editor do Registro. Reinicie a máquina e verifique se o erro persiste. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
G_santos 0 Denunciar post Postado Agosto 10, 2007 Ola Jgarcia Problema sanado , muito obrigado pela sua ajuda .Espero sempre contar com a turma do ImastersAbraços! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 10, 2007 Opa G_santos, Fico feliz por saber que o problema foi resolvido. :thumbsup: Para finalizar siga os procedimentos contidos no Post #6. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Setembro 14, 2007 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites