Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

mendingo

[Resolvido!]Trojans

Recommended Posts

Fui infectado pelos vírus abaixo, detectados pelo avast como trojans e postos em quarentena.

 

o Avast identificou win32:theef-H [trj], todos são plug ins directx .

O scanner on line da Kaspersky o detectou como : Trojan-Downloader.WMA.Wimad.l

(não consigo encontrar o logfile)

Baixei o Kasperski e ao abrí-lo deu arquivo corrompido, nao funciona. Bit defender nao é compativel com vista.

 

Tb fiz varredura com combo fix 2 vezes.

Vi q 1 arquivo foi removido "qmrg0". Ao reiniciar do meu sistema ( windows vista) não encontrei o log c:\combofix.txt.

Apareceu a pasta zip no meu desktop com nome Catch Me.

Tem dois arquivos qmgr0 e qmgr1. Abri em notepad e não dava pra etender nada.

Fiz varredura com bankerfix e ao concluir disse que nao encontrou nada.

Mesmo assim nao consigo encontrar o logfile através de c:\linhadefensiva\.

Tb agora, aparece um novo ícone do explorer no desk top e não é shortcut sem ter configurado.

 

Segue o texto de qmgr0.

 

õj+| Cü¤Ì›v÷+È@™JŸ:®½‰NêGD_ ©½ºD˜QÄ{¶ÀzÎ GD_ ©½ºD˜QÄ{¶ÀzÎGD_ ©½ºD˜QÄ{¶ÀzÎ GD_ ©½ºD˜QÄ{¶ÀzÎ÷+È@™JŸ:®½‰Nêõj+| Cü¤Ì›vt t a c h m e n t T a s k : e 9 2 2 0 d 7 d a 0 6 5 4 e 5 e 8 4 c 4 2 9 e d 0 b 4 7 b 5 9 c S - 1 - 5 - 2 0 @ x €` l ð @ \ ? ? ? ? 6ÚVwoQZC¬¬D¢HÿóM F C : \ P r o g r a m D a t a \ M i c r o s o f t \ e H o m e \ P a c k a g e s \ M C E S p o t l i g h t \ M C E S p o t l i g h t . c a b n h t t p : / / e p g . t v d o w n l o a d . m i c r o s o f t . c o m / p a c k a g e d e l i v e r y d a t a / M C E S p o t l i g h t / M C E S p o t l i g h t B R - 1 . 4 7 - 6 . 0 - A L L - 2 0 0 7 1 1 0 6 . c a b A C : \ P r o g r a m D a t a \ M i c r o s o f t \ e H o m e \ P a c k a g e s \ M C E S p o t l i g h t \ B I T 1 A 8 7 . t m p ,Þ ø C : \ 2 \ \ ? \ V o l u m e { 0 e b 5 d 3 c 1 - 6 a 7 4 - 1 1 d c - a a 2 6 - 8 0 6 e 6 f 6 e 6 9 6 3 } \ _Çeø € €Þcaº È 6ëNì+o$Dª`ÇnœN|2 ,Þ n h t t p : / / e p g . t v d o w n l o a d . m i c r o s o f t . c o m / p a c k a g e d e l i v e r y d a t a / M C E S p o t l i g h t / M C E S p o t l i g h t B R - 1 . 4 7 - 6 . 0 - A L L - 2 0 0 7 1 1 0 6 . c a b 6ëNì+o$Dª`ÇnœN|26ÚVwoQZC¬¬D¢HÿóM X u oÃåuCÈ_˜uCÈ_˜uCÈ _˜uCÈ_1õ-ŠÈ §v ‰Z˜®ÞÛO…ŸmOÌ¢ŸºGD_ ©½ºD˜QÄ{¶ÀzÎGD_ ©½ºD˜QÄ{¶ÀzÎ GD_ ©½ºD˜QÄ{¶ÀzÎ÷+È@™JŸ:®½‰Nêõj+| Cü¤Ì›võj+| Cü¤Ì›vÛO…ŸmOÌ¢ŸºGD_ ©½ºD˜QÄ{¶ÀzÎGD_ ©½ºD˜QÄ{¶ÀzÎ GD_ ©½ºD˜QÄ{¶ÀzÎ÷+È@™JŸ:®½‰Nêõj+| Cü¤Ì›v½‰Nêõj+| Cü¤Ì›v®½‰Nêõj+| Cü¤Ì›v \ ? ? ? ? 6ÚVwoQZC¬¬D¢HÿóM s C : \ W i n d o w s \ S o f t w a r e D i s t r i b u t i o n \ D o w n l o a d \ 2 5 3 f 9 7 6 2 7 b 2 9 6 7 f 0 9 c 0 a f 9 0 8 1 6 7 c 6 2 5 5 \ 7 d 0 4 a 2 1 a a b 1 f 2 e 6 a f 6 d 3 a 5 6 4 1 8 c 6 0 f e 4 f c 8 d c c e 8 h t t p : / / a u . d o w n l o a d . w i n d o w s u p d a t e . c o

 

 

Estou com problemas ? O q fazer?

 

Segue logfile hijack , obrigado.

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 17:19:51, on 20/01/2008

Platform: Unknown Windows (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16546)

 

Running processes:

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Program Files\Hp\QuickPlay\QPService.exe

C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\LimeWire\LimeWire.exe

C:\Windows\system32\sdclt.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe

C:\Users\Daniel Yogo\AppData\Local\Temp\Temp1_hijackthis.zip\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files\Scpad\scpsssh2.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\BR\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=101007 serial=DR12WEL-6341663-NKM lang=BP

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

1º passo

 

* Menu Iniciar / Executar e digite: (ou copie e cole)

 

combofix /u

*Essa operação irá desinstalar o ComboFix.

 

2º passo

 

:!: Desative seu antivirus, antispywares e firewall, para não causar conflitos.

 

Faça o download do ComboFix (by SUBs)

Salve-o na sua área de trabalho.

 

1. Feche todas as janelas e programas. Rode o ComboFix.

2. Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir o Fix.

3. É um pouco demorado, por favor seja paciente.

 

 

Não clique em nada e não aperte nenhuma tecla durante o exame, pois a ferramenta não funcionará corretamente.

Quando a ferramenta terminar de rodar, gerará um log. Cole o arquivo C:\ComboFix.txt na sua próxima resposta, juntamente com um novo log do HijackThis.


  • Importante:
     
     
  • É preciso estar logado no sistema com privilégios de administrador.
     
  • Mantenha seu antivirus, antispywares e firewall desativados durante os procedimentos com o ComboFix. Torne a ativá-los quando terminar tudo.
     
  • Caso você já tenha usado o Combofix anteriormente, então delete-o e baixe-o novamente.
    Nesse caso, apague também as pastas C:\Combofix e C:\Qoobox, caso as encontre.
     
  • Não rode o ComboFix mais do que uma vez. Isso irá sobreescrever o log e dificultará a remoção do(s) malware(s)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desinstalei o combofix. Mas não consigo deletar a pasta c:\combofix. Aparece uma janela dizendo que a pasta está sendo usada por outro programa e para isto devo fechar o programa. Fiz control alt del para ver o q está rodando e nao tem nada rodando. O q fazer?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe e execute o ComboFix em Modo Seguro, que ele sobrescreverá os arquivos.

 

:!: Para iniciar em Modo Seguro, pressione intermitentemente F8 durante a inicialização, no menu que aparecer escolha através da seta de navegação, Modo Seguro)

Compartilhar este post


Link para o post
Compartilhar em outros sites
Baixe e execute o ComboFix em Modo Seguro, que ele sobrescreverá os arquivos.

 

:!: Para iniciar em Modo Seguro, pressione intermitentemente F8 durante a inicialização, no menu que aparecer escolha através da seta de navegação, Modo Seguro)

 

 

 

Caiu a luz enquanto o Combofix preparava o LOG.

Liguei o computador e só apareceu a flecha do mouse e fundo preto.

Desliguei e liguei , entrei no safemode.

Apaguei o Combofix novamente e fiz download do combofix . Executei no safemode. Ao terminar abriu no modo normal procurei por c:\combofix.txt e o windows não encontra.

O mesmo no safe mode.

No safemode vejo as duas pastas combofix e qoobox.

O logfile deve estar com outro nome. Tem uma pasta Creg e parece um logfile.

 

Começa assim,

 

REGEDIT4

 

[-HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR"=dword:00000000

"CreateFirstRunRp"=dword:00000001

 

; 2007-10-20

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5DF6AFEE-2291-4041-9A74-354624861746}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5fb8c5d4-929f-4870-89e2-7e3ee26ee701}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F776B2A-72DF-40C1-BD69-EDB642A706D7}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5E87A05-F463-4841-B19E-DD3EC3862368}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE12D60D-AD9A-4095-B839-3BE6862679FD}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9751A53-4494-4d7c-9732-AE3058D8145F}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BCBD80C9-6AD7-48ed-8DF1-6963414B3649}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AC7107A-938F-4347-864C-C51E49EC586E}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5085333B-FD15-4754-A571-852F7077C5F2}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3464F94-A3FE-4675-8D96-49B008E12CD3}]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar]

"{3723900A-B26F-40EC-B606-B7B37132B83F}"=-

"{A037112F-183D-4E98-8CEA-1A0D93BA9F48}"=-

"{D94D49D7-31D6-42E1-A5FE-438C7BFD6498}"=-

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{C7CD9E83-3BF6-47F8-B2E2-B114C96C1888}"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"asvdnmo"=-

"bgntlvo"=-

"bklgvsf"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{1D098345-9012-8750-8910-9128098134D1}"=-

"{8960356A-458E-DE24-BD50-268F589A56A8}"=-

"{8A1247C1-53DA-FF43-ABD3-345F323A48D8}"=-

"{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}"=-

"{C5E87A05-F463-4841-B19E-DD3EC3862368}"=-

"{C7D81718-1314-5200-2597-58790101807C}"=-

"{C859245F-345D-BC13-AC4F-145D47DA34FC}"=-

"{E34345F1-DACF-3452-CB7D-4620F34A153E}"=-

"{EE12D60D-AD9A-4095-B839-3BE6862679FD}"=-

"{E159854F-6971-3456-6941-10235412974E}"=-

"{FCE1C203-FF2B-4EC1-9983-E2900D29BBD8}"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ClientMan1"=-

"ntuser"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"WSockDrv32"=-

"NAVMon32"=-

"RegSrv64D"=-

"SHAProc"=-

"PTSShell"=-

"LotusHlp"=-

"WINSvr32"=-

"troy44"=-

"PromoReg"=-

"msbb"=-

"KeenValue"=-

"ContinueInstall"=-

"autoload"=-

"ntuser"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\Software\Microsoft\windows\currentversion\runservices]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

 

; ----------------------------------------------------------------------------

 

 

[-HKEY_LOCAL_MACHINE\SOFTWARE\TSoft]

[-HKEY_CLASSES_ROOT\CLSID\{5DF6AFEE-2291-4041-9A74-354624861746}]

[-HKEY_CLASSES_ROOT\MyWayToolBar.NetscapeShutdown.1]

[-HKEY_CLASSES_ROOT\MyWayToolBar.NetscapeStartup.1]

[-HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin.1]

[-HKEY_CLASSES_ROOT\URLLauncher.URLLauncherControl.1]

[-HKEY_CLASSES_ROOT\CLSID\{000000DA-0786-4633-87C6-1AA7A4429EF1}]

[-HKEY_CLASSES_ROOT\CLSID\{00000EF1-34E3-4633-87C6-1AA7A44296DA}]

[-HKEY_CLASSES_ROOT\CLSID\{014DA6CD-189F-421a-88CD-07CFE51CFF10}]

[-HKEY_CLASSES_ROOT\CLSID\{0494D0D5-F8E0-41ad-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\CLSID\{0494D0D7-F8E0-41ad-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\CLSID\{0494D0DB-F8E0-41ad-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\CLSID\{34EF5B1C-52CB-400b-8B7C-F787018B3826}]

[-HKEY_CLASSES_ROOT\CLSID\{DFAA31C8-A356-4313-9D95-5EDAB46C5070}]

[-HKEY_CLASSES_ROOT\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\Interface\{E9D8697E-BEA9-4170-84F3-509AD2A11951}]

[-HKEY_CLASSES_ROOT\Interface\{F1E1543F-62F6-4B17-8847-68C4442BB767}]

[-HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}]

[-HKEY_CLASSES_ROOT\TypeLib\{3CD9D85E-1FF2-4BF7-A113-6669B8D1E676}]

[-HKEY_CLASSES_ROOT\TypeLib\{E54DD685-E190-437E-9650-B25D4D14152C}]

[-HKEY_CLASSES_ROOT\ensfolr.bqto]

[-HKEY_CLASSES_ROOT\MyWayToolBar.NetscapeShutdown]

[-HKEY_CLASSES_ROOT\MyWayToolBar.NetscapeStartup]

[-HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin]

[-HKEY_CLASSES_ROOT\URLLauncher.URLLauncherControl]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KeenValue]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msbb]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\nCASE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\KeenValue]

[-HKEY_LOCAL_MACHINE\SOFTWARE\MSView]

[-HKEY_LOCAL_MACHINE\SOFTWARE\VGroup]

[-HKEY_CLASSES_ROOT\CLSID\{3C7AE669-931D-4E0B-B

 

O q fazer?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue Combofix + Hijack

 

ComboFix 08-01-20.1 - 2008-01-22 14:44:03.4 - NTFSx86 MINIMAL

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.674 [GMT -2:00]

Running from: C:\Users\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

Unable to gain System Privileges

 

 

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 14:54, on 2008-01-22

Platform: Unknown Windows (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16546)

 

Running processes:

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\Hp\QuickPlay\QPService.exe

C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\NOTEPAD.EXE

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe

C:\Users\Daniel Yogo\AppData\Local\Temp\Temp1_hijackthis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files\Scpad\scpsssh2.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\BR\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=101007 serial=DR12WEL-6341663-NKM lang=BP

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desculpe Mendingo, mas o log está incompleto. <_<

 

Desinstale o ComboFix e volte a executá-lo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aleluia… Obrigado Lucas pela paciência. Espero que ainda dê pra identificar o malware.

 

 

ComboFix 08-01-20.1 - Daniel Yogo 2008-01-23 12:16:56.4 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.352 [GMT -2:00]

Running from: c:\Users\Daniel Yogo\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))

.

 

2008-01-22 10:12 . 2008-01-22 10:12 <DIR> d-------- C:\Program Files\Google

2008-01-22 09:53 . 2008-01-22 09:53 13,413,048 --a------ C:\Program Files\Google_Earth.exe

2008-01-21 14:16 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe

2008-01-21 07:38 . 2008-01-21 07:38 <DIR> d-------- C:\kav

2008-01-20 22:37 . 2008-01-20 22:37 <DIR> d-------- C:\Windows\System32\Kaspersky Lab

2008-01-20 22:04 . 2008-01-20 22:04 <DIR> d-------- C:\Windows\BDOSCAN8

2008-01-20 21:49 . 2008-01-20 21:50 <DIR> d-------- C:\LinhaDefensiva

2008-01-02 21:09 . 2008-01-02 21:09 <DIR> d-------- C:\Program Files\Google Video

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-23 10:52 13,307 ----a-w C:\Users\Daniel Yogo\AppData\Roaming\nvModes.dat

2008-01-20 00:54 --------- d-----w C:\Users\Daniel Yogo\AppData\Roaming\Skype

2008-01-19 18:47 --------- d-----w C:\Users\Daniel Yogo\AppData\Roaming\LimeWire

2007-12-09 00:05 --------- d-----w C:\Program Files\LimeWire

2007-12-08 20:24 3,381,280 ----a-w C:\Program Files\LimeWireWin.exe

2007-12-08 20:24 3,381,280 ----a-w C:\Program Files\LimeWireWin - Copy.exe

2007-11-26 13:10 11,156,059 ----a-w C:\Program Files\setupecserverdde.exe

2007-11-21 21:47 92,448 ----a-w C:\Users\Daniel Yogo\AppData\Roaming\GDIPFONTCACHEV1.DAT

2007-10-25 12:26 53,248 ----a-w C:\Windows\bdoscandel.exe

2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini

2007-10-11 14:19 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

2007-10-11 14:19 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

2007-10-11 14:19 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

2007-10-07 18:27 22 --sha-w C:\Windows\SMINST\HPCD.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 10:36 201728]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 10:34 1004136]

"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 03:28 36352]

"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 21:12 317128]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 01:36 827392]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-04-20 06:44 77824]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-02-28 16:26 7770112]

"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 08:06 79224]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 04:06 40048]

"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 16:38 159744]

"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-02-28 16:26 90191]

"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 18:18 472776]

"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-03-28 22:45 176128]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-02-28 16:26 81920]

"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 04:11 49152]

"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 16:54 50696]

"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\BR\Programs\Registration.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]

"{A3717295-941D-416F-9384-ED1736729F1C}"= C:\Program Files\Scpad\scpLIB.dll [2007-03-27 02:29 128512]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"CompIBBrd"= {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll [2007-03-27 02:29 128512]

 

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-09-06 08:02]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-05 07:39]

R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 06:50]

S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 13:43]

S4 scpVista;scpVista;C:\Program Files\Scpad\scpVista.exe [2006-12-18 16:02]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

 

.

Contents of the 'Scheduled Tasks' folder

"2008-01-23 13:53:14 C:\Windows\Tasks\User_Feed_Synchronization-{A7239A1C-6C60-4DD2-BB44-5ED863715D5C}.job"

- C:\Windows\system32\msfeedssync.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-23 12:19:43

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-01-23 12:20:48

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 12:24, on 2008-01-23

Platform: Unknown Windows (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16546)

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Program Files\Hp\QuickPlay\QPService.exe

C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Windows\Explorer.exe

C:\Users\Daniel Yogo\AppData\Local\Temp\Temp2_hijackthis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files\Scpad\scpsssh2.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\BR\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=101007 serial=DR12WEL-6341663-NKM lang=BP

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites
Os logs estão limpos :!:

 

Algum problema ainda ?

 

 

Lucas, obrigado velho. Veja , eu resolvi fazer a varredura tudo de novo. E veja que finalmente o combofix deletou um malware. Seguem Logs e perguntas abaixo. Abs.

 

ComboFix 08-01-23.2 - Daniel Yogo 2008-01-24 9:31:46.5 - NTFSx86 NETWORK

Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.619 [GMT -2:00]

Running from: C:\Users\Daniel Yogo\Desktop\ComboFix.exe

.

 

Unable to gain System Privileges

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Windows\system32\koos.exe

C:\Windows\system32\kprof

C:\Windows\system32\poof

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

.

-------\LEGACY_IDSVIX86

 

 

((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))

.

 

2008-01-24 09:30 . 2000-08-31 08:00 51,200 --a------ C:\Windows\Nircmd.exe

2008-01-22 10:12 . 2008-01-22 10:12 <DIR> d-------- C:\Program Files\Google

2008-01-22 09:53 . 2008-01-22 09:53 13,413,048 --a------ C:\Program Files\Google_Earth.exe

2008-01-21 07:38 . 2008-01-21 07:38 <DIR> d-------- C:\kav

2008-01-20 22:37 . 2008-01-20 22:37 <DIR> d-------- C:\Windows\System32\Kaspersky Lab

2008-01-20 22:04 . 2008-01-20 22:04 <DIR> d-------- C:\Windows\BDOSCAN8

2008-01-20 21:49 . 2008-01-20 21:50 <DIR> d-------- C:\LinhaDefensiva

2008-01-02 21:09 . 2008-01-02 21:09 <DIR> d-------- C:\Program Files\Google Video

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2007-12-09 00:05 --------- d-----w C:\Program Files\LimeWire

2007-12-08 20:24 3,381,280 ----a-w C:\Program Files\LimeWireWin.exe

2007-12-08 20:24 3,381,280 ----a-w C:\Program Files\LimeWireWin - Copy.exe

2007-11-26 13:10 11,156,059 ----a-w C:\Program Files\setupecserverdde.exe

2007-10-25 12:26 53,248 ----a-w C:\Windows\bdoscandel.exe

2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini

2007-10-11 14:19 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

2007-10-11 14:19 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

2007-10-11 14:19 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

2007-10-07 18:27 22 --sha-w C:\Windows\SMINST\HPCD.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

 

C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]

"{A3717295-941D-416F-9384-ED1736729F1C}"= C:\Program Files\Scpad\scpLIB.dll [2007-03-27 02:29 128512]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

"CompIBBrd"= {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll [2007-03-27 02:29 128512]

 

R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-09-06 08:02]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-05 07:39]

R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 06:50]

S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 13:43]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

 

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-24 09:38:05

Windows 6.0.6000 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 09:42, on 2008-01-25

Platform: Unknown Windows (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16546)

 

Running processes:

C:\Windows\Explorer.EXE

C:\Users\Daniel Yogo\AppData\Local\Temp\Temp2_hijackthis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files\Scpad\scpsssh2.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe

O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe

O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

 

1) A pequena área de arraste do notebook , (onde se arrasta o dedo para movimentar a flecha do mouse) possui uma linha vertical desenhada do lado direito que ao arrastar o dedo de baixo para cima ou de cima para baixo funciona como scroll. Esta funçao deixou de funcionar logo após esta varredura do combofix? Testei todos os outros comandos e tudo funciona. O q fazer?

 

 

2) Se apago todos cookies, arquivos temporários, add-ons 1 vez por semana ainda há necessidade de usar Cleaner?

 

3) Devo apagar tudo na lixeira?

 

4) Devo trocar todas minhas senhas?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Mendingo,

 

Os logs estão limpos. ^_^

 

1) A pequena área de arraste do notebook , (onde se arrasta o dedo para movimentar a flecha do mouse) possui uma linha vertical desenhada do lado direito que ao arrastar o dedo de baixo para cima ou de cima para baixo funciona como scroll. Esta funçao deixou de funcionar logo após esta varredura do combofix? Testei todos os outros comandos e tudo funciona. O q fazer?

 

Pelo log do ComboFix, a ferramenta não removeu nenhum arquivo legítimo. Experimente configurar o Touchpad com os drivers da Synaptics:

http://www.synaptics.com/support/index.cfm

 

2) Se apago todos cookies, arquivos temporários, add-ons 1 vez por semana ainda há necessidade de usar Cleaner?

 

3) Devo apagar tudo na lixeira?

 

Na minha opinião, arquivos temporários e inúteis devem ser removidos/limpados diariamente. O CCleaner já automatiza para o usuário.

 

4) Devo trocar todas minhas senhas?

Você estava infectado por um rootkit. Não impede/garante que esse malware tenha dado alguma liberdade para trojans ladrão de senhas. Portanto, trocar as senhas é uma medida importante e deve ser feita com urgência.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado pelas dicas.

Bem, tentei desinstalar o combofix conforme o comando que você postou acima. Mas não está funcionando.

O combofix inicia varredura normalmente e nada de desinstalar.

É necessário desinstalar? COmo desinstalar entao?

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bem, tentei desinstalar o combofix conforme o comando que você postou acima. Mas não está funcionando.

O combofix inicia varredura normalmente e nada de desinstalar.

É necessário desinstalar? Como desinstalar entao?

 

Olá Mendingo,

 

Desculpe a demora. Estive meio ocupado durante a semana com estudos e estágio.

 

Digite no executar ComboFix /u e escolha a opção 2.

 

Baixe o CCleaner e faça uma varredura no Registro do Windows:

http://ccleaner.com

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.