brou-nf 0 Denunciar post Postado Março 4, 2008 Por favor me ajudem Analizem o log que segui abaixo Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:52:48, on 3/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\vsnpstd.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\McAfee\Common Framework\McTray.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\WINDOWS\system32\rundll32.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ig.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [242ebde5] rundll32.exe "C:\WINDOWS\system32\lchtjsoj.dll",b O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Ubisoft register.lnk = C:\Arquivos de programas\UBISOFT\Register\schedule.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.directradios.com.br/nsvplayx_vp6_aac.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E561684E-57E6-4E8C-9600-5567FFF72219}: NameServer = 200.149.55.140 200.165.132.147 O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe -- End of file - 6749 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 4, 2008 Bom Dia brou-nf! >@< Faça o download do VundoFix. >@< Salve-o no Desktop! >@< Execute o VundoFix.exe >@< Quando o VundoFix abrir,novamente, clique em Scan for Vundo. >@< Quando ele terminar, clique em Remove Vundo. >@< Você receberá um prompt perguntando se quer remover os arquivos. Confirme! >@< Sua área de trabalho vai desaparecer! >@< Surgirá um aviso dizendo que seu computador deve ser desligado. >@< Clique em OK e depois,ligue o computador novamente! >@< É possível que o VundoFix encontre um arquivo, mas não consiga removê-lo. Se isso acontecer, a ferramenta rodará ao reiniciar. >@< Quando o VundoFix aparecer, clique no botão Scan for Vundo para repetir o processo. >@< Quando o VundoFix não encontrar mais nenhum arquivo,que não consiga remover,poste o seu relatório ( Log ) que se encontra em C:\Vundofix.txt >@< Poste,também,um nôvo Log do HijackThis. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
brou-nf 0 Denunciar post Postado Março 5, 2008 bom ai vai o meu log do VUNDOFIX Beginning removal... Attempting to delete C:\WINDOWS\system32\lchtjsoj.dll C:\WINDOWS\system32\lchtjsoj.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\urqrsrs.dll C:\WINDOWS\system32\urqrsrs.dll Could not be deleted. Performing Repairs to the registry. Done! VundoFix V6.7.10 Checking Java version... Sun Java not detected Scan started at 01:05:46 4/3/2008 Listing files found while scanning.... C:\WINDOWS\system32\urqrsrs.dll Beginning removal... Attempting to delete C:\WINDOWS\system32\urqrsrs.dll C:\WINDOWS\system32\urqrsrs.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal... Attempting to delete C:\WINDOWS\system32\urqrsrs.dll C:\WINDOWS\system32\urqrsrs.dll Has been deleted! Performing Repairs to the registry. Done! E TANMBEM O NOVOLOG DO HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:59:10, on 5/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\vsnpstd.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\McAfee\Common Framework\McTray.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ig.com.br R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5A0C9DD7-9F39-447A-9D79-E1C0C5FA55D2} - C:\WINDOWS\system32\mljjh.dll (file missing) O2 - BHO: (no name) - {635A6000-4CCC-46BD-92CA-A4FE00E1D102} - (no file) O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Arquivos de programas\McAfee\VirusScan Enterprise\scriptcl.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: {7a1d8b65-9f90-31c8-7f54-23706e43b24f} - {f42b34e6-0732-45f7-8c13-09f956b8d1a7} - C:\WINDOWS\system32\ykjkstvv.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [242ebde5] rundll32.exe "C:\WINDOWS\system32\lchtjsoj.dll",b O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.directradios.com.br/nsvplayx_vp6_aac.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E561684E-57E6-4E8C-9600-5567FFF72219}: NameServer = 200.149.55.140 200.165.132.147 O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe -- End of file - 7522 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 5, 2008 Bom Dia brou-nf! >@< Faça o download do ComboFix. >@< Baixe-o para o Desktop! Mas,não rode-o ainda. _________________________ >@< Reinicie o computador,em Modo de Segurança. >@< Abra o HijackThis,e clique em: Do a system scan only >@< Marque as entradas,logo abaixo,e clique em Fix checked. O2 - BHO: (no name) - {5A0C9DD7-9F39-447A-9D79-E1C0C5FA55D2} - C:\WINDOWS\system32\mljjh.dll (file missing)O2 - BHO: (no name) - {635A6000-4CCC-46BD-92CA-A4FE00E1D102} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: {7a1d8b65-9f90-31c8-7f54-23706e43b24f} - {f42b34e6-0732-45f7-8c13-09f956b8d1a7} - C:\WINDOWS\system32\ykjkstvv.dll (file missing) O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [242ebde5] rundll32.exe "C:\WINDOWS\system32\lchtjsoj.dll",b >@< Ainda em Modo Seguro,execute o ComboFix.exe <!> >@< Abrir-se-à,a janela Auto Scan. Aguarde! >@< Digite a opção,para continuar,e aperte Enter. >@< Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! >@< Terminando,reinicie em Modo Normal. ________________________ >@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
brou-nf 0 Denunciar post Postado Março 5, 2008 AI AMIGO MUITO OBRIGADO POR ESTA ME AJUDANDO BOM AI VAI O LOG DO ComboFix ComboFix 08-03-05.1 - Higo 2008-03-05 15:55:46.4 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.805 [GMT -3:00] Executando de: C:\Documents and Settings\Higo\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((( Ficheiros criados de 2008-02-05 to 2008-03-05 )))))))))))))))))))))))))))))))) . 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\Documents and Settings\Higo\Configuraþ§es locais 2008-03-04 23:39 . 2008-03-04 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\POP3Profiles 2008-03-04 22:38 . 2008-03-04 22:38 <DIR> d-------- C:\Arquivos de programas\Ubisoft 2008-03-04 00:33 . 2008-03-04 01:32 <DIR> d-------- C:\VundoFix Backups 2008-03-01 10:22 . 2008-03-01 10:22 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-03-01 00:46 . 2008-03-01 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-02-29 10:05 . 2008-03-05 15:29 <DIR> d-------- C:\QUARANTINE 2008-02-29 10:05 . 2007-02-09 14:34 420,816 --a------ C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe 2008-02-28 18:19 . 2008-02-28 18:18 737,280 --a------ C:\WINDOWS\iun6002.exe 2008-02-28 14:32 . 2008-02-28 14:37 <DIR> d-a------ C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2008-02-28 10:38 . 2008-02-28 10:38 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\CyberLink 2008-02-28 10:37 . 2008-02-28 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\CyberLink 2008-02-25 01:08 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2008-02-25 01:08 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys 2008-02-25 01:07 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2008-02-25 01:07 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2008-02-20 00:36 . 2008-02-20 00:36 <DIR> d--h----- C:\WINDOWS\PIF 2008-02-13 00:02 . 2008-02-03 18:17 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys 2008-02-12 23:18 . 2008-02-12 23:18 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\AdobeUM 2008-02-12 21:42 . 2008-02-12 21:42 664,064 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2008-02-12 21:42 . 2008-02-12 21:42 96,256 --a------ C:\WINDOWS\system32\drivers\sptd7309.sys 2008-02-12 21:00 . 2008-02-12 21:00 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-02-12 19:16 . 2003-10-27 13:06 140,488 --a------ C:\WINDOWS\system32\comdlg32.ocx 2008-02-12 19:16 . 2003-10-27 13:06 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL 2008-02-12 19:16 . 2003-10-27 13:06 69,632 --a------ C:\WINDOWS\system32\xmltok.dll 2008-02-12 19:16 . 2003-10-27 13:06 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll 2008-02-12 19:16 . 2003-10-27 13:06 35,840 --a------ C:\WINDOWS\system32\comdlg32.oca 2008-02-12 19:16 . 2003-10-27 13:06 29,184 --a------ C:\WINDOWS\system32\MSINET.oca 2008-02-12 19:16 . 2003-10-27 13:06 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe 2008-02-12 19:16 . 2003-10-27 13:06 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll 2008-02-12 18:44 . 2001-08-17 21:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2008-02-12 18:44 . 2001-08-17 21:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys 2008-02-12 18:43 . 2008-02-12 18:43 <DIR> d-------- C:\Arquivos de programas\USB Game Controller 2008-02-10 09:35 . 2008-02-10 09:35 <DIR> d-------- C:\Arquivos de programas\Elaborate Bytes 2008-02-10 08:01 . 2008-02-10 08:01 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\fltk.org . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-05 02:21 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-03-04 04:47 --------- d-----w C:\Arquivos de programas\HIGO PRG 2008-02-28 13:32 --------- d-----w C:\Arquivos de programas\CyberLink 2008-02-28 13:30 505,392 ----a-w C:\WINDOWS\system32\msvcp71.dll 2008-02-25 03:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink 2008-02-13 20:10 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f42b34e6-0732-45f7-8c13-09f956b8d1a7}] C:\WINDOWS\system32\ykjkstvv.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-28 18:06 68856] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648] "SecurDisc"="C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-02-12 11:23 1620480] "InCD"="C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-02-12 11:19 1050112] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 01:17 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 01:13 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 01:17 118784] "SkyTel"="SkyTel.EXE" [2006-05-16 07:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-11-14 06:21 16270848 C:\WINDOWS\RTHDCPL.EXE] "ShStatEXE"="C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 19:50 112216] "McAfeeUpdaterUI"="C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 10:27 136768] "snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 12:48 286720] "Emurayden PSX Emulator"="" [] "CloneDVDElbyDelay"="C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 03:33 45056] "RemoteControl"="C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 16:24 71216] "LanguageShortcut"="C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 16:21 54832] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoStartMenuPinnedList"= 0 (0x0) "NoStartMenuMFUprogramsList"= 0 (0x0) "NoUserNameInStartMenu"= 0 (0x0) "NoStartMenuSubFolders"= 0 (0x0) "NoCommonGroups"= 0 (0x0) "NoPrinterTabs"= 0 (0x0) "NoDeletePrinter"= 0 (0x0) "NoAddPrinter"= 0 (0x0) "NoPrinters"= 0 (0x0) "NoFavoritesMenu"= 0 (0x0) "NoToolbarCustomize"= 0 (0x0) "NoRecentDocsNetHood"= 0 (0x0) "NoChangeAnimation"= 0 (0x0) "NoChangeKeyboardNavigationIndicators"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\McAfee\\Common Framework\\FrameworkService.exe"= "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "C:\\WINDOWS\\system32\\dpvsetup.exe"= "C:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Nero Web\\SetupX.exe"= "C:\\Arquivos de programas\\CyberLink\\PowerDVD\\PowerDVD.exe"= S2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Arquivos de programas\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51] . Conteúdo da pasta 'Tarefas Agendadas' "2008-02-29 17:00:00 C:\WINDOWS\Tasks\At1.job" - C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe "2008-02-29 23:00:00 C:\WINDOWS\Tasks\At2.job" - C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe "2008-02-29 13:05:07 C:\WINDOWS\Tasks\At3.job" - C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-05 15:56:13 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}] "ImagePath"="\??\C:\Arquivos de programas\CyberLink\PowerDVD\000.fcl" . Tempo para conclusão: 2008-03-05 15:56:42 ComboFix-quarantined-files.txt 2008-03-05 18:56:35 ComboFix2.txt 2008-03-05 18:54:32 ComboFix3.txt 2008-03-05 18:38:37 ComboFix4.txt 2008-03-05 18:21:39 . 2008-02-13 03:38:08 --- E O F --- E TAMBEM O DO HijackThis ATUALIZADO Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:52:26, on 5/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Safe mode Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe C:\Arquivos de programas\Microsoft Office\OFFICE11\WINWORD.EXE C:\WINDOWS\system32\ctfmon.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ig.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: {7a1d8b65-9f90-31c8-7f54-23706e43b24f} - {f42b34e6-0732-45f7-8c13-09f956b8d1a7} - C:\WINDOWS\system32\ykjkstvv.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.directradios.com.br/nsvplayx_vp6_aac.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe -- End of file - 5597 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 5, 2008 Boa Noite brou-nf! Delete: C:\QooBox C:\ComboFix.txt << Log anterior do ComboFix. __________________ >@< Selecione e copie,todo o conteúdo que está na área do quote,para o Bloco de Notas. >@< Salve-o,no Desktop,com o nome: CFScript.txt File::C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe C:\WINDOWS\system32\ykjkstvv.dll C:\WINDOWS\Tasks\At1.job C:\WINDOWS\Tasks\At2.job C:\WINDOWS\Tasks\At3.job Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f42b34e6-0732-45f7-8c13-09f956b8d1a7}] Folder:: C:\QUARANTINE >@< Arraste,com o Mouse,o CFScript.txt para o ícone do ComboFix. >@< Veja a demonstraçaõ! >@< Com esse procedimento,o ComboFix irá executar e,reiniciará o computador,automaticamente! >@< Caso não reinicie,faça-o manualmente! >@< Durante a execução,não utilize o teclado ou Mouse! >@< Terminando,poste o relatório C:\ComboFix.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
brou-nf 0 Denunciar post Postado Março 6, 2008 BOA TARDE AI VAI O RELATORIO DO ComboFix.txt ComboFix 08-03-05.3 - Higo 2008-03-06 16:14:19.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.640 [GMT -3:00] Executando de: C:\Documents and Settings\Higo\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Higo\Desktop\CFScript.txt.txt * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe C:\WINDOWS\system32\ykjkstvv.dll C:\WINDOWS\Tasks\At1.job C:\WINDOWS\Tasks\At2.job C:\WINDOWS\Tasks\At3.job . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Higo\Dados de aplicativos\wunauclt.exe C:\QUARANTINE C:\WINDOWS\Tasks\At1.job C:\WINDOWS\Tasks\At2.job C:\WINDOWS\Tasks\At3.job . ((((((((((((((((((((((( Ficheiros criados de 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))) . 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-03-05 15:21 . 2008-03-05 15:21 <DIR> d-------- C:\Documents and Settings\Higo\Configuraþ§es locais 2008-03-04 23:39 . 2008-03-04 23:39 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\POP3Profiles 2008-03-04 22:38 . 2008-03-04 22:38 <DIR> d-------- C:\Arquivos de programas\Ubisoft 2008-03-04 00:33 . 2008-03-04 01:32 <DIR> d-------- C:\VundoFix Backups 2008-03-01 10:22 . 2008-03-01 10:22 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-03-01 00:46 . 2008-03-01 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-02-28 18:19 . 2008-02-28 18:18 737,280 --a------ C:\WINDOWS\iun6002.exe 2008-02-28 14:32 . 2008-02-28 14:37 <DIR> d-a------ C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2008-02-28 10:38 . 2008-02-28 10:38 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\CyberLink 2008-02-28 10:37 . 2008-02-28 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\CyberLink 2008-02-25 01:08 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2008-02-25 01:08 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys 2008-02-25 01:07 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2008-02-25 01:07 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2008-02-20 00:36 . 2008-02-20 00:36 <DIR> d--h----- C:\WINDOWS\PIF 2008-02-13 00:02 . 2008-02-03 18:17 223,128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys 2008-02-12 23:18 . 2008-02-12 23:18 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\AdobeUM 2008-02-12 21:42 . 2008-02-12 21:42 664,064 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2008-02-12 21:42 . 2008-02-12 21:42 96,256 --a------ C:\WINDOWS\system32\drivers\sptd7309.sys 2008-02-12 21:00 . 2008-02-12 21:00 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-02-12 19:16 . 2003-10-27 13:06 140,488 --a------ C:\WINDOWS\system32\comdlg32.ocx 2008-02-12 19:16 . 2003-10-27 13:06 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL 2008-02-12 19:16 . 2003-10-27 13:06 69,632 --a------ C:\WINDOWS\system32\xmltok.dll 2008-02-12 19:16 . 2003-10-27 13:06 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll 2008-02-12 19:16 . 2003-10-27 13:06 35,840 --a------ C:\WINDOWS\system32\comdlg32.oca 2008-02-12 19:16 . 2003-10-27 13:06 29,184 --a------ C:\WINDOWS\system32\MSINET.oca 2008-02-12 19:16 . 2003-10-27 13:06 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe 2008-02-12 19:16 . 2003-10-27 13:06 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll 2008-02-12 18:44 . 2001-08-17 21:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2008-02-12 18:44 . 2001-08-17 21:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys 2008-02-12 18:43 . 2008-02-12 18:43 <DIR> d-------- C:\Arquivos de programas\USB Game Controller 2008-02-10 09:35 . 2008-02-10 09:35 <DIR> d-------- C:\Arquivos de programas\Elaborate Bytes 2008-02-10 08:01 . 2008-02-10 08:01 <DIR> d-------- C:\Documents and Settings\Higo\Dados de aplicativos\fltk.org . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-05 02:21 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-03-04 04:47 --------- d-----w C:\Arquivos de programas\HIGO PRG 2008-02-28 13:32 --------- d-----w C:\Arquivos de programas\CyberLink 2008-02-28 13:30 505,392 ----a-w C:\WINDOWS\system32\msvcp71.dll 2008-02-25 03:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink 2008-02-13 20:10 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-28 18:06 68856] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648] "SecurDisc"="C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-02-12 11:23 1620480] "InCD"="C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-02-12 11:19 1050112] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 01:17 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 01:13 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 01:17 118784] "SkyTel"="SkyTel.EXE" [2006-05-16 07:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-11-14 06:21 16270848 C:\WINDOWS\RTHDCPL.EXE] "ShStatEXE"="C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 19:50 112216] "McAfeeUpdaterUI"="C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 10:27 136768] "snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 12:48 286720] "Emurayden PSX Emulator"="" [] "CloneDVDElbyDelay"="C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 03:33 45056] "RemoteControl"="C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 16:24 71216] "LanguageShortcut"="C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 16:21 54832] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoStartMenuPinnedList"= 0 (0x0) "NoStartMenuMFUprogramsList"= 0 (0x0) "NoUserNameInStartMenu"= 0 (0x0) "NoStartMenuSubFolders"= 0 (0x0) "NoCommonGroups"= 0 (0x0) "NoPrinterTabs"= 0 (0x0) "NoDeletePrinter"= 0 (0x0) "NoAddPrinter"= 0 (0x0) "NoPrinters"= 0 (0x0) "NoFavoritesMenu"= 0 (0x0) "NoToolbarCustomize"= 0 (0x0) "NoRecentDocsNetHood"= 0 (0x0) "NoChangeAnimation"= 0 (0x0) "NoChangeKeyboardNavigationIndicators"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\McAfee\\Common Framework\\FrameworkService.exe"= "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "C:\\WINDOWS\\system32\\dpvsetup.exe"= "C:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Nero Web\\SetupX.exe"= "C:\\Arquivos de programas\\CyberLink\\PowerDVD\\PowerDVD.exe"= R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Arquivos de programas\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51] . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-06 16:15:07 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}] "ImagePath"="\??\C:\Arquivos de programas\CyberLink\PowerDVD\000.fcl" . Tempo para conclusão: 2008-03-06 16:15:24 ComboFix-quarantined-files.txt 2008-03-06 19:15:22 ComboFix2.txt 2008-03-06 19:00:03 . 2008-02-13 03:38:08 --- E O F --- AGORA O HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:20:59, on 6/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe C:\WINDOWS\vsnpstd.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\McAfee\Common Framework\McTray.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ig.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [shStatEXE] "C:\Arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Arquivos de programas\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Arquivos de programas\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/cabs/ascstubie.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.directradios.com.br/nsvplayx_vp6_aac.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Arquivos de programas\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Arquivos de programas\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared files\RichVideo.exe -- End of file - 6496 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 6, 2008 Boa Noite brou-nf! >@< Apague as pastas: C:\VundoFix Backups C:\Qoobox ___________________________ >@< Faça o download do CCleaner 2.05.555. >@< Baixe-o para o Desktop! >@< Abra o programa e clique em Analisar >> Executar Limpeza. >@< Terminando,clique em Registro >> Procurar erros >> Corrigir erros selecionados. ___________________________ Estando tudo Ok com o PC,crie um Ponto de Restauração do Sistema,completamente Limpo!Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok. Depois,desmarque novamente! >> Aplicar >> Ok. Para maiores detalhes,vá em:< Docs > >@< O Virtumonde,ainda,lhe incomoda? >@< Bom trabalho! >@< Log limpo! :thumbsup: Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
brou-nf 0 Denunciar post Postado Março 8, 2008 Muito obrigado bom antes de você me ajudar meu pc tava muito lento e agora ele voutou ao normal bom eu só tenho é o que agradecer valeu meu amigo e tb quando entrava na net ele abria altomaticamente um monte de pagina e depois da ajuda não abriu mais MUITO ABRIGADO Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 9, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico. Compartilhar este post Link para o post Compartilhar em outros sites