1sefirot1 0 Denunciar post Postado Março 21, 2008 Galera... tem muito tempo que eu nao dou uma verificada no pc. e gostaria de deixar ele com o log limpo pq vou começar a usa-lo para trabalho. Ele esta MUITO lento, e de vez em quando aparece uns executaveis na area de trabalho estranhos. Fora as travadas esporadicas. LA VAI O LOG Logfile of HijackThis v1.99.1 Scan saved at 15:52:17, on 27/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe C:\WINDOWS\Explorer.EXE c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Lexmark 1200 Series\lxczbmgr.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Lexmark 1200 Series\lxczbmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe c:\ARQUIV~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\ping.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\hijackthis\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\ARQUIV~1\mcafee\VIRUSS~1\scriptcl.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - (no file) O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Arquivos de programas\Lexmark 1200 Series\lxczbmgr.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [updateMgr] "C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\ARQUIV~1\ARQUIV~1\McAfee\EmProxy\emproxy.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 22, 2008 Bom Dia! Gsbad >@< Faça o download do ComboFix. >@< Baixe-o para o Desktop! >@< Desabilite as proteções residente de: antivírus,antispywares e Firewall. >@< Feche todas as janelas e execute a ferramenta! Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.Salve-a no Desktop,renomeada como: Kombo.exe Ps: Nomeie durante o salvamento,e não após salvá-la! >@< Abrirá a janela Auto Scan. Aguarde! >@< Digite a opção para continuar e < Enter > >@< Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! _______________________________ >@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 22, 2008 Bom dia DigRam, tudo bem? Fiz os procedimentos citados.. aqui vão os logs.. COMBO FIX ComboFix 08-03-22.1 - Gustavo 2008-03-28 14:16:30.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1046.18.719 [GMT -7:00] Executando de: C:\Documents and Settings\Gustavo\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . The following files were disabled during the run: C:\WINDOWS\svcpool.dll ((((((((((((((((((((((( Ficheiros criados de 2008-02-28 to 2008-03-28 )))))))))))))))))))))))))))))))) . 2008-03-30 18:55 . 2008-03-30 18:56 <DIR> d-------- C:\Arquivos de programas\Project64 v1.5 2008-03-30 18:14 . 2008-03-30 18:14 <DIR> d-------- C:\Arquivos de programas\Crawler 2008-03-30 18:11 . 2008-03-30 18:11 <DIR> d-------- C:\Arquivos de programas\Anark 2008-03-30 17:00 . 2008-03-28 13:51 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\MegauploadToolbar 2008-03-30 17:00 . 2008-03-30 17:00 <DIR> d-------- C:\Arquivos de programas\MegauploadToolbar 2008-03-29 19:05 . 2008-03-02 11:11 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LimeWire 2008-03-29 19:05 . 2008-03-29 19:05 <DIR> d-------- C:\Arquivos de programas\LimeWire 2008-03-28 14:10 . 2008-03-28 14:18 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS 2008-03-28 08:05 . 2008-03-28 08:12 0 --a------ C:\WINDOWS\lkjsoiq 2008-03-27 19:35 . 2008-03-27 19:35 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LEGO Company 2008-03-27 19:35 . 2008-03-27 19:36 <DIR> d-------- C:\Arquivos de programas\LEGO Company 2008-03-27 18:03 . 2008-03-27 18:03 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\TuneUp Software 2008-03-27 18:03 . 2008-03-27 18:03 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-03-27 18:03 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software 2008-03-27 18:02 . 2008-03-27 18:03 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008 2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-03-19 07:51 . 2008-03-19 07:51 268 --ah----- C:\sqmdata02.sqm 2008-03-19 07:51 . 2008-03-19 07:51 244 --ah----- C:\sqmnoopt02.sqm 2008-03-18 11:01 . 2008-03-18 11:07 54,238 --a------ C:\WINDOWS\ban_cartao.html 2008-03-18 11:00 . 2008-03-18 11:00 43,089 --a------ C:\WINDOWS\temp.html 2008-03-18 11:00 . 2008-03-18 11:00 41,930 --a------ C:\WINDOWS\ban_ass.html 2008-03-13 18:57 . 2008-03-16 16:00 0 --a------ C:\WINDOWS\PlayList.Fpl 2008-03-13 18:55 . 2008-03-16 16:00 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX 2008-03-13 18:54 . 2008-03-13 18:54 <DIR> d-------- C:\WINDOWS\system32\FTCodecs 2008-03-13 18:54 . 2006-04-21 00:27 544,768 --a------ C:\WINDOWS\system32\CLVSD.ax 2008-03-13 18:54 . 2005-06-10 13:09 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll 2008-03-13 18:54 . 2003-03-25 05:49 45,056 --a------ C:\WINDOWS\system32\ogg.dll 2008-03-13 18:54 . 2008-03-16 16:00 3,209 --a------ C:\WINDOWS\FantasyDVD.ini 2008-03-13 18:54 . 2008-03-16 16:00 2,417 --a------ C:\WINDOWS\ShortCutInf.ini 2008-03-13 18:53 . 2008-03-13 18:53 <DIR> d-------- C:\Arquivos de programas\Fantasysoft-Studio 2008-03-13 18:39 . 2008-03-13 18:39 <DIR> d-------- C:\Arquivos de programas\VistaCodecPack 2008-03-09 07:12 . 2008-03-09 07:12 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller 2008-02-28 19:57 . 2008-02-28 19:57 <DIR> d-------- C:\WINDOWS\_tmp 2008-02-28 19:54 . 2008-02-28 19:54 759,296 --a------ C:\WINDOWS\gbiehbsb.dll 2008-02-28 19:54 . 2008-02-28 19:54 311,296 --a------ C:\WINDOWS\ping.exe 2008-02-28 19:54 . 2008-02-28 19:54 121,344 --------- C:\WINDOWS\svcpool.dll 2008-02-28 19:54 . 2008-02-28 19:57 4,016 --a------ C:\WINDOWS\svchost . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\McAfee 2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\McAfee 2008-03-28 18:21 --------- d-----w C:\Arquivos de programas\eMule 2008-03-28 00:42 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software 2008-03-14 01:39 --------- d-----w C:\Arquivos de programas\Real Alternative 2008-02-29 17:37 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin 2008-02-29 02:54 --------- d-----w C:\Arquivos de programas\GbPlugin 2008-02-23 02:21 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2008-02-13 21:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help 2008-02-10 23:17 --------- d-----w C:\Documents and Settings\Gustavo\Dados de aplicativos\Audacity 2008-02-10 22:51 208,896 ----a-w C:\WINDOWS\system32\lame_enc.dll 2008-02-10 21:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-02-10 21:31 --------- d-----w C:\Arquivos de programas\Motorola Phone Tools 2008-02-10 21:28 24,192 ----a-w C:\Documents and Settings\Gustavo\usbsermptxp.sys 2008-02-10 21:28 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys 2008-02-10 21:28 22,768 ----a-w C:\Documents and Settings\Gustavo\usbsermpt.sys 2008-01-10 18:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll 2008-01-10 18:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB}] 2008-02-28 19:54 759296 --a------ C:\WINDOWS\gbiehbsb.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-05-17 23:27 16207872 C:\WINDOWS\RTHDCPL.exe] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Wireless Configuration Utility HW.15.lnk - C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe [2006-11-20 00:04:12 634880] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveSearch"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "gbieh.1"= rundll32 C:\WINDOWS\gbiehbsb.dll ForcarNotify [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] C:\ARQUIV~1\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\WINDOWS\\system32\\LEXPPS.EXE"= "C:\\Arquivos de programas\\eMule\\emule.exe"= "C:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 05:00] R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-02 10:57] S2 0216361206738838mcinstcleanup;McAfee Application Installer Cleanup (0216361206738838);C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE C:\ARQUIV~1\ARQUIV~1\McAfee\INSTAL~1\cleanup.ini [] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-27 18:03] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp *Newly Created Service* - 0216361206738838MCINSTCLEANUP *Newly Created Service* - SJYPKT . Conteúdo da pasta 'Tarefas Agendadas' "2008-03-28 01:03:11 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-28 14:18:26 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Emproxy] "ImagePath"="C:\ARQUIV~1\ARQUIV~1\McAfee\EmProxy\emproxy.exe" -- [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McAfee HackerWatch Service] "ImagePath"="\"C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe\"" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcmispupdmgr] "ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcupdmgr.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcmscsvc] "ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McNASvc] "ImagePath"="\"c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe\"" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McODS] "ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcpromgr] "ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McRedirector] "ImagePath"="c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McShield] "ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McSysmon] "ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe" -- [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfeavfk] "ImagePath"="system32\drivers\mfeavfk.sys" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfebopk] "ImagePath"="system32\drivers\mfebopk.sys" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfehidk] "ImagePath"="system32\drivers\mfehidk.sys" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mferkdk] "ImagePath"="system32\drivers\mferkdk.sys" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfesmfk] "ImagePath"="system32\drivers\mfesmfk.sys" -- [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MPFP] "ImagePath"="System32\Drivers\Mpfp.sys" [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MpfService] "ImagePath"="\"C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe\"" . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\svcpool.dll PROCESS: C:\WINDOWS\system32\lsass.exe -> C:\WINDOWS\svcpool.dll PROCESS: C:\WINDOWS\explorer.exe -> C:\WINDOWS\svcpool.dll PROCESS: C:\WINDOWS\system32\csrss.exe -> C:\WINDOWS\svcpool.dll . Tempo para conclusão: 2008-03-28 14:18:55 ComboFix-quarantined-files.txt 2008-03-28 21:18:52 ComboFix2.txt 2008-03-28 21:11:46 . 2008-02-13 21:28:32 --- E O F --- HIJACK THIS Logfile of HijackThis v1.99.1 Scan saved at 14:19:12, on 28/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing) O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 22, 2008 Boa Tarde! Gsbad Delete: C:\QooBox C:\ComboFix.txt << Log anterior do ComboFix. _____________________ >@< Selecione e copie,todo o conteúdo que está na área do quote,para o Bloco de Notas. >@< Salve-o,no Desktop,com o nome: CFScript.txt File::C:\WINDOWS\gbiehbsb.dll C:\WINDOWS\ping.exe C:\WINDOWS\svcpool.dll C:\WINDOWS\svchost C:\sqmdata02.sqm C:\sqmnoopt02.sqm Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "gbieh.1"=- Folder:: C:\WINDOWS\_tmp >@< Arraste,com o Mouse,o CFScript.txt para o ícone do ComboFix. >@< Veja a demonstração! >@< Com esse procedimento,o ComboFix irá executar e,reiniciará o computador,automaticamente! >@< Caso não reinicie,faça-o manualmente! >@< Durante a execução,não utilize o teclado ou Mouse! >@< Terminando,poste o relatório C:\ComboFix.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 22, 2008 Boa noite DigRam.. Fiz o que recomendou... vou postar os logs, mas agora quando reinicio o computador, ao iniciar o windows o sistema diz q nao pode encontrar essa dll "gbiehbsb.dll".. nao q isso seja um PROBLEMAO.. mas so pra você saber rsrs... COMBO FIX ComboFix 08-03-22.1 - Gustavo 2008-03-28 18:52:46.3 - NTFSx86 MINIMAL Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1046.18.807 [GMT -7:00] Executando de: C:\Documents and Settings\Gustavo\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gustavo\Desktop\CFScript.txt.txt WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\sqmdata02.sqm C:\sqmnoopt02.sqm C:\WINDOWS\gbiehbsb.dll C:\WINDOWS\ping.exe C:\WINDOWS\svchost C:\WINDOWS\svcpool.dll . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\sqmdata02.sqm C:\sqmnoopt02.sqm C:\WINDOWS\_tmp C:\WINDOWS\gbiehbsb.dll C:\WINDOWS\mssnmsgr.dll C:\WINDOWS\ping.exe C:\WINDOWS\svchost C:\WINDOWS\svcpool.dll C:\WINDOWS\winhlp.dll . ((((((((((((((((((((((( Ficheiros criados de 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))) . 2008-03-30 18:55 . 2008-03-30 18:56 <DIR> d-------- C:\Arquivos de programas\Project64 v1.5 2008-03-30 18:14 . 2008-03-30 18:14 <DIR> d-------- C:\Arquivos de programas\Crawler 2008-03-30 18:11 . 2008-03-30 18:11 <DIR> d-------- C:\Arquivos de programas\Anark 2008-03-30 17:00 . 2008-03-28 18:37 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\MegauploadToolbar 2008-03-30 17:00 . 2008-03-30 17:00 <DIR> d-------- C:\Arquivos de programas\MegauploadToolbar 2008-03-29 19:05 . 2008-03-02 11:11 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LimeWire 2008-03-29 19:05 . 2008-03-29 19:05 <DIR> d-------- C:\Arquivos de programas\LimeWire 2008-03-28 18:50 . 2007-11-01 12:56 <DIR> dr-h----- C:\Documents and Settings\Administrador\Dados de aplicativos 2008-03-28 18:50 . 2008-03-28 18:50 <DIR> d--h----- C:\Documents and Settings\Administrador\Configurações locais 2008-03-28 18:50 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Administrador\Ambiente de rede 2008-03-28 18:50 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Administrador\Ambiente de impressão 2008-03-28 18:49 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos 2008-03-28 18:49 . 2007-11-01 12:56 <DIR> d-------- C:\Documents and Settings\Administrador\Meus documentos 2008-03-28 18:49 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar 2008-03-28 18:49 . 2007-11-01 12:56 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos 2008-03-28 18:27 . 2008-03-28 18:28 <DIR> d-------- C:\wamp 2008-03-28 14:35 . 2008-03-28 14:35 <DIR> d-------- C:\Documents and Settings\Outros usuários\Dados de aplicativos\TuneUp Software 2008-03-28 14:31 . 2008-03-28 14:31 <DIR> d-------- C:\Documents and Settings\Outros usuários\Contacts 2008-03-28 14:31 . 2008-03-28 14:31 <DIR> d-------- C:\Documents and Settings\Outros usuários\Contacts 2008-03-28 14:30 . 2008-03-28 14:30 <DIR> d-------- C:\Documents and Settings\Outros usuários\Dados de aplicativos\MEGAUPLOADTOOLBAR 2008-03-28 14:25 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Modelos 2008-03-28 14:25 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Modelos 2008-03-28 14:25 . 2008-03-28 14:33 <DIR> dr------- C:\Documents and Settings\Outros usuários\Meus documentos 2008-03-28 14:25 . 2008-03-28 14:33 <DIR> dr------- C:\Documents and Settings\Outros usuários\Meus documentos 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Outros usuários\Menu Iniciar 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Outros usuários\Menu Iniciar 2008-03-28 14:25 . 2008-03-28 14:25 <DIR> dr------- C:\Documents and Settings\Outros usuários\Favoritos 2008-03-28 14:25 . 2008-03-28 14:25 <DIR> dr------- C:\Documents and Settings\Outros usuários\Favoritos 2008-03-28 14:25 . 2008-03-28 14:35 <DIR> dr-h----- C:\Documents and Settings\Outros usuários\Dados de aplicativos 2008-03-28 14:25 . 2008-03-28 14:35 <DIR> dr-h----- C:\Documents and Settings\Outros usuários\Dados de aplicativos 2008-03-28 14:25 . 2008-03-28 14:25 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Configurações locais 2008-03-28 14:25 . 2008-03-28 14:25 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Configurações locais 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de rede 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de rede 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de impressão 2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de impressão 2008-03-27 19:35 . 2008-03-27 19:35 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LEGO Company 2008-03-27 19:35 . 2008-03-27 19:36 <DIR> d-------- C:\Arquivos de programas\LEGO Company 2008-03-27 18:03 . 2008-03-27 18:03 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\TuneUp Software 2008-03-27 18:03 . 2008-03-27 18:03 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-03-27 18:03 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software 2008-03-27 18:02 . 2008-03-27 18:03 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008 2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-03-18 11:01 . 2008-03-18 11:07 54,238 --a------ C:\WINDOWS\ban_cartao.html 2008-03-18 11:00 . 2008-03-18 11:00 43,089 --a------ C:\WINDOWS\temp.html 2008-03-18 11:00 . 2008-03-18 11:00 41,930 --a------ C:\WINDOWS\ban_ass.html 2008-03-13 18:57 . 2008-03-16 16:00 0 --a------ C:\WINDOWS\PlayList.Fpl 2008-03-13 18:55 . 2008-03-16 16:00 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX 2008-03-13 18:54 . 2008-03-13 18:54 <DIR> d-------- C:\WINDOWS\system32\FTCodecs 2008-03-13 18:54 . 2006-04-21 00:27 544,768 --a------ C:\WINDOWS\system32\CLVSD.ax 2008-03-13 18:54 . 2005-06-10 13:09 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll 2008-03-13 18:54 . 2003-03-25 05:49 45,056 --a------ C:\WINDOWS\system32\ogg.dll 2008-03-13 18:54 . 2008-03-16 16:00 3,209 --a------ C:\WINDOWS\FantasyDVD.ini 2008-03-13 18:54 . 2008-03-16 16:00 2,417 --a------ C:\WINDOWS\ShortCutInf.ini 2008-03-13 18:53 . 2008-03-13 18:53 <DIR> d-------- C:\Arquivos de programas\Fantasysoft-Studio 2008-03-13 18:39 . 2008-03-13 18:39 <DIR> d-------- C:\Arquivos de programas\VistaCodecPack 2008-03-09 07:12 . 2008-03-09 07:12 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-29 01:16 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\McAfee 2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\McAfee 2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\McAfee 2008-03-28 18:21 --------- d-----w C:\Arquivos de programas\eMule 2008-03-28 00:42 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software 2008-03-14 01:39 --------- d-----w C:\Arquivos de programas\Real Alternative 2008-02-29 17:37 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin 2008-02-29 02:54 --------- d-----w C:\Arquivos de programas\GbPlugin 2008-02-23 02:21 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2008-02-13 21:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help 2008-02-10 23:17 --------- d-----w C:\Documents and Settings\Gustavo\Dados de aplicativos\Audacity 2008-02-10 22:51 208,896 ----a-w C:\WINDOWS\system32\lame_enc.dll 2008-02-10 21:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-02-10 21:31 --------- d-----w C:\Arquivos de programas\Motorola Phone Tools 2008-02-10 21:28 24,192 ----a-w C:\Documents and Settings\Gustavo\usbsermptxp.sys 2008-02-10 21:28 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys 2008-02-10 21:28 22,768 ----a-w C:\Documents and Settings\Gustavo\usbsermpt.sys 2008-01-10 18:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll 2008-01-10 18:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-05-17 23:27 16207872 C:\WINDOWS\RTHDCPL.exe] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Wireless Configuration Utility HW.15.lnk - C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe [2006-11-20 00:04:12 634880] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoResolveSearch"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] C:\ARQUIV~1\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\WINDOWS\\system32\\LEXPPS.EXE"= "C:\\Arquivos de programas\\eMule\\emule.exe"= "C:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\wamp\\bin\\apache\\apache2.2.6\\bin\\httpd.exe"= S2 0216361206738838mcinstcleanup;McAfee Application Installer Cleanup (0216361206738838);C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE C:\ARQUIV~1\ARQUIV~1\McAfee\INSTAL~1\cleanup.ini [] S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 05:00] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-27 18:03] S3 wampapache;wampapache;"c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice [] S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe wampmysqld [] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Conteúdo da pasta 'Tarefas Agendadas' "2008-03-29 01:06:15 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-28 18:54:02 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-03-28 18:54:24 ComboFix-quarantined-files.txt 2008-03-29 01:54:21 . 2008-02-13 21:28:32 --- E O F --- HIJACK THIS Logfile of HijackThis v1.99.1 Scan saved at 19:01, on 2008-03-28 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe C:\WINDOWS\system32\wuauclt.exe C:\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll (file missing) O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing) O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 22, 2008 Boa Noite! Gsbad >@< Abra o HijackThis e,com todos os programas fechados,dê Fix nesta entrada: O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll (file missing) >@< Faça uma busca ao arquivo: C:\WINDOWS\lkjsoiq << Se encontrar,delete! _____________________________ >@< Faça um escaneamento de desinfecção em < BitDefender > e poste o relatório. >@< Abrirá a página: < BitDefender OnLine Scanner > >@< Clique em: < > >@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan. <!> Leia o Tutorial: < Link > >@< Poste,então: Relatório do BitDefender + Log do HijackThis,atualizado. >@< Ps: O relatório do BitDefender,estará em: C:\Windows\BDOSCAN8\bdoscan.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 23, 2008 Bom dia DigRam, Seguem os logs.. BDOSCAN: [General] App = "BitDefender Online Scanner v8" Date = 29:03:2008 Time = 00:41:51 Scan Path = A:\;C:\;E:\;F:\;G:\;H:\;I:\; [Engines Info] Virus Definitions = 1021791 Engine build = "AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)" Scan plugins = 16 Archive plugins = 41 Unpack plugins = 7 E-mail plugins = 6 System plugins = 5 [scan Statistics] Folders = 5825 Files = 393426 Archives = 1332 Packed files = 26467 Identified viruses = 2 Infected files = 4 Warnings = 0 Suspect files = 0 Disinfected files = 0 Deleted files = 4 Copied files = 0 Moved files = 0 Renamed files = 0 I/O Errors = 29 [scan Settings] SecondAction = Delete FirstAction = Disinfect Heuristics = 1 Enable Warnings = 1 Exclude Ext = Extensions = *; Scan Emails = 1 Scan Archives = 1 Scan Packed = 1 Scan Files = 1 Scan Boot = 1 Verify Memory = 0 [scan Results] Line00000009 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Infected with: Generic.Banker.Delf.F3785D93" Line00000008 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Disinfection failed" Line00000007 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Deleted" Line00000006 = "C:\QooBox\Quarantine\C\WINDOWS\ping.exe.vir Infected with: Win32.Worm.Mixor.F" Line00000005 = "C:\QooBox\Quarantine\C\WINDOWS\ping.exe.vir Deleted" Line00000004 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Infected with: Generic.Banker.Delf.F3785D93" Line00000003 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Disinfection failed" Line00000002 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Deleted" Line00000001 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003305.exe Infected with: Win32.Worm.Mixor.F" Line00000000 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003305.exe Deleted" HIJACKTHIS: Logfile of HijackThis v1.99.1 Scan saved at 12:03, on 2008-03-29 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing) O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 24, 2008 DigRam.. Depois desses ultimos procedimentos alguma coisa aconteceu com o computador. Agora a noite quando eu fui ligar ele esta apresentando alguns erros. - O erro da dll persiste.. - Quando acesso algumas pastas... essa em especial: C:\Documents and Settings\Gustavo\Meus documentos\Meus Videos.., ocorre um erro de explorer.exe e tudo para de funcionar, tendo que reiniciar o computador. Sera q foi o ultimo filme q eu baixei q estava com virus? Em todo o caso.. ta aqui o ultimo log q eu baixei do hijack.. Logfile of HijackThis v1.99.1Scan saved at 21:26, on 2008-03-29 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\internet explorer\iexplore.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing) O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 24, 2008 Bom Dia! Gsbad Quando acesso algumas pastas... essa em especial: C:\Documents and Settings\Gustavo\Meus documentos\Meus Videos.., ocorre um erro de explorer.exe e tudo para de funcionar, tendo que reiniciar o computador.Sera q foi o ultimo filme q eu baixei q estava com virus? >@< Faça uma Restauração do sistema,para um ponto antes desse download. __________________________ O erro da dll persiste.. >@< Isso,pode ser uma requisição do shell do Windows,ao arquivo removido e,cuja chave,no registro,ainda permanece. __________________________ >@< Vá a esta página: < Link > >@< Localize: Registry Search Tool >@< Clique no ícone com uma seta àcima < > e,baixe o arquivo RegSrch.zip <!> >@< Extraia o conteúdo do zip para o Desktop! >@< Desabilite programas de proteção,que tenham bloqueio de scripts. >@< Execute o arquivo RegSrch.vbs e,na janela que abrir,digite: gbiehbsb >@< Dê o Ok. >@< Aguarde!Na janela que surgir,clique em Ok. >@< Surgirão informações de registro,que voçê passará ao Bloco de Notas e colará na sua resposta. >@< Salve-o com o nome: Requisit_gbiehbsb >@< Poste,então: Requisit_gbiehbsb.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 24, 2008 Boa tarde Digram.. Fiz o que sugeriu... O problema com o download e o erro do explorer.exe deu certo, resolvido. Mas quanto a dll.. No ponto que deveriam surgir as informações de regristro (q eu deveria colar no bloco de notas) aparece um erro Windows Script Host, que nao econtra o arquivo RegSrch.vbs (q esta no desktop)... Mas de qualquer forma ele encontrou a dll gbiehbsb... aqui segue o log do hijack... Logfile of HijackThis v1.99.1Scan saved at 14:56, on 2008-03-24 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\Arquivos de programas\internet explorer\iexplore.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing) O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing) O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 24, 2008 Boa Noite! Gsbad Mas quanto a dll..No ponto que deveriam surgir as informações de regristro (q eu deveria colar no bloco de notas) aparece um erro Windows Script Host, que nao econtra o arquivo RegSrch.vbs (q esta no desktop)... Mas de qualquer forma ele encontrou a dll gbiehbsb... >@< As configurações de segurança,de seu navegador,estão impedindo a execução do script. >@< Coloque < http://www.billsway.com/vbspage/ > como Site preferencial. >@< Nas configurações avançadas do IE,marque: Disable script debugging ( Internet Explorer ) Disable script debugging ( Other ) << ( Outros ) >@< Clique em Aplicar >> Ok. ______________________________ >@< Ps: Incluí informações,no Post anterior! Busque executar,novamente,a ferramenta. >@< Sem o relatório da ferramenta,meu amigo,será difícil anular essa requisição/solicitação da dll. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 25, 2008 >@< As configurações de segurança,de seu navegador,estão impedindo a execução do script.>@< Coloque < http://www.billsway.com/vbspage/ > como Site preferencial. >@< Nas configurações avançadas do IE,marque: Disable script debugging ( Internet Explorer ) Disable script debugging ( Other ) << ( Outros ) >@< Clique em Aplicar >> Ok. Boa noite Digram.. Nao sei colocar o site citado como "Site preferencial" o que vem a ser isso? nao consigui... Já as configurações avançadas do IE já estavam marcadas. Deixei como estavam. Disable script debugging ( Internet Explorer ) ATIVADO Disable script debugging ( Other ) << ( Outros ) ATIVADO Verifiquei o post anterior (que voce atualizou), e fiz o q estava la, desabilitei qualquer programa que possa bloquear o script.. mas o erro persiste.. :unsure: Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 25, 2008 a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro.. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 25, 2008 a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro.. _______________________ Opa! Gsbad Bom Dia! >@< Abra o Internet Explorer. >@< Clique em Ferramentas >> Opções da Internet>> Clique na guia Segurança. >@< Clique em Sites Confiáveis >> Sites, no campo Adicionar este site à zona,coloque: http://www.billsway.com/vbspage/ >@< Clique em Adicionar. >@< Desmarque a opção: Exigir Verificação do Servidor.( https ) >@< Clique Ok,em todas as janelas. _______________________ >@< Caso não funcione,reinstale o WindowsScript. <!> Faça o download do Windows Script 5.6. >@< Baixe-o para o Disco Local-C e instale-o aí mesmo! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 25, 2008 a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro.. _______________________ Opa! Gsbad Bom Dia! >@< Abra o Internet Explorer. >@< Clique em Ferramentas >> Opções da Internet>> Clique na guia Segurança. >@< Clique em Sites Confiáveis >> Sites, no campo Adicionar este site à zona,coloque: http://www.billsway.com/vbspage/ >@< Clique em Adicionar. >@< Desmarque a opção: Exigir Verificação do Servidor.( https ) >@< Clique Ok,em todas as janelas. _______________________ >@< Caso não funcione,reinstale o WindowsScript. <!> Faça o download do Windows Script 5.6. >@< Baixe-o para o Disco Local-C e instale-o aí mesmo! Abraços! Boa tarde Digram.. Instalei o Windows Script 5.6, reiniciei o computador e tentei eliminar a gbiehbsb novamente... não funcionou. O erro persiste. E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll. De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega. Sera q essa dll pode estar causando isso? :blink: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 25, 2008 Boa Tarde! Gsbad E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll.De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega. Sera q essa dll pode estar causando isso? >@< Eu não descartaria essa possibilidade!Mas,é bom verificar o Modem. ___________________________ >@< Faça o download do RegSeeker. >@< Salve-o no Disco Local-C e descompacte-o aí mesmo,em um pasta própria. >@< Execute o programa,com um duplo clique! >@< Clique em Languages e selecione: Português Brasil. >@< Clique em: Procurar por.... e,na caixa,digite: gbiehbsb >@< Clique em: < Procurar > >@< Selecione todos os valores encontrados e,com o botão direito do mouse,clique em: Apagar entradas selecionadas. ___________________________ >@< Verifique com o RegSrch.vbs,se o RegSeeker encontrou o mesmo número de objetos,indicados pelo script. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
1sefirot1 0 Denunciar post Postado Março 27, 2008 Boa Tarde! Gsbad E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll.De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega. Sera q essa dll pode estar causando isso? >@< Eu não descartaria essa possibilidade!Mas,é bom verificar o Modem. ___________________________ >@< Faça o download do RegSeeker. >@< Salve-o no Disco Local-C e descompacte-o aí mesmo,em um pasta própria. >@< Execute o programa,com um duplo clique! >@< Clique em Languages e selecione: Português Brasil. >@< Clique em: Procurar por.... e,na caixa,digite: gbiehbsb >@< Clique em: < Procurar > >@< Selecione todos os valores encontrados e,com o botão direito do mouse,clique em: Apagar entradas selecionadas. ___________________________ >@< Verifique com o RegSrch.vbs,se o RegSeeker encontrou o mesmo número de objetos,indicados pelo script. Abraços! Dig ram.. cabei formatando o computador.. pode fechar o topico.. brigadao :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 27, 2008 Boa Tarde! Gsbad >@< Foi uma pena,neste momento,a formatação. >@< Pois consegui desvendar o motivo,do erro de script e corrigi-lo. <!> Leia: < http://forum.imasters.com.br/index.php?showtopic=279024 > >@< Por meio de pesquisas,observei que alguns colegas,ao passar o procedimento,paravam neste erro. >@< E,no meu próprio PC,ocorreu o mesmo problema. >@< Daí,não tive alternativas e estudei o scripts,modificando alguns parâmetros. >@< Mas,valeu a experiência! >@< O Tópico será fechado,como Resolvido...não da forma como gostaria! Abraços! :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 27, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico. Compartilhar este post Link para o post Compartilhar em outros sites