Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

1sefirot1

[Resolvido] Computador lento!

Recommended Posts

Galera... tem muito tempo que eu nao dou uma verificada no pc. e gostaria de deixar ele com o log limpo pq vou começar a usa-lo para trabalho.

Ele esta MUITO lento, e de vez em quando aparece uns executaveis na area de trabalho estranhos. Fora as travadas esporadicas.

 

LA VAI O LOG

 

Logfile of HijackThis v1.99.1

Scan saved at 15:52:17, on 27/3/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe

C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe

c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe

C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe

C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe

C:\WINDOWS\Explorer.EXE

c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe

C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe

C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe

C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Lexmark 1200 Series\lxczbmgr.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Lexmark 1200 Series\lxczbmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

c:\ARQUIV~1\mcafee.com\agent\mcagent.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\ping.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\hijackthis\HijackThis.exe

C:\WINDOWS\system32\NOTEPAD.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\ARQUIV~1\mcafee\VIRUSS~1\scriptcl.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - (no file)

O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Arquivos de programas\Lexmark 1200 Series\lxczbmgr.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [updateMgr] "C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\ARQUIV~1\ARQUIV~1\McAfee\EmProxy\emproxy.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe

O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcupdmgr.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe

O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe

O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe

O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe

O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe

O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Gsbad

 

>@< Faça o download do ComboFix.

>@< Baixe-o para o Desktop!

>@< Desabilite as proteções residente de: antivírus,antispywares e Firewall.

>@< Feche todas as janelas e execute a ferramenta!

 

Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

Salve-a no Desktop,renomeada como: Kombo.exe

Ps: Nomeie durante o salvamento,e não após salvá-la!

>@< Abrirá a janela Auto Scan. Aguarde!

>@< Digite a opção para continuar e < Enter >

>@< Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado!

_______________________________

 

>@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam, tudo bem?

 

Fiz os procedimentos citados.. aqui vão os logs..

 

COMBO FIX

 

ComboFix 08-03-22.1 - Gustavo 2008-03-28 14:16:30.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1046.18.719 [GMT -7:00]

Executando de: C:\Documents and Settings\Gustavo\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

The following files were disabled during the run:

C:\WINDOWS\svcpool.dll

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-02-28 to 2008-03-28 ))))))))))))))))))))))))))))))))

.

 

2008-03-30 18:55 . 2008-03-30 18:56 <DIR> d-------- C:\Arquivos de programas\Project64 v1.5

2008-03-30 18:14 . 2008-03-30 18:14 <DIR> d-------- C:\Arquivos de programas\Crawler

2008-03-30 18:11 . 2008-03-30 18:11 <DIR> d-------- C:\Arquivos de programas\Anark

2008-03-30 17:00 . 2008-03-28 13:51 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\MegauploadToolbar

2008-03-30 17:00 . 2008-03-30 17:00 <DIR> d-------- C:\Arquivos de programas\MegauploadToolbar

2008-03-29 19:05 . 2008-03-02 11:11 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LimeWire

2008-03-29 19:05 . 2008-03-29 19:05 <DIR> d-------- C:\Arquivos de programas\LimeWire

2008-03-28 14:10 . 2008-03-28 14:18 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS

2008-03-28 08:05 . 2008-03-28 08:12 0 --a------ C:\WINDOWS\lkjsoiq

2008-03-27 19:35 . 2008-03-27 19:35 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LEGO Company

2008-03-27 19:35 . 2008-03-27 19:36 <DIR> d-------- C:\Arquivos de programas\LEGO Company

2008-03-27 18:03 . 2008-03-27 18:03 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\TuneUp Software

2008-03-27 18:03 . 2008-03-27 18:03 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-03-27 18:03 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software

2008-03-27 18:02 . 2008-03-27 18:03 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008

2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-03-19 07:51 . 2008-03-19 07:51 268 --ah----- C:\sqmdata02.sqm

2008-03-19 07:51 . 2008-03-19 07:51 244 --ah----- C:\sqmnoopt02.sqm

2008-03-18 11:01 . 2008-03-18 11:07 54,238 --a------ C:\WINDOWS\ban_cartao.html

2008-03-18 11:00 . 2008-03-18 11:00 43,089 --a------ C:\WINDOWS\temp.html

2008-03-18 11:00 . 2008-03-18 11:00 41,930 --a------ C:\WINDOWS\ban_ass.html

2008-03-13 18:57 . 2008-03-16 16:00 0 --a------ C:\WINDOWS\PlayList.Fpl

2008-03-13 18:55 . 2008-03-16 16:00 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX

2008-03-13 18:54 . 2008-03-13 18:54 <DIR> d-------- C:\WINDOWS\system32\FTCodecs

2008-03-13 18:54 . 2006-04-21 00:27 544,768 --a------ C:\WINDOWS\system32\CLVSD.ax

2008-03-13 18:54 . 2005-06-10 13:09 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll

2008-03-13 18:54 . 2003-03-25 05:49 45,056 --a------ C:\WINDOWS\system32\ogg.dll

2008-03-13 18:54 . 2008-03-16 16:00 3,209 --a------ C:\WINDOWS\FantasyDVD.ini

2008-03-13 18:54 . 2008-03-16 16:00 2,417 --a------ C:\WINDOWS\ShortCutInf.ini

2008-03-13 18:53 . 2008-03-13 18:53 <DIR> d-------- C:\Arquivos de programas\Fantasysoft-Studio

2008-03-13 18:39 . 2008-03-13 18:39 <DIR> d-------- C:\Arquivos de programas\VistaCodecPack

2008-03-09 07:12 . 2008-03-09 07:12 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

2008-02-28 19:57 . 2008-02-28 19:57 <DIR> d-------- C:\WINDOWS\_tmp

2008-02-28 19:54 . 2008-02-28 19:54 759,296 --a------ C:\WINDOWS\gbiehbsb.dll

2008-02-28 19:54 . 2008-02-28 19:54 311,296 --a------ C:\WINDOWS\ping.exe

2008-02-28 19:54 . 2008-02-28 19:54 121,344 --------- C:\WINDOWS\svcpool.dll

2008-02-28 19:54 . 2008-02-28 19:57 4,016 --a------ C:\WINDOWS\svchost

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\McAfee

2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\McAfee

2008-03-28 18:21 --------- d-----w C:\Arquivos de programas\eMule

2008-03-28 00:42 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software

2008-03-14 01:39 --------- d-----w C:\Arquivos de programas\Real Alternative

2008-02-29 17:37 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

2008-02-29 02:54 --------- d-----w C:\Arquivos de programas\GbPlugin

2008-02-23 02:21 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll

2008-02-13 21:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help

2008-02-10 23:17 --------- d-----w C:\Documents and Settings\Gustavo\Dados de aplicativos\Audacity

2008-02-10 22:51 208,896 ----a-w C:\WINDOWS\system32\lame_enc.dll

2008-02-10 21:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

2008-02-10 21:31 --------- d-----w C:\Arquivos de programas\Motorola Phone Tools

2008-02-10 21:28 24,192 ----a-w C:\Documents and Settings\Gustavo\usbsermptxp.sys

2008-02-10 21:28 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys

2008-02-10 21:28 22,768 ----a-w C:\Documents and Settings\Gustavo\usbsermpt.sys

2008-01-10 18:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll

2008-01-10 18:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB}]

2008-02-28 19:54 759296 --a------ C:\WINDOWS\gbiehbsb.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-17 23:27 16207872 C:\WINDOWS\RTHDCPL.exe]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Wireless Configuration Utility HW.15.lnk - C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe [2006-11-20 00:04:12 634880]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveSearch"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

"gbieh.1"= rundll32 C:\WINDOWS\gbiehbsb.dll ForcarNotify

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

C:\ARQUIV~1\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"C:\\WINDOWS\\system32\\LEXPPS.EXE"=

"C:\\Arquivos de programas\\eMule\\emule.exe"=

"C:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

 

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 05:00]

R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-02 10:57]

S2 0216361206738838mcinstcleanup;McAfee Application Installer Cleanup (0216361206738838);C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE C:\ARQUIV~1\ARQUIV~1\McAfee\INSTAL~1\cleanup.ini []

S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-27 18:03]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

*Newly Created Service* - 0216361206738838MCINSTCLEANUP

*Newly Created Service* - SJYPKT

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-03-28 01:03:11 C:\WINDOWS\Tasks\1-Click Maintenance.job"

- C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-28 14:18:26

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\Emproxy]

"ImagePath"="C:\ARQUIV~1\ARQUIV~1\McAfee\EmProxy\emproxy.exe"

--

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McAfee HackerWatch Service]

"ImagePath"="\"C:\Arquivos de programas\Arquivos comuns\McAfee\HackerWatch\HWAPI.exe\""

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcmispupdmgr]

"ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcupdmgr.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcmscsvc]

"ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcmscsvc.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McNASvc]

"ImagePath"="\"c:\ARQUIV~1\ARQUIV~1\mcafee\mna\mcnasvc.exe\""

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McODS]

"ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcods.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mcpromgr]

"ImagePath"="C:\ARQUIV~1\McAfee\MSC\mcpromgr.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McRedirector]

"ImagePath"="c:\ARQUIV~1\ARQUIV~1\mcafee\redirsvc\redirsvc.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McShield]

"ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcshield.exe"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\McSysmon]

"ImagePath"="C:\ARQUIV~1\McAfee\VIRUSS~1\mcsysmon.exe"

--

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfeavfk]

"ImagePath"="system32\drivers\mfeavfk.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfebopk]

"ImagePath"="system32\drivers\mfebopk.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfehidk]

"ImagePath"="system32\drivers\mfehidk.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mferkdk]

"ImagePath"="system32\drivers\mferkdk.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\mfesmfk]

"ImagePath"="system32\drivers\mfesmfk.sys"

--

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MPFP]

"ImagePath"="System32\Drivers\Mpfp.sys"

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MpfService]

"ImagePath"="\"C:\Arquivos de programas\McAfee\MPF\MPFSrv.exe\""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

PROCESS: C:\WINDOWS\system32\winlogon.exe

-> C:\WINDOWS\svcpool.dll

 

PROCESS: C:\WINDOWS\system32\lsass.exe

-> C:\WINDOWS\svcpool.dll

 

PROCESS: C:\WINDOWS\explorer.exe

-> C:\WINDOWS\svcpool.dll

 

PROCESS: C:\WINDOWS\system32\csrss.exe

-> C:\WINDOWS\svcpool.dll

.

Tempo para conclusão: 2008-03-28 14:18:55

ComboFix-quarantined-files.txt 2008-03-28 21:18:52

ComboFix2.txt 2008-03-28 21:11:46

.

2008-02-13 21:28:32 --- E O F ---

 

 

HIJACK THIS

 

Logfile of HijackThis v1.99.1

Scan saved at 14:19:12, on 28/3/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing)

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Gsbad

 

Delete:

 

C:\QooBox

C:\ComboFix.txt << Log anterior do ComboFix.

_____________________

 

>@< Selecione e copie,todo o conteúdo que está na área do quote,para o Bloco de Notas.

>@< Salve-o,no Desktop,com o nome: CFScript.txt

 

File::

C:\WINDOWS\gbiehbsb.dll

C:\WINDOWS\ping.exe

C:\WINDOWS\svcpool.dll

C:\WINDOWS\svchost

C:\sqmdata02.sqm

C:\sqmnoopt02.sqm

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

"gbieh.1"=-

Folder::

C:\WINDOWS\_tmp

>@< Arraste,com o Mouse,o CFScript.txt para o ícone do ComboFix.

>@< Veja a demonstração!

 

cpiadecfscriptxt7.gif

 

>@< Com esse procedimento,o ComboFix irá executar e,reiniciará o computador,automaticamente!

>@< Caso não reinicie,faça-o manualmente!

>@< Durante a execução,não utilize o teclado ou Mouse!

>@< Terminando,poste o relatório C:\ComboFix.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam..

 

Fiz o que recomendou... vou postar os logs, mas agora quando reinicio o computador, ao iniciar o windows o sistema diz q nao pode encontrar essa dll "gbiehbsb.dll".. nao q isso seja um PROBLEMAO.. mas so pra você saber rsrs...

 

COMBO FIX

ComboFix 08-03-22.1 - Gustavo 2008-03-28 18:52:46.3 - NTFSx86 MINIMAL

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1046.18.807 [GMT -7:00]

Executando de: C:\Documents and Settings\Gustavo\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Gustavo\Desktop\CFScript.txt.txt

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

 

FILE ::

C:\sqmdata02.sqm

C:\sqmnoopt02.sqm

C:\WINDOWS\gbiehbsb.dll

C:\WINDOWS\ping.exe

C:\WINDOWS\svchost

C:\WINDOWS\svcpool.dll

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\sqmdata02.sqm

C:\sqmnoopt02.sqm

C:\WINDOWS\_tmp

C:\WINDOWS\gbiehbsb.dll

C:\WINDOWS\mssnmsgr.dll

C:\WINDOWS\ping.exe

C:\WINDOWS\svchost

C:\WINDOWS\svcpool.dll

C:\WINDOWS\winhlp.dll

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-02-28 to 2008-03-29 ))))))))))))))))))))))))))))))))

.

 

2008-03-30 18:55 . 2008-03-30 18:56 <DIR> d-------- C:\Arquivos de programas\Project64 v1.5

2008-03-30 18:14 . 2008-03-30 18:14 <DIR> d-------- C:\Arquivos de programas\Crawler

2008-03-30 18:11 . 2008-03-30 18:11 <DIR> d-------- C:\Arquivos de programas\Anark

2008-03-30 17:00 . 2008-03-28 18:37 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\MegauploadToolbar

2008-03-30 17:00 . 2008-03-30 17:00 <DIR> d-------- C:\Arquivos de programas\MegauploadToolbar

2008-03-29 19:05 . 2008-03-02 11:11 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LimeWire

2008-03-29 19:05 . 2008-03-29 19:05 <DIR> d-------- C:\Arquivos de programas\LimeWire

2008-03-28 18:50 . 2007-11-01 12:56 <DIR> dr-h----- C:\Documents and Settings\Administrador\Dados de aplicativos

2008-03-28 18:50 . 2008-03-28 18:50 <DIR> d--h----- C:\Documents and Settings\Administrador\Configurações locais

2008-03-28 18:50 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Administrador\Ambiente de rede

2008-03-28 18:50 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Administrador\Ambiente de impressão

2008-03-28 18:49 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos

2008-03-28 18:49 . 2007-11-01 12:56 <DIR> d-------- C:\Documents and Settings\Administrador\Meus documentos

2008-03-28 18:49 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar

2008-03-28 18:49 . 2007-11-01 12:56 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos

2008-03-28 18:27 . 2008-03-28 18:28 <DIR> d-------- C:\wamp

2008-03-28 14:35 . 2008-03-28 14:35 <DIR> d-------- C:\Documents and Settings\Outros usuários\Dados de aplicativos\TuneUp Software

2008-03-28 14:31 . 2008-03-28 14:31 <DIR> d-------- C:\Documents and Settings\Outros usuários\Contacts

2008-03-28 14:31 . 2008-03-28 14:31 <DIR> d-------- C:\Documents and Settings\Outros usuários\Contacts

2008-03-28 14:30 . 2008-03-28 14:30 <DIR> d-------- C:\Documents and Settings\Outros usuários\Dados de aplicativos\MEGAUPLOADTOOLBAR

2008-03-28 14:25 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Modelos

2008-03-28 14:25 . 2007-11-01 21:07 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Modelos

2008-03-28 14:25 . 2008-03-28 14:33 <DIR> dr------- C:\Documents and Settings\Outros usuários\Meus documentos

2008-03-28 14:25 . 2008-03-28 14:33 <DIR> dr------- C:\Documents and Settings\Outros usuários\Meus documentos

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Outros usuários\Menu Iniciar

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> dr------- C:\Documents and Settings\Outros usuários\Menu Iniciar

2008-03-28 14:25 . 2008-03-28 14:25 <DIR> dr------- C:\Documents and Settings\Outros usuários\Favoritos

2008-03-28 14:25 . 2008-03-28 14:25 <DIR> dr------- C:\Documents and Settings\Outros usuários\Favoritos

2008-03-28 14:25 . 2008-03-28 14:35 <DIR> dr-h----- C:\Documents and Settings\Outros usuários\Dados de aplicativos

2008-03-28 14:25 . 2008-03-28 14:35 <DIR> dr-h----- C:\Documents and Settings\Outros usuários\Dados de aplicativos

2008-03-28 14:25 . 2008-03-28 14:25 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Configurações locais

2008-03-28 14:25 . 2008-03-28 14:25 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Configurações locais

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de rede

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de rede

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de impressão

2008-03-28 14:25 . 2007-11-01 12:56 <DIR> d--h----- C:\Documents and Settings\Outros usuários\Ambiente de impressão

2008-03-27 19:35 . 2008-03-27 19:35 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\LEGO Company

2008-03-27 19:35 . 2008-03-27 19:36 <DIR> d-------- C:\Arquivos de programas\LEGO Company

2008-03-27 18:03 . 2008-03-27 18:03 <DIR> d-------- C:\Documents and Settings\Gustavo\Dados de aplicativos\TuneUp Software

2008-03-27 18:03 . 2008-03-27 18:03 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-03-27 18:03 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software

2008-03-27 18:02 . 2008-03-27 18:03 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008

2008-03-27 18:02 . 2008-03-27 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-03-18 11:01 . 2008-03-18 11:07 54,238 --a------ C:\WINDOWS\ban_cartao.html

2008-03-18 11:00 . 2008-03-18 11:00 43,089 --a------ C:\WINDOWS\temp.html

2008-03-18 11:00 . 2008-03-18 11:00 41,930 --a------ C:\WINDOWS\ban_ass.html

2008-03-13 18:57 . 2008-03-16 16:00 0 --a------ C:\WINDOWS\PlayList.Fpl

2008-03-13 18:55 . 2008-03-16 16:00 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX

2008-03-13 18:54 . 2008-03-13 18:54 <DIR> d-------- C:\WINDOWS\system32\FTCodecs

2008-03-13 18:54 . 2006-04-21 00:27 544,768 --a------ C:\WINDOWS\system32\CLVSD.ax

2008-03-13 18:54 . 2005-06-10 13:09 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll

2008-03-13 18:54 . 2003-03-25 05:49 45,056 --a------ C:\WINDOWS\system32\ogg.dll

2008-03-13 18:54 . 2008-03-16 16:00 3,209 --a------ C:\WINDOWS\FantasyDVD.ini

2008-03-13 18:54 . 2008-03-16 16:00 2,417 --a------ C:\WINDOWS\ShortCutInf.ini

2008-03-13 18:53 . 2008-03-13 18:53 <DIR> d-------- C:\Arquivos de programas\Fantasysoft-Studio

2008-03-13 18:39 . 2008-03-13 18:39 <DIR> d-------- C:\Arquivos de programas\VistaCodecPack

2008-03-09 07:12 . 2008-03-09 07:12 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-29 01:16 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\McAfee

2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\McAfee

2008-03-28 21:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\McAfee

2008-03-28 18:21 --------- d-----w C:\Arquivos de programas\eMule

2008-03-28 00:42 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software

2008-03-14 01:39 --------- d-----w C:\Arquivos de programas\Real Alternative

2008-02-29 17:37 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

2008-02-29 02:54 --------- d-----w C:\Arquivos de programas\GbPlugin

2008-02-23 02:21 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll

2008-02-13 21:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help

2008-02-10 23:17 --------- d-----w C:\Documents and Settings\Gustavo\Dados de aplicativos\Audacity

2008-02-10 22:51 208,896 ----a-w C:\WINDOWS\system32\lame_enc.dll

2008-02-10 21:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

2008-02-10 21:31 --------- d-----w C:\Arquivos de programas\Motorola Phone Tools

2008-02-10 21:28 24,192 ----a-w C:\Documents and Settings\Gustavo\usbsermptxp.sys

2008-02-10 21:28 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys

2008-02-10 21:28 22,768 ----a-w C:\Documents and Settings\Gustavo\usbsermpt.sys

2008-01-10 18:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll

2008-01-10 18:15 755,027 ----a-w C:\WINDOWS\system32\xvidcore.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-17 23:27 16207872 C:\WINDOWS\RTHDCPL.exe]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Wireless Configuration Utility HW.15.lnk - C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe [2006-11-20 00:04:12 634880]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveSearch"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

C:\ARQUIV~1\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"C:\\WINDOWS\\system32\\LEXPPS.EXE"=

"C:\\Arquivos de programas\\eMule\\emule.exe"=

"C:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\wamp\\bin\\apache\\apache2.2.6\\bin\\httpd.exe"=

 

S2 0216361206738838mcinstcleanup;McAfee Application Installer Cleanup (0216361206738838);C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE C:\ARQUIV~1\ARQUIV~1\McAfee\INSTAL~1\cleanup.ini []

S2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 05:00]

S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-27 18:03]

S3 wampapache;wampapache;"c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice []

S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe wampmysqld []

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-03-29 01:06:15 C:\WINDOWS\Tasks\1-Click Maintenance.job"

- C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-28 18:54:02

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-03-28 18:54:24

ComboFix-quarantined-files.txt 2008-03-29 01:54:21

.

2008-02-13 21:28:32 --- E O F ---

 

 

HIJACK THIS

Logfile of HijackThis v1.99.1

Scan saved at 19:01, on 2008-03-28

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

C:\WINDOWS\system32\wuauclt.exe

C:\hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll (file missing)

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing)

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Gsbad

 

>@< Abra o HijackThis e,com todos os programas fechados,dê Fix nesta entrada:

 

O2 - BHO: Banco do Brasil S.A. - {FCAAAC14-BC46-40CA-9CB2-CBB12C6739EB} - C:\WINDOWS\gbiehbsb.dll (file missing)

 

>@< Faça uma busca ao arquivo: C:\WINDOWS\lkjsoiq << Se encontrar,delete!

_____________________________

 

>@< Faça um escaneamento de desinfecção em < BitDefender > e poste o relatório.

>@< Abrirá a página: < BitDefender OnLine Scanner >

>@< Clique em: < agree2.gif >

>@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan.

 

<!> Leia o Tutorial: < Link >

 

>@< Poste,então: Relatório do BitDefender + Log do HijackThis,atualizado.

>@< Ps: O relatório do BitDefender,estará em: C:\Windows\BDOSCAN8\bdoscan.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam,

 

Seguem os logs..

 

BDOSCAN:

 

[General]

App = "BitDefender Online Scanner v8"

Date = 29:03:2008

Time = 00:41:51

Scan Path = A:\;C:\;E:\;F:\;G:\;H:\;I:\;

 

[Engines Info]

Virus Definitions = 1021791

Engine build = "AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)"

Scan plugins = 16

Archive plugins = 41

Unpack plugins = 7

E-mail plugins = 6

System plugins = 5

 

[scan Statistics]

Folders = 5825

Files = 393426

Archives = 1332

Packed files = 26467

Identified viruses = 2

Infected files = 4

Warnings = 0

Suspect files = 0

Disinfected files = 0

Deleted files = 4

Copied files = 0

Moved files = 0

Renamed files = 0

I/O Errors = 29

 

[scan Settings]

SecondAction = Delete

FirstAction = Disinfect

Heuristics = 1

Enable Warnings = 1

Exclude Ext =

Extensions = *;

Scan Emails = 1

Scan Archives = 1

Scan Packed = 1

Scan Files = 1

Scan Boot = 1

Verify Memory = 0

 

[scan Results]

Line00000009 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Infected with: Generic.Banker.Delf.F3785D93"

Line00000008 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Disinfection failed"

Line00000007 = "C:\QooBox\Quarantine\C\WINDOWS\gbiehbsb.dll.vir Deleted"

Line00000006 = "C:\QooBox\Quarantine\C\WINDOWS\ping.exe.vir Infected with: Win32.Worm.Mixor.F"

Line00000005 = "C:\QooBox\Quarantine\C\WINDOWS\ping.exe.vir Deleted"

Line00000004 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Infected with: Generic.Banker.Delf.F3785D93"

Line00000003 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Disinfection failed"

Line00000002 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003304.dll Deleted"

Line00000001 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003305.exe Infected with: Win32.Worm.Mixor.F"

Line00000000 = "C:\System Volume Information\_restore{40A5CE1C-953C-4352-AFAF-E0A791039424}\RP3\A0003305.exe Deleted"

 

 

 

HIJACKTHIS:

Logfile of HijackThis v1.99.1

Scan saved at 12:03, on 2008-03-29

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing)

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam..

 

Depois desses ultimos procedimentos alguma coisa aconteceu com o computador.

 

Agora a noite quando eu fui ligar ele esta apresentando alguns erros.

 

- O erro da dll persiste..

- Quando acesso algumas pastas... essa em especial: C:\Documents and Settings\Gustavo\Meus documentos\Meus Videos.., ocorre um erro de explorer.exe e tudo para de funcionar, tendo que reiniciar o computador.

 

Sera q foi o ultimo filme q eu baixei q estava com virus?

 

Em todo o caso.. ta aqui o ultimo log q eu baixei do hijack..

Logfile of HijackThis v1.99.1

Scan saved at 21:26, on 2008-03-29

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\ARQUIV~1\GbPlugin\gbieh.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing)

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Gsbad

 

Quando acesso algumas pastas... essa em especial: C:\Documents and Settings\Gustavo\Meus documentos\Meus Videos.., ocorre um erro de explorer.exe e tudo para de funcionar, tendo que reiniciar o computador.

Sera q foi o ultimo filme q eu baixei q estava com virus?

>@< Faça uma Restauração do sistema,para um ponto antes desse download.

__________________________

 

O erro da dll persiste..

>@< Isso,pode ser uma requisição do shell do Windows,ao arquivo removido e,cuja chave,no registro,ainda permanece.

__________________________

 

>@< Vá a esta página: < Link >

>@< Localize: Registry Search Tool

>@< Clique no ícone com uma seta àcima < aaaayy4.jpg > e,baixe o arquivo RegSrch.zip <!>

>@< Extraia o conteúdo do zip para o Desktop!

>@< Desabilite programas de proteção,que tenham bloqueio de scripts.

>@< Execute o arquivo RegSrch.vbs e,na janela que abrir,digite: gbiehbsb

>@< Dê o Ok.

>@< Aguarde!Na janela que surgir,clique em Ok.

>@< Surgirão informações de registro,que voçê passará ao Bloco de Notas e colará na sua resposta.

>@< Salve-o com o nome: Requisit_gbiehbsb

>@< Poste,então: Requisit_gbiehbsb.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde Digram..

 

Fiz o que sugeriu...

 

O problema com o download e o erro do explorer.exe deu certo, resolvido.

 

 

Mas quanto a dll..

No ponto que deveriam surgir as informações de regristro (q eu deveria colar no bloco de notas) aparece um erro Windows Script Host, que nao econtra o arquivo RegSrch.vbs (q esta no desktop)...

 

Mas de qualquer forma ele encontrou a dll gbiehbsb... aqui segue o log do hijack...

 

Logfile of HijackThis v1.99.1

Scan saved at 14:56, on 2008-03-24

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\hijackthis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Wireless Configuration Utility HW.15.lnk = C:\Arquivos de programas\802.11 Wireless LAN\802.11g Wireless Adapter HW.15 V.1.00\WlanCU.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) - http://install.anark.com/client/version4/w...en/AMClient.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193983298159

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://www.driveragent.com/files/driveragent.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: McAfee Application Installer Cleanup (0216361206738838) (0216361206738838mcinstcleanup) - Unknown owner - C:\DOCUME~1\Gustavo\CONFIG~1\Temp\021636~1.EXE (file missing)

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: wampapache - Unknown owner - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)

O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Gsbad

 

Mas quanto a dll..

No ponto que deveriam surgir as informações de regristro (q eu deveria colar no bloco de notas) aparece um erro Windows Script Host, que nao econtra o arquivo RegSrch.vbs (q esta no desktop)...

Mas de qualquer forma ele encontrou a dll gbiehbsb...

>@< As configurações de segurança,de seu navegador,estão impedindo a execução do script.

>@< Coloque < http://www.billsway.com/vbspage/ > como Site preferencial.

>@< Nas configurações avançadas do IE,marque:

 

Disable script debugging ( Internet Explorer )

Disable script debugging ( Other ) << ( Outros )

 

>@< Clique em Aplicar >> Ok.

______________________________

 

>@< Ps: Incluí informações,no Post anterior! Busque executar,novamente,a ferramenta.

>@< Sem o relatório da ferramenta,meu amigo,será difícil anular essa requisição/solicitação da dll.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
>@< As configurações de segurança,de seu navegador,estão impedindo a execução do script.

>@< Coloque < http://www.billsway.com/vbspage/ > como Site preferencial.

>@< Nas configurações avançadas do IE,marque:

 

Disable script debugging ( Internet Explorer )

Disable script debugging ( Other ) << ( Outros )

 

>@< Clique em Aplicar >> Ok.

 

Boa noite Digram..

 

Nao sei colocar o site citado como "Site preferencial" o que vem a ser isso? nao consigui...

 

Já as configurações avançadas do IE já estavam marcadas. Deixei como estavam.

 

Disable script debugging ( Internet Explorer ) ATIVADO

Disable script debugging ( Other ) << ( Outros ) ATIVADO

 

 

Verifiquei o post anterior (que voce atualizou), e fiz o q estava la, desabilitei qualquer programa que possa bloquear o script..

 

mas o erro persiste.. :unsure:

Compartilhar este post


Link para o post
Compartilhar em outros sites

a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro..

Compartilhar este post


Link para o post
Compartilhar em outros sites
a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro..

_______________________

 

Opa! Gsbad

Bom Dia!

 

>@< Abra o Internet Explorer.

>@< Clique em Ferramentas >> Opções da Internet>> Clique na guia Segurança.

>@< Clique em Sites Confiáveis >> Sites, no campo Adicionar este site à zona,coloque:

 

http://www.billsway.com/vbspage/

 

>@< Clique em Adicionar.

>@< Desmarque a opção: Exigir Verificação do Servidor.( https )

>@< Clique Ok,em todas as janelas.

_______________________

 

>@< Caso não funcione,reinstale o WindowsScript.

 

<!> Faça o download do Windows Script 5.6.

 

>@< Baixe-o para o Disco Local-C e instale-o aí mesmo!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
a proposito.. tentei executar o programa em Modo de segurança tambem.. sem sucesso.. tambem dá esse erro..

_______________________

 

Opa! Gsbad

Bom Dia!

 

>@< Abra o Internet Explorer.

>@< Clique em Ferramentas >> Opções da Internet>> Clique na guia Segurança.

>@< Clique em Sites Confiáveis >> Sites, no campo Adicionar este site à zona,coloque:

 

http://www.billsway.com/vbspage/

 

>@< Clique em Adicionar.

>@< Desmarque a opção: Exigir Verificação do Servidor.( https )

>@< Clique Ok,em todas as janelas.

_______________________

 

>@< Caso não funcione,reinstale o WindowsScript.

 

<!> Faça o download do Windows Script 5.6.

 

>@< Baixe-o para o Disco Local-C e instale-o aí mesmo!

 

Abraços!

 

 

Boa tarde Digram..

 

Instalei o Windows Script 5.6, reiniciei o computador e tentei eliminar a gbiehbsb novamente... não funcionou. O erro persiste.

 

E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll.

 

De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega.

 

Sera q essa dll pode estar causando isso? :blink:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Gsbad

 

E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll.

De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega.

Sera q essa dll pode estar causando isso?

>@< Eu não descartaria essa possibilidade!Mas,é bom verificar o Modem.

___________________________

 

>@< Faça o download do RegSeeker.

>@< Salve-o no Disco Local-C e descompacte-o aí mesmo,em um pasta própria.

>@< Execute o programa,com um duplo clique!

>@< Clique em Languages e selecione: Português Brasil.

>@< Clique em: Procurar por.... e,na caixa,digite: gbiehbsb

>@< Clique em: < Procurar >

>@< Selecione todos os valores encontrados e,com o botão direito do mouse,clique em: Apagar entradas selecionadas.

___________________________

 

>@< Verifique com o RegSrch.vbs,se o RegSeeker encontrou o mesmo número de objetos,indicados pelo script.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Tarde! Gsbad

 

E tem uma coisa curiosa, nao sei se pode ter algo a ver com a dll.

De 2 dias pra cá o computador tem insistentemente ficando com a conexão Nula ou limitada. Nao pega o IP de jeito nenhum. Eu tenho q esperar uns 10 minutos (com ele ligado), e ele pega.

Sera q essa dll pode estar causando isso?

>@< Eu não descartaria essa possibilidade!Mas,é bom verificar o Modem.

___________________________

 

>@< Faça o download do RegSeeker.

>@< Salve-o no Disco Local-C e descompacte-o aí mesmo,em um pasta própria.

>@< Execute o programa,com um duplo clique!

>@< Clique em Languages e selecione: Português Brasil.

>@< Clique em: Procurar por.... e,na caixa,digite: gbiehbsb

>@< Clique em: < Procurar >

>@< Selecione todos os valores encontrados e,com o botão direito do mouse,clique em: Apagar entradas selecionadas.

___________________________

 

>@< Verifique com o RegSrch.vbs,se o RegSeeker encontrou o mesmo número de objetos,indicados pelo script.

 

Abraços!

 

 

Dig ram.. cabei formatando o computador.. pode fechar o topico.. brigadao :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Gsbad

 

>@< Foi uma pena,neste momento,a formatação.

>@< Pois consegui desvendar o motivo,do erro de script e corrigi-lo.

 

<!> Leia: < http://forum.imasters.com.br/index.php?showtopic=279024 >

 

>@< Por meio de pesquisas,observei que alguns colegas,ao passar o procedimento,paravam neste erro.

>@< E,no meu próprio PC,ocorreu o mesmo problema.

>@< Daí,não tive alternativas e estudei o scripts,modificando alguns parâmetros.

>@< Mas,valeu a experiência!

>@< O Tópico será fechado,como Resolvido...não da forma como gostaria!

 

Abraços! :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.