Edmero 0 Denunciar post Postado Abril 17, 2008 Olá, eu sou novo neste fórum, e tenho problema com pop-ups, aparecem a cada 5 minutos. Aqui vai o log do Hijack: Logfile of HijackThis v1.99.1 Scan saved at 20:31:43, on 17-04-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programas\ESET\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Java\jre1.6.0_05\bin\jusched.exe C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\Programas\Stop-the-Pop-Up Lite\stopthepop.exe C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Programas\Windows Defender\MSASCui.exe C:\Programas\ESET\ESET Smart Security\egui.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\ctfmon.exe C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programas\Windows Live\Messenger\MsnMsgr.Exe C:\Programas\Windows Sidebar\sidebar.exe C:\Programas\eMule\emule.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\Programas\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\MsPMSPSv.exe C:\Programas\Windows Sidebar\sidebar.exe C:\Programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\Programas\Internet Explorer\iexplore.exe C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe D:\Programas\IEPro\MiniDM.exe C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file) R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file) O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe" O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 18, 2008 Bom Dia! Edmero <!> DESINSTALE: < Stop-the-Pop-Up > <!> Após desinstalar,reinicie o computador! ------------------------- >@< Faça o download do LopS&D. >@< Salve-o no Disco Local-C. >@< Instale o programa e clique em: LopSD.cmd >@< Na janela que abrir,aperte o "p" >> Aperte Enter. >@< Em outra janela,aperte a opção 2 >> Aperte Enter >> Aguarde! >@< Terminando,salve e poste o relatório. ( C:\lopR.txt ) >@< Poste,também,HJT atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 18, 2008 Bom Dia! Aqui vai o relatório do LopS&D: -----------------------[ Lop S&D 4.1.1-3 XP/Vista ]--------------------- [ Windows XP (NT 5.1) Build 2600, Service Pack 2 ] [ USER : Alcides Lopes ] [ "C:\Lop SD" ] [ 18-04-2008 | 19:10:12,92 ] [ PC : ALCIDES-4E370DC ] [ MAJ : 17-04-2008 | 19:51 ] \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS //////////////////////////////// Arquivos/Ficheiros Hosts RESTAURADO //////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ -------------[ Lista de pastas em Application Data ]------------ [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\. [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\.. [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini [19-12-2007|21:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\. [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\.. [19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\desktop.ini [19-12-2007|21:09] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\Microsoft [14-04-2008|12:41] C:\DOCUME~1\ALCIDE~1\APPLIC~1\. [14-04-2008|12:41] C:\DOCUME~1\ALCIDE~1\APPLIC~1\.. [04-02-2008|12:54] C:\DOCUME~1\ALCIDE~1\APPLIC~1\ACD Systems [17-03-2008|14:27] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Adobe [13-01-2008|12:35] C:\DOCUME~1\ALCIDE~1\APPLIC~1\AdobeUM [05-01-2008|23:28] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Ahead [12-02-2008|12:48] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Apple Computer [07-02-2008|22:20] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Avant Profiles [14-04-2008|19:24] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Creative [19-12-2007|20:58] C:\DOCUME~1\ALCIDE~1\APPLIC~1\desktop.ini [05-04-2008|14:06] C:\DOCUME~1\ALCIDE~1\APPLIC~1\ESET [19-03-2008|21:43] C:\DOCUME~1\ALCIDE~1\APPLIC~1\flightgear.org [14-02-2008|21:38] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Google [01-04-2008|22:23] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Help [19-12-2007|21:16] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Identities [12-04-2008|23:16] C:\DOCUME~1\ALCIDE~1\APPLIC~1\IEPro [22-01-2008|13:54] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Leadertech [26-03-2008|01:01] C:\DOCUME~1\ALCIDE~1\APPLIC~1\LimeWire [09-02-2008|00:21] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Macromedia [10-04-2008|20:00] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Microsoft [09-04-2008|21:55] C:\DOCUME~1\ALCIDE~1\APPLIC~1\MiniDm [09-04-2008|21:39] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Mozilla [22-03-2008|17:20] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Nero [13-04-2008|00:31] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Real [06-01-2008|14:35] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Sun [19-12-2007|21:37] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Symantec [07-02-2008|22:56] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Talkback [20-02-2008|21:02] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Template [18-02-2008|22:18] C:\DOCUME~1\ALCIDE~1\APPLIC~1\UOL [08-01-2008|22:46] C:\DOCUME~1\ALCIDE~1\APPLIC~1\WinRAR [15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\. [15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.. [22-02-2008|22:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [23-02-2008|23:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Backup [15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CenerTCPMessenger [14-04-2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini [27-02-2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink [05-04-2008|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET [12-03-2008|00:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet [16-03-2008|19:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google [20-12-2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus! [10-04-2008|19:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [09-02-2008|16:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help [22-03-2008|17:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero [31-12-2007|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\sentinel [29-03-2008|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy [31-12-2007|20:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [17-03-2008|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP [18-02-2008|22:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UOL [19-12-2007|23:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [10-04-2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar [11-03-2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [13-02-2008|00:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [19-12-2007|20:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\. [19-12-2007|20:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.. [14-04-2008|12:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini [19-12-2007|21:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [19-12-2007|21:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\. [19-12-2007|21:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\.. [20-12-2007|12:57] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\. [19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\.. [19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft Relatório do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:16:59, on 18-04-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programas\ESET\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programas\Java\jre1.6.0_05\bin\jusched.exe C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Programas\Windows Defender\MSASCui.exe C:\Programas\ESET\ESET Smart Security\egui.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\ctfmon.exe C:\Programas\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Programas\WinZip\WZQKPICK.EXE C:\Programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe D:\Programas\IEPro\MiniDM.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Alcides Lopes\Definições locais\Temp\wz5870\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file) R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file) O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe" O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 19, 2008 Boa Noite! Edmero >@< Reinicie o computador,em Modo de Segurança. >@< Abra o HijackThis e,clique em Do a system scan only. >@< Marque as entradas,logo abaixo,e clique em Fix checked. << Marque as que encontrar! R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file)R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file) O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe >@< Ainda em Modo Seguro,procure deletar este ficheiro: C:\Windows\FrWall.exe << Delete! >@< Reinicie em Modo Normal. ------------------------------ >@< Poste: HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 19, 2008 Bom Dia! Aqui vai o log do HijackThis, actualizado: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:49:28, on 19-04-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programas\ESET\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programas\Java\jre1.6.0_05\bin\jusched.exe C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Programas\Windows Defender\MSASCui.exe C:\Programas\ESET\ESET Smart Security\egui.exe C:\WINDOWS\CTHELPER.EXE C:\Programas\Windows Live\Messenger\MsnMsgr.Exe C:\Programas\Windows Sidebar\sidebar.exe D:\Programas\VisualTaskTips\VisualTaskTips.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Sidebar\sidebar.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Programas\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\wuauclt.exe C:\Programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\Programas\Internet Explorer\iexplore.exe C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Alcides Lopes\Definições locais\Temp\wz4a39\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe" O4 - HKCU\..\Run: [VisualTaskTips] D:\Programas\VisualTaskTips\VisualTaskTips.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ViStart] C:\DOCUME~1\ALCIDE~1\DEFINI~1\Temp\Rar$EX04.375\ViStart 5259 Theme\ViStart 2490 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe -- End of file - 8019 bytes Muito Obrigado e um grande abraço! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 19, 2008 Boa Tarde! Edmero >@< BAIXE: < KillBox > >@< Salve-o numa pasta,em C:/ ------------------------------ >@< Abra o KillBox >> Marque a opção: Delete on Reboot >@< Copie a lista,sob o quote,para o Bloco de Notas. >@< No Bloco de Notas,deixe: ( Ctrl + a ) >> ( Ctrl + c ) C:\Windows\System32\WinSecure.exeC:\Windows\System32\NTSpool.exe >@< No KillBox,clique em File >> Paste from clipboard >> Clique no botão All Files. >@< Clique no X e,na pergunta.Diga Não! >@< Reinicie o computador! >@< Abra o HijackThis >> Clique: Do a system scan only O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exeO4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe >@< Marque as entradas,àcima,e clique em Fix checked. >@< Terminando,feche o programa. ------------------------------ >@< Faça e poste: HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 19, 2008 Boa Tarde! O log do HijackThis actualizado: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:11:53, on 19-04-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programas\Java\jre1.6.0_05\bin\jusched.exe C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Programas\Windows Defender\MSASCui.exe C:\Programas\ESET\ESET Smart Security\egui.exe C:\WINDOWS\CTHELPER.EXE C:\Programas\ESET\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programas\Windows Live\Messenger\MsnMsgr.Exe C:\Programas\Windows Sidebar\sidebar.exe D:\Programas\VisualTaskTips\VisualTaskTips.exe C:\WINDOWS\system32\ctfmon.exe C:\Programas\eMule\emule.exe C:\Programas\Windows Sidebar\sidebar.exe C:\Programas\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Styler\Styler.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Programas\Internet Explorer\IEXPLORE.EXE C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe D:\Programas\Hijack\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Programas\Styler\TB\StylerTB.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [VisualTaskTips] D:\Programas\VisualTaskTips\VisualTaskTips.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ViStart] C:\DOCUME~1\ALCIDE~1\DEFINI~1\Temp\Rar$EX04.375\ViStart 5259 Theme\ViStart 2490 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Styler.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe -- End of file - 7720 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 19, 2008 Boa Tarde! Edmero <!> As pop-ups,ainda,lhe incomodam? -------------------------------- >@< Faça o download do a-squared Free 3.5 Link Opcional: < > >@< Abra o programa e clique em: Atualizar agora >> Aguarde! >@< Terminando,clique em: Analisar agora. >@< Caso possa,procure fazer,esta análise,em Modo de Segurança! >@< Escolha a opção: A fundo >@< Clique em Analisar! >@< Terminando,envie os ítens encontrados para a quarentena. << Importante! >@< Aonde,daí,serão excluídos ou restaurados. >@< Salve o relatório,desta verificação,e poste na sua resposta. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 19, 2008 Muito Obrigado! As pop-ups já não me chateiam! Relatório do A-squared: a-squared Free - Versão 3.5 Última atualização 19-04-2008 22:23:23 Configurações da análise: Objetos: Memória, Rastros, Cookies, C:\WINDOWS\, C:\Programas Análise de arquivos: Ligado Heurística: Ligado Análise de ADS: Ligado Início da análise: 19-04-2008 22:23:59 Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AlertStyle(0) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineHotKey detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineModifier detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayHotKey detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayModifier detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyHotKey detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyModifier detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardHotKey detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardModifier detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> CloseAlert(0) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> elO(0) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> GroupChoice detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineHotKey detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineModifier detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OpenSensitivity(0) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup0 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup1 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup10 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup2 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup3 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup4 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup5 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup6 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup7 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup8 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup9 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> RSOTime detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(13) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(2) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(22) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(37) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(44) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(7) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider1 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechSpeed detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechVolume detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Time_Format detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(1) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(11) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(16) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(6) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(9) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MDLCap detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu1 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu2 detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(0) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(1) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(2) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(3) detectado: Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> WLMCaption detectado: Trace.Registry.DiscoveryLive Value: HKEY_LOCAL_MACHINE\SOFTWARE\Matt Holwood\MessengerDiscovery Live --> InstallDirectory detectado: Trace.Registry.DiscoveryLive c:\windows\system32\dijpg.dll detectado: Trace.File.ComKeylogger Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} detectado: Trace.Registry.YuupSearchToolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName detectado: Trace.Registry.Sniffem 1.1 Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString detectado: Trace.Registry.Sniffem 1.1 C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@atdmt[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[4].txt detectado: Trace.TrackingCookie Analisado Arquivos: 101591 Objetos: 390394 Cookies: 64 Processos: 45 Encontrado Arquivos: 0 Objetos: 56 Cookies: 3 Processos: 0 Chaves do registro: 0 Fim da análise: 19-04-2008 23:54:49 Duração da análise: 1:30:50 C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@atdmt[1].txt Em quarentena Trace.TrackingCookie C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[1].txt Em quarentena Trace.TrackingCookie C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[4].txt Em quarentena Trace.TrackingCookie Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName Em quarentena Trace.Registry.Sniffem 1.1 Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString Em quarentena Trace.Registry.Sniffem 1.1 Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} Em quarentena Trace.Registry.YuupSearchToolbar c:\windows\system32\dijpg.dll Em quarentena Trace.File.ComKeylogger Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AlertStyle(0) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineHotKey Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineModifier Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayHotKey Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayModifier Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyHotKey Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyModifier Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardHotKey Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardModifier Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> CloseAlert(0) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> elO(0) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> GroupChoice Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineHotKey Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineModifier Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OpenSensitivity(0) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup0 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup1 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup10 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup2 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup3 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup4 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup5 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup6 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup7 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup8 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup9 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> RSOTime Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(13) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(2) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(22) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(37) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(44) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(7) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider1 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechSpeed Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechVolume Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Time_Format Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(1) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(11) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(16) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(6) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(9) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MDLCap Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu1 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu2 Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(0) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(1) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(2) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(3) Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> WLMCaption Em quarentena Trace.Registry.DiscoveryLive Value: HKEY_LOCAL_MACHINE\SOFTWARE\Matt Holwood\MessengerDiscovery Live --> InstallDirectory Em quarentena Trace.Registry.DiscoveryLive Em quarentena Arquivos: 0 Objetos: 56 Cookies: 3 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 20, 2008 Bom Dia! Edmero >@< Por alguns dias,deixe estes objetos em quarentena e,estando tudo Ok,pode eliminá-los. ------------------------------- Estando tudo Ok com o PC,crie um Ponto de Restauração do Sistema,completamente Limpo!Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok. Depois,desmarque novamente! >> Aplicar >> Ok. Para maiores detalhes,vá em:< Docs > ------------------------------- >@< O log está limpo! >@< Bom trabalho! :thumbsup: Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 20, 2008 Errrrrrrr.................. Eu fiz porcaria, eleminei os itens da quarentena e voltaram a aparecer. Agora o que eu faço? Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 20, 2008 Errrrrrrr.................. Eu fiz porcaria, eleminei os itens da quarentena e voltaram a aparecer. Agora o que eu faço? ----------------------------- Opa! Edmero Boa Tarde! >@< Não se preocupe,pois são Falsos Positivos do a-squared,em sua máxima heurística. >@< Alguns,dos detectados,poderiam ser eliminados: Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName Em quarentena Trace.Registry.Sniffem 1.1 Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString Em quarentena Trace.Registry.Sniffem 1.1 Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} Em quarentena Trace.Registry.YuupSearchToolbar c:\windows\system32\dijpg.dll Em quarentena Trace.File.ComKeylogger >@< Faça um novo scan,em Modo Normal,na opção Inteligente. >@< Procure eliminar,somente,o que está no Quote. << Caso existam! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 22, 2008 Bom dia! Fiz um novo scan com a-squared e desta vez não detectou nada, e as pop-ups continuam a aparecer. Muito Obrigado pela ajuda! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 22, 2008 Bom dia!Fiz um novo scan com a-squared e desta vez não detectou nada, e as pop-ups continuam a aparecer. Muito Obrigado pela ajuda! --------------------------- Opa! Edmero Boa Tarde! >@< Faça o download do ComboFix. >@< Baixe-o para o Desktop! >@< Desabilite as proteções residente de: antivírus,antispywares e Firewall. >@< Feche todas as janelas e execute a ferramenta! Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.Salve-a no Desktop,renomeada como: Kombo.exe Ps: Nomeie durante o salvamento,e não após salvá-la! >@< Abrirá a janela Auto Scan. Aguarde! >@< Digite a opção para continuar e < Enter > >@< Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! --------------------------- >@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 22, 2008 Boa Tarde! Log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:01:17, on 22-04-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programas\a-squared Free\a2service.exe C:\Programas\Comodo\Firewall\cmdagent.exe C:\Programas\ESET\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Programas\Java\jre1.6.0_05\bin\jusched.exe C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Programas\Windows Defender\MSASCui.exe C:\Programas\ESET\ESET Smart Security\egui.exe C:\WINDOWS\CTHELPER.EXE C:\Programas\Comodo\Firewall\CPF.exe C:\Programas\Windows Live\Messenger\MsnMsgr.Exe C:\Programas\Windows Sidebar\sidebar.exe C:\WINDOWS\system32\ctfmon.exe C:\Programas\Spybot - Search & Destroy\TeaTimer.exe C:\Programas\WinZip\WZQKPICK.EXE C:\Programas\Windows Sidebar\sidebar.exe C:\WINDOWS\explorer.exe C:\Programas\Vistart\Slate\ViStart.exe C:\Programas\Internet Explorer\IEXPLORE.EXE C:\Programas\Windows Live\Messenger\usnsvc.exe D:\Programas\IEPro\MiniDM.exe D:\Programas\Hijack\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programas\Comodo\Firewall\CPF.exe" /background O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\TrueTransparency\TrueTransparency.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart O4 - HKCU\..\Run: [ViStart] C:\Programas\Vistart\Slate\ViStart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: VistaStart.lnk = ? O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe (file missing) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programas\a-squared Free\a2service.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programas\Comodo\Firewall\cmdagent.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe -- End of file - 8287 bytes Relatório do ComboFix: ComboFix 08-04-20.5 - Alcides Lopes 2008-04-22 19:30:28.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.2070.18.568 [GMT 1:00] Executando de: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\ComboFix.exe * Criado um novo ponto de restauro * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\ponto.DLL C:\WINDOWS\system32\drivers\core.cache(10).dsk C:\WINDOWS\system32\drivers\core.cache(2).dsk C:\WINDOWS\system32\drivers\core.cache(3).dsk C:\WINDOWS\system32\drivers\core.cache(4).dsk C:\WINDOWS\system32\drivers\core.cache(5).dsk C:\WINDOWS\system32\drivers\core.cache(6).dsk C:\WINDOWS\system32\drivers\core.cache(7).dsk C:\WINDOWS\system32\drivers\core.cache(8).dsk C:\WINDOWS\system32\drivers\core.cache(9).dsk C:\WINDOWS\system32\drivers\down C:\WINDOWS\youtubex.dll C:\WINDOWS\system32\drivers\core.cache.dsk . . . . falha na exclusão . ((((((((((((((((((((((( Ficheiros criados de 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))) . 2008-04-22 19:35 . 2008-04-22 19:35 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.BAK 2008-04-22 19:26 . 2008-04-22 19:26 <DIR> d-------- C:\Programas\Arquivos de programas 2008-04-22 19:08 . 2006-03-17 05:03 12,955,648 --a------ C:\WINDOWS\system32\shell32.dll.backup 2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo 2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Comodo 2008-04-22 12:06 . 2008-04-20 12:30 211 --a------ C:\boot.ini.comodofirewall 2008-04-22 12:04 . 2008-04-22 12:04 <DIR> d-------- C:\Programas\Comodo 2008-04-21 23:18 . 2008-04-21 23:13 691,545 --a------ C:\WINDOWS\unins000.exe 2008-04-21 23:18 . 2008-04-21 23:18 2,561 --a------ C:\WINDOWS\unins000.dat 2008-04-21 23:00 . 2008-04-22 11:08 <DIR> d-------- C:\Programas\Spybot - Search & Destroy 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Programas\IconTweaker 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IconTweaker 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IconTweaker 2008-04-20 17:40 . 2008-04-20 17:40 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2008-04-20 14:39 . 2008-04-20 14:39 <DIR> d-------- C:\Programas\Ficheiros comuns\Ulead Systems 2008-04-20 14:37 . 2008-04-22 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems 2008-04-19 22:18 . 2008-04-19 23:54 <DIR> d-------- C:\Programas\a-squared Free 2008-04-19 20:01 . 2008-04-19 20:01 <DIR> d-------- C:\Programas\Logon Loader 2008-04-19 18:57 . 2008-04-19 18:57 <DIR> d-------- C:\Programas\KillBox 2008-04-19 00:34 . 2008-04-19 00:34 1,979 --a------ C:\WINDOWS\system32\shell32.dll.manifest 2008-04-19 00:32 . 2008-04-19 00:34 8,451,072 --a------ C:\WINDOWS\system32\shell32.dll.patched 2008-04-18 23:21 . 2008-04-18 23:21 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Styler 2008-04-18 22:10 . 2008-04-18 23:48 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ViStart 2008-04-18 22:09 . 2008-04-21 21:14 <DIR> d-------- C:\Programas\Vistart 2008-04-18 19:09 . 2008-04-20 18:20 <DIR> d-------- C:\Lop SD 2008-04-17 19:29 . 2008-04-22 19:17 <DIR> d-------- C:\!KillBox 2008-04-16 19:21 . 2008-04-16 19:22 58 --a------ C:\WINDOWS\WinNetOptimize98ag.cfg 2008-04-15 20:19 . 2008-04-15 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CenerTCPMessenger 2008-04-15 20:09 . 2008-04-15 20:09 <DIR> d-------- C:\WINDOWS\l2schemas 2008-04-15 20:09 . 2008-04-15 21:59 <DIR> d-------- C:\Programas\Windows Sidebar 2008-04-14 19:27 . 2008-04-22 19:36 31,812 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-22 19:36 31,812 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-22 19:36 31,440 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-22 19:36 31,440 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-22 19:36 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-22 19:36 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm 2008-04-14 19:27 . 2008-04-22 19:36 1,080 --a------ C:\WINDOWS\system32\settings.sfm 2008-04-14 19:26 . 2008-04-22 19:35 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.CDF 2008-04-14 19:23 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini 2008-04-14 12:32 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll 2008-04-14 12:31 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\WindowsShell.Manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\wuaucpl.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\sapi.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\ncpa.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 488 -ra------ C:\WINDOWS\system32\logonui.exe.manifest 2008-04-14 12:18 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll 2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll 2008-04-13 18:08 . 2008-04-13 18:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Os meus documentos 2008-04-13 18:08 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Modelos 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Menu Iniciar 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Favoritos 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Defini‡äes locais 2008-04-13 18:08 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Ambiente de trabalho 2008-04-13 18:08 . 2008-04-16 19:00 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC 2008-04-13 18:08 . 2008-04-22 19:30 1,024 --ah----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\NtUser.dat.LOG 2008-04-13 00:11 . 2000-10-11 14:11 121,562 --a------ C:\WINDOWS\system32\PicFormat32.dll 2008-04-13 00:11 . 2000-10-11 13:22 36,864 --a------ C:\WINDOWS\system32\PicFormat32.ocx 2008-04-10 20:33 . 2008-04-22 19:30 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG 2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar 2008-04-09 21:55 . 2008-04-09 21:55 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\MiniDm 2008-04-09 21:54 . 2008-04-12 23:16 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IEPro 2008-04-05 14:06 . 2008-04-05 14:06 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ESET 2008-04-05 11:46 . 2008-04-05 11:46 65,024 --a------ C:\WINDOWS\system32\ssleay32.dll 2008-04-05 11:46 . 2008-04-05 11:46 29,525 --a------ C:\WINDOWS\system32\libeay32.dll 2008-04-05 11:45 . 2008-04-05 11:46 299,520 --a------ C:\WINDOWS\messengrs.exe 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Os meus documentos 2008-03-31 10:56 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador\Defini‡äes locais 2008-03-31 10:56 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador\Ambiente de trabalho 2008-03-31 10:56 . 2008-03-31 10:56 <DIR> d-------- C:\Documents and Settings\Administrador 2008-03-31 10:56 . 2008-04-22 19:30 1,024 --ah----- C:\Documents and Settings\Administrador\NtUser.dat.LOG 2008-03-29 20:49 . 2008-03-29 20:49 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2008-03-29 17:27 . 2008-03-29 17:27 <DIR> d-------- C:\Programas\Windows Defender 2008-03-29 17:06 . 2008-03-29 17:06 101 --a------ C:\WINDOWS\wininit.ini 2008-03-28 22:09 . 2008-04-22 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-03-28 13:12 . 2008-04-05 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET 2008-03-27 22:40 . 2008-04-05 15:31 <DIR> d-------- C:\Programas\Eset 2008-03-27 21:15 . 2008-04-22 19:41 <DIR> d-------- C:\Programas\eMule 2008-03-26 21:07 . 2008-03-26 21:07 <DIR> d-------- C:\Programas\Ficheiros comuns\SWF Studio 2008-03-26 01:18 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-03-26 00:59 . 2008-04-13 00:32 <DIR> d-------- C:\Programas\Ficheiros comuns\Real 2008-03-22 17:20 . 2008-03-22 17:20 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Nero 2008-03-22 17:14 . 2008-03-22 17:17 <DIR> d-------- C:\Programas\Ficheiros comuns\Nero 2008-03-22 17:14 . 2008-03-22 17:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-22 18:37 167,545 ----a-w C:\WINDOWS\system32\drivers\core.cache.dsk 2008-04-22 18:18 --------- d-----w C:\Programas\Messenger Plus! Live 2008-04-22 18:14 --------- d--h--w C:\Programas\InstallShield Installation Information 2008-04-21 18:03 --------- d-----w C:\Programas\Windows Live 2008-04-20 11:28 --------- d-----w C:\Programas\Gestão de Ficheiros DRI 2008-04-18 18:34 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2008-04-14 18:48 --------- d-----w C:\Programas\Program Files 2008-04-14 18:26 --------- d-----w C:\Programas\Creative 2008-04-14 18:25 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-04-14 18:25 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-04-14 18:24 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Creative 2008-03-30 11:01 98,304 ----a-w C:\WINDOWS\DUMP5880.tmp 2008-03-28 00:08 --------- d-----w C:\Programas\Ficheiros comuns\Panda Software 2008-03-26 00:18 --------- d-----w C:\Programas\Java 2008-03-26 00:01 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\LimeWire 2008-03-22 16:14 --------- d-----w C:\Programas\Nero 2008-03-22 16:14 --------- d-----w C:\Programas\Ficheiros comuns\Ahead 2008-03-19 20:43 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\flightgear.org 2008-03-17 16:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-03-12 12:57 --------- d-----w C:\Programas\Ficheiros comuns\Adobe 2008-03-11 23:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet 2008-03-11 23:22 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared 2008-03-11 23:20 --------- d-----w C:\Programas\Ficheiros comuns\ACD Systems 2008-03-11 22:41 --------- d-----w C:\Programas\Ficheiros comuns\Macrovision Shared 2008-03-11 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip 2008-03-06 17:57 63,488 ----a-w C:\WINDOWS\system32\drivers\phmcd.sys 2008-03-04 19:47 286,720 ----a-w C:\WINDOWS\iun507.exe 2008-02-27 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink 2008-02-26 11:41 --------- d-----w C:\Programas\Shield 2008-02-25 22:19 --------- d-----w C:\Programas\Ficheiros comuns\InstallShield 2008-02-23 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Backup 2008-02-23 21:44 37,888 ----a-w C:\WINDOWS\system32\rar.exe 2008-02-16 20:31 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE 2008-02-16 20:31 249,856 ----a-w C:\WINDOWS\Setup1.exe 2008-01-31 20:53 720,896 ----a-w C:\WINDOWS\iun6002ev.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" [ ] "MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184] "updateMgr"="C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ] "Sidebar"="C:\Programas\Windows Sidebar\sidebar.exe" [2007-07-28 14:53 1230848] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "TrueTransparency"="D:\Programas\TrueTransparency\TrueTransparency.exe" [ ] "SpybotSD TeaTimer"="C:\Programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] "eMuleAutoStart"="C:\Programas\eMule\emule.exe" [2007-05-13 15:57 5308416] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784] "SBDrvDet"="C:\Programas\Creative\SB Drive Det\SBDrvDet.exe" [ ] "OrderReminder"="C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 12:18 98304] "Adobe Reader Speed Launcher"="C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "Adobe Photo Downloader"="C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712] "NeroFilterCheck"="C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136] "NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 10:25 1828136] "Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584] "egui"="C:\Programas\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072] "CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE] "CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE] "COMODO Firewall Pro"="C:\Programas\Comodo\Firewall\CPF.exe" [2008-04-22 12:03 1115728] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] "DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2006-04-25 22:26 423184] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque\ WinZip Quick Pick.lnk - C:\Programas\WinZip\WZQKPICK.EXE [2008-03-11 22:14:55 389120] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.ACDV"= ACDV.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart] --a------ 2007-05-13 15:57 5308416 C:\Programas\eMule\emule.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueTransparency] D:\Programas\True Transparency\TrueTransparency.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programas\\eMule\\emule.exe"= "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "D:\\Programas\\IEPro\\MiniDM.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 phmcd;phmcd;C:\WINDOWS\system32\DRIVERS\phmcd.sys [2008-03-06 18:57] R1 udfss;udfss;C:\WINDOWS\system32\drivers\udfss.sys [2008-02-05 01:27] R2 PfDetNT;PfDetNT;C:\WINDOWS\system32\drivers\PfModNT.sys [2006-08-11 14:56] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a90845-0e43-11dd-b012-000feaa3ca56}] \Shell\AutoRun\command - RavMon.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c7ee7e-c761-11dc-aeb1-000feaa3ca56}] \Shell\AutoRun\command - ntde1ect.com \Shell\explore\Command - ntde1ect.com \Shell\open\Command - ntde1ect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59ce48b0-c68a-11dc-aea9-000feaa3ca56}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MSI.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cea8328c-0ebe-11dd-b013-000feaa3ca56}] \Shell\AutoRun\command - RavMon.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e37d3552-af21-11dc-ae41-000feaa3ca56}] \Shell\Auto\command - RavMon.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMon.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0b81609-e849-11dc-af54-000feaa3ca56}] \Shell\AutoRun\command - RavMon.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}] "C:\Programas\Windows Sidebar\sidebar.exe" /RegServer . Conte£do da pasta 'Tarefas Agendadas' "2008-04-22 18:40:40 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Programas\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-22 19:38:33 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 454 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Programas\Windows Defender\MsMpEng.exe C:\Programas\a-squared Free\a2service.exe C:\Programas\Comodo\Firewall\cmdagent.exe C:\Programas\Eset\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\snmp.exe C:\WINDOWS\system32\MsPMSPSv.exe . ************************************************************************** . Tempo para conclusÆo: 2008-04-22 19:47:30 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-22 18:46:42 Pre-Run: 202,822,377,472 bytes livres Post-Run: 205,397,110,784 bytes livres 263 --- E O F --- 2008-04-22 11:35:58 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 22, 2008 Boa Noite! Edmero Antes de executar este procedimento,insira sua(s) unidade(s) removíveis,na entrada USB. ------------------------ <!> Delete: C:\QooBox C:\ComboFix.txt << Log anterior do ComboFix. ------------------------ >@< Selecione e copie,todo o conteúdo que está na área do quote,para o Bloco de Notas. >@< Salve-o,no Desktop,com o nome: CFScript.txt File::C:\WINDOWS\system32\drivers\core.cache.dsk C:\WINDOWS\system32\DRIVERS\phmcd.sys C:\WINDOWS\system32\drivers\udfss.sys C:\WINDOWS\messengrs.exe Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a90845-0e43-11dd-b012-000feaa3ca56}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c7ee7e-c761-11dc-aeb1-000feaa3ca56}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cea8328c-0ebe-11dd-b013-000feaa3ca56}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e37d3552-af21-11dc-ae41-000feaa3ca56}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0b81609-e849-11dc-af54-000feaa3ca56}] Driver:: "phmcd" "udfss" Folder:: C:\!KillBox >@< Arraste,com o Mouse,o CFScript.txt para o ícone do ComboFix. >@< Veja a demonstração! >@< Com esse procedimento,o ComboFix irá executar e,reiniciará o computador,automaticamente! >@< Caso não reinicie,faça-o manualmente! >@< Durante a execução,não utilize o teclado ou Mouse! >@< Terminando,poste o relatório C:\ComboFix.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 23, 2008 Boa Tarde! Relatório do ComboFix: ComboFix 08-04-20.5 - Alcides Lopes 2008-04-23 19:55:02.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.2070.18.528 [GMT 1:00] Executando de: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\ComboFix.exe Command switches used :: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\CFScript.txt.txt * Criado um novo ponto de restauro * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\!KillBox C:\!KillBox\Logs\kb.log C:\WINDOWS\system32\drivers\core.cache.dsk . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_UDFSS -------\Service_udfss ((((((((((((((((((((((( Ficheiros criados de 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))) . 2008-04-22 23:44 . 2008-04-23 20:01 4,958,588 --------- C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.BAK 2008-04-22 21:27 . 2008-04-22 21:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus! 2008-04-22 21:03 . 2008-04-22 21:04 <DIR> d-------- C:\Programas\ComboFix 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definições locais 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\NetworkService\Definições locais 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\LocalService\Definições locais 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Default User\Definições locais 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Definições locais 2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Definições locais 2008-04-22 19:26 . 2008-04-22 19:26 <DIR> d-------- C:\Programas\Arquivos de programas 2008-04-22 19:08 . 2006-03-17 05:03 12,955,648 --a------ C:\WINDOWS\system32\shell32.dll.backup 2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo 2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Comodo 2008-04-22 12:06 . 2008-04-20 12:30 211 --a------ C:\boot.ini.comodofirewall 2008-04-22 12:04 . 2008-04-23 19:20 <DIR> d-------- C:\Programas\Comodo 2008-04-21 23:18 . 2008-04-21 23:13 691,545 --a------ C:\WINDOWS\unins000.exe 2008-04-21 23:18 . 2008-04-21 23:18 2,561 --a------ C:\WINDOWS\unins000.dat 2008-04-21 23:00 . 2008-04-22 11:08 <DIR> d-------- C:\Programas\Spybot - Search & Destroy 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Programas\IconTweaker 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IconTweaker 2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IconTweaker 2008-04-20 17:40 . 2008-04-20 17:40 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2008-04-20 14:39 . 2008-04-20 14:39 <DIR> d-------- C:\Programas\Ficheiros comuns\Ulead Systems 2008-04-20 14:37 . 2008-04-22 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems 2008-04-19 22:18 . 2008-04-19 23:54 <DIR> d-------- C:\Programas\a-squared Free 2008-04-19 20:01 . 2008-04-22 23:21 <DIR> d-------- C:\Programas\Logon Loader 2008-04-19 18:57 . 2008-04-19 18:57 <DIR> d-------- C:\Programas\KillBox 2008-04-19 00:34 . 2008-04-19 00:34 1,979 --a------ C:\WINDOWS\system32\shell32.dll.manifest 2008-04-19 00:32 . 2008-04-19 00:34 8,451,072 --a------ C:\WINDOWS\system32\shell32.dll.patched 2008-04-18 23:21 . 2008-04-18 23:21 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Styler 2008-04-18 22:10 . 2008-04-18 23:48 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ViStart 2008-04-18 22:09 . 2008-04-22 19:56 <DIR> d-------- C:\Programas\Vistart 2008-04-18 19:09 . 2008-04-20 18:20 <DIR> d-------- C:\Lop SD 2008-04-16 19:21 . 2008-04-16 19:22 58 --a------ C:\WINDOWS\WinNetOptimize98ag.cfg 2008-04-15 20:19 . 2008-04-15 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CenerTCPMessenger 2008-04-15 20:09 . 2008-04-15 20:09 <DIR> d-------- C:\WINDOWS\l2schemas 2008-04-15 20:09 . 2008-04-23 19:06 <DIR> d-------- C:\Programas\Windows Sidebar 2008-04-14 19:27 . 2008-04-23 20:05 31,812 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-23 20:05 31,812 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-23 20:05 31,440 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-23 20:05 31,440 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-23 20:05 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx 2008-04-14 19:27 . 2008-04-23 20:05 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm 2008-04-14 19:27 . 2008-04-23 20:05 1,080 --a------ C:\WINDOWS\system32\settings.sfm 2008-04-14 19:26 . 2008-04-23 20:01 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.CDF 2008-04-14 19:23 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini 2008-04-14 12:32 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll 2008-04-14 12:31 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\WindowsShell.Manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\wuaucpl.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\sapi.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\ncpa.cpl.manifest 2008-04-14 12:29 . 2008-04-14 12:29 488 -ra------ C:\WINDOWS\system32\logonui.exe.manifest 2008-04-14 12:18 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll 2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll 2008-04-13 18:08 . 2008-04-13 18:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Os meus documentos 2008-04-13 18:08 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Modelos 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Menu Iniciar 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Favoritos 2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Defini‡äes locais 2008-04-13 18:08 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Ambiente de trabalho 2008-04-13 18:08 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC 2008-04-13 18:08 . 2008-04-23 19:54 1,024 --ah----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\NtUser.dat.LOG 2008-04-13 00:11 . 2000-10-11 14:11 121,562 --a------ C:\WINDOWS\system32\PicFormat32.dll 2008-04-13 00:11 . 2000-10-11 13:22 36,864 --a------ C:\WINDOWS\system32\PicFormat32.ocx 2008-04-10 20:33 . 2008-04-23 19:54 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG 2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar 2008-04-09 21:55 . 2008-04-09 21:55 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\MiniDm 2008-04-09 21:54 . 2008-04-12 23:16 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IEPro 2008-04-05 14:06 . 2008-04-05 14:06 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ESET 2008-04-05 11:46 . 2008-04-05 11:46 65,024 --a------ C:\WINDOWS\system32\ssleay32.dll 2008-04-05 11:46 . 2008-04-05 11:46 29,525 --a------ C:\WINDOWS\system32\libeay32.dll 2008-04-05 11:45 . 2008-04-05 11:46 299,520 --a------ C:\WINDOWS\messengrs.exe 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Os meus documentos 2008-03-31 10:56 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos 2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador\Defini‡äes locais 2008-03-31 10:56 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador\Ambiente de trabalho 2008-03-31 10:56 . 2008-03-31 10:56 <DIR> d-------- C:\Documents and Settings\Administrador 2008-03-31 10:56 . 2008-04-23 19:54 1,024 --ah----- C:\Documents and Settings\Administrador\NtUser.dat.LOG 2008-03-29 20:49 . 2008-03-29 20:49 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2008-03-29 17:27 . 2008-03-29 17:27 <DIR> d-------- C:\Programas\Windows Defender 2008-03-29 17:06 . 2008-03-29 17:06 101 --a------ C:\WINDOWS\wininit.ini 2008-03-28 22:09 . 2008-04-22 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-03-28 13:12 . 2008-04-05 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET 2008-03-27 22:40 . 2008-04-05 15:31 <DIR> d-------- C:\Programas\Eset 2008-03-27 21:15 . 2008-04-23 20:14 <DIR> d-------- C:\Programas\eMule 2008-03-26 21:07 . 2008-03-26 21:07 <DIR> d-------- C:\Programas\Ficheiros comuns\SWF Studio 2008-03-26 01:18 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-03-26 00:59 . 2008-04-13 00:32 <DIR> d-------- C:\Programas\Ficheiros comuns\Real . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-22 19:02 --------- d-----w C:\Programas\Messenger Plus! Live 2008-04-22 18:14 --------- d--h--w C:\Programas\InstallShield Installation Information 2008-04-21 18:03 --------- d-----w C:\Programas\Windows Live 2008-04-20 11:28 --------- d-----w C:\Programas\Gestão de Ficheiros DRI 2008-04-14 18:48 --------- d-----w C:\Programas\Program Files 2008-04-14 18:26 --------- d-----w C:\Programas\Creative 2008-04-14 18:24 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Creative 2008-03-30 11:01 98,304 ----a-w C:\WINDOWS\DUMP5880.tmp 2008-03-28 00:08 --------- d-----w C:\Programas\Ficheiros comuns\Panda Software 2008-03-26 00:18 --------- d-----w C:\Programas\Java 2008-03-26 00:01 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\LimeWire 2008-03-22 16:20 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Nero 2008-03-22 16:17 --------- d-----w C:\Programas\Ficheiros comuns\Nero 2008-03-22 16:14 --------- d-----w C:\Programas\Nero 2008-03-22 16:14 --------- d-----w C:\Programas\Ficheiros comuns\Ahead 2008-03-22 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero 2008-03-19 20:43 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\flightgear.org 2008-03-17 16:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-03-12 12:57 --------- d-----w C:\Programas\Ficheiros comuns\Adobe 2008-03-11 23:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet 2008-03-11 23:22 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared 2008-03-11 23:20 --------- d-----w C:\Programas\Ficheiros comuns\ACD Systems 2008-03-11 22:41 --------- d-----w C:\Programas\Ficheiros comuns\Macrovision Shared 2008-03-11 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip 2008-03-06 17:57 63,488 ----a-w C:\WINDOWS\system32\drivers\phmcd.sys 2008-03-04 19:47 286,720 ----a-w C:\WINDOWS\iun507.exe 2008-02-27 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink 2008-02-26 11:41 --------- d-----w C:\Programas\Shield 2008-02-25 22:19 --------- d-----w C:\Programas\Ficheiros comuns\InstallShield 2008-02-23 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Backup 2008-02-16 20:31 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE 2008-02-16 20:31 249,856 ----a-w C:\WINDOWS\Setup1.exe 2008-01-31 20:53 720,896 ----a-w C:\WINDOWS\iun6002ev.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" [ ] "MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184] "updateMgr"="C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "TrueTransparency"="D:\Programas\TrueTransparency\TrueTransparency.exe" [ ] "SpybotSD TeaTimer"="C:\Programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] "ViStart"="C:\Programas\Vistart\Slate\ViStart" [ ] "eMuleAutoStart"="C:\Programas\eMule\emule.exe" [2007-05-13 15:57 5308416] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784] "SBDrvDet"="C:\Programas\Creative\SB Drive Det\SBDrvDet.exe" [ ] "OrderReminder"="C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 12:18 98304] "Adobe Reader Speed Launcher"="C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792] "Adobe Photo Downloader"="C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712] "NeroFilterCheck"="C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136] "NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 10:25 1828136] "Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584] "egui"="C:\Programas\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072] "CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE] "CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] "DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2006-04-25 22:26 423184] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque\ WinZip Quick Pick.lnk - C:\Programas\WinZip\WZQKPICK.EXE [2008-03-11 22:14:55 389120] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.ACDV"= ACDV.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart] --a------ 2007-05-13 15:57 5308416 C:\Programas\eMule\emule.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueTransparency] D:\Programas\True Transparency\TrueTransparency.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programas\\eMule\\emule.exe"= "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "D:\\Programas\\IEPro\\MiniDM.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 phmcd;phmcd;C:\WINDOWS\system32\DRIVERS\phmcd.sys [2008-03-06 18:57] R2 PfDetNT;PfDetNT;C:\WINDOWS\system32\drivers\PfModNT.sys [2006-08-11 14:56] . Conte£do da pasta 'Tarefas Agendadas' "2008-04-23 19:15:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Programas\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-23 20:13:27 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 454 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Programas\Windows Defender\MsMpEng.exe C:\Programas\a-squared Free\a2service.exe C:\Programas\Eset\ESET Smart Security\ekrn.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\snmp.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Programas\Vistart\Slate\ViStart.exe . ************************************************************************** . Tempo para conclusÆo: 2008-04-23 20:20:08 - machine was rebooted [Alcides Lopes] ComboFix-quarantined-files.txt 2008-04-23 19:19:42 Pre-Run: 206,201,094,144 bytes livres Post-Run: 206,103,900,160 bytes livres 241 --- E O F --- 2008-04-23 18:35:46 Muito Obrigado pela ajuda! Por agora as pop-ups não me chateiam! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 23, 2008 Boa Noite! Edmero Muito Obrigado pela ajuda! Por agora as pop-ups não me chateiam! >@< O Log está limpo,mas...existe um ficheiro que não foi removido pelo script. --------------------------------- >@< Faça uma pesquisa,pelo Jotti,ao arquivo: phmcd.sys >@< Em File to upload,coloque o caminho: C:\WINDOWS\system32\DRIVERS\phmcd.sys >@< Em seguida,clique em Submit. >@< Copie e poste,o relatório desta análise. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edmero 0 Denunciar post Postado Abril 24, 2008 Boa Tarde! Fiz a análise e não detectou nada e nem apareceu o relatório. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 24, 2008 Boa Tarde! Fiz a análise e não detectou nada e nem apareceu o relatório. ------------------------- Opa! Edmero Boa Noite! >@< Posteriormente,faça uma busca pelo ficheiro e,caso o encontre,pode deletar. ------------------------- >@< Faça o download do CCleaner. >@< Baixe-o para o Desktop! >@< Abra o programa e clique em Analisar >> Executar Limpeza. >@< Terminando,clique em Registro >> Procurar erros >> Corrigir erros selecionados. ------------------------- >@< As pop-ups,ainda,lhe chateiam? >@< Pois o log está Limpo! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites