Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Edmero

[Resolvido!]Pop-Ups irritantes( Wixawin, Celldorado, etc.)

Recommended Posts

Olá, eu sou novo neste fórum, e tenho problema com pop-ups, aparecem a cada 5 minutos.

Aqui vai o log do Hijack:

 

Logfile of HijackThis v1.99.1

Scan saved at 20:31:43, on 17-04-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programas\ESET\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Java\jre1.6.0_05\bin\jusched.exe

C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

C:\Programas\Stop-the-Pop-Up Lite\stopthepop.exe

C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Programas\Windows Defender\MSASCui.exe

C:\Programas\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\CTHELPER.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Programas\Windows Sidebar\sidebar.exe

C:\Programas\eMule\emule.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Programas\Windows Sidebar\sidebar.exe

C:\Programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programas\Internet Explorer\iexplore.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

D:\Programas\IEPro\MiniDM.exe

C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file)

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe

O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE

O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Edmero

 

<!> DESINSTALE: < Stop-the-Pop-Up >

<!> Após desinstalar,reinicie o computador!

-------------------------

>@< Faça o download do LopS&D.

>@< Salve-o no Disco Local-C.

>@< Instale o programa e clique em: LopSD.cmd

>@< Na janela que abrir,aperte o "p" >> Aperte Enter.

>@< Em outra janela,aperte a opção 2 >> Aperte Enter >> Aguarde!

>@< Terminando,salve e poste o relatório. ( C:\lopR.txt )

>@< Poste,também,HJT atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Aqui vai o relatório do LopS&D:

 

-----------------------[ Lop S&D 4.1.1-3 XP/Vista ]---------------------

 

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]

[ USER : Alcides Lopes ] [ "C:\Lop SD" ]

[ 18-04-2008 | 19:10:12,92 ] [ PC : ALCIDES-4E370DC ]

[ MAJ : 17-04-2008 | 19:51 ]

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS ////////////////////////////////

 

Arquivos/Ficheiros Hosts RESTAURADO

 

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

-------------[ Lista de pastas em Application Data ]------------

 

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\.

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\..

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini

[19-12-2007|21:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

 

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\.

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\..

[19-12-2007|20:58] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\desktop.ini

[19-12-2007|21:09] C:\DOCUME~1\ADMINI~1.ALC\APPLIC~1\Microsoft

 

[14-04-2008|12:41] C:\DOCUME~1\ALCIDE~1\APPLIC~1\.

[14-04-2008|12:41] C:\DOCUME~1\ALCIDE~1\APPLIC~1\..

[04-02-2008|12:54] C:\DOCUME~1\ALCIDE~1\APPLIC~1\ACD Systems

[17-03-2008|14:27] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Adobe

[13-01-2008|12:35] C:\DOCUME~1\ALCIDE~1\APPLIC~1\AdobeUM

[05-01-2008|23:28] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Ahead

[12-02-2008|12:48] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Apple Computer

[07-02-2008|22:20] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Avant Profiles

[14-04-2008|19:24] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Creative

[19-12-2007|20:58] C:\DOCUME~1\ALCIDE~1\APPLIC~1\desktop.ini

[05-04-2008|14:06] C:\DOCUME~1\ALCIDE~1\APPLIC~1\ESET

[19-03-2008|21:43] C:\DOCUME~1\ALCIDE~1\APPLIC~1\flightgear.org

[14-02-2008|21:38] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Google

[01-04-2008|22:23] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Help

[19-12-2007|21:16] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Identities

[12-04-2008|23:16] C:\DOCUME~1\ALCIDE~1\APPLIC~1\IEPro

[22-01-2008|13:54] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Leadertech

[26-03-2008|01:01] C:\DOCUME~1\ALCIDE~1\APPLIC~1\LimeWire

[09-02-2008|00:21] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Macromedia

[10-04-2008|20:00] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Microsoft

[09-04-2008|21:55] C:\DOCUME~1\ALCIDE~1\APPLIC~1\MiniDm

[09-04-2008|21:39] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Mozilla

[22-03-2008|17:20] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Nero

[13-04-2008|00:31] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Real

[06-01-2008|14:35] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Sun

[19-12-2007|21:37] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Symantec

[07-02-2008|22:56] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Talkback

[20-02-2008|21:02] C:\DOCUME~1\ALCIDE~1\APPLIC~1\Template

[18-02-2008|22:18] C:\DOCUME~1\ALCIDE~1\APPLIC~1\UOL

[08-01-2008|22:46] C:\DOCUME~1\ALCIDE~1\APPLIC~1\WinRAR

 

[15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.

[15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..

[22-02-2008|22:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe

[23-02-2008|23:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Backup

[15-04-2008|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CenerTCPMessenger

[14-04-2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini

[27-02-2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink

[05-04-2008|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET

[12-03-2008|00:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet

[16-03-2008|19:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google

[20-12-2007|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!

[10-04-2008|19:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft

[09-02-2008|16:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help

[22-03-2008|17:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero

[31-12-2007|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\sentinel

[29-03-2008|17:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy

[31-12-2007|20:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec

[17-03-2008|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP

[18-02-2008|22:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UOL

[19-12-2007|23:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[10-04-2008|19:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar

[11-03-2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

[13-02-2008|00:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

 

[19-12-2007|20:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.

[19-12-2007|20:58] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..

[14-04-2008|12:10] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini

[19-12-2007|21:09] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

 

[19-12-2007|21:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\.

[19-12-2007|21:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\..

[20-12-2007|12:57] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

 

[19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\.

[19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\..

[19-12-2007|21:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

 

Relatório do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:16:59, on 18-04-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programas\ESET\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Programas\Java\jre1.6.0_05\bin\jusched.exe

C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Programas\Windows Defender\MSASCui.exe

C:\Programas\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\CTHELPER.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Programas\Windows Live\Messenger\MsnMsgr.Exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Programas\WinZip\WZQKPICK.EXE

C:\Programas\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

D:\Programas\IEPro\MiniDM.exe

C:\PROGRA~1\WINZIP\winzip32.exe

C:\Documents and Settings\Alcides Lopes\Definições locais\Temp\wz5870\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file)

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe

O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE

O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart

O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe

O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edmero

 

>@< Reinicie o computador,em Modo de Segurança.

>@< Abra o HijackThis e,clique em Do a system scan only.

>@< Marque as entradas,logo abaixo,e clique em Fix checked. << Marque as que encontrar!

 

R3 - URLSearchHook: (no name) - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - (no file)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: (no name) - {5BBFC00A-312C-4777-A5DF-DDA65C67120C} - (no file)

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O4 - HKLM\..\Run: [Windows Services] C:\Windows\FrWall.exe

>@< Ainda em Modo Seguro,procure deletar este ficheiro:

 

C:\Windows\FrWall.exe << Delete!

 

>@< Reinicie em Modo Normal.

------------------------------

>@< Poste: HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Aqui vai o log do HijackThis, actualizado:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:49:28, on 19-04-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programas\ESET\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Programas\Java\jre1.6.0_05\bin\jusched.exe

C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Programas\Windows Defender\MSASCui.exe

C:\Programas\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\CTHELPER.EXE

C:\Programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Programas\Windows Sidebar\sidebar.exe

D:\Programas\VisualTaskTips\VisualTaskTips.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Sidebar\sidebar.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\Programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programas\Internet Explorer\iexplore.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\PROGRA~1\WINZIP\winzip32.exe

C:\Documents and Settings\Alcides Lopes\Definições locais\Temp\wz4a39\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [MzCpuAccelerator] C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe

O4 - HKCU\..\Run: [Fraps] D:\PROGRAMAS\FRAPS\FRAPS.EXE

O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\True Transparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [VisualTaskTips] D:\Programas\VisualTaskTips\VisualTaskTips.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [ViStart] C:\DOCUME~1\ALCIDE~1\DEFINI~1\Temp\Rar$EX04.375\ViStart 5259 Theme\ViStart 2490

O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart

O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe

O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 8019 bytes

 

Muito Obrigado e um grande abraço!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Edmero

 

>@< BAIXE: < KillBox >

>@< Salve-o numa pasta,em C:/

------------------------------

>@< Abra o KillBox >> Marque a opção: Delete on Reboot

>@< Copie a lista,sob o quote,para o Bloco de Notas.

>@< No Bloco de Notas,deixe: ( Ctrl + a ) >> ( Ctrl + c )

 

C:\Windows\System32\WinSecure.exe

C:\Windows\System32\NTSpool.exe

>@< No KillBox,clique em File >> Paste from clipboard >> Clique no botão All Files.

>@< Clique no X e,na pergunta.Diga Não!

>@< Reinicie o computador!

>@< Abra o HijackThis >> Clique: Do a system scan only

 

O4 - HKCU\..\Policies\Explorer\Run: [Windows Security Tool] WinSecure.exe

O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe

>@< Marque as entradas,àcima,e clique em Fix checked.

>@< Terminando,feche o programa.

------------------------------

>@< Faça e poste: HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! O log do HijackThis actualizado:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:11:53, on 19-04-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Programas\Java\jre1.6.0_05\bin\jusched.exe

C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Programas\Windows Defender\MSASCui.exe

C:\Programas\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\CTHELPER.EXE

C:\Programas\ESET\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Programas\Windows Sidebar\sidebar.exe

D:\Programas\VisualTaskTips\VisualTaskTips.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programas\eMule\emule.exe

C:\Programas\Windows Sidebar\sidebar.exe

C:\Programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Styler\Styler.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Programas\Internet Explorer\IEXPLORE.EXE

C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

D:\Programas\Hijack\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Programas\Styler\TB\StylerTB.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [VisualTaskTips] D:\Programas\VisualTaskTips\VisualTaskTips.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [ViStart] C:\DOCUME~1\ALCIDE~1\DEFINI~1\Temp\Rar$EX04.375\ViStart 5259 Theme\ViStart 2490

O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Styler.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 7720 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Edmero

 

<!> As pop-ups,ainda,lhe incomodam?

--------------------------------

>@< Faça o download do a-squared Free 3.5

 

Link Opcional:

 

< a2ppf_banner.jpg >

 

>@< Abra o programa e clique em: Atualizar agora >> Aguarde!

>@< Terminando,clique em: Analisar agora.

>@< Caso possa,procure fazer,esta análise,em Modo de Segurança!

>@< Escolha a opção: A fundo

>@< Clique em Analisar!

>@< Terminando,envie os ítens encontrados para a quarentena. << Importante!

>@< Aonde,daí,serão excluídos ou restaurados.

>@< Salve o relatório,desta verificação,e poste na sua resposta.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Muito Obrigado! As pop-ups já não me chateiam! Relatório do A-squared:

 

a-squared Free - Versão 3.5

Última atualização 19-04-2008 22:23:23

 

Configurações da análise:

 

Objetos: Memória, Rastros, Cookies, C:\WINDOWS\, C:\Programas

Análise de arquivos: Ligado

Heurística: Ligado

Análise de ADS: Ligado

 

Início da análise: 19-04-2008 22:23:59

 

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AlertStyle(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> CloseAlert(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> elO(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> GroupChoice detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OpenSensitivity(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup0 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup10 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup2 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup3 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup4 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup5 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup6 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup7 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup8 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup9 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> RSOTime detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(13) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(2) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(22) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(37) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(44) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(7) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechSpeed detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechVolume detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Time_Format detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(1) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(11) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(16) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(6) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(9) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MDLCap detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu2 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(1) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(2) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(3) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> WLMCaption detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Matt Holwood\MessengerDiscovery Live --> InstallDirectory detectado: Trace.Registry.DiscoveryLive

c:\windows\system32\dijpg.dll detectado: Trace.File.ComKeylogger

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} detectado: Trace.Registry.YuupSearchToolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName detectado: Trace.Registry.Sniffem 1.1

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString detectado: Trace.Registry.Sniffem 1.1

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@atdmt[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[4].txt detectado: Trace.TrackingCookie

 

Analisado

 

Arquivos: 101591

Objetos: 390394

Cookies: 64

Processos: 45

 

Encontrado

 

Arquivos: 0

Objetos: 56

Cookies: 3

Processos: 0

Chaves do registro: 0

 

Fim da análise: 19-04-2008 23:54:49

Duração da análise: 1:30:50

 

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@atdmt[1].txt Em quarentena Trace.TrackingCookie

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[1].txt Em quarentena Trace.TrackingCookie

C:\Documents and Settings\Alcides Lopes\Cookies\alcides_lopes@comboios[4].txt Em quarentena Trace.TrackingCookie

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName Em quarentena Trace.Registry.Sniffem 1.1

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString Em quarentena Trace.Registry.Sniffem 1.1

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} Em quarentena Trace.Registry.YuupSearchToolbar

c:\windows\system32\dijpg.dll Em quarentena Trace.File.ComKeylogger

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AlertStyle(0) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineHotKey Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineModifier Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayHotKey Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayModifier Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyHotKey Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyModifier Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardHotKey Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardModifier Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> CloseAlert(0) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> elO(0) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> GroupChoice Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineHotKey Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineModifier Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OpenSensitivity(0) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup0 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup1 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup10 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup2 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup3 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup4 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup5 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup6 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup7 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup8 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup9 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> RSOTime Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(13) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(2) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(22) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(37) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(44) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(7) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider1 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechSpeed Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechVolume Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Time_Format Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(1) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(11) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(16) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(6) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(9) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MDLCap Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu1 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> Menu2 Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(0) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(1) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(2) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(3) Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\Software\Matt Holwood\MessengerDiscovery Live --> WLMCaption Em quarentena Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Matt Holwood\MessengerDiscovery Live --> InstallDirectory Em quarentena Trace.Registry.DiscoveryLive

 

Em quarentena

 

Arquivos: 0

Objetos: 56

Cookies: 3

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Edmero

 

>@< Por alguns dias,deixe estes objetos em quarentena e,estando tudo Ok,pode eliminá-los.

-------------------------------

Estando tudo Ok com o PC,crie um Ponto de Restauração do Sistema,completamente Limpo!

Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok.

Depois,desmarque novamente! >> Aplicar >> Ok.

Para maiores detalhes,vá em:< Docs >

-------------------------------

>@< O log está limpo!

>@< Bom trabalho! :thumbsup:

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Errrrrrrr.................. Eu fiz porcaria, eleminei os itens da quarentena e voltaram a aparecer. Agora o que eu faço?

-----------------------------

Opa! Edmero

Boa Tarde!

 

>@< Não se preocupe,pois são Falsos Positivos do a-squared,em sua máxima heurística.

>@< Alguns,dos detectados,poderiam ser eliminados:

 

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> DisplayName Em quarentena Trace.Registry.Sniffem 1.1

 

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Product_Name --> UninstallString Em quarentena Trace.Registry.Sniffem 1.1

 

Value: HKEY_USERS\S-1-5-21-2052111302-220523388-1801674531-1005\software\microsoft\internet explorer\toolbar\webbrowser --> {1cbf31fc-3c23-4ba6-af16-2cec501bd837} Em quarentena Trace.Registry.YuupSearchToolbar

 

c:\windows\system32\dijpg.dll Em quarentena Trace.File.ComKeylogger

>@< Faça um novo scan,em Modo Normal,na opção Inteligente.

>@< Procure eliminar,somente,o que está no Quote. << Caso existam!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia!

Fiz um novo scan com a-squared e desta vez não detectou nada, e as pop-ups continuam a aparecer.

Muito Obrigado pela ajuda!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bom dia!

Fiz um novo scan com a-squared e desta vez não detectou nada, e as pop-ups continuam a aparecer.

Muito Obrigado pela ajuda!

---------------------------

Opa! Edmero

Boa Tarde!

 

>@< Faça o download do ComboFix.

>@< Baixe-o para o Desktop!

>@< Desabilite as proteções residente de: antivírus,antispywares e Firewall.

>@< Feche todas as janelas e execute a ferramenta!

 

Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

Salve-a no Desktop,renomeada como: Kombo.exe

Ps: Nomeie durante o salvamento,e não após salvá-la!

>@< Abrirá a janela Auto Scan. Aguarde!

>@< Digite a opção para continuar e < Enter >

>@< Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado!

---------------------------

>@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:01:17, on 22-04-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Programas\a-squared Free\a2service.exe

C:\Programas\Comodo\Firewall\cmdagent.exe

C:\Programas\ESET\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\System32\snmp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Programas\Java\jre1.6.0_05\bin\jusched.exe

C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Programas\Windows Defender\MSASCui.exe

C:\Programas\ESET\ESET Smart Security\egui.exe

C:\WINDOWS\CTHELPER.EXE

C:\Programas\Comodo\Firewall\CPF.exe

C:\Programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Programas\Windows Sidebar\sidebar.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Programas\WinZip\WZQKPICK.EXE

C:\Programas\Windows Sidebar\sidebar.exe

C:\WINDOWS\explorer.exe

C:\Programas\Vistart\Slate\ViStart.exe

C:\Programas\Internet Explorer\IEXPLORE.EXE

C:\Programas\Windows Live\Messenger\usnsvc.exe

D:\Programas\IEPro\MiniDM.exe

D:\Programas\Hijack\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - D:\Programas\IEPro\iepro.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sBDrvDet] C:\Programas\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [OrderReminder] C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [egui] "C:\Programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programas\Comodo\Firewall\CPF.exe" /background

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [updateMgr] C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [sidebar] C:\Programas\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [TrueTransparency] "D:\Programas\TrueTransparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [eMuleAutoStart] C:\Programas\eMule\emule.exe -AutoStart

O4 - HKCU\..\Run: [ViStart] C:\Programas\Vistart\Slate\ViStart

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: VistaStart.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - D:\Programas\IEPro\iepro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe (file missing)

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {D9CE2963-8547-4C18-A4CE-DA27278310D8} (Instalador Remoto UOL) - http://download.uol.com.br/discadorUOL/lig...tiveInstall.cab

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programas\a-squared Free\a2service.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programas\Comodo\Firewall\cmdagent.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Programas\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Programas\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 8287 bytes

 

Relatório do ComboFix:

 

ComboFix 08-04-20.5 - Alcides Lopes 2008-04-22 19:30:28.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.2070.18.568 [GMT 1:00]

Executando de: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\ComboFix.exe

* Criado um novo ponto de restauro

* Resident AV is active

 

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\ponto.DLL

C:\WINDOWS\system32\drivers\core.cache(10).dsk

C:\WINDOWS\system32\drivers\core.cache(2).dsk

C:\WINDOWS\system32\drivers\core.cache(3).dsk

C:\WINDOWS\system32\drivers\core.cache(4).dsk

C:\WINDOWS\system32\drivers\core.cache(5).dsk

C:\WINDOWS\system32\drivers\core.cache(6).dsk

C:\WINDOWS\system32\drivers\core.cache(7).dsk

C:\WINDOWS\system32\drivers\core.cache(8).dsk

C:\WINDOWS\system32\drivers\core.cache(9).dsk

C:\WINDOWS\system32\drivers\down

C:\WINDOWS\youtubex.dll

C:\WINDOWS\system32\drivers\core.cache.dsk . . . . falha na exclusão

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-03-22 to 2008-04-22 ))))))))))))))))))))))))))))))))

.

 

2008-04-22 19:35 . 2008-04-22 19:35 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.BAK

2008-04-22 19:26 . 2008-04-22 19:26 <DIR> d-------- C:\Programas\Arquivos de programas

2008-04-22 19:08 . 2006-03-17 05:03 12,955,648 --a------ C:\WINDOWS\system32\shell32.dll.backup

2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo

2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Comodo

2008-04-22 12:06 . 2008-04-20 12:30 211 --a------ C:\boot.ini.comodofirewall

2008-04-22 12:04 . 2008-04-22 12:04 <DIR> d-------- C:\Programas\Comodo

2008-04-21 23:18 . 2008-04-21 23:13 691,545 --a------ C:\WINDOWS\unins000.exe

2008-04-21 23:18 . 2008-04-21 23:18 2,561 --a------ C:\WINDOWS\unins000.dat

2008-04-21 23:00 . 2008-04-22 11:08 <DIR> d-------- C:\Programas\Spybot - Search & Destroy

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Programas\IconTweaker

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IconTweaker

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IconTweaker

2008-04-20 17:40 . 2008-04-20 17:40 <DIR> d-------- C:\WINDOWS\system32\ActiveScan

2008-04-20 14:39 . 2008-04-20 14:39 <DIR> d-------- C:\Programas\Ficheiros comuns\Ulead Systems

2008-04-20 14:37 . 2008-04-22 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems

2008-04-19 22:18 . 2008-04-19 23:54 <DIR> d-------- C:\Programas\a-squared Free

2008-04-19 20:01 . 2008-04-19 20:01 <DIR> d-------- C:\Programas\Logon Loader

2008-04-19 18:57 . 2008-04-19 18:57 <DIR> d-------- C:\Programas\KillBox

2008-04-19 00:34 . 2008-04-19 00:34 1,979 --a------ C:\WINDOWS\system32\shell32.dll.manifest

2008-04-19 00:32 . 2008-04-19 00:34 8,451,072 --a------ C:\WINDOWS\system32\shell32.dll.patched

2008-04-18 23:21 . 2008-04-18 23:21 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Styler

2008-04-18 22:10 . 2008-04-18 23:48 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ViStart

2008-04-18 22:09 . 2008-04-21 21:14 <DIR> d-------- C:\Programas\Vistart

2008-04-18 19:09 . 2008-04-20 18:20 <DIR> d-------- C:\Lop SD

2008-04-17 19:29 . 2008-04-22 19:17 <DIR> d-------- C:\!KillBox

2008-04-16 19:21 . 2008-04-16 19:22 58 --a------ C:\WINDOWS\WinNetOptimize98ag.cfg

2008-04-15 20:19 . 2008-04-15 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CenerTCPMessenger

2008-04-15 20:09 . 2008-04-15 20:09 <DIR> d-------- C:\WINDOWS\l2schemas

2008-04-15 20:09 . 2008-04-15 21:59 <DIR> d-------- C:\Programas\Windows Sidebar

2008-04-14 19:27 . 2008-04-22 19:36 31,812 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-22 19:36 31,812 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-22 19:36 31,440 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-22 19:36 31,440 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-22 19:36 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-22 19:36 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm

2008-04-14 19:27 . 2008-04-22 19:36 1,080 --a------ C:\WINDOWS\system32\settings.sfm

2008-04-14 19:26 . 2008-04-22 19:35 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.CDF

2008-04-14 19:23 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini

2008-04-14 12:32 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll

2008-04-14 12:31 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\WindowsShell.Manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\wuaucpl.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\sapi.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\ncpa.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 488 -ra------ C:\WINDOWS\system32\logonui.exe.manifest

2008-04-14 12:18 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys

2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll

2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll

2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll

2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll

2008-04-13 18:08 . 2008-04-13 18:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Os meus documentos

2008-04-13 18:08 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Modelos

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Menu Iniciar

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Favoritos

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Defini‡äes locais

2008-04-13 18:08 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Ambiente de trabalho

2008-04-13 18:08 . 2008-04-16 19:00 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC

2008-04-13 18:08 . 2008-04-22 19:30 1,024 --ah----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\NtUser.dat.LOG

2008-04-13 00:11 . 2000-10-11 14:11 121,562 --a------ C:\WINDOWS\system32\PicFormat32.dll

2008-04-13 00:11 . 2000-10-11 13:22 36,864 --a------ C:\WINDOWS\system32\PicFormat32.ocx

2008-04-10 20:33 . 2008-04-22 19:30 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG

2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar

2008-04-09 21:55 . 2008-04-09 21:55 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\MiniDm

2008-04-09 21:54 . 2008-04-12 23:16 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IEPro

2008-04-05 14:06 . 2008-04-05 14:06 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ESET

2008-04-05 11:46 . 2008-04-05 11:46 65,024 --a------ C:\WINDOWS\system32\ssleay32.dll

2008-04-05 11:46 . 2008-04-05 11:46 29,525 --a------ C:\WINDOWS\system32\libeay32.dll

2008-04-05 11:45 . 2008-04-05 11:46 299,520 --a------ C:\WINDOWS\messengrs.exe

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Os meus documentos

2008-03-31 10:56 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador\Defini‡äes locais

2008-03-31 10:56 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador\Ambiente de trabalho

2008-03-31 10:56 . 2008-03-31 10:56 <DIR> d-------- C:\Documents and Settings\Administrador

2008-03-31 10:56 . 2008-04-22 19:30 1,024 --ah----- C:\Documents and Settings\Administrador\NtUser.dat.LOG

2008-03-29 20:49 . 2008-03-29 20:49 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2008-03-29 17:27 . 2008-03-29 17:27 <DIR> d-------- C:\Programas\Windows Defender

2008-03-29 17:06 . 2008-03-29 17:06 101 --a------ C:\WINDOWS\wininit.ini

2008-03-28 22:09 . 2008-04-22 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-03-28 13:12 . 2008-04-05 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET

2008-03-27 22:40 . 2008-04-05 15:31 <DIR> d-------- C:\Programas\Eset

2008-03-27 21:15 . 2008-04-22 19:41 <DIR> d-------- C:\Programas\eMule

2008-03-26 21:07 . 2008-03-26 21:07 <DIR> d-------- C:\Programas\Ficheiros comuns\SWF Studio

2008-03-26 01:18 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-03-26 00:59 . 2008-04-13 00:32 <DIR> d-------- C:\Programas\Ficheiros comuns\Real

2008-03-22 17:20 . 2008-03-22 17:20 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Nero

2008-03-22 17:14 . 2008-03-22 17:17 <DIR> d-------- C:\Programas\Ficheiros comuns\Nero

2008-03-22 17:14 . 2008-03-22 17:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-22 18:37 167,545 ----a-w C:\WINDOWS\system32\drivers\core.cache.dsk

2008-04-22 18:18 --------- d-----w C:\Programas\Messenger Plus! Live

2008-04-22 18:14 --------- d--h--w C:\Programas\InstallShield Installation Information

2008-04-21 18:03 --------- d-----w C:\Programas\Windows Live

2008-04-20 11:28 --------- d-----w C:\Programas\Gestão de Ficheiros DRI

2008-04-18 18:34 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll

2008-04-14 18:48 --------- d-----w C:\Programas\Program Files

2008-04-14 18:26 --------- d-----w C:\Programas\Creative

2008-04-14 18:25 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll

2008-04-14 18:25 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll

2008-04-14 18:24 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Creative

2008-03-30 11:01 98,304 ----a-w C:\WINDOWS\DUMP5880.tmp

2008-03-28 00:08 --------- d-----w C:\Programas\Ficheiros comuns\Panda Software

2008-03-26 00:18 --------- d-----w C:\Programas\Java

2008-03-26 00:01 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\LimeWire

2008-03-22 16:14 --------- d-----w C:\Programas\Nero

2008-03-22 16:14 --------- d-----w C:\Programas\Ficheiros comuns\Ahead

2008-03-19 20:43 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\flightgear.org

2008-03-17 16:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-03-12 12:57 --------- d-----w C:\Programas\Ficheiros comuns\Adobe

2008-03-11 23:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet

2008-03-11 23:22 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared

2008-03-11 23:20 --------- d-----w C:\Programas\Ficheiros comuns\ACD Systems

2008-03-11 22:41 --------- d-----w C:\Programas\Ficheiros comuns\Macrovision Shared

2008-03-11 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip

2008-03-06 17:57 63,488 ----a-w C:\WINDOWS\system32\drivers\phmcd.sys

2008-03-04 19:47 286,720 ----a-w C:\WINDOWS\iun507.exe

2008-02-27 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink

2008-02-26 11:41 --------- d-----w C:\Programas\Shield

2008-02-25 22:19 --------- d-----w C:\Programas\Ficheiros comuns\InstallShield

2008-02-23 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Backup

2008-02-23 21:44 37,888 ----a-w C:\WINDOWS\system32\rar.exe

2008-02-16 20:31 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE

2008-02-16 20:31 249,856 ----a-w C:\WINDOWS\Setup1.exe

2008-01-31 20:53 720,896 ----a-w C:\WINDOWS\iun6002ev.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" [ ]

"MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]

"updateMgr"="C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

"Sidebar"="C:\Programas\Windows Sidebar\sidebar.exe" [2007-07-28 14:53 1230848]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"TrueTransparency"="D:\Programas\TrueTransparency\TrueTransparency.exe" [ ]

"SpybotSD TeaTimer"="C:\Programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

"eMuleAutoStart"="C:\Programas\eMule\emule.exe" [2007-05-13 15:57 5308416]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]

"SBDrvDet"="C:\Programas\Creative\SB Drive Det\SBDrvDet.exe" [ ]

"OrderReminder"="C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 12:18 98304]

"Adobe Reader Speed Launcher"="C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

"Adobe Photo Downloader"="C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]

"NeroFilterCheck"="C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]

"NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 10:25 1828136]

"Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]

"egui"="C:\Programas\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]

"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]

"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]

"COMODO Firewall Pro"="C:\Programas\Comodo\Firewall\CPF.exe" [2008-04-22 12:03 1115728]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

"DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2006-04-25 22:26 423184]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque\

WinZip Quick Pick.lnk - C:\Programas\WinZip\WZQKPICK.EXE [2008-03-11 22:14:55 389120]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.ACDV"= ACDV.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]

--a------ 2007-05-13 15:57 5308416 C:\Programas\eMule\emule.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]

D:\PROGRAMAS\FRAPS\FRAPS.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MzCpuAccelerator]

C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueTransparency]

D:\Programas\True Transparency\TrueTransparency.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programas\\eMule\\emule.exe"=

"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"D:\\Programas\\IEPro\\MiniDM.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R0 phmcd;phmcd;C:\WINDOWS\system32\DRIVERS\phmcd.sys [2008-03-06 18:57]

R1 udfss;udfss;C:\WINDOWS\system32\drivers\udfss.sys [2008-02-05 01:27]

R2 PfDetNT;PfDetNT;C:\WINDOWS\system32\drivers\PfModNT.sys [2006-08-11 14:56]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a90845-0e43-11dd-b012-000feaa3ca56}]

\Shell\AutoRun\command - RavMon.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c7ee7e-c761-11dc-aeb1-000feaa3ca56}]

\Shell\AutoRun\command - ntde1ect.com

\Shell\explore\Command - ntde1ect.com

\Shell\open\Command - ntde1ect.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59ce48b0-c68a-11dc-aea9-000feaa3ca56}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MSI.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cea8328c-0ebe-11dd-b013-000feaa3ca56}]

\Shell\AutoRun\command - RavMon.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e37d3552-af21-11dc-ae41-000feaa3ca56}]

\Shell\Auto\command - RavMon.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMon.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0b81609-e849-11dc-af54-000feaa3ca56}]

\Shell\AutoRun\command - RavMon.exe

 

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]

"C:\Programas\Windows Sidebar\sidebar.exe" /RegServer

.

Conte£do da pasta 'Tarefas Agendadas'

"2008-04-22 18:40:40 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Programas\Windows Defender\MpCmdRun.exe

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-22 19:38:33

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 454

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Programas\Windows Defender\MsMpEng.exe

C:\Programas\a-squared Free\a2service.exe

C:\Programas\Comodo\Firewall\cmdagent.exe

C:\Programas\Eset\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\snmp.exe

C:\WINDOWS\system32\MsPMSPSv.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-04-22 19:47:30 - machine was rebooted

ComboFix-quarantined-files.txt 2008-04-22 18:46:42

 

Pre-Run: 202,822,377,472 bytes livres

Post-Run: 205,397,110,784 bytes livres

 

263 --- E O F --- 2008-04-22 11:35:58

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edmero

 

Antes de executar este procedimento,insira sua(s) unidade(s) removíveis,na entrada USB.

------------------------

<!> Delete:

 

C:\QooBox

C:\ComboFix.txt << Log anterior do ComboFix.

------------------------

>@< Selecione e copie,todo o conteúdo que está na área do quote,para o Bloco de Notas.

>@< Salve-o,no Desktop,com o nome: CFScript.txt

 

File::

C:\WINDOWS\system32\drivers\core.cache.dsk

C:\WINDOWS\system32\DRIVERS\phmcd.sys

C:\WINDOWS\system32\drivers\udfss.sys

C:\WINDOWS\messengrs.exe

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a90845-0e43-11dd-b012-000feaa3ca56}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c7ee7e-c761-11dc-aeb1-000feaa3ca56}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cea8328c-0ebe-11dd-b013-000feaa3ca56}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e37d3552-af21-11dc-ae41-000feaa3ca56}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0b81609-e849-11dc-af54-000feaa3ca56}]

Driver::

"phmcd"

"udfss"

Folder::

C:\!KillBox

>@< Arraste,com o Mouse,o CFScript.txt para o ícone do ComboFix.

>@< Veja a demonstração!

 

cpiadecfscriptxt7.gif

 

>@< Com esse procedimento,o ComboFix irá executar e,reiniciará o computador,automaticamente!

>@< Caso não reinicie,faça-o manualmente!

>@< Durante a execução,não utilize o teclado ou Mouse!

>@< Terminando,poste o relatório C:\ComboFix.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Relatório do ComboFix:

 

ComboFix 08-04-20.5 - Alcides Lopes 2008-04-23 19:55:02.3 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.2070.18.528 [GMT 1:00]

Executando de: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\ComboFix.exe

Command switches used :: C:\Documents and Settings\Alcides Lopes\Os meus documentos\My Downloads\CFScript.txt.txt

* Criado um novo ponto de restauro

* Resident AV is active

 

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\!KillBox

C:\!KillBox\Logs\kb.log

C:\WINDOWS\system32\drivers\core.cache.dsk

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_UDFSS

-------\Service_udfss

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-03-23 to 2008-04-23 ))))))))))))))))))))))))))))))))

.

 

2008-04-22 23:44 . 2008-04-23 20:01 4,958,588 --------- C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.BAK

2008-04-22 21:27 . 2008-04-22 21:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!

2008-04-22 21:03 . 2008-04-22 21:04 <DIR> d-------- C:\Programas\ComboFix

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definições locais

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\NetworkService\Definições locais

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\LocalService\Definições locais

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Default User\Definições locais

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Definições locais

2008-04-22 19:47 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Definições locais

2008-04-22 19:26 . 2008-04-22 19:26 <DIR> d-------- C:\Programas\Arquivos de programas

2008-04-22 19:08 . 2006-03-17 05:03 12,955,648 --a------ C:\WINDOWS\system32\shell32.dll.backup

2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo

2008-04-22 12:07 . 2008-04-22 12:07 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Comodo

2008-04-22 12:06 . 2008-04-20 12:30 211 --a------ C:\boot.ini.comodofirewall

2008-04-22 12:04 . 2008-04-23 19:20 <DIR> d-------- C:\Programas\Comodo

2008-04-21 23:18 . 2008-04-21 23:13 691,545 --a------ C:\WINDOWS\unins000.exe

2008-04-21 23:18 . 2008-04-21 23:18 2,561 --a------ C:\WINDOWS\unins000.dat

2008-04-21 23:00 . 2008-04-22 11:08 <DIR> d-------- C:\Programas\Spybot - Search & Destroy

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Programas\IconTweaker

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IconTweaker

2008-04-21 21:30 . 2008-04-21 21:30 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IconTweaker

2008-04-20 17:40 . 2008-04-20 17:40 <DIR> d-------- C:\WINDOWS\system32\ActiveScan

2008-04-20 14:39 . 2008-04-20 14:39 <DIR> d-------- C:\Programas\Ficheiros comuns\Ulead Systems

2008-04-20 14:37 . 2008-04-22 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems

2008-04-19 22:18 . 2008-04-19 23:54 <DIR> d-------- C:\Programas\a-squared Free

2008-04-19 20:01 . 2008-04-22 23:21 <DIR> d-------- C:\Programas\Logon Loader

2008-04-19 18:57 . 2008-04-19 18:57 <DIR> d-------- C:\Programas\KillBox

2008-04-19 00:34 . 2008-04-19 00:34 1,979 --a------ C:\WINDOWS\system32\shell32.dll.manifest

2008-04-19 00:32 . 2008-04-19 00:34 8,451,072 --a------ C:\WINDOWS\system32\shell32.dll.patched

2008-04-18 23:21 . 2008-04-18 23:21 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\Styler

2008-04-18 22:10 . 2008-04-18 23:48 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ViStart

2008-04-18 22:09 . 2008-04-22 19:56 <DIR> d-------- C:\Programas\Vistart

2008-04-18 19:09 . 2008-04-20 18:20 <DIR> d-------- C:\Lop SD

2008-04-16 19:21 . 2008-04-16 19:22 58 --a------ C:\WINDOWS\WinNetOptimize98ag.cfg

2008-04-15 20:19 . 2008-04-15 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CenerTCPMessenger

2008-04-15 20:09 . 2008-04-15 20:09 <DIR> d-------- C:\WINDOWS\l2schemas

2008-04-15 20:09 . 2008-04-23 19:06 <DIR> d-------- C:\Programas\Windows Sidebar

2008-04-14 19:27 . 2008-04-23 20:05 31,812 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-23 20:05 31,812 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-23 20:05 31,440 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-23 20:05 31,440 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-23 20:05 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx

2008-04-14 19:27 . 2008-04-23 20:05 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm

2008-04-14 19:27 . 2008-04-23 20:05 1,080 --a------ C:\WINDOWS\system32\settings.sfm

2008-04-14 19:26 . 2008-04-23 20:01 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.CDF

2008-04-14 19:23 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini

2008-04-14 12:32 . 2004-08-04 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll

2008-04-14 12:31 . 2004-08-04 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\WindowsShell.Manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\wuaucpl.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\sapi.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 749 -ra------ C:\WINDOWS\system32\ncpa.cpl.manifest

2008-04-14 12:29 . 2008-04-14 12:29 488 -ra------ C:\WINDOWS\system32\logonui.exe.manifest

2008-04-14 12:18 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys

2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll

2008-04-14 12:11 . 2004-08-04 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll

2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll

2008-04-14 12:11 . 2004-08-04 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll

2008-04-13 18:08 . 2008-04-13 18:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Os meus documentos

2008-04-13 18:08 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Modelos

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Menu Iniciar

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Favoritos

2008-04-13 18:08 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Defini‡äes locais

2008-04-13 18:08 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\Ambiente de trabalho

2008-04-13 18:08 . 2008-04-22 19:47 <DIR> d-------- C:\Documents and Settings\Administrador.ALCIDES-4E370DC

2008-04-13 18:08 . 2008-04-23 19:54 1,024 --ah----- C:\Documents and Settings\Administrador.ALCIDES-4E370DC\NtUser.dat.LOG

2008-04-13 00:11 . 2000-10-11 14:11 121,562 --a------ C:\WINDOWS\system32\PicFormat32.dll

2008-04-13 00:11 . 2000-10-11 13:22 36,864 --a------ C:\WINDOWS\system32\PicFormat32.ocx

2008-04-10 20:33 . 2008-04-23 19:54 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG

2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar

2008-04-09 21:55 . 2008-04-09 21:55 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\MiniDm

2008-04-09 21:54 . 2008-04-12 23:16 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\IEPro

2008-04-05 14:06 . 2008-04-05 14:06 <DIR> d-------- C:\Documents and Settings\Alcides Lopes\Application Data\ESET

2008-04-05 11:46 . 2008-04-05 11:46 65,024 --a------ C:\WINDOWS\system32\ssleay32.dll

2008-04-05 11:46 . 2008-04-05 11:46 29,525 --a------ C:\WINDOWS\system32\libeay32.dll

2008-04-05 11:45 . 2008-04-05 11:46 299,520 --a------ C:\WINDOWS\messengrs.exe

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Os meus documentos

2008-03-31 10:56 . 2008-03-06 21:39 <DIR> d--h----- C:\Documents and Settings\Administrador\Modelos

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> dr------- C:\Documents and Settings\Administrador\Menu Iniciar

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d-------- C:\Documents and Settings\Administrador\Favoritos

2008-03-31 10:56 . 2007-12-19 20:58 <DIR> d--h----- C:\Documents and Settings\Administrador\Defini‡äes locais

2008-03-31 10:56 . 2007-12-19 21:11 <DIR> d-------- C:\Documents and Settings\Administrador\Ambiente de trabalho

2008-03-31 10:56 . 2008-03-31 10:56 <DIR> d-------- C:\Documents and Settings\Administrador

2008-03-31 10:56 . 2008-04-23 19:54 1,024 --ah----- C:\Documents and Settings\Administrador\NtUser.dat.LOG

2008-03-29 20:49 . 2008-03-29 20:49 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2008-03-29 17:27 . 2008-03-29 17:27 <DIR> d-------- C:\Programas\Windows Defender

2008-03-29 17:06 . 2008-03-29 17:06 101 --a------ C:\WINDOWS\wininit.ini

2008-03-28 22:09 . 2008-04-22 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-03-28 13:12 . 2008-04-05 14:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET

2008-03-27 22:40 . 2008-04-05 15:31 <DIR> d-------- C:\Programas\Eset

2008-03-27 21:15 . 2008-04-23 20:14 <DIR> d-------- C:\Programas\eMule

2008-03-26 21:07 . 2008-03-26 21:07 <DIR> d-------- C:\Programas\Ficheiros comuns\SWF Studio

2008-03-26 01:18 . 2008-02-22 03:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-03-26 00:59 . 2008-04-13 00:32 <DIR> d-------- C:\Programas\Ficheiros comuns\Real

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-22 19:02 --------- d-----w C:\Programas\Messenger Plus! Live

2008-04-22 18:14 --------- d--h--w C:\Programas\InstallShield Installation Information

2008-04-21 18:03 --------- d-----w C:\Programas\Windows Live

2008-04-20 11:28 --------- d-----w C:\Programas\Gestão de Ficheiros DRI

2008-04-14 18:48 --------- d-----w C:\Programas\Program Files

2008-04-14 18:26 --------- d-----w C:\Programas\Creative

2008-04-14 18:24 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Creative

2008-03-30 11:01 98,304 ----a-w C:\WINDOWS\DUMP5880.tmp

2008-03-28 00:08 --------- d-----w C:\Programas\Ficheiros comuns\Panda Software

2008-03-26 00:18 --------- d-----w C:\Programas\Java

2008-03-26 00:01 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\LimeWire

2008-03-22 16:20 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\Nero

2008-03-22 16:17 --------- d-----w C:\Programas\Ficheiros comuns\Nero

2008-03-22 16:14 --------- d-----w C:\Programas\Nero

2008-03-22 16:14 --------- d-----w C:\Programas\Ficheiros comuns\Ahead

2008-03-22 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero

2008-03-19 20:43 --------- d-----w C:\Documents and Settings\Alcides Lopes\Application Data\flightgear.org

2008-03-17 16:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-03-12 12:57 --------- d-----w C:\Programas\Ficheiros comuns\Adobe

2008-03-11 23:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet

2008-03-11 23:22 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared

2008-03-11 23:20 --------- d-----w C:\Programas\Ficheiros comuns\ACD Systems

2008-03-11 22:41 --------- d-----w C:\Programas\Ficheiros comuns\Macrovision Shared

2008-03-11 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip

2008-03-06 17:57 63,488 ----a-w C:\WINDOWS\system32\drivers\phmcd.sys

2008-03-04 19:47 286,720 ----a-w C:\WINDOWS\iun507.exe

2008-02-27 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink

2008-02-26 11:41 --------- d-----w C:\Programas\Shield

2008-02-25 22:19 --------- d-----w C:\Programas\Ficheiros comuns\InstallShield

2008-02-23 22:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Backup

2008-02-16 20:31 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE

2008-02-16 20:31 249,856 ----a-w C:\WINDOWS\Setup1.exe

2008-01-31 20:53 720,896 ----a-w C:\WINDOWS\iun6002ev.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programas\Ficheiros comuns\Ahead\lib\NMBgMonitor.exe" [ ]

"MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]

"updateMgr"="C:\Programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"TrueTransparency"="D:\Programas\TrueTransparency\TrueTransparency.exe" [ ]

"SpybotSD TeaTimer"="C:\Programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

"ViStart"="C:\Programas\Vistart\Slate\ViStart" [ ]

"eMuleAutoStart"="C:\Programas\eMule\emule.exe" [2007-05-13 15:57 5308416]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]

"SBDrvDet"="C:\Programas\Creative\SB Drive Det\SBDrvDet.exe" [ ]

"OrderReminder"="C:\Programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 12:18 98304]

"Adobe Reader Speed Launcher"="C:\Programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]

"Adobe Photo Downloader"="C:\Programas\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]

"NeroFilterCheck"="C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]

"NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 10:25 1828136]

"Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]

"egui"="C:\Programas\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]

"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]

"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

"DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2006-04-25 22:26 423184]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque\

WinZip Quick Pick.lnk - C:\Programas\WinZip\WZQKPICK.EXE [2008-03-11 22:14:55 389120]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.ACDV"= ACDV.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]

--a------ 2007-05-13 15:57 5308416 C:\Programas\eMule\emule.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]

D:\PROGRAMAS\FRAPS\FRAPS.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MzCpuAccelerator]

C:\Program Files\Mz_CpuAcc\MzCpuAccelerator.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueTransparency]

D:\Programas\True Transparency\TrueTransparency.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programas\\eMule\\emule.exe"=

"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"D:\\Programas\\IEPro\\MiniDM.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R0 phmcd;phmcd;C:\WINDOWS\system32\DRIVERS\phmcd.sys [2008-03-06 18:57]

R2 PfDetNT;PfDetNT;C:\WINDOWS\system32\drivers\PfModNT.sys [2006-08-11 14:56]

 

.

Conte£do da pasta 'Tarefas Agendadas'

"2008-04-23 19:15:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Programas\Windows Defender\MpCmdRun.exe

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-23 20:13:27

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 454

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Programas\Windows Defender\MsMpEng.exe

C:\Programas\a-squared Free\a2service.exe

C:\Programas\Eset\ESET Smart Security\ekrn.exe

C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\snmp.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Programas\Vistart\Slate\ViStart.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-04-23 20:20:08 - machine was rebooted [Alcides Lopes]

ComboFix-quarantined-files.txt 2008-04-23 19:19:42

 

Pre-Run: 206,201,094,144 bytes livres

Post-Run: 206,103,900,160 bytes livres

 

241 --- E O F --- 2008-04-23 18:35:46

 

Muito Obrigado pela ajuda! Por agora as pop-ups não me chateiam!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edmero

 

Muito Obrigado pela ajuda! Por agora as pop-ups não me chateiam!

>@< O Log está limpo,mas...existe um ficheiro que não foi removido pelo script.

---------------------------------

>@< Faça uma pesquisa,pelo Jotti,ao arquivo:

 

phmcd.sys

 

>@< Em File to upload,coloque o caminho: C:\WINDOWS\system32\DRIVERS\phmcd.sys

>@< Em seguida,clique em Submit.

>@< Copie e poste,o relatório desta análise.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Tarde! Fiz a análise e não detectou nada e nem apareceu o relatório.

-------------------------

Opa! Edmero

Boa Noite!

 

>@< Posteriormente,faça uma busca pelo ficheiro e,caso o encontre,pode deletar.

-------------------------

>@< Faça o download do CCleaner.

>@< Baixe-o para o Desktop!

>@< Abra o programa e clique em Analisar >> Executar Limpeza.

>@< Terminando,clique em Registro >> Procurar erros >> Corrigir erros selecionados.

-------------------------

>@< As pop-ups,ainda,lhe chateiam?

>@< Pois o log está Limpo!

 

Abraços! thumbs-up.gif

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.