Bond2006 0 Denunciar post Postado Maio 28, 2008 Será que eu peguei algum virus ou malware? Ola pessoal de domingo pra ca a minha internet ficou muito lenta,uma simples página demora 15 minutos para abrir,alem de abrir algumas paginas esquesitas e eu to desconfiando que peguei alguma coisa apesar do meu anti-virus não constatar nada,segue abaixo o meu log desde ja agradeço a todos,muito obrigado e ate logo. Logfile of HijackThis v1.99.1 Scan saved at 23:35:26, on 27/05/08 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\pctspk.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://m.busca.uol.com.br/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing) O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe O4 - HKLM\..\Run: [bM932a195d] Rundll32.exe "C:\WINDOWS\system32\vumulprs.dll",s O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Maio 28, 2008 Baixe o ComboFix e salve na área de trabalho. Feche todos os programas. Clique duas vezes sobre combofix.exe e tecle (1) logo após aperte Enter para continuar. O ComboFix irá reiniciar seu computador automaticamente, isto faz parte do processo de remoção. Ao se encerrar, será gerado um log, que vai estar em C:\ComboFix.txt. Atenção: Não clique em nada enquanto o Combofix estiver rodando, Do contrário seu desktop ficará em branco. Para parar o processo ou sair do ComboFix, tecle "2" e Enter. Aguardo um novo log do HijackThis juntamente com o ComboFix.txt Aguardo Retorno Compartilhar este post Link para o post Compartilhar em outros sites
Bond2006 0 Denunciar post Postado Maio 31, 2008 Segue abaixo os logs do HijackThis e do Combofix : Logfile of HijackThis v1.99.1 Scan saved at 12:05:02, on 31/05/08 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\pctspk.exe C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Timer-net.exe C:\Documents and Settings\gilberto\Desktop\Timer-net.exe C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing) O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) ComboFix 08-05-29.1 - gilberto 2008-05-31 11:26:39.1 - NTFSx86 Executando de: C:\Documents and Settings\gilberto\Desktop\ComboFix.exe * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM932a195d.xml C:\WINDOWS\Downloaded Program Files\setup.inf C:\WINDOWS\pskt.ini C:\WINDOWS\system32\AcdLoUvw.ini C:\WINDOWS\system32\AcdLoUvw.ini2 C:\WINDOWS\system32\asrogmoh.exe C:\WINDOWS\system32\cbXOGWpo.dll C:\WINDOWS\system32\Config.ini C:\WINDOWS\system32\didvbwcv.dll C:\WINDOWS\system32\ftopeiix.dll C:\WINDOWS\system32\hdbpmmkm.dll C:\WINDOWS\system32\kvsdlmei.exe C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mkmmpbdh.ini C:\WINDOWS\system32\mreygcau.dll C:\WINDOWS\system32\mwjfkxus.dll C:\WINDOWS\system32\nhnqedxc.exe C:\WINDOWS\system32\nnnmgjks.dll C:\WINDOWS\system32\nxvsgeie.dll C:\WINDOWS\system32\nypeykcv.dll C:\WINDOWS\system32\qthewrqv.ini C:\WINDOWS\system32\qvgrpumx.exe C:\WINDOWS\system32\rhelqwid.ini C:\WINDOWS\system32\snvnnqws.ini C:\WINDOWS\system32\swqnnvns.dll C:\WINDOWS\system32\ubuxhwbv.exe C:\WINDOWS\system32\ufmjvsit.exe C:\WINDOWS\system32\ugwokqhg.ini C:\WINDOWS\system32\urqPfFut.dll C:\WINDOWS\system32\vckyepyn.ini C:\WINDOWS\system32\vcwbvdid.ini C:\WINDOWS\system32\vofyuypg.dll C:\WINDOWS\system32\vumulprs.dll C:\WINDOWS\system32\wvUmnNFX.dll C:\WINDOWS\system32\wvUoLdcA.dll C:\WINDOWS\system32\xbrwyqpw.dll C:\WINDOWS\system32\xiiepotf.ini C:\WINDOWS\system32\yejxrcbc.ini . ((((((((((((((((((((((( Ficheiros criados de 2008-04-28 to 2008-05-31 )))))))))))))))))))))))))))))))) . 2008-05-30 21:11 . 2008-05-30 23:37 <DIR> d----c--- C:\Arquivos de programas\Real Alternative 2008-05-28 04:51 . 2008-05-28 04:51 294 ---hsc--- C:\WINDOWS\system32\uqyovgne.ini 2008-04-14 09:40 . 2008-04-14 09:40 435 --a--c--- C:\Atalho para Documentos compartilhados.lnk 2008-04-12 19:57 . 2008-04-12 20:35 <DIR> d-a--c--- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2008-04-06 14:20 . 2008-04-06 14:21 <DIR> d----c--- C:\Arquivos de programas\Easy Video Downloader 2008-04-04 01:37 . 2008-04-05 19:23 <DIR> d----c--- C:\Arquivos de programas\Runtime Software 2008-04-03 10:23 . 2008-04-04 12:01 <DIR> d----c--- C:\Arquivos de programas\Real Alternative(3) 2008-04-01 10:05 . 2008-04-10 09:33 <DIR> d----c--- C:\Arquivos de programas\Easy RealMedia Tools . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-30 07:54 --------- dc----w C:\Arquivos de programas\Discador UOL 10.0 Light 2008-05-27 13:49 --------- dc----w C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-05-05 23:25 --------- dc----w C:\Arquivos de programas\Aplus Video Convertor 2008-04-13 19:19 --------- dc----w C:\Arquivos de programas\uTorrent 2008-04-13 19:17 --------- dc----w C:\Arquivos de programas\BitComet 2008-04-13 19:15 --------- dc----w C:\Documents and Settings\gilberto\Dados de aplicativos\uTorrent 2008-04-10 18:24 --------- dc----w C:\Arquivos de programas\Easy Real Converter 1.55 2008-04-05 22:26 --------- dc----w C:\Arquivos de programas\All To Real Converter 2008-04-03 01:53 --------- dc----w C:\Arquivos de programas\CrossLoop 2008-04-01 13:05 35,365 -c--a-w C:\WINDOWS\system32\uninstHelixYUV.exe 2008-03-29 01:53 --------- dc----w C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer 2008-03-25 04:49 621,344 -c--a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:49 183,072 -c--a-w C:\WINDOWS\system32\msjint40.dll 2008-03-22 02:27 21,304 -c--a-w C:\Documents and Settings\gilberto\Dados de aplicativos\GDIPFONTCACHEV1.DAT 2008-03-20 08:09 1,845,376 -c--a-w C:\WINDOWS\system32\win32k.sys 2008-03-16 03:47 3,082 -c--a-w C:\WINDOWS\system32\affv9869p2now.sys 2008-03-16 02:39 50,688 -c--a-w C:\WINDOWS\system32\wbhelp2.dll 2008-03-12 13:09 10,856 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys 2008-03-01 13:02 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll 2008-02-25 13:56 737,280 -c--a-w C:\WINDOWS\iun6002.exe 2008-02-20 06:51 282,624 -c--a-w C:\WINDOWS\system32\gdi32.dll 2008-02-20 05:37 45,568 -c--a-w C:\WINDOWS\system32\dnsrslvr.dll 2006-10-19 14:13 0 -c--a-w C:\Arquivos de programas\dia.flg 2006-10-18 15:53 0 -c--a-w C:\Arquivos de programas\banner.jpg 2006-05-28 17:10 759,296 -c--a-w C:\Arquivos de programas\VirtualDub.exe 2003-10-06 12:40 913,408 -c--a-w C:\Arquivos de programas\Timer-net.exe 2003-08-05 19:52 8,628 -c--a-w C:\Arquivos de programas\Timer.GID 2003-08-05 19:52 22,772 -c--a-w C:\Arquivos de programas\Timer.HLP 2003-07-22 14:47 147,728 -c--a-w C:\Arquivos de programas\ASYCFILT.DLL 2002-11-20 20:28 895 -c--a-w C:\Arquivos de programas\config.ini 2002-08-09 19:05 177,152 ----a-w C:\Arquivos de programas\DisablePro32.ocx 2000-06-07 10:11 17,680 -c--a-w C:\Arquivos de programas\psapi.dll 2000-05-27 02:00 1,388,544 -c--a-w C:\Arquivos de programas\MSVBVM60.DLL 2000-05-22 18:58 140,488 -c--a-w C:\Arquivos de programas\comdlg32.ocx 2000-05-22 02:00 209,608 -c--a-w C:\Arquivos de programas\TABCTL32.OCX 1999-08-31 18:55 598,288 -c--a-w C:\Arquivos de programas\OLEAUT32.DLL 1999-08-31 18:55 17,920 -c--a-w C:\Arquivos de programas\STDOLE2.TLB 1999-08-31 18:55 164,112 -c--a-w C:\Arquivos de programas\OLEPRO32.DLL 1999-06-01 02:00 101,888 -c--a-w C:\Arquivos de programas\VB6STKIT.DLL 1999-05-06 00:22 463,120 -c--a-w C:\Arquivos de programas\WININET.DLL 1999-05-06 00:22 282,896 -c--a-w C:\Arquivos de programas\SHLWAPI.DLL 1999-03-09 19:50 557,328 -c--a-w C:\Arquivos de programas\DAO360.DLL 1998-06-24 02:00 244,024 -c--a-w C:\Arquivos de programas\MSFLXGRD.OCX 1998-06-24 02:00 166,200 -c--a-w C:\Arquivos de programas\Msmask32.ocx 1998-06-24 02:00 115,016 ----a-w C:\Arquivos de programas\MSINET.OCX 1998-06-24 02:00 108,336 -c--a-w C:\Arquivos de programas\MSWINSCK.OCX 1998-06-20 02:00 286,720 -c--a-w C:\Arquivos de programas\SETUP1.EXE 1998-06-18 02:00 73,216 -c--a-w C:\Arquivos de programas\ST6UNST.EXE 1998-05-31 02:00 22,288 -c--a-w C:\Arquivos de programas\COMCAT.DLL 1997-01-21 02:00 7,551 -c--a-w C:\Arquivos de programas\CAIXREG.WAV 1996-11-01 03:00 10,008 -c--a-w C:\Arquivos de programas\alerta.wav 2007-03-16 22:44 56 -csh--r C:\WINDOWS\system32\20958F7F54.sys . ------- Sigcheck ------- 02/03/05 15:20 577536 3ed0a4d74efd5aaf8408095f452e2613 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll 08/03/07 12:50 578560 f86d3e5c8fe13297e1c2d662f9e2d59d C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll 04/08/04 00:45 577536 e0ff28447d1038de106d1f2fdf851647 C:\WINDOWS\$NtUninstallKB890859$\user32.dll 02/03/05 15:18 577536 7ffbcf1b94e6929deece06670c2407d6 C:\WINDOWS\$NtUninstallKB925902$\user32.dll 08/03/07 12:36 578048 b5782ee6eafe3c218236f79f1a27b747 C:\WINDOWS\system32\user32.dll 08/03/07 12:36 578048 b5782ee6eafe3c218236f79f1a27b747 C:\WINDOWS\system32\dllcache\user32.dll 02/03/05 15:13 2061184 aed7b3aa86ad031cf39c6e4bba37e818 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe 19/12/06 15:45 2063616 cd84579bd1ea4653a0dc4de5b8aa943f C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe 28/02/07 13:08 2063616 d027f0097b8f099c09369b8cc97d7c32 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe 04/08/04 00:55 2061056 c9bae5544b8aa39454c50d8ff83ae5a8 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe 02/03/05 15:08 2061056 d5ed391b213fa2a6ee25de5ab8512360 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe 19/12/06 15:22 2061824 520c4341e3ba4f5099d23f758cad8fac C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe 28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe 28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\system32\ntkrnlpa.exe 28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 02/03/05 15:13 2183808 6e3ab4241e058b248cb7cdc5157449c3 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe 19/12/06 15:45 2186240 df77102101d135739bf39a13473fcfa6 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe 28/02/07 13:08 2186368 bfb4c8761976cce0b544d557b4c70825 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe 04/08/04 00:40 2185216 3b72a63f230dfb276fc96a99173a81be C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe 02/03/05 15:09 2183552 0da99d0cbd578ad96effd3a571ce8437 C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe 19/12/06 15:22 2184576 081a0dd300f8623d74b2af9ee0cf7b1a C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe 28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe 28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\system32\ntoskrnl.exe 28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\system32\dllcache\ntoskrnl.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/08/04 00:45 15360] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [13/10/04 13:24 1694208] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PCTVOICE"="pctspk.exe" [23/09/03 22:56 180224 C:\WINDOWS\system32\pctspk.exe] "Timer"="C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe" [06/10/03 09:40 913408] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/08/04 00:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE [13/02/01 08:01:04 83360] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoAutoUpdate"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i420vfw.dll "VIDC.MPG4"= APmpg4v1.dll "VIDC.MP42"= APmpg4v1.dll "VIDC.AP41"= APmpg4v1.dll "VIDC.MP43"= APmpg4v1.dll "VIDC.YV12"= yv12vfw.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\90192ac1] C:\WINDOWS\system32\ftopeiix.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet] --a--c--- 28/05/06 23:24 3368448 C:\Arquivos de programas\BitComet\BitComet.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM932a195d] C:\WINDOWS\system32\vofyuypg.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\McAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 13/10/04 13:24 1694208 C:\Arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ] -----c--- 14/04/05 15:56 1957888 C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a--c--- 09/07/01 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC] C:\Arquivos de programas\NitroPC\NitroPC.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask] C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\BitComet\\BitComet.exe"= "C:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "C:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "11548:TCP"= 11548:TCP:BitComet 11548 TCP "11548:UDP"= 11548:UDP:BitComet 11548 UDP "24699:TCP"= 24699:TCP:BitComet 24699 TCP(ED2K) "24699:UDP"= 24699:UDP:BitComet 24699 UDP(ED2K) R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [29/03/08 15:31] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [29/03/08 15:35] . Conte£do da pasta 'Tarefas Agendadas' "2008-05-31 14:00:00 C:\WINDOWS\Tasks\ABF3C74494AC42BC.job" - c:\docume~1\gilberto\dadosd~1\okaygr~1\Dash Blue Wipe.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-31 11:38:05 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\wdfmgr.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Tempo para conclusÆo: 31/05/08 11:48:13 - machine was rebooted [gilberto] ComboFix-quarantined-files.txt 2008-05-31 14:48:00 Pre-Run: 8,386,080,768 bytes disponíveis Post-Run: 8.334.712.832 bytes dispon¡veis 237 --- E O F --- 2008-05-17 12:31:19 Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Maio 31, 2008 Siga as Instruções: Baixe o MSNfix. Salve na área de trabalho, e descompacte ele, após isto, clique duas vezes em MSNFix.bat Vai se abrir a tela MSN_Fix-menu nela aperte a opçãp R, será dado inicio ao scaneamento. Caso o scan detecte algo irá aparecer a seguinte informação: Infection Presente, aperte enter, e prossiga. Caso queira interromper o processo aperte a tecla Q Na finalização vai se abrir o bloco de notas com um log, selecione todo ele e copie, que se encontra na pasta msnfix.txt. Poste juntamente um novo log do Hijackthis Aguardo o retorno. Compartilhar este post Link para o post Compartilhar em outros sites
Bond2006 0 Denunciar post Postado Junho 1, 2008 Ola assim q baixei o MSNFix ja deu erro na tela do prompt e nao apareceram as opçoes mesmo assim apertei a tecla R e ele simplesmente fechou,deixei sem mexer durante 15 minutos pq achei q estaria rodando mais nao aconteceu nada,entao encontrei um outro programa chamado MSN_PHOTO_VIRUS e apos ele detectar algumas dll´s ele reiniciou meu micro e produziu um log que eu reproduzo abaixo ,juntamente com o do Hijackthis : Starting Scan... Looking For Virus Services... No Virus Services Found. Looking For Virus Processes... Found Virus Process(es) MSMSGS.EXE ...Terminated Searching for Virus Files... Found C:\WINDOWS\system32\dllcache\iexplore.exe ...Removed Scanning Registry... Registry Scan Complete. Scanning Hosts File... No Infected Hosts File Entries Found. Done! Saving Log... Logfile of HijackThis v1.99.1 Scan saved at 21:59:27, on 31/05/08 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\pctspk.exe C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Discador UOL 10.0 Light\Discador Light.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://m.busca.uol.com.br/ie/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing) O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{57C60D2D-6BC4-4821-8D6E-BEE671B7DC49}: NameServer = 200.147.255.100 200.221.11.101 O17 - HKLM\System\CS1\Services\Tcpip\..\{57C60D2D-6BC4-4821-8D6E-BEE671B7DC49}: NameServer = 200.147.255.100 200.221.11.101 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 1, 2008 Reconhece o arquivo abaixo: C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe Aguardo Retorno Compartilhar este post Link para o post Compartilhar em outros sites
Bond2006 0 Denunciar post Postado Junho 1, 2008 Reconhece o arquivo abaixo:C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe Aguardo Retorno Compartilhar este post Link para o post Compartilhar em outros sites
Bond2006 0 Denunciar post Postado Junho 1, 2008 Sim reconheço esse é um programa que eu uso para controlar a minha conexão que é discada e com ele eu também consigo programar meu computador para desligar numa hora pré-determinada. Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 1, 2008 Sendo assim Log Limpo O problema persiste? Compartilhar este post Link para o post Compartilhar em outros sites
Bond2006 0 Denunciar post Postado Junho 3, 2008 Não,o problema já foi resolvido,obrigado. Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 3, 2008 Caso Resolvido Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Junho 13, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites