Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Bond2006

[Resolvido] Computador lento,segue inserido o lg do Hijackthis.

Recommended Posts

Será que eu peguei algum virus ou malware?

 

 

Ola pessoal de domingo pra ca a minha internet ficou muito lenta,uma simples página demora 15 minutos para abrir,alem de abrir algumas paginas esquesitas e eu to desconfiando que peguei alguma coisa apesar do meu anti-virus não constatar nada,segue abaixo o meu log desde ja agradeço a todos,muito obrigado e ate logo.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 23:35:26, on 27/05/08

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\pctspk.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

C:\WINDOWS\system32\Rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://m.busca.uol.com.br/ie/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing)

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

O4 - HKLM\..\Run: [bM932a195d] Rundll32.exe "C:\WINDOWS\system32\vumulprs.dll",s

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML

O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o ComboFix e salve na área de trabalho.

 

Feche todos os programas.

Clique duas vezes sobre combofix.exe e tecle (1) logo após aperte Enter para continuar.

O ComboFix irá reiniciar seu computador automaticamente, isto faz parte do processo de remoção.

 

Ao se encerrar, será gerado um log, que vai estar em C:\ComboFix.txt.

 

Atenção:

Não clique em nada enquanto o Combofix estiver rodando, Do contrário seu desktop ficará em branco.

 

Para parar o processo ou sair do ComboFix, tecle "2" e Enter.

 

Aguardo um novo log do HijackThis juntamente com o ComboFix.txt

 

 

Aguardo Retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue abaixo os logs do HijackThis e do Combofix :

 

 

 

 

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 12:05:02, on 31/05/08

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\pctspk.exe

C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Timer-net.exe

C:\Documents and Settings\gilberto\Desktop\Timer-net.exe

C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing)

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML

O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

 

 

 

 

 

 

ComboFix 08-05-29.1 - gilberto 2008-05-31 11:26:39.1 - NTFSx86

Executando de: C:\Documents and Settings\gilberto\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\BM932a195d.xml

C:\WINDOWS\Downloaded Program Files\setup.inf

C:\WINDOWS\pskt.ini

C:\WINDOWS\system32\AcdLoUvw.ini

C:\WINDOWS\system32\AcdLoUvw.ini2

C:\WINDOWS\system32\asrogmoh.exe

C:\WINDOWS\system32\cbXOGWpo.dll

C:\WINDOWS\system32\Config.ini

C:\WINDOWS\system32\didvbwcv.dll

C:\WINDOWS\system32\ftopeiix.dll

C:\WINDOWS\system32\hdbpmmkm.dll

C:\WINDOWS\system32\kvsdlmei.exe

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\mkmmpbdh.ini

C:\WINDOWS\system32\mreygcau.dll

C:\WINDOWS\system32\mwjfkxus.dll

C:\WINDOWS\system32\nhnqedxc.exe

C:\WINDOWS\system32\nnnmgjks.dll

C:\WINDOWS\system32\nxvsgeie.dll

C:\WINDOWS\system32\nypeykcv.dll

C:\WINDOWS\system32\qthewrqv.ini

C:\WINDOWS\system32\qvgrpumx.exe

C:\WINDOWS\system32\rhelqwid.ini

C:\WINDOWS\system32\snvnnqws.ini

C:\WINDOWS\system32\swqnnvns.dll

C:\WINDOWS\system32\ubuxhwbv.exe

C:\WINDOWS\system32\ufmjvsit.exe

C:\WINDOWS\system32\ugwokqhg.ini

C:\WINDOWS\system32\urqPfFut.dll

C:\WINDOWS\system32\vckyepyn.ini

C:\WINDOWS\system32\vcwbvdid.ini

C:\WINDOWS\system32\vofyuypg.dll

C:\WINDOWS\system32\vumulprs.dll

C:\WINDOWS\system32\wvUmnNFX.dll

C:\WINDOWS\system32\wvUoLdcA.dll

C:\WINDOWS\system32\xbrwyqpw.dll

C:\WINDOWS\system32\xiiepotf.ini

C:\WINDOWS\system32\yejxrcbc.ini

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-04-28 to 2008-05-31 ))))))))))))))))))))))))))))))))

.

 

2008-05-30 21:11 . 2008-05-30 23:37 <DIR> d----c--- C:\Arquivos de programas\Real Alternative

2008-05-28 04:51 . 2008-05-28 04:51 294 ---hsc--- C:\WINDOWS\system32\uqyovgne.ini

2008-04-14 09:40 . 2008-04-14 09:40 435 --a--c--- C:\Atalho para Documentos compartilhados.lnk

2008-04-12 19:57 . 2008-04-12 20:35 <DIR> d-a--c--- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

2008-04-06 14:20 . 2008-04-06 14:21 <DIR> d----c--- C:\Arquivos de programas\Easy Video Downloader

2008-04-04 01:37 . 2008-04-05 19:23 <DIR> d----c--- C:\Arquivos de programas\Runtime Software

2008-04-03 10:23 . 2008-04-04 12:01 <DIR> d----c--- C:\Arquivos de programas\Real Alternative(3)

2008-04-01 10:05 . 2008-04-10 09:33 <DIR> d----c--- C:\Arquivos de programas\Easy RealMedia Tools

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-30 07:54 --------- dc----w C:\Arquivos de programas\Discador UOL 10.0 Light

2008-05-27 13:49 --------- dc----w C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-05-05 23:25 --------- dc----w C:\Arquivos de programas\Aplus Video Convertor

2008-04-13 19:19 --------- dc----w C:\Arquivos de programas\uTorrent

2008-04-13 19:17 --------- dc----w C:\Arquivos de programas\BitComet

2008-04-13 19:15 --------- dc----w C:\Documents and Settings\gilberto\Dados de aplicativos\uTorrent

2008-04-10 18:24 --------- dc----w C:\Arquivos de programas\Easy Real Converter 1.55

2008-04-05 22:26 --------- dc----w C:\Arquivos de programas\All To Real Converter

2008-04-03 01:53 --------- dc----w C:\Arquivos de programas\CrossLoop

2008-04-01 13:05 35,365 -c--a-w C:\WINDOWS\system32\uninstHelixYUV.exe

2008-03-29 01:53 --------- dc----w C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer

2008-03-25 04:49 621,344 -c--a-w C:\WINDOWS\system32\mswstr10.dll

2008-03-25 04:49 183,072 -c--a-w C:\WINDOWS\system32\msjint40.dll

2008-03-22 02:27 21,304 -c--a-w C:\Documents and Settings\gilberto\Dados de aplicativos\GDIPFONTCACHEV1.DAT

2008-03-20 08:09 1,845,376 -c--a-w C:\WINDOWS\system32\win32k.sys

2008-03-16 03:47 3,082 -c--a-w C:\WINDOWS\system32\affv9869p2now.sys

2008-03-16 02:39 50,688 -c--a-w C:\WINDOWS\system32\wbhelp2.dll

2008-03-12 13:09 10,856 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys

2008-03-01 13:02 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll

2008-02-25 13:56 737,280 -c--a-w C:\WINDOWS\iun6002.exe

2008-02-20 06:51 282,624 -c--a-w C:\WINDOWS\system32\gdi32.dll

2008-02-20 05:37 45,568 -c--a-w C:\WINDOWS\system32\dnsrslvr.dll

2006-10-19 14:13 0 -c--a-w C:\Arquivos de programas\dia.flg

2006-10-18 15:53 0 -c--a-w C:\Arquivos de programas\banner.jpg

2006-05-28 17:10 759,296 -c--a-w C:\Arquivos de programas\VirtualDub.exe

2003-10-06 12:40 913,408 -c--a-w C:\Arquivos de programas\Timer-net.exe

2003-08-05 19:52 8,628 -c--a-w C:\Arquivos de programas\Timer.GID

2003-08-05 19:52 22,772 -c--a-w C:\Arquivos de programas\Timer.HLP

2003-07-22 14:47 147,728 -c--a-w C:\Arquivos de programas\ASYCFILT.DLL

2002-11-20 20:28 895 -c--a-w C:\Arquivos de programas\config.ini

2002-08-09 19:05 177,152 ----a-w C:\Arquivos de programas\DisablePro32.ocx

2000-06-07 10:11 17,680 -c--a-w C:\Arquivos de programas\psapi.dll

2000-05-27 02:00 1,388,544 -c--a-w C:\Arquivos de programas\MSVBVM60.DLL

2000-05-22 18:58 140,488 -c--a-w C:\Arquivos de programas\comdlg32.ocx

2000-05-22 02:00 209,608 -c--a-w C:\Arquivos de programas\TABCTL32.OCX

1999-08-31 18:55 598,288 -c--a-w C:\Arquivos de programas\OLEAUT32.DLL

1999-08-31 18:55 17,920 -c--a-w C:\Arquivos de programas\STDOLE2.TLB

1999-08-31 18:55 164,112 -c--a-w C:\Arquivos de programas\OLEPRO32.DLL

1999-06-01 02:00 101,888 -c--a-w C:\Arquivos de programas\VB6STKIT.DLL

1999-05-06 00:22 463,120 -c--a-w C:\Arquivos de programas\WININET.DLL

1999-05-06 00:22 282,896 -c--a-w C:\Arquivos de programas\SHLWAPI.DLL

1999-03-09 19:50 557,328 -c--a-w C:\Arquivos de programas\DAO360.DLL

1998-06-24 02:00 244,024 -c--a-w C:\Arquivos de programas\MSFLXGRD.OCX

1998-06-24 02:00 166,200 -c--a-w C:\Arquivos de programas\Msmask32.ocx

1998-06-24 02:00 115,016 ----a-w C:\Arquivos de programas\MSINET.OCX

1998-06-24 02:00 108,336 -c--a-w C:\Arquivos de programas\MSWINSCK.OCX

1998-06-20 02:00 286,720 -c--a-w C:\Arquivos de programas\SETUP1.EXE

1998-06-18 02:00 73,216 -c--a-w C:\Arquivos de programas\ST6UNST.EXE

1998-05-31 02:00 22,288 -c--a-w C:\Arquivos de programas\COMCAT.DLL

1997-01-21 02:00 7,551 -c--a-w C:\Arquivos de programas\CAIXREG.WAV

1996-11-01 03:00 10,008 -c--a-w C:\Arquivos de programas\alerta.wav

2007-03-16 22:44 56 -csh--r C:\WINDOWS\system32\20958F7F54.sys

.

 

------- Sigcheck -------

 

02/03/05 15:20 577536 3ed0a4d74efd5aaf8408095f452e2613 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll

08/03/07 12:50 578560 f86d3e5c8fe13297e1c2d662f9e2d59d C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll

04/08/04 00:45 577536 e0ff28447d1038de106d1f2fdf851647 C:\WINDOWS\$NtUninstallKB890859$\user32.dll

02/03/05 15:18 577536 7ffbcf1b94e6929deece06670c2407d6 C:\WINDOWS\$NtUninstallKB925902$\user32.dll

08/03/07 12:36 578048 b5782ee6eafe3c218236f79f1a27b747 C:\WINDOWS\system32\user32.dll

08/03/07 12:36 578048 b5782ee6eafe3c218236f79f1a27b747 C:\WINDOWS\system32\dllcache\user32.dll

 

02/03/05 15:13 2061184 aed7b3aa86ad031cf39c6e4bba37e818 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe

19/12/06 15:45 2063616 cd84579bd1ea4653a0dc4de5b8aa943f C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe

28/02/07 13:08 2063616 d027f0097b8f099c09369b8cc97d7c32 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe

04/08/04 00:55 2061056 c9bae5544b8aa39454c50d8ff83ae5a8 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe

02/03/05 15:08 2061056 d5ed391b213fa2a6ee25de5ab8512360 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe

19/12/06 15:22 2061824 520c4341e3ba4f5099d23f758cad8fac C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe

28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe

28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\system32\ntkrnlpa.exe

28/02/07 13:02 2061824 1683af18422f7de34575ee95be882ad1 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

 

02/03/05 15:13 2183808 6e3ab4241e058b248cb7cdc5157449c3 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe

19/12/06 15:45 2186240 df77102101d135739bf39a13473fcfa6 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe

28/02/07 13:08 2186368 bfb4c8761976cce0b544d557b4c70825 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe

04/08/04 00:40 2185216 3b72a63f230dfb276fc96a99173a81be C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe

02/03/05 15:09 2183552 0da99d0cbd578ad96effd3a571ce8437 C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe

19/12/06 15:22 2184576 081a0dd300f8623d74b2af9ee0cf7b1a C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe

28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe

28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\system32\ntoskrnl.exe

28/02/07 13:02 2184576 986c40660057a2bac752ed4f97cf4a10 C:\WINDOWS\system32\dllcache\ntoskrnl.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/08/04 00:45 15360]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [13/10/04 13:24 1694208]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"PCTVOICE"="pctspk.exe" [23/09/03 22:56 180224 C:\WINDOWS\system32\pctspk.exe]

"Timer"="C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe" [06/10/03 09:40 913408]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/08/04 00:45 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE [13/02/01 08:01:04 83360]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoAutoUpdate"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.I420"= i420vfw.dll

"VIDC.MPG4"= APmpg4v1.dll

"VIDC.MP42"= APmpg4v1.dll

"VIDC.AP41"= APmpg4v1.dll

"VIDC.MP43"= APmpg4v1.dll

"VIDC.YV12"= yv12vfw.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\90192ac1]

C:\WINDOWS\system32\ftopeiix.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]

--a--c--- 28/05/06 23:24 3368448 C:\Arquivos de programas\BitComet\BitComet.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM932a195d]

C:\WINDOWS\system32\vofyuypg.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]

c:\ARQUIV~1\mcafee.com\agent\McAgent.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]

c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--a------ 13/10/04 13:24 1694208 C:\Arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]

-----c--- 14/04/05 15:56 1957888 C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a--c--- 09/07/01 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC]

C:\Arquivos de programas\NitroPC\NitroPC.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]

C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]

C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]

C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\BitComet\\BitComet.exe"=

"C:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"C:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"11548:TCP"= 11548:TCP:BitComet 11548 TCP

"11548:UDP"= 11548:UDP:BitComet 11548 UDP

"24699:TCP"= 24699:TCP:BitComet 24699 TCP(ED2K)

"24699:UDP"= 24699:UDP:BitComet 24699 UDP(ED2K)

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [29/03/08 15:31]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [29/03/08 15:35]

 

.

Conte£do da pasta 'Tarefas Agendadas'

"2008-05-31 14:00:00 C:\WINDOWS\Tasks\ABF3C74494AC42BC.job"

- c:\docume~1\gilberto\dadosd~1\okaygr~1\Dash Blue Wipe.exe

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-31 11:38:05

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

.

**************************************************************************

.

Tempo para conclusÆo: 31/05/08 11:48:13 - machine was rebooted [gilberto]

ComboFix-quarantined-files.txt 2008-05-31 14:48:00

 

Pre-Run: 8,386,080,768 bytes disponíveis

Post-Run: 8.334.712.832 bytes dispon¡veis

 

237 --- E O F --- 2008-05-17 12:31:19

Compartilhar este post


Link para o post
Compartilhar em outros sites

Siga as Instruções:

Baixe o MSNfix.

Salve na área de trabalho, e descompacte ele, após isto, clique duas vezes em MSNFix.bat

Vai se abrir a tela MSN_Fix-menu nela aperte a opçãp R, será dado inicio ao scaneamento.

Caso o scan detecte algo irá aparecer a seguinte informação: Infection Presente, aperte enter, e prossiga.

Caso queira interromper o processo aperte a tecla Q

Na finalização vai se abrir o bloco de notas com um log, selecione todo ele e copie, que se encontra na pasta msnfix.txt.

Poste juntamente um novo log do Hijackthis

 

Aguardo o retorno.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ola assim q baixei o MSNFix ja deu erro na tela do prompt e nao apareceram as opçoes mesmo assim apertei a tecla R e ele simplesmente fechou,deixei sem mexer durante 15 minutos pq achei q estaria rodando mais nao aconteceu nada,entao encontrei um outro programa chamado MSN_PHOTO_VIRUS e apos ele detectar algumas dll´s ele reiniciou meu micro e produziu um log que eu reproduzo abaixo ,juntamente com o do Hijackthis :

 

 

Starting Scan...

Looking For Virus Services...

No Virus Services Found.

Looking For Virus Processes...

Found Virus Process(es)

MSMSGS.EXE ...Terminated

Searching for Virus Files...

Found C:\WINDOWS\system32\dllcache\iexplore.exe ...Removed

Scanning Registry...

Registry Scan Complete.

Scanning Hosts File...

No Infected Hosts File Entries Found.

Done!

Saving Log...

 

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 21:59:27, on 31/05/08

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Discador UOL 10.0 Light\Discador Light.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\gilberto\meus documentoss\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://m.busca.uol.com.br/ie/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: CUOLSearchHook Object - {1FE8243E-0A3A-41B9-B9CE-EFFEE51974D3} - C:\Arquivos de programas\Arquivos comuns\uol\urlsearch\UOLSearchHook.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll (file missing)

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [Timer] C:\Documents and Settings\gilberto\OUTROS PROGRAMAS\Timer-net.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Arquivos de programas\ICQToolbar\toolbaru.dll/SEARCH.HTML

O8 - Extra context menu item: Download all links using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download link using &BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Download videos using BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.7.4.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{57C60D2D-6BC4-4821-8D6E-BEE671B7DC49}: NameServer = 200.147.255.100 200.221.11.101

O17 - HKLM\System\CS1\Services\Tcpip\..\{57C60D2D-6BC4-4821-8D6E-BEE671B7DC49}: NameServer = 200.147.255.100 200.221.11.101

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sim reconheço esse é um programa que eu uso para controlar a minha conexão que é discada e com ele eu também consigo programar meu computador para desligar numa hora pré-determinada.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.