bs_coelho 0 Denunciar post Postado Junho 5, 2008 Boa Tarde! Estou precisando de uma ajudinha para poder remover o Trojan.Generic.71725 de uma arquivo do sistema(Spoolsv.exe). Depois que encontrei esse trojan minha impressora parou de funcionar!! Por favor me ajudem!! Aki vai o log do hijackthis: Logfile of HijackThis v1.99.1 Scan saved at 14:51:59, on 5/6/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\MSN Messenger\msnmsgr.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\ARQUIV~1\Crawler\CToolbar.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\Bruno\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/ O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [ccRegVfy] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1194735831639 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Serviço de Auto-Protect do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\NISUM.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Programador do LiveUpdate automático - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe Desde ja agradeço pela atençao e a ajuda!!! Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 5, 2008 Baixe o ComboFix e salve na área de trabalho. Feche todos os programas. Clique duas vezes sobre combofix.exe e tecle (1) logo após aperte Enter para continuar. O ComboFix irá reiniciar seu computador automaticamente, isto faz parte do processo de remoção. Ao se encerrar, será gerado um log, que vai estar em C:\ComboFix.txt. Atenção: Não clique em nada enquanto o Combofix estiver rodando, Do contrário seu desktop ficará em branco. Para parar o processo ou sair do ComboFix, tecle "2" e Enter. Aguardo um novo log do HijackThis juntamente com o ComboFix.txt Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 5, 2008 Utilizei o ComboFix e O hijackthis novamente como foi pedido! Aki vai o ComboFix.txt: ComboFix 08-06-03.4 - Bruno 2008-06-05 16:03:53.3 - NTFSx86 Executando de: C:\Documents and Settings\Bruno\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\WINDOWS\Downloaded Program Files\setup.inf C:\WINDOWS\system32\Cfx32.lic C:\WINDOWS\system32\cfx32.ocx . ((((((((((((((((((((((( Ficheiros criados de 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))) . 2008-06-05 13:25 . 2001-10-28 15:07 20,238 --------- C:\SPOOLSV.EX_ 2008-06-05 13:25 . 2001-10-28 15:06 16,384 --------- C:\EXPAND.EXE 2008-06-05 12:13 . 2007-07-11 13:51 119,001 --------- C:\WINDOWS\hpoins11.dat.temp 2008-06-05 12:13 . 2006-05-05 21:17 11,634 --------- C:\WINDOWS\hpomdl11.dat.temp 2008-06-05 11:58 . 2008-06-05 11:59 20,284 --a------ C:\loterias3_temp_20080605.zip 2008-06-03 09:13 . 2008-06-03 09:14 20,284 --a------ C:\loterias3_temp_20080603.zip 2008-06-01 12:32 . 2008-06-01 12:32 <DIR> d-------- C:\Documents and Settings\COELHO\Dados de aplicativos\Symantec 2008-05-31 00:58 . 2008-05-31 00:58 <DIR> d-------- C:\Documents and Settings\LocalService\Dados de aplicativos\Symantec 2008-05-29 22:17 . 2008-05-29 22:17 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Vbox 2008-05-29 22:17 . 2008-05-29 22:17 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Macromedia 2008-05-29 22:16 . 2008-05-29 22:17 <DIR> d-------- C:\Arquivos de programas\Macromedia 2008-05-27 12:21 . 2008-05-27 12:21 0 --a------ C:\TP0C5ADB.$$$ 2008-05-27 12:01 . 2008-05-27 12:01 0 --a------ C:\TP0C0753.$$$ 2008-05-27 08:29 . 2008-05-27 08:30 20,178 --a------ C:\loterias3_temp_20080527.zip 2008-05-26 08:42 . 2008-05-26 08:43 20,066 --a------ C:\loterias3_temp_20080526.zip 2008-05-23 11:34 . 2008-06-05 14:59 <DIR> d-------- C:\Arquivos de programas\Crawler 2008-05-23 10:20 . 2008-05-23 10:20 <DIR> d-------- C:\Documents and Settings\COELHO\Dados de aplicativos\Notepad++ 2008-05-22 08:29 . 2008-05-22 08:30 20,066 --a------ C:\loterias3_temp_20080522.zip 2008-05-21 09:54 . 2008-05-21 09:55 20,066 --a------ C:\loterias3_temp_20080521.zip 2008-05-18 12:09 . 2008-05-18 12:09 <DIR> d-------- C:\Documents and Settings\Rafael\Nova pasta 2008-05-08 22:20 . 2008-05-25 03:03 <DIR> d-------- C:\Arquivos de programas\Notepad++ 2008-05-08 09:02 . 2008-05-08 09:03 19,857 --a------ C:\loterias3_temp_20080508.zip 2008-05-07 00:31 . 2008-05-07 00:31 0 --a------ C:\TP008720.$$$ 2008-05-06 12:30 . 2008-05-06 12:31 19,857 --a------ C:\loterias3_temp_20080506.zip . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-05 19:00 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-05 17:52 --------- d-----w C:\Arquivos de programas\Spyware Terminator 2008-06-05 17:44 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Spyware Terminator 2008-06-05 16:11 --------- d-----w C:\Documents and Settings\COELHO\Dados de aplicativos\Spyware Terminator 2008-06-05 12:24 --------- d-----w C:\Arquivos de programas\WinClamAVShield 2008-06-02 16:47 --------- d-----w C:\Documents and Settings\Rafael\Dados de aplicativos\LimeWire 2008-05-30 01:17 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-05-30 01:16 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-05-25 19:29 --------- d-----w C:\Arquivos de programas\a-squared Free 2008-05-24 14:38 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-05-21 00:10 --------- d-----w C:\Documents and Settings\COELHO\Dados de aplicativos\Image Zone Express 2008-05-17 21:21 --------- d-----w C:\Documents and Settings\Rafael\Dados de aplicativos\Spyware Terminator 2008-05-05 00:30 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software 2008-05-04 14:47 1,665 ----a-w C:\loterias3_temp_20080504.zip 2008-04-29 11:55 19,746 ----a-w C:\loterias3_temp_20080429.zip 2008-04-25 20:46 19,692 ----a-w C:\loterias3_temp_20080425.zip 2008-04-25 15:28 --------- d-----w C:\Arquivos de programas\Valve 2008-04-23 12:53 19,591 ----a-w C:\loterias3_temp_20080423.zip 2008-04-22 22:30 19,591 ----a-w C:\loterias3_temp_20080422.zip 2008-04-22 04:29 --------- d-----w C:\Arquivos de programas\eMule 2008-04-19 03:39 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-04-17 20:13 --------- d-----w C:\Arquivos de programas\Conduit 2008-04-17 20:12 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE 2008-04-17 20:12 --------- d-----w C:\Arquivos de programas\P2P_Energy 2008-04-16 21:40 --------- d-----w C:\Arquivos de programas\LimeWireTurbo 2008-04-16 21:25 --------- d-----w C:\Arquivos de programas\Shareaza Pro 2008-04-16 20:05 --------- d-----w C:\Arquivos de programas\Symantec 2008-04-16 18:25 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys 2008-04-06 16:02 --------- d-----w C:\Documents and Settings\Rafael\Dados de aplicativos\gridslowwin 2008-04-06 04:26 --------- d-----w C:\Arquivos de programas\Masfoot 2006 2008-03-14 21:11 19,037 ----a-w C:\loterias3_temp_20080314.zip 2008-03-03 20:37 24,192 ----a-w C:\Documents and Settings\Rafael\usbsermptxp.sys 2008-03-03 20:37 22,768 ----a-w C:\Documents and Settings\Rafael\usbsermpt.sys 2008-03-02 16:19 92,064 ----a-w C:\Documents and Settings\Bruno\mqdmmdm.sys 2008-03-02 16:19 9,232 ----a-w C:\Documents and Settings\Bruno\mqdmmdfl.sys 2008-03-02 16:19 79,328 ----a-w C:\Documents and Settings\Bruno\mqdmserd.sys 2008-03-02 16:19 66,656 ----a-w C:\Documents and Settings\Bruno\mqdmbus.sys 2008-03-02 16:19 6,208 ----a-w C:\Documents and Settings\Bruno\mqdmcmnt.sys 2008-03-02 16:19 5,936 ----a-w C:\Documents and Settings\Bruno\mqdmwhnt.sys 2008-03-02 16:19 4,048 ----a-w C:\Documents and Settings\Bruno\mqdmcr.sys 2008-03-02 16:19 25,600 ----a-w C:\Documents and Settings\Bruno\usbsermptxp.sys 2008-03-02 16:19 22,768 ----a-w C:\Documents and Settings\Bruno\usbsermpt.sys 2007-11-20 11:58 71,680 --sha-w C:\Arquivos de programas\Thumbs.db . ------- Sigcheck ------- 2004-08-04 03:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\SoftwareDistribution\Download\5a73e1547a48c6170f6f527eb3596c9b\ip6fw.sys . ((((((((((((((((((((((((((((( snapshot@2008-06-05_15.55.41,01 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-05 17:19:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-06-05 19:00:13 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2008-06-05 17:23:53 51,358 ----a-w C:\WINDOWS\system32\perfc009.dat + 2008-06-05 19:04:35 51,358 ----a-w C:\WINDOWS\system32\perfc009.dat - 2008-06-05 17:23:53 62,078 ----a-w C:\WINDOWS\system32\perfc016.dat + 2008-06-05 19:04:36 62,078 ----a-w C:\WINDOWS\system32\perfc016.dat - 2008-06-05 17:23:53 351,080 ----a-w C:\WINDOWS\system32\perfh009.dat + 2008-06-05 19:04:36 351,080 ----a-w C:\WINDOWS\system32\perfh009.dat - 2008-06-05 17:23:53 386,984 ----a-w C:\WINDOWS\system32\perfh016.dat + 2008-06-05 19:04:36 386,984 ----a-w C:\WINDOWS\system32\perfh016.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-28 15:06 13312] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-10-11 20:41 95960] "SoundMan"="SOUNDMAN.EXE" [2006-03-01 05:22 577536 C:\WINDOWS\soundman.exe] "SiSPower"="SiSPower.dll" [2006-05-05 10:13 49152 C:\WINDOWS\system32\SiSPower.dll] "ccRegVfy"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe" [2002-09-16 15:04 38576] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2002-09-16 15:04 54960] "SpywareTerminator"="C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-07 16:17 1817600] "TkBellExe"="C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-02-18 21:27 185896] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-28 15:06 13312] "Symantec NetDriver Warning"="C:\ARQUIV~1\SYMNET~1\SNDWarn.exe" [2005-07-29 10:37 218232] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.exe.lnk] backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^HP Digital Imaging Monitor.lnk] backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-01-11 22:16 39792 C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CoolSMS] --a------ 2007-08-28 16:01 1067520 C:\Arquivos de programas\CoolSMS\CoolSMS.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2006-02-19 02:41 49152 C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam] --a------ 2007-01-12 22:48 275800 C:\Arquivos de programas\Microsoft LifeCam\LifeExp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2001-08-02 07:14 1077277 C:\Arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ] --------- 2005-06-02 15:03 1957888 C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] -rahs---- 2008-01-28 11:43 2097488 C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-02-22 04:25 144784 C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] --a------ 2007-11-08 13:45 68856 C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2008-02-18 21:27 185896 C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000] -ra------ 2006-12-05 20:38 707360 C:\WINDOWS\vVX1000.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "InterBaseServer"=3 (0x3) "InterBaseGuardian"=2 (0x2) "MSCamSvc"=2 (0x2) "gusvc"=3 (0x3) "a2free"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . Conteúdo da pasta 'Tarefas Agendadas' "2007-08-03 21:59:43 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job" - E:\setup.exe "2008-04-18 23:00:05 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job" - C:\ARQUIV~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec\NORTON~2\Tasks\mycomp.sca . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-05 16:05:08 Windows 5.1.2600 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-06-05 16:06:41 ComboFix-quarantined-files.txt 2008-06-05 19:06:40 Pre-Run: 17,275,924,480 bytes disponíveis Post-Run: 17,265,766,400 bytes disponíveis 188 --- E O F --- 2008-03-24 13:06:55 E aki vai o novo log do hijack: Logfile of HijackThis v1.99.1 Scan saved at 16:07:24, on 5/6/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Bruno\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [ccRegVfy] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1194735831639 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Serviço de Auto-Protect do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\NISUM.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Programador do LiveUpdate automático - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 5, 2008 Siga as instruções abaixo: Faça o download do VundoFix no link : http://www.atribune.org/ccount/click.php?id=4 Clique duas vezes em VundoFix.exee ele ira iniciar. Ao abrir o VundoFix clique em scan for Vundo. Espere acabar o scan. Terminado o scan clique em Remove Vundo Irá aparecer um alerta lhe indagando se deseja remover os arquivos. Clique em YES. Sua área de trabalho irá sumir, mas não se preocupe isto é padrão. Reinicie o pc para que se complete o scan, clique em [OK Retorne com o log do VundoFix que se encontra em C:\vundofix.txt juntamente com um novo log do hijackthis Aguardo Retorno Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 6, 2008 Bom Silas, fiz o q você me pediu mas o VundoFix nao encontrou nada!!! =/ O q eu posso fazer agora?? Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 6, 2008 Sigas as instruções abaixo: Baixe o Bankerfix. desative o seu antivírus temporariamente, para não haver conflitos e para uma melhor detecção. Clique duas vezes sobre bankerfix.exe, dê o Enter e espere ele terminar. Ao terminar, leia a mensagem na tela e aperte Enter novamente. Habilite o seu antivírus. e gere um novo log do hijackthis. Aguardo o Retorno Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 6, 2008 O Banker tbm nao encontrou nda!!! =/ Mas msm assim to mandando um novo log do hijack!! Logfile of HijackThis v1.99.1 Scan saved at 22:30:27, on 5/6/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Documents and Settings\Bruno\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [ccRegVfy] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1194735831639 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Serviço de Auto-Protect do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\NISUM.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Programador do LiveUpdate automático - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 6, 2008 Log Limpo O problema persiste? Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 6, 2008 Tento adicionar uma impressora pois a q tinha antes sumiu e aparece a seguinte mensagem: Não foi possivel concluir a operação! Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 6, 2008 Bom verifique as conexões e o driver da impressora pois como o spooler foi contaminado é bem capaz que o driver tenha entrado em conflito. Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 6, 2008 Restaurei um ponto de restauraçao do windows...o problema da impressora sumiu mas o trojan ainda se encontra no pc...no spoolsv.exe e numa chave de registro!! Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 6, 2008 Siga as Instruções: Baixe o MSNfix. Salve na área de trabalho, e descompacte ele, após isto, clique duas vezes em MSNFix.bat Vai se abrir a tela MSN_Fix-menu nela aperte a opçãp R, será dado inicio ao scaneamento. Caso o scan detecte algo irá aparecer a seguinte informação: Infection Presente, aperte enter, e prossiga. Caso queira interromper o processo aperte a tecla Q Na finalização vai se abrir o bloco de notas com um log, selecione todo ele e copie, que se encontra na pasta msnfix.txt. Poste juntamente um novo log do Hijackthis Aguardo o retorno. Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 7, 2008 Aki vai o log do msnfix: MSNFix 1.720-1 C:\Documents and Settings\Bruno\Desktop\MSNFix Fix lançado dia s b 07/06/2008 - 2:11:50,04 By Bruno modo normal ************************ Procurando os arquivos presentes Nenhum arquivo encontrado ************************ Procurando as pastas presentes ... C:\WINDOWS\system32\service\ ************************ Apagando os arquivos ************************ Apagando as pastas .. OK ... C:\WINDOWS\system32\service\ ************************ Limpeza do registro ************************ Arquivos suspeitos /!\ Estes arquivos necessitam de uma opiniao de alguem competente antes de qualquer intervencao [C:\loterias3_temp_20080127.zip] CC1EEF756AC26B6140D202FAE0A14AE6 [C:\loterias3_temp_20080208.zip] CFB0C440FF4947F99F424DBC6EB9E9F9 [C:\loterias3_temp_20080216.zip] 9C259398EDFCF8150DAB6B96E3D52E04 [C:\loterias3_temp_20080221.zip] 40FA526509A8EA62F6BDC12D5774FE42 [C:\loterias3_temp_20080223.zip] FA7E126D45EDB142979BAC43087F4713 [C:\loterias3_temp_20080227.zip] 1B2EB9DACDDB61E628C03BF229F66E6B [C:\loterias3_temp_20080304.zip] C64317EC56F1DD8C040791CD52085026 [C:\loterias3_temp_20080314.zip] 9F7D02A1368DE71FB89264A299C95657 [C:\loterias3_temp_20080422.zip] 6EDAC53F1A0C9162015F001C13FBE086 [C:\loterias3_temp_20080423.zip] 6EDAC53F1A0C9162015F001C13FBE086 [C:\loterias3_temp_20080425.zip] 76A3A67023AC89910B9D9BE8ADFECA9B [C:\loterias3_temp_20080429.zip] 9C4A985862866E0ACB4E8C05EAF20AF4 [C:\loterias3_temp_20080504.zip] 741927E3276FB7460849088F17167602 [C:\loterias3_temp_20080506.zip] 5B50911460A422BD9127F01F5F156153 [C:\loterias3_temp_20080508.zip] 5B50911460A422BD9127F01F5F156153 [C:\loterias3_temp_20080521.zip] 21948DA0F6D43951E51895F24D659B01 [C:\loterias3_temp_20080522.zip] 21948DA0F6D43951E51895F24D659B01 [C:\loterias3_temp_20080526.zip] 6226B6F66D208C5263D788F457323DD1 [C:\loterias3_temp_20080527.zip] AE0F927CD3EA7859ADDD78FE4F291260 [C:\loterias3_temp_20080603.zip] 77C7BF0F8396591EFAF1A6ACC78635AE [C:\loterias3_temp_20080605.zip] 77C7BF0F8396591EFAF1A6ACC78635AE ==> Por favor não esqueça de mandar o arquivo C:\DOCUME~1\Bruno\Desktop\Upload_Me.zip no http://upload.changelog.fr Os arquivos e as chaves do registro apagados foram salvos no arquivo s b 07062008_ 2124489.zip ************************ HKLM\...\Winlogon\Userinit Userinit = C:\WINDOWS\system32\userinit.exe, ------------------------------------------------------------------------ Autor : !aur3n7 Contact: http://changelog.fr ------------------------------------------------------------------------ --------------------------------------------- END --------------------------------------------- E aki o log do hijack após o msnfix: Logfile of HijackThis v1.99.1 Scan saved at 02:14:14, on 7/6/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\Bruno\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/ O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [ccRegVfy] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1194735831639 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Serviço de Auto-Protect do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\NISUM.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Programador do LiveUpdate automático - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 7, 2008 Siga as instruções abaixo: Iniciar » Configurações » Painel de Controle » Opções de Pasta » Na Aba: Modo de Exibição » Selecione "Mostrar Todos os Arquivos Ocultos do Sistema. Faça o Active Scan Ignore qualquer alerta sobre um possível virus. Clique sobre Analisar e logo em seguida forneças as informações pedidas, Na seleção do modo de scan escolhaPesquise agora sem custos" Siga todas as instruções que lhe serão passadas e aguarde o fim da varredura. Quando finalizar o scan clique em visualizar o log e o salve, após salvo poste o log do scan aqui. Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 7, 2008 Aki vai o log do activescan: ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2008-06-07 13:35:00 PROTECTIONS: 1 MALWARE: 11 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== Norton AntiVirus 2003 No Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00122168 Application/Restart HackTools No 0 Yes No C:\WINDOWS\system32\Tools\Restart.exe 00139535 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Bruno\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\Cache\27FB1AB7d01[MSNFix/incl/Process.exe] 00139535 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Bruno\Desktop\MSNFix\incl\Process.exe 00139535 Application/Processor HackTools No 0 Yes No D:\Programas\MSNFix.zip[MSNFix/incl/Process.exe] 00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.yadro.ru/] 00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.xiti.com/] 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Cookies\bruno@bs.serving-sys[1].txt 00170553 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.ig.com.br/] 00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Rafael\Cookies\rafael@overture[1].txt 00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.overture.com/] 00170557 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.terra.com.br/] 00170559 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Cookies\bruno@uol.com[2].txt 00170559 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Bruno\Dados de aplicativos\Mozilla\Firefox\Profiles\6h5fvb1t.default\cookies.txt[.uol.com.br/] 01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{EC66E716-9BE9-4A75-8787-E7998F0C9043}\RP278\A0264334.exe[327882R2FWJFW\NirCmdC.cfexe] 01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{EC66E716-9BE9-4A75-8787-E7998F0C9043}\RP278\A0264202.exe[327882R2FWJFW\NirCmdC.cfexe] 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{EC66E716-9BE9-4A75-8787-E7998F0C9043}\RP277\A0264002.EXE ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location d) 3Y ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description d) 3Y ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= =================== Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 8, 2008 Siga as instruções abaixo: Clique com o botão direito do mouse em cima do MEU COMPUTADOR/ Propiedades/ Restauração do Sistema/ marque Desativar Restauração do Sistema Depois a versão share do kaspersky: Kaspersky Esta é uma versão trial é só para eliminar algumas pragas depois disto desisntale Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 8, 2008 Pow Silas, to ficando grilado com esse pc ja...uhauhauhauhauhauhahuhauh ao abrir internet explorer e qnd vai carregar outra pagina a nao ser a principal ele fecha automaticamente...e o windows media player idem...ao abrir clico em qlqr botao pra escutar as musicas e ele fecha automaticamente... vou mandar um novo log do hijack pra você ver se tem algo de estranho Logfile of HijackThis v1.99.1 Scan saved at 13:39:43, on 8/6/2008 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton Internet Security\NISUM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\ctfmon.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\MSN Messenger\msnmsgr.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Documents and Settings\Bruno\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/ O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file) O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\ctbr.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [ccRegVfy] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O8 - Extra context menu item: Crawler Search - tbr:iemenu O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Estatísticas do Antivírus da Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1194735831639 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\ccPxySvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Serviço de Auto-Protect do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\NISUM.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Programador do LiveUpdate automático - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe Desde ja agradeço a você por me aturar e me ajudar!!! Vlw msm!!! Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 9, 2008 Execute o HijackThis, selecione as linhas: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb Clique em Fix Checked Gere um novo log do hiajckthis Aguardo Retorno Compartilhar este post Link para o post Compartilhar em outros sites
bs_coelho 0 Denunciar post Postado Junho 9, 2008 Agradeço a você Silas por toda a atençao q teve comigo!! Ontem uma onda de problemas aconteceram no meu pc e fui obrigado a formata-lo!!! Mas mto obrigado pela ajuda q você me deu!! você ta de parabens pelo q você faz pelas pessoas!! Mta gente nao tem paciencia de ajudar!! :clap: Vlw msm por td!!! :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Junho 13, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites