Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

noelle

[Arquivado] Erro de aplicativo "avgwdsvc.exe"

Recommended Posts

Olá,

Hoje instalei o programa "WindowBlinds" e junto a ele um programinha que alterava o SID, para poder utilizar o tal programa sem a necessidade de registrá-lo ou comprá-lo.

Como de praxe fiz um ponto de restauração do sistema, instalei e tudo funcionou normalmente.

Porém, mais tarde, ao ligar o pc novamente , aparecia mensagens de erro na tela de escolha de usuários, reiniciando o computador logo após clicar em OK. Tentei utilizar a restauração do sistema, mas não foi possível, pois ao clicar no botão "Avençar" nada ocorria. Deletei as contas de usuários, modifiquei novamente a SID (por uma aleatória, segundo o programa), reinicie e iniciou normalmente, porém durante a utilização do programa apareceu novamente a mensagem de erro:

Erro de aplicativo "avgwdsvc.exe"

A instrução "0x78147436" fez referência à memória no "0x009be000". A memória não pôde ser lida

 

Passei o HijackThis e eis o log:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:42:32, on 8/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\AVG\AVG8\avgscanx.exe

C:\ARQUIV~1\AVG\AVG8\avgupd.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{A773EB9C-AF40-4B71-84F7-D2F380E7B533}: NameServer = 85.255.114.88;85.255.112.72

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 5907 bytes

 

 

Agradeço desde já, espero que possam me ajudar.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Este processo "avgwdsvc.exe" é do seu antivirus AVG. Mas seu log possui infecções. O DNS de seu PC foi alterado por um trojan.

 

- Faça o download do Malwarebytes Anti-Malware e salve-o no desktop;

 

● Dê dois cliques no programa para iniciar a instalação. Selecione o idioma Português (Brasil);

● No meio da instalação, marque as opções "Atualizar Malwarebytes Anti-Malware" e "Executar Malwarebytes Anti-Malware", e clique em Concluir;

● Após a instalação execute o programa;

● Marque a opção Verificação Rápida e depois clique em Verificar;

● Quando o scan terminar, clique em OK e o log será automaticamente aberto para você;

● Se algo for detectado, verifique se todos os itens estão marcados e clique no botão Remover;

● O log pode ser consultado clicando em Logs do menu principal também;

 

Copie e cole o conteúdo desse log na sua próxima resposta, juntamente com um novo log do HijackThis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá MGuitar, obrigada pela rápida resposta :)

 

Aqui está o log Malwarebytes Anti-Malware:

(Não sei se está tudo certo, pois ele deu uma mensagem falando que alguns arquivos só seriam removidos após a reinicialização do computador, porém enquanto ele reiniciava, acho que "travou" e eu tive que desligar o computador. Mas espero que esteja tudo certo.)

 

Malwarebytes' Anti-Malware 1.31

Versão do banco de dados: 1475

Windows 5.1.2600 Service Pack 2

 

8/12/2008 22:46:25

mbam-log-2008-12-08 (22-46-25).txt

 

Tipo de Verificação: Rápida

Objetos verificados: 49727

Tempo decorrido: 2 minute(s), 43 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 6

Pastas infectadas: 1

Arquivos infectados: 8

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully.

 

Arquivos infectados:

C:\WINDOWS\system32\msqpdxosvdnrsr.dll (Trojan.Agent) -> Delete on reboot.

C:\WINDOWS\system32\drivers\msqpdxpaxtoexh.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\msqpdxriqpcfub.dll (Trojan.Agent) -> Delete on reboot.

C:\WINDOWS\system32\drivers\msqpdxserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\Temp\tempo-0B1.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully.

C:\WINDOWS\Temp\tempo-A21.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully.

C:\WINDOWS\Temp\tempo-B1B.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully.

 

 

E aqui o log do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:56:07, on 8/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\AVG\AVG8\avgupd.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 5561 bytes

 

Muito obrigada mesmo :)

Vamos ver se está tudo certo, né?

:)

Compartilhar este post


Link para o post
Compartilhar em outros sites

O trojan que alterou o DNS de seu sistema foi removido com sucesso. Por favor siga as instruções abaixo agora.

 

- Faça o download do ComboFix e salve-o na área de trabalho;

 

● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus;

● Duplo clique no ícone combofix.exe para iniciar o scan;

● Leia o contrato que aparecerá e clique em Sim para continuar;

● Abrirá uma janela do Console de Recuperação, clique em Sim para instalar. Se aparecer outra janela do Console, clique em OK > Sim;

● Aguarde enquanto o ComboFix faz o scan;

● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento;

Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta;

● Se quiser sair ou parar o ComboFix, tecle N;

● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde;

● Será gerado um log em C:\ComboFix.txt.

 

Cole este log em sua próxima resposta, juntamente com um novo log do HijackThis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá :)

Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo.

 

Log COMBOFIX:

 

ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00]

Executando de: c:\documents and settings\User\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

c:\arquivos de programas\Windows Live\Messenger\msimg32.dll

C:\Autorun.inf

c:\windows\IE4 Error Log.txt

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 ))))))))))))))))))))))))))))

.

 

2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun

2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun

2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java

2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl

2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro

2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos

2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão

2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876

2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão

2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador

2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys

2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock

2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini

2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2

2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2

2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock

2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll

2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live

2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar

2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite

2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead

2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic

2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini

2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack

2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer

2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe

2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE

2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools

2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent

2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent

2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts

2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData

2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES

2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll

2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm

2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm

2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm

2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm

2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm

2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm

2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm

2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm

2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm

2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$

2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm

2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm

2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm

2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm

2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm

2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm

2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm

2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm

2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm

2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm

2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm

2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm

2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm

2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm

2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm

2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8

2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys

2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll

2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead

2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead

2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET

2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works

2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG

2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink

2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink

2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll

2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll

2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll

2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll

2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll

2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

"Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104]

"uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

"Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]

"InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600]

"AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

 

c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]

Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704]

R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Stephanie\Configura []

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe

 

 

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-11 11:04:19

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys]

"imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys"

.

Tempo para conclusão: 2008-12-11 11:05:50

ComboFix-quarantined-files.txt 2008-12-11 13:05:29

 

Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis

Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis

 

224 --- E O F --- 2008-12-10 22:29:35

 

E aqui o log do HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:06:50, on 11/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 5892 bytes

 

Obrigada!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá :)

Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo.

 

Log COMBOFIX:

 

ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00]

Executando de: c:\documents and settings\User\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

c:\arquivos de programas\Windows Live\Messenger\msimg32.dll

C:\Autorun.inf

c:\windows\IE4 Error Log.txt

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 ))))))))))))))))))))))))))))

.

 

2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun

2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun

2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java

2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl

2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro

2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos

2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão

2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876

2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão

2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador

2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys

2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock

2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini

2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2

2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2

2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock

2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll

2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live

2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar

2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite

2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead

2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic

2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini

2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack

2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer

2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe

2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE

2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools

2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent

2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent

2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts

2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData

2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES

2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll

2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm

2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm

2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm

2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm

2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm

2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm

2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm

2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm

2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm

2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$

2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm

2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm

2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm

2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm

2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm

2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm

2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm

2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm

2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm

2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm

2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm

2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm

2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm

2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm

2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm

2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8

2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys

2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll

2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead

2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead

2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET

2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works

2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG

2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink

2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink

2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll

2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll

2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll

2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll

2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll

2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

"Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104]

"uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

"Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]

"InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600]

"AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

 

c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]

Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704]

R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Stephanie\Configura []

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe

 

 

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-11 11:04:19

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys]

"imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys"

.

Tempo para conclusão: 2008-12-11 11:05:50

ComboFix-quarantined-files.txt 2008-12-11 13:05:29

 

Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis

Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis

 

224 --- E O F --- 2008-12-10 22:29:35

 

E aqui o log do HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:06:50, on 11/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 5892 bytes

 

Obrigada!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá :)

Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo.

 

Log COMBOFIX:

 

ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00]

Executando de: c:\documents and settings\User\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

c:\arquivos de programas\Windows Live\Messenger\msimg32.dll

C:\Autorun.inf

c:\windows\IE4 Error Log.txt

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 ))))))))))))))))))))))))))))

.

 

2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun

2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun

2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java

2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl

2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro

2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos

2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão

2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876

2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão

2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador

2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys

2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock

2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini

2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2

2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2

2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock

2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll

2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live

2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar

2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite

2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead

2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic

2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini

2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack

2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer

2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe

2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE

2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools

2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent

2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent

2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts

2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData

2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES

2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll

2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm

2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm

2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm

2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm

2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm

2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm

2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm

2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm

2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm

2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm

2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$

2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm

2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm

2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm

2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm

2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm

2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm

2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm

2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm

2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm

2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm

2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm

2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm

2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm

2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm

2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm

2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8

2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys

2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll

2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead

2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead

2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET

2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works

2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG

2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink

2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink

2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll

2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll

2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll

2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll

2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll

2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

"Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104]

"uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

"Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]

"InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600]

"AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

 

c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]

Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704]

R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Stephanie\Configura []

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe

 

 

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-11 11:04:19

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys]

"imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys"

.

Tempo para conclusão: 2008-12-11 11:05:50

ComboFix-quarantined-files.txt 2008-12-11 13:05:29

 

Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis

Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis

 

224 --- E O F --- 2008-12-10 22:29:35

 

E aqui o log do HijackThis:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:06:50, on 11/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 5892 bytes

 

Obrigada!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ai, desculpa pelos posts repetidos =/

A minha internet travou e eu achei que não tinha sido enviado.

Enfim, eu não descobri como apaga, mas fique à vontade para fazê-lo.

Obrigada e desculpa :~

Compartilhar este post


Link para o post
Compartilhar em outros sites
Ai, desculpa pelos posts repetidos =/

A minha internet travou e eu achei que não tinha sido enviado.

Enfim, eu não descobri como apaga, mas fique à vontade para fazê-lo.

Obrigada e desculpa :~

Não se preocupe. O problema é no fórum mesmo.

 

Selecione e copie este texto aqui abaixo dentro do CODE (começando de File). Cole-o no bloco de notas de seu computador e salve-o na área de trabalho com o nome de CFScript.txt

 

File::C:\sqmdata18.sqmC:\sqmnoopt18.sqmC:\sqmnoopt19.sqmC:\sqmdata19.sqmC:\sqmdata17.sqmC:\sqmnoopt17.sqmC:\sqmdata16.sqmC:\sqmnoopt16.sqmC:\sqmdata15.sqmC:\sqmnoopt15.sqmC:\sqmdata14.sqmC:\sqmnoopt14.sqmC:\sqmdata13.sqmC:\sqmnoopt13.sqmC:\sqmdata12.sqmC:\sqmnoopt12.sqmC:\sqmdata11.sqmC:\sqmnoopt11.sqmC:\sqmdata10.sqmC:\sqmnoopt10.sqmC:\sqmdata09.sqmC:\sqmnoopt09.sqmC:\sqmdata08.sqmC:\sqmnoopt08.sqmC:\sqmdata07.sqmC:\sqmnoopt07.sqmC:\sqmdata06.sqmC:\sqmnoopt06.sqmRegistry::[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusDisableNotify"=dword:00000000"UpdatesDisableNotify"=dword:00000000

 

Arraste o CFScript para o ComboFix como na imagem aqui abaixo e aguarde a execução automática da ferramenta:

 

CFScript.gif

 

● Se for solicitado à você, pressione Enter para iniciar o processo de remoção;

Não use o mouse nem o teclado quando o ComboFix estiver rodando;

● Quando terminar, será gerado um novo log que estará em C:\ComboFix.txt;

● Talvez seu computador seja reiniciado automaticamente. Caso não ocorra, reinicie-o manualmente;

 

Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, dessa vez ocorreu tudo normalmente ;)

 

Aqui vai o log do ComboFix:

 

ComboFix 08-12-09.03 - User 2008-12-12 15:34:03.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.157 [GMT -2:00]

Executando de: c:\documents and settings\User\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\User\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

C:\sqmdata06.sqm

C:\sqmdata07.sqm

C:\sqmdata08.sqm

C:\sqmdata09.sqm

C:\sqmdata10.sqm

C:\sqmdata11.sqm

C:\sqmdata12.sqm

C:\sqmdata13.sqm

C:\sqmdata14.sqm

C:\sqmdata15.sqm

C:\sqmdata16.sqm

C:\sqmdata17.sqm

C:\sqmdata18.sqm

C:\sqmdata19.sqm

C:\sqmnoopt06.sqm

C:\sqmnoopt07.sqm

C:\sqmnoopt08.sqm

C:\sqmnoopt09.sqm

C:\sqmnoopt10.sqm

C:\sqmnoopt11.sqm

C:\sqmnoopt12.sqm

C:\sqmnoopt13.sqm

C:\sqmnoopt14.sqm

C:\sqmnoopt15.sqm

C:\sqmnoopt16.sqm

C:\sqmnoopt17.sqm

C:\sqmnoopt18.sqm

C:\sqmnoopt19.sqm

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\sqmdata06.sqm

C:\sqmdata07.sqm

C:\sqmdata08.sqm

C:\sqmdata09.sqm

C:\sqmdata10.sqm

C:\sqmdata11.sqm

C:\sqmdata12.sqm

C:\sqmdata13.sqm

C:\sqmdata14.sqm

C:\sqmdata15.sqm

C:\sqmdata16.sqm

C:\sqmdata17.sqm

C:\sqmdata18.sqm

C:\sqmdata19.sqm

C:\sqmnoopt06.sqm

C:\sqmnoopt07.sqm

C:\sqmnoopt08.sqm

C:\sqmnoopt09.sqm

C:\sqmnoopt10.sqm

C:\sqmnoopt11.sqm

C:\sqmnoopt12.sqm

C:\sqmnoopt13.sqm

C:\sqmnoopt14.sqm

C:\sqmnoopt15.sqm

C:\sqmnoopt16.sqm

C:\sqmnoopt17.sqm

C:\sqmnoopt18.sqm

C:\sqmnoopt19.sqm

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-12 to 2008-12-12 ))))))))))))))))))))))))))))

.

 

2008-12-12 15:18 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys

2008-12-12 15:18 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys

2008-12-12 10:56 . 2008-12-12 10:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Last.fm

2008-12-12 10:56 . 2008-12-12 10:56 <DIR> d-------- c:\arquivos de programas\Last.fm

2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun

2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun

2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java

2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl

2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys

2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro

2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos

2008-12-08 14:39 . 2008-12-12 15:36 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede

2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão

2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876

2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede

2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão

2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador

2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys

2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock

2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini

2008-12-05 12:37 . 2008-12-12 15:11 <DIR> d-------- c:\documents and settings\User\.rainlendar2

2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2

2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock

2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll

2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live

2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar

2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite

2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead

2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic

2008-11-27 14:45 . 2008-12-11 13:52 49 --a------ c:\windows\NeroDigital.ini

2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack

2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer

2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe

2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE

2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools

2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2008-11-26 21:46 . 2008-12-12 15:18 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent

2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent

2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts

2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData

2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES

2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll

2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8

2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys

2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll

2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead

2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero

2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead

2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET

2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works

2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG

2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink

2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink

2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll

2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll

2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll

2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll

2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll

2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys

.

 

((((((((((((((((((((((((((((( snapshot@2008-12-11_11.04.47.42 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-12-12 17:11:29 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_230.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]

"Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104]

"uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

"Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]

"InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600]

"AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

 

c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]

Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704]

R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-12 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Stephanie\Configura []

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-12 15:36:24

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys]

"imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(672)

c:\windows\system32\avgrsstx.dll

c:\windows\system32\Cabinet.dll

 

- - - - - - - > 'lsass.exe'(736)

c:\windows\system32\avgrsstx.dll

.

Tempo para conclusão: 2008-12-12 15:37:45

ComboFix-quarantined-files.txt 2008-12-12 17:37:25

ComboFix2.txt 2008-12-11 13:05:51

 

Pré-execução: 10 pasta(s) 47.080.034.304 bytes disponíveis

Pós execução: 10 pasta(s) 47,074,332,672 bytes disponíveis

 

260 --- E O F --- 2008-12-10 22:29:35

 

 

E o do HijackThis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:41:45, on 12/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\uTorrent\uTorrent.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

C:\Arquivos de programas\AVG\AVG8\avgtray.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 6391 bytes

 

Obrigada!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Olá, dessa vez ocorreu tudo normalmente ;)

Que bom, ótimo!

 

Acesse o Kaspersky Online Scanner e prossiga com um scan online seguindo o tutorial do link aqui abaixo.

 

Tutorial Kaspersky Online Scanner

 

Ao término do scan, salve o relatório com a extensão .txt em seu computador e poste-o em sua próxima resposta.

 

Uma pergunta: Como está o computador? Aquele problema que você descreveu no começo do tópico ainda ocorre?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá!

Não consegui rodar o programa, pois aparecem duas mensagens:

 

Your computer doesn't meet the requirements to run Kaspersky Online Scanner 7.0. Check the system requirements in the program help.

 

Attention: Kaspersky Online Scanner 7.0 may not run successfully while any other antivirus program is running. If you have another antivirus program installed, please turn it off before running Kaspersky Online Scanner 7.0.

 

Mesmo com o anti-vírus desabilitado.

Alguma idéia do que eu possa fazer?

 

Não, o problema inicial foi resolvido!

Compartilhar este post


Link para o post
Compartilhar em outros sites

- Com o navegador Internet Explorer, acesse o Eset Online Scanner;

- Marque a caixinha Yes, I accept the terms of use, e clique em Start.

- Na proxima janela clique com o botão direito sobre a caixinha e selecione Instalar controle activeX.

- Aguarde o aviso de segurança e clique em Instalar.

- Na proxima pagina, clique em Start e aguarde;

- Marque as auas caixinhas e clique em Scan. Aguarde;

- Quando o scan terminar o log podera ser visto em C:\arquivos de programas\esetonlinescanner\log.

 

Poste este log em sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.