noelle 0 Denunciar post Postado Dezembro 8, 2008 Olá, Hoje instalei o programa "WindowBlinds" e junto a ele um programinha que alterava o SID, para poder utilizar o tal programa sem a necessidade de registrá-lo ou comprá-lo. Como de praxe fiz um ponto de restauração do sistema, instalei e tudo funcionou normalmente. Porém, mais tarde, ao ligar o pc novamente , aparecia mensagens de erro na tela de escolha de usuários, reiniciando o computador logo após clicar em OK. Tentei utilizar a restauração do sistema, mas não foi possível, pois ao clicar no botão "Avençar" nada ocorria. Deletei as contas de usuários, modifiquei novamente a SID (por uma aleatória, segundo o programa), reinicie e iniciou normalmente, porém durante a utilização do programa apareceu novamente a mensagem de erro: Erro de aplicativo "avgwdsvc.exe" A instrução "0x78147436" fez referência à memória no "0x009be000". A memória não pôde ser lida Passei o HijackThis e eis o log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:42:32, on 8/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\AVG\AVG8\avgscanx.exe C:\ARQUIV~1\AVG\AVG8\avgupd.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{A773EB9C-AF40-4B71-84F7-D2F380E7B533}: NameServer = 85.255.114.88;85.255.112.72 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.88;85.255.112.72 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 5907 bytes Agradeço desde já, espero que possam me ajudar. Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 8, 2008 Este processo "avgwdsvc.exe" é do seu antivirus AVG. Mas seu log possui infecções. O DNS de seu PC foi alterado por um trojan. - Faça o download do Malwarebytes Anti-Malware e salve-o no desktop; ● Dê dois cliques no programa para iniciar a instalação. Selecione o idioma Português (Brasil); ● No meio da instalação, marque as opções "Atualizar Malwarebytes Anti-Malware" e "Executar Malwarebytes Anti-Malware", e clique em Concluir; ● Após a instalação execute o programa; ● Marque a opção Verificação Rápida e depois clique em Verificar; ● Quando o scan terminar, clique em OK e o log será automaticamente aberto para você; ● Se algo for detectado, verifique se todos os itens estão marcados e clique no botão Remover; ● O log pode ser consultado clicando em Logs do menu principal também; Copie e cole o conteúdo desse log na sua próxima resposta, juntamente com um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 9, 2008 Olá MGuitar, obrigada pela rápida resposta :) Aqui está o log Malwarebytes Anti-Malware: (Não sei se está tudo certo, pois ele deu uma mensagem falando que alguns arquivos só seriam removidos após a reinicialização do computador, porém enquanto ele reiniciava, acho que "travou" e eu tive que desligar o computador. Mas espero que esteja tudo certo.) Malwarebytes' Anti-Malware 1.31 Versão do banco de dados: 1475 Windows 5.1.2600 Service Pack 2 8/12/2008 22:46:25 mbam-log-2008-12-08 (22-46-25).txt Tipo de Verificação: Rápida Objetos verificados: 49727 Tempo decorrido: 2 minute(s), 43 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 0 Valores do Registro infectados: 0 Ítens do Registro infectados: 6 Pastas infectadas: 1 Arquivos infectados: 8 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: (Nenhum ítem malicioso foi detectado) Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{a773eb9c-af40-4b71-84f7-d2f380e7b533}\NameServer (Trojan.DNSChanger) -> Data: 85.255.114.88;85.255.112.72 -> Quarantined and deleted successfully. Pastas infectadas: C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully. Arquivos infectados: C:\WINDOWS\system32\msqpdxosvdnrsr.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\msqpdxpaxtoexh.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\resycled\boot.com (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msqpdxriqpcfub.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\msqpdxserv.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tempo-0B1.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tempo-A21.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tempo-B1B.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. E aqui o log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:56:07, on 8/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\wuauclt.exe C:\ARQUIV~1\AVG\AVG8\avgupd.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 5561 bytes Muito obrigada mesmo :) Vamos ver se está tudo certo, né? :) Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 9, 2008 O trojan que alterou o DNS de seu sistema foi removido com sucesso. Por favor siga as instruções abaixo agora. - Faça o download do ComboFix e salve-o na área de trabalho; ● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus; ● Duplo clique no ícone combofix.exe para iniciar o scan; ● Leia o contrato que aparecerá e clique em Sim para continuar; ● Abrirá uma janela do Console de Recuperação, clique em Sim para instalar. Se aparecer outra janela do Console, clique em OK > Sim; ● Aguarde enquanto o ComboFix faz o scan; ● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento; ● Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta; ● Se quiser sair ou parar o ComboFix, tecle N; ● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde; ● Será gerado um log em C:\ComboFix.txt. Cole este log em sua próxima resposta, juntamente com um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 11, 2008 Olá :) Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo. Log COMBOFIX: ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00] Executando de: c:\documents and settings\User\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:\arquivos de programas\Windows Live\Messenger\msimg32.dll C:\Autorun.inf c:\windows\IE4 Error Log.txt . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))) . 2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun 2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun 2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java 2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl 2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0 2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys 2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$ 2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos 2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão 2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876 2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão 2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador 2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys 2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock 2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini 2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2 2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2 2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock 2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll 2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus! 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live 2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar 2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite 2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead 2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic 2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini 2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack 2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer 2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe 2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE 2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools 2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent 2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent 2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts 2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData 2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES 2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll 2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm 2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm 2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm 2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm 2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm 2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm 2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm 2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm 2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm 2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm 2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm 2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm 2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm 2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm 2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm 2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm 2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm 2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm 2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm 2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm 2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm 2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm 2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm 2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm 2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys 2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll 2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead 2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead 2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET 2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works 2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG 2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink 2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink 2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage 2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line 2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços 2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll 2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll 2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll 2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll 2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104] "uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] "Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208] "InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600] "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704] R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job - c:\documents and settings\Stephanie\Configura [] . - - - - ORFÃOS REMOVIDOS - - - - HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-11 11:04:19 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys] "imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys" . Tempo para conclusão: 2008-12-11 11:05:50 ComboFix-quarantined-files.txt 2008-12-11 13:05:29 Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis 224 --- E O F --- 2008-12-10 22:29:35 E aqui o log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:06:50, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 5892 bytes Obrigada! Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 11, 2008 Olá :) Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo. Log COMBOFIX: ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00] Executando de: c:\documents and settings\User\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:\arquivos de programas\Windows Live\Messenger\msimg32.dll C:\Autorun.inf c:\windows\IE4 Error Log.txt . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))) . 2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun 2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun 2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java 2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl 2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0 2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys 2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$ 2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos 2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão 2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876 2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão 2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador 2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys 2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock 2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini 2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2 2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2 2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock 2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll 2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus! 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live 2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar 2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite 2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead 2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic 2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini 2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack 2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer 2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe 2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE 2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools 2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent 2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent 2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts 2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData 2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES 2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll 2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm 2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm 2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm 2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm 2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm 2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm 2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm 2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm 2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm 2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm 2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm 2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm 2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm 2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm 2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm 2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm 2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm 2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm 2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm 2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm 2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm 2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm 2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm 2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm 2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys 2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll 2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead 2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead 2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET 2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works 2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG 2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink 2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink 2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage 2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line 2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços 2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll 2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll 2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll 2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll 2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104] "uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] "Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208] "InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600] "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704] R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job - c:\documents and settings\Stephanie\Configura [] . - - - - ORFÃOS REMOVIDOS - - - - HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-11 11:04:19 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys] "imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys" . Tempo para conclusão: 2008-12-11 11:05:50 ComboFix-quarantined-files.txt 2008-12-11 13:05:29 Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis 224 --- E O F --- 2008-12-10 22:29:35 E aqui o log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:06:50, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 5892 bytes Obrigada! Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 11, 2008 Olá :) Fiz o que foi pedido, porém o ComboFix não reiniciou meu computador... Mas acho que deu tudo certo. Log COMBOFIX: ComboFix 08-12-09.03 - User 2008-12-11 11:02:27.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.270 [GMT -2:00] Executando de: c:\documents and settings\User\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:\arquivos de programas\Windows Live\Messenger\msimg32.dll C:\Autorun.inf c:\windows\IE4 Error Log.txt . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))) . 2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun 2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun 2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java 2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl 2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0 2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys 2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$ 2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos 2008-12-08 14:39 . 2008-12-11 11:04 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão 2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876 2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão 2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador 2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys 2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock 2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini 2008-12-05 12:37 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\.rainlendar2 2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2 2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock 2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll 2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus! 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live 2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar 2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite 2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead 2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic 2008-11-27 14:45 . 2008-12-05 16:15 49 --a------ c:\windows\NeroDigital.ini 2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack 2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer 2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe 2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE 2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools 2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-11-26 21:46 . 2008-12-11 11:00 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent 2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent 2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts 2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData 2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES 2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll 2008-11-17 18:43 . 2008-11-17 18:43 268 --ah----- C:\sqmdata18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 244 --ah----- C:\sqmnoopt18.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmnoopt19.sqm 2008-11-17 18:43 . 2008-11-17 18:43 172 --ah----- C:\sqmdata19.sqm 2008-11-16 20:44 . 2008-11-16 20:44 268 --ah----- C:\sqmdata17.sqm 2008-11-16 20:44 . 2008-11-16 20:44 244 --ah----- C:\sqmnoopt17.sqm 2008-11-16 16:55 . 2008-11-16 16:55 268 --ah----- C:\sqmdata16.sqm 2008-11-16 16:55 . 2008-11-16 16:55 244 --ah----- C:\sqmnoopt16.sqm 2008-11-16 16:47 . 2008-11-16 16:47 268 --ah----- C:\sqmdata15.sqm 2008-11-16 16:47 . 2008-11-16 16:47 244 --ah----- C:\sqmnoopt15.sqm 2008-11-16 11:43 . 2008-11-16 11:43 268 --ah----- C:\sqmdata14.sqm 2008-11-16 11:43 . 2008-11-16 11:43 244 --ah----- C:\sqmnoopt14.sqm 2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-11-15 20:15 . 2008-11-15 20:15 268 --ah----- C:\sqmdata13.sqm 2008-11-15 20:15 . 2008-11-15 20:15 244 --ah----- C:\sqmnoopt13.sqm 2008-11-15 19:51 . 2008-11-15 19:51 268 --ah----- C:\sqmdata12.sqm 2008-11-15 19:51 . 2008-11-15 19:51 244 --ah----- C:\sqmnoopt12.sqm 2008-11-15 19:02 . 2008-11-15 19:02 268 --ah----- C:\sqmdata11.sqm 2008-11-15 19:02 . 2008-11-15 19:02 244 --ah----- C:\sqmnoopt11.sqm 2008-11-15 18:57 . 2008-11-15 18:57 268 --ah----- C:\sqmdata10.sqm 2008-11-15 18:57 . 2008-11-15 18:57 244 --ah----- C:\sqmnoopt10.sqm 2008-11-15 18:56 . 2008-11-15 18:56 268 --ah----- C:\sqmdata09.sqm 2008-11-15 18:56 . 2008-11-15 18:56 244 --ah----- C:\sqmnoopt09.sqm 2008-11-15 09:54 . 2008-11-15 09:54 268 --ah----- C:\sqmdata08.sqm 2008-11-15 09:54 . 2008-11-15 09:54 244 --ah----- C:\sqmnoopt08.sqm 2008-11-15 09:51 . 2008-11-15 09:51 268 --ah----- C:\sqmdata07.sqm 2008-11-15 09:51 . 2008-11-15 09:51 244 --ah----- C:\sqmnoopt07.sqm 2008-11-14 19:18 . 2008-11-14 19:18 268 --ah----- C:\sqmdata06.sqm 2008-11-14 19:18 . 2008-11-14 19:18 244 --ah----- C:\sqmnoopt06.sqm . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys 2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll 2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead 2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead 2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET 2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works 2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG 2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink 2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink 2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage 2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line 2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços 2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll 2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll 2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll 2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll 2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104] "uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] "Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208] "InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600] "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704] R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-11 c:\windows\Tasks\GoogleUpdateTaskUser.job - c:\documents and settings\Stephanie\Configura [] . - - - - ORFÃOS REMOVIDOS - - - - HKCU-Run-RocketDock - c:\arquivos de programas\RocketDock\RocketDock.exe ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-11 11:04:19 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys] "imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys" . Tempo para conclusão: 2008-12-11 11:05:50 ComboFix-quarantined-files.txt 2008-12-11 13:05:29 Pré-execução: 10 pasta(s) 44,549,451,776 bytes disponíveis Pós execução: 10 pasta(s) 44,596,686,848 bytes disponíveis 224 --- E O F --- 2008-12-10 22:29:35 E aqui o log do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:06:50, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 5892 bytes Obrigada! Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 11, 2008 Ai, desculpa pelos posts repetidos =/ A minha internet travou e eu achei que não tinha sido enviado. Enfim, eu não descobri como apaga, mas fique à vontade para fazê-lo. Obrigada e desculpa :~ Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 11, 2008 Ai, desculpa pelos posts repetidos =/A minha internet travou e eu achei que não tinha sido enviado. Enfim, eu não descobri como apaga, mas fique à vontade para fazê-lo. Obrigada e desculpa :~ Não se preocupe. O problema é no fórum mesmo. Selecione e copie este texto aqui abaixo dentro do CODE (começando de File). Cole-o no bloco de notas de seu computador e salve-o na área de trabalho com o nome de CFScript.txt File::C:\sqmdata18.sqmC:\sqmnoopt18.sqmC:\sqmnoopt19.sqmC:\sqmdata19.sqmC:\sqmdata17.sqmC:\sqmnoopt17.sqmC:\sqmdata16.sqmC:\sqmnoopt16.sqmC:\sqmdata15.sqmC:\sqmnoopt15.sqmC:\sqmdata14.sqmC:\sqmnoopt14.sqmC:\sqmdata13.sqmC:\sqmnoopt13.sqmC:\sqmdata12.sqmC:\sqmnoopt12.sqmC:\sqmdata11.sqmC:\sqmnoopt11.sqmC:\sqmdata10.sqmC:\sqmnoopt10.sqmC:\sqmdata09.sqmC:\sqmnoopt09.sqmC:\sqmdata08.sqmC:\sqmnoopt08.sqmC:\sqmdata07.sqmC:\sqmnoopt07.sqmC:\sqmdata06.sqmC:\sqmnoopt06.sqmRegistry::[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusDisableNotify"=dword:00000000"UpdatesDisableNotify"=dword:00000000 Arraste o CFScript para o ComboFix como na imagem aqui abaixo e aguarde a execução automática da ferramenta: ● Se for solicitado à você, pressione Enter para iniciar o processo de remoção; ● Não use o mouse nem o teclado quando o ComboFix estiver rodando; ● Quando terminar, será gerado um novo log que estará em C:\ComboFix.txt; ● Talvez seu computador seja reiniciado automaticamente. Caso não ocorra, reinicie-o manualmente; Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 12, 2008 Olá, dessa vez ocorreu tudo normalmente ;) Aqui vai o log do ComboFix: ComboFix 08-12-09.03 - User 2008-12-12 15:34:03.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.157 [GMT -2:00] Executando de: c:\documents and settings\User\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\User\Desktop\CFScript.txt * Criado um novo ponto de restauro FILE :: C:\sqmdata06.sqm C:\sqmdata07.sqm C:\sqmdata08.sqm C:\sqmdata09.sqm C:\sqmdata10.sqm C:\sqmdata11.sqm C:\sqmdata12.sqm C:\sqmdata13.sqm C:\sqmdata14.sqm C:\sqmdata15.sqm C:\sqmdata16.sqm C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmdata19.sqm C:\sqmnoopt06.sqm C:\sqmnoopt07.sqm C:\sqmnoopt08.sqm C:\sqmnoopt09.sqm C:\sqmnoopt10.sqm C:\sqmnoopt11.sqm C:\sqmnoopt12.sqm C:\sqmnoopt13.sqm C:\sqmnoopt14.sqm C:\sqmnoopt15.sqm C:\sqmnoopt16.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm C:\sqmnoopt19.sqm . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\sqmdata06.sqm C:\sqmdata07.sqm C:\sqmdata08.sqm C:\sqmdata09.sqm C:\sqmdata10.sqm C:\sqmdata11.sqm C:\sqmdata12.sqm C:\sqmdata13.sqm C:\sqmdata14.sqm C:\sqmdata15.sqm C:\sqmdata16.sqm C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmdata19.sqm C:\sqmnoopt06.sqm C:\sqmnoopt07.sqm C:\sqmnoopt08.sqm C:\sqmnoopt09.sqm C:\sqmnoopt10.sqm C:\sqmnoopt11.sqm C:\sqmnoopt12.sqm C:\sqmnoopt13.sqm C:\sqmnoopt14.sqm C:\sqmnoopt15.sqm C:\sqmnoopt16.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm C:\sqmnoopt19.sqm . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))) . 2008-12-12 15:18 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys 2008-12-12 15:18 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys 2008-12-12 10:56 . 2008-12-12 10:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Last.fm 2008-12-12 10:56 . 2008-12-12 10:56 <DIR> d-------- c:\arquivos de programas\Last.fm 2008-12-10 22:19 . 2008-12-10 22:19 <DIR> d-------- c:\windows\Sun 2008-12-10 21:41 . 2008-12-10 21:41 <DIR> d-------- c:\arquivos de programas\Sun 2008-12-10 21:40 . 2008-12-10 21:40 <DIR> d-------- c:\arquivos de programas\Java 2008-12-10 21:40 . 2008-12-10 21:40 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-10 21:40 . 2008-12-10 21:40 73,728 --a------ c:\windows\system32\javacpl.cpl 2008-12-10 20:23 . 2008-12-10 20:23 <DIR> d-------- c:\arquivos de programas\MSXML 4.0 2008-12-10 00:27 . 2008-08-14 11:45 2,184,576 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,140,160 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,061,952 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2008-12-10 00:27 . 2008-08-14 11:45 2,019,840 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2008-12-10 00:26 . 2008-10-24 09:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 --------- c:\windows\system32\drivers\bthport.sys 2008-12-10 00:24 . 2008-06-14 15:59 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys 2008-12-09 20:40 . 2008-12-10 20:29 <DIR> d--h----- c:\windows\$hf_mig$ 2008-12-09 20:40 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2008-12-08 22:42 . 2008-12-08 22:42 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2008-12-08 22:42 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 22:42 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2008-12-08 15:29 . 2008-12-08 15:29 <DIR> d-------- c:\arquivos de programas\Trend Micro 2008-12-08 14:39 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Modelos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Meus documentos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador.WINDOWS-810F876\Menu Iniciar 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876\Favoritos 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador.WINDOWS-810F876\Dados de aplicativos 2008-12-08 14:39 . 2008-12-12 15:36 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Configurações locais 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de rede 2008-12-08 14:39 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador.WINDOWS-810F876\Ambiente de impressão 2008-12-08 14:39 . 2008-12-08 14:39 <DIR> d-------- c:\documents and settings\Administrador.WINDOWS-810F876 2008-12-08 14:27 . 2008-11-10 11:56 <DIR> d--h----- c:\documents and settings\Administrador\Modelos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d-------- c:\documents and settings\Administrador\Favoritos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede 2008-12-08 14:27 . 2008-11-10 09:49 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão 2008-12-08 14:27 . 2008-12-08 14:27 <DIR> d-------- c:\documents and settings\Administrador 2008-12-08 12:01 . 2008-12-08 12:33 27,904 --a------ c:\windows\system32\drivers\Ndisprot.sys 2008-12-05 12:55 . 2008-12-08 14:59 <DIR> d-------- c:\arquivos de programas\RocketDock 2008-12-05 12:39 . 2008-12-05 12:39 0 --a------ c:\windows\WB.ini 2008-12-05 12:37 . 2008-12-12 15:11 <DIR> d-------- c:\documents and settings\User\.rainlendar2 2008-12-05 12:37 . 2008-12-05 12:37 <DIR> d-------- c:\arquivos de programas\Rainlendar2 2008-12-05 12:35 . 2008-12-05 12:35 <DIR> d-------- c:\arquivos de programas\Stardock 2008-12-05 12:35 . 2008-04-26 16:14 42,672 --a------ c:\windows\system32\wbsys.dll 2008-12-02 09:16 . 2008-12-02 09:16 <DIR> d-------- c:\documents and settings\User\Configuraes locais 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2008-12-02 00:28 . 2008-12-02 00:28 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2008-11-29 09:45 . 2008-11-29 09:45 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus! 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-29 09:43 . 2008-11-29 09:43 <DIR> d-------- c:\arquivos de programas\Messenger Plus! Live 2008-11-28 14:34 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar 2008-11-28 14:33 . 2008-11-28 14:34 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite 2008-11-27 19:46 . 2008-11-27 19:48 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Ahead 2008-11-27 14:45 . 2008-11-27 14:45 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Media Player Classic 2008-11-27 14:45 . 2008-12-11 13:52 49 --a------ c:\windows\NeroDigital.ini 2008-11-27 11:30 . 2008-11-27 11:30 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack 2008-11-26 23:56 . 2008-11-27 12:47 <DIR> d-------- c:\arquivos de programas\Sims 2 Categorizer 2008-11-26 23:56 . 2008-11-26 23:56 249,856 --a------ c:\windows\Setup1.exe 2008-11-26 23:56 . 2008-11-26 23:56 73,216 --a------ c:\windows\ST6UNST.EXE 2008-11-26 22:21 . 2008-11-26 22:21 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\DAEMON Tools 2008-11-26 22:21 . 2008-11-26 22:21 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-11-26 21:46 . 2008-12-12 15:18 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\uTorrent 2008-11-26 21:46 . 2008-11-26 21:46 <DIR> d-------- c:\arquivos de programas\uTorrent 2008-11-26 20:23 . 2008-11-27 10:14 <DIR> d-------- c:\documents and settings\User\Contacts 2008-11-26 19:23 . 2008-11-26 19:23 <DIR> d---s---- c:\documents and settings\User\UserData 2008-11-26 13:40 . 2008-11-28 17:39 <DIR> d-------- c:\arquivos de programas\EA GAMES 2008-11-26 13:40 . 2004-08-18 06:34 442,368 -ra------ c:\windows\system32\vp6vfw.dll 2008-11-16 09:14 . 2008-11-28 19:06 <DIR> d--h----- C:\$AVG8.VAULT$ . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-08 17:19 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\avg8 2008-12-02 02:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-29 11:43 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-11-27 09:08 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-27 09:08 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys 2008-11-27 09:08 10,520 ----a-w c:\windows\system32\avgrsstx.dll 2008-11-10 16:41 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Ahead 2008-11-10 16:40 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Nero 2008-11-10 16:40 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead 2008-11-10 16:21 --------- d-----w c:\arquivos de programas\Microsoft.NET 2008-11-10 16:20 --------- d-----w c:\arquivos de programas\Microsoft Works 2008-11-10 16:08 --------- d-----w c:\arquivos de programas\AVG 2008-11-10 16:02 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-10 16:02 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\CyberLink 2008-11-10 16:02 --------- d-----w c:\arquivos de programas\CyberLink 2008-11-10 16:01 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-11-10 14:01 --------- d-----w c:\arquivos de programas\microsoft frontpage 2008-11-10 13:59 --------- d-----w c:\arquivos de programas\Serviços on-line 2008-11-10 13:58 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços 2008-11-02 14:02 7,680 ----a-w c:\windows\system32\ff_vfw.dll 2008-10-28 22:35 684,032 ----a-w c:\windows\system32\divx.dll 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 10:39 661,504 ----a-w c:\windows\system32\wininet.dll 2008-10-03 10:16 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll 2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll 2008-09-15 15:40 1,846,144 ----a-w c:\windows\system32\win32k.sys . ((((((((((((((((((((((((((((( snapshot@2008-12-11_11.04.47.42 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-12 17:11:29 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_230.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352] "Google Update"="c:\documents and settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-11-26 133104] "uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-11-26 270128] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360] "Rainlendar2"="c:\arquivos de programas\Rainlendar2\Rainlendar2.exe" [2008-08-24 4067328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SecurDisc"="c:\arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208] "InCD"="c:\arquivos de programas\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-10 136600] "AGRSMMSG"="AGRSMMSG.exe" [2003-09-23 c:\windows\AGRSMMSG.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360] c:\documents and settings\User\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-10 97928] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2008-11-27 875288] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-27 231704] R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-10 76040] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-12 c:\windows\Tasks\GoogleUpdateTaskUser.job - c:\documents and settings\Stephanie\Configura [] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-12 15:36:24 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys] "imagepath"="\systemroot\system32\drivers\msqpdxpaxtoexh.sys" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(672) c:\windows\system32\avgrsstx.dll c:\windows\system32\Cabinet.dll - - - - - - - > 'lsass.exe'(736) c:\windows\system32\avgrsstx.dll . Tempo para conclusão: 2008-12-12 15:37:45 ComboFix-quarantined-files.txt 2008-12-12 17:37:25 ComboFix2.txt 2008-12-11 13:05:51 Pré-execução: 10 pasta(s) 47.080.034.304 bytes disponíveis Pós execução: 10 pasta(s) 47,074,332,672 bytes disponíveis 260 --- E O F --- 2008-12-10 22:29:35 E o do HijackThis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:41:45, on 12/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe C:\WINDOWS\AGRSMMSG.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\uTorrent\uTorrent.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe C:\Arquivos de programas\AVG\AVG8\avgtray.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [securDisc] C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Rainlendar2] C:\Arquivos de programas\Rainlendar2\Rainlendar2.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- End of file - 6391 bytes Obrigada! Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 12, 2008 Olá, dessa vez ocorreu tudo normalmente ;) Que bom, ótimo! Acesse o Kaspersky Online Scanner e prossiga com um scan online seguindo o tutorial do link aqui abaixo. Tutorial Kaspersky Online Scanner Ao término do scan, salve o relatório com a extensão .txt em seu computador e poste-o em sua próxima resposta. Uma pergunta: Como está o computador? Aquele problema que você descreveu no começo do tópico ainda ocorre? Compartilhar este post Link para o post Compartilhar em outros sites
noelle 0 Denunciar post Postado Dezembro 21, 2008 Olá! Não consegui rodar o programa, pois aparecem duas mensagens: Your computer doesn't meet the requirements to run Kaspersky Online Scanner 7.0. Check the system requirements in the program help. Attention: Kaspersky Online Scanner 7.0 may not run successfully while any other antivirus program is running. If you have another antivirus program installed, please turn it off before running Kaspersky Online Scanner 7.0. Mesmo com o anti-vírus desabilitado. Alguma idéia do que eu possa fazer? Não, o problema inicial foi resolvido! Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 22, 2008 - Com o navegador Internet Explorer, acesse o Eset Online Scanner; - Marque a caixinha Yes, I accept the terms of use, e clique em Start. - Na proxima janela clique com o botão direito sobre a caixinha e selecione Instalar controle activeX. - Aguarde o aviso de segurança e clique em Instalar. - Na proxima pagina, clique em Start e aguarde; - Marque as auas caixinhas e clique em Scan. Aguarde; - Quando o scan terminar o log podera ser visto em C:\arquivos de programas\esetonlinescanner\log. Poste este log em sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Janeiro 22, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites