Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

fgmiloski

[Resolvido!] Laptop lento na inicialização e carregando programas

Recommended Posts

Olá, gostaria de uma ajuda possuo um laptop HP, ultimamente o mesmo se apresenta muito lento

tanto para iniciar quanto quando vou usar alguns programas, alguns filmes ficam travando. Queria

uma ajuda para "limpá-lo". Vale a pena desfragmentar frequentemente? Vale a pena baixar o adaware ou

outro programa? Grato

 

Pentium M Centrino 1,73 GHz com 1Gb de RAM

HD 80GB

Uso o XP home edition 2002 service pack 3

Antivirus Avast Home 4.8

Spybot

Uso o Opera e o firefox

também o Bitcomet

 

Aí vai o log

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 09:55:33, on 26/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\vVX3000.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Opera\opera.exe

C:\Chico\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: http://*.windowsupdate.com

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1211543930656

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{ACD78122-5EE5-4C24-961A-83318F3FDBDA}: NameServer = 10.1.200.1,200.152.98.2

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

 

--

End of file - 7663 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar.

 

PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta.

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO.

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Valeu Jgarcia,

fiz todas as etapas, foi tudo ok, mas meu laptop não reiniciou, mas aparentemente nao ocorreu nenhum erro durante o processo, ai abaico vai o log

do combofix:

 

ComboFix 08-12-26.03 - Chico Miloski 2008-12-27 17:33:55.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.669 [GMT -2:00]

Running from: c:\documents and settings\Chico Miloski\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1296 [VPS 081222-0] *On-access scanning disabled* (Updated)

* Created a new restore point

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

E:\Autorun.inf

 

.

((((((((((((((((((((((((( Files Created from 2008-11-27 to 2008-12-27 )))))))))))))))))))))))))))))))

.

 

2008-12-27 17:26 . 2008-12-27 17:26 2,888,367 --a------ c:\program files\ComboFix.exe

2008-12-26 22:00 . 2008-12-26 22:00 <DIR> d-------- c:\program files\iphonebrowser

2008-12-26 21:51 . 2008-12-26 21:51 462,087 --a------ c:\program files\SetupiPhoneBrowser.1.52.zip

2008-12-26 20:25 . 2008-04-14 01:12 159,232 --a------ c:\windows\system32\ptpusd.dll

2008-12-26 20:25 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys

2008-12-26 20:25 . 2008-04-13 19:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys

2008-12-26 20:25 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll

2008-12-26 08:58 . 2008-12-27 17:27 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Apple Computer

2008-12-26 08:58 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll

2008-12-26 08:58 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys

2008-12-26 08:57 . 2008-12-26 08:57 <DIR> d-------- c:\program files\iPod

2008-12-26 08:56 . 2008-12-26 08:58 <DIR> d-------- c:\program files\iTunes

2008-12-26 08:56 . 2008-12-26 08:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-12-26 08:55 . 2008-12-26 08:55 <DIR> d-------- c:\program files\Bonjour

2008-12-26 08:54 . 2008-12-26 08:55 <DIR> d-------- c:\program files\QuickTime

2008-12-26 08:54 . 2008-12-26 08:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer

2008-12-26 08:53 . 2008-12-26 08:53 <DIR> d-------- c:\program files\Apple Software Update

2008-12-26 08:53 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys

2008-12-26 08:52 . 2008-12-26 08:57 <DIR> d-------- c:\program files\Common Files\Apple

2008-12-26 08:52 . 2008-12-26 08:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

2008-12-26 08:44 . 2008-12-26 08:49 68,756,776 --a------ c:\program files\iTunesSetup.exe

2008-12-26 08:40 . 2008-12-26 08:40 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Nokia

2008-12-26 08:39 . 2008-12-26 08:39 <DIR> d-------- c:\program files\DIFX

2008-12-26 08:37 . 2008-12-26 08:37 <DIR> d-------- c:\program files\Common Files\Nokia

2008-12-26 08:35 . 2008-12-26 08:36 <DIR> d-------- c:\program files\Nokia

2008-12-26 08:35 . 2008-12-26 08:37 <DIR> d-------- c:\program files\Common Files\PCSuite

2008-12-26 08:35 . 2008-12-26 08:39 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\PC Suite

2008-12-26 08:35 . 2008-12-26 08:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite

2008-12-26 08:35 . 2006-05-29 08:26 127,488 --a------ c:\windows\system32\drivers\nmwcd.sys

2008-12-26 08:35 . 2006-05-29 08:26 50,688 --a------ c:\windows\system32\nmwcdcls.dll

2008-12-26 08:35 . 2006-05-29 08:26 30,720 --a------ c:\windows\system32\nmwcdcocls.dll

2008-12-26 08:35 . 2006-05-29 08:26 13,312 --a------ c:\windows\system32\drivers\nmwcdcm.sys

2008-12-26 08:35 . 2006-05-29 08:26 13,312 --a------ c:\windows\system32\drivers\nmwcdcj.sys

2008-12-26 08:35 . 2006-05-29 08:26 8,704 --a------ c:\windows\system32\drivers\nmwcdc.sys

2008-12-26 08:35 . 2006-05-29 08:26 4,608 --a------ c:\windows\system32\nmwcdlog.dll

2008-12-26 08:34 . 2008-12-26 08:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations

2008-12-16 21:25 . 2008-12-16 21:24 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-09 17:49 . 2008-12-09 17:49 <DIR> d-------- C:\Mosby

2008-12-08 22:59 . 2008-12-08 22:59 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Desktopicon

2008-12-05 17:04 . 2008-12-05 17:04 <DIR> d-------- c:\program files\MSECache

2008-12-05 16:57 . 2008-12-05 17:04 28,868,320 --a------ c:\program files\FileFormatConverters.exe

2008-11-27 18:02 . 2008-11-27 18:04 2,972,736 --a------ c:\program files\ccsetup214.exe

2008-11-27 14:45 . 2008-11-27 14:47 <DIR> d---s---- c:\documents and settings\Administrator

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-26 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2008-12-24 00:07 --------- d-----w c:\documents and settings\Chico Miloski\Application Data\LimeWire

2008-12-16 23:23 --------- d-----w c:\program files\Java

2008-12-05 19:17 55,768 ----a-w c:\documents and settings\Chico Miloski\Application Data\GDIPFONTCACHEV1.DAT

2008-11-13 14:47 487,584 ----a-w c:\program files\ChromeSetup.exe

2008-11-12 02:20 --------- d-----w c:\program files\MSXML 4.0

2008-11-10 22:41 --------- d-----w c:\program files\Spybot - Search & Destroy

2008-11-10 21:43 --------- d-----w c:\documents and settings\All Users\Application Data\Age of Empires 3

2008-11-10 21:06 --------- d--h--w c:\program files\InstallShield Installation Information

2008-11-10 20:34 --------- d-----w c:\program files\Microsoft Games

2008-11-06 17:46 --------- d-----w c:\documents and settings\Chico Miloski\Application Data\Media Player Classic

2008-11-05 16:42 --------- d-----w c:\documents and settings\All Users\Application Data\TechSmith

2008-11-05 16:41 --------- d-----w c:\program files\TechSmith

2008-11-05 16:41 --------- d-----w c:\program files\Common Files\TechSmith Shared

2008-11-05 16:33 39,138,304 ----a-w c:\program files\camtasia.msi

2008-11-05 16:07 1,364,995 ----a-w c:\program files\CamStudio20.exe

2008-11-04 18:22 --------- d-----w c:\program files\URUSoft

2008-10-30 18:43 --------- d-----w c:\program files\K-Lite Codec Pack

2008-10-28 16:52 --------- d-----w c:\program files\Opera

2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll

2008-10-21 20:06 9,659,828 ----a-w c:\program files\CamStudio.exe

2008-10-21 18:14 162,816 ----a-w c:\windows\system32\fmod.dll

2008-10-21 17:43 11,523,750 ----a-w c:\program files\qqvideo17.exe

2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll

2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll

2008-10-06 18:44 8,929,896 ----a-w c:\program files\Opera_952_10108_in.exe

2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-07-16 21:39 85,779,656 ----a-w c:\program files\OneNote.exe

2008-07-16 21:31 5,808,057 ----a-w c:\program files\aTubeCatcher_1_0_236_setup.exe

2008-07-16 21:09 32,334,608 ----a-w c:\program files\OneNote2003SP2-KB887619-FullFile-ENU.exe

2008-07-10 14:57 8,323,636 -c--a-w c:\program files\aMSN-0.97.1-windows-installer.exe

2008-05-24 17:36 2,915,697 ----a-w c:\program files\wrar371br.exe

2008-05-23 18:55 7,467,056 ----a-w c:\program files\spybotsd15.exe

2008-05-23 18:48 9,352,392 ----a-w c:\program files\Install_MSN_Messenger.exe

2008-05-23 18:43 2,400,784 ----a-w c:\program files\WLinstaller.exe

2008-05-23 18:41 4,502,280 ----a-w c:\program files\LimeWireWin.exe

2008-05-23 18:35 5,742,544 ----a-w c:\program files\bitcomet_setup.exe

2008-05-23 18:31 9,730,075 ----a-w c:\program files\vlc-0.8.6f-win32.exe

2008-05-23 18:13 23,124,872 ----a-w c:\program files\setupporpro.exe

2008-05-23 18:12 5,840,544 ----a-w c:\program files\Firefox Setup 2.0.0.14.exe

2004-03-19 13:53 1,107,022 ----a-w c:\program files\SubtitleWorkshop251.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]

"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-14 1015808]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-22 155648]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-22 126976]

"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-11-05 233534]

"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-16 136600]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-14 102400]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]

"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitComet\\BitComet.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\aMSN\\bin\\wish.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=

"c:\\WINDOWS\\system32\\javaw.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"8994:TCP"= 8994:TCP:BitComet 8994 TCP

"8994:UDP"= 8994:UDP:BitComet 8994 UDP

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-23 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-05-23 20560]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9fa8362a-2b61-11dd-8ee1-00c09ff8909d}]

\Shell\AutoRun\command - F:\gkguss.exe

\Shell\explore\Command - F:\gkguss.exe

\Shell\open\Command - F:\gkguss.exe

 

*Newly Created Service* - PROCEXP90

.

Contents of the 'Scheduled Tasks' folder

 

2008-12-27 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Chico Miloski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 12:48]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = *.local

IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

TCP: {ACD78122-5EE5-4C24-961A-83318F3FDBDA} = 10.1.200.1,200.152.98.2

 

c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}

hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

c:\windows\Downloaded Program Files\gbpdist.inf

FF - ProfilePath - c:\documents and settings\Chico Miloski\Application Data\Mozilla\Firefox\Profiles\vqpo4lbt.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.periodicos.capes.gov.br

FF - prefs.js: network.proxy.http - acessocapes.cremerj.org.br

FF - prefs.js: network.proxy.http_port - 3128

FF - prefs.js: network.proxy.type - 1

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll

FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll

FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll

FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-27 17:36:12

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????4?7?1?4??p???? ?,?B?????????????hLC? ??????

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-12-27 17:37:57

ComboFix-quarantined-files.txt 2008-12-27 19:37:36

 

Pre-Run: 34.855.239.680 bytes free

Post-Run: 34,850,197,504 bytes free

 

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

 

215 --- E O F --- 2008-12-18 02:24:22

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

F:\gkguss.exe

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9fa8362a-2b61-11dd-8ee1-00c09ff8909d}]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

 

PS.: Execute a ação com o Pendrive conectado ao PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Jgarcia,

mais uma vez obrigado pela ajuda

ai vai o log do combofix:

 

ComboFix 08-12-29.02 - Chico Miloski 2008-12-30 20:39:42.2 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.656 [GMT -2:00]

Running from: c:\documents and settings\Chico Miloski\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Chico Miloski\Desktop\CFScript.txt

AV: avast! antivirus 4.8.1296 [VPS 081227-0] *On-access scanning disabled* (Updated)

* Created a new restore point

 

FILE ::

F:\gkguss.exe

.

 

((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))

.

 

2008-12-27 22:51 . 2008-12-27 22:51 <DIR> d-------- C:\divx

2008-12-27 22:42 . 2008-11-21 19:47 129,784 --------- c:\windows\system32\pxafs.dll

2008-12-27 22:42 . 2008-11-21 19:47 120,056 --------- c:\windows\system32\pxcpyi64.exe

2008-12-27 22:42 . 2008-11-21 19:47 118,520 --------- c:\windows\system32\pxinsi64.exe

2008-12-27 22:42 . 2008-11-21 19:47 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys

2008-12-27 22:42 . 2008-11-21 19:47 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys

2008-12-27 22:40 . 2008-12-27 22:43 <DIR> d-------- c:\program files\DivX

2008-12-27 21:11 . 2008-12-27 21:11 <DIR> d-------- c:\documents and settings\Chico Miloski\Phone Browser

2008-12-27 21:11 . 2008-12-27 21:11 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\DataLayer

2008-12-27 18:24 . 2008-12-27 18:40 457 --a------ c:\windows\cdplayer.ini

2008-12-27 18:23 . 2008-12-27 18:23 <DIR> d-------- c:\program files\FreeRIP3

2008-12-27 18:23 . 2008-12-27 18:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\FreeRIP

2008-12-27 17:26 . 2008-12-27 17:26 2,888,367 --a------ c:\program files\ComboFix.exe

2008-12-26 22:00 . 2008-12-26 22:00 <DIR> d-------- c:\program files\iphonebrowser

2008-12-26 21:51 . 2008-12-26 21:51 462,087 --a------ c:\program files\SetupiPhoneBrowser.1.52.zip

2008-12-26 20:25 . 2008-04-14 01:12 159,232 --a------ c:\windows\system32\ptpusd.dll

2008-12-26 20:25 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys

2008-12-26 20:25 . 2008-04-13 19:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys

2008-12-26 20:25 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll

2008-12-26 08:58 . 2008-12-27 17:27 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Apple Computer

2008-12-26 08:58 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll

2008-12-26 08:58 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys

2008-12-26 08:57 . 2008-12-26 08:57 <DIR> d-------- c:\program files\iPod

2008-12-26 08:56 . 2008-12-26 08:58 <DIR> d-------- c:\program files\iTunes

2008-12-26 08:56 . 2008-12-26 08:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2008-12-26 08:55 . 2008-12-26 08:55 <DIR> d-------- c:\program files\Bonjour

2008-12-26 08:54 . 2008-12-26 08:55 <DIR> d-------- c:\program files\QuickTime

2008-12-26 08:54 . 2008-12-26 08:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer

2008-12-26 08:53 . 2008-12-26 08:53 <DIR> d-------- c:\program files\Apple Software Update

2008-12-26 08:53 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys

2008-12-26 08:52 . 2008-12-26 08:57 <DIR> d-------- c:\program files\Common Files\Apple

2008-12-26 08:52 . 2008-12-26 08:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

2008-12-26 08:44 . 2008-12-26 08:49 68,756,776 --a------ c:\program files\iTunesSetup.exe

2008-12-26 08:40 . 2008-12-26 08:40 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Nokia

2008-12-26 08:39 . 2008-12-26 08:39 <DIR> d-------- c:\program files\DIFX

2008-12-26 08:37 . 2008-12-26 08:37 <DIR> d-------- c:\program files\Common Files\Nokia

2008-12-26 08:35 . 2008-12-26 08:36 <DIR> d-------- c:\program files\Nokia

2008-12-26 08:35 . 2008-12-26 08:37 <DIR> d-------- c:\program files\Common Files\PCSuite

2008-12-26 08:35 . 2008-12-26 08:39 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\PC Suite

2008-12-26 08:35 . 2008-12-26 08:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite

2008-12-26 08:35 . 2006-05-29 08:26 127,488 --a------ c:\windows\system32\drivers\nmwcd.sys

2008-12-26 08:35 . 2006-05-29 08:26 50,688 --a------ c:\windows\system32\nmwcdcls.dll

2008-12-26 08:35 . 2006-05-29 08:26 30,720 --a------ c:\windows\system32\nmwcdcocls.dll

2008-12-26 08:35 . 2006-05-29 08:26 13,312 --a------ c:\windows\system32\drivers\nmwcdcm.sys

2008-12-26 08:35 . 2006-05-29 08:26 13,312 --a------ c:\windows\system32\drivers\nmwcdcj.sys

2008-12-26 08:35 . 2006-05-29 08:26 8,704 --a------ c:\windows\system32\drivers\nmwcdc.sys

2008-12-26 08:35 . 2006-05-29 08:26 4,608 --a------ c:\windows\system32\nmwcdlog.dll

2008-12-26 08:34 . 2008-12-26 08:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations

2008-12-16 21:25 . 2008-12-16 21:24 410,984 --a------ c:\windows\system32\deploytk.dll

2008-12-09 17:49 . 2008-12-09 17:49 <DIR> d-------- C:\Mosby

2008-12-08 22:59 . 2008-12-08 22:59 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Desktopicon

2008-12-05 17:04 . 2008-12-05 17:04 <DIR> d-------- c:\program files\MSECache

2008-12-05 16:57 . 2008-12-05 17:04 28,868,320 --a------ c:\program files\FileFormatConverters.exe

2008-11-27 18:02 . 2008-11-27 18:04 2,972,736 --a------ c:\program files\ccsetup214.exe

2008-11-27 14:45 . 2008-11-27 14:47 <DIR> d---s---- c:\documents and settings\Administrator

2008-11-21 19:47 . 2008-11-21 19:47 3,596,288 --a------ c:\windows\system32\qt-dx331.dll

2008-11-21 19:47 . 2008-11-21 19:47 524,288 --a------ c:\windows\system32\DivXsm.exe

2008-11-21 19:47 . 2008-11-21 19:47 4,816 --a------ c:\windows\system32\divxsm.tlb

2008-11-21 19:46 . 2008-11-21 19:46 1,044,480 --a------ c:\windows\system32\libdivx.dll

2008-11-21 19:46 . 2008-11-21 19:46 200,704 --a------ c:\windows\system32\ssldivx.dll

2008-11-21 19:44 . 2008-11-21 19:44 161,096 --a------ c:\windows\system32\DivXCodecVersionChecker.exe

2008-11-21 19:44 . 2008-11-21 19:44 12,288 --a------ c:\windows\system32\DivXWMPExtType.dll

2008-11-13 12:46 . 2008-11-13 12:47 487,584 --a------ c:\program files\ChromeSetup.exe

2008-11-12 15:28 . 2008-09-04 15:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

2008-11-12 13:16 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-11-12 00:20 . 2008-11-12 00:20 <DIR> d-------- c:\program files\MSXML 4.0

2008-11-10 19:43 . 2008-11-10 19:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Age of Empires 3

2008-11-10 18:34 . 2008-11-10 18:34 <DIR> d-------- c:\program files\Microsoft Games

2008-11-06 15:45 . 2008-11-06 15:46 <DIR> d-------- c:\documents and settings\Chico Miloski\Application Data\Media Player Classic

2008-11-05 14:42 . 2008-11-05 14:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\TechSmith

2008-11-05 14:42 . 2008-07-10 12:56 107,864 --a------ c:\windows\system32\tsccvid.dll

2008-11-05 14:41 . 2008-11-05 14:41 <DIR> d-------- c:\program files\TechSmith

2008-11-05 14:41 . 2008-11-05 14:41 <DIR> d-------- c:\program files\Common Files\TechSmith Shared

2008-11-05 14:06 . 2008-11-05 14:07 1,364,995 --a------ c:\program files\CamStudio20.exe

2008-11-04 16:22 . 2008-11-04 16:22 <DIR> d-------- c:\program files\URUSoft

2008-11-04 16:21 . 2004-03-19 11:53 1,107,022 --a------ c:\program files\SubtitleWorkshop251.exe

2008-11-04 16:15 . 2008-11-04 16:15 4,068 --a--c--- c:\windows\SETUP.LST

2008-11-04 16:15 . 2008-11-04 16:15 303 --a--c--- c:\windows\ST6UNST.000

2008-11-04 10:30 . 2008-11-04 10:30 90,112 --a------ c:\windows\system32\QuickTimeVR.qtx

2008-11-04 10:30 . 2008-11-04 10:30 57,344 --a------ c:\windows\system32\QuickTime.qts

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-26 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2008-12-24 00:07 --------- d-----w c:\documents and settings\Chico Miloski\Application Data\LimeWire

2008-12-16 23:23 --------- d-----w c:\program files\Java

2008-12-05 19:17 55,768 ----a-w c:\documents and settings\Chico Miloski\Application Data\GDIPFONTCACHEV1.DAT

2008-11-21 21:47 43,528 ------w c:\windows\system32\drivers\pxhelp20.sys

2008-11-10 22:41 --------- d-----w c:\program files\Spybot - Search & Destroy

2008-11-10 21:06 --------- d--h--w c:\program files\InstallShield Installation Information

2008-11-05 16:33 39,138,304 ----a-w c:\program files\camtasia.msi

2008-10-30 18:43 --------- d-----w c:\program files\K-Lite Codec Pack

2008-10-28 16:52 --------- d-----w c:\program files\Opera

2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll

2008-10-21 20:06 9,659,828 ----a-w c:\program files\CamStudio.exe

2008-10-21 18:14 162,816 ----a-w c:\windows\system32\fmod.dll

2008-10-21 17:43 11,523,750 ----a-w c:\program files\qqvideo17.exe

2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll

2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll

2008-10-06 18:44 8,929,896 ----a-w c:\program files\Opera_952_10108_in.exe

2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys

2008-09-10 01:14 1,307,648 ------w c:\windows\system32\msxml6.dll

2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll

2008-07-16 21:39 85,779,656 ----a-w c:\program files\OneNote.exe

2008-07-16 21:31 5,808,057 ----a-w c:\program files\aTubeCatcher_1_0_236_setup.exe

2008-07-16 21:09 32,334,608 ----a-w c:\program files\OneNote2003SP2-KB887619-FullFile-ENU.exe

2008-07-10 14:57 8,323,636 -c--a-w c:\program files\aMSN-0.97.1-windows-installer.exe

2008-05-24 17:36 2,915,697 ----a-w c:\program files\wrar371br.exe

2008-05-23 18:55 7,467,056 ----a-w c:\program files\spybotsd15.exe

2008-05-23 18:48 9,352,392 ----a-w c:\program files\Install_MSN_Messenger.exe

2008-05-23 18:43 2,400,784 ----a-w c:\program files\WLinstaller.exe

2008-05-23 18:41 4,502,280 ----a-w c:\program files\LimeWireWin.exe

2008-05-23 18:35 5,742,544 ----a-w c:\program files\bitcomet_setup.exe

2008-05-23 18:31 9,730,075 ----a-w c:\program files\vlc-0.8.6f-win32.exe

2008-05-23 18:13 23,124,872 ----a-w c:\program files\setupporpro.exe

2008-05-23 18:12 5,840,544 ----a-w c:\program files\Firefox Setup 2.0.0.14.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-12-27_17.36.49,90 )))))))))))))))))))))))))))))))))))))))))

.

- 2007-12-04 02:33:16 682,496 ----a-w c:\windows\system32\divx.dll

+ 2008-11-21 21:45:06 684,032 ----a-w c:\windows\system32\DivX.dll

+ 2008-11-21 21:45:08 823,296 ----a-w c:\windows\system32\divx_xx07.dll

+ 2008-11-21 21:45:08 815,104 ----a-w c:\windows\system32\divx_xx0a.dll

+ 2008-11-21 21:45:08 823,296 ----a-w c:\windows\system32\divx_xx0c.dll

+ 2008-11-21 21:45:08 802,816 ----a-w c:\windows\system32\divx_xx11.dll

- 2007-11-29 23:28:24 81,920 ----a-w c:\windows\system32\dpl100.dll

+ 2008-11-21 21:45:16 81,920 ----a-w c:\windows\system32\dpl100.dll

+ 2008-11-21 21:45:12 294,912 ----a-w c:\windows\system32\dpu10.dll

+ 2008-11-21 21:45:12 294,912 ----a-w c:\windows\system32\dpu11.dll

+ 2008-11-21 21:45:12 53,248 ----a-w c:\windows\system32\dpuGUI10.dll

+ 2008-11-21 21:45:12 593,920 ----a-w c:\windows\system32\dpuGUI11.dll

+ 2008-11-21 21:45:12 344,064 ----a-w c:\windows\system32\dpus11.dll

+ 2008-11-21 21:45:12 57,344 ----a-w c:\windows\system32\dpv11.dll

+ 2008-11-21 21:45:16 196,608 ----a-w c:\windows\system32\dtu100.dll

- 2005-04-17 14:21:16 372,736 ----a-w c:\windows\system32\Px.dll

+ 2008-11-21 21:47:48 551,672 ------w c:\windows\system32\Px.dll

+ 2008-11-21 21:47:48 66,296 ------w c:\windows\system32\pxcpya64.exe

- 2005-04-15 00:01:00 417,792 ----a-w c:\windows\system32\pxdrv.dll

+ 2008-11-21 21:47:48 518,904 ------w c:\windows\system32\pxdrv.dll

+ 2008-11-21 21:47:48 72,440 ------w c:\windows\system32\pxhpinst.exe

+ 2008-11-21 21:47:48 64,760 ------w c:\windows\system32\pxinsa64.exe

- 2005-04-17 14:20:20 172,032 ----a-w c:\windows\system32\PxMas.dll

+ 2008-11-21 21:47:50 187,128 ------w c:\windows\system32\PxMas.dll

- 2005-01-26 13:39:04 1,077,248 ----a-w c:\windows\system32\PxSFS.DLL

+ 2008-11-21 21:47:48 1,628,920 ------w c:\windows\system32\PxSFS.DLL

- 2005-04-17 14:19:50 339,968 ----a-w c:\windows\system32\PxWave.dll

+ 2008-11-21 21:47:48 379,640 ------w c:\windows\system32\PxWave.dll

- 2005-01-12 00:00:00 28,672 ----a-w c:\windows\system32\VXBLOCK.dll

+ 2008-11-21 21:47:46 88,824 ------w c:\windows\system32\VXBLOCK.dll

+ 2008-12-30 22:18:00 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_3ec.dat

+ 2008-12-30 22:17:49 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_65c.dat

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]

"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]

"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-14 1015808]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-22 155648]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-22 126976]

"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-11-05 233534]

"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-16 136600]

"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-14 102400]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]

"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\BitComet\\BitComet.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Program Files\\aMSN\\bin\\wish.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=

"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=

"c:\\WINDOWS\\system32\\javaw.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"8994:TCP"= 8994:TCP:BitComet 8994 TCP

"8994:UDP"= 8994:UDP:BitComet 8994 UDP

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-23 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-05-23 20560]

.

Contents of the 'Scheduled Tasks' folder

 

2008-12-28 c:\windows\Tasks\GoogleUpdateTaskUser.job

- c:\documents and settings\Chico Miloski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 12:48]

.

.

------- Supplementary Scan -------

.

uInternet Settings,ProxyOverride = *.local

IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

Trusted Zone: windowsupdate.microsoft.com

Trusted Zone: www.update.microsoft.com

Trusted Zone: *.windowsupdate.com

TCP: {ACD78122-5EE5-4C24-961A-83318F3FDBDA} = 10.1.200.1,200.152.98.2

 

c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}

hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

c:\windows\Downloaded Program Files\gbpdist.inf

FF - ProfilePath - c:\documents and settings\Chico Miloski\Application Data\Mozilla\Firefox\Profiles\vqpo4lbt.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.periodicos.capes.gov.br

FF - prefs.js: network.proxy.http - acessocapes.cremerj.org.br

FF - prefs.js: network.proxy.http_port - 3128

FF - prefs.js: network.proxy.type - 1

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll

FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll

FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll

FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-30 20:42:36

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????4?7?1?4??????? ?,?B?????????????hLC? ??????

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-12-30 20:44:09

ComboFix-quarantined-files.txt 2008-12-30 22:43:43

ComboFix2.txt 2008-12-27 19:37:59

 

Pre-Run: 34.701.729.792 bytes free

Post-Run: 34,763,399,168 bytes free

 

273 --- E O F --- 2008-12-18 02:24:22

 

 

AGORA o do HIJACKTHIS:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:45:53, on 30/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Opera\opera.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Chico\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - Trusted Zone: http://*.windowsupdate.com

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1211543930656

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{ACD78122-5EE5-4C24-961A-83318F3FDBDA}: NameServer = 10.1.200.1,200.152.98.2

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

 

--

End of file - 7441 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Baixe a EliStarA = no final da página clique no botão Descargar EliStarA.

 

Sugiro que imprima ou salve os procedimentos abaixo, e não utilize a internet até terminado o procedimento.

 

Reinicie em Modo Seguro (pressione repetidamente a tecla F8 durante a inicialização, até que apareça o menu, onde você deverá selecionar Modo Seguro).

 

Execute o EliStarA.exe e aguarde, pois o scan é um pouco demorado.

 

Terminado o processo, reinicie e poste o log (ele estará em C:\infoSat.txt).

 

Abraços.

 

PS.: O pendrive deverá estar conectado ao PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Valeu Jgarcia,

ai vai o resultado do Elistar:

 

 

Wed Dec 31 12:28:16 2008

EliStartPage v17.71 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Diciembre del 2008)

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Restaurado fichero de Configuración del IE, (IERESET.INF)

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

 

Wed Dec 31 12:28:34 2008

EliStartPage v17.71 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Diciembre del 2008)

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando "C:\"

C:\Documents and Settings\Chico Miloski\Application Data\Desktopicon\EBAYSHORTCUTS.EXE --> Eliminado, PWS-WoW.YU

C:\Program Files\ATUBECATCHER_1_0_236_SETUP.EXE --> Eliminado, Dropper(ConHook)

C:\Program Files\Synaptics\SynTP\Media\SYNTPCO2.DLL --> Eliminado, AutoRun.K

C:\WINDOWS\system32\SYNTPCO2.DLL --> Eliminado, AutoRun.K

C:\WINDOWS\system32\ReinstallBackups\0017\DriverFiles\SYNTPCO2.DLL --> Eliminado, AutoRun.K

 

Nº Total de Directorios: 5438

Nº Total de Ficheros: 49697

Nº de Ficheros Analizados: 16199

Nº de Ficheros Infectados: 5

Nº de Ficheros Limpiados: 5

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

1. Baixe o BankerFix 3.0.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM.

 

4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado.

 

5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos.

 

6. Terminado o scan, leia a mensagem na tela e aperte Enter.

 

7. Habilite o seu anti-vírus.

 

8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

 

PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Jgarcia,

aí vai o relatório do banker:

Obrigado

 

 

BankerFix 3.0 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2009-01-11 - 20:22

-------------------------------------------------------

Lista de Definição: 2008-12-14-1 | CORE: 2008-12-14-1

=======================================================

 

Arquivo infectado detectado: \autoexec.bat

Arquivo infectado removido com sucesso!

 

 

 

----- Fim -------------------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Desculpe a imensa demora, pois o tempo anda curto. :(

 

Bem, o Malwarebytes AntiMalware é um produto relativamente novo, porém com grande eficácia na remoção de infecções comuns. O programa é pequeno, gratuito e em português.

 

A sua instalação é o primeiro passo para a limpeza de um sistema operacional infectado.

 

Neste tutorial você aprenderá a instalá-lo e executá-lo.

 

1) Primeiramente faça o download do programa:

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

 

2) Agora proceda a instalação do programa, conforme segue:

 

Execute o programa de instalação:

capturadatelaha4.png

 

Logo após a execução do arquivo de instalação, será exibida a seguinte tela:

capturadatela1zv8.png

 

Agora, clique em Instalar para concluir:

capturadatela6yd8.png

 

Ao término da instalação deixe marcadas as opções de Atualização e Execução:

capturadatela7cd6.png

 

Será exibida então a tela de atualização do programa:

capturadatela9en9.png

 

3) Essa é a tela inicial do programa. Marque a opção Verificação Completa e clique no botão Verificar.

capturadatela10vs1.png

 

Aguarde até o final da verificação:

capturadatela12zo1.png

 

Ao concluir a verificação, será exibida essa mensagem:

capturadatela13oi2.png

 

O resultado da verificação será exibido, com o nome dos arquivos e malwares encontrados.

Para efetivar a limpeza, clique em Remover selecionados:

capturadatela14qb8.png

 

Para concluir a limpeza haverá a necessidade da reinicialização do computador:

capturadatela15um2ed5.png

 

O programa guarda os logs das verificações feitas na pasta C:\Documents and Settings\Seu nome de Usuario\Dados de aplicativos\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa.

 

Retorne com o resultado da varredura.

 

Créditos: Fabio Assolini.

 

Link para a postagem original: aqui.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Jgarcia, ai vai, mas nao veio nenhum arquivo infectado....

e o pc continua lento... :(

 

mas não

 

Malwarebytes' Anti-Malware 1.33

Versão do banco de dados: 1697

Windows 5.1.2600 Service Pack 3

 

27/1/2009 06:57:24

mbam-log-2009-01-27 (06-57-24).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 110306

Tempo decorrido: 2 hour(s), 13 minute(s), 42 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 0

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

(Nenhum ítem malicioso foi detectado)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Vamos tentar resolver o problema remanescente por meio do CCleaner -> baixe aqui.

 

1. Para efetivar a limpeza basta marcar a opção Limpezano alto e à esquerda – e clicar em Executar Limpezaabaixo e à direita. Neste caso você poderá optar pela limpeza do Windows, de Programas ou de ambos;

 

2. Para a correção de erros basta escolher a opção Registrono alto e à esquerda – clicar em Procurar errosabaixo e à esquerda – e depois em Corrigir Erros Selecionados – abaixo e à direita (por padrão todos serão selecionados);

 

3. Em Ferramentasno alto e à esquerda – você poderá efetivar a desinstalação de programas (os mesmos contidos em Adicionar / Remover programas) ou ainda remover processos de programas contidos na inicialização (somente para usuários experientes);

 

4. Em Opções encontram-se os dispositivos de configuração do CCleaner, os quais sugiro que permaneçam inalterados.

 

Execute as ações acima (apenas 1. e 2.) e retorne com o resultado.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites
O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Esta é a situação atual da inicialização de sua máquina. O que me diz? Há necessidade de manter tantos softs na inicialização?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá jgarcia,

E' tb acho que tem aplicativos demais a serem abertos na inicializacao sem necessidade

Por mim só deixariam os que são essenciais para serem abertos ao iniciar. Então

quais são os dispensáveis e como faço para retira-los?

 

Obrigado,

Fgmiloski

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

Execute o HijackThis, clique em Do a system scan only, marque os itens abaixo e clique em Fix:

O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe

O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"

O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Reinicie a máquina e verifique a performance durante a inicialização.

 

Retorne com um novo log do HijackThis.

 

Abraços.

 

PS.: A ação acima foi solicitada com o único intuito de desafogar o processo de inicialização da máquina do usuário, mas as entradas indicadas não são ruins ou parte de malwares. É importante que isto fique claro.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá jgarcia,

melhorou um pouco mas ainda não está 100%, ai vai o log:

 

obrigado

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:44:17, on 31/1/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Documents and Settings\Chico Miloski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Opera\opera.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Chico Miloski\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Chico Miloski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Baixar link usando &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos os links usando BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Baixar todos os vídeos usando BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1211543930656

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{ACD78122-5EE5-4C24-961A-83318F3FDBDA}: NameServer = 10.1.200.1,200.152.98.2

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

 

--

End of file - 7012 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa fgmiloski,

 

1. Baixe o DDS e salve-o em seu Desktop.

 

2. Desabilite seu anti-vírus temporiamente.

 

3.duplo-clique sobre o ícone icon.jpg alocado em seu Desktop.

 

4. Quando a janela se abrir solicitando autorização para a execução do arquivo, clique sobre Executar.

 

5. Uma janela abrir-se-á, conforme abaixo ilustrado:

dds-information.jpg

 

6. O DDS iniciará a varredura na máquina.

 

7. Ao fim do processo dois arquivos serão criados: dds.txt e attach.txt.

 

8. Preciso que você poste o conteúdo do dds.txt em sua próxima resposta.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.