roberfc 0 Denunciar post Postado Fevereiro 16, 2009 vi nesse forum que um membro teve o mesmo problema resolvido,por isso me registrei aqui,como cada caso é um caso né vou postar meu log do hjhackthis Logfile of HijackThis v1.99.1 Scan saved at 21:12:44, on 15/2/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\netdde.exe C:\WINDOWS\system32\clipsrv.exe C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe C:\WINDOWS\system32\taskmgr.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\XP\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765 O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe se alguem puder ajudar ficarei agradecido,ja tentei varias dica que pesquisei via google e nenhuma deu certo Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 16, 2009 - Faça o download do SDFIX Reinicie seu computador, e aperte a tecla F8 (F5 em alguns casos) intermitentemente durante a inicialização, até aparecer um menu onde você deverá escolher a opção Modo Seguro 1. Entre na pasta SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat 2. Tecle Y para que a ferramenta inicie o processo de remoção 3. Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar. Ao pressionar qualquer tecla, o computador será reiniciado automaticamente 4. Após reiniciar, a ferramenta ainda será executada novamente e irá terminar o seu trabalho e a palavra Finished irá aparecer. Pressione qualquer tecla. 5. Uma janela com o relatório do SDFix irá aparecer. 6. Copie e cole este relatório na sua resposta . Caso você tenha fechado a janela, uma cópia do relatório estará na pasta SDFix com o nome Report.txt. Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 16, 2009 no report.txt tava só isso SDFix: Version 1.240 Run by XP on seg 16/02/2009 at 07:53 Microsoft Windows XP [versão 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 16, 2009 não apareceu a palavra finished depois que reiniciou do modo de segurança,porem apareceu um monte de txt na pasta do programa,como só estou abrindo com o gerenciador de tarefas não tem como copiar e colar o nome de tds pra você,mas vou escrever um por um e passar pra você ver... backupreg(pasta) backups(pasta) attrib.exe catchm.exe dummi.exe editreg.exe rtsdnif.exe runthis.bat dnif.exe hosts sdfix_readme_online beepfa0.txt beepfa1.txt beepfa2.txt beepfa3.txt beepfa4.txt beepxcodec0.txt beepxcodec1.txt beepxcodec2.txt beepxcodec3.txt beepxcodec4.txt bptest1.txt bptest3.txt delavi0.txt delzip0.txt dest.txt filekilllist1.txt filelist1.txt find.txt findv2009.txt findv2009a.txt findbhos1.txt findircbrute.txt findroguerun.txt findrun002.txt findrun002a.txt findrun30.txt findrun31.txt findrun31a.txt findrun31b.txt findrun32.txt findrunbifrose1.txt findrunboot1.txt findrundw_start.txt findzip.txt patched2a.txt patched2b.txt patched2c.txt remlat1.txt remlat2.txt remlat3.txt remlat4.txt report.txt userinfix.reg add_dbfix_runonce_key.inf w2k_virusalert_repair.inf xp_virusalert_repair.inf bom é isso que esta dentro da pasta do programa,estou no aguardo para novas instruções !! Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 16, 2009 para mim ter acesso aos programas que tenho instalado tenho que fazer o caminho ctrl+alt+del gerenciador de tarefas arquivo executar nova tarefa e procurar dai procuro o programa que quero abrir no meu pc e abro por ali,mas 2 coisas que notei de estranho,não acho a pasta painel de controle e todos os icones estão normal menos o icone do meu computador que aparece como uma folha em branco obs: só vou poder postar na parte da manha pq a tarde trabalho e só saio as 22 hrs de manha fico por aqui até umas 12:30 hrs mais ou menos e qd chego as 22 hrs nem entro mais na net dai só no outro dia de manha,então se você postar a noite só responderei na parte da manha do outro dia... Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 16, 2009 vou postar outro log do hjackthis com todos os programas na inicialização ativados... Logfile of HijackThis v1.99.1 Scan saved at 11:38:07, on 16/2/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\netdde.exe C:\WINDOWS\system32\clipsrv.exe C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\taskmgr.exe C:\Documents and Settings\XP\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKLM\..\Run: [sDFix] C:\SDFix\RunThis.bat /second O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765 O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing) O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 16, 2009 • Baixe: < ComboFix.exe > • Salve-o no Desktop! • Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) • Feche todas as janelas e execute a ferramenta! • Na solicitação: "Negação de garantia de software" --> Clique em Sim! • Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.-- Salve-a no desktop,renomeada como: Kombo.exe -- Ps: Nomeie durante o salvamento,e não após salvá-la! -- Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. -- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! -- Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas. • Abrir-se-á a janela Auto Scan. --> Aguarde! • Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. • Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter. • Aguarde a conclusão! • Durante o scan,evite manusear o mouse ou teclado! <-- Importante! • Para parar ou sair do ComboFix,tecle "N" --> Enter. ---------------------- • Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 16, 2009 ComboFix 09-02-15.01 - XP 2009-02-16 13:16:01.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.673 [GMT -3:00] Executando de: C:\Documents and Settings\XP\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated) FW: ZoneAlarm Security Suite Firewall *enabled* * Criado um novo ponto de restauro . combfix.txt só tinha isso obs zone alarm é um programa que eu ja desistalei da maquina faz tempo e pedia pra mim desabilitar ele ,não sei onde pq ja desistalei,então passei assim mesmo minha area de trabalho não apareceu ainda agora vou passar o do hijackthis Logfile of HijackThis v1.99.1 Scan saved at 13:28, on 2009-02-16 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\netdde.exe C:\WINDOWS\system32\clipsrv.exe C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe C:\WINDOWS\system32\taskmgr.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\XP\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [sDFix] C:\SDFix\RunThis.bat /second O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\CF7434.exe /c C:\ComboFix\Combobatch.bat O4 - HKLM\..\RunOnce: [combofix] C:\WINDOWS\system32\CF7434.exe /c C:\ComboFix\Combobatch.bat O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765 O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing) O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe agora to indo trampa só entro amanha lá pelas 8:30 hrs da manha falows !! Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 16, 2009 Olá, Por favor execute o programa combofix novamente, mais dessa vez execute-o em modo segurança Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 17, 2009 bom como você indicou entrei em modo seguro(f5) executei o combofix deu aquela mesma msg que o sistema residente do zone alarm estava ativo para mim desativar cliquei para seguir em frente disse que por minha conta e risco que pd danificar a maquina,mas não sei pq ta dando isso,deve ter alguma entrada no registro dele que não foi apagada,mas depois que desistalei ele ja tinha passado varios programas de limpeza de registro bom dai executei ele,passou normalmente e no final deu uma msg que o windowns não conseguia encontrar explorer.exe... e gerou um log salvei na area de trabalho obs:combofix não reiniciou o pc e na pasta do combo fix no c ta vazia eu tinha apagado o conteudo da primeira passada,mas o log como salvei na area de trabalho vou passar ai vai; ComboFix 09-02-15.01 - XP 2009-02-17 9:23:09.3 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.816 [GMT -3:00] Executando de: c:\documents and settings\XP\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated) FW: ZoneAlarm Security Suite Firewall *enabled* . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-17 to 2009-02-17 )))))))))))))))))))))))))))) . 2009-02-16 07:52 . 2009-02-16 07:52 579,072 --a--c--- c:\windows\system32\dllcache\user32.dll 2009-02-16 07:50 . 2009-02-16 07:51 <DIR> d-------- c:\windows\ERUNT 2009-02-15 20:05 . 2009-02-15 20:05 <DIR> d-------- c:\arquivos de programas\Panda Security 2009-02-15 20:05 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2009-02-15 16:52 . 2009-02-15 16:52 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\Codemasters 2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\InstallShield 2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\InstallShield 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\windows\system32\AGEIA 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- C:\ProgramData 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\arquivos de programas\AGEIA Technologies 2009-02-15 15:30 . 2009-02-15 15:30 <DIR> d-------- c:\arquivos de programas\Codemasters 2009-02-15 15:30 . 2007-04-27 11:12 78,784 --a------ c:\windows\system32\ISUSPM.cpl 2009-02-15 10:17 . 2009-02-15 10:17 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\VitySoft 2009-02-15 10:16 . 2009-02-15 14:30 <DIR> d-------- c:\arquivos de programas\FreeRapid-0.81 2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys 2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\documents and settings\XP\Dados de aplicativos\PnkBstrK.sys 2009-02-12 08:39 . 2009-02-12 08:39 682,280 --a------ c:\windows\system32\pbsvc.exe 2009-02-12 08:39 . 2009-02-12 08:39 107,832 --a------ c:\windows\system32\PnkBstrB.exe 2009-02-12 08:39 . 2009-02-12 08:39 66,872 --a------ c:\windows\system32\PnkBstrA.exe 2009-02-12 08:24 . 2009-02-12 08:43 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\GetRightToGo 2009-02-12 07:50 . 2009-02-12 07:50 <DIR> d-------- c:\windows\Logs 2009-02-12 07:50 . 2008-05-30 13:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll 2009-02-12 07:50 . 2008-05-30 13:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll 2009-02-12 07:50 . 2008-05-30 13:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll 2009-02-12 07:50 . 2008-05-30 13:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll 2009-02-12 07:50 . 2008-05-30 13:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll 2009-02-12 07:50 . 2008-05-30 13:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll 2009-02-12 07:50 . 2008-05-30 13:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll 2009-02-01 16:35 . 2009-02-01 16:35 <DIR> d-------- c:\arquivos de programas\CCleaner 2009-01-26 07:34 . 2009-01-26 07:34 46 --a------ c:\windows\mxcdr.INI 2009-01-25 10:08 . 2009-02-01 21:15 129 --a------ c:\windows\MovieEdit.INI 2009-01-25 10:06 . 2009-01-26 07:38 <DIR> d-------- c:\windows\system32\MAGIX 2009-01-25 09:51 . 2009-01-25 10:07 <DIR> d-------- C:\MAGIX 2009-01-25 09:51 . 2002-09-20 23:33 1,089,536 --a------ c:\windows\system32\ROBOEX32.DLL 2009-01-25 09:51 . 1998-10-15 16:28 85,504 --a------ c:\windows\system32\HtmlWH.dll 2009-01-25 09:51 . 1999-01-28 13:44 49,152 --a------ c:\windows\system32\INETWH32.dll 2009-01-25 09:51 . 2009-01-25 09:57 85 --a------ c:\windows\magix.ini 2009-01-25 09:50 . 2004-06-01 09:53 176,128 --a------ c:\windows\system32\mgxoschk.dll 2009-01-25 09:50 . 2004-06-11 11:19 979 --a------ c:\windows\mgxoschk.ini 2009-01-25 08:31 . 1998-06-17 22:00 102,912 --a------ c:\windows\system32\VB6STKIT.DLL . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-17 12:17 720,928 --sha-w c:\windows\system32\drivers\fidbox2.dat 2009-02-17 12:17 4,053,536 --sha-w c:\windows\system32\drivers\fidbox.dat 2009-02-17 12:17 32,748 --sha-w c:\windows\system32\drivers\fidbox.idx 2009-02-17 12:17 3,544 --sha-w c:\windows\system32\drivers\fidbox2.idx 2009-02-16 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2009-02-16 16:11 --------- d-----w c:\arquivos de programas\Spybot - Search & Destroy 2009-02-16 12:34 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab 2009-02-15 23:24 --------- d-----w c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-02-15 22:19 --------- d-----w c:\arquivos de programas\Orbitdownloader 2009-02-15 18:30 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2009-02-15 18:30 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2009-02-12 10:30 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\uTorrent 2009-02-12 01:16 --------- d-----w c:\arquivos de programas\Megacubo 2009-02-11 15:26 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help 2009-02-11 13:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 13:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-02-10 12:00 33,808 ----a-w c:\windows\system32\drivers\klbg.sys 2009-02-03 18:07 89,601 ----a-w c:\windows\system32\drivers\klick.dat 2009-02-03 18:07 101,287 ----a-w c:\windows\system32\drivers\klin.dat 2009-02-01 16:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2009-02-01 15:14 107,888 ----a-w c:\windows\system32\CmdLineExt.dll 2009-01-30 11:06 --------- d-----w c:\arquivos de programas\SopCast 2009-01-25 12:45 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-01-16 23:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink 2009-01-16 14:32 --------- d-----w c:\arquivos de programas\WinAVIVideoConverter 2009-01-09 13:27 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Malwarebytes 2009-01-09 13:27 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-08 22:05 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Vso 2009-01-08 14:14 --------- d-----w c:\arquivos de programas\System Explorer 2009-01-08 13:57 15,360 ----a-w c:\windows\system32\taskman.exe 2009-01-08 10:16 244,736 ----a-w c:\windows\system32\taskmgr.exe 2009-01-07 14:22 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Kana Solution 2009-01-07 13:23 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\OpenDNS Updater 2009-01-06 15:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TVU Networks 2009-01-03 21:56 --------- d-----w c:\arquivos de programas\UOL 2008-12-25 15:24 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\RealPopup 2008-12-25 12:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SystemExplorer 2008-12-23 20:06 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Pure Networks 2008-12-20 23:06 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\UOL 2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll 2008-12-20 22:44 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\UOL 2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS 2008-12-13 21:39 96,096,280 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_2_2.BIN 2008-12-13 21:30 58,332,708 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_1_1.BIN 2008-11-30 14:13 901,120 ----a-w c:\windows\TMUninst.exe 2007-08-28 00:21 94,208 ----a-w c:\documents and settings\XP\Dados de aplicativos\ezplay.sys 2007-08-28 00:21 47,360 ----a-w c:\documents and settings\XP\Dados de aplicativos\pcouffin.sys 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe 2008-05-07 15:00 32,768 --sha-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012008050720080508\index.dat . ------- Sigcheck ------- 2006-04-20 09:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 13:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-06-20 08:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys 2007-10-30 14:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtServicePackUninstall$\tcpip.sys 2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys 2006-04-20 08:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys 2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys 2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS 2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\dllcache\TCPIP.SYS 2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\drivers\TCPIP.SYS 2004-08-04 00:45 543744 3550bfe59972a67ac2f7781041d28ea7 c:\windows\$NtServicePackUninstall$\winlogon.exe 2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\ServicePackFiles\i386\winlogon.exe 2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\system32\winlogon.exe 2008-04-13 23:21 509952 71d440f79b711627b12b567fb2eadb42 c:\windows\VistaMizer\old\winlogon.exe 2004-08-04 00:45 25088 a3f0971dbba9657034c303b39464ea5b c:\windows\$NtServicePackUninstall$\ctfmon.exe 2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\ServicePackFiles\i386\ctfmon.exe 2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\system32\ctfmon.exe 2008-04-13 23:20 15360 4e486adfe3a0b9ed0eb0639902e9f64f c:\windows\VistaMizer\old\ctfmon.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 25088] "VisualTaskTips"="c:\arquivos de programas\VisualTaskTips\VisualTaskTips.exe" [2008-05-31 65536] "TrueTransparency"="c:\arquivos de programas\TrueTransparency\TrueTransparency.exe" [2008-05-27 371200] "MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-12-25 133104] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264] "avp.exe"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 201992] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Padrão do Windows"="do Windows'" [X] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "tspuf"="c:\arquivos de programas\Telefonica\Speedy\SATUF.exe" [2003-06-16 24576] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-08-03 144792] "OrderReminder"="c:\arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13574144] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "Malwarebytes' Anti-Malware"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "DrvIcon"="c:\arquivos de programas\VistaDriveIcon\DrvIcon.exe" [2008-04-13 49152] "DAEMON Tools"="c:\arquivos de programas\DAEMON Tools\daemon.exe" [2008-02-02 128920] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 196096] "nwiz"="nwiz.exe" [2008-08-23 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Orbit.lnk] backup=c:\windows\pss\Orbit.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Styler.lnk] backup=c:\windows\pss\Styler.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^VisualTaskTips.lnk] backup=c:\windows\pss\VisualTaskTips.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration .LNK] backup=c:\windows\pss\Registration .LNKStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration Myst V] backup=c:\windows\pss\Registration Myst VStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Sidebar.lnk] backup=c:\windows\pss\Thoosje Sidebar.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Vista Sidebar.lnk] backup=c:\windows\pss\Thoosje Vista Sidebar.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^UOL Voip.lnk] backup=c:\windows\pss\UOL Voip.lnkStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Glass2k HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPopup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartDefrag HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "aawservice"=2 (0x2) "NBService"=3 (0x3) "StarWindServiceAE"=2 (0x2) "MDM"=2 (0x2) "WMPNetworkSvc"=2 (0x2) "usnjsvc"=2 (0x2) "FLEXnet Licensing Service"=3 (0x3) "AdobeActiveFileMonitor6.0"=2 (0x2) "WLSetupSvc"=3 (0x3) "WinDefend"=2 (0x2) "WudfSvc"=3 (0x3) "TermService"=2 (0x2) "SysmonLog"=3 (0x3) "SENS"=2 (0x2) "Eventlog"=2 (0x2) "aspnet_state"=3 (0x3) "NVSvc"=2 (0x2) "vsmon"=3 (0x3) "odserv"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "JavaQuickStarterService"=2 (0x2) "PnkBstrB"=2 (0x2) "PnkBstrA"=2 (0x2) "OpenDNS Updater.exe"=2 (0x2) "MBAMService"=2 (0x2) "DynDNS_Updater_Service"=2 (0x2) "AVP"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "PowerBar"= [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "c:\\Arquivos de programas\\DremTeamShare\\DreMule\\emule.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Arquivos de programas\\SopCast\\SopCast.exe"= "c:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"= "c:\\WINDOWS\\system32\\tlntsvr.exe"= "c:\\Arquivos de programas\\Megacubo\\megacubo.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Arquivos de programas\\Java\\jre6\\launch4j-tmp\\frd.exe"= "c:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-07-27 11264] S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-15 28544] S1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-04-23 82200] S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-01-07 44928] S4 OpenDNS Updater.exe;OpenDNS Updater; [x] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a719a67-79b2-11dc-a5f0-001a9294b946}] \Shell\AutoRun\command - E:\Launcher.exe . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1390067357-725345543-1003.job - c:\documents and settings\XP\Configura [] 2008-08-25 c:\windows\Tasks\User_Feed_Synchronization-{7FE8A15C-7F8C-41DA-822B-85CE77794BB8}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 11:58] . - - - - ORFÃOS REMOVIDOS - - - - HKLM-Run-SDFix - c:\sdfix\RunThis.bat . ------- Scan Suplementar ------- . uStart Page = about:blank mStart Page = about:blank uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: Down&load all by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/202 IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {B5B84699-FE8D-45AD-9CB8-26E176466BBF} = 208.67.222.222,208.67.220.220 DPF: Microsoft XML Parser for Java FF - ProfilePath - c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\ FF - prefs.js: browser.search.selectedEngine - BuscaPé FF - prefs.js: browser.startup.homepage - hxxp://www.gamevicio.com.br/portal/3/3823/wii/news/12/12886/index.html?pt=Anuncio+da+Engine+de+Cursed+Mountain FF - prefs.js: network.proxy.type - 4 FF - component: c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-17 09:24:54 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(300) c:\windows\system32\sfc_os.dll c:\windows\system32\klogon.dll c:\windows\system32\COMRes.dll c:\windows\system32\cscui.dll . Tempo para conclusão: 2009-02-17 9:27:12 ComboFix-quarantined-files.txt 2009-02-17 12:27:10 Pré-execução: 16 pasta(s) 20,889,763,840 bytes disponíveis Pós execução: 16 pasta(s) 20,874,784,768 bytes disponíveis Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4 314 --- E O F --- 2009-02-11 15:27:56 é isso no aguardo para novas instruções!!!! Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 17, 2009 ha ja ia me esquecendo o do hijack ai vai Logfile of HijackThis v1.99.1 Scan saved at 10:13:57, on 17/2/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\netdde.exe C:\WINDOWS\system32\clipsrv.exe C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\XP\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765 O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing) O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 18, 2009 Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::E:\Launcher.exe Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "vsmon"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000000 [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a719a67-79b2-11dc-a5f0-001a9294b946}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 18, 2009 fiz o que você falou,criei o scrip,salvei na area de trabalho,mas surgiu um pequeno problema,como disse só consigo executar os programas atravess do menu executar que acesso via crtl+alt+del,depois localizar o exe do programa e depois de selecionado dar ok então sendo assim atraves dessa janela não tem como eu arrastar dentro do kombo fix,tentei fazer e não aconteceu nada ja que só consigo executar algo selecionando e dando ok e não tem como selecionar os 2 ao mesmo tempo,percebi que meu explorer.exe não existe mais,como que se tivesse sido apagado baixei o autorun para ver meus processos e vi que no explorer.exe esta como file missing ia tentar até essa dica http://www.guiadowindows.net/2008/02/como-...windows-xp.html para ver se conseguia recuperar meu explorer,mas não tenho o cd do win xp meu pc veio sem o cd...poxa será mesmo que vou ter que formatar? Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 18, 2009 me deu uma luz na cabeça percebi atraves de pesquisas via google que varias pessoas que passou por esse problema tinha o kaspersky instalado,resolvi dar uma fuçada nele e na area de quarentena lá estava meu explorer.exe classificado como potencialmente perigoso keylogger pedi para restaurar depois disso fui no executar e digitei explorer dai minha area de trabalho enfim voltou,agora só preciso saber pq meu explorer foi para no anti virus vou passar agora o scrip que você pedi e te mando o log Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 18, 2009 ai vai o log agora to indo trampa,pelo menos minha area de trabalho voltou o combofix continua dando a msg de zone alarm ativo como residente na memoria tem como apagar esses registros do zone alarm..?? ComboFix 09-02-17.02 - XP 2009-02-18 13:15:13.6 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.549 [GMT -3:00] Executando de: c:\documents and settings\XP\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\XP\Desktop\CFScript.txt AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated) FW: ZoneAlarm Security Suite Firewall *enabled* * Criado um novo ponto de restauro FILE :: E:\Launcher.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . E:\Launcher.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-18 to 2009-02-18 )))))))))))))))))))))))))))) . 2009-02-16 07:52 . 2009-02-16 07:52 579,072 --a--c--- c:\windows\system32\dllcache\user32.dll 2009-02-16 07:50 . 2009-02-16 07:51 <DIR> d-------- c:\windows\ERUNT 2009-02-15 20:05 . 2009-02-15 20:05 <DIR> d-------- c:\arquivos de programas\Panda Security 2009-02-15 20:05 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2009-02-15 16:52 . 2009-02-15 16:52 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\Codemasters 2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\InstallShield 2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\InstallShield 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\windows\system32\AGEIA 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- C:\ProgramData 2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\arquivos de programas\AGEIA Technologies 2009-02-15 15:30 . 2009-02-15 15:30 <DIR> d-------- c:\arquivos de programas\Codemasters 2009-02-15 15:30 . 2007-04-27 11:12 78,784 --a------ c:\windows\system32\ISUSPM.cpl 2009-02-15 10:17 . 2009-02-15 10:17 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\VitySoft 2009-02-15 10:16 . 2009-02-15 14:30 <DIR> d-------- c:\arquivos de programas\FreeRapid-0.81 2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys 2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\documents and settings\XP\Dados de aplicativos\PnkBstrK.sys 2009-02-12 08:39 . 2009-02-12 08:39 682,280 --a------ c:\windows\system32\pbsvc.exe 2009-02-12 08:39 . 2009-02-12 08:39 107,832 --a------ c:\windows\system32\PnkBstrB.exe 2009-02-12 08:39 . 2009-02-12 08:39 66,872 --a------ c:\windows\system32\PnkBstrA.exe 2009-02-12 08:24 . 2009-02-12 08:43 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\GetRightToGo 2009-02-12 07:50 . 2009-02-12 07:50 <DIR> d-------- c:\windows\Logs 2009-02-12 07:50 . 2008-05-30 13:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll 2009-02-12 07:50 . 2008-05-30 13:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll 2009-02-12 07:50 . 2008-05-30 13:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll 2009-02-12 07:50 . 2008-05-30 13:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll 2009-02-12 07:50 . 2008-05-30 13:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll 2009-02-12 07:50 . 2008-05-30 13:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll 2009-02-12 07:50 . 2008-05-30 13:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll 2009-02-01 16:35 . 2009-02-01 16:35 <DIR> d-------- c:\arquivos de programas\CCleaner 2009-01-26 07:34 . 2009-01-26 07:34 46 --a------ c:\windows\mxcdr.INI 2009-01-25 10:08 . 2009-02-01 21:15 129 --a------ c:\windows\MovieEdit.INI 2009-01-25 10:06 . 2009-01-26 07:38 <DIR> d-------- c:\windows\system32\MAGIX 2009-01-25 09:51 . 2009-01-25 10:07 <DIR> d-------- C:\MAGIX 2009-01-25 09:51 . 2002-09-20 23:33 1,089,536 --a------ c:\windows\system32\ROBOEX32.DLL 2009-01-25 09:51 . 1998-10-15 16:28 85,504 --a------ c:\windows\system32\HtmlWH.dll 2009-01-25 09:51 . 1999-01-28 13:44 49,152 --a------ c:\windows\system32\INETWH32.dll 2009-01-25 09:51 . 2009-01-25 09:57 85 --a------ c:\windows\magix.ini 2009-01-25 09:50 . 2004-06-01 09:53 176,128 --a------ c:\windows\system32\mgxoschk.dll 2009-01-25 09:50 . 2004-06-11 11:19 979 --a------ c:\windows\mgxoschk.ini 2009-01-25 08:31 . 1998-06-17 22:00 102,912 --a------ c:\windows\system32\VB6STKIT.DLL . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-18 16:16 720,928 --sha-w c:\windows\system32\drivers\fidbox2.dat 2009-02-18 16:16 4,053,536 --sha-w c:\windows\system32\drivers\fidbox.dat 2009-02-18 16:16 32,748 --sha-w c:\windows\system32\drivers\fidbox.idx 2009-02-18 16:16 3,544 --sha-w c:\windows\system32\drivers\fidbox2.idx 2009-02-18 16:00 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab 2009-02-16 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2009-02-16 16:11 --------- d-----w c:\arquivos de programas\Spybot - Search & Destroy 2009-02-15 23:24 --------- d-----w c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-02-15 22:19 --------- d-----w c:\arquivos de programas\Orbitdownloader 2009-02-15 18:30 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2009-02-15 18:30 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2009-02-12 10:30 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\uTorrent 2009-02-12 01:16 --------- d-----w c:\arquivos de programas\Megacubo 2009-02-11 15:26 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help 2009-02-11 13:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 13:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-02-10 12:00 33,808 ----a-w c:\windows\system32\drivers\klbg.sys 2009-02-03 18:07 89,601 ----a-w c:\windows\system32\drivers\klick.dat 2009-02-03 18:07 101,287 ----a-w c:\windows\system32\drivers\klin.dat 2009-02-01 16:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2009-01-30 11:06 --------- d-----w c:\arquivos de programas\SopCast 2009-01-25 12:45 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-01-16 23:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink 2009-01-16 14:32 --------- d-----w c:\arquivos de programas\WinAVIVideoConverter 2009-01-09 13:27 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Malwarebytes 2009-01-09 13:27 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-08 22:05 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Vso 2009-01-08 14:14 --------- d-----w c:\arquivos de programas\System Explorer 2009-01-07 14:22 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Kana Solution 2009-01-07 13:23 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\OpenDNS Updater 2009-01-06 15:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TVU Networks 2009-01-03 21:56 --------- d-----w c:\arquivos de programas\UOL 2008-12-25 15:24 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\RealPopup 2008-12-25 12:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SystemExplorer 2008-12-23 20:06 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Pure Networks 2008-12-20 23:06 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\UOL 2008-12-20 22:44 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\UOL 2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS 2008-12-13 21:39 96,096,280 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_2_2.BIN 2008-12-13 21:30 58,332,708 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_1_1.BIN 2008-11-30 14:13 901,120 ----a-w c:\windows\TMUninst.exe 2007-08-28 00:21 94,208 ----a-w c:\documents and settings\XP\Dados de aplicativos\ezplay.sys 2007-08-28 00:21 47,360 ----a-w c:\documents and settings\XP\Dados de aplicativos\pcouffin.sys 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe 2008-05-07 15:00 32,768 --sha-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012008050720080508\index.dat . ------- Sigcheck ------- 2006-04-20 09:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 13:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-06-20 08:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys 2007-10-30 14:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtServicePackUninstall$\tcpip.sys 2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys 2006-04-20 08:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys 2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys 2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS 2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\dllcache\TCPIP.SYS 2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\drivers\TCPIP.SYS 2004-08-04 00:45 543744 3550bfe59972a67ac2f7781041d28ea7 c:\windows\$NtServicePackUninstall$\winlogon.exe 2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\ServicePackFiles\i386\winlogon.exe 2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\system32\winlogon.exe 2008-04-13 23:21 509952 71d440f79b711627b12b567fb2eadb42 c:\windows\VistaMizer\old\winlogon.exe 2008-08-13 20:32 1554432 7b198d92210d9da9d4e0db1e4855b727 c:\windows\explorer.exe 2007-06-13 10:10 1035264 45d521506825a10b80833b4e9621ccf6 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe 2007-06-13 10:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 c:\windows\$NtServicePackUninstall$\explorer.exe 2004-08-04 00:45 1552896 9da14fe20c421e7f45dbe3d04b4c4fc9 c:\windows\$NtUninstallKB938828$\explorer.exe 2008-04-13 23:20 1554432 7b198d92210d9da9d4e0db1e4855b727 c:\windows\ServicePackFiles\i386\explorer.exe 2008-04-13 23:20 1035776 064ec7ff5f58b928c3e119402977fa6d c:\windows\VistaMizer\old\explorer.exe 2004-08-04 00:45 25088 a3f0971dbba9657034c303b39464ea5b c:\windows\$NtServicePackUninstall$\ctfmon.exe 2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\ServicePackFiles\i386\ctfmon.exe 2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\system32\ctfmon.exe 2008-04-13 23:20 15360 4e486adfe3a0b9ed0eb0639902e9f64f c:\windows\VistaMizer\old\ctfmon.exe . ((((((((((((((((((((((((((((( SnapShot@2009-02-17_ 9.25.21.78 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-03 18:24:26 312,680 ----a-w c:\windows\Downloaded Program Files\avsniff.dll + 2009-02-03 18:24:28 255,336 ----a-w c:\windows\Downloaded Program Files\avsniffdlgs.dll + 2009-02-11 04:00:00 2,504 ----a-w c:\windows\Downloaded Program Files\catalog.dat + 2009-02-03 18:14:26 42,112 ----a-w c:\windows\Downloaded Program Files\ecmldr32.dll + 2009-02-11 04:00:00 259,368 ----a-w c:\windows\Downloaded Program Files\ecmsvr32.dll + 2009-02-03 18:14:42 201,896 ----a-w c:\windows\Downloaded Program Files\navapi32.dll + 2009-02-11 04:00:00 177,520 ----a-w c:\windows\Downloaded Program Files\naveng32.dll + 2009-02-11 04:00:00 1,181,040 ----a-w c:\windows\Downloaded Program Files\navex32a.dll + 2009-02-03 18:24:36 296,336 ----a-w c:\windows\Downloaded Program Files\rufsi.dll + 2009-02-11 04:00:00 97,776 ----a-w c:\windows\Downloaded Program Files\scrauth.dat + 2009-02-11 04:00:00 488,261 ----a-w c:\windows\Downloaded Program Files\tcdefs.dat + 2009-02-11 04:00:00 11,046,727 ----a-w c:\windows\Downloaded Program Files\tcscan7.dat + 2009-02-11 04:00:00 171,825 ----a-w c:\windows\Downloaded Program Files\tcscan8.dat + 2009-02-11 04:00:00 485,395 ----a-w c:\windows\Downloaded Program Files\tcscan9.dat + 2009-02-11 04:00:00 1,957 ----a-w c:\windows\Downloaded Program Files\tinfl.dat + 2009-02-11 04:00:00 72,567 ----a-w c:\windows\Downloaded Program Files\tscan1.dat + 2009-02-11 04:00:00 3,760 ----a-w c:\windows\Downloaded Program Files\tscan1hd.dat + 2009-02-11 04:00:00 1,014,111 ----a-w c:\windows\Downloaded Program Files\virscan1.dat + 2009-02-11 04:00:00 571,956 ----a-w c:\windows\Downloaded Program Files\virscan2.dat + 2009-02-11 04:00:00 153,164 ----a-w c:\windows\Downloaded Program Files\virscan3.dat + 2009-02-11 04:00:00 320,259 ----a-w c:\windows\Downloaded Program Files\virscan4.dat + 2009-02-11 04:00:00 11,179,842 ----a-w c:\windows\Downloaded Program Files\virscan5.dat + 2009-02-11 04:00:00 395,444 ----a-w c:\windows\Downloaded Program Files\virscan6.dat + 2009-02-11 04:00:00 35,658,217 ----a-w c:\windows\Downloaded Program Files\virscan7.dat + 2009-02-11 04:00:00 1,068,862 ----a-w c:\windows\Downloaded Program Files\virscan8.dat + 2009-02-11 04:00:00 3,660,672 ----a-w c:\windows\Downloaded Program Files\virscan9.dat + 2009-02-17 14:26:12 2,072 ----a-w c:\windows\Downloaded Program Files\vscanmsx.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 25088] "VisualTaskTips"="c:\arquivos de programas\VisualTaskTips\VisualTaskTips.exe" [2008-05-31 65536] "TrueTransparency"="c:\arquivos de programas\TrueTransparency\TrueTransparency.exe" [2008-05-27 371200] "MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Google Update"="c:\documents and settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-12-25 133104] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264] "avp.exe"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 201992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "tspuf"="c:\arquivos de programas\Telefonica\Speedy\SATUF.exe" [2003-06-16 24576] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-08-03 144792] "OrderReminder"="c:\arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13574144] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "Malwarebytes' Anti-Malware"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "DrvIcon"="c:\arquivos de programas\VistaDriveIcon\DrvIcon.exe" [2008-04-13 49152] "DAEMON Tools"="c:\arquivos de programas\DAEMON Tools\daemon.exe" [2008-02-02 128920] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 196096] "nwiz"="nwiz.exe" [2008-08-23 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Orbit.lnk] backup=c:\windows\pss\Orbit.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Styler.lnk] backup=c:\windows\pss\Styler.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^VisualTaskTips.lnk] backup=c:\windows\pss\VisualTaskTips.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration .LNK] backup=c:\windows\pss\Registration .LNKStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration Myst V] backup=c:\windows\pss\Registration Myst VStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Sidebar.lnk] backup=c:\windows\pss\Thoosje Sidebar.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Vista Sidebar.lnk] backup=c:\windows\pss\Thoosje Vista Sidebar.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^UOL Voip.lnk] backup=c:\windows\pss\UOL Voip.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "aawservice"=2 (0x2) "NBService"=3 (0x3) "StarWindServiceAE"=2 (0x2) "MDM"=2 (0x2) "WMPNetworkSvc"=2 (0x2) "usnjsvc"=2 (0x2) "FLEXnet Licensing Service"=3 (0x3) "AdobeActiveFileMonitor6.0"=2 (0x2) "WLSetupSvc"=3 (0x3) "WinDefend"=2 (0x2) "WudfSvc"=3 (0x3) "TermService"=2 (0x2) "SysmonLog"=3 (0x3) "SENS"=2 (0x2) "Eventlog"=2 (0x2) "aspnet_state"=3 (0x3) "NVSvc"=2 (0x2) "odserv"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "JavaQuickStarterService"=2 (0x2) "PnkBstrB"=2 (0x2) "PnkBstrA"=2 (0x2) "OpenDNS Updater.exe"=2 (0x2) "MBAMService"=2 (0x2) "DynDNS_Updater_Service"=2 (0x2) "AVP"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "PowerBar"= [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "c:\\Arquivos de programas\\DremTeamShare\\DreMule\\emule.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Arquivos de programas\\SopCast\\SopCast.exe"= "c:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"= "c:\\WINDOWS\\system32\\tlntsvr.exe"= "c:\\Arquivos de programas\\Megacubo\\megacubo.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Arquivos de programas\\Java\\jre6\\launch4j-tmp\\frd.exe"= "c:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808] R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-15 28544] R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-07-27 11264] R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-04-23 82200] S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-01-07 44928] S4 OpenDNS Updater.exe;OpenDNS Updater; [x] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1390067357-725345543-1003.job - c:\documents and settings\XP\Configura [] 2008-08-25 c:\windows\Tasks\User_Feed_Synchronization-{7FE8A15C-7F8C-41DA-822B-85CE77794BB8}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 11:58] . . ------- Scan Suplementar ------- . uStart Page = about:blank mStart Page = about:blank uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: Down&load all by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/202 IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {B5B84699-FE8D-45AD-9CB8-26E176466BBF} = 208.67.222.222,208.67.220.220 DPF: Microsoft XML Parser for Java FF - ProfilePath - c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\ FF - prefs.js: browser.search.selectedEngine - BuscaPé FF - prefs.js: browser.startup.homepage - hxxp://www.gamevicio.com.br/portal/3/3823/wii/news/12/12886/index.html?pt=Anuncio+da+Engine+de+Cursed+Mountain FF - prefs.js: network.proxy.type - 4 FF - component: c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-18 13:18:52 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(908) c:\windows\system32\sfc_os.dll c:\windows\system32\klogon.dll c:\windows\system32\COMRes.dll c:\windows\system32\cscui.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\windows\system32\netdde.exe c:\windows\system32\clipsrv.exe c:\arquivos de programas\NetLimiter 2 Pro\nlsvc.exe c:\arquivos de programas\NetLimiter 2 Pro\NLClient.exe c:\windows\system32\rundll32.exe c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe . ************************************************************************** . Tempo para conclusão: 2009-02-18 13:22:06 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-02-18 16:22:03 ComboFix2.txt 2009-02-18 15:49:36 ComboFix3.txt 2009-02-18 15:30:13 ComboFix4.txt 2009-02-17 12:28:27 Pré-execução: 16 pasta(s) 20.636.733.440 bytes disponíveis Pós execução: 16 pasta(s) 20,619,100,160 bytes disponíveis Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4 345 --- E O F --- 2009-02-11 15:27:56 Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 18, 2009 Olá siga minhas instruções na seqüencia para não ocorrer confusão na análise. 1) • Vá a este Link,e baixe: < Malwarebytes > • Atualize o programa! • Escolha o escaneamento Rápido! • Desabilite programas de proteção,ao executar o malwarebytes. • Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. • Para maiores detalhes: < Link > 2) Com o navegador Internet Explorer, acesse o Kaspersky Online Scanner e faça um scan online seguindo o tutorial abaixo. Tutorial Kaspersky Online Scanner Ao término do scan, salve o relatório com a extensão .txt (como mostra no final do tutorial) e poste em sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 19, 2009 bom vamos a respostas o Malwarebytes eu ja tinha instalado no meu pc,passei e não encontrou nada o scan on line comecei por 2 vezes e no meio da atualização deu uma tela azul com um monte de informação e no final possivelmente causado por KIif.sys minha area de trabalho voltou,mas os atalhos para meu computador e minhas pastas não funcionando meu computador só joguei novamente o atalho do menu iniciar para a area de trabalho,mas as minhas pastas ja apaguei os atalhos velhos e criei novos e não adiantou nada,sempre da a mesma msg este arquivo não tem um programa associado a ele para realizar essa ação,crie uma associação no painel de controle "opções de pasta" só nos atalhos das pastas que até agora vi dar isso tentei craiar associação não consegui não sei ao certo como fazer,criei uma nova associação com a extensão LNK para shortcuts mas não hablita a opção aplicar,então não muda nada,mas minha area de trabalho voltou até agora não voltei a habilitar as proteções do meu anti virus,amanha vou tentar voltar pra ver no que vai dar...alguma sugestão? Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 19, 2009 Faça um scan online com o bitdefender como mostra nesse tutorial Compartilhar este post Link para o post Compartilhar em outros sites
roberfc 0 Denunciar post Postado Fevereiro 21, 2009 desculpe pela demora para responder,estava ausente,passei o anti virus conforme você pediu,deixei passando,encontrou alguma coisa,mas infelizmente o log nem eu vi,minha esposa sem saber fechou tudo,mas meu pc agora ta realmente como era antes,os problemas de atalhos resolvido com um restaurar o sistema para um semana atras,realmente meu problema era um bug do anti virus veja http://www.webtuga.com/kaspersky-classific...exe-como-virus/ Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Fevereiro 22, 2009 ok, podemos considerar o problema como resolvido? Compartilhar este post Link para o post Compartilhar em outros sites