Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

roberfc

[Resolvido!] minha area de trabalho sumiu só tenho acesso ao crtl

Recommended Posts

vi nesse forum que um membro teve o mesmo problema resolvido,por isso me registrei aqui,como cada caso é um caso né vou postar meu log do hjhackthis

 

Logfile of HijackThis v1.99.1

Scan saved at 21:12:44, on 15/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\XP\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab

O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765

O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB

O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

 

se alguem puder ajudar ficarei agradecido,ja tentei varias dica que pesquisei via google e nenhuma deu certo

Compartilhar este post


Link para o post
Compartilhar em outros sites

- Faça o download do SDFIX

 

Reinicie seu computador, e aperte a tecla F8 (F5 em alguns casos) intermitentemente durante a inicialização, até aparecer um menu onde você deverá escolher a opção Modo Seguro

 

1. Entre na pasta SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat

2. Tecle Y para que a ferramenta inicie o processo de remoção

3. Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar. Ao pressionar qualquer tecla, o computador será reiniciado automaticamente

4. Após reiniciar, a ferramenta ainda será executada novamente e irá terminar o seu trabalho e a palavra Finished irá aparecer. Pressione qualquer tecla.

5. Uma janela com o relatório do SDFix irá aparecer.

6. Copie e cole este relatório na sua resposta . Caso você tenha fechado a janela, uma cópia do relatório estará na pasta SDFix com o nome Report.txt.

Compartilhar este post


Link para o post
Compartilhar em outros sites

no report.txt tava só isso

 

SDFix: Version 1.240

Run by XP on seg 16/02/2009 at 07:53

 

Microsoft Windows XP [versão 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

 

Restoring Default Security Values

Restoring Default Hosts File

 

Rebooting

Compartilhar este post


Link para o post
Compartilhar em outros sites

não apareceu a palavra finished depois que reiniciou do modo de segurança,porem apareceu um monte de txt na pasta do programa,como só estou abrindo com o gerenciador de tarefas não tem como copiar e colar o nome de tds pra você,mas vou escrever um por um e passar pra você ver...

 

backupreg(pasta)

backups(pasta)

attrib.exe

catchm.exe

dummi.exe

editreg.exe

rtsdnif.exe

runthis.bat

dnif.exe

hosts

sdfix_readme_online

beepfa0.txt

beepfa1.txt

beepfa2.txt

beepfa3.txt

beepfa4.txt

beepxcodec0.txt

beepxcodec1.txt

beepxcodec2.txt

beepxcodec3.txt

beepxcodec4.txt

bptest1.txt

bptest3.txt

delavi0.txt

delzip0.txt

dest.txt

filekilllist1.txt

filelist1.txt

find.txt

findv2009.txt

findv2009a.txt

findbhos1.txt

findircbrute.txt

findroguerun.txt

findrun002.txt

findrun002a.txt

findrun30.txt

findrun31.txt

findrun31a.txt

findrun31b.txt

findrun32.txt

findrunbifrose1.txt

findrunboot1.txt

findrundw_start.txt

findzip.txt

patched2a.txt

patched2b.txt

patched2c.txt

remlat1.txt

remlat2.txt

remlat3.txt

remlat4.txt

report.txt

userinfix.reg

add_dbfix_runonce_key.inf

w2k_virusalert_repair.inf

xp_virusalert_repair.inf

 

bom é isso que esta dentro da pasta do programa,estou no aguardo para novas instruções !!

Compartilhar este post


Link para o post
Compartilhar em outros sites

para mim ter acesso aos programas que tenho instalado tenho que fazer o caminho

ctrl+alt+del

gerenciador de tarefas

arquivo

executar nova tarefa e

procurar dai procuro o programa que quero abrir no meu pc e abro por ali,mas 2 coisas que notei de estranho,não acho a pasta painel de controle e todos os icones estão normal menos o icone do meu computador que aparece como uma folha em branco

obs: só vou poder postar na parte da manha pq a tarde trabalho e só saio as 22 hrs

de manha fico por aqui até umas 12:30 hrs mais ou menos e qd chego as 22 hrs nem entro mais na net dai só no outro dia de manha,então se você postar a noite só responderei na parte da manha do outro dia...

Compartilhar este post


Link para o post
Compartilhar em outros sites

vou postar outro log do hjackthis com todos os programas na inicialização ativados...

 

Logfile of HijackThis v1.99.1

Scan saved at 11:38:07, on 16/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe

C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Documents and Settings\XP\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [sDFix] C:\SDFix\RunThis.bat /second

O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon

O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab

O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765

O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB

O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

• Baixe: < ComboFix.exe >

• Salve-o no Desktop!

Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

Feche todas as janelas e execute a ferramenta!

• Na solicitação: "Negação de garantia de software" --> Clique em Sim!

• Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

-- Salve-a no desktop,renomeada como: Kombo.exe

-- Ps: Nomeie durante o salvamento,e não após salvá-la!

-- Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança.

-- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

-- Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.

• Abrir-se-á a janela Auto Scan. --> Aguarde!

• Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

• Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter.

Aguarde a conclusão!

Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

• Para parar ou sair do ComboFix,tecle "N" --> Enter.

----------------------

• Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-02-15.01 - XP 2009-02-16 13:16:01.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.673 [GMT -3:00]

Executando de: C:\Documents and Settings\XP\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated)

FW: ZoneAlarm Security Suite Firewall *enabled*

* Criado um novo ponto de restauro

.

 

combfix.txt só tinha isso obs zone alarm é um programa que eu ja desistalei da maquina faz tempo e pedia pra mim desabilitar ele ,não sei onde pq ja desistalei,então passei assim mesmo minha area de trabalho não apareceu ainda agora vou passar o do hijackthis

 

Logfile of HijackThis v1.99.1

Scan saved at 13:28, on 2009-02-16

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\XP\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [sDFix] C:\SDFix\RunThis.bat /second

O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\CF7434.exe /c C:\ComboFix\Combobatch.bat

O4 - HKLM\..\RunOnce: [combofix] C:\WINDOWS\system32\CF7434.exe /c C:\ComboFix\Combobatch.bat

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon

O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab

O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765

O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB

O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

 

agora to indo trampa só entro amanha lá pelas 8:30 hrs da manha falows !!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

Por favor execute o programa combofix novamente, mais dessa vez execute-o em modo segurança

Compartilhar este post


Link para o post
Compartilhar em outros sites

bom como você indicou entrei em modo seguro(f5)

executei o combofix deu aquela mesma msg que o sistema residente do zone alarm estava ativo para mim desativar cliquei para seguir em frente disse que por minha conta e risco que pd danificar a maquina,mas não sei pq ta dando isso,deve ter alguma entrada no registro dele que não foi apagada,mas depois que desistalei ele ja tinha passado varios programas de limpeza de registro bom dai executei ele,passou normalmente e no final deu uma msg que o windowns não conseguia encontrar explorer.exe...

e gerou um log salvei na area de trabalho

obs:combofix não reiniciou o pc e na pasta do combo fix no c ta vazia eu tinha apagado o conteudo da primeira passada,mas o log como salvei na area de trabalho vou passar ai vai;

 

ComboFix 09-02-15.01 - XP 2009-02-17 9:23:09.3 - NTFSx86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.816 [GMT -3:00]

Executando de: c:\documents and settings\XP\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated)

FW: ZoneAlarm Security Suite Firewall *enabled*

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-17 to 2009-02-17 ))))))))))))))))))))))))))))

.

 

2009-02-16 07:52 . 2009-02-16 07:52 579,072 --a--c--- c:\windows\system32\dllcache\user32.dll

2009-02-16 07:50 . 2009-02-16 07:51 <DIR> d-------- c:\windows\ERUNT

2009-02-15 20:05 . 2009-02-15 20:05 <DIR> d-------- c:\arquivos de programas\Panda Security

2009-02-15 20:05 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys

2009-02-15 16:52 . 2009-02-15 16:52 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\Codemasters

2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\InstallShield

2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\InstallShield

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\windows\system32\AGEIA

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- C:\ProgramData

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\arquivos de programas\AGEIA Technologies

2009-02-15 15:30 . 2009-02-15 15:30 <DIR> d-------- c:\arquivos de programas\Codemasters

2009-02-15 15:30 . 2007-04-27 11:12 78,784 --a------ c:\windows\system32\ISUSPM.cpl

2009-02-15 10:17 . 2009-02-15 10:17 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\VitySoft

2009-02-15 10:16 . 2009-02-15 14:30 <DIR> d-------- c:\arquivos de programas\FreeRapid-0.81

2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys

2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\documents and settings\XP\Dados de aplicativos\PnkBstrK.sys

2009-02-12 08:39 . 2009-02-12 08:39 682,280 --a------ c:\windows\system32\pbsvc.exe

2009-02-12 08:39 . 2009-02-12 08:39 107,832 --a------ c:\windows\system32\PnkBstrB.exe

2009-02-12 08:39 . 2009-02-12 08:39 66,872 --a------ c:\windows\system32\PnkBstrA.exe

2009-02-12 08:24 . 2009-02-12 08:43 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\GetRightToGo

2009-02-12 07:50 . 2009-02-12 07:50 <DIR> d-------- c:\windows\Logs

2009-02-12 07:50 . 2008-05-30 13:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll

2009-02-12 07:50 . 2008-05-30 13:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll

2009-02-12 07:50 . 2008-05-30 13:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll

2009-02-12 07:50 . 2008-05-30 13:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll

2009-02-12 07:50 . 2008-05-30 13:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll

2009-02-12 07:50 . 2008-05-30 13:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll

2009-02-12 07:50 . 2008-05-30 13:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll

2009-02-01 16:35 . 2009-02-01 16:35 <DIR> d-------- c:\arquivos de programas\CCleaner

2009-01-26 07:34 . 2009-01-26 07:34 46 --a------ c:\windows\mxcdr.INI

2009-01-25 10:08 . 2009-02-01 21:15 129 --a------ c:\windows\MovieEdit.INI

2009-01-25 10:06 . 2009-01-26 07:38 <DIR> d-------- c:\windows\system32\MAGIX

2009-01-25 09:51 . 2009-01-25 10:07 <DIR> d-------- C:\MAGIX

2009-01-25 09:51 . 2002-09-20 23:33 1,089,536 --a------ c:\windows\system32\ROBOEX32.DLL

2009-01-25 09:51 . 1998-10-15 16:28 85,504 --a------ c:\windows\system32\HtmlWH.dll

2009-01-25 09:51 . 1999-01-28 13:44 49,152 --a------ c:\windows\system32\INETWH32.dll

2009-01-25 09:51 . 2009-01-25 09:57 85 --a------ c:\windows\magix.ini

2009-01-25 09:50 . 2004-06-01 09:53 176,128 --a------ c:\windows\system32\mgxoschk.dll

2009-01-25 09:50 . 2004-06-11 11:19 979 --a------ c:\windows\mgxoschk.ini

2009-01-25 08:31 . 1998-06-17 22:00 102,912 --a------ c:\windows\system32\VB6STKIT.DLL

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-17 12:17 720,928 --sha-w c:\windows\system32\drivers\fidbox2.dat

2009-02-17 12:17 4,053,536 --sha-w c:\windows\system32\drivers\fidbox.dat

2009-02-17 12:17 32,748 --sha-w c:\windows\system32\drivers\fidbox.idx

2009-02-17 12:17 3,544 --sha-w c:\windows\system32\drivers\fidbox2.idx

2009-02-16 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2009-02-16 16:11 --------- d-----w c:\arquivos de programas\Spybot - Search & Destroy

2009-02-16 12:34 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab

2009-02-15 23:24 --------- d-----w c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-02-15 22:19 --------- d-----w c:\arquivos de programas\Orbitdownloader

2009-02-15 18:30 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2009-02-15 18:30 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2009-02-12 10:30 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\uTorrent

2009-02-12 01:16 --------- d-----w c:\arquivos de programas\Megacubo

2009-02-11 15:26 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help

2009-02-11 13:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-11 13:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-02-10 12:00 33,808 ----a-w c:\windows\system32\drivers\klbg.sys

2009-02-03 18:07 89,601 ----a-w c:\windows\system32\drivers\klick.dat

2009-02-03 18:07 101,287 ----a-w c:\windows\system32\drivers\klin.dat

2009-02-01 16:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard

2009-02-01 15:14 107,888 ----a-w c:\windows\system32\CmdLineExt.dll

2009-01-30 11:06 --------- d-----w c:\arquivos de programas\SopCast

2009-01-25 12:45 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-01-16 23:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink

2009-01-16 14:32 --------- d-----w c:\arquivos de programas\WinAVIVideoConverter

2009-01-09 13:27 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Malwarebytes

2009-01-09 13:27 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-08 22:05 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Vso

2009-01-08 14:14 --------- d-----w c:\arquivos de programas\System Explorer

2009-01-08 13:57 15,360 ----a-w c:\windows\system32\taskman.exe

2009-01-08 10:16 244,736 ----a-w c:\windows\system32\taskmgr.exe

2009-01-07 14:22 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Kana Solution

2009-01-07 13:23 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\OpenDNS Updater

2009-01-06 15:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TVU Networks

2009-01-03 21:56 --------- d-----w c:\arquivos de programas\UOL

2008-12-25 15:24 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\RealPopup

2008-12-25 12:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SystemExplorer

2008-12-23 20:06 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Pure Networks

2008-12-20 23:06 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\UOL

2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll

2008-12-20 22:44 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\UOL

2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL

2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS

2008-12-13 21:39 96,096,280 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_2_2.BIN

2008-12-13 21:30 58,332,708 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_1_1.BIN

2008-11-30 14:13 901,120 ----a-w c:\windows\TMUninst.exe

2007-08-28 00:21 94,208 ----a-w c:\documents and settings\XP\Dados de aplicativos\ezplay.sys

2007-08-28 00:21 47,360 ----a-w c:\documents and settings\XP\Dados de aplicativos\pcouffin.sys

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

2008-05-07 15:00 32,768 --sha-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012008050720080508\index.dat

.

 

------- Sigcheck -------

 

2006-04-20 09:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys

2007-10-30 13:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-06-20 08:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

2007-10-30 14:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtServicePackUninstall$\tcpip.sys

2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys

2006-04-20 08:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys

2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys

2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS

2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\dllcache\TCPIP.SYS

2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\drivers\TCPIP.SYS

 

2004-08-04 00:45 543744 3550bfe59972a67ac2f7781041d28ea7 c:\windows\$NtServicePackUninstall$\winlogon.exe

2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\ServicePackFiles\i386\winlogon.exe

2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\system32\winlogon.exe

2008-04-13 23:21 509952 71d440f79b711627b12b567fb2eadb42 c:\windows\VistaMizer\old\winlogon.exe

 

2004-08-04 00:45 25088 a3f0971dbba9657034c303b39464ea5b c:\windows\$NtServicePackUninstall$\ctfmon.exe

2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\ServicePackFiles\i386\ctfmon.exe

2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\system32\ctfmon.exe

2008-04-13 23:20 15360 4e486adfe3a0b9ed0eb0639902e9f64f c:\windows\VistaMizer\old\ctfmon.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 25088]

"VisualTaskTips"="c:\arquivos de programas\VisualTaskTips\VisualTaskTips.exe" [2008-05-31 65536]

"TrueTransparency"="c:\arquivos de programas\TrueTransparency\TrueTransparency.exe" [2008-05-27 371200]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Google Update"="c:\documents and settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-12-25 133104]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]

"avp.exe"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 201992]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"Padrão do Windows"="do Windows'" [X]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"tspuf"="c:\arquivos de programas\Telefonica\Speedy\SATUF.exe" [2003-06-16 24576]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-08-03 144792]

"OrderReminder"="c:\arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13574144]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

"Malwarebytes' Anti-Malware"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"DrvIcon"="c:\arquivos de programas\VistaDriveIcon\DrvIcon.exe" [2008-04-13 49152]

"DAEMON Tools"="c:\arquivos de programas\DAEMON Tools\daemon.exe" [2008-02-02 128920]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 196096]

"nwiz"="nwiz.exe" [2008-08-23 c:\windows\system32\nwiz.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.l3fhg"= mp3fhg.acm

"msacm.divxa32"= divxa32.acm

"VIDC.X264"= x264vfw.dll

"VIDC.HFYU"= huffyuv.dll

"vidc.i263"= i263_32.drv

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Orbit.lnk]

backup=c:\windows\pss\Orbit.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Styler.lnk]

backup=c:\windows\pss\Styler.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^VisualTaskTips.lnk]

backup=c:\windows\pss\VisualTaskTips.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^WinZip Quick Pick.lnk]

backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration .LNK]

backup=c:\windows\pss\Registration .LNKStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration Myst V]

backup=c:\windows\pss\Registration Myst VStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Sidebar.lnk]

backup=c:\windows\pss\Thoosje Sidebar.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Vista Sidebar.lnk]

backup=c:\windows\pss\Thoosje Vista Sidebar.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^UOL Voip.lnk]

backup=c:\windows\pss\UOL Voip.lnkStartup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Glass2k

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPopup

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartDefrag

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"aawservice"=2 (0x2)

"NBService"=3 (0x3)

"StarWindServiceAE"=2 (0x2)

"MDM"=2 (0x2)

"WMPNetworkSvc"=2 (0x2)

"usnjsvc"=2 (0x2)

"FLEXnet Licensing Service"=3 (0x3)

"AdobeActiveFileMonitor6.0"=2 (0x2)

"WLSetupSvc"=3 (0x3)

"WinDefend"=2 (0x2)

"WudfSvc"=3 (0x3)

"TermService"=2 (0x2)

"SysmonLog"=3 (0x3)

"SENS"=2 (0x2)

"Eventlog"=2 (0x2)

"aspnet_state"=3 (0x3)

"NVSvc"=2 (0x2)

"vsmon"=3 (0x3)

"odserv"=3 (0x3)

"Microsoft Office Groove Audit Service"=3 (0x3)

"JavaQuickStarterService"=2 (0x2)

"PnkBstrB"=2 (0x2)

"PnkBstrA"=2 (0x2)

"OpenDNS Updater.exe"=2 (0x2)

"MBAMService"=2 (0x2)

"DynDNS_Updater_Service"=2 (0x2)

"AVP"=2 (0x2)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"PowerBar"=

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\WINDOWS\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"=

"c:\\Arquivos de programas\\DremTeamShare\\DreMule\\emule.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\SopCast\\SopCast.exe"=

"c:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"=

"c:\\WINDOWS\\system32\\tlntsvr.exe"=

"c:\\Arquivos de programas\\Megacubo\\megacubo.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"c:\\Arquivos de programas\\Java\\jre6\\launch4j-tmp\\frd.exe"=

"c:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

 

R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-07-27 11264]

S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]

S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-15 28544]

S1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-04-23 82200]

S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-01-07 44928]

S4 OpenDNS Updater.exe;OpenDNS Updater; [x]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a719a67-79b2-11dc-a5f0-001a9294b946}]

\Shell\AutoRun\command - E:\Launcher.exe

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1390067357-725345543-1003.job

- c:\documents and settings\XP\Configura []

 

2008-08-25 c:\windows\Tasks\User_Feed_Synchronization-{7FE8A15C-7F8C-41DA-822B-85CE77794BB8}.job

- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKLM-Run-SDFix - c:\sdfix\RunThis.bat

 

 

.

------- Scan Suplementar -------

.

uStart Page = about:blank

mStart Page = about:blank

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = *.local

IE: Down&load all by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/202

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {B5B84699-FE8D-45AD-9CB8-26E176466BBF} = 208.67.222.222,208.67.220.220

DPF: Microsoft XML Parser for Java

FF - ProfilePath - c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\

FF - prefs.js: browser.search.selectedEngine - BuscaPé

FF - prefs.js: browser.startup.homepage - hxxp://www.gamevicio.com.br/portal/3/3823/wii/news/12/12886/index.html?pt=Anuncio+da+Engine+de+Cursed+Mountain

FF - prefs.js: network.proxy.type - 4

FF - component: c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-17 09:24:54

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(300)

c:\windows\system32\sfc_os.dll

c:\windows\system32\klogon.dll

c:\windows\system32\COMRes.dll

c:\windows\system32\cscui.dll

.

Tempo para conclusão: 2009-02-17 9:27:12

ComboFix-quarantined-files.txt 2009-02-17 12:27:10

 

Pré-execução: 16 pasta(s) 20,889,763,840 bytes disponíveis

Pós execução: 16 pasta(s) 20,874,784,768 bytes disponíveis

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

314 --- E O F --- 2009-02-11 15:27:56

 

 

é isso no aguardo para novas instruções!!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ha ja ia me esquecendo o do hijack ai vai

 

Logfile of HijackThis v1.99.1

Scan saved at 10:13:57, on 17/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\NetLimiter 2 Pro\NLClient.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\XP\Desktop\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [tspuf] C:\Arquivos de programas\Telefonica\Speedy\SATUF.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [OrderReminder] C:\Arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [DrvIcon] C:\Arquivos de programas\VistaDriveIcon\DrvIcon.exe

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [VisualTaskTips] "C:\Arquivos de programas\VisualTaskTips\VisualTaskTips.exe" noTrayIcon

O4 - HKCU\..\Run: [TrueTransparency] "C:\Arquivos de programas\TrueTransparency\TrueTransparency.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [avp.exe] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKCU\..\RunOnce: [Padrão do Windows] C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/InstallVS:'','Padrão do Windows','Normal'" C:\WINDOWS\system32\themeui.dll

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://127.0.0.1:9070/etc/var/TVUAx.cab

O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.33/g_bin/eng/boards_2_0_0_35.cab

O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192305901765

O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB

O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B84699-FE8D-45AD-9CB8-26E176466BBF}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

E:\Launcher.exe

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"vsmon"=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000000

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a719a67-79b2-11dc-a5f0-001a9294b946}]

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

cfscript.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

fiz o que você falou,criei o scrip,salvei na area de trabalho,mas surgiu um pequeno problema,como disse só consigo executar os programas atravess do menu executar que acesso via crtl+alt+del,depois localizar o exe do programa e depois de selecionado dar ok então sendo assim atraves dessa janela não tem como eu arrastar dentro do kombo fix,tentei fazer e não aconteceu nada ja que só consigo executar algo selecionando e dando ok e não tem como selecionar os 2 ao mesmo tempo,percebi que meu explorer.exe não existe mais,como que se tivesse sido apagado baixei o autorun para ver meus processos e vi que no explorer.exe esta como file missing ia tentar até essa dica

 

http://www.guiadowindows.net/2008/02/como-...windows-xp.html

 

para ver se conseguia recuperar meu explorer,mas não tenho o cd do win xp meu pc veio sem o cd...poxa será mesmo que vou ter que formatar?

Compartilhar este post


Link para o post
Compartilhar em outros sites

me deu uma luz na cabeça percebi atraves de pesquisas via google que varias pessoas que passou por esse problema tinha o kaspersky instalado,resolvi dar uma fuçada nele e na area de quarentena lá estava meu explorer.exe classificado como potencialmente perigoso keylogger pedi para restaurar depois disso fui no executar e digitei explorer dai minha area de trabalho enfim voltou,agora só preciso saber pq meu explorer foi para no anti virus vou passar agora o scrip que você pedi e te mando o log

Compartilhar este post


Link para o post
Compartilhar em outros sites

ai vai o log agora to indo trampa,pelo menos minha area de trabalho voltou o combofix continua dando a msg de zone alarm ativo como residente na memoria tem como apagar esses registros do zone alarm..??

 

 

 

 

ComboFix 09-02-17.02 - XP 2009-02-18 13:15:13.6 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1022.549 [GMT -3:00]

Executando de: c:\documents and settings\XP\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\XP\Desktop\CFScript.txt

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated)

FW: ZoneAlarm Security Suite Firewall *enabled*

* Criado um novo ponto de restauro

 

FILE ::

E:\Launcher.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

E:\Launcher.exe

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-18 to 2009-02-18 ))))))))))))))))))))))))))))

.

 

2009-02-16 07:52 . 2009-02-16 07:52 579,072 --a--c--- c:\windows\system32\dllcache\user32.dll

2009-02-16 07:50 . 2009-02-16 07:51 <DIR> d-------- c:\windows\ERUNT

2009-02-15 20:05 . 2009-02-15 20:05 <DIR> d-------- c:\arquivos de programas\Panda Security

2009-02-15 20:05 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys

2009-02-15 16:52 . 2009-02-15 16:52 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\Codemasters

2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\InstallShield

2009-02-15 15:38 . 2009-02-15 15:38 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\InstallShield

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\windows\system32\AGEIA

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- C:\ProgramData

2009-02-15 15:37 . 2009-02-15 15:37 <DIR> d-------- c:\arquivos de programas\AGEIA Technologies

2009-02-15 15:30 . 2009-02-15 15:30 <DIR> d-------- c:\arquivos de programas\Codemasters

2009-02-15 15:30 . 2007-04-27 11:12 78,784 --a------ c:\windows\system32\ISUSPM.cpl

2009-02-15 10:17 . 2009-02-15 10:17 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\VitySoft

2009-02-15 10:16 . 2009-02-15 14:30 <DIR> d-------- c:\arquivos de programas\FreeRapid-0.81

2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys

2009-02-12 08:40 . 2009-02-12 08:40 22,328 --a------ c:\documents and settings\XP\Dados de aplicativos\PnkBstrK.sys

2009-02-12 08:39 . 2009-02-12 08:39 682,280 --a------ c:\windows\system32\pbsvc.exe

2009-02-12 08:39 . 2009-02-12 08:39 107,832 --a------ c:\windows\system32\PnkBstrB.exe

2009-02-12 08:39 . 2009-02-12 08:39 66,872 --a------ c:\windows\system32\PnkBstrA.exe

2009-02-12 08:24 . 2009-02-12 08:43 <DIR> d-------- c:\documents and settings\XP\Dados de aplicativos\GetRightToGo

2009-02-12 07:50 . 2009-02-12 07:50 <DIR> d-------- c:\windows\Logs

2009-02-12 07:50 . 2008-05-30 13:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll

2009-02-12 07:50 . 2008-05-30 13:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll

2009-02-12 07:50 . 2008-05-30 13:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll

2009-02-12 07:50 . 2008-05-30 13:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll

2009-02-12 07:50 . 2008-05-30 13:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll

2009-02-12 07:50 . 2008-05-30 13:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll

2009-02-12 07:50 . 2008-05-30 13:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll

2009-02-01 16:35 . 2009-02-01 16:35 <DIR> d-------- c:\arquivos de programas\CCleaner

2009-01-26 07:34 . 2009-01-26 07:34 46 --a------ c:\windows\mxcdr.INI

2009-01-25 10:08 . 2009-02-01 21:15 129 --a------ c:\windows\MovieEdit.INI

2009-01-25 10:06 . 2009-01-26 07:38 <DIR> d-------- c:\windows\system32\MAGIX

2009-01-25 09:51 . 2009-01-25 10:07 <DIR> d-------- C:\MAGIX

2009-01-25 09:51 . 2002-09-20 23:33 1,089,536 --a------ c:\windows\system32\ROBOEX32.DLL

2009-01-25 09:51 . 1998-10-15 16:28 85,504 --a------ c:\windows\system32\HtmlWH.dll

2009-01-25 09:51 . 1999-01-28 13:44 49,152 --a------ c:\windows\system32\INETWH32.dll

2009-01-25 09:51 . 2009-01-25 09:57 85 --a------ c:\windows\magix.ini

2009-01-25 09:50 . 2004-06-01 09:53 176,128 --a------ c:\windows\system32\mgxoschk.dll

2009-01-25 09:50 . 2004-06-11 11:19 979 --a------ c:\windows\mgxoschk.ini

2009-01-25 08:31 . 1998-06-17 22:00 102,912 --a------ c:\windows\system32\VB6STKIT.DLL

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-18 16:16 720,928 --sha-w c:\windows\system32\drivers\fidbox2.dat

2009-02-18 16:16 4,053,536 --sha-w c:\windows\system32\drivers\fidbox.dat

2009-02-18 16:16 32,748 --sha-w c:\windows\system32\drivers\fidbox.idx

2009-02-18 16:16 3,544 --sha-w c:\windows\system32\drivers\fidbox2.idx

2009-02-18 16:00 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab

2009-02-16 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2009-02-16 16:11 --------- d-----w c:\arquivos de programas\Spybot - Search & Destroy

2009-02-15 23:24 --------- d-----w c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-02-15 22:19 --------- d-----w c:\arquivos de programas\Orbitdownloader

2009-02-15 18:30 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2009-02-15 18:30 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2009-02-12 10:30 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\uTorrent

2009-02-12 01:16 --------- d-----w c:\arquivos de programas\Megacubo

2009-02-11 15:26 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help

2009-02-11 13:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-11 13:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys

2009-02-10 12:00 33,808 ----a-w c:\windows\system32\drivers\klbg.sys

2009-02-03 18:07 89,601 ----a-w c:\windows\system32\drivers\klick.dat

2009-02-03 18:07 101,287 ----a-w c:\windows\system32\drivers\klin.dat

2009-02-01 16:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard

2009-01-30 11:06 --------- d-----w c:\arquivos de programas\SopCast

2009-01-25 12:45 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-01-16 23:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink

2009-01-16 14:32 --------- d-----w c:\arquivos de programas\WinAVIVideoConverter

2009-01-09 13:27 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Malwarebytes

2009-01-09 13:27 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-08 22:05 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Vso

2009-01-08 14:14 --------- d-----w c:\arquivos de programas\System Explorer

2009-01-07 14:22 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\Kana Solution

2009-01-07 13:23 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\OpenDNS Updater

2009-01-06 15:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TVU Networks

2009-01-03 21:56 --------- d-----w c:\arquivos de programas\UOL

2008-12-25 15:24 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\RealPopup

2008-12-25 12:07 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SystemExplorer

2008-12-23 20:06 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Pure Networks

2008-12-20 23:06 --------- d-----w c:\documents and settings\XP\Dados de aplicativos\UOL

2008-12-20 22:44 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\UOL

2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL

2008-12-20 20:44 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS

2008-12-13 21:39 96,096,280 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_2_2.BIN

2008-12-13 21:30 58,332,708 ----a-w c:\documents and settings\XP\TRACE_BOOT+DRIVERS_1_1.BIN

2008-11-30 14:13 901,120 ----a-w c:\windows\TMUninst.exe

2007-08-28 00:21 94,208 ----a-w c:\documents and settings\XP\Dados de aplicativos\ezplay.sys

2007-08-28 00:21 47,360 ----a-w c:\documents and settings\XP\Dados de aplicativos\pcouffin.sys

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

2008-05-07 15:00 32,768 --sha-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012008050720080508\index.dat

.

 

------- Sigcheck -------

 

2006-04-20 09:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys

2007-10-30 13:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-06-20 08:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

2007-10-30 14:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtServicePackUninstall$\tcpip.sys

2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys

2006-04-20 08:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys

2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys

2008-04-13 16:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\TCPIP.SYS

2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\dllcache\TCPIP.SYS

2008-12-20 17:44 361600 cbeebeb899e31ef52b962cb31fc8ca5c c:\windows\system32\drivers\TCPIP.SYS

 

2004-08-04 00:45 543744 3550bfe59972a67ac2f7781041d28ea7 c:\windows\$NtServicePackUninstall$\winlogon.exe

2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\ServicePackFiles\i386\winlogon.exe

2008-04-13 23:21 549376 b0c0bf2504b830bfc1e93ca39f3c75fe c:\windows\system32\winlogon.exe

2008-04-13 23:21 509952 71d440f79b711627b12b567fb2eadb42 c:\windows\VistaMizer\old\winlogon.exe

 

2008-08-13 20:32 1554432 7b198d92210d9da9d4e0db1e4855b727 c:\windows\explorer.exe

2007-06-13 10:10 1035264 45d521506825a10b80833b4e9621ccf6 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

2007-06-13 10:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 c:\windows\$NtServicePackUninstall$\explorer.exe

2004-08-04 00:45 1552896 9da14fe20c421e7f45dbe3d04b4c4fc9 c:\windows\$NtUninstallKB938828$\explorer.exe

2008-04-13 23:20 1554432 7b198d92210d9da9d4e0db1e4855b727 c:\windows\ServicePackFiles\i386\explorer.exe

2008-04-13 23:20 1035776 064ec7ff5f58b928c3e119402977fa6d c:\windows\VistaMizer\old\explorer.exe

 

2004-08-04 00:45 25088 a3f0971dbba9657034c303b39464ea5b c:\windows\$NtServicePackUninstall$\ctfmon.exe

2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\ServicePackFiles\i386\ctfmon.exe

2008-04-13 23:20 25088 d67945a2290e98bb54d7792f09e7504e c:\windows\system32\ctfmon.exe

2008-04-13 23:20 15360 4e486adfe3a0b9ed0eb0639902e9f64f c:\windows\VistaMizer\old\ctfmon.exe

.

((((((((((((((((((((((((((((( SnapShot@2009-02-17_ 9.25.21.78 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-02-03 18:24:26 312,680 ----a-w c:\windows\Downloaded Program Files\avsniff.dll

+ 2009-02-03 18:24:28 255,336 ----a-w c:\windows\Downloaded Program Files\avsniffdlgs.dll

+ 2009-02-11 04:00:00 2,504 ----a-w c:\windows\Downloaded Program Files\catalog.dat

+ 2009-02-03 18:14:26 42,112 ----a-w c:\windows\Downloaded Program Files\ecmldr32.dll

+ 2009-02-11 04:00:00 259,368 ----a-w c:\windows\Downloaded Program Files\ecmsvr32.dll

+ 2009-02-03 18:14:42 201,896 ----a-w c:\windows\Downloaded Program Files\navapi32.dll

+ 2009-02-11 04:00:00 177,520 ----a-w c:\windows\Downloaded Program Files\naveng32.dll

+ 2009-02-11 04:00:00 1,181,040 ----a-w c:\windows\Downloaded Program Files\navex32a.dll

+ 2009-02-03 18:24:36 296,336 ----a-w c:\windows\Downloaded Program Files\rufsi.dll

+ 2009-02-11 04:00:00 97,776 ----a-w c:\windows\Downloaded Program Files\scrauth.dat

+ 2009-02-11 04:00:00 488,261 ----a-w c:\windows\Downloaded Program Files\tcdefs.dat

+ 2009-02-11 04:00:00 11,046,727 ----a-w c:\windows\Downloaded Program Files\tcscan7.dat

+ 2009-02-11 04:00:00 171,825 ----a-w c:\windows\Downloaded Program Files\tcscan8.dat

+ 2009-02-11 04:00:00 485,395 ----a-w c:\windows\Downloaded Program Files\tcscan9.dat

+ 2009-02-11 04:00:00 1,957 ----a-w c:\windows\Downloaded Program Files\tinfl.dat

+ 2009-02-11 04:00:00 72,567 ----a-w c:\windows\Downloaded Program Files\tscan1.dat

+ 2009-02-11 04:00:00 3,760 ----a-w c:\windows\Downloaded Program Files\tscan1hd.dat

+ 2009-02-11 04:00:00 1,014,111 ----a-w c:\windows\Downloaded Program Files\virscan1.dat

+ 2009-02-11 04:00:00 571,956 ----a-w c:\windows\Downloaded Program Files\virscan2.dat

+ 2009-02-11 04:00:00 153,164 ----a-w c:\windows\Downloaded Program Files\virscan3.dat

+ 2009-02-11 04:00:00 320,259 ----a-w c:\windows\Downloaded Program Files\virscan4.dat

+ 2009-02-11 04:00:00 11,179,842 ----a-w c:\windows\Downloaded Program Files\virscan5.dat

+ 2009-02-11 04:00:00 395,444 ----a-w c:\windows\Downloaded Program Files\virscan6.dat

+ 2009-02-11 04:00:00 35,658,217 ----a-w c:\windows\Downloaded Program Files\virscan7.dat

+ 2009-02-11 04:00:00 1,068,862 ----a-w c:\windows\Downloaded Program Files\virscan8.dat

+ 2009-02-11 04:00:00 3,660,672 ----a-w c:\windows\Downloaded Program Files\virscan9.dat

+ 2009-02-17 14:26:12 2,072 ----a-w c:\windows\Downloaded Program Files\vscanmsx.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 25088]

"VisualTaskTips"="c:\arquivos de programas\VisualTaskTips\VisualTaskTips.exe" [2008-05-31 65536]

"TrueTransparency"="c:\arquivos de programas\TrueTransparency\TrueTransparency.exe" [2008-05-27 371200]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Google Update"="c:\documents and settings\XP\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2008-12-25 133104]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]

"avp.exe"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 201992]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"tspuf"="c:\arquivos de programas\Telefonica\Speedy\SATUF.exe" [2003-06-16 24576]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-08-03 144792]

"OrderReminder"="c:\arquivos de programas\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13574144]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

"Malwarebytes' Anti-Malware"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"DrvIcon"="c:\arquivos de programas\VistaDriveIcon\DrvIcon.exe" [2008-04-13 49152]

"DAEMON Tools"="c:\arquivos de programas\DAEMON Tools\daemon.exe" [2008-02-02 128920]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 196096]

"nwiz"="nwiz.exe" [2008-08-23 c:\windows\system32\nwiz.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.l3fhg"= mp3fhg.acm

"msacm.divxa32"= divxa32.acm

"VIDC.X264"= x264vfw.dll

"VIDC.HFYU"= huffyuv.dll

"vidc.i263"= i263_32.drv

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Orbit.lnk]

backup=c:\windows\pss\Orbit.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Styler.lnk]

backup=c:\windows\pss\Styler.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^VisualTaskTips.lnk]

backup=c:\windows\pss\VisualTaskTips.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^WinZip Quick Pick.lnk]

backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration .LNK]

backup=c:\windows\pss\Registration .LNKStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Registration Myst V]

backup=c:\windows\pss\Registration Myst VStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Sidebar.lnk]

backup=c:\windows\pss\Thoosje Sidebar.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^Thoosje Vista Sidebar.lnk]

backup=c:\windows\pss\Thoosje Vista Sidebar.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^XP^Menu Iniciar^Programas^Inicializar^UOL Voip.lnk]

backup=c:\windows\pss\UOL Voip.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"aawservice"=2 (0x2)

"NBService"=3 (0x3)

"StarWindServiceAE"=2 (0x2)

"MDM"=2 (0x2)

"WMPNetworkSvc"=2 (0x2)

"usnjsvc"=2 (0x2)

"FLEXnet Licensing Service"=3 (0x3)

"AdobeActiveFileMonitor6.0"=2 (0x2)

"WLSetupSvc"=3 (0x3)

"WinDefend"=2 (0x2)

"WudfSvc"=3 (0x3)

"TermService"=2 (0x2)

"SysmonLog"=3 (0x3)

"SENS"=2 (0x2)

"Eventlog"=2 (0x2)

"aspnet_state"=3 (0x3)

"NVSvc"=2 (0x2)

"odserv"=3 (0x3)

"Microsoft Office Groove Audit Service"=3 (0x3)

"JavaQuickStarterService"=2 (0x2)

"PnkBstrB"=2 (0x2)

"PnkBstrA"=2 (0x2)

"OpenDNS Updater.exe"=2 (0x2)

"MBAMService"=2 (0x2)

"DynDNS_Updater_Service"=2 (0x2)

"AVP"=2 (0x2)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"PowerBar"=

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\WINDOWS\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"=

"c:\\Arquivos de programas\\DremTeamShare\\DreMule\\emule.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\SopCast\\SopCast.exe"=

"c:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"=

"c:\\WINDOWS\\system32\\tlntsvr.exe"=

"c:\\Arquivos de programas\\Megacubo\\megacubo.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"c:\\Arquivos de programas\\Java\\jre6\\launch4j-tmp\\frd.exe"=

"c:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 2009\\avp.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

 

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-15 28544]

R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-07-27 11264]

R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-04-23 82200]

S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [2008-01-07 44928]

S4 OpenDNS Updater.exe;OpenDNS Updater; [x]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-1390067357-725345543-1003.job

- c:\documents and settings\XP\Configura []

 

2008-08-25 c:\windows\Tasks\User_Feed_Synchronization-{7FE8A15C-7F8C-41DA-822B-85CE77794BB8}.job

- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]

.

.

------- Scan Suplementar -------

.

uStart Page = about:blank

mStart Page = about:blank

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = *.local

IE: Down&load all by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/202

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {B5B84699-FE8D-45AD-9CB8-26E176466BBF} = 208.67.222.222,208.67.220.220

DPF: Microsoft XML Parser for Java

FF - ProfilePath - c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\

FF - prefs.js: browser.search.selectedEngine - BuscaPé

FF - prefs.js: browser.startup.homepage - hxxp://www.gamevicio.com.br/portal/3/3823/wii/news/12/12886/index.html?pt=Anuncio+da+Engine+de+Cursed+Mountain

FF - prefs.js: network.proxy.type - 4

FF - component: c:\documents and settings\XP\Dados de aplicativos\Mozilla\Firefox\Profiles\e3opz2do.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-18 13:18:52

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(908)

c:\windows\system32\sfc_os.dll

c:\windows\system32\klogon.dll

c:\windows\system32\COMRes.dll

c:\windows\system32\cscui.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\netdde.exe

c:\windows\system32\clipsrv.exe

c:\arquivos de programas\NetLimiter 2 Pro\nlsvc.exe

c:\arquivos de programas\NetLimiter 2 Pro\NLClient.exe

c:\windows\system32\rundll32.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-02-18 13:22:06 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-02-18 16:22:03

ComboFix2.txt 2009-02-18 15:49:36

ComboFix3.txt 2009-02-18 15:30:13

ComboFix4.txt 2009-02-17 12:28:27

 

Pré-execução: 16 pasta(s) 20.636.733.440 bytes disponíveis

Pós execução: 16 pasta(s) 20,619,100,160 bytes disponíveis

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

345 --- E O F --- 2009-02-11 15:27:56

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá siga minhas instruções na seqüencia para não ocorrer confusão na análise.

 

1)

 

• Vá a este Link,e baixe: < Malwarebytes >

Atualize o programa!

• Escolha o escaneamento Rápido!

Desabilite programas de proteção,ao executar o malwarebytes.

• Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

• Para maiores detalhes: < Link >

 

2)

 

Com o navegador Internet Explorer, acesse o Kaspersky Online Scanner e faça um scan online seguindo o tutorial abaixo.

 

Tutorial Kaspersky Online Scanner

 

Ao término do scan, salve o relatório com a extensão .txt (como mostra no final do tutorial) e poste em sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

bom vamos a respostas

o Malwarebytes eu ja tinha instalado no meu pc,passei e não encontrou nada

o scan on line comecei por 2 vezes e no meio da atualização deu uma tela azul com um monte de informação e no final possivelmente causado por KIif.sys

minha area de trabalho voltou,mas os atalhos para meu computador e minhas pastas não funcionando meu computador só joguei novamente o atalho do menu iniciar para a area de trabalho,mas as minhas pastas ja apaguei os atalhos velhos e criei novos e não adiantou nada,sempre da a mesma msg este arquivo não tem um programa associado a ele para realizar essa ação,crie uma associação no painel de controle "opções de pasta" só nos atalhos das pastas que até agora vi dar isso tentei craiar associação não consegui não sei ao certo como fazer,criei uma nova associação com a extensão LNK para shortcuts mas não hablita a opção aplicar,então não muda nada,mas minha area de trabalho voltou até agora não voltei a habilitar as proteções do meu anti virus,amanha vou tentar voltar pra ver no que vai dar...alguma sugestão?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Faça um scan online com o bitdefender como mostra nesse tutorial

Compartilhar este post


Link para o post
Compartilhar em outros sites

desculpe pela demora para responder,estava ausente,passei o anti virus conforme você pediu,deixei passando,encontrou alguma coisa,mas infelizmente o log nem eu vi,minha esposa sem saber fechou tudo,mas meu pc agora ta realmente como era antes,os problemas de atalhos resolvido com um restaurar o sistema para um semana atras,realmente meu problema era um bug do anti virus veja

 

http://www.webtuga.com/kaspersky-classific...exe-como-virus/

Compartilhar este post


Link para o post
Compartilhar em outros sites

ok, podemos considerar o problema como resolvido?

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.