Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

cicerod2

[Arquivado] Problemas com a Janela do internet explorer "CiD&

Recommended Posts

galera me ajudem por favor, toda vez que eu inicio o internet explorer abre uma janela tipo pop up com prppragandas, no titulo da janela vem assim "CiD....." ja li em outros post que isso é um maleware e gostaria que você me ajudassem a exterminar essa praga do meu pc.

 

vai ai o log do HijackThis

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 09:28:57, on 16/11/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Drivers\trcboot.exe

C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\C4ebreg\c4ebreg.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\notes\ntmulti.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Drivers\ldlcserv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IBM\Personal Communications\tpam.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe

C:\Program Files\C4ebreg\isamtray.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\DAP\DAP.EXE

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\New Folder\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll

O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll

O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)

O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup

O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe

O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q

O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe"

O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [searchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe

O4 - HKLM\..\Run: [fast city ping help] C:\Documents and Settings\All Users\Application Data\long extra fast city\inside media.exe

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - Global Startup: Lotus QuickStart.lnk = ?

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O11 - Options group: [JAVA_IBM] Java (IBM)

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000

O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba

O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe

O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe

O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing)

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe

 

--

End of file - 12217 bytes

 

aguardo respostas

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Olá Cicero! Seja bem-vindo ao Fórum Imasters.

 

Siga estes procedimentos abaixo nesta seqüência em que eles estão:

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download de ToolBar S&D

*Salve-o no desktop (área de trabalho).

*Reinicie o PC em Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança).

*Execute o programa, e à seguir, aperte o "p" --> Enter --> Ok.

*Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde!

*Terminando, o relatório estará em C:\ToolBar SD\TB_1.txt

__________________________________

 

:seta: Vá no menu: Iniciar > Painel de Controle > Adicionar ou remover programas > Procure por este programa destacado abaixo e o desinstale:

 

pdfforge Toolbar

__________________________________

 

:seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho):

http://swandog46.geekstogo.com/avenger2/download.php

 

*Selecione e copie (Ctrl+C) todo o texto dentro do Quote (caixa branca) abaixo:

 

Folders to delete:

C:\Program Files\pdfforge Toolbar

 

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*O relatório será criado em C:\avenger.txt

_____________________________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll

 

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

 

O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll

 

O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll

 

O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)

 

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

 

O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll

 

O4 - HKLM\..\Run: [searchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe

_____________________________________

 

:seta: Faça o download do Lop S&D no endereço abaixo:

http://eric.71.mespages.googlepages.com/LopSD.exe

# Temporariamente desative seus programas de proteção (Antivirus, etc.) para não interferirem com a ferramenta.

# Dê um Duplo-Clique com o botão esquerdo do mouse no ícone do Lop S&D que estará no desktop (área de trabalho).

Se utiliza o Windows Vista, dê clique direito do mouse no LopSD.exe e escolha 'Executar como administrador'.

# Irá surgir uma janela, tecle P de Português e dê enter.

# Pressione agora o numero "2 - Remocao + Hosts" pressionando a tecla "2" e dê ENTER.

# A ferramenta irá rodar para que a infecção possa ser removida.

# No final será gerado um log que estará em C:\lopR.txt

_____________________________________

 

:seta: Faça o download desta ferramenta abaixo:

http://lop.com/new_uninstall.exe

 

Obs: Note que este desinstalador é detectado como trojan por diversos antivírus. Se isso acontecer, desabilite temporariamente o seu antivírus e volte a ativá-lo quando terminar o procedimento. O arquivo é perfeitamente seguro.

 

Dê um duplo clique neste desinstalador que você baixou acima > Clique em Ok > Clique em Ok novamente > aparecerão alguns números em uma tela, digite estes números no campo em branco e depois disto clique no botão UNINSTALL > clique em Ok > clique em Ok novamente >aí é só ir seguindo os passos que este desinstalador vai te passando.

_____________________________________

 

:seta: Siga também, por gentileza, as dicas deste tutorial para fazer uma limpeza de seu PC com o Malwarebytes:

 

'>http://dicasetutoriaisparapc.blogspot.com/2009/10/tutorial-do-malwarebytes-anti-malware.html"]Tutorial do Malwarebytes Anti-Malware

 

Na sua próxima resposta poste este log do Malwarebytes juntamente com o log que estará em C:\lopR.txt, o log que estará em C:\avenger.txt, o log que estará em C:\ToolBar SD\TB_1.txt e um novo log do Hijackthis e nos diga como está o seu PC após estes procedimentos.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá antonio, muito obrigado pela atenção:

 

fiz todos os procedimentos recomendados e seguem os logs abaixo;

 

log lopR

 

 

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2

X86-based PC ( Multiprocessor Free : Intel® Core2 Duo CPU E6550 @ 2.33GHz )

BIOS : Lenovo ThinkCentre BIOS Ver 2RKT44.0

USER : administrador ( Administrator )

BOOT : Normal boot

Antivirus : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 (Activated)

C:\ (Local Disk) - NTFS - Total:149 Go (Free:124 Go)

D:\ (CD or DVD)

E:\ (CD or DVD)

 

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )

Option : [2] ( seg 16/11/2009|13:02 )

 

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS

 

-

[ Arquivos/Ficheiros Hosts ] .. RESTAURADO

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

--------------------\\ Lista de pastas em APPLIC~1

 

[02/04/2007|19:20] C:\DOCUME~1\ADMINI~2\APPLIC~1\Adobe

[12/04/2006|00:08] C:\DOCUME~1\ADMINI~2\APPLIC~1\AdobeUM

[23/01/2006|22:47] C:\DOCUME~1\ADMINI~2\APPLIC~1\Help

[22/02/2007|20:55] C:\DOCUME~1\ADMINI~2\APPLIC~1\IBM

[04/04/2005|15:44] C:\DOCUME~1\ADMINI~2\APPLIC~1\Identities

[11/04/2006|23:22] C:\DOCUME~1\ADMINI~2\APPLIC~1\Macromedia

[01/04/2009|16:56] C:\DOCUME~1\ADMINI~2\APPLIC~1\Microsoft

[01/04/2009|16:52] C:\DOCUME~1\ADMINI~2\APPLIC~1\Sun

 

[27/04/2009|10:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe

[12/04/2006|00:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM

[23/01/2006|22:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help

[22/02/2007|20:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\IBM

[04/04/2005|15:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities

[11/04/2006|23:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia

[10/10/2007|13:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[27/04/2009|10:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Orbit

[27/04/2009|10:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real

[01/04/2009|15:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun

 

[13/11/2009|15:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe

[05/11/2009|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg9

[03/11/2009|09:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DAEMON Tools Lite

[11/11/2009|14:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet

[07/08/2009|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard

[07/08/2009|18:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP

[05/04/2005|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IBM

[20/02/2007|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IGS

[30/07/2009|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft

[09/04/2009|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help

[20/10/2009|14:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS

[20/04/2009|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real

[12/05/2009|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony

[29/07/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpeedBit

[01/04/2009|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec

[16/11/2009|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP

[30/07/2009|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ubisoft

[07/08/2009|18:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WEBREG

[18/08/2005|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[02/07/2009|11:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

[13/08/2009|10:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[06/08/2009|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

 

[20/04/2009|16:34] C:\DOCUME~1\carolina\APPLIC~1\Adobe

[20/04/2009|16:34] C:\DOCUME~1\carolina\APPLIC~1\Macromedia

 

[08/07/2009|15:03] C:\DOCUME~1\cicero\APPLIC~1\Adobe

[10/07/2009|12:34] C:\DOCUME~1\cicero\APPLIC~1\Macromedia

[27/10/2009|13:05] C:\DOCUME~1\cicero\APPLIC~1\pdfforge

 

[02/04/2007|19:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe

[12/04/2006|00:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AdobeUM

[23/01/2006|22:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Help

[22/02/2007|20:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\IBM

[04/04/2005|15:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities

[11/04/2006|23:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia

[10/10/2007|13:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

 

 

[04/04/2005|15:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[30/04/2009|18:47] C:\DOCUME~1\LOCALS~1\APPLIC~1\Softland

 

[04/04/2005|15:44] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

 

[17/02/2009|16:14] C:\DOCUME~1\renata\APPLIC~1\Microsoft

 

--------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks

 

[16/11/2009 12:24][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[16/11/2009 12:51][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[16/11/2009 12:50][--ah-----] C:\WINDOWS\tasks\SA.DAT

[04/08/2004 03:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

 

--------------------\\ Lista de pastas em C:\Program Files

 

[30/10/2009|17:54] C:\Program Files\Adobe

[05/04/2005|18:13] C:\Program Files\AFP Workbench 32

[01/04/2009|16:50] C:\Program Files\Ahead

[05/11/2009|10:47] C:\Program Files\Alwil Software

[28/11/2007|20:51] C:\Program Files\Analog Devices

[02/04/2009|10:21] C:\Program Files\Arquivos Comuns

[28/11/2007|20:59] C:\Program Files\AT&T Network Client Install

[26/05/2009|18:43] C:\Program Files\Audacity 1.3 Beta (Unicode)

[05/11/2009|09:57] C:\Program Files\AVG

[16/11/2009|12:50] C:\Program Files\C4ebreg

[18/08/2009|11:34] C:\Program Files\CC PDF Converter

[02/04/2009|10:40] C:\Program Files\CCleaner

[03/11/2009|13:37] C:\Program Files\Common Files

[04/04/2005|15:41] C:\Program Files\ComPlus Applications

[03/09/2009|16:05] C:\Program Files\Correios

[09/04/2009|12:12] C:\Program Files\Crystal Decisions

[04/11/2009|08:52] C:\Program Files\DAEMON Tools Lite

[20/10/2009|09:31] C:\Program Files\DAP

[02/04/2009|11:02] C:\Program Files\Edutec Sistemas

[28/10/2009|17:15] C:\Program Files\Eidos

[28/10/2009|16:25] C:\Program Files\Elaborate Bytes

[17/09/2009|11:26] C:\Program Files\ElcomSoft

[01/07/2009|17:42] C:\Program Files\Eltima Software

[02/04/2009|10:22] C:\Program Files\Firebird

[05/11/2009|10:35] C:\Program Files\Gabest

[11/11/2009|18:09] C:\Program Files\Google

[04/04/2005|16:07] C:\Program Files\HighMAT CD Writing Wizard

[01/04/2009|08:45] C:\Program Files\IBM

[07/08/2006|21:23] C:\Program Files\IBM Ayudame

[29/11/2007|13:54] C:\Program Files\IBM DLA

[29/10/2009|12:16] C:\Program Files\InstallShield Installation Information

[13/11/2009|17:08] C:\Program Files\Internet Explorer

[29/11/2007|13:55] C:\Program Files\InterVideo

[01/04/2009|16:01] C:\Program Files\Java

[10/11/2009|13:20] C:\Program Files\K-Lite Codec Pack

[10/09/2009|11:56] C:\Program Files\Koinonia Software

[26/05/2009|18:50] C:\Program Files\Lame for Audacity

[04/11/2009|08:54] C:\Program Files\LogMeIn Hamachi

[05/09/2007|18:13] C:\Program Files\Microsoft CAPICOM 2.1.0.2

[04/04/2005|15:44] C:\Program Files\microsoft frontpage

[16/09/2009|11:45] C:\Program Files\Microsoft Office

[09/09/2009|18:11] C:\Program Files\Microsoft Silverlight

[12/05/2009|17:25] C:\Program Files\Microsoft SQL Server

[01/04/2009|16:50] C:\Program Files\Microsoft Visual Studio

[01/04/2009|16:50] C:\Program Files\Microsoft Works

[01/04/2009|16:49] C:\Program Files\Microsoft.NET

[04/04/2005|15:42] C:\Program Files\Movie Maker

[03/04/2009|16:40] C:\Program Files\MP3Gain

[19/02/2007|22:39] C:\Program Files\MSBuild

[16/09/2009|11:44] C:\Program Files\MSECache

[04/04/2005|15:40] C:\Program Files\MSN

[04/04/2005|15:40] C:\Program Files\MSN Gaming Zone

[05/09/2007|18:11] C:\Program Files\MSXML 4.0

[05/09/2007|17:32] C:\Program Files\MSXML 6.0

[04/04/2005|15:42] C:\Program Files\NetMeeting

[04/04/2005|15:41] C:\Program Files\Online Services

[05/09/2007|17:26] C:\Program Files\Outlook Express

[27/10/2009|11:57] C:\Program Files\PDFCreator

[09/07/2009|16:03] C:\Program Files\PhotoFiltre Studio X

[16/11/2009|10:12] C:\Program Files\PhotoZoom Pro 3

[20/04/2009|17:25] C:\Program Files\Real Alternative

[19/02/2007|22:35] C:\Program Files\Reference Assemblies

[02/04/2009|10:21] C:\Program Files\Report Designer Component

[29/11/2007|13:56] C:\Program Files\Roxio

[01/07/2009|13:57] C:\Program Files\Seagate Software

[27/04/2009|15:17] C:\Program Files\Smallvideosoft

[02/08/2005|13:41] C:\Program Files\Snapshot Viewer

[30/04/2009|18:46] C:\Program Files\Softland

[13/05/2009|14:23] C:\Program Files\Sony

[13/05/2009|14:22] C:\Program Files\Sony Setup

[01/04/2009|16:01] C:\Program Files\Sun

[07/05/2009|13:00] C:\Program Files\Symantec Client Security

[05/04/2005|18:04] C:\Program Files\Tivoli

[23/10/2009|12:10] C:\Program Files\UltraVNC

[12/05/2009|17:25] C:\Program Files\Uninstall Information

[12/11/2009|16:33] C:\Program Files\URUSoft

[12/05/2009|17:24] C:\Program Files\Vstplugins

[22/09/2009|14:44] C:\Program Files\Webteh

[28/11/2007|20:56] C:\Program Files\wecminst

[04/04/2005|16:06] C:\Program Files\Windows Journal Viewer

[25/05/2009|14:49] C:\Program Files\Windows Media Player

[04/04/2005|15:40] C:\Program Files\Windows NT

[04/04/2005|15:43] C:\Program Files\WindowsUpdate

[01/04/2009|15:58] C:\Program Files\WinRAR

[01/04/2009|14:59] C:\Program Files\WST

[04/04/2005|15:44] C:\Program Files\xerox

 

--------------------\\ Lista de pastas em C:\Program Files\Common Files

 

[11/11/2009|16:42] C:\Program Files\Common Files\Adobe

[01/04/2009|16:50] C:\Program Files\Common Files\Ahead

[10/09/2009|12:01] C:\Program Files\Common Files\Borland Shared

[02/04/2009|10:20] C:\Program Files\Common Files\Crystal Decisions

[01/04/2009|16:50] C:\Program Files\Common Files\DESIGNER

[16/11/2009|09:38] C:\Program Files\Common Files\Edutec Sistemas

[07/08/2009|18:01] C:\Program Files\Common Files\Hewlett-Packard

[01/04/2009|08:45] C:\Program Files\Common Files\InstallShield

[01/04/2009|15:58] C:\Program Files\Common Files\Java

[30/10/2009|17:53] C:\Program Files\Common Files\Macrovision Shared

[09/04/2009|12:12] C:\Program Files\Common Files\Merge Modules

[05/11/2009|09:56] C:\Program Files\Common Files\Microsoft Shared

[04/04/2005|15:42] C:\Program Files\Common Files\MSSoap

[10/10/2007|13:31] C:\Program Files\Common Files\My Help

[04/04/2005|16:36] C:\Program Files\Common Files\ODBC

[10/09/2009|11:56] C:\Program Files\Common Files\Opus Shared

[28/04/2009|13:16] C:\Program Files\Common Files\SafeNet Sentinel

[04/04/2005|15:42] C:\Program Files\Common Files\Services

[29/11/2007|13:57] C:\Program Files\Common Files\Sonic Shared

[04/04/2005|16:36] C:\Program Files\Common Files\SpeechEngines

[01/04/2009|15:14] C:\Program Files\Common Files\Symantec Shared

[01/04/2009|16:50] C:\Program Files\Common Files\System

[03/04/2009|16:21] C:\Program Files\Common Files\Windows Live

 

--------------------\\ Process

 

( 57 Processes )

 

... OK !

 

--------------------\\ Procura pelo S_Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura no Registro

 

..... OK !

 

--------------------\\ Verificando o Arquivos/Ficheiros Hosts

 

Arquivos/Ficheiros Hosts LIMPO

 

 

--------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-11-16 13:03:37

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden files ...

folder error: C:\WINDOWS\System32\

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

[F:31][D:8]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

[F:16][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies

[F:514][D:5]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

 

1 - "C:\Lop SD\LopR_1.txt" - seg 16/11/2009|13:03 - Option : [2]

 

--------------------\\ Verificação completa em 13:03:49

 

log avanger

 

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

 

Platform: Windows XP (build 2600, Service Pack 2)

Mon Nov 16 11:53:27 2009

 

11:53:27: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

 

 

//////////////////////////////////////////

 

 

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

 

Platform: Windows XP (build 2600, Service Pack 2)

Mon Nov 16 11:55:05 2009

 

11:55:05: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

 

 

//////////////////////////////////////////

 

 

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

 

Completed script processing.

 

*******************

 

Finished! Terminate.

 

log malwarebytes

 

Malwarebytes' Anti-Malware 1.41

Versão do banco de dados: 3178

Windows 5.1.2600 Service Pack 2

 

16/11/09 13:41:19

mbam-log-2009-11-16 (13-41-19).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 221598

Tempo decorrido: 36 minute(s), 54 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 1

Valores do Registro infectados: 0

Ítens do Registro infectados: 3

Pastas infectadas: 0

Arquivos infectados: 2

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\glaide32 (Rootkit.Rustock) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

C:\Documents and Settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\OGKernel.dll (Malware.Packer.Morphine) -> Quarantined and deleted successfully.

 

log Toolbar S&D

 

 

-----------\\ ToolBar S&D 1.2.9 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2

X86-based PC ( Multiprocessor Free : Intel® Core2 Duo CPU E6550 @ 2.33GHz )

BIOS : Lenovo ThinkCentre BIOS Ver 2RKT44.0

USER : administrador ( Administrator )

BOOT : Fail-safe boot

Antivirus : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 (Not Activated)

C:\ (Local Disk) - NTFS - Total:149 Go (Free:124 Go)

D:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )

Option : [2] ( seg 16/11/2009|12:45 )

 

-----------\\ REMOVIDOS

 

Deletado! - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll

Deletado! - C:\Program Files\DAEMON Tools Toolbar\Resources

Deletado! - C:\Program Files\DAEMON Tools Toolbar\uninst.exe

Deletado! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml

Deletado! - C:\DOCUME~1\cicero\APPLIC~1\Search Settings\kb128

Deletado! - C:\Program Files\DAEMON Tools Toolbar

Deletado! - C:\DOCUME~1\cicero\APPLIC~1\Search Settings

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://w3.ibm.com/"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

"Url"="http://go.microsoft.com/fwlink/?LinkId=68929"

"Url"="http://go.microsoft.com/fwlink/?LinkId=68928"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

 

1 - "C:\ToolBar SD\TB_1.txt" - seg 16/11/2009|12:46 - Option : [2]

 

-----------\\ Verificação completa em 12:46:56,21

 

log hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:00:50, on 16/11/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Drivers\trcboot.exe

C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\C4ebreg\c4ebreg.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\notes\ntmulti.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Drivers\ldlcserv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

C:\Program Files\IBM\Personal Communications\tpam.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe

C:\Program Files\C4ebreg\isamtray.exe

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\CTFMON.EXE

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BDGQDFPC\HiJackThis[1].exe

C:\Program Files\IBM\My Help\MyHelp.exe

C:\Program Files\IBM\My Help\jre\bin\myhelpw.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w3.ibm.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup

O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe

O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q

O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe"

O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: Lotus QuickStart.lnk = ?

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O11 - Options group: [JAVA_IBM] Java (IBM)

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000

O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba

O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe

O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe

O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing)

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe

 

--

End of file - 10179 bytes

 

 

 

Antonio, mais uma vez muito obrigado pela ajuda e espero que tenha conseguido me livrar dessa praga. grande abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Vários problemas foram removidos do seu PC.

______________________________

 

:!: Houve um erro na hora de criar o script do Avenger. Para se certificar de que aquela pasta foi realmente removida, vá no menu: Iniciar > Todos os programas > Acessórios > Windows Explorer > Procure por esta pasta em vermelho abaixo e a exclua (se ela ainda existir):

 

C:\Program Files\pdfforge Toolbar

______________________________

 

:seta: Siga as dicas destes tutoriais:

 

Tutorial do Panda Anti-RootKit

 

Tutorial do Sophos Anti-RootKit

______________________________

 

:seta: Depois disto siga, por gentileza, esta dica para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento e se foi removido algum problema pelo Panda Anti-RootKit e pelo Sophos Anti-RootKit. Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá antonio

 

seguem os logs

 

log online scanner

 

 

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=32d5c757b4f8bb488c03e63f9f1994ec

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2009-11-16 06:06:09

# local_time=2009-11-16 04:06:09 (-0300, E. South America Daylight Time)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=769 16775141 100 98 0 193759624 0 0

# compatibility_mode=1024 16777215 100 0 49042 49042 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=57921

# found=1

# cleaned=1

# scan_time=1899

C:\Documents and Settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe a variant of Win32/Adware.ADON application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

 

log hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:13:13, on 16/11/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Drivers\trcboot.exe

C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\C4ebreg\c4ebreg.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\notes\ntmulti.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Drivers\ldlcserv.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IBM\Personal Communications\tpam.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe

C:\Program Files\C4ebreg\isamtray.exe

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\DAP\DAP.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup

O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe

O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q

O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe"

O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - Global Startup: Lotus QuickStart.lnk = ?

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O11 - Options group: [JAVA_IBM] Java (IBM)

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba

O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe

O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe

O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing)

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe

 

--

End of file - 11270 bytes

 

 

até agora o meu pc voltou a funcionar normalmente sem as janelas do "CiD". Espero que tenha conseguido resolver todos os problemas.

 

valeu, um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Mais um adware foi removido pelo Nod32 Online.

________________________________

 

:seta: Você executou o Panda Anti-RootKit e Sophos Anti-RootKit? Caso não tenha executado, execute-os por gentileza. Caso já tenha executado, eles detectaram e removeram algum problema?

________________________________

 

:seta: Você observou se esta pasta abaixo ainda existe e a excluiu caso ela exista?

C:\Program Files\pdfforge Toolbar

________________________________

 

:seta: Siga, por gentileza as dicas deste tutorial para fazer uma limpeza de seu PC com o Spyware Doctor:

 

Tutorial do Spyware Doctor Starter Edition

 

Na sua próxima resposta poste este log do Spyware Doctor juntamente com um novo log do Hijackthis e nos diga como está o seu Pc depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá antonio.

 

ontem eu executei o Panda Anti-RootKit e Sophos Anti-RootKit e eles não encontraram nada, e também observei que a pasta C:\Program Files\pdfforge Toolbar havia sido excluida.

 

vou postar agora o log do hijackthis

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:27:41, on 17/11/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Drivers\trcboot.exe

C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\C4ebreg\c4ebreg.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\notes\ntmulti.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Drivers\ldlcserv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IBM\Personal Communications\tpam.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe

C:\Program Files\C4ebreg\isamtray.exe

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\DAP\DAP.EXE

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\InterADE\interade.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup

O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe

O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q

O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe"

O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - Global Startup: Lotus QuickStart.lnk = ?

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O11 - Options group: [JAVA_IBM] Java (IBM)

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba

O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe

O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe

O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing)

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe

 

--

End of file - 12029 bytes

 

 

e o historico do PC Tools Spyware Doctor

 

PC Tools Spyware Doctor

Date Status

17/11/2009 11:46:20:35 Serviço Iniciado

Aplicações de Serviço do Spyware Doctor iniciadas

17/11/2009 11:46:20:35 Mecanismo Antimalware

Configuração do mecanismo antimalware carregada com sucesso.

17/11/2009 11:46:27:51 Verificação Iniciada

Tipo de Verificação - Intelli-Scan

 

17/11/2009 11:46:27:832 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ad.adnetwork.com.br/ ad.adnetwork.com.br

 

17/11/2009 11:46:27:832 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ad.yieldmanager.com/ ad.yieldmanager.com

 

17/11/2009 11:46:27:941 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 11:46:28:35 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - content.yieldmanager.com/ content.yieldmanager.com

 

17/11/2009 11:46:28:35 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - content.yieldmanager.com/ content.yieldmanager.com

 

17/11/2009 11:46:28:98 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ehg-fifa.hitbox.com/ ehg-fifa.hitbox.com

 

17/11/2009 11:46:28:191 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - forum.imasters.com.br/ forum.imasters.com.br

 

17/11/2009 11:46:28:395 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - hitbox.com/ hitbox.com

 

17/11/2009 11:46:28:457 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - imasters.com.br/ imasters.com.br

 

17/11/2009 11:46:28:754 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - quantserve.com/ quantserve.com

 

17/11/2009 11:46:28:926 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - uol.com.br/ uol.com.br

 

17/11/2009 11:46:29:207 Detectada uma infecção neste computador

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - zedo.com/ zedo.com

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol

 

17/11/2009 11:46:41:957 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore

 

17/11/2009 11:46:41:973 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Chave de Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty

 

17/11/2009 11:46:53:566 Status do IntelliGuard

Todos os IntelliGuards foram Ativados

17/11/2009 11:46:58:410 Resultados do Immunizer

A seção do ActiveX foi imunizada. Itens 5055 processados.

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden

 

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden

 

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:48:18:145 Detectada uma infecção neste computador

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:48:18:160 Verificação Concluída

Tipo de Verificação - Intelli-Scan

Itens Processados - 295267

Ameaças Detectadas - 3

Infecções Detectadas - 30

Infecções Ignoradas - 0

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - zedo.com/ zedo.com

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - uol.com.br/ uol.com.br

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - quantserve.com/ quantserve.com

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - imasters.com.br/ imasters.com.br

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - hitbox.com/ hitbox.com

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - forum.imasters.com.br/ forum.imasters.com.br

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ehg-fifa.hitbox.com/ ehg-fifa.hitbox.com

 

17/11/2009 11:49:13:457 Infecção excluída

Nome da Ameaça - Application.TrackingCookies

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ad.adnetwork.com.br/ ad.adnetwork.com.br

 

17/11/2009 11:49:13:504 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - content.yieldmanager.com/ content.yieldmanager.com

 

17/11/2009 11:49:13:504 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - content.yieldmanager.com/ content.yieldmanager.com

 

17/11/2009 11:49:13:504 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 11:49:13:504 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - ad.yieldmanager.com/ ad.yieldmanager.com

 

17/11/2009 11:49:13:551 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:551 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:551 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:551 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Chave de Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1

 

17/11/2009 11:49:13:566 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg

 

17/11/2009 11:49:13:582 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1

 

17/11/2009 11:49:13:598 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem

 

17/11/2009 11:49:13:598 Infecção em quarentena

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop

 

17/11/2009 11:49:13:676 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor de Registro Modificado

Nível de Risco - Alto

Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Chave de Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem

 

17/11/2009 11:49:13:691 Infecção excluída

Nome da Ameaça - Trojan.Autoit

Tipo - Valor do Registro

Nível de Risco - Alto

Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop

 

17/11/2009 11:49:15:723 Resumo de Infecções em Quarentena/Removidas

Quarentena - 18

Falha na Quarentena - 0

Removido - 30

Falha na Remoção - 0

 

17/11/2009 11:50:57:973 Verificação Iniciada

Tipo de Verificação - Intelli-Scan

 

17/11/2009 11:50:58:723 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 11:52:17:676 Verificação Concluída

Tipo de Verificação - Intelli-Scan

Itens Processados - 295377

Ameaças Detectadas - 1

Infecções Detectadas - 1

Infecções Ignoradas - 0

 

17/11/2009 11:52:23:660 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 11:52:25:691 Resumo de Infecções em Quarentena/Removidas

Quarentena - 0

Falha na Quarentena - 0

Removido - 1

Falha na Remoção - 0

 

17/11/2009 11:52:33:988 Verificação Iniciada

Tipo de Verificação - Verificação Completa

 

17/11/2009 11:58:13:926 Smart Update

O Smart Update determinou que o Spyware Doctor está atualizado

17/11/2009 11:58:15:551 Resultados do Immunizer

A seção do ActiveX foi imunizada. Nenhum item foi processado.

17/11/2009 12:10:32:530 Detectada uma infecção neste computador

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll

 

17/11/2009 12:10:32:561 Detectada uma infecção neste computador

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe

 

17/11/2009 12:20:33:453 Verificação Concluída

Tipo de Verificação - Verificação Completa

Itens Processados - 381676

Ameaças Detectadas - 1

Infecções Detectadas - 2

Infecções Ignoradas - 0

 

17/11/2009 12:21:10:872 Infecção em quarentena

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe

 

17/11/2009 12:21:10:903 Infecção em quarentena

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll

 

17/11/2009 12:21:10:966 Infecção excluída

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe

 

17/11/2009 12:21:10:981 Infecção excluída

Nome da Ameaça - PWSTool.SnadBoy!sd6

Tipo - Arquivo

Nível de Risco - Alto

Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll

 

17/11/2009 12:21:13:16 Resumo de Infecções em Quarentena/Removidas

Quarentena - 2

Falha na Quarentena - 0

Removido - 2

Falha na Remoção - 0

 

17/11/2009 12:22:00:122 Verificação Iniciada

Tipo de Verificação - Intelli-Scan

 

17/11/2009 12:22:03:142 Detectada uma infecção neste computador

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 12:23:43:269 Verificação Concluída

Tipo de Verificação - Intelli-Scan

Itens Processados - 295318

Ameaças Detectadas - 1

Infecções Detectadas - 1

Infecções Ignoradas - 0

 

17/11/2009 12:23:47:761 Infecção excluída

Nome da Ameaça - Adware.Advertising

Tipo - Cookie

Nível de Risco - Baixo

Infecção - atdmt.com/ atdmt.com

 

17/11/2009 12:23:49:795 Resumo de Infecções em Quarentena/Removidas

Quarentena - 0

Falha na Quarentena - 0

Removido - 1

Falha na Remoção - 0

 

 

OK! fico aguardando resposta! grande abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:thumbsup: Vários outros problemas foram removidos pelo Spyware Doctor.

______________________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download do ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Clique em “SIM” para continuar.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console antes de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADO COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log dele estará em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO ou caso os virus ou malwares bloqueiem a execução do Combofix, baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Neste caso, nomeie-o como Kombofix durante o salvamento e não após salvá-lo!

 

Em último caso, se não for possível executar o Combofix no Modo Normal do Windows, tente utilizar o ComboFix em MODO SEGURO (reiniciando o computador e pressionando a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização e escolha a opção Modo Seguro na tela que se apresenta) e repita o procedimento;

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

* Se por algum motivo você precisar parar ou sair do ComboFix, tecle "N".

* Se perder a conexão com a internet, reinicie o computador. Caso o problema persista, abra Conexões de Rede no Painel de Controle, clique com o botão direito do mouse sobre a sua conexão com a internet e em "Reparar";

 

Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá antonio, bem meu pc ta funcionando normalmente e com os programas que você indicou ja consegui retirar alguns virus.

passei o combofix vou postar o log para analise

 

combofix

ComboFix 09-11-17.03 - cicero 17/11/2009 13:48.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1033.18.2005.1364 [GMT -2:00]

Executando de: c:\documents and settings\cicero\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1356 [VPS 091117-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users\Start Menu\Internet Explorer.lnk

c:\documents and settings\cicero\Dados de aplicativos\Desktopicon

c:\documents and settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe

c:\documents and settings\cicero\Dados de aplicativos\Desktopicon\mc.ico

 

c:\windows\System32\Drivers\iaStor.sys . . . está infectado!!

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-10-17 to 2009-11-17 ))))))))))))))))))))))))))))

.

 

2009-11-17 15:32 . 2004-08-03 22:59 95360 -c--a-w- c:\windows\system32\dllcache\atapi.sys

2009-11-17 15:32 . 2004-08-03 22:59 95360 ----a-w- c:\windows\system32\drivers\atapi.sys

2009-11-17 13:49 . 2009-11-17 13:49 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2009-11-17 13:42 . 2008-12-11 10:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2009-11-17 13:42 . 2009-04-03 13:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-11-17 13:42 . 2008-12-18 14:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-11-17 13:42 . 2009-11-17 13:46 -------- d-----w- c:\program files\Common Files\PC Tools

2009-11-17 13:42 . 2008-12-10 13:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2009-11-17 13:41 . 2009-11-17 13:46 -------- d-----w- c:\program files\Spyware Doctor

2009-11-17 13:41 . 2009-11-17 13:41 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\PC Tools

2009-11-17 13:41 . 2009-11-17 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

2009-11-16 17:28 . 2009-11-16 17:28 -------- d-----w- c:\program files\ESET

2009-11-16 17:22 . 2009-11-16 17:22 -------- d-----w- c:\program files\Sophos

2009-11-16 15:50 . 2009-11-16 15:50 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\Malwarebytes

2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2009-11-16 15:05 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-11-16 15:05 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-11-16 12:12 . 2009-11-16 12:12 -------- d-----w- c:\program files\PhotoZoom Pro 3

2009-11-16 11:27 . 2009-11-16 11:37 -------- d-----w- C:\New Folder

2009-11-13 18:42 . 2009-11-13 18:44 -------- dc-h--w- c:\windows\ie8

2009-11-13 18:28 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2009-11-13 18:28 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2009-11-13 18:28 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2009-11-13 18:28 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll

2009-11-13 18:28 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2009-11-13 18:28 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll

2009-11-10 18:15 . 2008-10-16 16:06 268648 ----a-w- c:\windows\system32\mucltui.dll

2009-11-10 15:20 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll

2009-11-10 15:20 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll

2009-11-10 15:20 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll

2009-11-10 15:20 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll

2009-11-10 15:20 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll

2009-11-10 15:20 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll

2009-11-10 15:20 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll

2009-11-10 15:20 . 2009-01-07 18:14 60273 ----a-w- c:\windows\system32\pthreadGC2.dll

2009-11-10 15:20 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll

2009-11-10 15:20 . 2009-11-10 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack

2009-11-06 13:06 . 2009-11-06 13:06 2996 ----a-w- c:\windows\system32\drivers\hwinterface.sys

2009-11-05 12:57 . 2009-11-11 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet

2009-11-05 12:47 . 2009-09-15 09:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2009-11-05 12:47 . 2009-09-15 09:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2009-11-05 12:47 . 2009-09-15 09:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2009-11-05 12:47 . 2009-09-15 09:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys

2009-11-05 12:47 . 2009-09-15 09:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2009-11-05 12:47 . 2009-09-15 09:53 97480 ----a-w- c:\windows\system32\AvastSS.scr

2009-11-05 12:47 . 2009-09-15 09:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys

2009-11-05 12:47 . 2009-09-15 09:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2009-11-05 12:47 . 2009-09-15 09:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe

2009-11-05 12:47 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll

2009-11-05 12:47 . 2009-11-05 12:47 -------- d-----w- c:\program files\Alwil Software

2009-11-05 12:04 . 2008-08-05 01:00 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\AVGTOOLBAR

2009-11-05 11:57 . 2009-11-05 12:03 -------- d-----w- C:\$AVG

2009-11-05 11:57 . 2009-11-05 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9

2009-11-04 10:55 . 2009-09-23 11:41 26176 ---ha-w- c:\windows\system32\hamachi.sys

2009-11-04 10:54 . 2009-11-04 10:54 -------- d-----w- c:\program files\LogMeIn Hamachi

2009-11-03 14:24 . 2009-11-03 16:07 -------- d-----w- C:\PRO EVOLUTION SOCCER 2009

2009-11-03 11:00 . 2009-11-04 10:52 -------- d-----w- c:\program files\DAEMON Tools Lite

2009-10-30 19:53 . 2009-10-30 19:53 -------- d-----w- c:\program files\Common Files\Macrovision Shared

2009-10-29 10:39 . 2009-10-28 18:38 -------- d--h--r- c:\documents and settings\cicero\Dados de aplicativos\SecuROM

2009-10-28 18:25 . 2009-10-28 18:25 -------- d-----w- c:\program files\Elaborate Bytes

2009-10-27 13:56 . 2001-10-28 20:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll

2009-10-27 13:56 . 1998-07-06 04:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL

2009-10-27 13:56 . 2009-10-27 13:57 -------- d-----w- c:\program files\PDFCreator

2009-10-23 14:04 . 2009-11-17 15:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi

2009-10-20 16:16 . 2009-10-20 16:16 -------- d-----w- c:\documents and settings\cicero\html

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-11-17 15:44 . 2009-07-01 19:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-11-17 15:44 . 2005-04-05 17:21 -------- d-----w- c:\program files\C4ebreg

2009-11-17 11:29 . 2009-04-02 12:21 -------- d-----w- c:\program files\Common Files\Edutec Sistemas

2009-11-13 13:21 . 2009-11-13 13:14 -------- d-----w- c:\windows\Fonts\4000 Fuentes

2009-11-12 18:33 . 2009-09-24 12:32 -------- d-----w- c:\program files\URUSoft

2009-11-11 20:09 . 2009-04-24 11:35 -------- d-----w- c:\program files\Google

2009-11-11 18:42 . 2006-04-12 02:08 -------- d-----w- c:\program files\Common Files\Adobe

2009-11-10 11:29 . 2009-04-01 17:27 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2009-11-06 11:45 . 2009-04-27 12:16 204800 ----a-r- c:\documents and settings\cicero\Dados de aplicativos\Microsoft\Installer\{BF14F624-CC30-4E30-8E2B-D86996EB11C9}\NewShortcut1.83127830_6290_4E1E_87F9_DC629969AA98.exe

2009-11-06 11:45 . 2009-04-27 12:16 10134 ----a-r- c:\documents and settings\cicero\Dados de aplicativos\Microsoft\Installer\{BF14F624-CC30-4E30-8E2B-D86996EB11C9}\ARPPRODUCTICON.exe

2009-11-05 12:35 . 2009-09-24 14:27 -------- d-----w- c:\program files\Gabest

2009-11-05 11:57 . 2009-04-01 17:27 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2009-11-05 11:57 . 2009-04-01 17:27 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2009-11-05 11:57 . 2009-04-01 17:27 12464 ----a-w- c:\windows\system32\avgrsstx.dll

2009-11-05 11:57 . 2009-04-01 17:27 -------- d-----w- c:\program files\AVG

2009-11-03 11:00 . 2009-07-21 11:13 691696 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-11-03 11:00 . 2009-07-21 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite

2009-10-29 14:16 . 2005-04-05 19:45 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-10-23 14:10 . 2009-04-29 13:20 -------- d-----w- c:\program files\UltraVNC

2009-10-20 16:32 . 2009-08-07 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

2009-10-20 11:31 . 2009-07-27 17:43 -------- d-----w- c:\program files\DAP

2009-10-08 22:11 . 2009-10-09 11:57 7266304 ---ha-w- c:\documents and settings\cicero\prf75.tmp

2009-09-23 13:41 . 2009-09-23 13:41 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys

2009-09-22 16:44 . 2009-09-22 16:44 -------- d-----w- c:\program files\Webteh

2009-09-22 16:18 . 2009-09-22 16:18 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\InterVideo

2009-09-04 19:44 . 2009-11-03 16:06 515416 ----a-w- c:\windows\system32\XAudio2_5.dll

2009-09-04 19:44 . 2009-11-03 16:06 238936 ----a-w- c:\windows\system32\xactengine3_5.dll

2009-09-04 19:44 . 2009-11-03 16:06 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll

2009-09-04 19:29 . 2009-11-03 16:06 453456 ----a-w- c:\windows\system32\d3dx10_42.dll

2009-09-04 19:29 . 2009-11-03 16:06 235344 ----a-w- c:\windows\system32\d3dx11_42.dll

2009-09-04 19:29 . 2009-11-03 16:06 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll

2009-09-04 19:29 . 2009-11-03 16:06 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll

2009-09-04 19:29 . 2009-11-03 16:06 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll

2009-09-03 13:04 . 2009-07-29 11:42 83456 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll

2009-08-29 08:08 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-10-20 2803200]

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"stgclean"="c:\sdwork\w32main2.exe" [2007-10-24 266752]

"Tpam.exe"="c:\program files\IBM\Personal Communications\tpam.exe" [2005-09-06 28672]

"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352]

"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-21 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-21 166424]

"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-21 137752]

"MyHelpService"="c:\program files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe" [2006-12-19 81920]

"pmonmh"="c:\program files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe" [2007-09-17 188416]

"C4EBReg"="c:\program files\C4ebreg\c4ebreg.exe" [2007-09-07 364544]

"ISAMTray"="c:\program files\C4ebreg\isamtray.exe" [2007-09-07 237568]

"w32msgr"="c:\sdwork\W32MAIN2.exe" [2007-10-24 266752]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]

"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]

"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]

"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]

 

c:\documents and settings\carolina\Menu Iniciar\Programas\Inicializar\

UltraVNC Server.lnk - \\Ibm-4ce866f99f7\c$\Program Files\UltraVNC\winvnc.exe [2008-10-23 1148480]

 

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Lotus QuickStart.lnk - c:\lotus\wordpro\ltsstart.exe [2003-4-7 32768]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"disablecad"= 1 (0x1)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoDeletePrinter"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-11-05 11:57 12464 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst]

2005-09-06 18:43 49152 ----a-w- c:\windows\system32\pcsinst.dll

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

@=""

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

@=""

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

"IBMconfig"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\PRO EVOLUTION SOCCER 2009\\pes2009.exe"=

 

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [17/11/2009 11:42 130936]

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [05/11/2009 10:47 114768]

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [01/04/2009 15:27 333192]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [01/04/2009 15:27 360584]

R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [06/11/2009 11:06 2996]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/11/2009 10:47 20560]

R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [05/11/2009 09:57 285392]

R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]

R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29/10/2009 12:27 1074568]

R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [06/07/2009 15:11 133104]

S2 vuphzubwyjo;vuphzubwyjo;\??\c:\windows\system32\drivers\sgpgpkjhm.sys --> c:\windows\system32\drivers\sgpgpkjhm.sys [?]

S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\35.tmp --> c:\windows\system32\35.tmp [?]

S3 usb2vcom;USB Data Cable;c:\windows\system32\drivers\usb2vcom.sys [28/04/2009 12:36 22760]

 

--- =Outros Serviços/Drivers Na Memória ---

 

*NewlyCreated* - CLASSPNP_2

*Deregistered* - CLASSPNP_2

*Deregistered* - mbr

*Deregistered* - mchInjDrv

*Deregistered* - PROCEXP113

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

bcbksc

iyiyb

jbqeilpvy

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-06 17:11]

 

2009-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-06 17:11]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

mWindow Title =

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s

IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm

IE: &Download with &DAP - c:\program files\DAP\dapextie.htm

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {A152453C-986E-4F8B-B789-D8E955F06321} = 192.168.0.3,192.168.0.1

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} - hxxp://

DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab

.

- - - - ORFÃOS REMOVIDOS - - - -

 

Notify-atmgrtok - atmgrtok.dll

Notify-NavLogon - (no file)

AddRemove-HijackThis - c:\docume~1\cicero\CONFIG~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-11-17 13:56

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: MBR read successfully

called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A64F1F8]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf763bfc3

\Driver\ACPI -> ACPI.sys @ 0xf74a3cb8

\Driver\atapi -> 0x8a64f1f8

\Driver\iaStor -> iaStor.sys @ 0xf7b4a7b0

IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel® 82566DM-2 Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xba75bba0

PacketIndicateHandler -> NDIS.sys @ 0xba768b21

SendHandler -> NDIS.sys @ 0xba74687b

Warning: possible MBR rootkit infection !

user & kernel MBR OK

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]

"ImagePath"="C:/mysql/bin/mysqld-max.exe"

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]

"ImagePath"="\??\c:\windows\system32\35.tmp"

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]

"ImagePath"="C:/mysql/bin/mysqld-max.exe"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{18DFA061-844F-31F3-4A29-094E24333070}*]

"kafafaiggcfnjeddnmjdim"=hex:62,61,64,6a,00,02

 

[HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2E3A949E-ABEE-514C-A578-42C96B21D1F4}*]

"kabhkhhjkbjiaadfjbhfml"=hex:62,61,6c,6c,00,00

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(584)

c:\program files\IBM\Personal Communications\atmgrtok.dll

c:\program files\IBM\Personal Communications\MILLUTIL.DLL

c:\windows\system32\pcsinst.dll

.

Tempo para conclusão: 2009-11-17 13:58

ComboFix-quarantined-files.txt 2009-11-17 15:58

 

Pré-execução: 133.250.404.352 bytes free

Pós execução: 133.367.963.648 bytes free

 

- - End Of File - - FA92A4E333E89E03DEAC0239BE7AFD95

 

log hijackthis

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:14:16, on 17/11/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\Drivers\trcboot.exe

C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

C:\Program Files\C4ebreg\c4ebreg.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\notes\ntmulti.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe

C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Drivers\ldlcserv.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\IBM\Personal Communications\tpam.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\WINDOWS\system32\ICO.EXE

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\C4ebreg\isamtray.exe

C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

C:\Program Files\DAP\DAP.EXE

C:\Program Files\DAEMON Tools Lite\DTLite.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup

O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe

O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe

O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q

O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe"

O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - Global Startup: Lotus QuickStart.lnk = ?

O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O11 - Options group: [JAVA_IBM] Java (IBM)

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab

O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http://

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba

O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe

O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe

O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe

O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe

O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing)

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe

 

--

End of file - 11979 bytes

 

estarei aguardando retorno. abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:seta: Baixe o FixPolicies:

http://www.virus-protect.org/exxe/FixPolicies.exe

 

* Dê um duplo click no arquivo FixPolicies e em Executar

 

* Será criada uma pasta com o nome FixPolicies

 

* Abra a pasta e dê um duplo click no arquivo Fix Policies.cmd

 

*Aparecerá uma tela preta e rapidamente desaparecerá.Ignore qualquer aviso de erro;

 

*Reinicie o computador

_____________________________________

 

:seta: Vá no menu: Iniciar > Painel de Controle > Opções de Pasta

* Selecione a aba Modo de exibição

* Selecione o botão Mostrar pastas e arquivos ocultos

* Desmarque a caixa Ocultar arquivos protegidos do sistema operacional (recomendado)

* Clique em OK

 

Envie estes arquivos destacados em vermelho abaixo para serem analisados no site http://virscan.org/

c:\windows\System32\Drivers\iaStor.sys

c:\windows\system32\drivers\sgpgpkjhm.sys

_____________________________________

 

:seta: Selecione o texto abaixo dentro do Quote (caixa branca abaixo) e copie para o Bloco de notas. Salve-o no desktop (área de trabalho) como CFScript.txt

 

File::

c:\documents and settings\cicero\prf75.tmp

C:\WINDOWS\SYSTEM32\pcsinst.dll

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000000

"FirewallOverride"=dword:00000000

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst]

NetSvc::

bcbksc

iyiyb

jbqeilpvy

________________________________________

 

:seta: Depois disto siga as dicas deste tutorial:

 

Tutorial do Kaspersky Virus Removal Tool

 

Na sua próxima resposta poste este log do Kaspersky Virus Removal Tool

__________________________________

 

:seta: Faça o download desta ferramenta no link abaixo e salve-a no desktop (área de trabalho):

http://www2.gmer.net/mbr/mbr.exe

 

Dê um duplo clique sobre ela e será gerado um log que estará na sua área de trabalho. Dê um duplo clique sobre este log (mbr.log) > copie o conteúdo dele e poste-o em sua próxima resposta juntamente com o log do Kaspersky Virus Removal Tool, os links com o resultado do escaneamento dos dois arquivos no site VirSCAN e um novo log do Hijackthis e nos diga como está seu PC depois disto.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.