cicerod2 0 Denunciar post Postado Novembro 16, 2009 galera me ajudem por favor, toda vez que eu inicio o internet explorer abre uma janela tipo pop up com prppragandas, no titulo da janela vem assim "CiD....." ja li em outros post que isso é um maleware e gostaria que você me ajudassem a exterminar essa praga do meu pc. vai ai o log do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:28:57, on 16/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\C4ebreg\c4ebreg.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\notes\ntmulti.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\Explorer.EXE C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe C:\Program Files\C4ebreg\isamtray.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAP\DAP.EXE C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\New Folder\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file) O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe" O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [searchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe O4 - HKLM\..\Run: [fast city ping help] C:\Documents and Settings\All Users\Application Data\long extra fast city\inside media.exe O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - Global Startup: Lotus QuickStart.lnk = ? O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000 O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing) O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing) O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe -- End of file - 12217 bytes aguardo respostas Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Novembro 16, 2009 :thumbsup: Olá Cicero! Seja bem-vindo ao Fórum Imasters. Siga estes procedimentos abaixo nesta seqüência em que eles estão: :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download de ToolBar S&D *Salve-o no desktop (área de trabalho). *Reinicie o PC em Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). *Execute o programa, e à seguir, aperte o "p" --> Enter --> Ok. *Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde! *Terminando, o relatório estará em C:\ToolBar SD\TB_1.txt __________________________________ :seta: Vá no menu: Iniciar > Painel de Controle > Adicionar ou remover programas > Procure por este programa destacado abaixo e o desinstale: pdfforge Toolbar __________________________________ :seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho): http://swandog46.geekstogo.com/avenger2/download.php *Selecione e copie (Ctrl+C) todo o texto dentro do Quote (caixa branca) abaixo: Folders to delete:C:\Program Files\pdfforge Toolbar *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *O relatório será criado em C:\avenger.txt _____________________________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file) O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\pdfforgeToolbarIE.dll O4 - HKLM\..\Run: [searchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe _____________________________________ :seta: Faça o download do Lop S&D no endereço abaixo: http://eric.71.mespages.googlepages.com/LopSD.exe # Temporariamente desative seus programas de proteção (Antivirus, etc.) para não interferirem com a ferramenta. # Dê um Duplo-Clique com o botão esquerdo do mouse no ícone do Lop S&D que estará no desktop (área de trabalho). Se utiliza o Windows Vista, dê clique direito do mouse no LopSD.exe e escolha 'Executar como administrador'. # Irá surgir uma janela, tecle P de Português e dê enter. # Pressione agora o numero "2 - Remocao + Hosts" pressionando a tecla "2" e dê ENTER. # A ferramenta irá rodar para que a infecção possa ser removida. # No final será gerado um log que estará em C:\lopR.txt _____________________________________ :seta: Faça o download desta ferramenta abaixo: http://lop.com/new_uninstall.exe Obs: Note que este desinstalador é detectado como trojan por diversos antivírus. Se isso acontecer, desabilite temporariamente o seu antivírus e volte a ativá-lo quando terminar o procedimento. O arquivo é perfeitamente seguro. Dê um duplo clique neste desinstalador que você baixou acima > Clique em Ok > Clique em Ok novamente > aparecerão alguns números em uma tela, digite estes números no campo em branco e depois disto clique no botão UNINSTALL > clique em Ok > clique em Ok novamente >aí é só ir seguindo os passos que este desinstalador vai te passando. _____________________________________ :seta: Siga também, por gentileza, as dicas deste tutorial para fazer uma limpeza de seu PC com o Malwarebytes: '>http://dicasetutoriaisparapc.blogspot.com/2009/10/tutorial-do-malwarebytes-anti-malware.html"]Tutorial do Malwarebytes Anti-Malware Na sua próxima resposta poste este log do Malwarebytes juntamente com o log que estará em C:\lopR.txt, o log que estará em C:\avenger.txt, o log que estará em C:\ToolBar SD\TB_1.txt e um novo log do Hijackthis e nos diga como está o seu PC após estes procedimentos. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
cicerod2 0 Denunciar post Postado Novembro 16, 2009 olá antonio, muito obrigado pela atenção: fiz todos os procedimentos recomendados e seguem os logs abaixo; log lopR --------------------\\ Lop S&D 4.2.5-0 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Intel® Core2 Duo CPU E6550 @ 2.33GHz ) BIOS : Lenovo ThinkCentre BIOS Ver 2RKT44.0 USER : administrador ( Administrator ) BOOT : Normal boot Antivirus : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 (Activated) C:\ (Local Disk) - NTFS - Total:149 Go (Free:124 Go) D:\ (CD or DVD) E:\ (CD or DVD) "C:\Lop SD" ( MAJ : 19-12-2008|23:40 ) Option : [2] ( seg 16/11/2009|13:02 ) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS - [ Arquivos/Ficheiros Hosts ] .. RESTAURADO \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Lista de pastas em APPLIC~1 [02/04/2007|19:20] C:\DOCUME~1\ADMINI~2\APPLIC~1\Adobe [12/04/2006|00:08] C:\DOCUME~1\ADMINI~2\APPLIC~1\AdobeUM [23/01/2006|22:47] C:\DOCUME~1\ADMINI~2\APPLIC~1\Help [22/02/2007|20:55] C:\DOCUME~1\ADMINI~2\APPLIC~1\IBM [04/04/2005|15:44] C:\DOCUME~1\ADMINI~2\APPLIC~1\Identities [11/04/2006|23:22] C:\DOCUME~1\ADMINI~2\APPLIC~1\Macromedia [01/04/2009|16:56] C:\DOCUME~1\ADMINI~2\APPLIC~1\Microsoft [01/04/2009|16:52] C:\DOCUME~1\ADMINI~2\APPLIC~1\Sun [27/04/2009|10:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe [12/04/2006|00:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM [23/01/2006|22:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help [22/02/2007|20:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\IBM [04/04/2005|15:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities [11/04/2006|23:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia [10/10/2007|13:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft [27/04/2009|10:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\Orbit [27/04/2009|10:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real [01/04/2009|15:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun [13/11/2009|15:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [05/11/2009|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg9 [03/11/2009|09:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DAEMON Tools Lite [11/11/2009|14:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet [07/08/2009|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard [07/08/2009|18:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP [05/04/2005|17:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IBM [20/02/2007|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IGS [30/07/2009|10:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [09/04/2009|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help [20/10/2009|14:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS [20/04/2009|17:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real [12/05/2009|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony [29/07/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpeedBit [01/04/2009|15:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [16/11/2009|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP [30/07/2009|10:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ubisoft [07/08/2009|18:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WEBREG [18/08/2005|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [02/07/2009|11:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [13/08/2009|10:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [06/08/2009|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion [20/04/2009|16:34] C:\DOCUME~1\carolina\APPLIC~1\Adobe [20/04/2009|16:34] C:\DOCUME~1\carolina\APPLIC~1\Macromedia [08/07/2009|15:03] C:\DOCUME~1\cicero\APPLIC~1\Adobe [10/07/2009|12:34] C:\DOCUME~1\cicero\APPLIC~1\Macromedia [27/10/2009|13:05] C:\DOCUME~1\cicero\APPLIC~1\pdfforge [02/04/2007|19:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe [12/04/2006|00:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AdobeUM [23/01/2006|22:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Help [22/02/2007|20:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\IBM [04/04/2005|15:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities [11/04/2006|23:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia [10/10/2007|13:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [04/04/2005|15:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [30/04/2009|18:47] C:\DOCUME~1\LOCALS~1\APPLIC~1\Softland [04/04/2005|15:44] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [17/02/2009|16:14] C:\DOCUME~1\renata\APPLIC~1\Microsoft --------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks [16/11/2009 12:24][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [16/11/2009 12:51][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [16/11/2009 12:50][--ah-----] C:\WINDOWS\tasks\SA.DAT [04/08/2004 03:00][-rah-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Lista de pastas em C:\Program Files [30/10/2009|17:54] C:\Program Files\Adobe [05/04/2005|18:13] C:\Program Files\AFP Workbench 32 [01/04/2009|16:50] C:\Program Files\Ahead [05/11/2009|10:47] C:\Program Files\Alwil Software [28/11/2007|20:51] C:\Program Files\Analog Devices [02/04/2009|10:21] C:\Program Files\Arquivos Comuns [28/11/2007|20:59] C:\Program Files\AT&T Network Client Install [26/05/2009|18:43] C:\Program Files\Audacity 1.3 Beta (Unicode) [05/11/2009|09:57] C:\Program Files\AVG [16/11/2009|12:50] C:\Program Files\C4ebreg [18/08/2009|11:34] C:\Program Files\CC PDF Converter [02/04/2009|10:40] C:\Program Files\CCleaner [03/11/2009|13:37] C:\Program Files\Common Files [04/04/2005|15:41] C:\Program Files\ComPlus Applications [03/09/2009|16:05] C:\Program Files\Correios [09/04/2009|12:12] C:\Program Files\Crystal Decisions [04/11/2009|08:52] C:\Program Files\DAEMON Tools Lite [20/10/2009|09:31] C:\Program Files\DAP [02/04/2009|11:02] C:\Program Files\Edutec Sistemas [28/10/2009|17:15] C:\Program Files\Eidos [28/10/2009|16:25] C:\Program Files\Elaborate Bytes [17/09/2009|11:26] C:\Program Files\ElcomSoft [01/07/2009|17:42] C:\Program Files\Eltima Software [02/04/2009|10:22] C:\Program Files\Firebird [05/11/2009|10:35] C:\Program Files\Gabest [11/11/2009|18:09] C:\Program Files\Google [04/04/2005|16:07] C:\Program Files\HighMAT CD Writing Wizard [01/04/2009|08:45] C:\Program Files\IBM [07/08/2006|21:23] C:\Program Files\IBM Ayudame [29/11/2007|13:54] C:\Program Files\IBM DLA [29/10/2009|12:16] C:\Program Files\InstallShield Installation Information [13/11/2009|17:08] C:\Program Files\Internet Explorer [29/11/2007|13:55] C:\Program Files\InterVideo [01/04/2009|16:01] C:\Program Files\Java [10/11/2009|13:20] C:\Program Files\K-Lite Codec Pack [10/09/2009|11:56] C:\Program Files\Koinonia Software [26/05/2009|18:50] C:\Program Files\Lame for Audacity [04/11/2009|08:54] C:\Program Files\LogMeIn Hamachi [05/09/2007|18:13] C:\Program Files\Microsoft CAPICOM 2.1.0.2 [04/04/2005|15:44] C:\Program Files\microsoft frontpage [16/09/2009|11:45] C:\Program Files\Microsoft Office [09/09/2009|18:11] C:\Program Files\Microsoft Silverlight [12/05/2009|17:25] C:\Program Files\Microsoft SQL Server [01/04/2009|16:50] C:\Program Files\Microsoft Visual Studio [01/04/2009|16:50] C:\Program Files\Microsoft Works [01/04/2009|16:49] C:\Program Files\Microsoft.NET [04/04/2005|15:42] C:\Program Files\Movie Maker [03/04/2009|16:40] C:\Program Files\MP3Gain [19/02/2007|22:39] C:\Program Files\MSBuild [16/09/2009|11:44] C:\Program Files\MSECache [04/04/2005|15:40] C:\Program Files\MSN [04/04/2005|15:40] C:\Program Files\MSN Gaming Zone [05/09/2007|18:11] C:\Program Files\MSXML 4.0 [05/09/2007|17:32] C:\Program Files\MSXML 6.0 [04/04/2005|15:42] C:\Program Files\NetMeeting [04/04/2005|15:41] C:\Program Files\Online Services [05/09/2007|17:26] C:\Program Files\Outlook Express [27/10/2009|11:57] C:\Program Files\PDFCreator [09/07/2009|16:03] C:\Program Files\PhotoFiltre Studio X [16/11/2009|10:12] C:\Program Files\PhotoZoom Pro 3 [20/04/2009|17:25] C:\Program Files\Real Alternative [19/02/2007|22:35] C:\Program Files\Reference Assemblies [02/04/2009|10:21] C:\Program Files\Report Designer Component [29/11/2007|13:56] C:\Program Files\Roxio [01/07/2009|13:57] C:\Program Files\Seagate Software [27/04/2009|15:17] C:\Program Files\Smallvideosoft [02/08/2005|13:41] C:\Program Files\Snapshot Viewer [30/04/2009|18:46] C:\Program Files\Softland [13/05/2009|14:23] C:\Program Files\Sony [13/05/2009|14:22] C:\Program Files\Sony Setup [01/04/2009|16:01] C:\Program Files\Sun [07/05/2009|13:00] C:\Program Files\Symantec Client Security [05/04/2005|18:04] C:\Program Files\Tivoli [23/10/2009|12:10] C:\Program Files\UltraVNC [12/05/2009|17:25] C:\Program Files\Uninstall Information [12/11/2009|16:33] C:\Program Files\URUSoft [12/05/2009|17:24] C:\Program Files\Vstplugins [22/09/2009|14:44] C:\Program Files\Webteh [28/11/2007|20:56] C:\Program Files\wecminst [04/04/2005|16:06] C:\Program Files\Windows Journal Viewer [25/05/2009|14:49] C:\Program Files\Windows Media Player [04/04/2005|15:40] C:\Program Files\Windows NT [04/04/2005|15:43] C:\Program Files\WindowsUpdate [01/04/2009|15:58] C:\Program Files\WinRAR [01/04/2009|14:59] C:\Program Files\WST [04/04/2005|15:44] C:\Program Files\xerox --------------------\\ Lista de pastas em C:\Program Files\Common Files [11/11/2009|16:42] C:\Program Files\Common Files\Adobe [01/04/2009|16:50] C:\Program Files\Common Files\Ahead [10/09/2009|12:01] C:\Program Files\Common Files\Borland Shared [02/04/2009|10:20] C:\Program Files\Common Files\Crystal Decisions [01/04/2009|16:50] C:\Program Files\Common Files\DESIGNER [16/11/2009|09:38] C:\Program Files\Common Files\Edutec Sistemas [07/08/2009|18:01] C:\Program Files\Common Files\Hewlett-Packard [01/04/2009|08:45] C:\Program Files\Common Files\InstallShield [01/04/2009|15:58] C:\Program Files\Common Files\Java [30/10/2009|17:53] C:\Program Files\Common Files\Macrovision Shared [09/04/2009|12:12] C:\Program Files\Common Files\Merge Modules [05/11/2009|09:56] C:\Program Files\Common Files\Microsoft Shared [04/04/2005|15:42] C:\Program Files\Common Files\MSSoap [10/10/2007|13:31] C:\Program Files\Common Files\My Help [04/04/2005|16:36] C:\Program Files\Common Files\ODBC [10/09/2009|11:56] C:\Program Files\Common Files\Opus Shared [28/04/2009|13:16] C:\Program Files\Common Files\SafeNet Sentinel [04/04/2005|15:42] C:\Program Files\Common Files\Services [29/11/2007|13:57] C:\Program Files\Common Files\Sonic Shared [04/04/2005|16:36] C:\Program Files\Common Files\SpeechEngines [01/04/2009|15:14] C:\Program Files\Common Files\Symantec Shared [01/04/2009|16:50] C:\Program Files\Common Files\System [03/04/2009|16:21] C:\Program Files\Common Files\Windows Live --------------------\\ Process ( 57 Processes ) ... OK ! --------------------\\ Procura pelo S_Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura no Registro ..... OK ! --------------------\\ Verificando o Arquivos/Ficheiros Hosts Arquivos/Ficheiros Hosts LIMPO --------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-16 13:03:37 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden files ... folder error: C:\WINDOWS\System32\ --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. [F:31][D:8]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp [F:16][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies [F:514][D:5]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - seg 16/11/2009|13:03 - Option : [2] --------------------\\ Verificação completa em 13:03:49 log avanger ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Mon Nov 16 11:53:27 2009 11:53:27: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Mon Nov 16 11:55:05 2009 11:55:05: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Completed script processing. ******************* Finished! Terminate. log malwarebytes Malwarebytes' Anti-Malware 1.41 Versão do banco de dados: 3178 Windows 5.1.2600 Service Pack 2 16/11/09 13:41:19 mbam-log-2009-11-16 (13-41-19).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 221598 Tempo decorrido: 36 minute(s), 54 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 1 Valores do Registro infectados: 0 Ítens do Registro infectados: 3 Pastas infectadas: 0 Arquivos infectados: 2 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\glaide32 (Rootkit.Rustock) -> Quarantined and deleted successfully. Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: C:\Documents and Settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe (Adware.ADON) -> Quarantined and deleted successfully. C:\WINDOWS\system32\OGKernel.dll (Malware.Packer.Morphine) -> Quarantined and deleted successfully. log Toolbar S&D -----------\\ ToolBar S&D 1.2.9 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Intel® Core2 Duo CPU E6550 @ 2.33GHz ) BIOS : Lenovo ThinkCentre BIOS Ver 2RKT44.0 USER : administrador ( Administrator ) BOOT : Fail-safe boot Antivirus : avast! antivirus 4.8.1356 [VPS 091116-0] 4.8.1356 (Not Activated) C:\ (Local Disk) - NTFS - Total:149 Go (Free:124 Go) D:\ (CD or DVD) "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 ) Option : [2] ( seg 16/11/2009|12:45 ) -----------\\ REMOVIDOS Deletado! - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll Deletado! - C:\Program Files\DAEMON Tools Toolbar\Resources Deletado! - C:\Program Files\DAEMON Tools Toolbar\uninst.exe Deletado! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml Deletado! - C:\DOCUME~1\cicero\APPLIC~1\Search Settings\kb128 Deletado! - C:\Program Files\DAEMON Tools Toolbar Deletado! - C:\DOCUME~1\cicero\APPLIC~1\Search Settings -----------\\ Procura por Arquivos / Ficheiros ... -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://w3.ibm.com/" "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Url"="http://go.microsoft.com/fwlink/?LinkId=68929" "Url"="http://go.microsoft.com/fwlink/?LinkId=68928" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Start Page"="http://www.msn.com/" --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. 1 - "C:\ToolBar SD\TB_1.txt" - seg 16/11/2009|12:46 - Option : [2] -----------\\ Verificação completa em 12:46:56,21 log hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:00:50, on 16/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\C4ebreg\c4ebreg.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\notes\ntmulti.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe C:\Program Files\C4ebreg\isamtray.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\CTFMON.EXE C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\BDGQDFPC\HiJackThis[1].exe C:\Program Files\IBM\My Help\MyHelp.exe C:\Program Files\IBM\My Help\jre\bin\myhelpw.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w3.ibm.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe" O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Lotus QuickStart.lnk = ? O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000 O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing) O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing) O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe -- End of file - 10179 bytes Antonio, mais uma vez muito obrigado pela ajuda e espero que tenha conseguido me livrar dessa praga. grande abraço. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Novembro 16, 2009 :thumbsup: Vários problemas foram removidos do seu PC. ______________________________ :!: Houve um erro na hora de criar o script do Avenger. Para se certificar de que aquela pasta foi realmente removida, vá no menu: Iniciar > Todos os programas > Acessórios > Windows Explorer > Procure por esta pasta em vermelho abaixo e a exclua (se ela ainda existir): C:\Program Files\pdfforge Toolbar ______________________________ :seta: Siga as dicas destes tutoriais: Tutorial do Panda Anti-RootKit Tutorial do Sophos Anti-RootKit ______________________________ :seta: Depois disto siga, por gentileza, esta dica para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento e se foi removido algum problema pelo Panda Anti-RootKit e pelo Sophos Anti-RootKit. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
cicerod2 0 Denunciar post Postado Novembro 16, 2009 olá antonio seguem os logs log online scanner ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=32d5c757b4f8bb488c03e63f9f1994ec # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-11-16 06:06:09 # local_time=2009-11-16 04:06:09 (-0300, E. South America Daylight Time) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 16775141 100 98 0 193759624 0 0 # compatibility_mode=1024 16777215 100 0 49042 49042 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=57921 # found=1 # cleaned=1 # scan_time=1899 C:\Documents and Settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe a variant of Win32/Adware.ADON application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C log hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:13:13, on 16/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\C4ebreg\c4ebreg.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\notes\ntmulti.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\Explorer.EXE C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe C:\Program Files\C4ebreg\isamtray.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAP\DAP.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe" O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - Global Startup: Lotus QuickStart.lnk = ? O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing) O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing) O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe -- End of file - 11270 bytes até agora o meu pc voltou a funcionar normalmente sem as janelas do "CiD". Espero que tenha conseguido resolver todos os problemas. valeu, um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Novembro 17, 2009 :thumbsup: Mais um adware foi removido pelo Nod32 Online. ________________________________ :seta: Você executou o Panda Anti-RootKit e Sophos Anti-RootKit? Caso não tenha executado, execute-os por gentileza. Caso já tenha executado, eles detectaram e removeram algum problema? ________________________________ :seta: Você observou se esta pasta abaixo ainda existe e a excluiu caso ela exista? C:\Program Files\pdfforge Toolbar ________________________________ :seta: Siga, por gentileza as dicas deste tutorial para fazer uma limpeza de seu PC com o Spyware Doctor: Tutorial do Spyware Doctor Starter Edition Na sua próxima resposta poste este log do Spyware Doctor juntamente com um novo log do Hijackthis e nos diga como está o seu Pc depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
cicerod2 0 Denunciar post Postado Novembro 17, 2009 olá antonio. ontem eu executei o Panda Anti-RootKit e Sophos Anti-RootKit e eles não encontraram nada, e também observei que a pasta C:\Program Files\pdfforge Toolbar havia sido excluida. vou postar agora o log do hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:27:41, on 17/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\C4ebreg\c4ebreg.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\notes\ntmulti.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe C:\Program Files\C4ebreg\isamtray.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAP\DAP.EXE C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\InterADE\interade.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe" O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - Global Startup: Lotus QuickStart.lnk = ? O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing) O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe -- End of file - 12029 bytes e o historico do PC Tools Spyware Doctor PC Tools Spyware Doctor Date Status 17/11/2009 11:46:20:35 Serviço Iniciado Aplicações de Serviço do Spyware Doctor iniciadas 17/11/2009 11:46:20:35 Mecanismo Antimalware Configuração do mecanismo antimalware carregada com sucesso. 17/11/2009 11:46:27:51 Verificação Iniciada Tipo de Verificação - Intelli-Scan 17/11/2009 11:46:27:832 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - ad.adnetwork.com.br/ ad.adnetwork.com.br 17/11/2009 11:46:27:832 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - ad.yieldmanager.com/ ad.yieldmanager.com 17/11/2009 11:46:27:941 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 11:46:28:35 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - content.yieldmanager.com/ content.yieldmanager.com 17/11/2009 11:46:28:35 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - content.yieldmanager.com/ content.yieldmanager.com 17/11/2009 11:46:28:98 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - ehg-fifa.hitbox.com/ ehg-fifa.hitbox.com 17/11/2009 11:46:28:191 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - forum.imasters.com.br/ forum.imasters.com.br 17/11/2009 11:46:28:395 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - hitbox.com/ hitbox.com 17/11/2009 11:46:28:457 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - imasters.com.br/ imasters.com.br 17/11/2009 11:46:28:754 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - quantserve.com/ quantserve.com 17/11/2009 11:46:28:926 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - uol.com.br/ uol.com.br 17/11/2009 11:46:29:207 Detectada uma infecção neste computador Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - zedo.com/ zedo.com 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol 17/11/2009 11:46:41:957 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore 17/11/2009 11:46:41:973 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Chave de Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty 17/11/2009 11:46:53:566 Status do IntelliGuard Todos os IntelliGuards foram Ativados 17/11/2009 11:46:58:410 Resultados do Immunizer A seção do ActiveX foi imunizada. Itens 5055 processados. 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:48:18:145 Detectada uma infecção neste computador Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:48:18:160 Verificação Concluída Tipo de Verificação - Intelli-Scan Itens Processados - 295267 Ameaças Detectadas - 3 Infecções Detectadas - 30 Infecções Ignoradas - 0 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - zedo.com/ zedo.com 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - uol.com.br/ uol.com.br 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - quantserve.com/ quantserve.com 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - imasters.com.br/ imasters.com.br 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - hitbox.com/ hitbox.com 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - forum.imasters.com.br/ forum.imasters.com.br 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - ehg-fifa.hitbox.com/ ehg-fifa.hitbox.com 17/11/2009 11:49:13:457 Infecção excluída Nome da Ameaça - Application.TrackingCookies Tipo - Cookie Nível de Risco - Baixo Infecção - ad.adnetwork.com.br/ ad.adnetwork.com.br 17/11/2009 11:49:13:504 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - content.yieldmanager.com/ content.yieldmanager.com 17/11/2009 11:49:13:504 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - content.yieldmanager.com/ content.yieldmanager.com 17/11/2009 11:49:13:504 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 11:49:13:504 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - ad.yieldmanager.com/ ad.yieldmanager.com 17/11/2009 11:49:13:551 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:551 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:551 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:551 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Chave de Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1 17/11/2009 11:49:13:566 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg 17/11/2009 11:49:13:582 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1 17/11/2009 11:49:13:598 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem 17/11/2009 11:49:13:598 Infecção em quarentena Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop 17/11/2009 11:49:13:676 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main, Start Page 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor de Registro Modificado Nível de Risco - Alto Infecção - HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Chave de Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cocore 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, cb1 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ic1 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, kiu 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, instk4 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, regexp 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, eggol 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, dreg 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, exp1 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, rem 17/11/2009 11:49:13:691 Infecção excluída Nome da Ameaça - Trojan.Autoit Tipo - Valor do Registro Nível de Risco - Alto Infecção - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty, ilop 17/11/2009 11:49:15:723 Resumo de Infecções em Quarentena/Removidas Quarentena - 18 Falha na Quarentena - 0 Removido - 30 Falha na Remoção - 0 17/11/2009 11:50:57:973 Verificação Iniciada Tipo de Verificação - Intelli-Scan 17/11/2009 11:50:58:723 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 11:52:17:676 Verificação Concluída Tipo de Verificação - Intelli-Scan Itens Processados - 295377 Ameaças Detectadas - 1 Infecções Detectadas - 1 Infecções Ignoradas - 0 17/11/2009 11:52:23:660 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 11:52:25:691 Resumo de Infecções em Quarentena/Removidas Quarentena - 0 Falha na Quarentena - 0 Removido - 1 Falha na Remoção - 0 17/11/2009 11:52:33:988 Verificação Iniciada Tipo de Verificação - Verificação Completa 17/11/2009 11:58:13:926 Smart Update O Smart Update determinou que o Spyware Doctor está atualizado 17/11/2009 11:58:15:551 Resultados do Immunizer A seção do ActiveX foi imunizada. Nenhum item foi processado. 17/11/2009 12:10:32:530 Detectada uma infecção neste computador Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll 17/11/2009 12:10:32:561 Detectada uma infecção neste computador Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe 17/11/2009 12:20:33:453 Verificação Concluída Tipo de Verificação - Verificação Completa Itens Processados - 381676 Ameaças Detectadas - 1 Infecções Detectadas - 2 Infecções Ignoradas - 0 17/11/2009 12:21:10:872 Infecção em quarentena Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe 17/11/2009 12:21:10:903 Infecção em quarentena Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll 17/11/2009 12:21:10:966 Infecção excluída Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003690.exe 17/11/2009 12:21:10:981 Infecção excluída Nome da Ameaça - PWSTool.SnadBoy!sd6 Tipo - Arquivo Nível de Risco - Alto Infecção - C:\System Volume Information\_restore{01E266C2-86F5-40B2-9145-B4252FFF29C3}\RP27\A0003689.dll 17/11/2009 12:21:13:16 Resumo de Infecções em Quarentena/Removidas Quarentena - 2 Falha na Quarentena - 0 Removido - 2 Falha na Remoção - 0 17/11/2009 12:22:00:122 Verificação Iniciada Tipo de Verificação - Intelli-Scan 17/11/2009 12:22:03:142 Detectada uma infecção neste computador Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 12:23:43:269 Verificação Concluída Tipo de Verificação - Intelli-Scan Itens Processados - 295318 Ameaças Detectadas - 1 Infecções Detectadas - 1 Infecções Ignoradas - 0 17/11/2009 12:23:47:761 Infecção excluída Nome da Ameaça - Adware.Advertising Tipo - Cookie Nível de Risco - Baixo Infecção - atdmt.com/ atdmt.com 17/11/2009 12:23:49:795 Resumo de Infecções em Quarentena/Removidas Quarentena - 0 Falha na Quarentena - 0 Removido - 1 Falha na Remoção - 0 OK! fico aguardando resposta! grande abraço. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Novembro 17, 2009 :thumbsup: Vários outros problemas foram removidos pelo Spyware Doctor. ______________________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download do ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Clique em “SIM” para continuar. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console antes de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADO COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log dele estará em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO ou caso os virus ou malwares bloqueiem a execução do Combofix, baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Neste caso, nomeie-o como Kombofix durante o salvamento e não após salvá-lo! Em último caso, se não for possível executar o Combofix no Modo Normal do Windows, tente utilizar o ComboFix em MODO SEGURO (reiniciando o computador e pressionando a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização e escolha a opção Modo Seguro na tela que se apresenta) e repita o procedimento; OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. * Se por algum motivo você precisar parar ou sair do ComboFix, tecle "N". * Se perder a conexão com a internet, reinicie o computador. Caso o problema persista, abra Conexões de Rede no Painel de Controle, clique com o botão direito do mouse sobre a sua conexão com a internet e em "Reparar"; Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
cicerod2 0 Denunciar post Postado Novembro 17, 2009 olá antonio, bem meu pc ta funcionando normalmente e com os programas que você indicou ja consegui retirar alguns virus. passei o combofix vou postar o log para analise combofix ComboFix 09-11-17.03 - cicero 17/11/2009 13:48.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1033.18.2005.1364 [GMT -2:00] Executando de: c:\documents and settings\cicero\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1356 [VPS 091117-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Start Menu\Internet Explorer.lnk c:\documents and settings\cicero\Dados de aplicativos\Desktopicon c:\documents and settings\cicero\Dados de aplicativos\Desktopicon\eBayShortcuts.exe c:\documents and settings\cicero\Dados de aplicativos\Desktopicon\mc.ico c:\windows\System32\Drivers\iaStor.sys . . . está infectado!! . (((((((((((((((( Arquivos/Ficheiros criados de 2009-10-17 to 2009-11-17 )))))))))))))))))))))))))))) . 2009-11-17 15:32 . 2004-08-03 22:59 95360 -c--a-w- c:\windows\system32\dllcache\atapi.sys 2009-11-17 15:32 . 2004-08-03 22:59 95360 ----a-w- c:\windows\system32\drivers\atapi.sys 2009-11-17 13:49 . 2009-11-17 13:49 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-11-17 13:42 . 2008-12-11 10:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-11-17 13:42 . 2009-04-03 13:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-11-17 13:42 . 2008-12-18 14:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-11-17 13:42 . 2009-11-17 13:46 -------- d-----w- c:\program files\Common Files\PC Tools 2009-11-17 13:42 . 2008-12-10 13:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2009-11-17 13:41 . 2009-11-17 13:46 -------- d-----w- c:\program files\Spyware Doctor 2009-11-17 13:41 . 2009-11-17 13:41 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\PC Tools 2009-11-17 13:41 . 2009-11-17 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-11-16 17:28 . 2009-11-16 17:28 -------- d-----w- c:\program files\ESET 2009-11-16 17:22 . 2009-11-16 17:22 -------- d-----w- c:\program files\Sophos 2009-11-16 15:50 . 2009-11-16 15:50 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\Malwarebytes 2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-11-16 15:05 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-16 15:05 . 2009-11-16 15:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-11-16 15:05 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-11-16 12:12 . 2009-11-16 12:12 -------- d-----w- c:\program files\PhotoZoom Pro 3 2009-11-16 11:27 . 2009-11-16 11:37 -------- d-----w- C:\New Folder 2009-11-13 18:42 . 2009-11-13 18:44 -------- dc-h--w- c:\windows\ie8 2009-11-13 18:28 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-11-13 18:28 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-11-13 18:28 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-11-13 18:28 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-11-13 18:28 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-11-13 18:28 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-11-10 18:15 . 2008-10-16 16:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-11-10 15:20 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll 2009-11-10 15:20 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll 2009-11-10 15:20 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll 2009-11-10 15:20 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll 2009-11-10 15:20 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll 2009-11-10 15:20 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll 2009-11-10 15:20 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll 2009-11-10 15:20 . 2009-01-07 18:14 60273 ----a-w- c:\windows\system32\pthreadGC2.dll 2009-11-10 15:20 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2009-11-10 15:20 . 2009-11-10 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack 2009-11-06 13:06 . 2009-11-06 13:06 2996 ----a-w- c:\windows\system32\drivers\hwinterface.sys 2009-11-05 12:57 . 2009-11-11 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet 2009-11-05 12:47 . 2009-09-15 09:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-11-05 12:47 . 2009-09-15 09:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-11-05 12:47 . 2009-09-15 09:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2009-11-05 12:47 . 2009-09-15 09:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-11-05 12:47 . 2009-09-15 09:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-11-05 12:47 . 2009-09-15 09:53 97480 ----a-w- c:\windows\system32\AvastSS.scr 2009-11-05 12:47 . 2009-09-15 09:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys 2009-11-05 12:47 . 2009-09-15 09:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2009-11-05 12:47 . 2009-09-15 09:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe 2009-11-05 12:47 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll 2009-11-05 12:47 . 2009-11-05 12:47 -------- d-----w- c:\program files\Alwil Software 2009-11-05 12:04 . 2008-08-05 01:00 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\AVGTOOLBAR 2009-11-05 11:57 . 2009-11-05 12:03 -------- d-----w- C:\$AVG 2009-11-05 11:57 . 2009-11-05 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2009-11-04 10:55 . 2009-09-23 11:41 26176 ---ha-w- c:\windows\system32\hamachi.sys 2009-11-04 10:54 . 2009-11-04 10:54 -------- d-----w- c:\program files\LogMeIn Hamachi 2009-11-03 14:24 . 2009-11-03 16:07 -------- d-----w- C:\PRO EVOLUTION SOCCER 2009 2009-11-03 11:00 . 2009-11-04 10:52 -------- d-----w- c:\program files\DAEMON Tools Lite 2009-10-30 19:53 . 2009-10-30 19:53 -------- d-----w- c:\program files\Common Files\Macrovision Shared 2009-10-29 10:39 . 2009-10-28 18:38 -------- d--h--r- c:\documents and settings\cicero\Dados de aplicativos\SecuROM 2009-10-28 18:25 . 2009-10-28 18:25 -------- d-----w- c:\program files\Elaborate Bytes 2009-10-27 13:56 . 2001-10-28 20:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll 2009-10-27 13:56 . 1998-07-06 04:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL 2009-10-27 13:56 . 2009-10-27 13:57 -------- d-----w- c:\program files\PDFCreator 2009-10-23 14:04 . 2009-11-17 15:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi 2009-10-20 16:16 . 2009-10-20 16:16 -------- d-----w- c:\documents and settings\cicero\html . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-17 15:44 . 2009-07-01 19:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-11-17 15:44 . 2005-04-05 17:21 -------- d-----w- c:\program files\C4ebreg 2009-11-17 11:29 . 2009-04-02 12:21 -------- d-----w- c:\program files\Common Files\Edutec Sistemas 2009-11-13 13:21 . 2009-11-13 13:14 -------- d-----w- c:\windows\Fonts\4000 Fuentes 2009-11-12 18:33 . 2009-09-24 12:32 -------- d-----w- c:\program files\URUSoft 2009-11-11 20:09 . 2009-04-24 11:35 -------- d-----w- c:\program files\Google 2009-11-11 18:42 . 2006-04-12 02:08 -------- d-----w- c:\program files\Common Files\Adobe 2009-11-10 11:29 . 2009-04-01 17:27 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-11-06 11:45 . 2009-04-27 12:16 204800 ----a-r- c:\documents and settings\cicero\Dados de aplicativos\Microsoft\Installer\{BF14F624-CC30-4E30-8E2B-D86996EB11C9}\NewShortcut1.83127830_6290_4E1E_87F9_DC629969AA98.exe 2009-11-06 11:45 . 2009-04-27 12:16 10134 ----a-r- c:\documents and settings\cicero\Dados de aplicativos\Microsoft\Installer\{BF14F624-CC30-4E30-8E2B-D86996EB11C9}\ARPPRODUCTICON.exe 2009-11-05 12:35 . 2009-09-24 14:27 -------- d-----w- c:\program files\Gabest 2009-11-05 11:57 . 2009-04-01 17:27 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-11-05 11:57 . 2009-04-01 17:27 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-11-05 11:57 . 2009-04-01 17:27 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2009-11-05 11:57 . 2009-04-01 17:27 -------- d-----w- c:\program files\AVG 2009-11-03 11:00 . 2009-07-21 11:13 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-11-03 11:00 . 2009-07-21 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite 2009-10-29 14:16 . 2005-04-05 19:45 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-23 14:10 . 2009-04-29 13:20 -------- d-----w- c:\program files\UltraVNC 2009-10-20 16:32 . 2009-08-07 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-10-20 11:31 . 2009-07-27 17:43 -------- d-----w- c:\program files\DAP 2009-10-08 22:11 . 2009-10-09 11:57 7266304 ---ha-w- c:\documents and settings\cicero\prf75.tmp 2009-09-23 13:41 . 2009-09-23 13:41 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys 2009-09-22 16:44 . 2009-09-22 16:44 -------- d-----w- c:\program files\Webteh 2009-09-22 16:18 . 2009-09-22 16:18 -------- d-----w- c:\documents and settings\cicero\Dados de aplicativos\InterVideo 2009-09-04 19:44 . 2009-11-03 16:06 515416 ----a-w- c:\windows\system32\XAudio2_5.dll 2009-09-04 19:44 . 2009-11-03 16:06 238936 ----a-w- c:\windows\system32\xactengine3_5.dll 2009-09-04 19:44 . 2009-11-03 16:06 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll 2009-09-04 19:29 . 2009-11-03 16:06 453456 ----a-w- c:\windows\system32\d3dx10_42.dll 2009-09-04 19:29 . 2009-11-03 16:06 235344 ----a-w- c:\windows\system32\d3dx11_42.dll 2009-09-04 19:29 . 2009-11-03 16:06 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll 2009-09-04 19:29 . 2009-11-03 16:06 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll 2009-09-04 19:29 . 2009-11-03 16:06 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll 2009-09-03 13:04 . 2009-07-29 11:42 83456 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll 2009-08-29 08:08 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-10-20 2803200] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "stgclean"="c:\sdwork\w32main2.exe" [2007-10-24 266752] "Tpam.exe"="c:\program files\IBM\Personal Communications\tpam.exe" [2005-09-06 28672] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-21 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-21 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-21 137752] "MyHelpService"="c:\program files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe" [2006-12-19 81920] "pmonmh"="c:\program files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe" [2007-09-17 188416] "C4EBReg"="c:\program files\C4ebreg\c4ebreg.exe" [2007-09-07 364544] "ISAMTray"="c:\program files\C4ebreg\isamtray.exe" [2007-09-07 237568] "w32msgr"="c:\sdwork\W32MAIN2.exe" [2007-10-24 266752] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384] "Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056] c:\documents and settings\carolina\Menu Iniciar\Programas\Inicializar\ UltraVNC Server.lnk - \\Ibm-4ce866f99f7\c$\Program Files\UltraVNC\winvnc.exe [2008-10-23 1148480] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Lotus QuickStart.lnk - c:\lotus\wordpro\ltsstart.exe [2003-4-7 32768] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "disablecad"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDeletePrinter"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-11-05 11:57 12464 ----a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst] 2005-09-06 18:43 49152 ----a-w- c:\windows\system32\pcsinst.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 "IBMconfig"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\PRO EVOLUTION SOCCER 2009\\pes2009.exe"= R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [17/11/2009 11:42 130936] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [05/11/2009 10:47 114768] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [01/04/2009 15:27 333192] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [01/04/2009 15:27 360584] R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [06/11/2009 11:06 2996] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/11/2009 10:47 20560] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [05/11/2009 09:57 285392] R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29/10/2009 12:27 1074568] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [06/07/2009 15:11 133104] S2 vuphzubwyjo;vuphzubwyjo;\??\c:\windows\system32\drivers\sgpgpkjhm.sys --> c:\windows\system32\drivers\sgpgpkjhm.sys [?] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\35.tmp --> c:\windows\system32\35.tmp [?] S3 usb2vcom;USB Data Cable;c:\windows\system32\drivers\usb2vcom.sys [28/04/2009 12:36 22760] --- =Outros Serviços/Drivers Na Memória --- *NewlyCreated* - CLASSPNP_2 *Deregistered* - CLASSPNP_2 *Deregistered* - mbr *Deregistered* - mchInjDrv *Deregistered* - PROCEXP113 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs bcbksc iyiyb jbqeilpvy . Conteúdo da pasta 'Tarefas Agendadas' 2009-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-06 17:11] 2009-11-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-06 17:11] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ mWindow Title = uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\DAP\dapextie.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {A152453C-986E-4F8B-B789-D8E955F06321} = 192.168.0.3,192.168.0.1 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} - hxxp:// DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab . - - - - ORFÃOS REMOVIDOS - - - - Notify-atmgrtok - atmgrtok.dll Notify-NavLogon - (no file) AddRemove-HijackThis - c:\docume~1\cicero\CONFIG~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-17 13:56 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A64F1F8]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf763bfc3 \Driver\ACPI -> ACPI.sys @ 0xf74a3cb8 \Driver\atapi -> 0x8a64f1f8 \Driver\iaStor -> iaStor.sys @ 0xf7b4a7b0 IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel® 82566DM-2 Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xba75bba0 PacketIndicateHandler -> NDIS.sys @ 0xba768b21 SendHandler -> NDIS.sys @ 0xba74687b Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql] "ImagePath"="C:/mysql/bin/mysqld-max.exe" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\35.tmp" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql] "ImagePath"="C:/mysql/bin/mysqld-max.exe" . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{18DFA061-844F-31F3-4A29-094E24333070}*] "kafafaiggcfnjeddnmjdim"=hex:62,61,64,6a,00,02 [HKEY_USERS\S-1-5-21-2410898130-1753892677-3868454632-1126\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2E3A949E-ABEE-514C-A578-42C96B21D1F4}*] "kabhkhhjkbjiaadfjbhfml"=hex:62,61,6c,6c,00,00 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(584) c:\program files\IBM\Personal Communications\atmgrtok.dll c:\program files\IBM\Personal Communications\MILLUTIL.DLL c:\windows\system32\pcsinst.dll . Tempo para conclusão: 2009-11-17 13:58 ComboFix-quarantined-files.txt 2009-11-17 15:58 Pré-execução: 133.250.404.352 bytes free Pós execução: 133.367.963.648 bytes free - - End Of File - - FA92A4E333E89E03DEAC0239BE7AFD95 log hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:14:16, on 17/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Drivers\trcboot.exe C:\Program Files\IBM\Personal Communications\PCS_AGNT.EXE C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\C4ebreg\c4ebreg.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\notes\ntmulti.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Drivers\ldlcserv.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\IBM\Personal Communications\tpam.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.common_1.2.25\pmonmh.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\C4ebreg\isamtray.exe C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\DAP\DAP.EXE C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\DOCUME~1\cicero\CONFIG~1\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup O4 - HKLM\..\Run: [Tpam.exe] "C:\Program Files\IBM\Personal Communications\tpam.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [MyHelpService] C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\delayStart.exe O4 - HKLM\..\Run: [pmonmh] C:\Program Files\IBM\My Help\plugins\\com.ibm.myhelp.common_1.2.25/pmonmh.exe O4 - HKLM\..\Run: [C4EBReg] "C:\Program Files\C4ebreg\c4ebreg.exe" /q O4 - HKLM\..\Run: [iSAMTray] "C:\Program Files\C4ebreg\isamtray.exe" O4 - HKLM\..\Run: [w32msgr] C:\SDWORK\W32MAIN2.exe /log C:\SDWORK\MSGR.TXT OSPDB.POK.IBM.COM O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - Global Startup: Lotus QuickStart.lnk = ? O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com O16 - DPF: {1ACECAFE-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189037145890 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194968075000 O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} (Java2 Runtime Environment 1.5.0) - http:// O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\Software\..\Telephony: DomainName = liceu-fabes.spba O17 - HKLM\System\CCS\Services\Tcpip\..\{A152453C-986E-4F8B-B789-D8E955F06321}: NameServer = 192.168.0.3,192.168.0.1 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = liceu-fabes.spba O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = IBM.COM O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AppnNode - IBM Corporation - C:\WINDOWS\system32\Drivers\appnnode.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing) O23 - Service: IBM Standard Asset Manager Service (ISAMSvc) - IBM Corp. - C:\Program Files\C4ebreg\c4ebreg.exe O23 - Service: IBM Enterprise Extender (ldlcserv) - IBM Corporation - C:\WINDOWS\system32\Drivers\ldlcserv.exe O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\notes\ntmulti.exe O23 - Service: My Help (MyHelp) - Unknown owner - C:\Program Files\IBM\My Help\plugins\com.ibm.myhelp.installer\service\MyHelpService.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-max.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: SAVRoam (SavRoam) - Unknown owner - c:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe O23 - Service: IBM Trace Facility (TrcBoot) - IBM Corporation - C:\WINDOWS\system32\Drivers\trcboot.exe -- End of file - 11979 bytes estarei aguardando retorno. abraço. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Novembro 17, 2009 :seta: Baixe o FixPolicies: http://www.virus-protect.org/exxe/FixPolicies.exe * Dê um duplo click no arquivo FixPolicies e em Executar * Será criada uma pasta com o nome FixPolicies * Abra a pasta e dê um duplo click no arquivo Fix Policies.cmd *Aparecerá uma tela preta e rapidamente desaparecerá.Ignore qualquer aviso de erro; *Reinicie o computador _____________________________________ :seta: Vá no menu: Iniciar > Painel de Controle > Opções de Pasta * Selecione a aba Modo de exibição * Selecione o botão Mostrar pastas e arquivos ocultos * Desmarque a caixa Ocultar arquivos protegidos do sistema operacional (recomendado) * Clique em OK Envie estes arquivos destacados em vermelho abaixo para serem analisados no site http://virscan.org/ c:\windows\System32\Drivers\iaStor.sys c:\windows\system32\drivers\sgpgpkjhm.sys _____________________________________ :seta: Selecione o texto abaixo dentro do Quote (caixa branca abaixo) e copie para o Bloco de notas. Salve-o no desktop (área de trabalho) como CFScript.txt File::c:\documents and settings\cicero\prf75.tmp C:\WINDOWS\SYSTEM32\pcsinst.dll Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000000 "FirewallOverride"=dword:00000000 [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pcsinst] NetSvc:: bcbksc iyiyb jbqeilpvy ________________________________________ :seta: Depois disto siga as dicas deste tutorial: Tutorial do Kaspersky Virus Removal Tool Na sua próxima resposta poste este log do Kaspersky Virus Removal Tool __________________________________ :seta: Faça o download desta ferramenta no link abaixo e salve-a no desktop (área de trabalho): http://www2.gmer.net/mbr/mbr.exe Dê um duplo clique sobre ela e será gerado um log que estará na sua área de trabalho. Dê um duplo clique sobre este log (mbr.log) > copie o conteúdo dele e poste-o em sua próxima resposta juntamente com o log do Kaspersky Virus Removal Tool, os links com o resultado do escaneamento dos dois arquivos no site VirSCAN e um novo log do Hijackthis e nos diga como está seu PC depois disto. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Dezembro 17, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites