Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

lynna

[Resolvido!] PC reiniciando sozinho

Recommended Posts

Boa tarde, minha maquina utimamente tem reiniciado sozinha, e ao ligar aparece a seguinte mensagem "O Sistetema se recuperou de um erro grave" e seguinte log

assinatura do erro:

 

BCCode:1000000a BCP1:FFFFFFFC BCP:000000FF BCP3:00000000

BCP4:804DB973 0SVer:5_1_2600 SP:2_0 Product:256_1

 

Conteúdo do relatorio de erros

Os seguintes arquivos serão incluídos no relatorio de erros

C:\DOCUME~1\ASMINI~1\CONFIG~1\Temp\WER3c18.dir00\Mini020310-01.dmp

C:\DOCUME~1\ASMINI~1\CONFIG~1\Temp\WER3c18.dir00\sysdata.xml

 

por favor me ajude, desde já agradeço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Post um log conforme Regra 2 deste fórum

 

http://forum.imasters.com.br/index.php?showtopic=165906

Compartilhar este post


Link para o post
Compartilhar em outros sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:02:Juh, on 6/2/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\NCLAUNCH.EXe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe

O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized

O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe

O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: privtorador - Unknown owner - cmd.exe (file missing)

 

--

End of file - 8400 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde....

 

*Desative temporariamente seu antivírus

 

Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme.

*Baixe o ComboFix e salve-o no desktop

*Duplo-clique no arquivo Combofix.exe

*Aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso não esteja, uma janela conforme abaixo será aberta. Clique em [sIM] para aceitar a instalação do mesmo.

 

recovery-console-prompt.jpg

 

*Após a instalação, clique em [sIM] para continuar.

 

recovery-console-installed.jpg

 

*Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER.

 

*O programa será fechado automaticamente

 

*Cole o relatório criado em C:\combofix.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde....

 

1.

*Clique em [iniciar] > [Executar] > digite: Combofix /uninstall

*Clique [OK]

 

92674490.jpg

 

*Clique em [Executar]

*Surgirá a mensagem: "ComboFix está desinstalado"

 

*Clique [OK]

 

2.

*O PROCEDIMENTO ABAIXO SÓ PODERÁ SER FEITO USANDO O INTERNET EXPLORER

*Desative seu antivírus temporariamente

 

Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme.

*Faça um scan online com o NOD32 seguindo este tutorial

http://dicasetutoriaisparapc.blogspot.com/search/label/Tutorial%20do%20antivirus%20Nod32%20Online

*Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log

Compartilhar este post


Link para o post
Compartilhar em outros sites

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=ffffd6ae1647454da70bce88e24a35d7

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-02-13 05:03:34

# local_time=2010-02-13 03:03:34 (-0300, Horário brasileiro de verão)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=769 16775141 100 98 0 201454345 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=1251

# found=0

# cleaned=0

# scan_time=268

esets_scanner_update returned -1 esets_gle=53251

esets_scanner_update returned -1 esets_gle=53251

# version=7

# IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=ffffd6ae1647454da70bce88e24a35d7

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-02-14 09:43:42

# local_time=2010-02-14 07:43:42 (-0300, Horário brasileiro de verão)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=769 16775141 100 98 0 201557537 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=1255

# found=0

# cleaned=0

# scan_time=275

Compartilhar este post


Link para o post
Compartilhar em outros sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:09 Juh, on 15/2/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\NCLAUNCH.EXe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe

O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized

O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe

O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: privtorador - Unknown owner - cmd.exe (file missing)

 

--

End of file - 8577 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o MalwareBytes Anti-malwaree salve-o no desktop:

*Instale o programa

*Se alguma atualização existir,o download será automático. Aguarde...

*O programa será aberto automaticamente.

*Na aba [Verificação], selecione a opção [Verificação completa]

*Clique em [Verificar] e selecione as unidades a serem examinadas

*Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados]

*Selecione todos os resultados e clique em [Remover Selecionados]

*Um relatório (mbam-log-ano-mês-data.txt) será apresentado.

*Reinicie o PC

*Abra novamente o programa Malwarebytes e na aba [Logs] clique no arquivo mbam-log-ano-mês-data.txt

*Clique em [Abrir], copie, cole-o na sua próxima resposta e novo log do hijack

Compartilhar este post


Link para o post
Compartilhar em outros sites

Malwarebytes' Anti-Malware 1.44

Versão do banco de dados: 3743

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

 

16/2/2010 01:12:56 Juh

mbam-log-2010-02-16 (01-12-56).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 172098

Tempo decorrido: 1 hour(s), 41 minute(s), 10 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 2

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

C:\System Volume Information\_restore{6A7A1BD8-170B-4BE9-8FA0-41DF91278CDB}\RP258\A0931752.com (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\emplite.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

 

------------------------------------------------------------------------------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:33 Juh, on 16/2/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\VTTimer.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\NCLAUNCH.EXe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe

C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe

O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized

O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe

O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: privtorador - Unknown owner - cmd.exe (file missing)

 

--

End of file - 8417 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Remover tudo]

*Clique na aba [Logs], selecione o relatório e clique em [Remover]

 

2.

*Clique em [iniciar] > [Executar] > digite: services.msc

*Localize o Serviço privtorador , dê um duplo clique nele e em "Tipo de inicialização" clique em [Desativado]. Clique também em [Parar] > [Aplicar] > [OK]

 

3.

*Execute o HijackThis, clique em [Misc Tools] > [Delete an NT service...], coloque o serviço privtorador e clique em [Ok]. Quando perguntado se deseja reiniciar agora, clique em [sIM]

 

4.

*Baixe o OTL e salve-o no desktop

*Duplo clique em OTL.exe

*Selecione as opções abaixo:

 

[x] Scan All Users

[x[ Minimal Output

[x] Use Company Name WhiteList

[x] Skip Microsoft Files

[x] LOP Check

[x] Purity Check

*Em Custom Scans/Fixes cole o código abaixo:

 

netsvcs

%SYSTEMDRIVE%\

CREATERESTOREPOINT

*Clique em [Run Scan] e aguarde o término do processo

*Dois relatórios serão criados no desktop chamados: OTL.txt e Extras.txt

*Cole o relatório OTL.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...

 

1.

*Delete o programa OTL

 

2.

*Baixe o DDS e salve-o no desktop

*Desative temporariamente seu antiví­rus

 

Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme.

*Duplo clique em dds e aguarde. Salve os relatórios no desktop

*Cole o relatório criado em DDS.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

DDS (Ver_09-12-01.01) - NTFSx86

Run by Administrador at 17:07:46,29 on qua 17/02/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.238.24 [GMT -2:00]

 

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\NCLAUNCH.EXe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Windows Live\Toolbar\wltuser.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Administrador\Desktop\dds.scr

 

============== Pseudo HJT Report ===============

 

uSearch Page = hxxp://search.live.com

uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703

uSearch Bar = hxxp://search.live.com/sphome.aspx

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://search.live.com/sphome.aspx

BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\arquivos de programas\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll

BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\arquivos de programas\windows live\toolbar\wltcore.dll

TB: &Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll

TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\arquivos de programas\windows live\toolbar\wltcore.dll

TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File

TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File

TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [PcSync] c:\arquivos de programas\nokia\nokia pc suite 6\PcSync2.exe /NoDialog

uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe

uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray

uRun: [NitroPC] "c:\arquivos de programas\nitropc\NitroPC.exe" -minimized

uRun: [skwi372sm.exe] c:\windows\system32\skwi372sm.exe

uRun: [p3jsz8wer.exe] c:\windows\system32\p3jsz8wer.exe

mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre1.6.0_05\bin\jusched.exe"

mRun: [VTTimer] VTTimer.exe

mRun: [VTTrayp] VTtrayp.exe

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [soundMan] SOUNDMAN.EXE

mRun: [QuickTime Task] "c:\arquivos de programas\quicktime\qttask.exe" -atboottime

mRun: [TkBellExe] "c:\arquivos de programas\arquivos comuns\real\update_ob\realsched.exe" -osboot

mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe

mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [MsnMsgr] "c:\arquivos de programas\msn messenger\MsnMsgr.Exe" /background

dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"

dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe

StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\is-n9ea9.lnk - c:\documents and settings\administrador\desktop\virus removal tool\is-n9ea9\startup.exe

StartupFolder: c:\docume~1\alluse~1\menuin~1\progra~1\inicia~1\micros~1.lnk - c:\arquivos de programas\microsoft office\office10\OSA.EXE

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office10\EXCEL.EXE/3000

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\arquivos de programas\windows live\writer\WriterBrowserExtension.dll

DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab

DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://img2.orkut.com/activex/10035/photouploader.cab

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab

TCP: {3CD60846-44C9-4FC2-BF3C-17BF170C48DC} = 10.1.22.3

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\arquivos de programas\arquivos comuns\microsoft shared\web folders\PKMCDO.DLL

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

LSA: Authentication Packages = msv1_0 nwprovau

Hosts: 0.0.0.0 www.adcopy.info

Hosts: 0.0.0.0 classic.adlink.de #[iE-SpyAd]

Hosts: 0.0.0.0 regio.adlink.de

Hosts: 0.0.0.0 west.adlink.de

Hosts: 0.0.0.0 ad.ads.dk #[iE-SpyAd]

 

Note: multiple HOSTS entries found. Please refer to Attach.txt

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\admini~1\dadosd~1\mozilla\firefox\profiles\kf8vjucm.default\

FF - prefs.js: browser.search.selectedEngine - Ask

FF - component: c:\documents and settings\administrador\dados de aplicativos\mozilla\firefox\profiles\kf8vjucm.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll

FF - plugin: c:\arquivos de programas\google\update\1.2.183.13\npGoogleOneClick8.dll

FF - plugin: c:\arquivos de programas\microsoft\office live\npOLW.dll

FF - plugin: c:\arquivos de programas\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

 

============= SERVICES / DRIVERS ===============

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-8 114768]

R1 is-N9EA9drv;is-N9EA9drv;c:\windows\system32\drivers\82375415.sys [2009-9-10 148496]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-8 20560]

R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-5-8 138680]

S2 gupdate1ca5745167fc474;Google Update Service (gupdate1ca5745167fc474);c:\arquivos de programas\google\update\GoogleUpdate.exe [2009-10-27 133104]

S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-5-8 254040]

S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-5-8 352920]

S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2010-1-16 83496]

S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2010-1-16 15016]

S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2010-1-16 109992]

S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2010-1-16 103976]

S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2010-1-16 100008]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]

S3 SQTECH9160;Digital Camera;c:\windows\system32\drivers\Capt9160.sys [2006-10-27 45711]

S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2007-3-20 87824]

S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2007-3-20 85696]

S4 svService;service;c:\windows\system32\service.exe --> c:\windows\system32\service.exe [?]

 

=============== Created Last 30 ================

 

2010-02-16 00:14:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-16 00:14:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-16 00:14:03 0 d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-02-14 21:52:52 279 ----a-w- C:\Atalho para Disco local ©.lnk

2010-02-13 16:20:53 0 d-sh--w- c:\documents and settings\administrador\PrivacIE

2010-02-13 16:20:49 0 d-sh--w- c:\documents and settings\administrador\IECompatCache

2010-02-13 15:34:13 0 d-sh--w- c:\documents and settings\administrador\IETldCache

2010-02-13 14:44:01 0 d-----w- c:\windows\ie8updates

2010-02-13 14:39:53 0 dc-h--w- c:\windows\ie8

2010-02-13 14:34:16 69120 ------w- c:\windows\system32\dllcache\iecompat.dll

2010-02-13 14:33:59 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll

2010-02-13 14:33:58 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll

2010-02-13 14:33:57 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll

2010-02-13 14:33:57 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll

2010-02-13 14:33:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

2010-02-13 14:33:54 11070464 ------w- c:\windows\system32\dllcache\ieframe.dll

2010-02-11 13:47:19 0 d-s---w- C:\ComboFix

2010-02-10 22:52:32 0 d-sha-r- C:\cmdcons

2010-02-09 15:41:53 98816 ----a-w- c:\windows\sed.exe

2010-02-09 15:41:53 77312 ----a-w- c:\windows\MBR.exe

2010-02-09 15:41:53 261632 ----a-w- c:\windows\PEV.exe

2010-02-09 15:41:53 161792 ----a-w- c:\windows\SWREG.exe

2010-02-06 14:01:03 7168 --sha-w- c:\windows\Thumbs.db

2010-02-01 11:56:49 0 d-----w- c:\arquivos de programas\Avanquest update

2010-01-28 23:36:22 0 d-----w- c:\arquivos de programas\Conduit

 

==================== Find3M ====================

 

2010-02-16 18:14:25 12635492 --sha-w- c:\windows\system32\drivers\fidbox.idx

2010-02-16 18:14:25 1131956256 --sha-w- c:\windows\system32\drivers\fidbox.dat

2010-02-13 15:31:47 90112 ----a-w- c:\windows\DUMP3c9b.tmp

2010-02-12 16:58:21 90112 ----a-w- c:\windows\DUMP3aa7.tmp

2010-02-12 16:57:44 90112 ----a-w- c:\windows\DUMP3b24.tmp

2010-02-12 14:28:36 90112 ----a-w- c:\windows\DUMP3fc8.tmp

2010-02-11 14:04:08 90112 ----a-w- c:\windows\DUMP4110.tmp

2010-02-10 22:38:26 90112 ----a-w- c:\windows\DUMP3f99.tmp

2010-02-10 12:54:26 90112 ----a-w- c:\windows\DUMP3e70.tmp

2010-01-13 23:22:43 2039808 ----a-w- c:\windows\system32\skwi372sm.exe

2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-31 16:14:12 352640 ------w- c:\windows\system32\dllcache\srv.sys

2009-12-22 05:41:39 1506304 ------w- c:\windows\system32\dllcache\shdocvw.dll

2009-12-22 05:41:33 55808 ------w- c:\windows\system32\dllcache\extmgr.dll

2009-12-22 05:41:33 1055744 ------w- c:\windows\system32\dllcache\danim.dll

2009-12-22 05:41:32 151552 ------w- c:\windows\system32\dllcache\cdfview.dll

2009-12-22 05:41:32 1024000 ------w- c:\windows\system32\dllcache\browseui.dll

2009-12-21 19:08:00 916480 ----a-w- c:\windows\system32\wininet.dll

2009-12-21 19:08:00 916480 ------w- c:\windows\system32\dllcache\wininet.dll

2009-12-21 19:08:00 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll

2009-12-21 19:07:59 5942784 ------w- c:\windows\system32\dllcache\mshtml.dll

2009-12-21 19:07:59 206848 ------w- c:\windows\system32\dllcache\occache.dll

2009-12-21 19:07:56 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll

2009-12-21 19:07:55 184320 ------w- c:\windows\system32\dllcache\iepeers.dll

2009-12-21 19:07:52 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll

2009-12-21 13:22:00 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe

2009-12-17 07:59:45 345600 ----a-w- c:\windows\system32\mspaint.exe

2009-12-17 07:59:45 345600 ------w- c:\windows\system32\dllcache\mspaint.exe

2009-12-16 12:57:07 18432 ------w- c:\windows\system32\dllcache\iedw.exe

2009-12-14 07:36:35 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-14 07:36:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll

2009-12-11 18:37:05 76620 ----a-w- c:\windows\system32\perfc016.dat

2009-12-11 18:37:05 461968 ----a-w- c:\windows\system32\perfh016.dat

2009-12-09 10:27:05 2061952 ----a-w- c:\windows\system32\ntkrnlpa.exe

2009-12-09 10:27:05 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-12-09 10:27:04 2184576 ----a-w- c:\windows\system32\ntoskrnl.exe

2009-12-09 10:27:04 2184576 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2009-12-09 10:27:02 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-12-09 10:26:59 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2009-12-08 09:12:53 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll

2009-12-04 14:41:55 453760 ------w- c:\windows\system32\dllcache\mrxsmb.sys

2009-11-27 17:34:48 17920 ----a-w- c:\windows\system32\msyuv.dll

2009-11-27 17:34:48 17920 ------w- c:\windows\system32\dllcache\msyuv.dll

2009-11-27 17:34:48 1295872 ----a-w- c:\windows\system32\quartz.dll

2009-11-27 17:34:48 1295872 ------w- c:\windows\system32\dllcache\quartz.dll

2009-11-27 16:40:12 8704 ----a-w- c:\windows\system32\tsbyuv.dll

2009-11-27 16:40:12 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll

2009-11-27 16:40:12 48128 ----a-w- c:\windows\system32\iyuv_32.dll

2009-11-27 16:40:12 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll

2009-11-27 16:40:12 28672 ----a-w- c:\windows\system32\msvidc32.dll

2009-11-27 16:40:12 28672 ------w- c:\windows\system32\dllcache\msvidc32.dll

2009-11-27 16:40:12 11264 ----a-w- c:\windows\system32\msrle32.dll

2009-11-27 16:40:12 11264 ------w- c:\windows\system32\dllcache\msrle32.dll

2009-11-27 16:40:11 85504 ----a-w- c:\windows\system32\avifil32.dll

2009-11-27 16:40:11 85504 ------w- c:\windows\system32\dllcache\avifil32.dll

2009-11-21 16:42:23 470528 ------w- c:\windows\system32\dllcache\aclayers.dll

2004-10-01 18:00:16 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe

 

============= FINISH: 17:09:36,54 ===============

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Execute o hijack, clique em [Do a system scan only], selecione as entradas abaixo e clique em [Fix checked]

 

O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe

O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe

*Feche o hijack

 

2.

*Baixe o Avenger e extraia o conteúdo para o desktop

*Selecione e copie (Ctrl+C) todo o código abaixo:

 

Files to delete:

c:\windows\system32\skwi372sm.exe

c:\windows\system32\p3jsz8wer.exe

c:\windows\system32\service.exe

c:\windows\DUMP3c9b.tmp

c:\windows\DUMP3aa7.tmp

c:\windows\DUMP3b24.tmp

c:\windows\DUMP3fc8.tmp

c:\windows\DUMP4110.tmp

c:\windows\DUMP3f99.tmp

c:\windows\DUMP3e70.tmp

 

Drivers to disable:

svService

 

Drivers to delete:

svService

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*Cole o relatório criado em C:\avenger.txt e novo log do DDS

Compartilhar este post


Link para o post
Compartilhar em outros sites

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

File "c:\windows\system32\skwi372sm.exe" deleted successfully.

 

Error: file "c:\windows\system32\p3jsz8wer.exe" not found!

Deletion of file "c:\windows\system32\p3jsz8wer.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

 

 

Error: file "c:\windows\system32\service.exe" not found!

Deletion of file "c:\windows\system32\service.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

 

File "c:\windows\DUMP3c9b.tmp" deleted successfully.

File "c:\windows\DUMP3aa7.tmp" deleted successfully.

File "c:\windows\DUMP3b24.tmp" deleted successfully.

File "c:\windows\DUMP3fc8.tmp" deleted successfully.

File "c:\windows\DUMP4110.tmp" deleted successfully.

File "c:\windows\DUMP3f99.tmp" deleted successfully.

File "c:\windows\DUMP3e70.tmp" deleted successfully.

Driver "svService" disabled successfully.

Driver "svService" deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

--------------------------------------------------------------------------------------------------------------------------------------------

 

DDS (Ver_09-12-01.01) - NTFSx86

Run by Administrador at 1:26:39,82 on qui 18/02/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.238.108 [GMT -2:00]

 

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\NCLAUNCH.EXe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Real\RealPlayer\realplay.exe

C:\Documents and Settings\Administrador\Desktop\dds.scr

 

============== Pseudo HJT Report ===============

 

uSearch Page = hxxp://search.live.com

uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703

uSearch Bar = hxxp://search.live.com/sphome.aspx

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://search.live.com/sphome.aspx

BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\arquivos de programas\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll

BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\arquivos de programas\windows live\toolbar\wltcore.dll

TB: &Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll

TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\arquivos de programas\windows live\toolbar\wltcore.dll

TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File

TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File

TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [PcSync] c:\arquivos de programas\nokia\nokia pc suite 6\PcSync2.exe /NoDialog

uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe

uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray

uRun: [NitroPC] "c:\arquivos de programas\nitropc\NitroPC.exe" -minimized

mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre1.6.0_05\bin\jusched.exe"

mRun: [VTTimer] VTTimer.exe

mRun: [VTTrayp] VTtrayp.exe

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [soundMan] SOUNDMAN.EXE

mRun: [QuickTime Task] "c:\arquivos de programas\quicktime\qttask.exe" -atboottime

mRun: [TkBellExe] "c:\arquivos de programas\arquivos comuns\real\update_ob\realsched.exe" -osboot

mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe

mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [MsnMsgr] "c:\arquivos de programas\msn messenger\MsnMsgr.Exe" /background

dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"

dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe

StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\is-n9ea9.lnk - c:\documents and settings\administrador\desktop\virus removal tool\is-n9ea9\startup.exe

StartupFolder: c:\docume~1\alluse~1\menuin~1\progra~1\inicia~1\micros~1.lnk - c:\arquivos de programas\microsoft office\office10\OSA.EXE

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office10\EXCEL.EXE/3000

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\arquivos de programas\windows live\writer\WriterBrowserExtension.dll

DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab

DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://img2.orkut.com/activex/10035/photouploader.cab

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab

TCP: {3CD60846-44C9-4FC2-BF3C-17BF170C48DC} = 10.1.22.3

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\arquivos de programas\arquivos comuns\microsoft shared\web folders\PKMCDO.DLL

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

LSA: Authentication Packages = msv1_0 nwprovau

Hosts: 0.0.0.0 www.adcopy.info

Hosts: 0.0.0.0 classic.adlink.de #[iE-SpyAd]

Hosts: 0.0.0.0 regio.adlink.de

Hosts: 0.0.0.0 west.adlink.de

Hosts: 0.0.0.0 ad.ads.dk #[iE-SpyAd]

 

Note: multiple HOSTS entries found. Please refer to Attach.txt

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\admini~1\dadosd~1\mozilla\firefox\profiles\kf8vjucm.default\

FF - prefs.js: browser.search.selectedEngine - Ask

FF - component: c:\documents and settings\administrador\dados de aplicativos\mozilla\firefox\profiles\kf8vjucm.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll

FF - plugin: c:\arquivos de programas\google\update\1.2.183.13\npGoogleOneClick8.dll

FF - plugin: c:\arquivos de programas\microsoft\office live\npOLW.dll

FF - plugin: c:\arquivos de programas\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

 

============= SERVICES / DRIVERS ===============

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-8 114768]

R1 is-N9EA9drv;is-N9EA9drv;c:\windows\system32\drivers\82375415.sys [2009-9-10 148496]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-8 20560]

R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-5-8 138680]

S2 gupdate1ca5745167fc474;Google Update Service (gupdate1ca5745167fc474);c:\arquivos de programas\google\update\GoogleUpdate.exe [2009-10-27 133104]

S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-5-8 254040]

S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-5-8 352920]

S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2010-1-16 83496]

S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2010-1-16 15016]

S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2010-1-16 109992]

S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2010-1-16 103976]

S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2010-1-16 100008]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]

S3 SQTECH9160;Digital Camera;c:\windows\system32\drivers\Capt9160.sys [2006-10-27 45711]

S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2007-3-20 87824]

S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2007-3-20 85696]

 

=============== Created Last 30 ================

 

2010-02-16 00:14:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-02-16 00:14:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-02-16 00:14:03 0 d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-02-14 21:52:52 279 ----a-w- C:\Atalho para Disco local ©.lnk

2010-02-13 16:20:53 0 d-sh--w- c:\documents and settings\administrador\PrivacIE

2010-02-13 16:20:49 0 d-sh--w- c:\documents and settings\administrador\IECompatCache

2010-02-13 15:34:13 0 d-sh--w- c:\documents and settings\administrador\IETldCache

2010-02-13 14:44:01 0 d-----w- c:\windows\ie8updates

2010-02-13 14:39:53 0 dc-h--w- c:\windows\ie8

2010-02-13 14:34:16 69120 ------w- c:\windows\system32\dllcache\iecompat.dll

2010-02-13 14:33:59 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll

2010-02-13 14:33:58 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll

2010-02-13 14:33:57 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll

2010-02-13 14:33:57 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll

2010-02-13 14:33:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll

2010-02-13 14:33:54 11070464 ------w- c:\windows\system32\dllcache\ieframe.dll

2010-02-11 13:47:19 0 d-s---w- C:\ComboFix

2010-02-10 22:52:32 0 d-sha-r- C:\cmdcons

2010-02-09 15:41:53 98816 ----a-w- c:\windows\sed.exe

2010-02-09 15:41:53 77312 ----a-w- c:\windows\MBR.exe

2010-02-09 15:41:53 261632 ----a-w- c:\windows\PEV.exe

2010-02-09 15:41:53 161792 ----a-w- c:\windows\SWREG.exe

2010-02-06 14:01:03 7168 --sha-w- c:\windows\Thumbs.db

2010-02-01 11:56:49 0 d-----w- c:\arquivos de programas\Avanquest update

2010-01-28 23:36:22 0 d-----w- c:\arquivos de programas\Conduit

 

==================== Find3M ====================

 

2010-02-18 03:12:31 12635492 --sha-w- c:\windows\system32\drivers\fidbox.idx

2010-02-18 03:12:29 1131956256 --sha-w- c:\windows\system32\drivers\fidbox.dat

2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-31 16:14:12 352640 ------w- c:\windows\system32\dllcache\srv.sys

2009-12-22 05:41:39 1506304 ------w- c:\windows\system32\dllcache\shdocvw.dll

2009-12-22 05:41:33 55808 ------w- c:\windows\system32\dllcache\extmgr.dll

2009-12-22 05:41:33 1055744 ------w- c:\windows\system32\dllcache\danim.dll

2009-12-22 05:41:32 151552 ------w- c:\windows\system32\dllcache\cdfview.dll

2009-12-22 05:41:32 1024000 ------w- c:\windows\system32\dllcache\browseui.dll

2009-12-21 19:08:00 916480 ----a-w- c:\windows\system32\wininet.dll

2009-12-21 19:08:00 916480 ------w- c:\windows\system32\dllcache\wininet.dll

2009-12-21 19:08:00 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll

2009-12-21 19:07:59 5942784 ------w- c:\windows\system32\dllcache\mshtml.dll

2009-12-21 19:07:59 206848 ------w- c:\windows\system32\dllcache\occache.dll

2009-12-21 19:07:56 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll

2009-12-21 19:07:55 184320 ------w- c:\windows\system32\dllcache\iepeers.dll

2009-12-21 19:07:52 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll

2009-12-21 13:22:00 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe

2009-12-17 07:59:45 345600 ----a-w- c:\windows\system32\mspaint.exe

2009-12-17 07:59:45 345600 ------w- c:\windows\system32\dllcache\mspaint.exe

2009-12-16 12:57:07 18432 ------w- c:\windows\system32\dllcache\iedw.exe

2009-12-14 07:36:35 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-14 07:36:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll

2009-12-11 18:37:05 76620 ----a-w- c:\windows\system32\perfc016.dat

2009-12-11 18:37:05 461968 ----a-w- c:\windows\system32\perfh016.dat

2009-12-09 10:27:05 2061952 ----a-w- c:\windows\system32\ntkrnlpa.exe

2009-12-09 10:27:05 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-12-09 10:27:04 2184576 ----a-w- c:\windows\system32\ntoskrnl.exe

2009-12-09 10:27:04 2184576 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2009-12-09 10:27:02 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-12-09 10:26:59 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2009-12-08 09:12:53 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll

2009-12-04 14:41:55 453760 ------w- c:\windows\system32\dllcache\mrxsmb.sys

2009-11-27 17:34:48 17920 ----a-w- c:\windows\system32\msyuv.dll

2009-11-27 17:34:48 17920 ------w- c:\windows\system32\dllcache\msyuv.dll

2009-11-27 17:34:48 1295872 ----a-w- c:\windows\system32\quartz.dll

2009-11-27 17:34:48 1295872 ------w- c:\windows\system32\dllcache\quartz.dll

2009-11-27 16:40:12 8704 ----a-w- c:\windows\system32\tsbyuv.dll

2009-11-27 16:40:12 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll

2009-11-27 16:40:12 48128 ----a-w- c:\windows\system32\iyuv_32.dll

2009-11-27 16:40:12 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll

2009-11-27 16:40:12 28672 ----a-w- c:\windows\system32\msvidc32.dll

2009-11-27 16:40:12 28672 ------w- c:\windows\system32\dllcache\msvidc32.dll

2009-11-27 16:40:12 11264 ----a-w- c:\windows\system32\msrle32.dll

2009-11-27 16:40:12 11264 ------w- c:\windows\system32\dllcache\msrle32.dll

2009-11-27 16:40:11 85504 ----a-w- c:\windows\system32\avifil32.dll

2009-11-27 16:40:11 85504 ------w- c:\windows\system32\dllcache\avifil32.dll

2009-11-21 16:42:23 470528 ------w- c:\windows\system32\dllcache\aclayers.dll

2004-10-01 18:00:16 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe

 

============= FINISH: 1:27:48,21 ===============

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ela continua reiniciando, mas esta menos lenta

 

Pode ser problema de hardware.

 

Mande verificar a fonte e as memórias.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.