lynna 0 Denunciar post Postado Fevereiro 3, 2010 Boa tarde, minha maquina utimamente tem reiniciado sozinha, e ao ligar aparece a seguinte mensagem "O Sistetema se recuperou de um erro grave" e seguinte log assinatura do erro: BCCode:1000000a BCP1:FFFFFFFC BCP:000000FF BCP3:00000000 BCP4:804DB973 0SVer:5_1_2600 SP:2_0 Product:256_1 Conteúdo do relatorio de erros Os seguintes arquivos serão incluídos no relatorio de erros C:\DOCUME~1\ASMINI~1\CONFIG~1\Temp\WER3c18.dir00\Mini020310-01.dmp C:\DOCUME~1\ASMINI~1\CONFIG~1\Temp\WER3c18.dir00\sysdata.xml por favor me ajude, desde já agradeço Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Fevereiro 5, 2010 Post um log conforme Regra 2 deste fórum http://forum.imasters.com.br/index.php?showtopic=165906 Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 6, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:02:Juh, on 6/2/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\NCLAUNCH.EXe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: privtorador - Unknown owner - cmd.exe (file missing) -- End of file - 8400 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 8, 2010 Boa tarde.... *Desative temporariamente seu antivírus Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme. *Baixe o ComboFix e salve-o no desktop *Duplo-clique no arquivo Combofix.exe *Aceite o contrato *Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso não esteja, uma janela conforme abaixo será aberta. Clique em [sIM] para aceitar a instalação do mesmo. *Após a instalação, clique em [sIM] para continuar. *Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER. *O programa será fechado automaticamente *Cole o relatório criado em C:\combofix.txt Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 11, 2010 Bom dia.. Nao consigo fazer o que foi pedido, pois toda vez que inicio o combofix o computador reinicia Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 11, 2010 Boa tarde.... 1. *Clique em [iniciar] > [Executar] > digite: Combofix /uninstall *Clique [OK] *Clique em [Executar] *Surgirá a mensagem: "ComboFix está desinstalado" *Clique [OK] 2. *O PROCEDIMENTO ABAIXO SÓ PODERÁ SER FEITO USANDO O INTERNET EXPLORER *Desative seu antivírus temporariamente Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme. *Faça um scan online com o NOD32 seguindo este tutorial http://dicasetutoriaisparapc.blogspot.com/search/label/Tutorial%20do%20antivirus%20Nod32%20Online *Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 14, 2010 ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=ffffd6ae1647454da70bce88e24a35d7 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-02-13 05:03:34 # local_time=2010-02-13 03:03:34 (-0300, Horário brasileiro de verão) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=769 16775141 100 98 0 201454345 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=1251 # found=0 # cleaned=0 # scan_time=268 esets_scanner_update returned -1 esets_gle=53251 esets_scanner_update returned -1 esets_gle=53251 # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=ffffd6ae1647454da70bce88e24a35d7 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-02-14 09:43:42 # local_time=2010-02-14 07:43:42 (-0300, Horário brasileiro de verão) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=769 16775141 100 98 0 201557537 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=1255 # found=0 # cleaned=0 # scan_time=275 Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 14, 2010 Por favor... Novo log do hijack. Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 15, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:09 Juh, on 15/2/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\NCLAUNCH.EXe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: privtorador - Unknown owner - cmd.exe (file missing) -- End of file - 8577 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 15, 2010 *Baixe o MalwareBytes Anti-malwaree salve-o no desktop: *Instale o programa *Se alguma atualização existir,o download será automático. Aguarde... *O programa será aberto automaticamente. *Na aba [Verificação], selecione a opção [Verificação completa] *Clique em [Verificar] e selecione as unidades a serem examinadas *Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados] *Selecione todos os resultados e clique em [Remover Selecionados] *Um relatório (mbam-log-ano-mês-data.txt) será apresentado. *Reinicie o PC *Abra novamente o programa Malwarebytes e na aba [Logs] clique no arquivo mbam-log-ano-mês-data.txt *Clique em [Abrir], copie, cole-o na sua próxima resposta e novo log do hijack Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 16, 2010 Malwarebytes' Anti-Malware 1.44 Versão do banco de dados: 3743 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 16/2/2010 01:12:56 Juh mbam-log-2010-02-16 (01-12-56).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 172098 Tempo decorrido: 1 hour(s), 41 minute(s), 10 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 0 Valores do Registro infectados: 0 Ítens do Registro infectados: 0 Pastas infectadas: 0 Arquivos infectados: 2 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: (Nenhum ítem malicioso foi detectado) Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: C:\System Volume Information\_restore{6A7A1BD8-170B-4BE9-8FA0-41DF91278CDB}\RP258\A0931752.com (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\system32\emplite.exe (Trojan.Downloader) -> Quarantined and deleted successfully. ------------------------------------------------------------------------------------------------ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:33 Juh, on 16/2/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\NCLAUNCH.EXe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe C:\Documents and Settings\Administrador\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx'>http://search.live.com/sphome.aspx O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PcSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exe O4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O4 - Startup: is-N9EA9.lnk = C:\Documents and Settings\Administrador\Desktop\Virus Removal Tool\is-N9EA9\startup.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://img2.orkut.com/activex/10035/photouploader.cab O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{3CD60846-44C9-4FC2-BF3C-17BF170C48DC}: NameServer = 10.1.22.3 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Update Service (gupdate1ca5745167fc474) (gupdate1ca5745167fc474) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: privtorador - Unknown owner - cmd.exe (file missing) -- End of file - 8417 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 16, 2010 1. *Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Remover tudo] *Clique na aba [Logs], selecione o relatório e clique em [Remover] 2. *Clique em [iniciar] > [Executar] > digite: services.msc *Localize o Serviço privtorador , dê um duplo clique nele e em "Tipo de inicialização" clique em [Desativado]. Clique também em [Parar] > [Aplicar] > [OK] 3. *Execute o HijackThis, clique em [Misc Tools] > [Delete an NT service...], coloque o serviço privtorador e clique em [Ok]. Quando perguntado se deseja reiniciar agora, clique em [sIM] 4. *Baixe o OTL e salve-o no desktop *Duplo clique em OTL.exe *Selecione as opções abaixo: [x] Scan All Users [x[ Minimal Output [x] Use Company Name WhiteList [x] Skip Microsoft Files [x] LOP Check [x] Purity Check *Em Custom Scans/Fixes cole o código abaixo: netsvcs %SYSTEMDRIVE%\ CREATERESTOREPOINT *Clique em [Run Scan] e aguarde o término do processo *Dois relatórios serão criados no desktop chamados: OTL.txt e Extras.txt *Cole o relatório OTL.txt Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 17, 2010 Boa tarde, o programa OTL para de responder durante o scan Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 17, 2010 OK... 1. *Delete o programa OTL 2. *Baixe o DDS e salve-o no desktop *Desative temporariamente seu antivírus Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme. *Duplo clique em dds e aguarde. Salve os relatórios no desktop *Cole o relatório criado em DDS.txt Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 17, 2010 DDS (Ver_09-12-01.01) - NTFSx86 Run by Administrador at 17:07:46,29 on qua 17/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.238.24 [GMT -2:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\NCLAUNCH.EXe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jucheck.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Windows Live\Toolbar\wltuser.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Administrador\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://search.live.com uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703 uSearch Bar = hxxp://search.live.com/sphome.aspx uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://search.live.com/sphome.aspx BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\arquivos de programas\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\arquivos de programas\windows live\toolbar\wltcore.dll TB: &Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\arquivos de programas\windows live\toolbar\wltcore.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [PcSync] c:\arquivos de programas\nokia\nokia pc suite 6\PcSync2.exe /NoDialog uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray uRun: [NitroPC] "c:\arquivos de programas\nitropc\NitroPC.exe" -minimized uRun: [skwi372sm.exe] c:\windows\system32\skwi372sm.exe uRun: [p3jsz8wer.exe] c:\windows\system32\p3jsz8wer.exe mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre1.6.0_05\bin\jusched.exe" mRun: [VTTimer] VTTimer.exe mRun: [VTTrayp] VTtrayp.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [QuickTime Task] "c:\arquivos de programas\quicktime\qttask.exe" -atboottime mRun: [TkBellExe] "c:\arquivos de programas\arquivos comuns\real\update_ob\realsched.exe" -osboot mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [userFaultCheck] %systemroot%\system32\dumprep 0 -u dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [MsnMsgr] "c:\arquivos de programas\msn messenger\MsnMsgr.Exe" /background dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\is-n9ea9.lnk - c:\documents and settings\administrador\desktop\virus removal tool\is-n9ea9\startup.exe StartupFolder: c:\docume~1\alluse~1\menuin~1\progra~1\inicia~1\micros~1.lnk - c:\arquivos de programas\microsoft office\office10\OSA.EXE IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office10\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\arquivos de programas\windows live\writer\WriterBrowserExtension.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://img2.orkut.com/activex/10035/photouploader.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab TCP: {3CD60846-44C9-4FC2-BF3C-17BF170C48DC} = 10.1.22.3 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\arquivos de programas\arquivos comuns\microsoft shared\web folders\PKMCDO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau Hosts: 0.0.0.0 www.adcopy.info Hosts: 0.0.0.0 classic.adlink.de #[iE-SpyAd] Hosts: 0.0.0.0 regio.adlink.de Hosts: 0.0.0.0 west.adlink.de Hosts: 0.0.0.0 ad.ads.dk #[iE-SpyAd] Note: multiple HOSTS entries found. Please refer to Attach.txt ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\dadosd~1\mozilla\firefox\profiles\kf8vjucm.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - component: c:\documents and settings\administrador\dados de aplicativos\mozilla\firefox\profiles\kf8vjucm.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll FF - plugin: c:\arquivos de programas\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\arquivos de programas\microsoft\office live\npOLW.dll FF - plugin: c:\arquivos de programas\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-8 114768] R1 is-N9EA9drv;is-N9EA9drv;c:\windows\system32\drivers\82375415.sys [2009-9-10 148496] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-8 20560] R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-5-8 138680] S2 gupdate1ca5745167fc474;Google Update Service (gupdate1ca5745167fc474);c:\arquivos de programas\google\update\GoogleUpdate.exe [2009-10-27 133104] S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-5-8 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-5-8 352920] S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2010-1-16 83496] S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2010-1-16 15016] S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2010-1-16 109992] S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2010-1-16 103976] S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2010-1-16 100008] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?] S3 SQTECH9160;Digital Camera;c:\windows\system32\drivers\Capt9160.sys [2006-10-27 45711] S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2007-3-20 87824] S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2007-3-20 85696] S4 svService;service;c:\windows\system32\service.exe --> c:\windows\system32\service.exe [?] =============== Created Last 30 ================ 2010-02-16 00:14:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-16 00:14:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-16 00:14:03 0 d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2010-02-14 21:52:52 279 ----a-w- C:\Atalho para Disco local ©.lnk 2010-02-13 16:20:53 0 d-sh--w- c:\documents and settings\administrador\PrivacIE 2010-02-13 16:20:49 0 d-sh--w- c:\documents and settings\administrador\IECompatCache 2010-02-13 15:34:13 0 d-sh--w- c:\documents and settings\administrador\IETldCache 2010-02-13 14:44:01 0 d-----w- c:\windows\ie8updates 2010-02-13 14:39:53 0 dc-h--w- c:\windows\ie8 2010-02-13 14:34:16 69120 ------w- c:\windows\system32\dllcache\iecompat.dll 2010-02-13 14:33:59 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll 2010-02-13 14:33:58 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-13 14:33:57 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-02-13 14:33:57 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll 2010-02-13 14:33:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2010-02-13 14:33:54 11070464 ------w- c:\windows\system32\dllcache\ieframe.dll 2010-02-11 13:47:19 0 d-s---w- C:\ComboFix 2010-02-10 22:52:32 0 d-sha-r- C:\cmdcons 2010-02-09 15:41:53 98816 ----a-w- c:\windows\sed.exe 2010-02-09 15:41:53 77312 ----a-w- c:\windows\MBR.exe 2010-02-09 15:41:53 261632 ----a-w- c:\windows\PEV.exe 2010-02-09 15:41:53 161792 ----a-w- c:\windows\SWREG.exe 2010-02-06 14:01:03 7168 --sha-w- c:\windows\Thumbs.db 2010-02-01 11:56:49 0 d-----w- c:\arquivos de programas\Avanquest update 2010-01-28 23:36:22 0 d-----w- c:\arquivos de programas\Conduit ==================== Find3M ==================== 2010-02-16 18:14:25 12635492 --sha-w- c:\windows\system32\drivers\fidbox.idx 2010-02-16 18:14:25 1131956256 --sha-w- c:\windows\system32\drivers\fidbox.dat 2010-02-13 15:31:47 90112 ----a-w- c:\windows\DUMP3c9b.tmp 2010-02-12 16:58:21 90112 ----a-w- c:\windows\DUMP3aa7.tmp 2010-02-12 16:57:44 90112 ----a-w- c:\windows\DUMP3b24.tmp 2010-02-12 14:28:36 90112 ----a-w- c:\windows\DUMP3fc8.tmp 2010-02-11 14:04:08 90112 ----a-w- c:\windows\DUMP4110.tmp 2010-02-10 22:38:26 90112 ----a-w- c:\windows\DUMP3f99.tmp 2010-02-10 12:54:26 90112 ----a-w- c:\windows\DUMP3e70.tmp 2010-01-13 23:22:43 2039808 ----a-w- c:\windows\system32\skwi372sm.exe 2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-31 16:14:12 352640 ------w- c:\windows\system32\dllcache\srv.sys 2009-12-22 05:41:39 1506304 ------w- c:\windows\system32\dllcache\shdocvw.dll 2009-12-22 05:41:33 55808 ------w- c:\windows\system32\dllcache\extmgr.dll 2009-12-22 05:41:33 1055744 ------w- c:\windows\system32\dllcache\danim.dll 2009-12-22 05:41:32 151552 ------w- c:\windows\system32\dllcache\cdfview.dll 2009-12-22 05:41:32 1024000 ------w- c:\windows\system32\dllcache\browseui.dll 2009-12-21 19:08:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-21 19:08:00 916480 ------w- c:\windows\system32\dllcache\wininet.dll 2009-12-21 19:08:00 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll 2009-12-21 19:07:59 5942784 ------w- c:\windows\system32\dllcache\mshtml.dll 2009-12-21 19:07:59 206848 ------w- c:\windows\system32\dllcache\occache.dll 2009-12-21 19:07:56 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll 2009-12-21 19:07:55 184320 ------w- c:\windows\system32\dllcache\iepeers.dll 2009-12-21 19:07:52 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll 2009-12-21 13:22:00 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-17 07:59:45 345600 ----a-w- c:\windows\system32\mspaint.exe 2009-12-17 07:59:45 345600 ------w- c:\windows\system32\dllcache\mspaint.exe 2009-12-16 12:57:07 18432 ------w- c:\windows\system32\dllcache\iedw.exe 2009-12-14 07:36:35 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-14 07:36:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-11 18:37:05 76620 ----a-w- c:\windows\system32\perfc016.dat 2009-12-11 18:37:05 461968 ----a-w- c:\windows\system32\perfh016.dat 2009-12-09 10:27:05 2061952 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-09 10:27:05 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-09 10:27:04 2184576 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-09 10:27:04 2184576 ------w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-09 10:27:02 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-09 10:26:59 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 09:12:53 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 14:41:55 453760 ------w- c:\windows\system32\dllcache\mrxsmb.sys 2009-11-27 17:34:48 17920 ----a-w- c:\windows\system32\msyuv.dll 2009-11-27 17:34:48 17920 ------w- c:\windows\system32\dllcache\msyuv.dll 2009-11-27 17:34:48 1295872 ----a-w- c:\windows\system32\quartz.dll 2009-11-27 17:34:48 1295872 ------w- c:\windows\system32\dllcache\quartz.dll 2009-11-27 16:40:12 8704 ----a-w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:40:12 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll 2009-11-27 16:40:12 48128 ----a-w- c:\windows\system32\iyuv_32.dll 2009-11-27 16:40:12 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll 2009-11-27 16:40:12 28672 ----a-w- c:\windows\system32\msvidc32.dll 2009-11-27 16:40:12 28672 ------w- c:\windows\system32\dllcache\msvidc32.dll 2009-11-27 16:40:12 11264 ----a-w- c:\windows\system32\msrle32.dll 2009-11-27 16:40:12 11264 ------w- c:\windows\system32\dllcache\msrle32.dll 2009-11-27 16:40:11 85504 ----a-w- c:\windows\system32\avifil32.dll 2009-11-27 16:40:11 85504 ------w- c:\windows\system32\dllcache\avifil32.dll 2009-11-21 16:42:23 470528 ------w- c:\windows\system32\dllcache\aclayers.dll 2004-10-01 18:00:16 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe ============= FINISH: 17:09:36,54 =============== Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 17, 2010 1. *Execute o hijack, clique em [Do a system scan only], selecione as entradas abaixo e clique em [Fix checked] O4 - HKCU\..\Run: [skwi372sm.exe] C:\WINDOWS\system32\skwi372sm.exeO4 - HKCU\..\Run: [p3jsz8wer.exe] C:\WINDOWS\system32\p3jsz8wer.exe *Feche o hijack 2. *Baixe o Avenger e extraia o conteúdo para o desktop *Selecione e copie (Ctrl+C) todo o código abaixo: Files to delete:c:\windows\system32\skwi372sm.exe c:\windows\system32\p3jsz8wer.exe c:\windows\system32\service.exe c:\windows\DUMP3c9b.tmp c:\windows\DUMP3aa7.tmp c:\windows\DUMP3b24.tmp c:\windows\DUMP3fc8.tmp c:\windows\DUMP4110.tmp c:\windows\DUMP3f99.tmp c:\windows\DUMP3e70.tmp Drivers to disable: svService Drivers to delete: svService *Execute o programa Avenger *Clique em [Load Script] > [Paste from Clipboard] *Clique em [Execute] > [OK] *O PC será reiniciado *Cole o relatório criado em C:\avenger.txt e novo log do DDS Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 18, 2010 Logfile of The Avenger Version 2.0, © by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "c:\windows\system32\skwi372sm.exe" deleted successfully. Error: file "c:\windows\system32\p3jsz8wer.exe" not found! Deletion of file "c:\windows\system32\p3jsz8wer.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "c:\windows\system32\service.exe" not found! Deletion of file "c:\windows\system32\service.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "c:\windows\DUMP3c9b.tmp" deleted successfully. File "c:\windows\DUMP3aa7.tmp" deleted successfully. File "c:\windows\DUMP3b24.tmp" deleted successfully. File "c:\windows\DUMP3fc8.tmp" deleted successfully. File "c:\windows\DUMP4110.tmp" deleted successfully. File "c:\windows\DUMP3f99.tmp" deleted successfully. File "c:\windows\DUMP3e70.tmp" deleted successfully. Driver "svService" disabled successfully. Driver "svService" deleted successfully. Completed script processing. ******************* Finished! Terminate. -------------------------------------------------------------------------------------------------------------------------------------------- DDS (Ver_09-12-01.01) - NTFSx86 Run by Administrador at 1:26:39,82 on qui 18/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_05 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.238.108 [GMT -2:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\NOTEPAD.EXE C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\WINDOWS\SOUNDMAN.EXE C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\NCLAUNCH.EXe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Real\RealPlayer\realplay.exe C:\Documents and Settings\Administrador\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://search.live.com uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703 uSearch Bar = hxxp://search.live.com/sphome.aspx uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://search.live.com/sphome.aspx BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\arquivos de programas\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\arquivos de programas\windows live\toolbar\wltcore.dll TB: &Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\arquivos de programas\yahoo!\companion\installs\cpn2\ycomp5_6_2_0.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\arquivos de programas\windows live\toolbar\wltcore.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [PcSync] c:\arquivos de programas\nokia\nokia pc suite 6\PcSync2.exe /NoDialog uRun: [NCLaunch] c:\windows\NCLAUNCH.EXe uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray uRun: [NitroPC] "c:\arquivos de programas\nitropc\NitroPC.exe" -minimized mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre1.6.0_05\bin\jusched.exe" mRun: [VTTimer] VTTimer.exe mRun: [VTTrayp] VTtrayp.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [QuickTime Task] "c:\arquivos de programas\quicktime\qttask.exe" -atboottime mRun: [TkBellExe] "c:\arquivos de programas\arquivos comuns\real\update_ob\realsched.exe" -osboot mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [userFaultCheck] %systemroot%\system32\dumprep 0 -u dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [MsnMsgr] "c:\arquivos de programas\msn messenger\MsnMsgr.Exe" /background dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\is-n9ea9.lnk - c:\documents and settings\administrador\desktop\virus removal tool\is-n9ea9\startup.exe StartupFolder: c:\docume~1\alluse~1\menuin~1\progra~1\inicia~1\micros~1.lnk - c:\arquivos de programas\microsoft office\office10\OSA.EXE IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office10\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\arquivos de programas\java\jre1.6.0_05\bin\ssv.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\arquivos de programas\windows live\writer\WriterBrowserExtension.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://img2.orkut.com/activex/10035/photouploader.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab TCP: {3CD60846-44C9-4FC2-BF3C-17BF170C48DC} = 10.1.22.3 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\arquivos de programas\arquivos comuns\microsoft shared\web folders\PKMCDO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 nwprovau Hosts: 0.0.0.0 www.adcopy.info Hosts: 0.0.0.0 classic.adlink.de #[iE-SpyAd] Hosts: 0.0.0.0 regio.adlink.de Hosts: 0.0.0.0 west.adlink.de Hosts: 0.0.0.0 ad.ads.dk #[iE-SpyAd] Note: multiple HOSTS entries found. Please refer to Attach.txt ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\dadosd~1\mozilla\firefox\profiles\kf8vjucm.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - component: c:\documents and settings\administrador\dados de aplicativos\mozilla\firefox\profiles\kf8vjucm.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll FF - plugin: c:\arquivos de programas\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\arquivos de programas\microsoft\office live\npOLW.dll FF - plugin: c:\arquivos de programas\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-8 114768] R1 is-N9EA9drv;is-N9EA9drv;c:\windows\system32\drivers\82375415.sys [2009-9-10 148496] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-8 20560] R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-5-8 138680] S2 gupdate1ca5745167fc474;Google Update Service (gupdate1ca5745167fc474);c:\arquivos de programas\google\update\GoogleUpdate.exe [2009-10-27 133104] S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-5-8 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-5-8 352920] S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\system32\drivers\s916bus.sys [2010-1-16 83496] S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\system32\drivers\s916mdfl.sys [2010-1-16 15016] S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\system32\drivers\s916mdm.sys [2010-1-16 109992] S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s916mgmt.sys [2010-1-16 103976] S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\system32\drivers\s916obex.sys [2010-1-16 100008] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?] S3 SQTECH9160;Digital Camera;c:\windows\system32\drivers\Capt9160.sys [2006-10-27 45711] S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [2007-3-20 87824] S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [2007-3-20 85696] =============== Created Last 30 ================ 2010-02-16 00:14:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-16 00:14:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-16 00:14:03 0 d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2010-02-14 21:52:52 279 ----a-w- C:\Atalho para Disco local ©.lnk 2010-02-13 16:20:53 0 d-sh--w- c:\documents and settings\administrador\PrivacIE 2010-02-13 16:20:49 0 d-sh--w- c:\documents and settings\administrador\IECompatCache 2010-02-13 15:34:13 0 d-sh--w- c:\documents and settings\administrador\IETldCache 2010-02-13 14:44:01 0 d-----w- c:\windows\ie8updates 2010-02-13 14:39:53 0 dc-h--w- c:\windows\ie8 2010-02-13 14:34:16 69120 ------w- c:\windows\system32\dllcache\iecompat.dll 2010-02-13 14:33:59 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll 2010-02-13 14:33:58 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-13 14:33:57 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-02-13 14:33:57 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll 2010-02-13 14:33:55 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2010-02-13 14:33:54 11070464 ------w- c:\windows\system32\dllcache\ieframe.dll 2010-02-11 13:47:19 0 d-s---w- C:\ComboFix 2010-02-10 22:52:32 0 d-sha-r- C:\cmdcons 2010-02-09 15:41:53 98816 ----a-w- c:\windows\sed.exe 2010-02-09 15:41:53 77312 ----a-w- c:\windows\MBR.exe 2010-02-09 15:41:53 261632 ----a-w- c:\windows\PEV.exe 2010-02-09 15:41:53 161792 ----a-w- c:\windows\SWREG.exe 2010-02-06 14:01:03 7168 --sha-w- c:\windows\Thumbs.db 2010-02-01 11:56:49 0 d-----w- c:\arquivos de programas\Avanquest update 2010-01-28 23:36:22 0 d-----w- c:\arquivos de programas\Conduit ==================== Find3M ==================== 2010-02-18 03:12:31 12635492 --sha-w- c:\windows\system32\drivers\fidbox.idx 2010-02-18 03:12:29 1131956256 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-31 16:14:12 352640 ------w- c:\windows\system32\dllcache\srv.sys 2009-12-22 05:41:39 1506304 ------w- c:\windows\system32\dllcache\shdocvw.dll 2009-12-22 05:41:33 55808 ------w- c:\windows\system32\dllcache\extmgr.dll 2009-12-22 05:41:33 1055744 ------w- c:\windows\system32\dllcache\danim.dll 2009-12-22 05:41:32 151552 ------w- c:\windows\system32\dllcache\cdfview.dll 2009-12-22 05:41:32 1024000 ------w- c:\windows\system32\dllcache\browseui.dll 2009-12-21 19:08:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-21 19:08:00 916480 ------w- c:\windows\system32\dllcache\wininet.dll 2009-12-21 19:08:00 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll 2009-12-21 19:07:59 5942784 ------w- c:\windows\system32\dllcache\mshtml.dll 2009-12-21 19:07:59 206848 ------w- c:\windows\system32\dllcache\occache.dll 2009-12-21 19:07:56 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll 2009-12-21 19:07:55 184320 ------w- c:\windows\system32\dllcache\iepeers.dll 2009-12-21 19:07:52 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll 2009-12-21 13:22:00 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-17 07:59:45 345600 ----a-w- c:\windows\system32\mspaint.exe 2009-12-17 07:59:45 345600 ------w- c:\windows\system32\dllcache\mspaint.exe 2009-12-16 12:57:07 18432 ------w- c:\windows\system32\dllcache\iedw.exe 2009-12-14 07:36:35 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-14 07:36:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-11 18:37:05 76620 ----a-w- c:\windows\system32\perfc016.dat 2009-12-11 18:37:05 461968 ----a-w- c:\windows\system32\perfh016.dat 2009-12-09 10:27:05 2061952 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-09 10:27:05 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-09 10:27:04 2184576 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-09 10:27:04 2184576 ------w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-09 10:27:02 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-09 10:26:59 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 09:12:53 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 14:41:55 453760 ------w- c:\windows\system32\dllcache\mrxsmb.sys 2009-11-27 17:34:48 17920 ----a-w- c:\windows\system32\msyuv.dll 2009-11-27 17:34:48 17920 ------w- c:\windows\system32\dllcache\msyuv.dll 2009-11-27 17:34:48 1295872 ----a-w- c:\windows\system32\quartz.dll 2009-11-27 17:34:48 1295872 ------w- c:\windows\system32\dllcache\quartz.dll 2009-11-27 16:40:12 8704 ----a-w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:40:12 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll 2009-11-27 16:40:12 48128 ----a-w- c:\windows\system32\iyuv_32.dll 2009-11-27 16:40:12 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll 2009-11-27 16:40:12 28672 ----a-w- c:\windows\system32\msvidc32.dll 2009-11-27 16:40:12 28672 ------w- c:\windows\system32\dllcache\msvidc32.dll 2009-11-27 16:40:12 11264 ----a-w- c:\windows\system32\msrle32.dll 2009-11-27 16:40:12 11264 ------w- c:\windows\system32\dllcache\msrle32.dll 2009-11-27 16:40:11 85504 ----a-w- c:\windows\system32\avifil32.dll 2009-11-27 16:40:11 85504 ------w- c:\windows\system32\dllcache\avifil32.dll 2009-11-21 16:42:23 470528 ------w- c:\windows\system32\dllcache\aclayers.dll 2004-10-01 18:00:16 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe ============= FINISH: 1:27:48,21 =============== Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 18, 2010 OK.... Como está a máquina? Compartilhar este post Link para o post Compartilhar em outros sites
lynna 0 Denunciar post Postado Fevereiro 19, 2010 Ela continua reiniciando, mas esta menos lenta Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 19, 2010 Ela continua reiniciando, mas esta menos lenta Pode ser problema de hardware. Mande verificar a fonte e as memórias. Compartilhar este post Link para o post Compartilhar em outros sites