Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

isoliveira

[Arquivado] &nbspGerenciador de tarefas abre e fecha

Recommended Posts

Estou tentando abrir meu gerenciador de tarefas, porém ele abre e fecha muito rapido.

 

Meu pc está travando em determinados momentos

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:22:15, on 26/11/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Intel\WiFi\bin\S24EvMon.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

C:\Arquivos de programas\Arquivos comuns\Intel\WirelessCommon\iFrmewrk.exe

C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\stsystra.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\KADxMain.exe

C:\Arquivos de programas\Microsoft Xbox 360 Accessories\XboxStat.exe

C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe

C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Arquivos de programas\qubnfe\qubnfe.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\NitroPC\NitroPC.exe

C:\Arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

C:\Arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

C:\Arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Intel\WiFi\bin\EvtEng.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\LogMeIn\x86\LMIGuardianSvc.exe

C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe

C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\Arquivos de programas\Arquivos comuns\Intel\WirelessCommon\RegSrvc.exe

C:\Arquivos de programas\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Intel\WiFi\bin\WLKeeper.exe

C:\WINDOWS\system32\wbem\unsecapp.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Administrador\Meus documentos\Downloads\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [intelZeroConfig] "C:\Arquivos de programas\Intel\WiFi\bin\ZCfgSvc.exe"

O4 - HKLM\..\Run: [intelWireless] "C:\Arquivos de programas\Arquivos comuns\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray

O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe

O4 - HKLM\..\Run: [XboxStat] "C:\Arquivos de programas\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun

O4 - HKLM\..\Run: [avast5] C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe /nogui

O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [qubnfe] C:\Arquivos de programas\qubnfe\qubnfe.exe /auto

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\msagent" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Srchasst" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\system32\ime" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_08] cmd.exe /c md "%USERPROFILE%\Configurações locais\Temp" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_09] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_10] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_11] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\msagent" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (User 'Default user')

O4 - Global Startup: Bluetooth Manager.lnk = ?

O8 - Extra context menu item: &Download All using 4shared Desktop - C:\Arquivos de programas\4shared Desktop\down_all.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Arquivos de programas\PokerStars\PokerStarsUpdate.exe

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Mail Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Web Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Arquivos de programas\Intel\WiFi\bin\EvtEng.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LMIGuardianSvc.exe

O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe

O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe

O23 - Service: NMSAccess - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Arquivos de programas\Arquivos comuns\Intel\WirelessCommon\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Arquivos de programas\Intel\WiFi\bin\S24EvMon.exe

O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Arquivos de programas\SigmaTel\C-Major Audio\DellXPM_5515v131\WDM\StacSV.exe

O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Arquivos de programas\Intel\WiFi\bin\WLKeeper.exe

O24 - Desktop Component 1: (no name) - http://www.google.com.br/

 

--

End of file - 10388 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá isoliveira

 

1.

*Baixe o MalwareBytes Anti-malware e salve-o no desktop

 

*Instale o programa e aguarde a atualização

*O programa será aberto automaticamente

*Na aba [Verificação], selecione [Verificação completa]

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados]

*Clique [Remover Selecionados]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Como pode ver ele não identificou nada, porém o problema continua!

 

 

Malwarebytes' Anti-Malware 1.50

www.malwarebytes.org

 

Versão da Base de Dados: 5314

 

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

 

14/12/2010 21:39:56

mbam-log-2010-12-14 (21-39-56).txt

 

Tipo de Verificação: Verificação Completa (C:\|D:\|E:\|F:\|)

Objetos escaneados: 246558

Tempo decorrido: 37 minuto(s), 58 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 0

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

(Não foram detectados ítens maliciosos)

 

O Que eu façooo!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Desative temporariamente seu antivírus

Clique com o botão direito do mouse no ícone do Avast ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme.

*Baixe o ComboFix e salve-o no desktop

 

*Execute o Combofix e aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso contrário, clique [sIM] para instalar e depois [sIM] para continuar.

 

191d6c44ae.jpg

 

dd8ae98175.jpg

 

*Aguarde a conclusão de todas as etapas

 

etapas.jpg

 

*Não use o mouse e o teclado durante a execução do Combofix!!..... Para interromper o procedimento tecle [N] e depois [ENTER]

 

*Cole o relatório C:\combofix.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

Pronto Eu rodei o software 2x, pois a primeira xs ele detectou algo e pediu para escanear apos reiniciar:

 

Segue o primeiro log após reiniciar:

 

ComboFix 10-12-15.04 - Administrador 16/12/2010 0:24.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.3574.3153 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Meus documentos\Downloads\ComboFix.exe

AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected

.

\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected

.

(((((((((((((((( Arquivos/Ficheiros criados de 2010-11-16 to 2010-12-16 ))))))))))))))))))))))))))))

.

 

2010-12-15 02:25 . 2010-12-15 02:25 -------- d-----w- c:\arquivos de programas\Machinarium

2010-11-29 19:40 . 2010-12-08 19:40 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Symantec Shared

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\windows\system32\drivers\NSS

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Symantec

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Norton

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\arquivos de programas\Norton Security Scan

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\arquivos de programas\NortonInstaller

2010-11-25 01:33 . 2010-11-25 01:33 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2010-11-25 01:33 . 2010-11-29 19:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-25 01:33 . 2010-12-15 22:56 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-11-25 01:33 . 2010-11-29 19:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-11-25 01:33 . 2010-11-25 01:33 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2010-11-21 18:46 . 2010-11-21 18:46 -------- d-----w- c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\Unity

2010-11-20 17:15 . 2010-11-20 17:15 -------- d-----w- c:\arquivos de programas\iPod

2010-11-20 17:03 . 2010-11-20 17:03 -------- d-----w- c:\arquivos de programas\Bonjour

2010-11-20 15:57 . 2010-06-02 06:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll

2010-11-20 15:57 . 2010-06-02 06:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll

2010-11-20 15:57 . 2010-06-02 06:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll

2010-11-20 15:57 . 2010-05-26 13:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll

2010-11-20 15:56 . 2010-05-26 13:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll

2010-11-20 15:55 . 2010-11-20 15:55 -------- d-----w- c:\arquivos de programas\NVIDIA Corporation

2010-11-18 00:46 . 2010-11-18 00:46 -------- d-----w- C:\LinhaDefensiva

2010-11-18 00:37 . 2010-11-18 00:51 -------- d-----w- c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\NitroPC

2010-11-18 00:37 . 2010-11-18 00:37 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\TEMP

2010-11-18 00:37 . 2010-11-18 00:56 -------- d-----w- c:\arquivos de programas\NitroPC

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-12-08 19:41 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPef42.tmp

2010-12-06 19:41 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPecf1.tmp

2010-11-29 19:43 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPecf0.tmp

2010-11-27 14:24 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP2f5d.tmp

2010-11-16 19:12 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3be0.tmp

2010-11-11 14:59 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP398e.tmp

2010-11-02 03:33 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3911.tmp

2010-10-07 14:23 . 2010-10-07 14:23 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-10-07 14:23 . 2010-10-07 14:23 75040 ----a-w- c:\windows\system32\jdns_sd.dll

2010-10-07 14:23 . 2010-10-07 14:23 197920 ----a-w- c:\windows\system32\dnssdX.dll

2010-10-07 14:23 . 2010-10-07 14:23 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-10-06 01:22 . 2010-05-26 10:38 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll

2010-10-06 01:22 . 2010-05-26 10:38 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll

2010-10-06 01:22 . 2010-05-26 10:38 29568 ----a-w- c:\windows\system32\LMIport.dll

2010-10-06 01:22 . 2010-05-26 10:38 87424 ----a-w- c:\windows\system32\LMIinit.dll

2010-09-28 17:44 . 2010-06-17 22:52 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys

2010-09-28 17:44 . 2010-06-17 22:52 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll

2010-09-19 22:07 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3577.tmp

.

 

------- Sigcheck -------

 

[-] 2008-04-14 . 698F9583D1EB213B09F12DD5826A46E2 . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\f7670e43b3c19680acdc044a1fbe993f\sfcfiles.dll

[-] 2006-08-03 . AE1AA5ACEDEC2AC3362233B6F27870B3 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IntelZeroConfig"="c:\arquivos de programas\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]

"IntelWireless"="c:\arquivos de programas\Arquivos comuns\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]

"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]

"XboxStat"="c:\arquivos de programas\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]

"avast5"="c:\arquiv~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

"LogMeIn GUI"="c:\arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"AppleSyncNotifier"="c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]

"qubnfe"="c:\arquivos de programas\qubnfe\qubnfe.exe" [2010-11-01 754688]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2010-09-08 421888]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2010-11-17 421160]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10e.exe" [2010-01-27 256280]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Bluetooth Manager.lnk - c:\arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyPictures"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyPictures"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]

2010-10-06 01:22 87424 ----a-w- c:\windows\system32\LMIinit.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC]

2009-01-11 14:21 3477504 ----a-w- c:\arquivos de programas\NitroPC\NitroPC.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Java\\jre6\\bin\\javaw.exe"=

"c:\\Arquivos de programas\\TmNationsForever\\TmForever.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Pando Networks\\Media Booster\\PMB.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57764:TCP"= 57764:TCP:Pando Media Booster

"57764:UDP"= 57764:UDP:Pando Media Booster

 

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19/5/2010 01:34 165456]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/5/2010 01:34 17744]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\arquivos de programas\LogMeIn\x86\LMIGuardianSvc.exe [12/10/2010 00:37 374152]

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\arquivos de programas\LogMeIn\x86\rainfo.sys [11/8/2008 13:41 12856]

R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2/11/2006 13:32 97536]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2010-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2009-10-22 14:50]

 

2010-12-11 c:\windows\Tasks\Norton Security Scan for Administrador.job

- c:\arquivos de programas\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-11-28 11:48]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uInternet Connection Wizard,ShellNext = hxxp://www.google.com/

uInternet Settings,ProxyOverride = *.local

IE: &Download All using 4shared Desktop - c:\arquivos de programas\4shared Desktop\down_all.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\feps27w1.default\

FF - prefs.js: browser.startup.homepage - www.google.com.br

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\arquivos de programas\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Quick Starter: jqs@sun.com - c:\arquivos de programas\Java\jre6\lib\deploy\jqs\ff

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKLM-Run-SigmatelSysTrayApp - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-16 00:31

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,06,8b,53,86,8a,c1,43,b8,41,4f,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,06,8b,53,86,8a,c1,43,b8,41,4f,\

 

[HKEY_USERS\S-1-5-21-527237240-1682526488-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,80,de,49,4f,2c,88,4b,9f,46,dc,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,74,8f,b0,c7,85,0a,4a,b4,77,9b,\

"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,80,de,49,4f,2c,88,4b,9f,46,dc,\

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€| –Òw*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(884)

c:\windows\system32\LMIinit.dll

c:\windows\system32\netprovcredman.dll

c:\windows\system32\LMIRfsClientNP.dll

.

Tempo para conclusão: 2010-12-16 00:32:46

ComboFix-quarantined-files.txt 2010-12-16 02:32

 

Pré-execução: 10 pasta(s) 13.168.943.104 bytes disponíveis

Pós execução: 12 pasta(s) 13.409.673.216 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - E7EDFCA06F498C30F0C15EFCECA26DAD

 

 

Segue agora o Seundo Log depois de reiniciar.

 

ComboFix 10-12-15.04 - Administrador 16/12/2010 0:35.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.3574.2995 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Meus documentos\Downloads\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2010-11-16 to 2010-12-16 ))))))))))))))))))))))))))))

.

 

2010-12-15 02:25 . 2010-12-15 02:25 -------- d-----w- c:\arquivos de programas\Machinarium

2010-11-29 19:40 . 2010-12-08 19:40 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Symantec Shared

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\windows\system32\drivers\NSS

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Symantec

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Norton

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\arquivos de programas\Norton Security Scan

2010-11-28 03:29 . 2010-11-28 03:29 -------- d-----w- c:\arquivos de programas\NortonInstaller

2010-11-25 01:33 . 2010-11-25 01:33 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2010-11-25 01:33 . 2010-11-29 19:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-11-25 01:33 . 2010-12-15 22:56 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-11-25 01:33 . 2010-11-29 19:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-11-25 01:33 . 2010-11-25 01:33 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2010-11-21 18:46 . 2010-11-21 18:46 -------- d-----w- c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\Unity

2010-11-20 17:15 . 2010-11-20 17:15 -------- d-----w- c:\arquivos de programas\iPod

2010-11-20 17:03 . 2010-11-20 17:03 -------- d-----w- c:\arquivos de programas\Bonjour

2010-11-20 15:57 . 2010-06-02 06:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll

2010-11-20 15:57 . 2010-06-02 06:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll

2010-11-20 15:57 . 2010-06-02 06:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll

2010-11-20 15:57 . 2010-05-26 13:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll

2010-11-20 15:57 . 2010-05-26 13:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll

2010-11-20 15:56 . 2010-05-26 13:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll

2010-11-20 15:55 . 2010-11-20 15:55 -------- d-----w- c:\arquivos de programas\NVIDIA Corporation

2010-11-18 00:46 . 2010-11-18 00:46 -------- d-----w- C:\LinhaDefensiva

2010-11-18 00:37 . 2010-11-18 00:51 -------- d-----w- c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\NitroPC

2010-11-18 00:37 . 2010-11-18 00:37 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\TEMP

2010-11-18 00:37 . 2010-11-18 00:56 -------- d-----w- c:\arquivos de programas\NitroPC

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-12-08 19:41 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPef42.tmp

2010-12-06 19:41 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPecf1.tmp

2010-11-29 19:43 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMPecf0.tmp

2010-11-27 14:24 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP2f5d.tmp

2010-11-16 19:12 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3be0.tmp

2010-11-11 14:59 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP398e.tmp

2010-11-02 03:33 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3911.tmp

2010-10-07 14:23 . 2010-10-07 14:23 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-10-07 14:23 . 2010-10-07 14:23 75040 ----a-w- c:\windows\system32\jdns_sd.dll

2010-10-07 14:23 . 2010-10-07 14:23 197920 ----a-w- c:\windows\system32\dnssdX.dll

2010-10-07 14:23 . 2010-10-07 14:23 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-10-06 01:22 . 2010-05-26 10:38 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll

2010-10-06 01:22 . 2010-05-26 10:38 53632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll

2010-10-06 01:22 . 2010-05-26 10:38 29568 ----a-w- c:\windows\system32\LMIport.dll

2010-10-06 01:22 . 2010-05-26 10:38 87424 ----a-w- c:\windows\system32\LMIinit.dll

2010-09-28 17:44 . 2010-06-17 22:52 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys

2010-09-28 17:44 . 2010-06-17 22:52 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll

2010-09-19 22:07 . 2010-05-15 20:09 90112 ----a-w- c:\windows\DUMP3577.tmp

.

 

------- Sigcheck -------

 

[-] 2008-04-14 . 698F9583D1EB213B09F12DD5826A46E2 . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\f7670e43b3c19680acdc044a1fbe993f\sfcfiles.dll

[-] 2006-08-03 . AE1AA5ACEDEC2AC3362233B6F27870B3 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IntelZeroConfig"="c:\arquivos de programas\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]

"IntelWireless"="c:\arquivos de programas\Arquivos comuns\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]

"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]

"XboxStat"="c:\arquivos de programas\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]

"avast5"="c:\arquiv~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

"LogMeIn GUI"="c:\arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"AppleSyncNotifier"="c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]

"qubnfe"="c:\arquivos de programas\qubnfe\qubnfe.exe" [2010-11-01 754688]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2010-09-08 421888]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2010-11-17 421160]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10e.exe" [2010-01-27 256280]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Bluetooth Manager.lnk - c:\arquivos de programas\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-11 2150400]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyPictures"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NoSMMyPictures"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]

2010-10-06 01:22 87424 ----a-w- c:\windows\system32\LMIinit.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NitroPC]

2009-01-11 14:21 3477504 ----a-w- c:\arquivos de programas\NitroPC\NitroPC.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Java\\jre6\\bin\\javaw.exe"=

"c:\\Arquivos de programas\\TmNationsForever\\TmForever.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Pando Networks\\Media Booster\\PMB.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57764:TCP"= 57764:TCP:Pando Media Booster

"57764:UDP"= 57764:UDP:Pando Media Booster

 

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19/5/2010 01:34 165456]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/5/2010 01:34 17744]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\arquivos de programas\LogMeIn\x86\LMIGuardianSvc.exe [12/10/2010 00:37 374152]

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\arquivos de programas\LogMeIn\x86\rainfo.sys [11/8/2008 13:41 12856]

R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2/11/2006 13:32 97536]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2010-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2009-10-22 14:50]

 

2010-12-11 c:\windows\Tasks\Norton Security Scan for Administrador.job

- c:\arquivos de programas\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-11-28 11:48]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uInternet Connection Wizard,ShellNext = hxxp://www.google.com/

uInternet Settings,ProxyOverride = *.local

IE: &Download All using 4shared Desktop - c:\arquivos de programas\4shared Desktop\down_all.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\feps27w1.default\

FF - prefs.js: browser.startup.homepage - www.google.com.br

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\arquivos de programas\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Quick Starter: jqs@sun.com - c:\arquivos de programas\Java\jre6\lib\deploy\jqs\ff

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-12-16 00:38

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (LocalSystem)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,06,8b,53,86,8a,c1,43,b8,41,4f,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,06,8b,53,86,8a,c1,43,b8,41,4f,\

 

[HKEY_USERS\S-1-5-21-527237240-1682526488-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,80,de,49,4f,2c,88,4b,9f,46,dc,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ee,74,8f,b0,c7,85,0a,4a,b4,77,9b,\

"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,80,de,49,4f,2c,88,4b,9f,46,dc,\

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€| –Òw*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(884)

c:\windows\system32\LMIinit.dll

c:\windows\system32\netprovcredman.dll

c:\windows\system32\LMIRfsClientNP.dll

 

- - - - - - - > 'explorer.exe'(2224)

c:\windows\system32\WININET.dll

c:\arquiv~1\WINDOW~2\wmpband.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Tempo para conclusão: 2010-12-16 00:38:54

ComboFix-quarantined-files.txt 2010-12-16 02:38

ComboFix2.txt 2010-12-16 02:32

 

Pré-execução: 11 pasta(s) 13.442.011.136 bytes disponíveis

Pós execução: 12 pasta(s) 13.408.641.024 bytes disponíveis

 

- - End Of File - - 7F3CDDFF2403BCD026D3BD2AE2541526

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Clique [iniciar] > [Executar] > copie e cole: Combofix /uninstall

 

9c7dcf5090.jpg

 

*Clique [OK] > [Executar]

*Aguarde surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

2.

*Baixe o Kaspersky Virus Removal Tool e salve-o no desktop

*Instale o programa

*Selecione a opção:

[X] Meu Computador

*Clique [start scan]. Caso encontre algo, clique [skip]

*Ao finalizar, clique [Report]

*Uma janela chamada "Detailed report" será aberta

*Clique no sinal [+] ao lado de Autoscan para expandir os eventos

*Clique com o botão direito do mouse em Autoscan e selecione "Select all"

*Clique novamente com o botão direito do mouse e selecione "Copy"

*Abra o bloco de notas, cole (Ctrl+v) e salve o arquivo no desktop como log.txt

*Feche a janela "Detailed report" do Kasperky

*Na tela principal do Kaspersky clique em [Exit] > [No]

*Cole o relatório log.txt salvo no desktop

Compartilhar este post


Link para o post
Compartilhar em outros sites

A forma como você seguiu o procedimento não está correta.

 

Estarei postando um procedimento.

 

Entrarei de férias e outros analistas já estão cientes.

 

1.

*Abra a pasta Virus Removal Tool, localizada no desktop, execute o atalho Start

*Clique em [Exit] > [Yes] > [sim] > [sim]

*O PC será reiniciado

*Delete os arquivos setup do Kaspersky e log.txt salvos no desktop

 

2.

*Faça um scan online com o NOD32

 

4682a6d30e.gif

 

*Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log

 

3.

*Baixe o taskfix e salve-o no desktop

*Execute-o e aceite a entrada no registro.

*Reinicie o PC

 

Informe se resolveu.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok sem problemas, porem não foi esse proc que você me passou da primeira Xs:

 

Postou 16 dezembro 2010 - 05:15

1.

*Clique [iniciar] > [Executar] > copie e cole: Combofix /uninstall

 

Imagem

 

*Clique [OK] > [Executar]

*Aguarde surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

2.

*Baixe o Kaspersky Virus Removal Tool e salve-o no desktop

*Instale o programa

*Selecione a opção:

 

Quote

[X] Meu Computador

 

*Clique [start scan]. Caso encontre algo, clique [skip]

*Ao finalizar, clique [Report]

*Uma janela chamada "Detailed report" será aberta

*Clique no sinal [+] ao lado de Autoscan para expandir os eventos

*Clique com o botão direito do mouse em Autoscan e selecione "Select all"

*Clique novamente com o botão direito do mouse e selecione "Copy"

*Abra o bloco de notas, cole (Ctrl+v) e salve o arquivo no desktop como log.txt

*Feche a janela "Detailed report" do Kasperky

*Na tela principal do Kaspersky clique em [Exit] > [No]

*Cole o relatório log.txt salvo no desktop

 

 

Vou realizar esse ecaneamento agora!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Não está disponibilizando nenhum log!

 

Está meio confuso, qual a ferramenta que devo utilizar?

 

Obrigado...

 

Muito obrigado...

 

Mas ainda não está abrindo o gerenciador! :(

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, isoliveira! Seja Bem Vindo ao iMasters Fóruns!

 

A pedido do Wings estaremos dando continuidade no caso.

 

O relatório de verificação do NOD32 online está no seguinte diretório:

C:\Arquivos de programas\EsetOnlineScanner\log

 

Você fez o procedimento abaixo:

3.

*Baixe o taskfix e salve-o no desktop

*Execute-o e aceite a entrada no registro.

*Reinicie o PC

 

Fico no aguardo para darmos continuidade na análise.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.