|
![]() |
||
cpu em uso 100% com qualquer coisa
|
||
. Nós temos 759.214 usuários, convidamos você fazer parte de nossa comunidade também! Se ainda não encontrou o que procura use nossa pesquisa. Esperamos que aprecie nosso trabalho.
![]() |
|
|
Opções do Tópico |
|
|
#1 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
Ola... estou precisando muito de uma ajuda.... meu pc estava normal a 3 dias atrás, então comprei um minimodem 3g huawei e160 e coloquei a 3g da tim e comecei a usar muito ruim por sinal, meu cpu começou a dar uso de 100% em qualquer coisa que faço se eu abro firefox ele usa 98, 99 , se eu uso o wmplayer tb da 98, 99, olho os processos e não entendo quais posso finalizar estou com 36 processos aqui, mas os unicos que dão esses picos são as coisas que mexo tipo firefox, wmplayer ou qualquer outro programa que eu abrir, aquele discador da tim, qualquer coisa que mexer abre la o processo respectivo, e vai pra 98,99, estou sem saber o q fazer aki, se alguém souber alguma coisa, me de uma luz por favorrrr...![]() |
|
|
|
|
|
#2 (permalink) |
|
Veterano
Registrado em: Apr 2007
Localização: Washington, DC
Idade: 32
Mensagens: 1.461
Reputação: 26
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
estranho....ta com cara de ser virus.
Teste seu PC sem o minimodem pra ver se acontece a mesma coisa.
__________________
Q9400 GA-EP45-UD3L SAPPHIRE HD 4870 1GB Toxic Vapor-X ![]() 2 x 2GB Corsair Dominator 1066MHz Western Digital 500GB Caviar Blue SE16 Seagate Barracuda 160GB Corsair HX850 Modular ![]() Gabinete Akasa Freedom X2 |
|
|
|
|
|
#3 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
ola.. ja testei sem o minimodem o problema continua se eu colocar uma música ou outra coisa qualquer o uso do cpu sobe 98,99... ja passei antivirus e achou um virus coloquei na quarentena depois lendo alguns tópicos por ai vi que poderia apagar tudo da quarentena pra ver se resolvia , apaguei mas não resolveu... ai fiquei sem saber mais o que fazer, tenho nitro pc , ja fiz a remoção de erros e otimização e nada ..... fico na espera... desde ja obrigado por responder ...
|
|
|
|
|
|
#4 (permalink) |
|
General de Pijama
Registrado em: Jan 2008
Mensagens: 3.051
Reputação: 7375
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Recomedo você a postar esse problema na sala de vírus para o pessoal te ajudar melhor, já que você achou um vírus no computador e mesmo deletando o problema persiste
|
|
|
|
|
|
#5 (permalink) |
|
GeeK
Registrado em: Sep 2007
Localização: Rio de Janeiro
Mensagens: 2.195
Reputação: 2911
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
1: Baixe essa ferramenta ((hijackthis))
http://go.trendmicro.com/free-tools/...sInstaller.exe 2: Salve no desktop Instale o Programa, na pasta, C:\Arquivos de programa\ 3: Depois clique no ícone do Hijackthis, executa-o clicando no primeiro botão ((Do a system scan and a save logfile)) abrirá um log automatico copia e mande para a sala que cuida da área de vírus.
__________________
3VAAV / P3 750 Mhz / 320 Mb Dimm Gravador DVD LG / Gravador Sony HD Maxtor 160Gb / HD 20Gb Sansung / LG 17 XP / Kurumin 7 |
|
|
|
|
|
#6 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
olaa estou postando meu problema aki onde me indicaram pois meu pc da uso de cpu 100% pra qualquer coisa que mexo e passei o anti virus e detectou um virus e mandei para quarentena depois vendo alguns tópicos limpei a quarentena pra ver se resolvia e nada , eu não sei mais o que faço , eu tb coloquei um minimodem 3g aki e percebi que depois disso começou a ficar assim qdo olho os processos eles estão tipo se eu uso firefox ele usa 98,99 se eu uso wmplayer a mesma coisa qualquer programa fica assim tem 38 processos aki mas n entendo muito, me pediram pra baixar um programa e copiar o log e postar aki então ai vai
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:42:18, on 5/3/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16981) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\NitroPC\NitroPC.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TIM\GSM\TIMWEB.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\taskmgr.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file) O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Arquivos de programas\Windows Live\Family Safety\fssbho.dll O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file) O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.d ll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file) O4 - HKLM\..\Run: [avast!] "C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.semptoshiba.com.br O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E355F345-0899-42C7-8EC9-5EB513C50D05}: NameServer = 200.204.0.10,200.204.0.138 O17 - HKLM\System\CCS\Services\Tcpip\..\{E97E6F67-B20B-4369-A6F5-9E6274A9E549}: NameServer = 189.40.224.5 189.38.95.95 O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NitroPC Service (NitroPCSrv) - Intelliclick Informática - C:\Arquivos de programas\NitroPC\NitroPCService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe -- End of file - 8329 bytes |
|
|
|
|
|
#7 (permalink) | |
|
Ubbergeek
|
Olá, alessandra.!
Vamos por etapa. 1º Abra novamente o hijackthis clique em » Do a system scam only marque a(s) seguinte(s) linha(s) abaixo, clique em Fix checked: Citação:
2º * Faça o download do DelDomains * Clique com o botão direito no DelDomains.inf e clicar em Instalar. * Reinicie a máquina. Novo Log do Hijackthis. Última edição por Felipe_88 : 05-03-2010 às 20:08. |
|
|
|
|
|
|
#8 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
marquei e apareceram duas caixas de mensagem não sei dizendo o que... e depois essas tres opções sumiram e ficou assim
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:11:44, on 5/3/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16981) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\NitroPC\NitroPC.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TIM\GSM\TIMWEB.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\taskmgr.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Arquivos de programas\Windows Live\Family Safety\fssbho.dll O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file) O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.d ll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file) O4 - HKLM\..\Run: [avast!] "C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.semptoshiba.com.br O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E355F345-0899-42C7-8EC9-5EB513C50D05}: NameServer = 200.204.0.10,200.204.0.138 O17 - HKLM\System\CCS\Services\Tcpip\..\{E97E6F67-B20B-4369-A6F5-9E6274A9E549}: NameServer = 189.40.224.5 189.38.95.95 O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NitroPC Service (NitroPCSrv) - Intelliclick Informática - C:\Arquivos de programas\NitroPC\NitroPCService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe -- End of file - 7991 bytes |
|
|
|
|
|
#9 (permalink) |
|
Ubbergeek
|
alessandra.,
Ok. Faça o 2º procedimento, conforme indicado posteriormente. E posta um novo Log do Hijackthis. |
|
|
|
|
|
#10 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
pronto ficou assim
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:32:34, on 5/3/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16981) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Arquivos de programas\NitroPC\NitroPC.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\TIM\GSM\TIMWEB.exe C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\taskmgr.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Alwil Software\Avast4\setup\avast.setup C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://br.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Arquivos de programas\Windows Live\Family Safety\fssbho.dll O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file) O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.d ll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file) O4 - HKLM\..\Run: [avast!] "C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.semptoshiba.com.br O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E355F345-0899-42C7-8EC9-5EB513C50D05}: NameServer = 200.204.0.10,200.204.0.138 O17 - HKLM\System\CCS\Services\Tcpip\..\{E97E6F67-B20B-4369-A6F5-9E6274A9E549}: NameServer = 189.40.224.5 189.38.95.95 O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NitroPC Service (NitroPCSrv) - Intelliclick Informática - C:\Arquivos de programas\NitroPC\NitroPCService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe -- End of file - 8081 bytes |
|
|
|
|
|
#11 (permalink) |
|
Ubbergeek
|
alessandra.,
*Baixe o ComboFix e salve-o no desktop *Duplo-clique no arquivo Combofix.exe *Aceite o contrato *Se o console de recuperação do Windows já estiver instalado, o ComboFix irá continuar o processo automaticamente. Caso não esteja uma janela, conforme abaixo, será aberta. Clique em [SIM] para aceitar a instalação do mesmo. ![]() *Após a instalação, clique em [SIM] para continuar. ![]() *Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER. *O programa será fechado automaticamente *Cole o relatório criado em C:\combofix.txt Ficamos no aguardo! |
|
|
|
|
|
#12 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
ficou assim
ComboFix 10-03-05.01 - MICHEL ANSELHO 05/03/2010 21:43:13.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.524 [GMT -3:00] Executando de: C:\Documents and Settings\MICHEL ANSELHO\Meus documentos\Downloads\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100305-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !! . ADS - drivers: deleted 204 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) ) . . ---- Execuções precedente ------- . C:\Arquivos de programas\FunWebProducts C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\FunWebProducts C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\FunWebProducts\Data\MICHEL ANSELHO\avatar.dat C:\RECYCLER\S-1-5-21-1060284298-764733703-1801674531-500 C:\RECYCLER\S-1-5-21-842981454-340626357-2149463755-500 C:\WINDOWS\macromix.dll C:\WINDOWS\system32\WinUpdate . (((((((((((((((( Arquivos/Ficheiros criados de 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))) . 2010-03-05 22:41:01 . 2010-03-05 22:41:01 -------- d-----w- C:\Arquivos de programas\Trend Micro 2010-03-04 12:50:24 . 2009-01-13 20:42:30 113968 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}\components\GbMzhBb.dll 2010-03-04 12:49:52 . 2010-02-18 13:20:44 30752 ----a-w- C:\WINDOWS\system32\drivers\gbpkm.sys 2010-03-04 12:49:38 . 2010-03-04 12:49:52 -------- d-----w- C:\Arquivos de programas\GbPlugin 2010-03-04 12:49:38 . 2010-03-04 12:49:38 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin 2010-03-04 12:48:38 . 2010-02-24 13:53:26 1688288 ----a-w- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP\gbplugin_ie_bb_setup.exe 2010-03-01 17:35:34 . 2008-04-13 19:45:40 32128 -c--a-w- C:\WINDOWS\system32\dllcache\usbccgp.sys 2010-03-01 17:35:34 . 2008-04-13 19:45:40 32128 ----a-w- C:\WINDOWS\system32\drivers\usbccgp.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 621056 ----a-w- C:\WINDOWS\system32\drivers\mod7700.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 101120 ----a-w- C:\WINDOWS\system32\drivers\ewusbmdm.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 100992 ----a-w- C:\WINDOWS\system32\drivers\ewusbnet.sys 2010-03-01 17:34:49 . 2008-12-17 19:00:50 24448 ----a-w- C:\WINDOWS\system32\drivers\ewdcsc.sys 2010-03-01 17:34:49 . 2008-12-17 19:00:50 103168 ----a-w- C:\WINDOWS\system32\drivers\ewusbfake.sys 2010-03-01 17:34:23 . 2010-03-01 17:34:23 -------- d-----w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\TIM 2010-03-01 17:34:22 . 2010-03-01 17:34:23 -------- d-----w- C:\Arquivos de programas\TIM 2010-02-18 15:24:18 . 2010-02-18 15:33:35 -------- d-----w- C:\Arquivos de programas\Zylom Games . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2010-03-04 12:50:17 . 2008-11-06 18:50:52 -------- d---a-w- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2010-02-23 17:13:55 . 2006-03-02 12:00:00 80546 ----a-w- C:\WINDOWS\system32\perfc016.dat 2010-02-23 17:13:55 . 2006-03-02 12:00:00 471708 ----a-w- C:\WINDOWS\system32\perfh016.dat 2010-02-18 15:29:31 . 2009-08-22 02:54:41 -------- d-----w- C:\Arquivos de programas\Google 2010-02-10 14:02:39 . 2008-11-05 02:13:32 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help 2010-02-07 12:10:57 . 2009-07-17 19:54:29 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\Norton 2010-02-07 12:10:54 . 2009-07-17 20:21:52 -------- d-----w- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2010-01-31 12:08:32 . 2010-01-31 12:08:32 -------- d-----w- C:\Arquivos de programas\Microsoft CAPICOM 2.1.0.2 2010-01-20 16:32:57 . 2009-09-30 18:16:10 -------- d-----w- C:\Arquivos de programas\Microsoft Silverlight 2010-01-16 00:43:37 . 2010-01-16 00:43:37 -------- d-----w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\gtk-2.0 2010-01-11 19:19:27 . 2008-11-04 01:33:51 -------- d-----w- C:\Arquivos de programas\Windows Live 2010-01-11 19:03:38 . 2010-01-11 19:03:38 3584 ----a-r- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2010-01-11 19:03:36 . 2010-01-11 19:03:36 -------- d-----w- C:\Arquivos de programas\Windows Installer Clean Up 2010-01-11 19:03:13 . 2010-01-11 19:03:13 -------- d-----w- C:\Arquivos de programas\MSECACHE 2010-01-08 18:58:30 . 2010-01-08 18:56:42 -------- d-----w- C:\Arquivos de programas\Cute Cute 2010-01-08 18:56:51 . 2010-01-08 18:56:51 -------- d-----w- C:\Arquivos de programas\Firebird 2010-01-08 02:57:28 . 2008-11-05 02:17:59 -------- d-----w- C:\Arquivos de programas\Microsoft Works 2010-01-06 14:08:08 . 2010-01-08 12:12:38 57856 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\components\coo lirisstub.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 545280 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\PicLensHe lper.exe 2010-01-06 14:08:08 . 2010-01-08 12:12:38 4726272 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\cooliris1 90.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 4725760 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\cooliris1 92.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 344064 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\LaunchCoo liris.exe 2010-01-06 14:08:08 . 2010-01-08 12:12:38 153600 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\plugins\npcool irisplugin.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 103424 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\pixomatic .dll 2010-01-05 09:56:13 . 2006-03-02 12:00:00 832512 ------w- C:\WINDOWS\system32\wininet.dll 2010-01-05 09:56:07 . 2009-06-09 23:27:05 78336 ----a-w- C:\WINDOWS\system32\ieencode.dll 2010-01-05 09:56:06 . 2006-03-02 12:00:00 17408 ----a-w- C:\WINDOWS\system32\corpol.dll 2009-12-31 16:50:03 . 2008-10-19 21:49:58 353792 ----a-w- C:\WINDOWS\system32\drivers\srv.sys 2009-12-21 13:10:01 . 2009-05-27 13:58:12 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll 2009-12-21 13:09:28 . 2009-12-21 13:09:28 152576 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Sun\Java\jre1.6.0_17\lzma.dll 2009-12-21 13:05:54 . 2009-12-21 13:05:54 79488 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Sun\Java\jre1.6.0_17\gtapi.dll 2009-12-17 07:41:40 . 2008-10-09 12:38:43 345600 ----a-w- C:\WINDOWS\system32\mspaint.exe 2009-12-14 07:09:23 . 2006-03-02 12:00:00 33280 ----a-w- C:\WINDOWS\system32\csrsrv.dll 2009-12-09 10:09:22 . 2008-10-19 21:49:34 2193408 ------w- C:\WINDOWS\system32\ntoskrnl.exe 2009-12-09 10:09:21 . 2008-10-19 21:49:34 2070272 ------w- C:\WINDOWS\system32\ntkrnlpa.exe 2009-08-22 02:54:37 . 2009-08-22 02:54:37 56 --sh--r- C:\WINDOWS\system32\351D17868A.sys 2009-08-22 02:54:37 . 2009-08-22 02:54:37 1682 --sha-w- C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( SnapShot@2010-03-05_23.50.22 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-06 00:41:56 . 2010-03-06 00:41:56 16384 C:\WINDOWS\Temp\Perflib_Perfdata_670.dat + 2010-03-06 00:42:00 . 2010-03-06 00:42:00 16384 C:\WINDOWS\Temp\Perflib_Perfdata_2cc.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "NitroPC"="C:\Arquivos de programas\NitroPC\NitroPC.exe" [2008-08-19 20:11:07 3477504] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "avast!"="C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" [2009-11-24 23:51:40 81000] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 20:10:28 35696] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-15 15:46:46 135168] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-15 15:46:46 159744] "Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2008-02-15 15:46:18 131072] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre6\bin\jusched.exe" [2009-12-21 13:10:04 149280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce] "GbPluginBb"="C:\ARQUIV~1\GbPlugin\gbieh.dll" [2010-02-18 13:19:34 323360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 02:20:54 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2010-02-18 13:19:34 323360 ----a-w- C:\Arquivos de programas\GbPlugin\gbieh.dll HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CoolSMS HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-03 21:43:28 69632 ----a-w- C:\WINDOWS\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 02:20:54 15360 ------w- C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2009-04-23 13:51:38 691656 ----a-w- C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fssui] 2009-08-06 01:48:42 647520 ----a-w- C:\Arquivos de programas\Windows Live\Family Safety\fsui.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] C:\Arquivos de programas\Microsoft ActiveSync\Wcescomm.exe [BU] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2008-02-15 15:46:46 159744 ----a-w- C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2008-02-15 15:46:46 135168 ----a-w- C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] 2007-09-20 12:51:46 1836328 ----a-w- C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2007-03-01 18:57:24 153136 ----a-w- C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2008-02-15 15:46:18 131072 ----a-w- C:\WINDOWS\system32\igfxpers.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2005-01-12 06:01:32 32768 ----a-w- C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2007-10-16 21:30:10 16855552 ----a-w- C:\WINDOWS\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] 2007-10-11 14:04:04 1826816 ----a-w- C:\WINDOWS\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM] C:\Arquivos de programas\SweetIM\Messenger\SweetIM.exe [BU] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "ose"=3 (0x3) "odserv"=3 (0x3) "gusvc"=2 (0x2) "fsssvc"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Arquivos de programas\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"= "C:\\Arquivos de programas\\NitroPC\\NitroPC.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 GbpKm;Gbp KernelMode;C:\WINDOWS\system32\drivers\gbpkm.sys [4/3/2010 09:49:52 30752] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [13/1/2009 10:16:15 114768] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswF sBlk.sys [13/1/2009 10:16:15 20560] R2 fssfltr;FssFltr;C:\WINDOWS\system32\drivers\fssflt r_tdi.sys [8/1/2009 18:25:35 54752] R2 GbpSv;Gbp Service;C:\ARQUIV~1\GbPlugin\GbpSv.exe [4/3/2010 09:49:50 54048] S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [10/12/2008 19:45:06 721904] S3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbE xDisk.Sys [2/8/2009 18:51:10 36608] S3 NitroPCSrv;NitroPC Service;C:\Arquivos de programas\NitroPC\NitroPCService.exe [29/5/2009 23:29:46 847376] S4 fsssvc;Serviço Windows Live Proteção para a Família;C:\Arquivos de programas\Windows Live\Family Safety\fsssvc.exe [5/8/2009 22:48:42 704864] . Conteúdo da pasta 'Tarefas Agendadas' 2010-03-06 C:\WINDOWS\Tasks\OGALogon.job - C:\WINDOWS\system32\OGAEXEC.exe [2009-08-03 18:07:42 . 2009-08-03 18:07:42] . . ------- Scan Suplementar ------- . uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm490YYBR&fl=0&ptb=3LukTTJP75 SSyzeK7ZGIbw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms} uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk TCP: {E355F345-0899-42C7-8EC9-5EB513C50D05} = 200.204.0.10,200.204.0.138 DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab FF - ProfilePath - C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\ FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q= FF - prefs.js: browser.search.selectedEngine - SweetIM Search FF - prefs.js: browser.startup.homepage - www.google.com.br FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q= FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- C:\Arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . - - - - ORFÃOS REMOVIDOS - - - - WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-05 21:47:32 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************** ************************ . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-2794425892-4234795162-1915792908-1004\Software\Microsoft\SystemCertificates\Address Book*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(788) C:\Arquivos de programas\GbPlugin\gbieh.dll . Tempo para conclusão: 2010-03-05 21:49:27 ComboFix-quarantined-files.txt 2010-03-06 00:49:25 Pré-execução: 13 pasta(s) 138.706.808.832 bytes disponíveis Pós execução: 14 pasta(s) 138.693.603.328 bytes disponíveis - - End Of File - - 850B7CEC7B5C52D13456C33B0283B469 |
|
|
|
|
|
#13 (permalink) | |
|
Ubbergeek
|
*Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo:
Citação:
*Arraste o arquivo para o Combofix conforme ilustração abaixo: ![]() *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!! *Ao final do procedimento, o programa será fechado automaticamente e será mostrado o relatório *Cole o relatório criado em C:\combofix.txt e novo log do hijack Ficamos no aguardo! |
|
|
|
|
|
|
#14 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
ficou assim
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:41:27, on 5/3/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16981) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\NitroPC\NitroPC.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\TIM\GSM\TIMWEB.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Arquivos de programas\Windows Live\Family Safety\fssbho.dll O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file) O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.d ll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file) O4 - HKLM\..\Run: [avast!] "C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [NitroPC] "C:\Arquivos de programas\NitroPC\NitroPC.exe" -minimized O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.semptoshiba.com.br O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E355F345-0899-42C7-8EC9-5EB513C50D05}: NameServer = 200.204.0.10,200.204.0.138 O17 - HKLM\System\CCS\Services\Tcpip\..\{E97E6F67-B20B-4369-A6F5-9E6274A9E549}: NameServer = 189.40.224.5 189.38.95.95 O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NitroPC Service (NitroPCSrv) - Intelliclick Informática - C:\Arquivos de programas\NitroPC\NitroPCService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe -- End of file - 7633 bytes |
|
|
|
|
|
#15 (permalink) |
|
Ubbergeek
|
Faltou o Log do combofix.
|
|
|
|
|
|
#16 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
aki o do combo fix
omboFix 10-03-05.01 - MICHEL ANSELHO 06/03/2010 18:39:30.4.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.523 [GMT -3:00] Executando de: C:\Documents and Settings\MICHEL ANSELHO\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100305-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !! . ADS - drivers: deleted 204 bytes in 1 streams. (((((((((((((((( Arquivos/Ficheiros criados de 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))) . 2010-03-05 22:41:01 . 2010-03-05 22:41:01 -------- d-----w- C:\Arquivos de programas\Trend Micro 2010-03-04 12:50:24 . 2009-01-13 20:42:30 113968 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}\components\GbMzhBb.dll 2010-03-04 12:49:52 . 2010-02-18 13:20:44 30752 ----a-w- C:\WINDOWS\system32\drivers\gbpkm.sys 2010-03-04 12:49:38 . 2010-03-04 12:49:52 -------- d-----w- C:\Arquivos de programas\GbPlugin 2010-03-04 12:49:38 . 2010-03-04 12:49:38 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin 2010-03-04 12:48:38 . 2010-02-24 13:53:26 1688288 ----a-w- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP\gbplugin_ie_bb_setup.exe 2010-03-01 17:35:34 . 2008-04-13 19:45:40 32128 -c--a-w- C:\WINDOWS\system32\dllcache\usbccgp.sys 2010-03-01 17:35:34 . 2008-04-13 19:45:40 32128 ----a-w- C:\WINDOWS\system32\drivers\usbccgp.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 621056 ----a-w- C:\WINDOWS\system32\drivers\mod7700.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 101120 ----a-w- C:\WINDOWS\system32\drivers\ewusbmdm.sys 2010-03-01 17:34:50 . 2008-12-17 19:00:50 100992 ----a-w- C:\WINDOWS\system32\drivers\ewusbnet.sys 2010-03-01 17:34:49 . 2008-12-17 19:00:50 24448 ----a-w- C:\WINDOWS\system32\drivers\ewdcsc.sys 2010-03-01 17:34:49 . 2008-12-17 19:00:50 103168 ----a-w- C:\WINDOWS\system32\drivers\ewusbfake.sys 2010-03-01 17:34:23 . 2010-03-01 17:34:23 -------- d-----w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\TIM 2010-03-01 17:34:22 . 2010-03-01 17:34:23 -------- d-----w- C:\Arquivos de programas\TIM 2010-02-18 15:24:18 . 2010-02-18 15:33:35 -------- d-----w- C:\Arquivos de programas\Zylom Games . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2010-03-04 12:50:17 . 2008-11-06 18:50:52 -------- d---a-w- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2010-02-23 17:13:55 . 2006-03-02 12:00:00 80546 ----a-w- C:\WINDOWS\system32\perfc016.dat 2010-02-23 17:13:55 . 2006-03-02 12:00:00 471708 ----a-w- C:\WINDOWS\system32\perfh016.dat 2010-02-18 15:29:31 . 2009-08-22 02:54:41 -------- d-----w- C:\Arquivos de programas\Google 2010-02-10 14:02:39 . 2008-11-05 02:13:32 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help 2010-02-07 12:10:57 . 2009-07-17 19:54:29 -------- d-----w- C:\Documents and Settings\All Users\Dados de aplicativos\Norton 2010-02-07 12:10:54 . 2009-07-17 20:21:52 -------- d-----w- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2010-01-31 12:08:32 . 2010-01-31 12:08:32 -------- d-----w- C:\Arquivos de programas\Microsoft CAPICOM 2.1.0.2 2010-01-20 16:32:57 . 2009-09-30 18:16:10 -------- d-----w- C:\Arquivos de programas\Microsoft Silverlight 2010-01-16 00:43:37 . 2010-01-16 00:43:37 -------- d-----w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\gtk-2.0 2010-01-11 19:19:27 . 2008-11-04 01:33:51 -------- d-----w- C:\Arquivos de programas\Windows Live 2010-01-11 19:03:38 . 2010-01-11 19:03:38 3584 ----a-r- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe 2010-01-11 19:03:36 . 2010-01-11 19:03:36 -------- d-----w- C:\Arquivos de programas\Windows Installer Clean Up 2010-01-11 19:03:13 . 2010-01-11 19:03:13 -------- d-----w- C:\Arquivos de programas\MSECACHE 2010-01-08 18:58:30 . 2010-01-08 18:56:42 -------- d-----w- C:\Arquivos de programas\Cute Cute 2010-01-08 18:56:51 . 2010-01-08 18:56:51 -------- d-----w- C:\Arquivos de programas\Firebird 2010-01-08 02:57:28 . 2008-11-05 02:17:59 -------- d-----w- C:\Arquivos de programas\Microsoft Works 2010-01-06 14:08:08 . 2010-01-08 12:12:38 57856 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\components\coo lirisstub.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 545280 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\PicLensHe lper.exe 2010-01-06 14:08:08 . 2010-01-08 12:12:38 4726272 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\cooliris1 90.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 4725760 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\cooliris1 92.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 344064 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\LaunchCoo liris.exe 2010-01-06 14:08:08 . 2010-01-08 12:12:38 153600 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\plugins\npcool irisplugin.dll 2010-01-06 14:08:08 . 2010-01-08 12:12:38 103424 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\extensions\piclens@cooliris.com\libs\pixomatic .dll 2010-01-05 09:56:13 . 2006-03-02 12:00:00 832512 ------w- C:\WINDOWS\system32\wininet.dll 2010-01-05 09:56:07 . 2009-06-09 23:27:05 78336 ----a-w- C:\WINDOWS\system32\ieencode.dll 2010-01-05 09:56:06 . 2006-03-02 12:00:00 17408 ----a-w- C:\WINDOWS\system32\corpol.dll 2009-12-31 16:50:03 . 2008-10-19 21:49:58 353792 ----a-w- C:\WINDOWS\system32\drivers\srv.sys 2009-12-21 13:10:01 . 2009-05-27 13:58:12 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll 2009-12-21 13:09:28 . 2009-12-21 13:09:28 152576 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Sun\Java\jre1.6.0_17\lzma.dll 2009-12-21 13:05:54 . 2009-12-21 13:05:54 79488 ----a-w- C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Sun\Java\jre1.6.0_17\gtapi.dll 2009-12-17 07:41:40 . 2008-10-09 12:38:43 345600 ----a-w- C:\WINDOWS\system32\mspaint.exe 2009-12-14 07:09:23 . 2006-03-02 12:00:00 33280 ----a-w- C:\WINDOWS\system32\csrsrv.dll 2009-12-09 10:09:22 . 2008-10-19 21:49:34 2193408 ------w- C:\WINDOWS\system32\ntoskrnl.exe 2009-12-09 10:09:21 . 2008-10-19 21:49:34 2070272 ------w- C:\WINDOWS\system32\ntkrnlpa.exe 2009-08-22 02:54:37 . 2009-08-22 02:54:37 56 --sh--r- C:\WINDOWS\system32\351D17868A.sys 2009-08-22 02:54:37 . 2009-08-22 02:54:37 1682 --sha-w- C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( SnapShot@2010-03-05_23.50.22 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-06 21:38:19 . 2010-03-06 21:38:19 16384 C:\WINDOWS\Temp\Perflib_Perfdata_678.dat + 2010-03-06 21:38:19 . 2010-03-06 21:38:19 16384 C:\WINDOWS\Temp\Perflib_Perfdata_358.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "NitroPC"="C:\Arquivos de programas\NitroPC\NitroPC.exe" [2008-08-19 20:11:07 3477504] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "avast!"="C:\Arquivos de programas\Alwil Software\Avast4\ashDisp.exe" [2009-11-24 23:51:40 81000] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 20:10:28 35696] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-15 15:46:46 135168] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-15 15:46:46 159744] "Persistence"="C:\WINDOWS\system32\igfxpers.ex e" [2008-02-15 15:46:18 131072] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre6\bin\jusched.exe" [2009-12-21 13:10:04 149280] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce] "GbPluginBb"="C:\ARQUIV~1\GbPlugin\gbieh.dll" [2010-02-18 13:19:34 323360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 02:20:54 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2010-02-18 13:19:34 323360 ----a-w- C:\Arquivos de programas\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-03 21:43:28 69632 ----a-w- C:\WINDOWS\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2008-04-14 02:20:54 15360 ------w- C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] 2009-04-23 13:51:38 691656 ----a-w- C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fssui] 2009-08-06 01:48:42 647520 ----a-w- C:\Arquivos de programas\Windows Live\Family Safety\fsui.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] C:\Arquivos de programas\Microsoft ActiveSync\Wcescomm.exe [BU] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2008-02-15 15:46:46 159744 ----a-w- C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2008-02-15 15:46:46 135168 ----a-w- C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] 2007-09-20 12:51:46 1836328 ----a-w- C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2007-03-01 18:57:24 153136 ----a-w- C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2008-02-15 15:46:18 131072 ----a-w- C:\WINDOWS\system32\igfxpers.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2005-01-12 06:01:32 32768 ----a-w- C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2007-10-16 21:30:10 16855552 ----a-w- C:\WINDOWS\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] 2007-10-11 14:04:04 1826816 ----a-w- C:\WINDOWS\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM] C:\Arquivos de programas\SweetIM\Messenger\SweetIM.exe [BU] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "ose"=3 (0x3) "odserv"=3 (0x3) "gusvc"=2 (0x2) "fsssvc"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Arquivos de programas\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"= "C:\\Arquivos de programas\\NitroPC\\NitroPC.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 GbpKm;Gbp KernelMode;C:\WINDOWS\system32\drivers\gbpkm.sys [4/3/2010 09:49:52 30752] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [13/1/2009 10:16:15 114768] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswF sBlk.sys [13/1/2009 10:16:15 20560] R2 fssfltr;FssFltr;C:\WINDOWS\system32\drivers\fssflt r_tdi.sys [8/1/2009 18:25:35 54752] R2 GbpSv;Gbp Service;C:\ARQUIV~1\GbPlugin\GbpSv.exe [4/3/2010 09:49:50 54048] S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [10/12/2008 19:45:06 721904] S3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbE xDisk.Sys [2/8/2009 18:51:10 36608] S3 NitroPCSrv;NitroPC Service;C:\Arquivos de programas\NitroPC\NitroPCService.exe [29/5/2009 23:29:46 847376] S4 fsssvc;Serviço Windows Live Proteção para a Família;C:\Arquivos de programas\Windows Live\Family Safety\fsssvc.exe [5/8/2009 22:48:42 704864] . Conteúdo da pasta 'Tarefas Agendadas' 2010-03-06 C:\WINDOWS\Tasks\OGALogon.job - C:\WINDOWS\system32\OGAEXEC.exe [2009-08-03 18:07:42 . 2009-08-03 18:07:42] . . ------- Scan Suplementar ------- . uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm490YYBR&fl=0&ptb=3LukTTJP75 SSyzeK7ZGIbw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms} uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MICHEL ANSELHO\Menu Iniciar\Programas\IMVU\Run IMVU.lnk TCP: {E355F345-0899-42C7-8EC9-5EB513C50D05} = 200.204.0.10,200.204.0.138 DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab FF - ProfilePath - C:\Documents and Settings\MICHEL ANSELHO\Dados de aplicativos\Mozilla\Firefox\Profiles\n26drtqt.defa ult\ FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q= FF - prefs.js: browser.search.selectedEngine - SweetIM Search FF - prefs.js: browser.startup.homepage - www.google.com.br FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q= FF - plugin: C:\Arquivos de programas\Microsoft\Office Live\npOLW.dll FF - plugin: C:\Arquivos de programas\Mozilla Firefox\plugins\npyaxmpb.dll FF - plugin: C:\Arquivos de programas\Mozilla Firefox\plugins\npzylomgamesplayer.dll FF - plugin: C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Documents and Settings\All Users\Dados de aplicativos\Zylom\ZylomGamesPlayer\npzylomgamespla yer.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- C:\Arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-06 18:44:06 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************** ************************ . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-2794425892-4234795162-1915792908-1004\Software\Microsoft\SystemCertificates\Address Book*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(768) C:\Arquivos de programas\GbPlugin\gbieh.dll . Tempo para conclusão: 2010-03-06 18:45:54 ComboFix-quarantined-files.txt 2010-03-06 21:45:51 ComboFix2.txt 2010-03-06 01:41:06 Pré-execução: 13 pasta(s) 138.707.492.864 bytes disponíveis Pós execução: 14 pasta(s) 138.694.115.328 bytes disponíveis - - End Of File - - D7CFD1C4CCC09A2DEE05DEB84AD726CB o que faço agora qdo inicio o pc sempre fica o combofix trabalhando e como não entendo muito queria saber o que deu nesses relatorios rs que estou boiando rs... desde ja muito obrigado |
|
|
|
|
|
#17 (permalink) |
|
Ubbergeek
|
Log limpo.
*Clique em [Iniciar] > [Executar] > digite: Combofix /uninstall *Clique [OK] ![]() *Clique em [Executar] *Aguarde até surgir a mensagem: "ComboFix está desinstalado" *Clique [OK] Abraço! |
|
|
|
|
|
#18 (permalink) |
|
Newbie
Registrado em: Oct 2009
Mensagens: 12
Reputação: 0
![]() |
Olaa...muito obrigado pela ajuda ja desinstalei o combofix deu tudo certo...
|
|
|
|
![]() |
| Opções do Tópico | |
|
|