Ir ao conteúdo
  • Comunicados

    • diego_moicano

      Gostaria de se tornar um analista em Remoção de Malware?   07-12-2015

      Gostaria de se tornar um analista em Remoção de Malware? O Fórum Clube do Hardware deu início a um programa de treinamento em análises de log. Os interessados deverão enviar um email para aprendizes (arroba) clubedohardware (ponto) com (ponto) br respondendo as seguintes perguntas: Por que você gostaria de aprender a analisar logs? Possui tempo hábil para o treinamento? Tem conhecimentos em informática? Se sim descreva-os. Possui inglês para leitura? Qual seu objetivo após completar o treinamento?   Não se esqueça de incluir no e-mail o seu nome de usuário (fornecer o link também), idade e cidade onde vive. Adicione também qualquer experiência e/ou razão sobre o porquê você seria um bom Analista. É digno de nota que apenas os que forem selecionados receberão resposta por MP (Mensagem Pessoal), não existe um padrão na escolha dos futuros aprendizes, todos os e-mails serão lidos e serão analisados de forma imparcial, portanto não será permitido reclamações neste aspecto. O treinamento é dado no próprio fórum. Quando um aprendiz é selecionado ele é movido para um novo grupo, onde terá acesso a fóruns fechados para os demais usuários onde poderá dar inicio ao seu treinamento. Importante: A cada 30 dias os e-mails não selecionados serão apagados, portanto você pode enviar um novo e-mail após 1 mês, e-mails enviados antes serão desconsiderados.  
    • Gabriel Torres

      Seja um moderador do Clube do Hardware!   12-02-2016

      Prezados membros do Clube do Hardware, Está aberto o processo de seleção de novos moderadores para diversos setores ou áreas do Clube do Hardware. Os requisitos são:   Pelo menos 500 posts e um ano de cadastro; Boa frequência de participação; Ser respeitoso, cordial e educado com os demais membros; Ter bom nível de português; Ter razoável conhecimento da área em que pretende atuar; Saber trabalhar em equipe (com os moderadores, coordenadores e administradores).   Os interessados deverão enviar uma mensagem privada para o usuário @Equipe Clube do Hardware com o título "Candidato a moderador". A mensagem deverá conter respostas às perguntas abaixo:   Qual o seu nome completo? Qual sua data de nascimento? Qual sua formação/profissão? Já atuou como moderador em algo outro fórum, se sim, qual? De forma sucinta, explique o porquê de querer ser moderador do fórum e conte-nos um pouco sobre você.   OBS: Não se trata de função remunerada. Todos que fazem parte do staff são voluntários.
Entre para seguir isso  
andereana

por favor analise meu log....o q devo fazer?

Recommended Posts

esta abrindo janelas automaticas no IE....dum tal de proteja seu pc...ACHO Q DEVE SER ALGUM SYWARE

vi qual programas a serem usados...mas não sei exatamente como uSAR

AQUI VAI O LOG

Logfile of HijackThis v1.99.1

Scan saved at 16:34:51, on 24/3/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\sistray.exe

C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE

c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\mstsc.exe

C:\Arquivos de programas\WinRAR\WinRAR.exe

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\Rar$EX00.422\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {2B0B59B4-55A3-4737-9FD5-B93C6430BF75} - C:\WINDOWS\system32\gfhcxash.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar2.dll

O2 - BHO: G-Buster Browser Defense Sicredi - {C41A1C0E-EA6C-11D4-B1B8-444553540011} - C:\ARQUIV~1\GbPlugin\gbiehscd.dll

O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Arquivos de programas\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar2.dll

O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Arquivos de programas\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

O4 - HKCU\..\Run: [EPSON Stylus CX5600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAL.EXE /FU "C:\WINDOWS\TEMP\E_SA3.tmp" /EF "HKCU"

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399011} (GbPluginObj Class) - https://si-plg.sicredi.com.br/Cab/GbPluginScd.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginScd - C:\ARQUIV~1\GbPlugin\gbiehscd.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O20 - Winlogon Notify: winwea32 - winwea32.dll (file missing)

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)

Compartilhar este post


Link para o post
Compartilhar em outros sites

- Faça o download do ComboFix

  • Desative, temporariamente, o antivírus;
  • Feche todas as janelas abertas;
  • Dê um duplo-clique no ComboFix.exe, clique em "Executar" e digite "1" + Enter para prosseguir o Fix. Pode demorar algum tempo.
  • O ComboFix poderá reiniciar o PC automaticamente para completar o processo de remoção.
  • Quando terminar, será gerado um log, que estará em C:\ComboFix.txt.
  • Não clique na Janela do ComboFix, nem o feche clicando no X, enquanto estiver rodando, não mova o mouse e não use o teclado, pois senão irá parar e seu desktop ficará em branco.
  • Para parar ou sair do ComboFix, tecle "N".
  • Cole o ComboFix.txt na sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites
  • Autor do tópico
  • ComboFix 08-03-22.3 - Administrador 2008-04-01 8:16:35.2 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.504 [GMT -3:00]

    Executando de: C:\Documents and Settings\Administrador\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    .

    ((((((((((((((((((((((( Ficheiros criados de 2008-03-01 to 2008-04-01 ))))))))))))))))))))))))))))))))

    .

    2008-03-31 15:55 . 2008-04-01 08:16 <DIR> d-------- C:\Arquivos de programas\ClienteCobranca

    2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Sony

    2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Arquivos de programas\Vstplugins

    2008-03-27 16:24 . 2008-03-27 16:25 <DIR> d-------- C:\Arquivos de programas\Sony

    2008-03-27 16:23 . 2008-03-27 16:23 <DIR> d-------- C:\Arquivos de programas\Sony Setup

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\WINDOWS\system32\xircom

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\WINDOWS\system32\oobe

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\Arquivos de programas\microsoft frontpage

    2008-03-24 15:54 . 2008-03-24 15:58 <DIR> d-------- C:\HijackThis

    2008-03-20 09:26 . 2008-03-20 09:26 <DIR> d-------- C:\Arquivos de programas\ABBYY FineReader 6.0 Sprint

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\WINDOWS\system32\PhotoImpression Slideshow

    2008-03-20 09:25 . 2008-03-20 11:33 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\ArcSoft

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\ArcSoft

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\Arquivos de programas\ArcSoft

    2008-03-20 09:25 . 2004-08-04 07:52 413,696 -ra------ C:\WINDOWS\system32\msvc1e8a.rra

    2008-03-20 09:25 . 2004-12-07 10:11 258,352 --a------ C:\WINDOWS\system32\unicows.dll

    2008-03-20 09:25 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL

    2008-03-20 09:25 . 2006-10-26 09:29 126,976 --a------ C:\WINDOWS\system32\PhotoImpression Slideshow.scr

    2008-03-20 09:25 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys

    2008-03-20 09:24 . 2008-03-20 09:24 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\EPSON

    2008-03-20 09:24 . 2006-12-07 23:04 76,800 --a------ C:\WINDOWS\system32\E_FLBCAL.DLL

    2008-03-20 09:24 . 2006-04-18 23:00 62,976 --a------ C:\WINDOWS\system32\E_FD4BCAL.DLL

    2008-03-20 09:24 . 2005-09-19 16:43 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

    2008-03-20 09:24 . 2005-09-19 16:43 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys

    2008-03-20 09:24 . 2005-09-19 16:43 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys

    2008-03-20 09:24 . 2006-07-11 22:00 1,963 --a------ C:\WINDOWS\EPBUYINK.HTM

    2008-03-20 09:22 . 2008-03-20 09:22 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\InstallShield

    2008-03-20 09:22 . 2008-03-26 07:40 <DIR> d-------- C:\Arquivos de programas\epson

    2008-03-20 09:07 . 2008-03-20 09:07 53,824 --a------ C:\WINDOWS\system32\gfhcxash.dll

    2008-03-18 08:31 . 2008-03-18 08:31 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Lavasoft

    2008-03-18 08:31 . 2008-03-18 08:31 <DIR> d-------- C:\Arquivos de programas\Lavasoft

    2008-03-18 08:30 . 2008-03-18 08:30 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

    2008-03-18 08:27 . 2008-03-18 08:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe

    2008-03-18 07:52 . 2008-03-20 08:59 1,343,991 ---hs---- C:\WINDOWS\system32\hvjdedip.ini

    2008-03-14 07:44 . 2008-03-14 07:44 <DIR> d-------- C:\Arquivos de programas\MSXML 6.0

    2008-03-14 07:43 . 2008-03-18 07:41 1,350,686 ---hs---- C:\WINDOWS\system32\ooaynnfp.ini

    2008-03-13 06:47 . 2008-03-14 07:40 1,343,375 ---hs---- C:\WINDOWS\system32\eywgywgb.ini

    2008-03-12 06:42 . 2008-03-13 06:43 1,343,255 ---hs---- C:\WINDOWS\system32\xiiwrhkj.ini

    2008-03-11 15:21 . 2008-03-11 15:21 <DIR> d-------- C:\Arquivos de programas\Microsoft.NET

    2008-03-11 15:19 . 2008-03-18 07:44 <DIR> d-------- C:\Arquivos de programas\Microsoft SQL Server

    2008-03-11 15:06 . 2008-03-11 15:06 <DIR> d-------- C:\Arquivos de programas\Microsoft Works

    2008-03-11 15:02 . 2008-03-11 15:06 <DIR> d-------- C:\WINDOWS\SHELLNEW

    2008-03-11 15:02 . 2008-03-11 15:02 <DIR> dr-h----- C:\MSOCache

    2008-03-11 15:02 . 2008-03-14 07:45 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help

    2008-03-11 13:28 . 2008-03-12 06:39 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

    2008-03-11 13:28 . 2008-03-12 06:39 <DIR> d-------- C:\Arquivos de programas\GbPlugin

    2008-03-11 07:50 . 2008-03-26 17:01 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\skypePM

    2008-03-11 07:50 . 2008-03-11 07:50 32 --a------ C:\Documents and Settings\All Users\Dados de aplicativos\ezsid.dat

    2008-03-10 14:40 . 2008-03-18 08:25 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\AdobeUM

    2008-03-10 11:19 . 2008-03-10 11:19 268 --ah----- C:\sqmdata02.sqm

    2008-03-10 11:19 . 2008-03-10 11:19 244 --ah----- C:\sqmnoopt02.sqm

    2008-03-10 11:11 . 2008-03-10 11:11 268 --ah----- C:\sqmdata01.sqm

    2008-03-10 11:11 . 2008-03-10 11:11 244 --ah----- C:\sqmnoopt01.sqm

    2008-03-10 11:10 . 2008-03-10 11:10 268 --ah----- C:\sqmdata00.sqm

    2008-03-10 11:10 . 2008-03-10 11:10 244 --ah----- C:\sqmnoopt00.sqm

    2008-03-10 11:09 . 2008-03-10 11:09 4,128 --a------ C:\WINDOWS\system32\DllCache\INFCACHE.1

    2008-03-10 06:38 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

    2008-03-10 06:38 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Skype

    2008-03-07 10:13 . 2008-03-26 17:01 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Skype

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Arquivos de programas\Skype

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Skype

    2008-03-07 10:06 . 2008-03-07 10:06 <DIR> d-------- C:\Documents and Settings\Administrador\Contacts

    2008-03-07 09:45 . 2008-03-11 15:38 <DIR> d-------- C:\Arquivos de programas\Windows Live Toolbar

    2008-03-07 09:39 . 2008-03-07 09:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE

    2008-03-07 09:28 . 2008-03-07 09:32 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

    2008-03-07 09:27 . 2008-03-07 09:27 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

    2008-03-07 09:27 . 2008-03-11 15:37 <DIR> d-------- C:\Arquivos de programas\Windows Live

    2008-03-07 09:11 . 2008-03-07 09:11 <DIR> d-------- C:\WINDOWS\system32\pt-br

    2008-03-07 09:10 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

    2008-03-07 09:09 . 2008-03-10 15:13 <DIR> d-------- C:\WINDOWS\system32\DllCache

    2008-03-07 09:05 . 2007-12-06 23:09 6,066,176 --------- C:\WINDOWS\system32\DllCache\ieframe.dll

    2008-03-07 09:05 . 2007-07-01 00:31 2,455,488 --------- C:\WINDOWS\system32\DllCache\ieapfltr.dat

    2008-03-07 09:05 . 2007-07-01 00:36 1,024,000 --------- C:\WINDOWS\system32\DllCache\ieframe.dll.mui

    2008-03-07 09:05 . 2007-12-06 23:09 459,264 --------- C:\WINDOWS\system32\DllCache\msfeeds.dll

    2008-03-07 09:05 . 2007-12-06 23:09 383,488 --------- C:\WINDOWS\system32\DllCache\ieapfltr.dll

    2008-03-07 09:05 . 2007-12-06 23:09 267,776 --------- C:\WINDOWS\system32\DllCache\iertutil.dll

    2008-03-07 09:05 . 2007-12-06 23:09 63,488 --------- C:\WINDOWS\system32\DllCache\icardie.dll

    2008-03-07 09:05 . 2007-12-06 23:09 52,224 --------- C:\WINDOWS\system32\DllCache\msfeedsbs.dll

    2008-03-07 09:05 . 2007-12-06 08:00 13,824 --------- C:\WINDOWS\system32\DllCache\ieudinit.exe

    2008-03-07 09:01 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\DllCache\custsat.dll

    2008-03-07 08:16 . 2007-07-09 10:19 582,656 --------- C:\WINDOWS\system32\DllCache\rpcrt4.dll

    2008-03-07 08:08 . 2006-12-07 02:29 2,374,472 --------- C:\WINDOWS\system32\DllCache\wmvcore.dll

    2008-03-07 07:59 . 2008-03-10 11:25 <DIR> d--h----- C:\WINDOWS\$hf_mig$

    2008-03-07 07:57 . 2008-03-07 07:57 <DIR> d--hs---- C:\Documents and Settings\Administrador\UserData

    2008-03-07 07:56 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui

    2008-03-07 07:56 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui

    2008-03-07 07:56 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui

    2008-03-07 07:56 . 2007-07-30 19:18 20,824 --a------ C:\WINDOWS\system32\wuaueng.dll.mui

    2008-03-07 07:54 . 2008-03-07 07:54 1,190 --a------ C:\WINDOWS\mozver.dat

    2008-03-06 17:35 . 2008-03-06 17:35 0 --a------ C:\WINDOWS\nsreg.dat

    2008-03-06 17:03 . 2008-03-10 13:02 <DIR> d-------- C:\Arquivos de programas\Google

    2008-03-06 17:02 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

    2008-03-06 13:06 . 2005-09-19 13:42 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys

    2008-03-06 13:05 . 2008-03-06 16:48 <DIR> d-------- C:\WINDOWS\SiS

    2008-03-06 13:05 . 2005-09-19 13:43 57,984 --a------ C:\WINDOWS\system32\drivers\redbook.sys

    .

    ((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2008-03-20 12:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

    2008-03-06 20:02 --------- d-----w C:\Arquivos de programas\Java

    2008-03-06 19:54 --------- d-----w C:\Arquivos de programas\Realtek Sound Manager

    2008-03-06 19:54 --------- d-----w C:\Arquivos de programas\AvRack

    2008-03-06 19:53 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

    2008-03-06 19:49 --------- d-----w C:\Arquivos de programas\SiS VGA Utilities V3.61a

    2008-03-06 19:22 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Java

    2008-03-06 19:18 --------- d-----w C:\Arquivos de programas\ESET

    2008-03-06 19:15 --------- d-----w C:\Arquivos de programas\Serviços on-line

    2008-03-06 19:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços

    2008-03-06 19:09 4,128 ----a-w C:\WINDOWS\system32\drivers\INFCACHE.1

    2008-01-11 05:37 44,544 ------w C:\WINDOWS\system32\DllCache\pngfilt.dll

    .

    ((((((((((((((((((((((((((((( snapshot@2008-03-24_16.10.07.90 )))))))))))))))))))))))))))))))))))))))))

    .

    + 2007-09-14 18:51:56 655,360 ----a-w C:\WINDOWS\system32\CDDBControl.dll

    + 2007-09-14 18:51:56 98,304 ----a-w C:\WINDOWS\system32\CddbLangDE.dll

    + 2007-09-14 18:51:56 98,304 ----a-w C:\WINDOWS\system32\CddbLangES.dll

    + 2007-09-14 18:51:56 98,304 ----a-w C:\WINDOWS\system32\CddbLangFR.dll

    + 2007-09-14 18:51:56 102,400 ----a-w C:\WINDOWS\system32\CddbLangIT.dll

    + 2007-09-14 18:51:56 77,824 ----a-w C:\WINDOWS\system32\CddbLangJA.dll

    + 2007-09-14 18:51:56 98,304 ----a-w C:\WINDOWS\system32\CddbLangNL.dll

    + 2007-09-14 18:51:56 765,952 ----a-w C:\WINDOWS\system32\CDDBUI.dll

    + 2003-08-07 23:01:50 237,568 ----a-w C:\WINDOWS\system32\lame_enc.dll

    - 2004-08-04 03:45:26 1,392,671 ----a-w C:\WINDOWS\system32\msvbvm60.dll

    + 2004-02-23 08:00:00 1,386,496 ----a-w C:\WINDOWS\system32\msvbvm60.dll

    + 2002-01-06 00:37:00 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll

    + 2006-12-02 01:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll

    + 2006-12-02 01:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll

    + 2006-12-02 01:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll

    + 2006-12-02 01:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

    + 2006-12-02 03:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll

    + 2006-12-02 03:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll

    + 2006-12-02 03:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll

    + 2006-12-02 03:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll

    + 2006-12-02 03:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll

    + 2006-12-02 03:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll

    + 2006-12-02 03:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll

    + 2006-12-02 03:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll

    + 2006-12-02 03:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll

    + 2006-12-02 03:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll

    + 2006-12-02 03:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll

    + 2006-12-02 03:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll

    + 2006-12-02 03:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll

    + 2006-12-02 03:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll

    .

    -- Snapshot reset to current date --

    .

    (((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

    .

    .

    REGEDIT4

    *Nota* entradas vazias & legítimas por defeito não são mostradas.

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B0B59B4-55A3-4737-9FD5-B93C6430BF75}]

    2008-03-20 09:07 53824 --a------ C:\WINDOWS\system32\gfhcxash.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540011}]

    2007-12-17 17:51 336832 --a------ C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

    "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 06:46 68856]

    "updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

    "EPSON Stylus CX5600 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAL.exe" [2007-01-25 03:00 179200]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

    "SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 07:15 106496]

    "SoundMan"="SOUNDMAN.EXE" [2004-09-16 09:39 69632 C:\WINDOWS\SOUNDMAN.EXE]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

    "MsnMsgr"="C:\Arquivos de programas\MSN Messenger\MsnMsgr.exe" [ ]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "nlsf"="cmd.exe" [2004-08-04 00:45 400384 C:\WINDOWS\system32\cmd.exe]

    "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 00:34 44544]

    C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

    Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

    Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-03-06 16:48:27 331776]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

    "{E37CB5F0-51F5-4395-A808-5FA49E399011}"= C:\ARQUIV~1\GbPlugin\gbiehscd.dll [2007-12-17 17:51 336832]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginScd]

    C:\ARQUIV~1\GbPlugin\gbiehscd.dll 2007-12-17 17:51 336832 C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwea32]

    winwea32.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

    C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"=

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

    "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

    "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

    "C:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

    R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []

    R2 SQLWriter;Escritor VSS do SQL Server;"c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]

    S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 11:43]

    .

    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-04-01 08:18:21

    Windows 5.1.2600 Service Pack 2 NTFS

    Procurando processos ocultos ...

    Procurando entradas auto inicializáveis ocultas ...

    Procurando ficheiros ocultos ...

    Varredura completada com sucesso

    Ficheiros ocultos: 0

    **************************************************************************

    .

    Tempo para conclusão: 2008-04-01 8:18:58

    ComboFix-quarantined-files.txt 2008-04-01 11:18:44

    ComboFix2.txt 2008-03-24 19:11:22

    .

    2008-03-18 10:48:12 --- E O F ---

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    - Selecione o texto abaixo e copie para o bloco de notas. Salve-o como CFScript.txt;

    File::
    C:\WINDOWS\system32\hvjdedip.ini
    C:\WINDOWS\system32\ooaynnfp.ini
    C:\WINDOWS\system32\eywgywgb.ini
    C:\WINDOWS\system32\xiiwrhkj.ini
    C:\WINDOWS\system32\gfhcxash.dll
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B0B59B4-55A3-4737-9FD5-B93C6430BF75}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwea32]

    - Arraste o CFScript.txt para o ComboFix conforme a imagem abaixo:

    CF_Script.gif

    O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

    Não use o mouse nem o teclado quando o ComboFix estiver rodando.

    Quando terminar, será gerado um log, que estará em C:\ComboFix.txt.

    Obs: Se o Combofix não reiniciar seu computador automaticamente, faça-o manualmente.

    Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • ComboFix 08-03-22.3 - Administrador 2008-04-03 9:31:28.3 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.480 [GMT -3:00]

    Executando de: C:\Documents and Settings\Administrador\Desktop\ComboFix.exe

    Command switches used :: C:\Documents and Settings\Administrador\Desktop\CFScript.txt

    * Criado um novo ponto de restauro

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    FILE ::

    C:\WINDOWS\system32\eywgywgb.ini

    C:\WINDOWS\system32\gfhcxash.dll

    C:\WINDOWS\system32\hvjdedip.ini

    C:\WINDOWS\system32\ooaynnfp.ini

    C:\WINDOWS\system32\xiiwrhkj.ini

    .

    ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\WINDOWS\system32\eywgywgb.ini

    C:\WINDOWS\system32\gfhcxash.dll

    C:\WINDOWS\system32\hvjdedip.ini

    C:\WINDOWS\system32\ooaynnfp.ini

    C:\WINDOWS\system32\xiiwrhkj.ini

    .

    ((((((((((((((((((((((( Ficheiros criados de 2008-03-03 to 2008-04-03 ))))))))))))))))))))))))))))))))

    .

    2008-03-31 15:55 . 2008-04-01 11:41 <DIR> d-------- C:\Arquivos de programas\ClienteCobranca

    2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Sony

    2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Arquivos de programas\Vstplugins

    2008-03-27 16:24 . 2008-03-27 16:25 <DIR> d-------- C:\Arquivos de programas\Sony

    2008-03-27 16:23 . 2008-03-27 16:23 <DIR> d-------- C:\Arquivos de programas\Sony Setup

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

    2008-03-24 16:11 . 2008-03-24 16:11 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\WINDOWS\system32\xircom

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\WINDOWS\system32\oobe

    2008-03-24 16:08 . 2008-03-24 16:08 <DIR> d-------- C:\Arquivos de programas\microsoft frontpage

    2008-03-24 15:54 . 2008-03-24 15:58 <DIR> d-------- C:\HijackThis

    2008-03-20 09:26 . 2008-03-20 09:26 <DIR> d-------- C:\Arquivos de programas\ABBYY FineReader 6.0 Sprint

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\WINDOWS\system32\PhotoImpression Slideshow

    2008-03-20 09:25 . 2008-03-20 11:33 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\ArcSoft

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\ArcSoft

    2008-03-20 09:25 . 2008-03-20 09:25 <DIR> d-------- C:\Arquivos de programas\ArcSoft

    2008-03-20 09:25 . 2004-08-04 07:52 413,696 -ra------ C:\WINDOWS\system32\msvc1e8a.rra

    2008-03-20 09:25 . 2004-12-07 10:11 258,352 --a------ C:\WINDOWS\system32\unicows.dll

    2008-03-20 09:25 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL

    2008-03-20 09:25 . 2006-10-26 09:29 126,976 --a------ C:\WINDOWS\system32\PhotoImpression Slideshow.scr

    2008-03-20 09:25 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys

    2008-03-20 09:24 . 2008-03-20 09:24 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\EPSON

    2008-03-20 09:24 . 2006-12-07 23:04 76,800 --a------ C:\WINDOWS\system32\E_FLBCAL.DLL

    2008-03-20 09:24 . 2006-04-18 23:00 62,976 --a------ C:\WINDOWS\system32\E_FD4BCAL.DLL

    2008-03-20 09:24 . 2005-09-19 16:43 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

    2008-03-20 09:24 . 2005-09-19 16:43 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys

    2008-03-20 09:24 . 2005-09-19 16:43 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys

    2008-03-20 09:24 . 2006-07-11 22:00 1,963 --a------ C:\WINDOWS\EPBUYINK.HTM

    2008-03-20 09:22 . 2008-03-20 09:22 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\InstallShield

    2008-03-20 09:22 . 2008-03-26 07:40 <DIR> d-------- C:\Arquivos de programas\epson

    2008-03-18 08:31 . 2008-03-18 08:31 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Lavasoft

    2008-03-18 08:31 . 2008-03-18 08:31 <DIR> d-------- C:\Arquivos de programas\Lavasoft

    2008-03-18 08:30 . 2008-03-18 08:30 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

    2008-03-18 08:27 . 2008-03-18 08:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe

    2008-03-14 07:44 . 2008-03-14 07:44 <DIR> d-------- C:\Arquivos de programas\MSXML 6.0

    2008-03-11 15:21 . 2008-03-11 15:21 <DIR> d-------- C:\Arquivos de programas\Microsoft.NET

    2008-03-11 15:19 . 2008-03-18 07:44 <DIR> d-------- C:\Arquivos de programas\Microsoft SQL Server

    2008-03-11 15:06 . 2008-03-11 15:06 <DIR> d-------- C:\Arquivos de programas\Microsoft Works

    2008-03-11 15:02 . 2008-03-11 15:06 <DIR> d-------- C:\WINDOWS\SHELLNEW

    2008-03-11 15:02 . 2008-03-11 15:02 <DIR> dr-h----- C:\MSOCache

    2008-03-11 15:02 . 2008-03-14 07:45 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help

    2008-03-11 13:28 . 2008-04-03 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

    2008-03-11 13:28 . 2008-03-12 06:39 <DIR> d-------- C:\Arquivos de programas\GbPlugin

    2008-03-11 07:50 . 2008-03-26 17:01 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\skypePM

    2008-03-11 07:50 . 2008-03-11 07:50 32 --a------ C:\Documents and Settings\All Users\Dados de aplicativos\ezsid.dat

    2008-03-10 14:40 . 2008-03-18 08:25 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\AdobeUM

    2008-03-10 11:19 . 2008-03-10 11:19 268 --ah----- C:\sqmdata02.sqm

    2008-03-10 11:19 . 2008-03-10 11:19 244 --ah----- C:\sqmnoopt02.sqm

    2008-03-10 11:11 . 2008-03-10 11:11 268 --ah----- C:\sqmdata01.sqm

    2008-03-10 11:11 . 2008-03-10 11:11 244 --ah----- C:\sqmnoopt01.sqm

    2008-03-10 11:10 . 2008-03-10 11:10 268 --ah----- C:\sqmdata00.sqm

    2008-03-10 11:10 . 2008-03-10 11:10 244 --ah----- C:\sqmnoopt00.sqm

    2008-03-10 11:09 . 2008-03-10 11:09 4,128 --a------ C:\WINDOWS\system32\DllCache\INFCACHE.1

    2008-03-10 06:38 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

    2008-03-10 06:38 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Skype

    2008-03-07 10:13 . 2008-03-26 17:01 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Skype

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Arquivos de programas\Skype

    2008-03-07 10:13 . 2008-03-07 10:13 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Skype

    2008-03-07 10:06 . 2008-03-07 10:06 <DIR> d-------- C:\Documents and Settings\Administrador\Contacts

    2008-03-07 09:45 . 2008-03-11 15:38 <DIR> d-------- C:\Arquivos de programas\Windows Live Toolbar

    2008-03-07 09:39 . 2008-03-07 09:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE

    2008-03-07 09:28 . 2008-03-07 09:32 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

    2008-03-07 09:27 . 2008-03-07 09:27 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

    2008-03-07 09:27 . 2008-03-11 15:37 <DIR> d-------- C:\Arquivos de programas\Windows Live

    2008-03-07 09:11 . 2008-03-07 09:11 <DIR> d-------- C:\WINDOWS\system32\pt-br

    2008-03-07 09:10 . 2005-06-28 09:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

    2008-03-07 09:09 . 2008-03-10 15:13 <DIR> d-------- C:\WINDOWS\system32\DllCache

    2008-03-07 09:05 . 2007-12-06 23:09 6,066,176 --------- C:\WINDOWS\system32\DllCache\ieframe.dll

    2008-03-07 09:05 . 2007-07-01 00:31 2,455,488 --------- C:\WINDOWS\system32\DllCache\ieapfltr.dat

    2008-03-07 09:05 . 2007-07-01 00:36 1,024,000 --------- C:\WINDOWS\system32\DllCache\ieframe.dll.mui

    2008-03-07 09:05 . 2007-12-06 23:09 459,264 --------- C:\WINDOWS\system32\DllCache\msfeeds.dll

    2008-03-07 09:05 . 2007-12-06 23:09 383,488 --------- C:\WINDOWS\system32\DllCache\ieapfltr.dll

    2008-03-07 09:05 . 2007-12-06 23:09 267,776 --------- C:\WINDOWS\system32\DllCache\iertutil.dll

    2008-03-07 09:05 . 2007-12-06 23:09 63,488 --------- C:\WINDOWS\system32\DllCache\icardie.dll

    2008-03-07 09:05 . 2007-12-06 23:09 52,224 --------- C:\WINDOWS\system32\DllCache\msfeedsbs.dll

    2008-03-07 09:05 . 2007-12-06 08:00 13,824 --------- C:\WINDOWS\system32\DllCache\ieudinit.exe

    2008-03-07 09:01 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\DllCache\custsat.dll

    2008-03-07 08:16 . 2007-07-09 10:19 582,656 --------- C:\WINDOWS\system32\DllCache\rpcrt4.dll

    2008-03-07 08:08 . 2006-12-07 02:29 2,374,472 --------- C:\WINDOWS\system32\DllCache\wmvcore.dll

    2008-03-07 07:59 . 2008-03-10 11:25 <DIR> d--h----- C:\WINDOWS\$hf_mig$

    2008-03-07 07:57 . 2008-03-07 07:57 <DIR> d--hs---- C:\Documents and Settings\Administrador\UserData

    2008-03-07 07:56 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui

    2008-03-07 07:56 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui

    2008-03-07 07:56 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui

    2008-03-07 07:56 . 2007-07-30 19:18 20,824 --a------ C:\WINDOWS\system32\wuaueng.dll.mui

    2008-03-07 07:54 . 2008-03-07 07:54 1,190 --a------ C:\WINDOWS\mozver.dat

    2008-03-06 17:35 . 2008-03-06 17:35 0 --a------ C:\WINDOWS\nsreg.dat

    2008-03-06 17:03 . 2008-03-10 13:02 <DIR> d-------- C:\Arquivos de programas\Google

    2008-03-06 17:02 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

    2008-03-06 13:06 . 2005-09-19 13:42 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys

    2008-03-06 13:05 . 2008-03-06 16:48 <DIR> d-------- C:\WINDOWS\SiS

    2008-03-06 13:05 . 2005-09-19 13:43 57,984 --a------ C:\WINDOWS\system32\drivers\redbook.sys

    2008-03-06 13:05 . 2005-09-19 13:43 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS

    2008-03-06 13:04 . 2005-09-19 13:43 76,288 --a------ C:\WINDOWS\system32\usbui.dll

    2008-03-06 13:02 . 2008-03-06 16:13 <DIR> d--h----- C:\Documents and Settings\Default User\Modelos

    2008-03-06 13:02 . 2008-03-06 13:02 <DIR> d-------- C:\Documents and Settings\Default User\Meus documentos

    2008-03-06 13:02 . 2008-03-06 13:02 <DIR> dr------- C:\Documents and Settings\Default User\Menu Iniciar

    .

    ((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2008-03-20 12:31 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

    2008-03-06 20:02 --------- d-----w C:\Arquivos de programas\Java

    2008-03-06 19:54 --------- d-----w C:\Arquivos de programas\Realtek Sound Manager

    2008-03-06 19:54 --------- d-----w C:\Arquivos de programas\AvRack

    2008-03-06 19:53 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

    2008-03-06 19:49 --------- d-----w C:\Arquivos de programas\SiS VGA Utilities V3.61a

    2008-03-06 19:22 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Java

    2008-03-06 19:18 --------- d-----w C:\Arquivos de programas\ESET

    2008-03-06 19:15 --------- d-----w C:\Arquivos de programas\Serviços on-line

    2008-03-06 19:15 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços

    2008-03-06 19:09 4,128 ----a-w C:\WINDOWS\system32\drivers\INFCACHE.1

    2008-01-11 05:37 44,544 ------w C:\WINDOWS\system32\DllCache\pngfilt.dll

    .

    (((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

    .

    .

    REGEDIT4

    *Nota* entradas vazias & legítimas por defeito não são mostradas.

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540011}]

    2007-12-17 17:51 336832 --a------ C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

    "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 06:46 68856]

    "updateMgr"="C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

    "EPSON Stylus CX5600 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAL.exe" [2007-01-25 03:00 179200]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

    "SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 07:15 106496]

    "SoundMan"="SOUNDMAN.EXE" [2004-09-16 09:39 69632 C:\WINDOWS\SOUNDMAN.EXE]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

    "MsnMsgr"="C:\Arquivos de programas\MSN Messenger\MsnMsgr.exe" [ ]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "nlsf"="cmd.exe" [2004-08-04 00:45 400384 C:\WINDOWS\system32\cmd.exe]

    "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 00:34 44544]

    C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

    Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

    Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-03-06 16:48:27 331776]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

    "{E37CB5F0-51F5-4395-A808-5FA49E399011}"= C:\ARQUIV~1\GbPlugin\gbiehscd.dll [2007-12-17 17:51 336832]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginScd]

    C:\ARQUIV~1\GbPlugin\gbiehscd.dll 2007-12-17 17:51 336832 C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

    C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\system32\\sessmgr.exe"=

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

    "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

    "C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

    "C:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

    R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []

    R2 SQLWriter;Escritor VSS do SQL Server;"c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]

    S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 11:43]

    .

    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-04-03 09:32:51

    Windows 5.1.2600 Service Pack 2 NTFS

    Procurando processos ocultos ...

    Procurando entradas auto inicializáveis ocultas ...

    Procurando ficheiros ocultos ...

    Varredura completada com sucesso

    Ficheiros ocultos: 0

    **************************************************************************

    .

    Tempo para conclusão: 2008-04-03 9:33:28

    ComboFix-quarantined-files.txt 2008-04-03 12:33:14

    ComboFix2.txt 2008-04-01 11:18:59

    ComboFix3.txt 2008-03-24 19:11:22

    .

    2008-03-18 10:48:12 --- E O F ---

    --------------------------***************************----------------------------------------------------------------------

    Logfile of HijackThis v1.99.1

    Scan saved at 09:39:13, on 3/4/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16608)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\ARQUIV~1\GbPlugin\GbpSv.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE

    c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\wscntfy.exe

    C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe

    C:\WINDOWS\SOUNDMAN.EXE

    C:\WINDOWS\system32\ctfmon.exe

    C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\WINDOWS\system32\sistray.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Arquivos de programas\WinRAR\WinRAR.exe

    C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\Rar$EX00.078\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

    O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar2.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

    O2 - BHO: G-Buster Browser Defense Sicredi - {C41A1C0E-EA6C-11D4-B1B8-444553540011} - C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar2.dll

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"

    O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe

    O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKCU\..\Run: [updateMgr] C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

    O4 - HKCU\..\Run: [EPSON Stylus CX5600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAL.EXE /FU "C:\WINDOWS\TEMP\E_SA3.tmp" /EF "HKCU"

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

    O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O11 - Options group: [iNTERNATIONAL] International*

    O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

    O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399011} (GbPluginObj Class) - https://si-plg.sicredi.com.br/Cab/GbPluginScd.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{3382DA65-5028-49E9-B37E-C1CD7985122F}: NameServer = 10.1.1.1

    O17 - HKLM\System\CS1\Services\Tcpip\..\{3382DA65-5028-49E9-B37E-C1CD7985122F}: NameServer = 10.1.1.1

    O17 - HKLM\System\CS2\Services\Tcpip\..\{3382DA65-5028-49E9-B37E-C1CD7985122F}: NameServer = 10.1.1.1

    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

    O20 - Winlogon Notify: GbPluginScd - C:\ARQUIV~1\GbPlugin\gbiehscd.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    - Ok, o log está limpo :)

    - Digite no Executar combofix /u e clique em Ok. Na próxima janela clique em "Executar" e aguarde a remoção do programa;

    - Recomendo uma manutenção no computador para exclusão dos arquivos temporários, desnecessários e entradas inválidas no registro. Faça o download do CCleaner:

    • Abra o programa e clique em Executar Limpeza;
    • Após isto, clique em Registro > Procurar erros > Corrigir erros selecionados

    - Desative e ative novamente a Restauração do Sistema

    - Leia o artigo Proteja seu PC para mais informações sobre como evitar infecções.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • muito OBRIGADO PELA ATENÇÃO...MINHA MAQUINA MELHOROU muito

    valeu

    \ABRAÇOS:lol:

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
    Entre para seguir isso  





    Sobre o Clube do Hardware

    No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas publicações sobre tecnologia do Brasil. Leia mais

    Direitos autorais

    Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

    ×