Virus? Spyware? o que poderá ser?

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

Virus? Spyware? o que poderá ser?

Mensagempor Darkblood » Terça Mai 22, 2007 23:01

Boas

Não percebo o que se tá a passar o meu pc. Tá a funcionar na boa e de repente algumas aplicações começam a dar erro, os icones da barra de tarefas ficam invisiveis, assim como o iniciar e alguns atalhos que estão lá...eu tenho o active virus shield, tem os updates mais recentes e já fiz um scan mas nao encontrou nada. De anti-spyware tenho O Spybot, spyware terminator e também o da AVG e já fiz o mesmo que fiz para o anti-virus, por acaso já me encontrou alguns spywares, mas pelos vistos não eram a causa do meu problema...

Cumps
Imagem
Darkblood
Membro de Ouro
Membro de Ouro
 
Mensagens: 830
Registado: Quinta Mar 02, 2006 22:35
Localização: Coimbra

Mensagempor lnogueir » Terça Mai 22, 2007 23:50

Olha que não és o único... Isso começou-me a acontecer à cerca de 15 dias. Também uso o active virus shield! Será ele o responsável por isso! é mesmo uma cena esquesita... Parece que as coisas começam a desaparecer!

Cheguei a pensar que fosse das ATI-DNA drivers, mas como já as tinhas e isso só começou depois... ainda não encontrei o responsável!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor GigaManiac » Quarta Mai 23, 2007 1:00

Isso cá pra mim é de teres tantos antivirus instalados ao mesmo tempo. Exprimenta apaga-los todos e instalarar um antivirus com uma boa firewall, anti spyware e certifica-te que desactivas a firewall do windows antes de activar outra.
GigaManiac
Membro de Prata
Membro de Prata
 
Mensagens: 120
Registado: Sexta Mar 23, 2007 5:50
Localização: Lisboa

Mensagempor jotoa » Quarta Mai 23, 2007 6:25

Interessante...antes do format também me acontecia isso e tenho o Active Virus Shield. Mas cho que não era dele, porque quando isso acontecia era quando o Pest Patrol estava a reiniciar a aplicação depois de ter feito update, dava um erro e começavam a desparecer as letras, ficando só a ver-se imagens :? Mas aagora estou na boa.
Imagem
Capitão Moura: Justo! Honesto! Coerente! Imparcial!
O meu computador
jotoa
Membro Dedicado
Membro Dedicado
 
Mensagens: 5535
Registado: Sábado Jun 17, 2006 18:27
Localização: Pontinha, Lisboa

Mensagempor lfernandes » Quarta Mai 23, 2007 8:25

isso não deve ser do antivirus, é o que tenho e até agora nunca tive problemas, isso deve ser conflitos de software ou muita tralha a arrancar com o windows. usa o hijackthis e posta aqui o log.
lfernandes
Membro de Prata
Membro de Prata
 
Mensagens: 384
Registado: Sábado Ago 26, 2006 2:19

Mensagempor lnogueir » Quarta Mai 23, 2007 12:09

Começo a desconfiar mesmo do active virus shield! Parece que quem tem este fenómeno o tem instalado! Ainda o desinstalo e vejo no que resulta!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor lnogueir » Quarta Mai 23, 2007 12:13

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 13:12:40, on 23-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Programas\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\Programas\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Programas\Comodo\Firewall\cmdagent.exe
C:\Programas\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Programas\OO Software\CleverCache\ooccag.exe
C:\Programas\Raxco\PerfectDiskRx\PD9Engine.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Raxco\PerfectDisk\PDAgent.exe
C:\Programas\Spyware Terminator\sp_rsser.exe
C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Raxco\PerfectDisk\PDEngine.exe
C:\Programas\Synaptics\SynTP\SynTPEnh.exe
C:\Programas\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\LGDMEBTN.exe
C:\Program Files\LG Software\On Screen Display\HotKey.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\Programas\Comodo\Firewall\CPF.exe
C:\Programas\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programas\Fingerprint Sensor\ATSwpNav.exe
C:\Programas\LG Software\Battery Miser\batterymiser.exe
C:\Programas\Microsoft IntelliPoint\ipoint.exe
C:\Programas\Raxco\PerfectDiskRx\PerfectDiskRx.exe
C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRSTrayApp.exe
C:\Programas\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\TrueCrypt\TrueCrypt.exe
C:\Programas\DNA-drivers\DNA-ATi\Driver\ATI Tray Tools\atitray.exe
C:\Programas\TaskSwitchXP\TaskSwitchXP.exe
C:\Programas\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Programas\CyberLink\PowerDVD\PDVDServ.exe
C:\Programas\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Programas\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Programas\Raxco\PerfectDiskRx\PDCleaner.exe
C:\Programas\Raxco\PerfectDiskRx\PDState.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Programas\Raxco\PerfectDiskRx\PD9Agent.exe
C:\Programas\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Programas\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\OO Software\CleverCache\ooccctrl.exe
C:\Programas\Softex\OmniPass\scureapp.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\AGRSMMSG.exe
D:\Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.evillabs.sk/evillyrics/faq/faq1.php?faqnr=49
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Programas\FlashGet\jccatch.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programas\MegauploadToolbar\megauploadtoolbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Explorer Breadcrumbs Helper Class - {DB5FC78C-0D12-448B-A0B0-DB0F0E6B67DB} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Programas\FlashGet\getflash.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\Programas\MegauploadToolbar\megauploadtoolbar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Explorer Breadcrumbs - {A3EB65EC-D9B4-4DC1-88AF-0C7A21EBE5F9} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll
O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] C:\Programas\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Programas\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [LG Direct Media Button Service] LGDMEBTN.exe
O4 - HKLM\..\Run: [KeybdUtility] "C:\Program Files\LG Software\On Screen Display\HotKey.exe"
O4 - HKLM\..\Run: [aol] "C:\Programas\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programas\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programas\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\VIPv3\VIPhd\vsdrv.exe
O4 - HKLM\..\Run: [StartupDelayer] "C:\Programas\r2 Studios\Startup Delayer\Startup Launcher.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATSwpNav] "C:\Programas\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [batterymiser] "C:\Programas\LG Software\Battery Miser\batterymiser.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programas\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [PerfectDiskRx] C:\Programas\Raxco\PerfectDiskRx\PerfectDiskRx.exe /tray /startrun
O4 - HKCU\..\Run: [SRSTrayApp] C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRSTrayApp.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Programas\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TrueCrypt] "C:\Programas\TrueCrypt\TrueCrypt.exe" /q preferences
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Programas\DNA-drivers\DNA-ATi\Driver\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Programas\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-21-1004336348-630328440-839522115-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrador')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Programas\IVT Corporation\BlueSoleil\BlueSoleil.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download All with FlashGet - C:\Programas\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Programas\FlashGet\jc_link.htm
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Programas\Portable Offline Browser\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Programas\Portable Offline Browser\Add_AllO.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.1_01\bin\npjpi141_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programas\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programas\FlashGet\FlashGet.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon da cache de categorias dos componentes - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programas\Ficheiros comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Active Virus Shield (AVP) - AOL - C:\Programas\AOL\Active Virus Shield\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Programas\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programas\Comodo\Firewall\cmdagent.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programas\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Programas\Softex\OmniPass\Omniserv.exe
O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Programas\OO Software\CleverCache\ooccag.exe
O23 - Service: PD9Engine - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDiskRx\PD9Engine.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Programas\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programas\Spyware Terminator\sp_rsser.exe
O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Programas\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 11149 bytes
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor lfernandes » Quarta Mai 23, 2007 16:26

C:\WINDOWS\system32\LGDMEBTN.exe

O2 - BHO: Explorer Breadcrumbs Helper Class - {DB5FC78C-0D12-448B-A0B0-DB0F0E6B67DB} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll

O3 - Toolbar: Explorer Breadcrumbs - {A3EB65EC-D9B4-4DC1-88AF-0C7A21EBE5F9} - C:\Programas\Minimalist\Explorer Breadcrumbs\BCToolbar.dll

O4 - HKLM\..\Run: [LG Direct Media Button Service] LGDMEBTN.exe

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


isto é suspeito. usa o hijackthis para corrigir estas linhas
lfernandes
Membro de Prata
Membro de Prata
 
Mensagens: 384
Registado: Sábado Ago 26, 2006 2:19

Mensagempor lnogueir » Quarta Mai 23, 2007 16:52

Nenhum deles é suspeito para mim! Sei exactamente o que são todos eles!

Mas obrigado pelo ajuda!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor Darkblood » Quarta Mai 23, 2007 19:45

GigaManiac Escreveu:Isso cá pra mim é de teres tantos antivirus instalados ao mesmo tempo. Exprimenta apaga-los todos e instalarar um antivirus com uma boa firewall, anti spyware e certifica-te que desactivas a firewall do windows antes de activar outra.


Eu só tenho o active virus shield como anti-virus, não tenho outro. Tenho é 2 anti-spywares com protecção em tempo-real, acho que não há nenhum problema nisso.

Logfile of HijackThis v1.99.1
Scan saved at 20:40:08, on 23-05-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\Programas\Comodo\Firewall\cmdagent.exe
C:\Programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\SPYWAR~2\sp_rsser.exe
C:\Programas\Unlocker\UnlockerAssistant.exe
C:\Programas\Java\jre1.5.0_10\bin\jusched.exe
C:\Programas\HP\hpcoretech\hpcmpmgr.exe
C:\Programas\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\svchost.exe
C:\Programas\RAM Idle LE\RAM_XP.exe
C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Programas\Folder Lockbox\flockbox.exe
C:\Programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Programas\PC Connectivity Solution\ServiceLayer.exe
C:\Programas\Ficheiros comuns\PCSuite\DataLayer\DataLayer.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\PROGRA~1\SPYWAR~2\SpywareTerminatorShield.exe
C:\Programas\Comodo\Firewall\CPF.exe
C:\Programas\AOL\Active Virus Shield\avp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programas\ATI Technologies\ATI.ACE\cli.exe
C:\Programas\ATI Technologies\ATI.ACE\cli.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programas\ABIT\ABITEQ\ABITEQ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\FICHEI~1\Nokia\MPAPI\MPAPI3s.exe
C:\Programas\MSN Messenger\msnmsgr.exe
C:\Programas\PeerGuardian2\pg2.exe
C:\Programas\Conceptronic\Bluetooth Software\BTTray.exe
C:\Programas\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\CONCEP~1\BLUETO~1\BTSTAC~1.EXE
C:\Programas\Xecutor\Xecutor.exe
C:\Programas\MSN Messenger\usnsvc.exe
C:\Programas\Azureus\Azureus.exe
C:\Programas\Mozilla Firefox\firefox.exe
C:\Programas\foobar2000\foobar2000.exe
C:\Documents and Settings\Administrador\Ambiente de trabalho\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Programas\Crawler\Toolbar\ctbr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Programas\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Programas\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Programas\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Programas\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Programas\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [flockbox] C:\Programas\Folder Lockbox\flockbox.exe /a
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Programas\Ficheiros comuns\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~2\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programas\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [aol] "C:\Programas\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ABIT uGuruIII] C:\Programas\ABIT\ABITEQ\ABITEQ.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PcSync] C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PeerGuardian] C:\Programas\PeerGuardian2\pg2.exe
O4 - Startup: Xecutor.lnk = C:\Programas\Xecutor\Xecutor.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programas\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Programas\Crawler\Toolbar\ctbr.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Programas\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: BOCore - Unknown owner - C:\Programas\Comodo\CBOClean\BOCORE.exe (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Programas\Comodo\Firewall\cmdagent.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Programas\WinClamAVShield\sp_clamsrv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\PROGRA~1\SPYWAR~2\sp_rsser.exe
Imagem
Darkblood
Membro de Ouro
Membro de Ouro
 
Mensagens: 830
Registado: Quinta Mar 02, 2006 22:35
Localização: Coimbra

Mensagempor lnogueir » Quarta Mai 23, 2007 20:01

Há aí qualquer coisa estranha... tens uma placa ATI. Mas eu vejo aí algumas entradas NVIDIA! Já começa a haver coisas em comum: ambos temos avs e drivers ati!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor GigaManiac » Quinta Mai 24, 2007 6:08

Vai ao menu iniciar depois a executar e escreves msconfig, clika ok. Depois vais ao arranque e diz-nos o que é que tens lá. Se tiver em inglês é start»run»msconfig»startup.

Cumps :wink:
GigaManiac
Membro de Prata
Membro de Prata
 
Mensagens: 120
Registado: Sexta Mar 23, 2007 5:50
Localização: Lisboa

Mensagempor lnogueir » Quinta Jun 21, 2007 0:38

Estes ataques esquesitos continuam! Se deixo o pc sozinho por umas horas... quando volto funciono com ele uns minutos e o no ecrã começa tudo a ficar marado!

Tou a ver que mais tarde ou mesmo cedo vou ter que formatar isto!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29

Mensagempor lnogueir » Segunda Jun 25, 2007 16:41

Pessoal será que mais ningúem tem este problema???

Preciso de ajuda!

Há mais gente com este problema mas não consigo encontrar de onde vem!

http://forum.notebookreview.com/showthread.php?t=104409

Agradece-se ajuda!
lnogueir
Membro de Prata
Membro de Prata
 
Mensagens: 254
Registado: Quinta Nov 16, 2006 13:29


Voltar para Segurança Informática

Quem está ligado:

Utilizador a ver este Fórum: Nenhum utilizador registado e 1 visitante

cron