Virus no PC

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

Virus no PC

Mensagempor Tom » Segunda Nov 23, 2009 18:03

Olá! boa tarde a todos/as.Eu sou novo aqui no forum e necessitava de uma ajuda ajuda com um problema que tenho no meu pc, que acho que é virus.
Eu fiz não coseguia sequer fazer um restauro do sistema porque aparecia-me a dizer que o restauro estava activado pela politica de grupos e nem sequer um ponto de restauro podia fazer, depois começou-me aparecer a linha de comandos que dizia em cima"taskeng.exe" isto acontecia sempre que abria uma pagina de um site.
Então decidi escanear o pc com o combofix, o pc melhorou mas acho que não o suficiente, acho que ainda têm algum virus.
Mas como não sei ler os logs, gostaria que alguem me ajudasse a ver se tenho mais algum virus no pc e como poderei removê-lo.
Deixo aqui o relatório do combofix.
Obrigado!


Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.351.2070.18.1022.151 [GMT 0:00]
Executando de: c:\users\Gil\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-190165824-915554596-616950441-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2250718083-3983787178-620054659-1002
c:\users\Gil\AppData\Roaming\inst.exe

.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-10-22 to 2009-11-22 ))))))))))))))))))))))))))))
.

2009-11-22 23:19 . 2009-11-22 23:19 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2009-11-22 22:34 . 2009-11-22 22:34 -------- d-----w- c:\users\Gil\AppData\Roaming\Uniblue
2009-11-22 22:34 . 2009-11-22 22:34 -------- d-----w- c:\program files\Uniblue
2009-11-22 21:26 . 2009-11-22 21:26 -------- d-----w- c:\users\Gil\AppData\Local\G DATA
2009-11-21 19:24 . 2009-11-22 21:28 29128 ----a-w- c:\windows\system32\drivers\GRD.sys
2009-11-21 19:17 . 2009-11-21 19:17 50888 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2009-11-21 19:16 . 2009-11-21 19:16 51656 ----a-w- c:\windows\system32\drivers\PktIcpt.sys
2009-11-21 19:16 . 2009-11-21 19:16 32200 ----a-w- c:\windows\system32\drivers\HookCentre.sys
2009-11-21 19:15 . 2009-11-21 19:15 39880 ----a-w- c:\windows\system32\drivers\gdwfpcd32.sys
2009-11-21 19:11 . 2009-11-21 19:24 4096 d-----w- c:\programdata\G DATA
2009-11-21 19:11 . 2009-11-21 19:15 4096 d-----w- c:\program files\Common Files\G DATA
2009-11-21 19:11 . 2009-11-21 19:11 -------- d-----w- c:\program files\G DATA
2009-11-21 16:51 . 2009-11-21 16:51 -------- d-----w- c:\programdata\IObit
2009-11-21 16:07 . 2009-11-21 16:07 4096 d-----w- C:\LinhaDefensiva
2009-11-21 14:20 . 2009-11-21 14:20 -------- d-----w- c:\programdata\Simply Super Software
2009-11-20 22:12 . 2009-11-21 00:12 -------- d-----w- c:\users\Gil\AppData\Roaming\QuickScan
2009-11-20 22:12 . 2009-10-29 15:39 679936 ----a-w- c:\users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\d0umh1j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-11-20 22:12 . 2009-10-29 15:39 614400 ----a-w- c:\users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\d0umh1j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2009-11-20 19:53 . 2009-11-20 19:53 -------- d-----w- c:\users\Gil\AppData\Local\MigWiz
2009-11-19 10:09 . 2009-11-19 10:09 -------- d-----w- c:\program files\CCleaner
2009-11-19 09:52 . 2009-11-16 11:25 17224 ----a-w- c:\windows\system32\authuitu.dll
2009-11-19 09:52 . 2009-11-16 11:25 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-11-19 09:52 . 2009-11-19 09:52 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-11-19 09:31 . 2009-11-19 09:52 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-11-19 09:31 . 2009-11-19 09:31 -------- d-----w- c:\users\Gil\AppData\Roaming\TuneUp Software
2009-11-19 09:25 . 2009-11-19 09:56 49152 d-----w- c:\program files\TuneUp Utilities 2009
2009-11-19 09:25 . 2009-11-19 09:25 -------- d-----w- c:\programdata\TuneUp Software
2009-11-19 09:23 . 2009-11-19 09:23 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-11-18 21:57 . 2009-11-18 21:57 4096 d-----w- c:\windows\system32\Samsung
2009-11-18 21:55 . 2009-11-18 21:56 4096 d-----w- c:\windows\system32\Samsung PC Studio Codecs
2009-11-18 21:55 . 2009-11-18 21:55 -------- d-----w- c:\program files\Samsung
2009-11-18 20:48 . 2009-11-21 17:51 71096 ----a-w- c:\users\Gil\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-18 20:15 . 2009-11-18 20:15 -------- d-----w- c:\program files\Marcos Velasco Security
2009-11-17 00:40 . 2009-11-18 21:08 -------- d-----w- c:\users\Gil\AppData\Local\eSupport.com
2009-11-16 12:54 . 2009-11-16 13:10 4096 d-----w- c:\users\Gil\AppData\Roaming\Nero
2009-11-16 12:53 . 2009-11-16 12:53 -------- d-----w- c:\programdata\LightScribe
2009-11-16 12:05 . 2009-11-16 12:21 4096 d-----w- c:\program files\Common Files\Nero
2009-11-15 22:54 . 2009-11-15 22:54 -------- d-----w- c:\users\Gil\AppData\Roaming\Canneverbe_Limited
2009-11-15 22:54 . 2009-11-15 23:59 16384 d-----w- c:\program files\CDBurnerXP
2009-11-15 22:47 . 2009-11-15 22:47 -------- d-----w- c:\programdata\vsosdk
2009-11-11 12:45 . 2009-11-11 12:45 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-11 12:42 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-11-11 12:42 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-11-11 12:42 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-11 12:40 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-11-11 12:36 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-11-11 12:36 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-11 12:36 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-11-11 12:07 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 12:07 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-10 10:41 . 2009-11-10 10:41 -------- d-----w- C:\found.001
2009-11-05 19:07 . 2009-11-05 19:50 -------- d-----w- c:\users\Gil\AppData\Roaming\Trellian
2009-11-05 19:07 . 2009-11-05 19:37 -------- d-----w- c:\users\Gil\AppData\Local\WebPage
2009-11-05 19:06 . 2007-09-07 23:43 512000 ----a-w- c:\windows\system32\Achroma2.dll
2009-11-05 19:06 . 2009-11-16 00:02 -------- d-----w- c:\program files\Trellian
2009-10-30 13:19 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-30 13:19 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-30 13:19 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-30 13:19 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-30 13:18 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-30 13:18 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-30 13:18 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-30 13:17 . 2009-08-06 19:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-30 13:17 . 2009-08-06 18:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-28 09:36 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 09:36 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL

.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-22 22:59 . 2009-11-18 22:30 99415 ----a-w- c:\programdata\nvModes.dat
2009-11-21 23:28 . 2009-04-16 15:11 -------- d-----w- c:\users\Gil\AppData\Roaming\Vso
2009-11-21 22:12 . 2009-05-09 09:29 40960 d-----w- c:\program files\Spyware Doctor
2009-11-21 18:17 . 2007-02-09 03:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-19 10:28 . 2007-02-09 10:49 650438 ----a-w- c:\windows\system32\prfh0816.dat
2009-11-19 10:28 . 2007-02-09 10:49 127778 ----a-w- c:\windows\system32\prfc0816.dat
2009-11-16 22:09 . 2009-08-31 13:05 -------- d-----w- c:\users\Gil\AppData\Roaming\HpUpdate
2009-11-16 18:52 . 2009-05-29 16:07 281625 ------r- c:\programdata\Norton\Norton2009Reset.exe
2009-11-16 18:52 . 2009-05-12 20:58 -------- d-----w- c:\programdata\Norton
2009-11-16 12:20 . 2009-04-16 16:51 -------- d-----w- c:\program files\Nero
2009-11-16 12:11 . 2009-04-16 16:51 4096 d-----w- c:\programdata\Nero
2009-11-16 12:02 . 2007-02-09 03:09 12288 d---a-w- c:\program files\Common Files\LightScribe
2009-11-16 11:22 . 2009-04-16 14:49 12288 d-----w- c:\program files\BT Next Evolution
2009-11-16 00:05 . 2009-09-08 11:53 -------- d-----w- c:\users\Gil\AppData\Roaming\SUPERAntiSpyware.com
2009-11-15 23:18 . 2009-11-15 23:17 4096 d-----w- c:\program files\K-Lite Codec Pack
2009-11-12 08:43 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-11-11 12:45 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-11 12:44 . 2009-11-11 12:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-11 12:44 . 2009-11-11 12:44 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-11 12:31 . 2009-04-16 12:47 -------- d-----w- c:\programdata\NVIDIA
2009-11-11 12:24 . 2009-05-07 20:05 -------- d-----w- c:\programdata\Microsoft Help
2009-11-09 23:56 . 2007-02-09 03:11 28672 d-----w- c:\program files\Microsoft Works
2009-11-09 18:00 . 2009-11-15 23:17 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-11-09 17:51 . 2009-05-07 12:40 -------- d-----w- c:\program files\Java
2009-11-05 20:02 . 2009-05-07 11:32 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-02 20:42 . 2009-10-14 10:17 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 00:23 . 2009-04-25 20:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-01 00:23 . 2009-04-25 20:02 4045527 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-22 18:39 . 2009-10-22 18:39 14 ----a-w- c:\windows\system32\SysEngine2.SYS
2009-10-22 15:38 . 2009-10-22 15:38 -------- d-----w- c:\programdata\SlySoft
2009-10-20 21:55 . 2009-10-20 19:32 -------- d-----w- c:\users\Gil\AppData\Roaming\TalesRunner
2009-10-20 21:43 . 2009-10-20 21:43 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-10-20 19:28 . 2009-10-20 19:28 -------- d-----w- c:\program files\gpotato
2009-10-19 17:11 . 2009-04-16 14:33 4096 d-----w- c:\program files\Windows Live
2009-10-19 17:10 . 2009-10-19 17:10 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-19 17:08 . 2009-10-19 17:08 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-19 17:06 . 2009-04-16 14:34 -------- d-----w- c:\program files\Microsoft
2009-10-12 19:44 . 2009-04-16 08:35 -------- d-----w- c:\users\Gil\AppData\Roaming\Hewlett-Packard
2009-10-12 19:44 . 2007-02-09 03:28 -------- d-----w- c:\programdata\Hewlett-Packard
2009-10-12 19:44 . 2007-02-09 03:03 4096 d-----w- c:\program files\Hewlett-Packard
2009-10-11 04:17 . 2009-05-07 12:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-04 21:14 . 2009-10-04 21:14 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-10-04 21:14 . 2009-05-09 09:29 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-01 01:02 . 2009-11-11 12:40 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-11 12:40 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-11 12:40 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-11 12:40 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-11 12:40 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-11 12:40 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-11 12:40 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-11 12:40 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-11-11 12:40 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-11 12:40 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-11 12:40 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-11-11 12:40 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-11-11 12:40 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-11-11 12:40 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-11-11 12:40 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-25 02:10 . 2009-11-11 12:41 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-11 12:41 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-11 12:41 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-11 12:41 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-11 12:41 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-11 12:41 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-11 12:41 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-11 12:41 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-11 12:41 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-11 12:41 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-11 12:41 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-11 12:41 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-11 12:41 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-11 12:41 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-11 12:41 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-11 12:41 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-11 12:41 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-11 12:41 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-11 12:41 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-11 12:41 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-11 12:41 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-11 12:41 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-11 12:41 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-11 12:41 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-11 12:41 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-11 12:41 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-11 12:41 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-17 13:51 . 2009-09-17 13:51 2373416 ----a-w- c:\programdata\Nero\Nero 9\DrWeb\DrWeb32.dll
2009-09-17 12:58 . 2009-09-17 12:58 2373416 ----a-w- c:\programdata\Nero\Nero\DrWeb\DrWeb32.dll
2009-09-14 09:29 . 2009-10-15 21:19 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-15 21:20 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 14:54 . 2009-04-25 20:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 . 2009-04-25 20:01 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 11:41 . 2009-10-15 21:21 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 00:27 . 2009-09-02 21:34 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 21:34 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:22 . 2009-10-15 21:19 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-15 21:19 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 05:17 . 2009-10-15 21:19 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 03:42 . 2009-10-15 21:19 133632 ----a-w- c:\windows\system32\ieUnatt.exe
.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-09-04 95536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2006-11-20 155648]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-26 13789728]
"VMonitorVMUVC"="c:\program files\Vimicro\Vimicro UVC USB2.0 PC Camera\x86\VMonitor.exe" [2007-04-13 114688]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-26 92704]
"GDFirewallTray"="c:\program files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe" [2008-09-22 1037992]
"G DATA AntiVirus Trayapplication"="c:\program files\G DATA\InternetSecurity\AVKTray\AVKTray.exe" [2008-09-22 993352]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-24 44136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):42,95,d1,84,97,05,ca,01

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [09-05-2009 09:29 206256]
R1 gdwfpcd;G DATA WFP CD;c:\windows\System32\drivers\gdwfpcd32.sys [21-11-2009 19:15 39880]
R1 GRD;G DATA Rootkit Detector Driver;c:\windows\System32\drivers\GRD.sys [21-11-2009 19:24 29128]
R2 AVKProxy;G DATA AntiVirus Proxy;c:\program files\Common Files\G DATA\AVKProxy\AVKProxy.exe [22-09-2008 11:09 650824]
R2 AVKService;G DATA Scheduler;c:\program files\G DATA\InternetSecurity\AVK\AVKService.exe [22-09-2008 11:09 386120]
R2 AVKWCtl;Protector anti-vírus AntiVirus;c:\program files\G DATA\InternetSecurity\AVK\AVKWCtl.exe [14-08-2008 08:55 1185496]
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [03-09-2006 10:32 208896]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [19-11-2009 09:31 604488]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30-03-2009 15:28 1533808]
R3 GDFwSvc;G DATA Personal Firewall;c:\program files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe [15-08-2008 14:51 1395616]
R3 GDMnIcpt;GDMnIcpt;c:\windows\System32\drivers\MiniIcpt.sys [21-11-2009 19:17 50888]
R3 GDPkIcpt;GDPkIcpt;c:\windows\System32\drivers\PktIcpt.sys [21-11-2009 19:16 51656]
R3 HookCentre;HookCentre;c:\windows\System32\drivers\HookCentre.sys [21-11-2009 19:16 32200]
R3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\System32\drivers\Ph3xIB32.sys [06-11-2006 10:14 1119616]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [10-05-2009 08:38 721904]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [10-05-2006 09:13 29696]
S3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\System32\drivers\3xHybrid.sys [09-02-2007 10:51 2807936]
S3 FontCache;Serviço de Cache de Tipos de Letra do Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20-04-2009 16:22 21504]
S3 npggsvc;nProtect GameGuard Service; [x]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [09-05-2009 09:29 348752]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\System32\drivers\VMUVC.sys [17-04-2009 10:58 248192]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\System32\drivers\vvftUVC.sys [17-04-2009 10:59 476032]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Conteúdo da pasta 'Tarefas Agendadas'

2009-11-22 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 15:54]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.pt/webhp?sourceid=nav ... R&ie=UTF-8
IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\d0umh1j1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.sapo.pt/
FF - component: c:\users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\d0umh1j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\d0umh1j1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORFÃOS REMOVIDOS - - - -

HKCU-RunOnce-UniblueRegistryBooster - launcher.exe



**************************************************************************
Procurando processos ocultos ...

Procurando entradas auto inicializáveis ocultas ...

Procurando ficheiros/arquivos ocultos ...

Varredura completada com sucesso
arquivos/ficheiros ocultos:

**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Tempo para conclusão: 2009-11-22 23:26
ComboFix-quarantined-files.txt 2009-11-22 23:26

Pré-execução: 70.803.697.664 bytes livres
Pós execução: 109.190.512.640 bytes livres
Tom
Novato
Novato
 
Mensagens: 3
Registado: Segunda Nov 23, 2009 17:45

Mensagempor alr_tech » Terça Nov 24, 2009 15:40

boas

desculpa...
mas, não há tempo para isso...

ok.. instala e corre Malwarebytes e spybot... superantyspyware
não esquecer os updates...

desliga da net...

desligar, o recovery...
usar o ccleaner....

repetir em safe mode....

fazer um scandisk e um defrag....

entrar em modo normal...
repetir os testes....

se não aparecer mais nada... então ligar a net ir ao karpesky e fazer um scan...

veriifca se não tens + de uma firewall activa....
isso provoca pequenos brakes... mantém apenas os serviços de uma suite de segurança activos...
utiliza os outros apenas para pesquizas...

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa

Mensagempor Tom » Quinta Nov 26, 2009 18:45

alr_tech Escreveu:boas

desculpa...
mas, não há tempo para isso...

ok.. instala e corre Malwarebytes e spybot... superantyspyware
não esquecer os updates...

desliga da net...

desligar, o recovery...
usar o ccleaner....

repetir em safe mode....

fazer um scandisk e um defrag....

entrar em modo normal...
repetir os testes....

se não aparecer mais nada... então ligar a net ir ao karpesky e fazer um scan...

veriifca se não tens + de uma firewall activa....
isso provoca pequenos brakes... mantém apenas os serviços de uma suite de segurança activos...
utiliza os outros apenas para pesquizas...

cumps



Olá!Obrigado pela ajuda.
Eu fiz o que tu dissestes, mas não encontrava qualquer virus, então decidi baixar o panda e ele acusou-me estes dois virus.
[b]Trojan detectado <A href="malwareinfo">Generic Malware</A> Localização: C:\Program Files\Trellian\Toolbar\toolbar.dll Trojan detectado <A href="malwareinfo">Generic Malware</A> Localização: C:\Program Files\Trellian\Toolbar\toolbar.dl[/b]l, só que o antivirus não está a conseguir remove-los, como posso remove-los manualmente?
Obrigado.
Tom
Novato
Novato
 
Mensagens: 3
Registado: Segunda Nov 23, 2009 17:45

Mensagempor alr_tech » Sexta Nov 27, 2009 9:17

boas

o trellian... não é propriamente um problema...
é um programa para ajudar a desenvolver pag de web...

pode ser é que esteja alguma DLL embichada...

tenta desinstalar a toolbar... ou o programa em si...

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa

Mensagempor Tom » Sexta Nov 27, 2009 21:18

alr_tech Escreveu:boas

o trellian... não é propriamente um problema...
é um programa para ajudar a desenvolver pag de web...

pode ser é que esteja alguma DLL embichada...

tenta desinstalar a toolbar... ou o programa em si...

cumps



Boas!
Eu desinstalei o toolbar e ja fiz um scan com praticamente todos os antivirus e não tenho encontrado mais nada, mas o que me deixa um pouco desconfiado que talvez haja mais algum virus que não esteja a conseguir detectar é que normalmente quando abro uma pagina ou tento instalar algum programa, abre-me uma janela que parece da linha de comandos e diz "taskeng.exe".Porque será que esta janela abre do nada?
Obrigado pela atenção.
Tom
Novato
Novato
 
Mensagens: 3
Registado: Segunda Nov 23, 2009 17:45

Mensagempor alr_tech » Sexta Nov 27, 2009 21:58

boas

há dezenas de posts pela net fora sobre problemas com o "taskeng.exe"...

o que se passa é que houve má reparação do reg. quando o virus foi desactivado....
infelizmente , devido às muitas variantes, nem sempre o processo de desinfecção é inócuo...

tenta o truque de criar um novo user com privilégios de admin e tenta entrar por ele... vê se o problema ainda surge...

cumps
AMD XP 2400+, ASUS A7N8X-E Deluxe
1 Gb DDR 400, Seagate 80 GB ATA + 120 Gb ATA, ATI 9600 XT
alr_tech
Gurus
Gurus
 
Mensagens: 6768
Registado: Quinta Fev 17, 2005 18:01
Localização: Lisboa


Voltar para Segurança Informática

Quem está ligado:

Utilizadores a ver este Fórum: Nenhum utilizador registado e 0 visitantes

cron