Ajuda - Pesquisa - Usuários - Calendário
Versão Completa Sites lentos, downloads normais

Fórum Linha Defensiva > Remoção de Malware > Casos Resolvidos
Hakghen
Boa Noite,

A 1 semana mais ou menos, estou tendo esse problema. Os sites demoram muito para abrir (e as vezes nem abrem), porém os downloads ou qualquer outro aplicativo com acesso a internet funcionam com a velocidade normal. Possuo velox de 1mb, apenas para informar.

Não sei se se trata de um erro de malware, porém, acredito que sim, pois estou recebendo vários e-mail de notificação de e-mail inválido, acho que alguma coisa está enviando aqueles spams com virus para toda a minha lista...

Segue abaixo log do HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 19:24:19, on 20/4/2010
Platform: Windows XP SP3 (WinNT

5.01.2600)
MSIE: Internet Explorer v8.00 SP3

(8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Cisco VPN Client\cvpnd.exe
C:\Arquivos de programas\ESET\ESET Smart Security\ekrn.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\ESET\ESET Smart Security\egui.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Office Mouse Driver\MouseDrv.exe
C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Documents and Settings\André\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHe
lperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-4DAF1D92D43
} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Arquivos de programas\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehUni.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Arquivos de programas\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WireLessMouse] C:\Arquivos de programas\Office Mouse Driver\StartAutorun.exe MouseDrv.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFa
vClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploa
der55.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Cisco VPN Client\cvpnd.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET Smart Security\ekrn.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de
programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - D:\OpenVPN\bin\openvpnserv.exe
O23 - Service: ServiceLayer - Nokia - C:\Arquivos de programas\PC Connectivity
Solution\ServiceLayer.exe


[]'s,
André Luiz
JoseMelo
- Faça o download do Malwarebytes Anti-Malware
http://www.besttechie.net/tools/mbam-setup.exe
  • Faça a instalação dando um duplo clique em "mbam-setup.exe";
  • Marque "Atualizar Malwarebytes Anti-Malware" e "Executar Malwarebytes Anti-Malware", e clique em concluir;
  • Marque "Verificação Completa" e depois clique em Verificar;
  • Quando o scan terminar, clique em Ok e em "Mostrar Resultados" para ver o log;
  • Se algo for detectado, veja se tudo está marcado e clique em "Remover";
  • O log é automaticamente gravado e pode ser consultado clicando em "Logs" do menu principal;
  • Copie e cole o conteúdo desse log na sua próxima resposta.
- Gere novo log do HijackThis e cole na sua resposta.
Hakghen
Log do MBAM:

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Versão da Base de Dados: 4020

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

22/4/2010 10:23:53
mbam-log-2010-04-22 (10-23-53).txt

Tipo de Verificação: Verificação Completa (C:\|D:\|F:\|)
Objetos escaneados: 490133
Tempo decorrido: 2 hora(s), 56 minuto(s), 45 segundo(s)

Processos de Memória Infectados: 0
Módulos de Memória Infectados: 0
Chaves de Registro Infectadas: 0
Valores de Registro Infectados: 0
Itens de Dados no Registro Infectados: 0
Pastas Infectadas: 0
Arquivos Infectados: 6

Processos de Memória Infectados:
(Não foram detectados ítens maliciosos)

Módulos de Memória Infectados:
(Não foram detectados ítens maliciosos)

Chaves de Registro Infectadas:
(Não foram detectados ítens maliciosos)

Valores de Registro Infectados:
(Não foram detectados ítens maliciosos)

Itens de Dados no Registro Infectados:
(Não foram detectados ítens maliciosos)

Pastas Infectadas:
(Não foram detectados ítens maliciosos)

Arquivos Infectados:
C:\Qoobox\Quarantine\C\WINDOWS\system32\28463\LKAY.007.vir (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\28463\LMQN.007.vir (PUP.ArdamaxKeyLogger) -> Quarantined and deleted successfully.
D:\Downloads\webview.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
D:\Arquivos de programas\Winamp\Plugins\gen_msn.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\Brutus\BrutusA2.exe (HackTool.Brutus) -> Quarantined and deleted successfully.
D:\Cheat Engine\Systemcallretriever.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

Log do HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 10:24:53, on 22/4/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 SP3 (8.00.6001.18702)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Cisco VPN Client\cvpnd.exe
C:\Arquivos de programas\ESET\ESET Smart Security\ekrn.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\ESET\ESET Smart Security\egui.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\Arquivos de programas\Office Mouse Driver\MouseDrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Documents and Settings\André\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Arquivos de programas\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehUni.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Arquivos de programas\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WireLessMouse] C:\Arquivos de programas\Office Mouse Driver\StartAutorun.exe MouseDrv.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0...oUploader55.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - D:\Cisco VPN Client\cvpnd.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET Smart Security\ekrn.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - D:\OpenVPN\bin\openvpnserv.exe
O23 - Service: ServiceLayer - Nokia - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe
JoseMelo
Baixe o Kaspersky AVP Tool:
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/

Salve-o em sua área de trabalho.

Execute o arquivo e vá seguindo os prompts. Quando terminar, entre na pasta Virus Removal Tool, que foi criada no mesmo diretório onde você salvou o arquivo de instalação.

Para abrir o programa, faça duplo clique sobre o atalho
Imagem postada pelo usuário


Marque a caixa ao lado de:
  • Meu Computador
  • Disco local (C:)

Marque também todas as unidades que aparecem abaixo de Disco Local, caso houver.

Clique no botão
Imagem postada pelo usuário


Tenha paciência, é um pouco demorado.

Quando terminar, caso tenha detectado algo, o programa irá lhe perguntar o que fazer.
Clique em Skip (queremos apenas o log).

Obs: Talvez seja necessário clicar em Skip várias vezes, caso o programa encontre vários arquivos, portanto seja paciente.

Enquanto durar o exame, o botão Scan será substituído por um quadrado vermelho, com a mensagem Stop Scan

Quando o exame terminar, o botão Scan aparecerá novamente.

Caso a ferramenta tenha encontrado algo, este botão
Imagem postada pelo usuário
ficará vermelho
Imagem postada pelo usuário


Quando terminar, clique no botão Report, no rodapé da janela.

Clique no sinal + ao lado do último Autoscan da lista (o mais recente)

Imagem postada pelo usuário


Clique uma vez sobre Task Started para selecionar a linha, segure a tecla shift pressionada e depois clique uma vez sobre Task Completed

Clique com o direito sobre a seleção, depois clique em Copy

Vá em Iniciar > Executar e digite notepad

Quando o bloco de notas abrir, clique com o botão direito do mouse em qualquer lugar vazio e escolha a opção colar
Salve o log com o nome log.txt, em algum local de fácil acesso.

Copie todo o conteúdo deste log e cole na sua próxima resposta.
Hakghen
Segue log do kaspersky:

23/4/2010 01:06:24 Task started
23/4/2010 01:31:35 Detected: Worm.Win32.AutoIt.tc C:\Documents and Settings\All Users\Documentos\itltll.exe/script.au3
23/4/2010 01:42:39 Detected: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\34\97b94e2-3aa103a2/Inicio.class
23/4/2010 01:42:40 Detected: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\4\3ea51c04-278bb802/Inicio.class
23/4/2010 09:58:26 Untreated: Worm.Win32.AutoIt.tc C:\Documents and Settings\All Users\Documentos\itltll.exe/script.au3 Write not supported
23/4/2010 09:58:27 Detected: Packed.Win32.Krap.l C:\Documents and Settings\All Users\Documentos\itltll.exe/09966AAAE58B7515.au3.tbl.decoded
23/4/2010 09:58:28 Untreated: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\34\97b94e2-3aa103a2/Inicio.class Skipped by user
23/4/2010 09:58:28 Untreated: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\4\3ea51c04-278bb802/Inicio.class Skipped by user
23/4/2010 09:58:35 Detected: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\61\2d99f97d-26feb139/Inicio.class
23/4/2010 09:58:43 Untreated: Trojan-Downloader.Java.Agent.au C:\Documents and Settings\André\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\61\2d99f97d-26feb139/Inicio.class Skipped by user
23/4/2010 10:03:11 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:11 Untreated: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe Write not supported
23/4/2010 10:03:12 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:13 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:14 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:16 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:17 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:18 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:20 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:21 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:22 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:23 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:25 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:26 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:27 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:28 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:29 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:03:29 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools_Trainer_GBS_Public_v5.0.0___GamerzAimPro.rar/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro/GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:31:46 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:31:56 Untreated: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe Skipped by user
23/4/2010 10:32:02 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:10 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:15 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:16 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:18 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:20 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:21 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:23 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:25 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:29 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:33 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:37 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:39 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:41 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:42 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 10:32:45 Detected: HEUR:Trojan.Win32.Generic C:\Documents and Settings\André\Meus documentos\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro\GamerzTools Trainer GBS Public v5.0.0 + GamerzAimPro.exe
23/4/2010 11:07:34 Detected: Trojan-Downloader.Win32.Banload.aqig C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/msnr.exe
23/4/2010 11:07:34 Untreated: Trojan-Downloader.Win32.Banload.aqig C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/msnr.exe Skipped by user
23/4/2010 11:07:35 Detected: Trojan-Spy.Win32.Ardamax.ce C:\Qoobox\Quarantine\C\WINDOWS\system32\28463\LKAY.exe.vir
23/4/2010 11:07:35 Detected: Trojan.Win32.Scar.bigm C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/smcss.exe
23/4/2010 11:07:38 Untreated: Trojan.Win32.Scar.bigm C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/smcss.exe Skipped by user
23/4/2010 11:07:38 Untreated: Trojan-Spy.Win32.Ardamax.ce C:\Qoobox\Quarantine\C\WINDOWS\system32\28463\LKAY.exe.vir Skipped by user
23/4/2010 11:07:38 Detected: Trojan.Win32.Scar.bigm C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/winlp.exe
23/4/2010 11:07:39 Untreated: Trojan.Win32.Scar.bigm C:\Qoobox\Quarantine\[4]-Submit_2010-02-07_22.12.15.zip/winlp.exe Skipped by user
JoseMelo
- Clique na aba Detected Threats e em "Delete all";

- No mais, o log está limpo smile.gif

- Recomendo uma manutenção no computador para exclusão dos arquivos temporários, desnecessários e entradas inválidas no registro. Faça o download do CCleaner:
  • Clique em Salvar e quando terminado o download, faça a instalação;
  • Abra o programa e clique em Executar Limpeza;
  • Após isto, clique em Registro > Procurar erros > Corrigir erros selecionados
- Desative e ative novamente a Restauração do Sistema

- Leitura recomendada:
http://www.linhadefensiva.org/forum/index....showtopic=75646

- Leia o artigo Proteja seu PC para maiores informações sobre como evitar infecções;

- Se não tiver mais problema, clique no botão
Imagem postada pelo usuário
e diga que o seu caso foi resolvido.
LUA
Problema Resolvido!

Caso o autor necessite que o tópico seja reaberto, entre em contato com um dos membros da equipe de moderação.
Esta é uma versão "lo-fi" do conteúdo. Para acessar a versão completa com mais informações, formatação e imagens, por favor clique aqui .
©2005-2008 Linha Defensiva. Todos os Direitos Reservados.
Invision Power Board © 2001-2010 Invision Power Services, Inc.
Adaptado por Shaun Harrison
Traduzido e modificado por Fantome e David, Lafter