Olá
Efetuei os procedimentos,mas o programa parou quandoem um determinado momento,quase 50 min. se não me engano estava em pastas e o final era TEMP.
pertei a tecla n e reiniciou normalmente.
Aqui esta o relatorio:
ComboFix 12-07-16.01 - Alessandra 16/07/2012 11:46:52.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.55.1046.18.991.572 [GMT -3:00]
Executando de: c:\documents and settings\Alessandra\Desktop\ComboFix.exe
AV: avast! antivírus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Norton antivírus *Enabled/Updated* {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Internet Security *Enabled* {825036E0-9F94-4752-8789-8B92454AF49B}
FW: PC Tools Firewall Plus *Disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
.
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Dados de aplicativos\TEMP
c:\documents and settings\All Users\Dados de aplicativos\TEMP\C31F31E6.TMP
c:\documents and settings\All Users\Dados de aplicativos\TEMP\DFC5A2B2.TMP
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SET33.tmp
c:\windows\system32\wpcap.dll
P:\Autorun.inf
P:\Setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2012-06-16 to 2012-07-16 ))))))))))))))))))))))))))))
.
.
2012-07-16 15:39 . 2012-07-16 15:39 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\TEMP
2012-07-16 13:42 . 2012-07-16 13:42 -------- d-----w- C:\backups
2012-07-16 02:27 . 2012-07-16 02:27 388608 ----a-w- C:\HijackThis.exe
2012-07-13 10:48 . 2012-05-31 03:41 6762896 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\{8E539BB5-B42C-4C3F-A019-D5576D25C3A9}\mpengine.dll
2012-07-12 12:52 . 2012-07-12 12:52 9226440 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-06-29 01:33 . 2012-06-29 01:33 -------- d-----w- C:\FOUND.046
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 12:53 . 2012-04-08 02:51 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 12:53 . 2011-05-17 22:17 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 16:46 . 2010-03-01 16:19 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 16:21 . 2011-02-24 22:33 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2009-01-04 22:21 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2009-01-04 22:21 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2009-01-04 22:21 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 16:21 . 2009-01-04 22:21 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 16:21 . 2009-01-04 22:21 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2009-01-04 22:21 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2009-01-04 22:21 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 16:21 . 2010-06-29 11:29 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2009-01-04 22:20 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-13 13:55 . 2004-12-03 18:25 1866240 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-04-14 02:20 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2004-12-03 18:25 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2004-12-03 18:25 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 18:19 . 2008-03-17 13:26 15896 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 18:19 . 2008-03-17 13:26 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 18:19 . 2004-12-03 18:54 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 18:19 . 2004-12-03 18:54 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 18:19 . 2004-12-03 18:54 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 18:19 . 2008-03-17 13:26 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 18:19 . 2005-05-26 07:16 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 18:19 . 2004-12-03 19:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 18:19 . 2004-12-03 18:54 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 18:19 . 2004-12-03 18:25 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 18:19 . 2008-03-17 13:26 23576 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 18:19 . 2004-12-03 18:54 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 18:19 . 2004-12-03 18:54 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 18:18 . 2008-03-18 12:59 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 18:18 . 2008-03-18 12:59 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 18:18 . 2008-03-18 12:59 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:21 . 2004-12-03 18:25 605184 ----a-w- c:\windows\system32\crypt32.dll
2012-05-31 03:41 . 2010-04-03 15:34 6762896 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-05-16 15:08 . 2004-12-03 18:25 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:43 . 2004-12-03 18:25 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:43 . 2004-12-03 18:25 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:39 . 2004-12-03 18:25 385024 ----a-w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2004-12-03 18:25 2152448 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-04 03:40 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2004-12-03 18:53 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:_arquivos de programas_c44"="c:\arquivos de programas\Corel\Corel Graphics 12\Programs\CorUpd.exe" [2003-11-18 139264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-17 69632]
"desp2k"="c:\arquivos de programas\Oi Velox\Manager\desp2k.exe" [2006-08-03 65536]
"00PCTFW"="c:\arquivos de programas\PC Tools Firewall Plus\FirewallGUI.exe" [2010-11-29 2676696]
"QuickTime Task"="c:\arquivos de programas\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" [2009-08-30 413696]
"Disney"="c:\arquivos de programas\Disney Interactive\mapeia.bat" [2004-12-03 63]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"avast"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2012-07-03 4273976]
.
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 08:37 843712 ----a-w- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 00:52 49152 ----a-w- c:\arquivos de programas\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 14:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-08-30 19:19 413696 ----a-w- c:\arquivos de programas\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 17:02 254696 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Click21\\DialUP.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\Ares\\Ares.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8028:TCP"= 8028:TCP:emule
"26329:TCP"= 26329:TCP:BitComet 26329 TCP
"26329:UDP"= 26329:UDP:BitComet 26329 UDP
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [24/2/2011 19:33 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/1/2009 19:21 353688]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [1/5/2010 11:46 249616]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/1/2009 19:21 21256]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [1/5/2010 11:46 160448]
R2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 19:19 13592]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [6/3/2008 23:29 47360]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [1/5/2010 11:45 89192]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [1/5/2010 11:45 57536]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [1/5/2010 11:45 124992]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/4/2012 23:51 250056]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [29/5/2006 12:43 64512]
S3 utmzodcz;AVZ Kernel Driver; [x]
.
--- =Outros Serviços/Drivers Na Memória ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2012-07-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]
.
2010-10-07 c:\windows\Tasks\SmartDefrag.job
- c:\arquivos de programas\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-07-07 19:48]
.
2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 12:53]
.
2012-07-16 c:\windows\Tasks\User_Feed_Synchronization-{A114D1D3-B9AA-4CD5-9551-E329A97A36F8}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 07:31]
.
2012-07-16 c:\windows\Tasks\avast! Emergency Update.job
- c:\arquivos de programas\Alwil Software\Avast5\AvastEmUpdate.exe [2012-06-28 16:21]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.globo.com.br/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = hxxp://www.positivoinformatica.com.br/
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254 198.153.192.1 198.153.194.1
TCP: Interfaces\{281F10F2-6BDE-47CA-BDFB-5863E5017A63}: NameServer = 198.153.192.50,198.153.194.50
.
- - - - ORFÃOS REMOVIDOS - - - -
.
HKLM-Run-Cmaudio - cmicnfg.cpl
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-07-16 12:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
Procurando processos ocultos ...
.
Procurando entradas auto inicializáveis ocultas ...
.
Procurando ficheiros/arquivos ocultos ...
.
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
.
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]
"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
.
- - - - - - - > 'explorer.exe'(7540)
c:\windows\system32\WININET.dll
c:\arquivos de programas\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\arquivos de programas\Alwil Software\Avast5\AvastSvc.exe
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\arquivos de programas\PC Tools Firewall Plus\FWService.exe
c:\windows\SOUNDMAN.EXE
c:\arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Tempo para conclusão: 2012-07-16 12:46:04 - Máquina reiniciou
ComboFix-quarantined-files.txt 2012-07-16 15:45
.
Pré-execução: 12 pasta(s) 41.160.933.376 bytes disponíveis
Pós execução: 61 pasta(s) 41.875.177.472 bytes disponíveis
.
WindowsXP-KB310994-SP2-Home-BootDisk-PTB.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C6BD047A9E644FC31A54AB18298DD741
Se eu tiver feito alguma coisa errada por favor,pode me mandar novas instruções,ou repetir o programa .Obrigada