Analisar meu log do hijackthis

Fechado
RobertoPaes Posts 1 Data de inscrição quarta 23 de setembro de 2015 Status Membro Última visita 23 de setembro de 2015 - 23 set 2015 às 00:53
JESUS CRISTO Posts 1591 Data de inscrição segunda 4 de outubro de 2010 Status Contribuinte Última visita 23 de junho de 2016 - 23 set 2015 às 23:43
Bom dia;

Preciso que me ajudem analisando meu log do hijackthis, pois minha maquina esta lenta, as vezes nao abre alguns programas, o antivirus nao funciona, nao consigo abrir sites de antivirus, e sequer instalar antivirus, nao consigo usar scan online tambem.

HELPP

segue abaixo o log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:35:41, on 23/09/2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Dados de aplicativos\aWinManProa\ProtectWindowsManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\ToolsUpdatePlatform\UpdatePlatform.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Alterdata\PDV Alterdata\ServidorOffLine.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
C:\Arquivos de programas\Alterdata Software\NF-Stock\Monitor\bin\NFStockMonitorUI.exe
C:\Filizola\Backup Manager\bkpmanager.exe
C:\Arquivos de programas\Alterdata\Shop\ServidorOffLine.exe
C:\Arquivos de programas\Alterdata\PDV Alterdata\ServidorOffLineGuardian.exe
C:\Arquivos de programas\Alterdata\Updater\bin\AlterdataAutoUpdate.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\EPSON\EPuras\EPurasLog.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ScsiCommandService2.exe
C:\Arquivos de programas\EPSON\EPuras\EPuras.exe
C:\Arquivos de programas\Alterdata\Servidor\nxServer.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Arquivos de programas\Alterdata\Shop\AltShopProc_AlinhamentoTransacaoPendenteWSHOP.exe
C:\Arquivos de programas\Alterdata\Shop\ExpOffLine.Exe
C:\Arquivos de programas\TeamViewer\TeamViewer_Service.exe
C:\Arquivos de programas\TeamViewer\TeamViewer.exe
C:\Arquivos de programas\TeamViewer\tv_w32.exe
c:\arquivos de programas\teamviewer\TeamViewer_Desktop.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.google.com/webhp?gws_rd=ssl{searchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/webhp?gws_rd=ssl{searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\Arquivos de programas\webget\bin\Pac9064.js
O2 - BHO: DealExpress - {4be8efc6-5e56-40ba-b4f9-8dde13d4c4ea} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.8.0_40\bin\ssv.dll
O2 - BHO: CheapMe - {8128355c-baa2-44eb-be60-fe0fd6526da5} - C:\Documents and Settings\All Users\Dados de aplicativos\CheapMe\lrP6LVdsR0mUHN.dll
O2 - BHO: NetoCoupon - {94cdd9d1-78a3-4e89-81af-36c3c4cc9db8} - (no file)
O2 - BHO: DiscountExtensi - {a35fc21f-b5c0-4621-95ff-44e705a4115e} - (no file)
O2 - BHO: G-Buster Browser Defense Banco Real - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Arquivos de programas\GbPlugin\gbiehabn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre1.8.0_40\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ServidorOffLine] C:\Arquivos de programas\Alterdata\PDV Alterdata\ServidorOffLine.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [NF-Stock Monitor] "C:\Documents and Settings\All Users\Menu Iniciar\Programas\Alterdata\NF-Stock\NF-Stock Monitor.lnk" -on -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ServidorOffLine.lnk = Shop\ServidorOffLine.exe
O4 - Global Startup: Backup Manager.lnk = ?
O4 - Global Startup: Status Monitor.lnk = ?
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Arquivos de programas\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Arquivos de programas\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2fbr%2faccess%2fallinone.asp%3f
O15 - Trusted Zone: https://www.santander.com.br/
O15 - Trusted Zone: https://www.santander.com.br/
O15 - Trusted Zone: http://www.cte.fazenda.gov.br/portal/
O15 - Trusted Zone: http://www.nfe.fazenda.gov.br/portal/
O15 - Trusted Zone: www.santander.com.br
O15 - Trusted Zone: https://www.santander.com.br/
O15 - Trusted Zone: www.santanderempresarial.com.br
O15 - Trusted Zone: https://www.santander.com.br/?segmento=negocios-empresas
O15 - Trusted Zone: www.santandernet.com.br
O15 - Trusted Zone: wwws.santandernet.com.br
O15 - Trusted Zone: wwws2.santandernet.com.br
O15 - Trusted Zone: www.santandernetibe.com.br
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BE94CF9-315E-4FB0-BD71-451E49462412}: NameServer = 192.168.1.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehAbn.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Alterdata Updater - Alterdata Software - C:\Arquivos de programas\Alterdata\Updater\bin\AlterdataAutoUpdate.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BlackBerry Device Manager (Blackberry Device Manager) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Research In Motion\USB Drivers\BbDevMgr.exe (file missing)
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Arquivos de programas\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: Epson Puras Service (EpsonPuras) - SEIKO EPSON CORPORATION - C:\Arquivos de programas\EPSON\EPuras\EPuras.exe
O23 - Service: Epson Puras Log Service (EpsonPurasLog) - SEIKO EPSON CORPORATION - C:\Arquivos de programas\EPSON\EPuras\EPurasLog.exe
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Arquivos de programas\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)
O23 - Service: MgAssist Service (MgAssistService) - Unknown owner - C:\Arquivos de programas\Mobogenie\MgAssist.exe (file missing)
O23 - Service: Microsoft SharePoint Workspace Audit Service - Unknown owner - C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE (file missing)
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
O23 - Service: NexusDB Server V3 (NXDBServerV3) - Unknown owner - C:\Arquivos de programas\Alterdata\Servidor\nxServer.exe
O23 - Service: Office Software Protection Platform (osppsvc) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (file missing)
O23 - Service: SCSI command service (ScsiCommandService2) - Mobile Leader Co.,Ltd. - C:\WINDOWS\system32\ScsiCommandService2.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Arquivos de programas\TeamViewer\TeamViewer_Service.exe
O23 - Service: Update webget - Unknown owner - C:\Arquivos de programas\webget\updatewebget.exe (file missing)
O23 - Service: Util webget - Unknown owner - C:\Arquivos de programas\webget\bin\utilwebget.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - DTools LIMITED - C:\Documents and Settings\All Users\Dados de aplicativos\aWinManProa\ProtectWindowsManager.exe

End of file - 12184 bytes

1 Respostas

JESUS CRISTO Posts 1591 Data de inscrição segunda 4 de outubro de 2010 Status Contribuinte Última visita 23 de junho de 2016 3.160
23 set 2015 às 23:43
HELLO,ROBERTO



SIM SEU PC ESTA INFECTADO!


C:\Documents and Settings\All Users\Dados de aplicativos\aWinManProa\ProtectWindowsManager.exe

LINK: https://www.bleepingcomputer.com/startups/ProtectWindowsManager.exe-28697.html


PASSOS PARA LIMPEZA DE SEU PC:


1º FAÇA O DOWNLOAD DOS SEGUINTES PROGRAMAS:

LINK: https://www.bleepingcomputer.com/download/combofix/

LINK: https://www.bleepingcomputer.com/download/rkill/

LINK: https://www.bleepingcomputer.com/download/adwcleaner/

LINK: https://www.ccleaner.com/ccleaner/download/standard


2º REINICIE SEU PC EM MODO DE SEGURANÇA COM REDE

" REINICIE E APERTE VÁRIAS VEZES A TECLA F9 OU F8 DEPENDE DA PLACA MÃE E SELECIONE MODO DE SEGURANÇA COM REDE "


3º USE O COMBOFIX:

TUTORIAL LINK: https://www.bleepingcomputer.com/combofix/pt/como-usar-o-combofix


4º APÓS A LIMPEZA COM O COMBOFIX TERMINAR USE O RKILL


" O RKILL NÃO TEM MISTÉRIOS,CLICK COM O BOTÃO DIREITO DO MOUSE SOBRE ELE E SELECIONE EXECUTAR COMO ADMINISTRADOR CONFIRME E ESPERE ELE FINALIZAR OS PROCESSOS SUSPEITOS "


5º AGORA USE O ADWCLEANER

" NA PAGINA DE DOWNLOAD DO ADWCLEANER TEM AS FOTOS COM OS PASSOS PARA ESCANEAR E LIMPAR "


6º FEITO ISSO USE O CCLEANER


" VEJA O VIDEO ABAIXO PARA SABER COMO USAR "RECOMENDO VC USAR APENAS A PARTE DE LIMPEZA DO VIDEO OK "

LINK: https://www.youtube.com/watch?t=2&v=oIXYwnEOh8g


7º REINICIE O PC E VEJA SE RESOLVEU!


8º FAÇA O ESCANEAMENTO COMPLETO COM SEU ANTIVIRUS OK.



OBS: " PARECE SER MUITA COISA PRA FAZER MAS É BEM FÁCIL E RÁPIDO RESOLVER "

OBS2: " SE NÃO CONSEGUIR FAZER DOWNLOAD DOS PROGRAMAS EM SEU PC,PEÇA PARA UM AMIGO BAIXAR E SALVAR EM UM PENDRIVE OK "


DEPOIS FALE SE RESOLVEU O PROBLEMA!
0

Assine nossa newsletter!

Assine nossa newsletter!
Junte-se à comunidade