Ir para conteúdo

BABOO e KTS 2018 no YouTube Loja online do BABOO

cbareis

Participante
  • Postagens

    17
  • Desde

  • Última visita

Perfil

  • Estado
    São Paulo
  • Sexo
    masculino
  1. a) O que o teria corrompido? b) Quais os riscos de continuar nesse estado, tendo em vista que o sistema parece normal? c) Qual a relação entre a mensagem de erro atípica do Windows repair e a constatação da corrupção do OS? Nunca vi um programa que ao tentar executar acusa a si próprio de provavelmente infectado. Considero muito estranho. Muito obrigado!!
  2. Mas qual é a minha situação afinal, Mr. Million?
  3. Ao clicar em repair.Windows.exe, apareceu uma tela com título repair_windows.exe e texto "file corrupted! This program has been manipulated and maybe its's infected by a virus or cracked. This file won't work anymore". Salvei um print, se precisar.
  4. Estou fazendo agora a analise do junkware. Mas está demorando muito, mais de 20 min. Está na última etapa, shortcuts. Algum parecer até agora?
  5. Malwarebytes www.malwarebytes.com -Detalhes de registro- Data da análise: 20/03/17 Hora da análise: 18:32 Arquivo de registro: Administrador: Sim -Informação do software- Versão: 3.0.6.1469 Versão de componentes: 1.0.75 Versão do pacote de definições: 1.0.1549 Licença: Versão de avaliação -Informação do sistema- Sistema operacional: Windows 7 Service Pack 1 CPU: x64 Sistema de arquivos: NTFS Usuário: xxxxxxxxxxxxxxxxxxxxxxxxx -Resumo da análise- Tipo de análise: Análise de Ameaças Resultado: Concluído Objetos verificados: 385628 Tempo decorrido: 4 min, 41 seg -Opções da análise- Memória: Habilitado Inicialização: Habilitado Sistema de arquivos: Habilitado Arquivos compactados: Habilitado Rootkits: Habilitado Heurística: Habilitado PUP: Habilitado PUM: Habilitado -Detalhes da análise- Processo: 0 (Nenhum item malicioso detectado) Módulo: 0 (Nenhum item malicioso detectado) Chave de registro: 0 (Nenhum item malicioso detectado) Valor de registro: 0 (Nenhum item malicioso detectado) Dados de registro: 0 (Nenhum item malicioso detectado) Fluxo de dados: 0 (Nenhum item malicioso detectado) Pasta: 0 (Nenhum item malicioso detectado) Arquivo: 0 (Nenhum item malicioso detectado) Setor físico: 0 (Nenhum item malicioso detectado) (end)
  6. Colegas de forum, trago o meu log do hijachthis ao final. A situação é a seguinte: Suspeito que meu PC está infectado. Há algum tempo, na inicialização do Windows, é solicitada autorização pra execução de um arquivo de desenvolvedor desconhecedor. O arquivo é o systempropertiesperformance.exe, na pasta Windows/system32. Pesquisei e esse arquivo é do próprio Windows. Fiz o upload dele para o virustotal e nada foi indicado. Além de pedir essa autorização no início (que uma vez por descuido dei), o PC apresentava outro comportamento estranho: não conseguia instalar antivírus. Bitdefender, AVG e Avast dão erro na instalação, não instalam. O bit trava o PC, o avast fica carregando a instalação sempre e o AVG dá erro de instalação por excesso de prazo. Já o Avira instalou, rodei, achou alguma coisa mas não mudou a solicitação de autorização do arquivo. Busquei orientação, rodei outros programas: adwcleaner_6.042, Kaspersky anti virus removal tool. Lembro que quando fiz isso a autorização ainda era pedida. Mas logo em seguida consegui instalar o BitDefender free. Agora estou com o BitDefender Total e não sei exatamente desde quando mas a autorização não é mais solicitada. Em suma, o PC parece normal. Mas não sei o que fazer. Devo proceder de mais alguma maneira? Peço desculpas pela minha conduta errática, mas faltou tempo para planejar e executar as ações. Obrigado!! "Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 17:10:00, on 20/03/2017 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.18015) Boot mode: Normal Running processes: C:\PROGRA~2\GbPlugin\GbpSv.exe C:\Program Files (x86)\Lingoes\Translator2\Lingoes.exe C:\Users\Carlos Bernardo\AppData\Local\FluxSoftware\Flux\flux.exe C:\Users\Carlos Bernardo\AppData\Roaming\uTorrent\uTorrent.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe C:\Program Files (x86)\Corsair\Corsair Link\CorsairLINK.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\MPC-HC\mpc-hc.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Users\Carlos Bernardo\Downloads\HijackThis.exe C:\Program Files (x86)\Opera\Launcher.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe C:\Program Files (x86)\Opera\43.0.2442.1144\opera_crashreporter.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Carteira Bitdefender - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2017\Antispam32\pmbxie.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES (X86)\GBPLUGIN\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll O3 - Toolbar: Carteira Bitdefender - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2017\Antispam32\pmbxie.dll O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN O4 - HKLM\..\Run: [OnScreen Control] C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe O4 - HKCU\..\Run: [Lingoes] C:\Program Files (x86)\Lingoes\Translator2\Lingoes.exe -minimize O4 - HKCU\..\Run: [f.lux] "C:\Users\Carlos Bernardo\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow O4 - HKCU\..\Run: [uTorrent] "C:\Users\Carlos Bernardo\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED O4 - HKCU\..\Run: [Dropbox Update] "C:\Users\Carlos Bernardo\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_2DBCF4E7F914FE0B0264A657058A10C4] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 O4 - Startup: Windows Live Mail.lnk = C:\Program Files (x86)\Windows Live\Mail\wlmail.exe O4 - Global Startup: Windows Live Mail.lnk = C:\Program Files (x86)\Windows Live\Mail\wlmail.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\Windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\Windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O15 - Trusted Zone: http://www.bb.com.br O17 - HKLM\System\CCS\Services\Tcpip\..\{421DE416-6B0D-48BE-B9F8-472A80CE0582}: NameServer = 208.67.222.222,208.67.220.200 O17 - HKLM\System\CCS\Services\Tcpip\..\{64081C7D-2E11-4ED0-B201-30E1654C1449}: NameServer = 8.8.8.8,8.8.4.4 O17 - HKLM\System\CCS\Services\Tcpip\..\{F426ABCA-F55D-43B9-BD05-E1EF0D5A4B80}: NameServer = 8.8.8.8,8.8.4.4 O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES (X86)\GBPLUGIN\gbieh.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: Serviço de Gerenciamento de Dispositivos do Bitdefender (DevMgmtService) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender Device Management\DevMgmtService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: Everything - Unknown owner - C:\Program Files\Everything\Everything.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe O23 - Service: ProductAgentService - Bitdefender - C:\Program Files\Bitdefender Agent\ProductAgentService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: RealtekCU - Realtek Semiconductor Corp. - C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: Splashtop® Remote Service (SplashtopRemoteService) - Splashtop Inc. - C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Bitdefender Desktop Update Service (UPDATESRV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2017\updatesrv.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: Bitdefender Virus Shield (VSSERV) - Bitdefender - C:\Program Files\Bitdefender\Bitdefender 2017\vsserv.exe O23 - Service: Warsaw Technology - GAS Tecnologia LTDA - C:\Program Files\Diebold\Warsaw\core.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 14141 bytes"
  7. Suspeita de pc infectado, o que fazer?

    Obrigado pela dica e desculpas pelo equívoco.
  8. Erro no Windows que Desconheço (vide print)

    Obrigado, Tatha. Sim, tenho o bitdefender. O erro é eventual. Não vale a pena desinstalar o av. Engraçado que troquei recentemente o av 2015 pelo 2016 e o erro aconteceu em ambos. Assim, se o problema parece ser o bitdefender, fico tranquilo. Obrigado!
  9. Erro no Windows que Desconheço (vide print)

    Galera, enquanto eu usava normalmente o Windows 7 aparece essa tela azul: Não faço a mínima idéia do que seja. Uso SSD. Nunca mais aconteceu. Devo me preocupar?
×