1. Este site usa cookies. Ao continuar a usar este site está a concordar com o nosso uso de cookies. Saber Mais.

A barra de iniciar e os itens do ambiente de trabalho aparecem e depois desaparecem

Discussão em 'Dúvidas e Suporte Técnico PC' iniciada por delet, 12 de Novembro de 2008. (Respostas: 12; Visualizações: 928)

  1. Quando ligo o pc, a barra de iniciar desaparece e os itens do ambiente de trabalho tambem, e aparecem denovo de 5 em 5 seg...
    Sera algum viros?
     
  2. luxboy

    luxboy Power Member

    posta aki um log do hijackthis
     
  3. MunieZ

    MunieZ Power Member

    quaze deserteza que é um virus...
     
  4. Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:58:21, on 12-11-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
    C:\Programas\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programas\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\V0220Mon.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Programas\Creative\Creative Live! Cam\VideoFX\StartFX.exe
    C:\Programas\Ficheiros comuns\InstallShield\UpdateService\ISUSPM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programas\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
    C:\Programas\Windows Live\Messenger\MsnMsgr.Exe
    C:\Programas\Ficheiros comuns\LightScribe\LSSrvc.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
    C:\Programas\Alwil Software\Avast4\ashWebSv.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Chrome\Application\chrome.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Chrome\Application\chrome.exe
    C:\Programas\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [V0220Mon.exe] C:\WINDOWS\V0220Mon.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [AVFX Engine] C:\Programas\Creative\Creative Live! Cam\VideoFX\StartFX.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ISUSPM] "C:\Programas\Ficheiros comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKLM\..\Run: [muBlinder] C:\Documents and Settings\Familia\Ambiente de trabalho\muBlinder.exe -startup
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Programas\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Familia\Definições locais\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [uTorrent] "C:\Programas\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Programas\IObit\Advanced SystemCare 3 Beta\AWC.exe" /startup
    O4 - HKCU\..\Run: [Chatango] C:\Programas\Chatango\Chatango.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Xfire.lnk = C:\Programas\Xfire\xfire.exe
    O4 - Startup: µTorrent.lnk = C:\Programas\uTorrent\uTorrent.exe
    O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programas\Ficheiros comuns\LightScribe\LSSrvc.exe
    O24 - Desktop Component 0: (no name) - http://i4.ytimg.com/vi/sae1itsXt_M/default.jpg

    --
    End of file - 6553 bytes
     
  5. eu acho que é um processo que se chama rundll32.exe que esta a causar isto...
    como posso arranjar isto?

    mais uma coisa, se eu for no gestor de tarefas e fizer uma tarefa chamada explorer.exe vai ao normal, mas passado 5 seg volta a fazer a mesma coisa
     
    Última edição: 12 de Novembro de 2008
  6. luxboy

    luxboy Power Member

    apaga esse ultima linha a 024.. é algo estranho :S
     
  7. é só apagar no bloco de notas e guardar?
     
  8. já sei como se apaga!
    já apaguei e o problema continua
     
  9. luxboy

    luxboy Power Member

    fazes o hijackthis e depois seleccionas esse item e metes FIX.. depois reinicias o pc..
     
  10. agora não posso reninciar o pc, estou a verificar o computador no site da microsoft
     
  11. pedro6250

    pedro6250 Power Member

    Deve ser virus, no meu pc anterior aconteceu uma cena identica...
     
  12. fgaifen

    fgaifen Power Member

    Tenta apagar estas:

    O4 - HKCU\..\Run: [Chatango] C:\Programas\Chatango\Chatango.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
    O24 - Desktop Component 0: (no name) - http://i4.ytimg.com/vi/sae1itsXt_M/default.jpg
     

Partilhar esta Página