Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Reivax

[Resolvido!] Sality.aa

Recommended Posts

Caros colegas do Fórum, desde já agradeço pela ajuda.

Recentemente meu pc foi infectado pelo vírus Win32/Sality.aa. Nisso eu estava usando o Win Vista Ultimate 64x em uma das duas partições, e na outra eu uso para guardar meus arquivos, também infectados.

Na falta de ferramentas para remover esse vírus compatível com meu SO, resolvi instalar o WinXP no lugar do Vista (sem excluir nem formatar minha outra partição), onde tentei varias formas de remover essa praga. Na minha última tentativa pensei ter obtido sucesso, usando o Sality_off e o Dr, Web, que detectaram mais de mil arquivos infectados e restaurados (pelo menos era o que o Dr. Web dizia).

Senti uma melhora considerável no sistema, porém, com o passar do tempo, ele começou a ficar mais lento, e qualquer antivírus que eu utilize não atualiza de jeito nenhum, além de demorar pra acessar os arquivos na outra partição que uso pra armazenar dados.

Já formatei o PC várias vezes depois disso e os sintomas sempre voltam. Já tentei usar as ferramentas usadas acima e não detectaram nenhum outro vírus, mas dá pra perceber nitidamente que o PC está infectado.

Preciso da ajuda de vcs pra resolver esse problema, pois não posso formatar a partição de dados (que está infectada) pois tenho muitos arquivos importantes nele.

Segue o log do Hijackthis abaixo. Mais uma vez obrigado! Abraços!

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:39:53, on 11/08/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Arquivos de programas\Internet Download Manager\IDMan.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

E:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

E:\Arquivos de programas\Mozilla Firefox\firefox.exe

E:\WINDOWS\AhnRpta.exe

E:\Arquivos de programas\ESET\ESET Online Scanner\OnlineScannerApp.exe

E:\Arquivos de programas\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe

E:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

E:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

E:\WINDOWS\system32\svchost.exe

E:\Hijackthis\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: IEHlprObj Class - {AF4DA69B-E1D6-469A-855B-6445294857D4} - E:\WINDOWS\system32\ahnxsds0.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [avgnt] "E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [ahnsoft] E:\WINDOWS\system32\ahnsbsb.exe

O4 - HKCU\..\Run: [iDMan] E:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Download all links with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - E:\Arquivos de programas\Internet Download Manager\IEExt.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://E:\ARQUIV~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\ARQUIV~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249779356781

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

 

--

End of file - 5801 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Reivax

 

<!> O ideal,para a desinfecção,seria baixar as ferramentas por intermédio de outro computador,mantendo esse desconectado. Desabilite,também,a Restauração do Sistema.

<><><><><><><><><><>

<@> Baixe: < SafeBootKeyRepair >

<@> Salve-a,diretamente,no Disco-local (E).

<@> Execute-a!E,ao terminar,gerará um relatório: E:\SafeBoot_Repair.txt <-- Não poste!

<@> Verifique se já pode entrar,em Modo de Segurança!

<><><><><><><><><><>

<@> Baixe: < AVPTool > ( by Kaspersky Labs )

<@> Salve-o em Arquivos de Programas,e instale-o aí mesmo!

<@> Reinicie o computador,em Modo de Segurança! <-- Importante!

<@> Dê início ao exame,clicando em "Scan".

<@> A verificação é muito demorada. <-- Aguarde!

<@> Caso sejam encontradas infecções,clique em "disinfect" se a opção estiver habilitada.

<@> Ps: Para algumas detecções ( Cracks ou Keygens ),conhecidas,clique em skip.

<@> Evite,para esses casos,a opção "Delete".

<@> Terminando,clique na aba Events.

<@> Desmarque a caixa de seleção "Show all events".

<@> Clique em "Save to file".

<@> Nomeie-o e salve-o no desktop! <-- Relatório para postagem!

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite, DigRam!

Bom, você disse que o scan ia ser demorado, mas nao imaginei que fosse tanto...

Deixei a noite toda, fui trabalhar, cheguei agora a pouco e só tinha scaneado 6% do Micro!

Será que nao teria outra ferramenta (sem querer abusar)?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite, DigRam!

Bom, você disse que o scan ia ser demorado, mas nao imaginei que fosse tanto...

Deixei a noite toda, fui trabalhar, cheguei agora a pouco e só tinha scaneado 6% do Micro!

Será que nao teria outra ferramenta (sem querer abusar)?

<><><><><><><><><>

Opa! Reivax

 

<!> Desmarcou essa caixa: "Show all events" <--

<!> Desmarque-a e repita o scan.

<!> Tendo,ainda,dificuldades utilize primeiro o DrWebCureIt.

<><><><><><><><><>

<@> Baixe: < DrWebCureIt >

<@> Caso tenha dificuldades para o download,utilize outro computador ou proxy.

<@> Vá em: < Proxify >

<@> Digite,na caixa,a URL ao DrWebCureIt.

<@> Clique em Proxify.

<@> Salve a ferramenta no desktop!

<@> Reinicie o computador em Modo de Segurança.

<@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit.

<@> Na janela que abrir,clique em Iniciar --> OK.

<@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda!

<@> Terminando,marque a caixa de "Verificação Completa".

<@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis".

 

Neste modo são verificados os seguintes objectos:

 

* Sectores de Arranque de Todos os Discos. <--

 

* Todas as Unidades Removíveis. <--

 

* Todos os Discos Locais. <--

<@> Clique em "Iniciar verificação" --> Aguarde!

<@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim.

<@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios".

<@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Converta em Texto!

<@> Poste: DrWeb.csv + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa, beleza?!

Antes de fazer o que você pediu, instalei o Avira versão gratuita, e ele identificou mais de 320 TR/Agent.542720.C, e senti uma leve melhora no sistema. Bom, taí o log do Dr.Web.

 

A0001670.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001712.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001836.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001842.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP14;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001972.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP15;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001979.exe;D:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP16;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001643.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001645.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.11478;Eliminado.;

A0001650.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001662.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.11478;Eliminado.;

A0001672.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001706.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.11478;Eliminado.;

A0001714.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001831.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.11478;Eliminado.;

A0001838.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP13;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001844.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP14;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001974.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP15;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001981.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP16;Trojan.PWS.Wsgame.10150;Eliminado.;

A0001984.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP16;Trojan.PWS.Wsgame.12342;Eliminado.;

A0001989.exe;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP16;Trojan.PWS.Wsgame.10150;Eliminado.;

A0002004.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP16;Trojan.PWS.Wsgame.12342;Eliminado.;

A0002366.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP21;Trojan.PWS.Wsgame.12342;Eliminado.;

A0002369.bat;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP21;Trojan.Nsanti.Packed.56;Incurável.Movido.;

A0002370.dll;E:\System Volume Information\_restore{34DA3DC3-4202-435F-A9AC-3C86AF8AA968}\RP21;Trojan.PWS.Wsgame.11478;Eliminado.;

 

 

Hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:46:09, on 14/08/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

E:\Arquivos de programas\Internet Download Manager\IDMan.exe

E:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

E:\Arquivos de programas\Mozilla Firefox\firefox.exe

E:\WINDOWS\system32\ctfmon.exe

E:\WINDOWS\system32\wuauclt.exe

E:\Documents and Settings\Robson\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: IEHlprObj Class - {AF4DA69B-E1D6-469A-855B-6445294857D4} - E:\WINDOWS\system32\ahnxsds0.dll (file missing)

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [avgnt] "E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [iDMan] E:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Download all links with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - E:\Arquivos de programas\Internet Download Manager\IEExt.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://E:\ARQUIV~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\ARQUIV~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249779356781

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

 

--

End of file - 5598 bytes

 

Valeu!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Reivax

 

<@> Baixe: < thumb_mbam256.png > Malwarebytes

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<><><><><><><><><><><>

<@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá! Boa tarde!

Aí estão os logs:

 

 

mbam-log-2009-08-15 (17-37-30)

 

Malwarebytes' Anti-Malware 1.40

Versão do banco de dados: 2630

Windows 5.1.2600 Service Pack 3

 

15/08/2009 17:37:30

mbam-log-2009-08-15 (17-37-30).txt

 

Tipo de Verificação: Completa (C:\|D:\|E:\|H:\|)

Objetos verificados: 150927

Tempo decorrido: 18 minute(s), 21 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 5

Valores do Registro infectados: 1

Ítens do Registro infectados: 1

Pastas infectadas: 0

Arquivos infectados: 1

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{af4da69b-e1d6-469a-855b-6445294857d4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{af4da69b-e1d6-469a-855b-6445294857d4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\iehlprobj.iehlprobj.1 (Spyware.OnlineGames) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{bb4c402f-882a-4526-8c08-51278ea437c1} (Spyware.OnlineGames) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af4da69b-e1d6-469a-855b-6445294857d4} (Spyware.OnlineGames) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bb4c402f-882a-4526-8c08-51278ea437c1} (Spyware.OnlineGames) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

E:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.

 

 

Hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:42:56, on 15/08/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

E:\WINDOWS\Explorer.EXE

E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

E:\Arquivos de programas\Internet Download Manager\IDMan.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

E:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

E:\WINDOWS\system32\wuauclt.exe

E:\Documents and Settings\Robson\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - E:\Arquivos de programas\Canon\Easy-WebPrint\EWPBrowseLoader.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll

O4 - HKLM\..\Run: [avgnt] "E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [Easy-PrintToolBox] E:\Arquivos de programas\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon

O4 - HKCU\..\Run: [iDMan] E:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Download all links with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - E:\Arquivos de programas\Internet Download Manager\IEExt.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://E:\ARQUIV~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\ARQUIV~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249779356781

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

 

--

End of file - 6368 bytes

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Reivax

 

<@> Baixe: < desktopicon.png > ( ...by sUBs )

<@> Salve-o no desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

 

<@> Ps: A execução,por comando,também é possível:

<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\Desktop\Combofix.exe" /killall

<@> Clique em Ok.

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link!

 

<!> Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:

 

Rookit_found.gif

 

<!> Ps: Anote essas detecções,e dê o OK.

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!

<!> Ps: Para evitar problemas,siga todas as recomendações propostas.

<!> Ps: O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

<><><><><><><><><><><><>

<@> Terminando,poste os relatórios: E:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite!

 

Log ComboFix

 

ComboFix 09-08-10.06 - Robson 15/08/2009 23:48.1.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1791.1268 [GMT -3:00]

Executando de: e:\documents and settings\Robson\Desktop\ComboFix.exe

AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

 

ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-07-16 to 2009-08-16 ))))))))))))))))))))))))))))

.

 

2009-08-15 19:50 . 2009-08-15 19:50 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\Malwarebytes

2009-08-15 19:49 . 2009-08-03 16:36 38160 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys

2009-08-15 19:49 . 2009-08-15 19:49 -------- d-----w- e:\arquivos de programas\Malwarebytes' Anti-Malware

2009-08-15 19:49 . 2009-08-15 19:49 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-08-15 19:49 . 2009-08-03 16:36 19096 ----a-w- e:\windows\system32\drivers\mbam.sys

2009-08-15 01:10 . 2003-09-18 17:32 1060864 ----a-w- e:\windows\system32\MFC71.dll

2009-08-15 01:10 . 2009-08-15 01:10 -------- d--h--w- e:\documents and settings\All Users\Dados de aplicativos\CanonBJ

2009-08-15 01:09 . 2006-09-13 05:00 197632 ----a-w- e:\windows\system32\CNMLM7X.DLL

2009-08-15 01:09 . 2009-08-15 01:09 -------- d--h--w- e:\windows\system32\CanonIJ Uninstaller Information

2009-08-15 01:09 . 2009-08-15 01:09 -------- d--h--w- e:\arquivos de programas\CanonBJ

2009-08-15 01:08 . 2009-08-15 01:11 -------- d-----w- e:\arquivos de programas\Canon

2009-08-15 01:07 . 2008-04-13 14:47 25856 -c--a-w- e:\windows\system32\dllcache\usbprint.sys

2009-08-15 01:07 . 2008-04-13 14:47 25856 ----a-w- e:\windows\system32\drivers\usbprint.sys

2009-08-13 01:43 . 2009-03-30 13:33 96104 ----a-w- e:\windows\system32\drivers\avipbb.sys

2009-08-13 01:43 . 2009-02-13 15:29 22360 ----a-w- e:\windows\system32\drivers\avgntmgr.sys

2009-08-13 01:43 . 2009-02-13 15:17 45416 ----a-w- e:\windows\system32\drivers\avgntdd.sys

2009-08-13 01:42 . 2009-08-16 02:50 21182496 --sha-w- e:\windows\system32\drivers\fidbox.dat

2009-08-13 00:54 . 2009-08-13 01:40 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\NOS

2009-08-13 00:54 . 2009-08-13 01:40 -------- d-----w- e:\arquivos de programas\NOS

2009-08-13 00:17 . 2009-08-13 00:17 -------- d-sh--w- e:\documents and settings\LocalService\IETldCache

2009-08-12 23:31 . 2009-08-12 23:31 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\Avira

2009-08-12 02:46 . 2009-08-12 02:46 552 ----a-w- e:\windows\system32\d3d8caps.dat

2009-08-12 02:31 . 2008-07-08 17:54 148496 ----a-w- e:\windows\system32\drivers\23831203.sys

2009-08-12 02:27 . 2009-08-12 02:31 41423800 ----a-w- e:\arquivos de programas\setup_7.0.0.290_12.08.2009_05-24.exe

2009-08-12 02:22 . 2009-08-12 02:22 288654 ----a-w- E:\SafeBootKeyRepair.exe

2009-08-12 01:04 . 2009-08-12 01:04 -------- d-----w- e:\windows\SHELLNEW

2009-08-12 01:04 . 2009-08-12 01:04 -------- d-----w- e:\arquivos de programas\Microsoft.NET

2009-08-12 00:59 . 2009-08-12 01:39 -------- d-----w- E:\Hijackthis

2009-08-12 00:15 . 2009-08-12 00:15 -------- d-----w- e:\arquivos de programas\ESET

2009-08-11 23:58 . 2009-08-11 23:58 -------- d-----r- e:\documents and settings\LocalService\Favoritos

2009-08-11 23:56 . 2009-07-28 19:33 55656 ----a-w- e:\windows\system32\drivers\avgntflt.sys

2009-08-11 23:56 . 2009-08-11 23:56 -------- d-----w- e:\arquivos de programas\Avira

2009-08-10 10:49 . 2009-06-23 14:06 245408 ----a-w- e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\extensions\LogMeInClient@logmein.com\plugins\unicows.dll

2009-08-10 10:49 . 2009-04-05 17:26 8784 ----a-w- e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\extensions\LogMeInClient@logmein.com\plugins\ractrlkeyhook.dll

2009-08-10 10:49 . 2009-04-05 17:26 71248 ----a-w- e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\extensions\LogMeInClient@logmein.com\plugins\LMIProxyHelper.exe

2009-08-10 10:49 . 2009-02-19 14:38 2633728 ----a-w- e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll

2009-08-10 01:39 . 2009-08-13 02:06 -------- d-----w- E:\Caddy

2009-08-09 22:44 . 2009-08-09 22:44 -------- d-----w- e:\arquivos de programas\PFPortChecker

2009-08-09 22:30 . 1999-01-20 08:01 210032 ----a-w- e:\windows\system32\dbclient.dll

2009-08-09 22:30 . 2009-08-09 22:30 -------- d-----w- e:\arquivos de programas\Borland

2009-08-09 22:30 . 2009-08-09 22:30 -------- d-----w- e:\arquivos de programas\Arquivos comuns\Borland Shared

2009-08-09 22:30 . 1999-07-28 23:28 178688 ----a-w- e:\windows\system32\D5uninst.dll

2009-08-09 22:30 . 1998-10-10 08:01 36864 ----a-w- e:\windows\system32\IDUNINST.DLL

2009-08-09 22:29 . 1998-10-29 19:45 306688 ----a-w- e:\windows\IsUninst.exe

2009-08-09 22:27 . 2009-08-09 22:27 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\DAEMON Tools Pro

2009-08-09 22:27 . 2009-08-09 22:27 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\DAEMON Tools

2009-08-09 22:25 . 2009-08-09 22:25 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite

2009-08-09 22:24 . 2009-08-09 22:24 -------- d-----w- e:\arquivos de programas\DAEMON Tools Toolbar

2009-08-09 22:24 . 2009-08-09 22:24 -------- d-----w- e:\arquivos de programas\DAEMON Tools Lite

2009-08-09 14:28 . 2009-08-09 14:28 -------- d-----w- e:\arquivos de programas\GameVicio

2009-08-09 14:25 . 2008-10-16 17:06 268648 ----a-w- e:\windows\system32\mucltui.dll

2009-08-09 14:21 . 2009-08-09 14:21 -------- d-----w- e:\arquivos de programas\Microsoft Games

2009-08-09 02:04 . 2009-08-09 02:04 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\Nero

2009-08-09 02:01 . 2009-08-09 02:03 -------- d-----w- e:\arquivos de programas\Arquivos comuns\Nero

2009-08-09 02:01 . 2009-08-09 02:01 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\Nero

2009-08-09 02:01 . 2009-08-09 02:01 -------- d-----w- e:\arquivos de programas\Nero

2009-08-09 01:22 . 2009-08-09 01:22 -------- d-----w- e:\windows\ie8updates

2009-08-09 01:16 . 2009-08-09 01:16 -------- d-----w- e:\windows\system32\XPSViewer

2009-08-09 01:16 . 2009-08-09 01:16 -------- d-----w- e:\arquivos de programas\MSBuild

2009-08-09 01:16 . 2009-08-09 01:16 -------- d-----w- e:\arquivos de programas\Reference Assemblies

2009-08-09 01:16 . 2008-07-06 12:06 89088 -c----w- e:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-08-09 01:16 . 2008-07-06 12:06 575488 -c----w- e:\windows\system32\dllcache\xpsshhdr.dll

2009-08-09 01:16 . 2008-07-06 12:06 575488 ------w- e:\windows\system32\xpsshhdr.dll

2009-08-09 01:16 . 2008-07-06 12:06 1676288 -c----w- e:\windows\system32\dllcache\xpssvcs.dll

2009-08-09 01:16 . 2008-07-06 12:06 1676288 ------w- e:\windows\system32\xpssvcs.dll

2009-08-09 01:16 . 2008-07-06 12:06 117760 ------w- e:\windows\system32\prntvpt.dll

2009-08-09 01:16 . 2008-07-06 10:50 597504 -c----w- e:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-08-09 01:12 . 2009-08-09 01:12 -------- d-----w- e:\arquivos de programas\MSXML 4.0

2009-08-09 01:10 . 2008-04-14 10:00 221184 ----a-w- e:\windows\system32\wmpns.dll

2009-08-09 01:09 . 2008-04-13 14:45 26368 -c--a-w- e:\windows\system32\dllcache\usbstor.sys

2009-08-09 01:08 . 2009-08-09 01:08 717296 ----a-w- e:\windows\system32\drivers\sptd.sys

2009-08-09 01:08 . 2009-08-09 22:29 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\DAEMON Tools Lite

2009-08-09 00:56 . 2009-08-15 22:46 -------- d-----w- e:\documents and settings\Robson\Tracing

2009-08-09 00:54 . 2009-08-09 00:54 -------- d-----w- e:\arquivos de programas\Microsoft

2009-08-09 00:54 . 2009-08-09 00:54 -------- d-----w- e:\arquivos de programas\Windows Live SkyDrive

2009-08-09 00:53 . 2009-08-09 00:54 -------- d-----w- e:\arquivos de programas\Windows Live

2009-08-09 00:52 . 2009-08-09 00:52 -------- d-----w- e:\arquivos de programas\Arquivos comuns\Windows Live

2009-08-09 00:28 . 2009-08-09 00:28 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\Media Player Classic

2009-08-09 00:15 . 2009-08-09 00:15 -------- d-----w- e:\arquivos de programas\CCleaner

2009-08-09 00:05 . 2009-08-09 00:05 -------- d-----w- e:\arquivos de programas\Java

2009-08-09 00:05 . 2009-08-09 00:05 -------- d-----w- e:\arquivos de programas\Arquivos comuns\Java

2009-08-09 00:00 . 2008-06-14 17:34 272384 -c----w- e:\windows\system32\dllcache\bthport.sys

2009-08-09 00:00 . 2008-06-14 17:34 272384 ------w- e:\windows\system32\drivers\bthport.sys

2009-08-08 23:59 . 2009-02-09 11:25 2193280 -c----w- e:\windows\system32\dllcache\ntoskrnl.exe

2009-08-08 23:58 . 2009-07-03 16:59 55296 -c----w- e:\windows\system32\dllcache\msfeedsbs.dll

2009-08-08 23:58 . 2009-07-03 16:59 12800 -c----w- e:\windows\system32\dllcache\xpshims.dll

2009-08-08 23:58 . 2009-07-03 16:59 246272 -c----w- e:\windows\system32\dllcache\ieproxy.dll

2009-08-08 23:58 . 2009-07-03 16:59 1985536 -c----w- e:\windows\system32\dllcache\iertutil.dll

2009-08-08 23:58 . 2009-07-03 16:59 594432 -c----w- e:\windows\system32\dllcache\msfeeds.dll

2009-08-08 23:58 . 2009-08-08 23:58 -------- d-----w- e:\arquivos de programas\TaskSwitchXP

2009-08-08 23:58 . 2008-04-14 10:00 2790912 ----a-w- e:\windows\system32\XPize_Logon.exe

2009-08-08 23:56 . 2009-08-09 00:52 -------- d-----w- e:\documents and settings\Robson\Contacts

2009-08-08 23:55 . 2009-08-08 23:58 -------- d--h--w- e:\windows\XPize Darkside

2009-08-08 23:49 . 2008-04-14 10:00 26624 ----a-w- e:\documents and settings\LocalService\Dados de aplicativos\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

2009-08-08 23:46 . 2009-08-08 23:46 -------- d-----w- e:\arquivos de programas\Foxit Software

2009-08-08 23:45 . 2009-08-08 23:45 -------- d-----w- e:\arquivos de programas\CDisplay

2009-08-08 23:44 . 2009-08-08 23:44 165296 ----a-w- e:\documents and settings\Robson\Dados de aplicativos\IDM\idmmzcc2\components\idmmzcc.dll

2009-08-08 23:44 . 2009-08-16 02:50 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\DMCache

2009-08-08 23:44 . 2009-08-09 22:33 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\IDM

2009-08-08 23:44 . 2009-08-13 00:21 -------- d-----w- e:\arquivos de programas\Internet Download Manager

2009-08-08 23:37 . 2008-02-07 20:10 -------- d-sh--w- E:\ckis

2009-08-08 23:32 . 2009-08-11 23:55 -------- d-----w- e:\arquivos de programas\Kaspersky Lab

2009-08-08 23:31 . 2009-08-11 23:53 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab Setup Files

2009-08-08 23:30 . 2009-08-08 23:30 -------- d-----w- e:\arquivos de programas\uTorrent

2009-08-08 23:30 . 2009-08-09 22:45 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\uTorrent

2009-08-08 19:39 . 2009-08-08 19:44 -------- d-----w- e:\documents and settings\Robson\DoctorWeb

2009-08-08 19:18 . 2009-08-08 19:18 -------- d-----w- e:\windows\system32\Lang

2009-08-08 19:18 . 2009-08-08 19:18 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\ATI

2009-08-08 19:18 . 2009-08-08 19:18 -------- d-----w- e:\documents and settings\All Users\Dados de aplicativos\ATI

2009-08-08 19:17 . 2009-08-08 19:17 0 ----a-w- e:\windows\ativpsrm.bin

2009-08-08 19:11 . 2008-08-30 03:37 307200 ----a-r- e:\windows\system32\atiiiexx.dll

2009-08-08 19:11 . 2008-08-30 04:56 425984 ----a-r- e:\windows\system32\ATIDEMGX.dll

2009-08-08 19:11 . 2008-08-30 04:13 887724 ----a-r- e:\windows\system32\ativva6x.dat

2009-08-08 19:11 . 2008-08-30 04:13 3107788 ----a-r- e:\windows\system32\ativva5x.dat

2009-08-08 19:11 . 2008-08-30 04:13 3107788 ----a-r- e:\windows\system32\ativvaxx.dat

2009-08-08 19:11 . 2008-08-14 18:40 176214 ----a-r- e:\windows\system32\atiicdxx.dat

2009-08-08 19:11 . 2009-08-08 19:15 -------- d-----w- e:\arquivos de programas\ATI Technologies

2009-08-08 19:10 . 2009-08-08 23:49 -------- dc----w- e:\windows\system32\DRVSTORE

2009-08-08 19:10 . 2007-04-16 19:46 33792 ----a-w- e:\windows\system32\drivers\AmdPPM.sys

2009-08-08 19:10 . 2009-08-08 19:10 -------- d-----w- e:\arquivos de programas\AMD

2009-08-08 19:10 . 2008-09-25 13:51 115328 ----a-r- e:\windows\system32\drivers\Rtenicxp.sys

2009-08-08 19:10 . 2008-07-16 14:35 9728 ----a-r- e:\windows\system32\RtNicProp32.dll

2009-08-08 19:10 . 2009-08-08 19:10 -------- d-----w- e:\windows\OPTIONS

2009-08-08 19:10 . 2009-08-08 19:10 -------- d-----w- e:\documents and settings\Robson\Dados de aplicativos\InstallShield

2009-08-08 19:10 . 2006-08-01 07:02 49152 ------r- e:\windows\system32\ChCfg.exe

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-15 20:44 . 2008-04-14 10:00 79226 ----a-w- e:\windows\system32\perfc016.dat

2009-08-15 20:44 . 2008-04-14 10:00 468438 ----a-w- e:\windows\system32\perfh016.dat

2009-08-15 20:38 . 2009-08-13 01:42 147716 --sha-w- e:\windows\system32\drivers\fidbox.idx

2009-08-10 03:48 . 2009-08-08 18:52 86327 ----a-w- e:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-08-08 23:43 . 2009-08-08 23:43 0 ----a-w- e:\windows\nsreg.dat

2009-08-08 23:43 . 2009-08-08 23:43 -------- d-----w- e:\arquivos de programas\K-Lite Codec Pack

2009-08-08 19:09 . 2009-08-08 19:08 319488 ----a-w- e:\windows\HideWin.exe

2009-08-08 19:09 . 2009-08-08 19:09 -------- d-----w- e:\arquivos de programas\Realtek

2009-08-08 18:55 . 2009-08-08 18:55 -------- d-----w- e:\arquivos de programas\microsoft frontpage

2009-08-08 18:53 . 2009-08-08 18:53 -------- d-----w- e:\arquivos de programas\Windows Media Connect 2

2009-08-08 18:51 . 2009-08-08 18:51 -------- d-----w- e:\arquivos de programas\Serviços on-line

2009-08-08 18:50 . 2009-08-08 18:50 -------- d-----w- e:\arquivos de programas\Arquivos comuns\Serviços

2009-08-08 18:48 . 2009-08-08 18:48 21844 ----a-w- e:\windows\system32\emptyregdb.dat

2009-08-05 09:00 . 2008-04-14 10:00 205312 ----a-w- e:\windows\system32\mswebdvd.dll

2009-07-17 19:03 . 2008-04-14 10:00 58880 ----a-w- e:\windows\system32\atl.dll

2009-07-14 02:43 . 2006-10-18 22:47 286208 ----a-w- e:\windows\system32\wmpdxm.dll

2009-07-03 16:59 . 2008-04-14 10:00 915456 ----a-w- e:\windows\system32\wininet.dll

2009-06-16 14:39 . 2008-04-14 10:00 81920 ----a-w- e:\windows\system32\fontsub.dll

2009-06-16 14:39 . 2008-04-14 10:00 119808 ----a-w- e:\windows\system32\t2embed.dll

2009-06-15 10:44 . 2008-04-14 10:00 77824 ----a-w- e:\windows\system32\telnet.exe

2009-06-15 10:44 . 2008-04-14 10:00 81408 ----a-w- e:\windows\system32\tlntsess.exe

2009-06-10 14:14 . 2008-04-14 10:00 85504 ----a-w- e:\windows\system32\avifil32.dll

2009-06-10 12:21 . 2009-08-08 18:46 2066432 ----a-w- e:\windows\system32\mstscax.dll

2009-06-10 06:15 . 2008-04-14 10:00 132096 ----a-w- e:\windows\system32\wkssvc.dll

2009-06-03 19:10 . 2009-03-21 17:20 1295872 ----a-w- e:\windows\system32\quartz.dll

.

 

------- Sigcheck -------

 

[-] 2008-04-14 10:00 1697792 73772D4046638E7F59E75489E4CF911A e:\windows\explorer.exe

[-] 2008-04-14 10:00 1697792 73772D4046638E7F59E75489E4CF911A e:\windows\system32\dllcache\explorer.exe

[7] 2008-04-14 10:00 1035776 064EC7FF5F58B928C3E119402977FA6D e:\windows\XPize Darkside\Backup\explorer.exe

 

[-] 2008-04-14 10:00 30208 855155452D91BDDB42633590640B5744 e:\windows\system32\ctfmon.exe

[-] 2008-04-14 10:00 30208 855155452D91BDDB42633590640B5744 e:\windows\system32\dllcache\ctfmon.exe

[7] 2008-04-14 10:00 15360 4E486ADFE3A0B9ED0EB0639902E9F64F e:\windows\XPize Darkside\Backup\ctfmon.exe

 

[-] 2008-04-14 10:00 832000 6337C1A60A1384230BC314FBCB123C21 e:\windows\system32\comres.dll

[-] 2008-04-14 10:00 832000 6337C1A60A1384230BC314FBCB123C21 e:\windows\system32\dllcache\comres.dll

[7] 2008-04-14 10:00 821760 D3F8E8DBE93A80440CAC78B305B40A67 e:\windows\XPize Darkside\Backup\comres.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IDMan"="e:\arquivos de programas\Internet Download Manager\IDMan.exe" [2009-08-09 2745776]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="e:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

"Easy-PrintToolBox"="e:\arquivos de programas\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2006-10-17 398944]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 30208]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00

 

[HKLM\~\startupfolder\E:^Documents and Settings^Robson^Menu Iniciar^Programas^Inicializar^is-32GM2.lnk]

path=e:\documents and settings\Robson\Menu Iniciar\Programas\Inicializar\is-32GM2.lnk

backup=e:\windows\pss\is-32GM2.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"e:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"e:\\Documents and Settings\\All Users\\Dados de aplicativos\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Brazilian\\setup.exe"=

"e:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"e:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R1 is-32GM2drv;is-32GM2drv;e:\windows\system32\drivers\23831203.sys [11/08/2009 23:31 148496]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [12/08/2009 22:43 108289]

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"e:\windows\system32\rundll32.exe" "e:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-08-16 e:\windows\Tasks\User_Feed_Synchronization-{035A2954-48A6-439A-8021-AF57B3E565C4}.job

- e:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

IE: Download all links with IDM - e:\arquivos de programas\Internet Download Manager\IEGetAll.htm

IE: Download FLV video content with IDM - e:\arquivos de programas\Internet Download Manager\IEGetVL.htm

IE: Download with IDM - e:\arquivos de programas\Internet Download Manager\IEExt.htm

IE: E&xportar para o Microsoft Excel - e:\arquiv~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

IE: Easy-WebPrint Add To Print List - e:\arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html

IE: Easy-WebPrint High Speed Print - e:\arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html

IE: Easy-WebPrint Preview - e:\arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html

IE: Easy-WebPrint Print - e:\arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

LSP: e:\windows\system32\idmmbc.dll

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

FF - ProfilePath - e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/

FF - component: e:\documents and settings\Robson\Dados de aplicativos\IDM\idmmzcc2\components\idmmzcc.dll

FF - plugin: e:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: e:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: e:\documents and settings\Robson\Dados de aplicativos\Mozilla\Firefox\Profiles\6sm7i2hy.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll

 

---- FIREFOX POLICIES ----

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);

e:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);

e:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);

e:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-15 23:50

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]

"Enabled"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]

@="e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]

@Denied: (A 2) (Everyone)

@="IFlashBroker3"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(784)

e:\windows\system32\Ati2evxx.dll

e:\windows\system32\cscui.dll

 

- - - - - - - > 'lsass.exe'(840)

e:\windows\system32\idmmbc.dll

 

- - - - - - - > 'explorer.exe'(1520)

e:\windows\system32\WININET.dll

e:\windows\System32\cscui.dll

e:\arquiv~1\WINDOW~2\wmpband.dll

e:\windows\system32\NETSHELL.dll

e:\windows\system32\credui.dll

e:\windows\system32\webcheck.dll

e:\windows\system32\WPDShServiceObj.dll

e:\windows\system32\PortableDeviceTypes.dll

e:\windows\system32\PortableDeviceApi.dll

.

Tempo para conclusão: 2009-08-16 23:51

ComboFix-quarantined-files.txt 2009-08-16 02:51

 

Pré-execução: 6 pasta(s) 29,360,857,088 bytes disponíveis

Pós execução: 6 pasta(s) 30,380,806,144 bytes disponíveis

 

329 --- E O F --- 2009-08-15 09:39

 

 

Log Hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:54:21, on 15/08/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

E:\WINDOWS\System32\smss.exe

E:\WINDOWS\system32\winlogon.exe

E:\WINDOWS\system32\services.exe

E:\WINDOWS\system32\lsass.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\svchost.exe

E:\WINDOWS\System32\svchost.exe

E:\WINDOWS\system32\Ati2evxx.exe

E:\WINDOWS\system32\spoolsv.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

E:\Arquivos de programas\Internet Download Manager\IDMan.exe

E:\WINDOWS\system32\ctfmon.exe

E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe

E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

E:\WINDOWS\explorer.exe

E:\Documents and Settings\Robson\Desktop\Ferramentas Sality\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - E:\Arquivos de programas\Canon\Easy-WebPrint\EWPBrowseLoader.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Arquivos de programas\DAEMON Tools Toolbar\DTToolbar.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll

O4 - HKLM\..\Run: [avgnt] "E:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [Easy-PrintToolBox] E:\Arquivos de programas\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon

O4 - HKCU\..\Run: [iDMan] E:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Download all links with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - E:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - E:\Arquivos de programas\Internet Download Manager\IEExt.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://E:\ARQUIV~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://E:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\ARQUIV~1\MICROS~4\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1249779356781

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - E:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - E:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

 

--

End of file - 6065 bytes

 

Obrigado pela paciência e pelo tempo quem dispõe pra me ajudar!!!

Abraço!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Reivax

 

<@> Vá em Iniciar --> Executar --> Digite ou cole:

 

"%userprofile%\Desktop\combofix" /u

 

<@> Clique OK.

<><><><><><><><><>

<@> Desinstale o AVPTool.

<@> Feche todos os programas ou navegador.

<@> Execute o arquivo unins000.exe,que está na pasta onde se encontra o instalador.

<@> O computador dará reboot --> Aguarde!

<><><><><><><><><>

<@> Baixe: < ATF.gif > ( ...by Atribune )

<@> Salve-o no Desktop!

<@> Reinicie o computador,em Modo de Segurança!

<@> Clique em ATF-Cleaner.exe

<@> Em "Select Files To Delete",marque Select All.

<@> Clique em Empty Selected.

<@> Na janela Done Cleaning,dê o OK --> Exit

 

<@> Atenção: Se utiliza o Firefox:

 

* No topo,clique em Firefox e escolha: Select All --> Clique em Empty Selected.

 

<@> Atenção: Se utiliza o Opera:

 

* No topo,clique em Opera e escolha: Select All --> Clique em Empty Selected.

<><><><><><><><><>

<!> Seus logs estão limpos! :bye:

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Muitissimo obrigado, DigRam!!!

Em poucos dias você resolveu um problema que me atormentava a quase um mês.

Esse Fórum realmente é muito bom!!! Devia ter procurado vcs antes.

Abraços e tudo de bom!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.