Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
Olá, pessoal estou novamente precisando da ajuda de vcs!!! Não sei mais o que fazer!! Grato Altair!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44:23, on 27/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
C:\Arquivos de programas\D-Tools\daemon.exe
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
C:\Arquivos de programas\QuickTime\QTTask.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\WINDOWS\vsnpstd.exe
C:\ARQUIV~1\AVG\AVG8\avgtray.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\Arquivos de programas\Skype\Phone\Skype.exe
C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\twumk.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\ARQUIV~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Altair.HOME\Configurações locais\Temporary Internet Files\Content.IE5\TIGEHO6T\HiJackThis[2].exe
C:\WINDOWS\system32\HPZipm12.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXNHWQK.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: {b2755231-0b14-6dc9-be34-bedbe901145c} - {c541109e-bdeb-43eb-9cd6-41b01325572b} - C:\WINDOWS\system32\tefmey.dll
O2 - BHO: (no name) - {C7EF6252-DF2E-4622-B55A-D25E0736DFF3} - C:\WINDOWS\system32\cbXOFvUK.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [84af38f1] rundll32.exe "C:\WINDOWS\system32\swuwcsdo.dll",b
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Sumário do OneNote.onetoc2
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\arquiv~1\bandoo\bndhook.dll,avgrsstx.dll tefmey.dll
O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll (file missing)
O20 - Winlogon Notify: cbXNHWQK - C:\WINDOWS\SYSTEM32\cbXNHWQK.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
--
End of file - 12214 bytes
Boa Tarde! altasena
<@> Baixe: < ComboFix.exe > ( ...by sUBs )
<@> Salve-o no Desktop!
<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )
<@> Feche todas as janelas e execute a ferramenta!
<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!
<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!
<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.<!> Salve-a no desktop,renomeada como: Kombo.exe
<!> Ps: Nomeie durante o salvamento,e não após salvá-la!
<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link!
<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!
<!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.
<@> Abrir-se-á a janela Auto Scan. --> Aguarde!
<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.
<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!
<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!
<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!
----------------------
<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.
Abraços!
Olá amigo fiz o que você pediu!!! Muito grato !! UM abraço!
ComboFix 08-12-28.01 - Altair 2008-12-28 18:16:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.452 [GMT -2:00]
Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free On-access scanning disabled (Outdated)
* Criado um novo ponto de restauro
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\arquivos de programas\Antivirus 2009
c:\arquivos de programas\Antivirus 2009\av2009.exe
c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\pi.exe
c:\windows\system32\amjgjc.dll
c:\windows\system32\Cache
c:\windows\system32\cbXNHWQK.dll
c:\windows\system32\cbXOFvUK.dll
c:\windows\system32\cmifrr.dll
c:\windows\system32\efcBrOhh.dll
c:\windows\system32\eijscg.dll
c:\windows\system32\erkfykas.dll
c:\windows\system32\fluqfwcb.dll
c:\windows\system32\gbiehuni.dll , GBIEHCEF.DLL , gbiehabn.dll, GBIEHABN.DLL, SCPSSSH2.DLL
c:\windows\system32\gegsvdwq.dll
c:\windows\system32\ieupdates.exe
c:\windows\system32\Implode.dll
c:\windows\system32\jmgnlsib.dll
c:\windows\system32\KUvFOXbc.ini
c:\windows\system32\KUvFOXbc.ini2
c:\windows\system32\odscwuws.ini
c:\windows\system32\ogkdymgg.ini
c:\windows\system32\qwdvsgeg.ini
c:\windows\system32\tefmey.dll
c:\windows\system32\xywgaeve.dll
----- BITS: Sites possivelmente infetados -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GBPSV
-------\Service_GbpSv
(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-28 ))))))))))))))))))))))))))))
.
2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft
2008-12-27 12:26 . 2008-12-27 12:25 401,720 --a------ C:\HiJackThis.exe
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon
2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll
2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-22 18:09 . 2008-12-24 19:49 <DIR> d-------- c:\windows\system32\Prefetchxs
2008-12-22 18:09 . 2008-12-28 14:28 <DIR> d-------- c:\windows\system32\CatRoot_3
2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe
2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe
2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm
2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm
2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao
2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD
2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX
2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL
2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL
2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386
2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386
2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI
2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY
2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV
2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE
2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL
2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL
2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL
2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games
2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl
2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm
2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm
2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft
2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft
2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule
2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin
2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express
2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java
2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help
2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype
2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist
2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin
2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8
2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2
2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe
2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed
2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!
2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger
2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller
2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live
2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live
2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector
2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft
2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live
2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr
2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe
2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys
2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys
2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys
2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys
2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys
2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys
2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys
2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys
2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys
2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll
2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll
2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll
2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll
2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]
"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]
"twumk.exe"="c:\windows\system32\twumk.exe" [2008-12-22 478064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]
"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]
"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\
Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
Sum rio do OneNote.onetoc2 [2008-04-15 3656]
c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\
ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]
Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\Valve\\hlds.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=
"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=
"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=
"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]
R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []
S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
2008-12-28 c:\windows\Tasks\okvtgigf.job
.
BHO-{4c956910-c391-4da7-8b81-3a2feefd6a37} - c:\windows\system32\amjgjc.dll
BHO-{C025DEA7-A297-406D-9FA7-A62C66973A3D} - c:\windows\system32\cbXOFvUK.dll
HKCU-Run-Nero PhotoShow Media Manager - c:\arquiv~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
HKCU-Run-ares - c:\arquivos de programas\Ares\Ares.exe
HKLM-Run-WinampAgent - c:\arquivos de programas\Winamp\winampa.exe
HKLM-Run-NWEReboot - (no file)
ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399007} - c:\arquiv~1\GbPlugin\gbiehabn.dll
Notify- GbPluginAbn - c:\arquiv~1\GbPlugin\gbiehabn.dll
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.globo.com.br/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}
hxxp://www.powerchallenge.com/applet/PowerLoader.cab
c:\windows\Downloaded Program Files\PowerLoader.inf
O16 -: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab
c:\windows\Downloaded Program Files\GbPluginABN.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 18:24:53
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
c:\windows\system32\Ati2evxx.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe
c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe
c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe
c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\arquivos de programas\Bonjour\mDNSResponder.exe
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\searchindexer.exe
c:\arquivos de programas\AVG\AVG8\avgrsx.exe
c:\arquivos de programas\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Tempo para conclusão: 2008-12-28 18:29:36 - Máquina reiniciou [Altair]
ComboFix-quarantined-files.txt 2008-12-28 20:29:11
Pré-execução: 41 pasta(s) 19.734.994.944 bytes disponíveis
Pós execução: 41 pasta(s) 20,452,155,392 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
276 --- E O F --- 2008-12-19 21:40:20
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:35:05, on 28/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\D-Tools\daemon.exe
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
C:\Arquivos de programas\QuickTime\QTTask.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\ARQUIV~1\AVG\AVG8\avgtray.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\Arquivos de programas\Skype\Phone\Skype.exe
C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\twumk.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\ARQUIV~1\AVG\AVG8\avgrsx.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Altair.HOME\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Sumário do OneNote.onetoc2
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
--
End of file - 10892 bytes
Um abraço!!! Te aguardo!
Boa Noite! altasena
<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.
<@> Salve-o,no Desktop,com o nome: CFScript.txt
>
Files::c:\windows\system32\jkkjIbxy.dll
c:\windows\system32\twumk.exe
c:\windows\system32\jumps.exe
c:\windows\Tasks\okvtgigf.job
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"twumk.exe"=-
Folder::
c:\windows\system32\Prefetchxs
c:\windows\system32\CatRoot_3
<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.
<@> Veja a demonstração!
/applications/core/interface/imageproxy/imageproxy.php?img=http://farm4.static.flickr.com/3028/2872959479_997d4500c4_o.gif&key=5df91a69abacb5902724f70d14994f3bf5ba8d87bf300cea4c6fd8c885940cf0" alt="2872959479_997d4500c4_o.gif" />
<@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix.
<@> Ps: Faça o arraste,até surgir essa solicitação! ( janela )
<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.
Abraços!
Boa Noite! altasena
<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.
<@> Salve-o,no Desktop,com o nome: CFScript.txt
>
Files::c:\windows\system32\jkkjIbxy.dll
c:\windows\system32\twumk.exe
c:\windows\system32\jumps.exe
c:\windows\Tasks\okvtgigf.job
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"twumk.exe"=-
Folder::
c:\windows\system32\Prefetchxs
c:\windows\system32\CatRoot_3
<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.
<@> Veja a demonstração!
/applications/core/interface/imageproxy/imageproxy.php?img=http://farm4.static.flickr.com/3028/2872959479_997d4500c4_o.gif&key=5df91a69abacb5902724f70d14994f3bf5ba8d87bf300cea4c6fd8c885940cf0" alt="2872959479_997d4500c4_o.gif" />
<@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix.
<@> Ps: Faça o arraste,até surgir essa solicitação! ( janela )
<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.
Abraços!
Olá DigRam, desde já quero lhe agradecer a atenção!! Abaixo posto o que você pede!! Um abraço!! Altair!!
ComboFix 08-12-28.01 - Altair 2008-12-29 15:03:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.473 [GMT -2:00]
Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt
AV: AVG Anti-Virus Free On-access scanning disabled (Outdated)
* Criado um novo ponto de restauro
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\CatRoot_3
c:\windows\system32\CatRoot_3\edb.chk
c:\windows\system32\CatRoot_3\TimeStemp
c:\windows\system32\Prefetchxs
c:\windows\system32\Prefetchxs\euzinho.rifle@gmail.com
c:\windows\system32\Prefetchxs\paulaa1968@gmail.com
c:\windows\system32\Prefetchxs\ruan1995@globo.com
c:\windows\system32\Prefetchxs\uid=10073878566382367689
c:\windows\system32\Prefetchxs\uid=10093758571540450781
c:\windows\system32\Prefetchxs\uid=10318076534728906346
c:\windows\system32\Prefetchxs\uid=10376206228721919992
c:\windows\system32\Prefetchxs\uid=1037826073188409423
c:\windows\system32\Prefetchxs\uid=1051980406115856981
c:\windows\system32\Prefetchxs\uid=1055921848046133103
c:\windows\system32\Prefetchxs\uid=10721037389106661121
c:\windows\system32\Prefetchxs\uid=10728788135134822204
c:\windows\system32\Prefetchxs\uid=10753374287914678364
c:\windows\system32\Prefetchxs\uid=10877353640376038936
c:\windows\system32\Prefetchxs\uid=10918111566442582744
c:\windows\system32\Prefetchxs\uid=10950601282798126008
c:\windows\system32\Prefetchxs\uid=10956919542720223358
c:\windows\system32\Prefetchxs\uid=11016391003574553870
c:\windows\system32\Prefetchxs\uid=11020678768250863806
c:\windows\system32\Prefetchxs\uid=11036436431735649852
c:\windows\system32\Prefetchxs\uid=11199477647029985133
c:\windows\system32\Prefetchxs\uid=11262391093952789965
c:\windows\system32\Prefetchxs\uid=11280594305607972052
c:\windows\system32\Prefetchxs\uid=11358131272357950205
c:\windows\system32\Prefetchxs\uid=11443970396258807410
c:\windows\system32\Prefetchxs\uid=11484878243886469514
c:\windows\system32\Prefetchxs\uid=11571005024792751819
c:\windows\system32\Prefetchxs\uid=11745451256050003900
c:\windows\system32\Prefetchxs\uid=11749763375533333310
c:\windows\system32\Prefetchxs\uid=11797652174971255140
c:\windows\system32\Prefetchxs\uid=11813171764432298374
c:\windows\system32\Prefetchxs\uid=11830588709266355629
c:\windows\system32\Prefetchxs\uid=11839414164978064914
c:\windows\system32\Prefetchxs\uid=11874960705434815573
c:\windows\system32\Prefetchxs\uid=11916729235859937679
c:\windows\system32\Prefetchxs\uid=12010613158930182566
c:\windows\system32\Prefetchxs\uid=1205304755662828404
c:\windows\system32\Prefetchxs\uid=12096663257902347545
c:\windows\system32\Prefetchxs\uid=1213353535175675734
c:\windows\system32\Prefetchxs\uid=12199251504948993038
c:\windows\system32\Prefetchxs\uid=12201939323992660801
c:\windows\system32\Prefetchxs\uid=12235547070827549821
c:\windows\system32\Prefetchxs\uid=12244952592532755868
c:\windows\system32\Prefetchxs\uid=12270485368898448011
c:\windows\system32\Prefetchxs\uid=12284256882460730488
c:\windows\system32\Prefetchxs\uid=12286974763530794004
c:\windows\system32\Prefetchxs\uid=12297297778612910959
c:\windows\system32\Prefetchxs\uid=12343713330503194813
c:\windows\system32\Prefetchxs\uid=12369969336459853282
c:\windows\system32\Prefetchxs\uid=12461194792458146462
c:\windows\system32\Prefetchxs\uid=12593241567072277950
c:\windows\system32\Prefetchxs\uid=12646740765483213484
c:\windows\system32\Prefetchxs\uid=12656349530278003562
c:\windows\system32\Prefetchxs\uid=12759868615278858725
c:\windows\system32\Prefetchxs\uid=12785222156104882519
c:\windows\system32\Prefetchxs\uid=12926907381779125893
c:\windows\system32\Prefetchxs\uid=12979005293491328285
c:\windows\system32\Prefetchxs\uid=13004242084970453072
c:\windows\system32\Prefetchxs\uid=13248116689144518380
c:\windows\system32\Prefetchxs\uid=13319763956901222665
c:\windows\system32\Prefetchxs\uid=13408001446782127852
c:\windows\system32\Prefetchxs\uid=13575821045996628990
c:\windows\system32\Prefetchxs\uid=13578932015319581870
c:\windows\system32\Prefetchxs\uid=13586797816265553385
c:\windows\system32\Prefetchxs\uid=13618910123000198975
c:\windows\system32\Prefetchxs\uid=1368406374434022710
c:\windows\system32\Prefetchxs\uid=13708106737354049354
c:\windows\system32\Prefetchxs\uid=14033681777567248755
c:\windows\system32\Prefetchxs\uid=14154274315834407116
c:\windows\system32\Prefetchxs\uid=14345836480146051042
c:\windows\system32\Prefetchxs\uid=14391558695245912892
c:\windows\system32\Prefetchxs\uid=14397424949232815178
c:\windows\system32\Prefetchxs\uid=14517859927662358394
c:\windows\system32\Prefetchxs\uid=14621169681292567846
c:\windows\system32\Prefetchxs\uid=14758020743406156925
c:\windows\system32\Prefetchxs\uid=14758331840854850809
c:\windows\system32\Prefetchxs\uid=14788114409140444079
c:\windows\system32\Prefetchxs\uid=14836681653344905388
c:\windows\system32\Prefetchxs\uid=14837581274728878233
c:\windows\system32\Prefetchxs\uid=15099378276452038829
c:\windows\system32\Prefetchxs\uid=15139606282167918330
c:\windows\system32\Prefetchxs\uid=15227835053411261543
c:\windows\system32\Prefetchxs\uid=15319911708974642101
c:\windows\system32\Prefetchxs\uid=15333671415825547775
c:\windows\system32\Prefetchxs\uid=15443312399709093574
c:\windows\system32\Prefetchxs\uid=15591697453809545723
c:\windows\system32\Prefetchxs\uid=15610140654977286660
c:\windows\system32\Prefetchxs\uid=15631772112373874146
c:\windows\system32\Prefetchxs\uid=15650598175424752713
c:\windows\system32\Prefetchxs\uid=1572516361401864176
c:\windows\system32\Prefetchxs\uid=15779539878669013717
c:\windows\system32\Prefetchxs\uid=15986415852703340375
c:\windows\system32\Prefetchxs\uid=16045898512434157296
c:\windows\system32\Prefetchxs\uid=16089154660527986624
c:\windows\system32\Prefetchxs\uid=16092442136748431046
c:\windows\system32\Prefetchxs\uid=16098201787268449689
c:\windows\system32\Prefetchxs\uid=16203958252952290316
c:\windows\system32\Prefetchxs\uid=16459392728856169014
c:\windows\system32\Prefetchxs\uid=16537765680623062569
c:\windows\system32\Prefetchxs\uid=16541748872158314859
c:\windows\system32\Prefetchxs\uid=16752773174491741816
c:\windows\system32\Prefetchxs\uid=16815558688181237951
c:\windows\system32\Prefetchxs\uid=16849388344701797543
c:\windows\system32\Prefetchxs\uid=1695625355352171933
c:\windows\system32\Prefetchxs\uid=17007434935122131458
c:\windows\system32\Prefetchxs\uid=17026999308948241214
c:\windows\system32\Prefetchxs\uid=17087965737943822296
c:\windows\system32\Prefetchxs\uid=17104061258941128375
c:\windows\system32\Prefetchxs\uid=17149192978996363067
c:\windows\system32\Prefetchxs\uid=17283461571260786246
c:\windows\system32\Prefetchxs\uid=17371238549052410729
c:\windows\system32\Prefetchxs\uid=17409921102459049983
c:\windows\system32\Prefetchxs\uid=17453284220659407758
c:\windows\system32\Prefetchxs\uid=17470466962151896115
c:\windows\system32\Prefetchxs\uid=17572219506996396869
c:\windows\system32\Prefetchxs\uid=17594411983989541530
c:\windows\system32\Prefetchxs\uid=17611956217266136712
c:\windows\system32\Prefetchxs\uid=17630906075949467253
c:\windows\system32\Prefetchxs\uid=17725963066297716235
c:\windows\system32\Prefetchxs\uid=17774204340009323036
c:\windows\system32\Prefetchxs\uid=17832459778107465151
c:\windows\system32\Prefetchxs\uid=17840185582919609449
c:\windows\system32\Prefetchxs\uid=18033996669212227995
c:\windows\system32\Prefetchxs\uid=18092516642475707604
c:\windows\system32\Prefetchxs\uid=18094354364943314380
c:\windows\system32\Prefetchxs\uid=18135830265463537323
c:\windows\system32\Prefetchxs\uid=18164650581172002042
c:\windows\system32\Prefetchxs\uid=18181004936305455425
c:\windows\system32\Prefetchxs\uid=18264835970928276117
c:\windows\system32\Prefetchxs\uid=18363885718008299196
c:\windows\system32\Prefetchxs\uid=1857279662614826226
c:\windows\system32\Prefetchxs\uid=2130968248785583708
c:\windows\system32\Prefetchxs\uid=216482689323116115
c:\windows\system32\Prefetchxs\uid=2399042952424672621
c:\windows\system32\Prefetchxs\uid=2476615765253753718
c:\windows\system32\Prefetchxs\uid=2678703094997445236
c:\windows\system32\Prefetchxs\uid=2787885661403679677
c:\windows\system32\Prefetchxs\uid=2803487434741902881
c:\windows\system32\Prefetchxs\uid=2833342090580429834
c:\windows\system32\Prefetchxs\uid=2858862162027413768
c:\windows\system32\Prefetchxs\uid=2864067739441436794
c:\windows\system32\Prefetchxs\uid=2899585598435687001
c:\windows\system32\Prefetchxs\uid=2969901922060825967
c:\windows\system32\Prefetchxs\uid=3043016122715034243
c:\windows\system32\Prefetchxs\uid=3063404058926592050
c:\windows\system32\Prefetchxs\uid=3098975966941828863
c:\windows\system32\Prefetchxs\uid=3144168639184154694
c:\windows\system32\Prefetchxs\uid=3285559606333028835
c:\windows\system32\Prefetchxs\uid=3347575097387378572
c:\windows\system32\Prefetchxs\uid=355052566428888648
c:\windows\system32\Prefetchxs\uid=3566026570809483114
c:\windows\system32\Prefetchxs\uid=3624645770535521750
c:\windows\system32\Prefetchxs\uid=3710671789055322065
c:\windows\system32\Prefetchxs\uid=3753167318627965364
c:\windows\system32\Prefetchxs\uid=3854783922219264407
c:\windows\system32\Prefetchxs\uid=3902194959107196915
c:\windows\system32\Prefetchxs\uid=3918931612567757498
c:\windows\system32\Prefetchxs\uid=4014980926181728886
c:\windows\system32\Prefetchxs\uid=4022627279217337851
c:\windows\system32\Prefetchxs\uid=4056639853220268424
c:\windows\system32\Prefetchxs\uid=4093857205928726547
c:\windows\system32\Prefetchxs\uid=4167717884913735448
c:\windows\system32\Prefetchxs\uid=4242227188048141702
c:\windows\system32\Prefetchxs\uid=4243016045489330693
c:\windows\system32\Prefetchxs\uid=4422922577410055706
c:\windows\system32\Prefetchxs\uid=4510223448302285363
c:\windows\system32\Prefetchxs\uid=4545892322993955079
c:\windows\system32\Prefetchxs\uid=4731658822392730112
c:\windows\system32\Prefetchxs\uid=4853723186040484838
c:\windows\system32\Prefetchxs\uid=5143566996177373149
c:\windows\system32\Prefetchxs\uid=5163557574071812023
c:\windows\system32\Prefetchxs\uid=5186846842581322570
c:\windows\system32\Prefetchxs\uid=520169805547905569
c:\windows\system32\Prefetchxs\uid=5259498052295135294
c:\windows\system32\Prefetchxs\uid=5408626071421062022
c:\windows\system32\Prefetchxs\uid=5449234284126105896
c:\windows\system32\Prefetchxs\uid=5467250980643862831
c:\windows\system32\Prefetchxs\uid=549321652507702352
c:\windows\system32\Prefetchxs\uid=5521397596668568035
c:\windows\system32\Prefetchxs\uid=5629875623574554170
c:\windows\system32\Prefetchxs\uid=583320514511203722
c:\windows\system32\Prefetchxs\uid=5845373145314677688
c:\windows\system32\Prefetchxs\uid=5910815741967626367
c:\windows\system32\Prefetchxs\uid=591289038084055870
c:\windows\system32\Prefetchxs\uid=5939472925834161514
c:\windows\system32\Prefetchxs\uid=6010620053536081532
c:\windows\system32\Prefetchxs\uid=6187802616734630159
c:\windows\system32\Prefetchxs\uid=6392425348096693941
c:\windows\system32\Prefetchxs\uid=6479605176319772615
c:\windows\system32\Prefetchxs\uid=64885662926306312
c:\windows\system32\Prefetchxs\uid=6516552060363860497
c:\windows\system32\Prefetchxs\uid=6597658775284147558
c:\windows\system32\Prefetchxs\uid=659792742321439189
c:\windows\system32\Prefetchxs\uid=6640759388682189402
c:\windows\system32\Prefetchxs\uid=6678949085630121456
c:\windows\system32\Prefetchxs\uid=6696289611759756857
c:\windows\system32\Prefetchxs\uid=6708085563630436084
c:\windows\system32\Prefetchxs\uid=6769778535346891805
c:\windows\system32\Prefetchxs\uid=6832904718025177134
c:\windows\system32\Prefetchxs\uid=6884213501064563330
c:\windows\system32\Prefetchxs\uid=6976390535963747801
c:\windows\system32\Prefetchxs\uid=7183318946386091091
c:\windows\system32\Prefetchxs\uid=7247856382081566212
c:\windows\system32\Prefetchxs\uid=727995930909720907
c:\windows\system32\Prefetchxs\uid=7417978813562875197
c:\windows\system32\Prefetchxs\uid=7447859970100521944
c:\windows\system32\Prefetchxs\uid=7479574837620946000
c:\windows\system32\Prefetchxs\uid=7547919322998424447
c:\windows\system32\Prefetchxs\uid=7649585037296408922
c:\windows\system32\Prefetchxs\uid=7689447059690104835
c:\windows\system32\Prefetchxs\uid=7713853776959622769
c:\windows\system32\Prefetchxs\uid=7743603295177440899
c:\windows\system32\Prefetchxs\uid=7899684907037879963
c:\windows\system32\Prefetchxs\uid=7916152784990654420
c:\windows\system32\Prefetchxs\uid=798948828211733739
c:\windows\system32\Prefetchxs\uid=8001925070752697414
c:\windows\system32\Prefetchxs\uid=8059680416395077494
c:\windows\system32\Prefetchxs\uid=8120382425132161521
c:\windows\system32\Prefetchxs\uid=8135391379948449263
c:\windows\system32\Prefetchxs\uid=8175479418631985633
c:\windows\system32\Prefetchxs\uid=8177403549451759729
c:\windows\system32\Prefetchxs\uid=8205100703250754696
c:\windows\system32\Prefetchxs\uid=82434288492434776
c:\windows\system32\Prefetchxs\uid=8271340054378194125
c:\windows\system32\Prefetchxs\uid=8316336335839885650
c:\windows\system32\Prefetchxs\uid=8335288639516210566
c:\windows\system32\Prefetchxs\uid=8357388538391273941
c:\windows\system32\Prefetchxs\uid=8466853291579384225
c:\windows\system32\Prefetchxs\uid=8484094847063476271
c:\windows\system32\Prefetchxs\uid=8513840659578531302
c:\windows\system32\Prefetchxs\uid=8551955857254593212
c:\windows\system32\Prefetchxs\uid=870702175526869565
c:\windows\system32\Prefetchxs\uid=8765030040314685288
c:\windows\system32\Prefetchxs\uid=8801447007258465991
c:\windows\system32\Prefetchxs\uid=8821179526365770801
c:\windows\system32\Prefetchxs\uid=8858581735769172969
c:\windows\system32\Prefetchxs\uid=8928734603918484442
c:\windows\system32\Prefetchxs\uid=9004109795273719271
c:\windows\system32\Prefetchxs\uid=9214622304138349084
c:\windows\system32\Prefetchxs\uid=9215459002929603959
c:\windows\system32\Prefetchxs\uid=9254453388885949959
c:\windows\system32\Prefetchxs\uid=9313112675929779222
c:\windows\system32\Prefetchxs\uid=9381675108527649814
c:\windows\system32\Prefetchxs\uid=9384431913903158521
c:\windows\system32\Prefetchxs\uid=9554252579906789770
c:\windows\system32\Prefetchxs\uid=9605882217387355497
c:\windows\system32\Prefetchxs\uid=961808341291469650
c:\windows\system32\Prefetchxs\uid=9635350036978112307
c:\windows\system32\Prefetchxs\uid=9663001314758677592
c:\windows\system32\Prefetchxs\uid=9664000623637542800
c:\windows\system32\Prefetchxs\uid=980085587220775764
c:\windows\system32\Prefetchxs\uid=9853152139065298060
c:\windows\system32\Prefetchxs\uid=9951860571554449712
c:\windows\system32\Prefetchxs\uid=9953917749837968090
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-29 ))))))))))))))))))))))))))))
.
2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe
2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon
2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll
2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe
2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe
2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm
2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm
2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao
2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD
2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX
2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL
2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL
2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386
2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386
2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI
2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY
2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV
2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE
2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL
2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL
2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL
2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games
2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl
2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm
2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm
2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft
2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft
2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule
2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin
2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express
2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java
2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help
2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype
2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist
2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin
2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8
2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2
2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe
2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed
2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!
2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger
2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller
2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live
2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live
2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector
2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft
2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live
2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr
2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe
2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys
2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys
2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys
2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys
2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys
2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys
2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys
2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys
2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys
2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll
2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll
2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll
2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll
2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-29 17:12:11 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_9d4.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]
"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]
"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]
"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\
Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
Sum rio do OneNote.onetoc2 [2008-04-15 3656]
c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\
ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]
Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\Valve\\hlds.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=
"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=
"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=
"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]
R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []
S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
2008-12-29 c:\windows\Tasks\okvtgigf.job
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.globo.com.br/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147
c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}
hxxp://www.powerchallenge.com/applet/PowerLoader.cab
c:\windows\Downloaded Program Files\PowerLoader.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 15:12:22
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
c:\windows\system32\Ati2evxx.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe
c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe
c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe
c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\arquivos de programas\Bonjour\mDNSResponder.exe
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\searchindexer.exe
c:\arquivos de programas\AVG\AVG8\avgrsx.exe
c:\arquivos de programas\iPod\bin\iPodService.exe
.
**************************************************************************
.
Tempo para conclusão: 2008-12-29 15:18:17 - Máquina reiniciou
ComboFix-quarantined-files.txt 2008-12-29 17:17:53
ComboFix2.txt 2008-12-28 20:29:42
Pré-execução: 41 pasta(s) 20.478.480.384 bytes disponíveis
Pós execução: 41 pasta(s) 20,421,996,544 bytes disponíveis
488 --- E O F --- 2008-12-19 21:40:20
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:28:31, on 29/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Arquivos de programas\D-Tools\daemon.exe
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
C:\Arquivos de programas\QuickTime\QTTask.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\ARQUIV~1\AVG\AVG8\avgtray.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\Arquivos de programas\Skype\Phone\Skype.exe
C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe
C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
C:\Arquivos de programas\Bonjour\mDNSResponder.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\ARQUIV~1\AVG\AVG8\avgrsx.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Sumário do OneNote.onetoc2
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe
O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 0: (no name) - http://www.google-analytics.com/urchin.js
--
End of file - 10892 bytes
Um abraço!!! Aguardo!!!
Bom Dia! altasena
<@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas.
<@> Salve-as,no desktop,como: CFScript <-- Texto!
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
File::
c:\windows\system32\jkkjIbxy.dll
c:\windows\Tasks\okvtgigf.job
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
<@> Arraste o CFScript.txt,para o ícone do ComboFix.
<@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe.
<@> Terminando,poste: ComboFix.txt
Abraços!
Bom Dia! altasena
<@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas.
<@> Salve-as,no desktop,como: CFScript <-- Texto!
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
File::
c:\windows\system32\jkkjIbxy.dll
c:\windows\Tasks\okvtgigf.job
C:\sqmdata18.sqm
C:\sqmnoopt18.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
<@> Arraste o CFScript.txt,para o ícone do ComboFix.
<@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe.
<@> Terminando,poste: ComboFix.txt
Abraços!
OLá Digram, boa tarde, mais uma vez muito obrigada pela atenção!!! UM abraço!!
ComboFix 08-12-29.02 - Altair 2008-12-30 15:22:57.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.558 [GMT -2:00]
Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt
* Criado um novo ponto de restauro
FILE ::
C:\sqmdata17.sqm
C:\sqmdata18.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
c:\windows\system32\jkkjIbxy.dll
c:\windows\Tasks\okvtgigf.job
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat
C:\sqmdata17.sqm
C:\sqmdata18.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
c:\windows\system32\jkkjIbxy.dll
c:\windows\Tasks\okvtgigf.job
----- BITS: Sites possivelmente infetados -----
hxxp://childhe.com
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-30 ))))))))))))))))))))))))))))
.
2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe
2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon
2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon
2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe
2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe
2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao
2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD
2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE
2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX
2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL
2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL
2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386
2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386
2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI
2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY
2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV
2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE
2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL
2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL
2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL
2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games
2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl
2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll
2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe
2008-11-26 21:42 . 2008-11-26 21:43 <DIR> d-------- c:\arquivos de programas\weblin
2008-11-26 21:40 . 2008-11-26 21:43 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist
2008-11-24 12:14 . 2008-12-30 14:20 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-11-24 12:14 . 2008-11-24 12:14 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8
2008-11-24 12:14 . 2008-11-24 12:14 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-24 12:14 . 2008-11-24 12:14 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-14 08:50 . 2008-11-14 09:40 <DIR> d-------- c:\arquivos de programas\O Resgate dos Bichos - CD 2
2008-11-14 08:50 . 2008-11-14 08:50 90,112 --a------ c:\windows\Cuninst.exe
2008-11-14 08:01 . 2008-11-14 08:04 1,385 --a------ c:\windows\disney.ini
2008-11-14 08:01 . 2008-11-14 08:01 205 --a------ c:\windows\disneysy.ini
2008-11-12 09:47 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 09:47 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-05 18:45 . 2008-11-05 18:45 224 --a------ c:\documents and settings\ALTAIR~1.xml
2008-11-05 18:22 . 2008-11-05 18:30 119,001 --a------ c:\windows\hpoins11.dat
2008-11-02 21:41 . 2008-11-03 18:35 <DIR> d-------- c:\arquivos de programas\gamespeed
2008-11-02 21:41 . 2005-12-08 10:09 49,152 --a------ c:\windows\system32\mydll.dll
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 16:56 --------- d-----w c:\arquivos de programas\MegaJogos
2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft
2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft
2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule
2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin
2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express
2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java
2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help
2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype
2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!
2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger
2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller
2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live
2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live
2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector
2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft
2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live
2008-10-23 12:37 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr
2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe
2008-10-16 20:23 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-27 14:12 94,578 ----a-w c:\windows\FreeOCR.net Uninstaller.exe
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-08 16:57 126,976 ----a-w c:\windows\system32\UAService7.exe
2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys
2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys
2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys
2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys
2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys
2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys
2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys
2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys
2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys
2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll
2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll
2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll
2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll
2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat
+ 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat.bak
+ 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat
+ 2008-12-29 18:01:05 78,924 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
+ 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-29 18:01:00 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-30 17:18:41 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_948.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]
"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]
"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]
"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\
Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
Sum rio do OneNote.onetoc2 [2008-04-15 3656]
c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\
ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]
Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\Valve\\hlds.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=
"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=
"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=
"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]
R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []
S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []
Newly Created Service - CATCHME
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.globo.com.br/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147
c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}
hxxp://www.powerchallenge.com/applet/PowerLoader.cab
c:\windows\Downloaded Program Files\PowerLoader.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 15:26:22
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
c:\windows\system32\Ati2evxx.dll
.
Tempo para conclusão: 2008-12-30 15:28:51
ComboFix-quarantined-files.txt 2008-12-30 17:27:48
ComboFix2.txt 2008-12-29 17:18:19
ComboFix3.txt 2008-12-28 20:29:42
Pré-execução: 41 pasta(s) 20.443.369.472 bytes disponíveis
Pós execução: 41 pasta(s) 20,439,085,056 bytes disponíveis
259 --- E O F --- 2008-12-19 21:40:20
Grato Altair!!
Bom Dia! altasena
<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.
<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )
<@> Clique em Executar --> Aguarde!
<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.
<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!
----------------------------
<@> Vá a este Link,e baixe: < Malwarebytes >
<@> Atualize o programa!
<@> Escolha o escaneamento Rápido!
<@> Desabilite programas de proteção,ao executar o malwarebytes.
<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.
<@> Para maiores detalhes: < Link >
-----------------------
<@> Poste: mbam-log-2008-xx-xx (00-00-00).txt
Abraços!
Bom Dia! altasena
<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.
<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )
<@> Clique em Executar --> Aguarde!
<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.
<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!
----------------------------
<@> Vá a este Link,e baixe: < Malwarebytes >
<@> Atualize o programa!
<@> Escolha o escaneamento Rápido!
<@> Desabilite programas de proteção,ao executar o malwarebytes.
<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.
<@> Para maiores detalhes: < Link >
-----------------------
<@> Poste: mbam-log-2008-xx-xx (00-00-00).txt
Abraços!
Boa Tarde e feilz 2009 DigRam
Malwarebytes' Anti-Malware 1.31
Versão do banco de dados: 1590
Windows 5.1.2600 Service Pack 3
1/1/2009 17:58:09
mbam-log-2009-01-01 (17-58-09).txt
Tipo de Verificação: Rápida
Objetos verificados: 73565
Tempo decorrido: 6 minute(s), 12 second(s)
Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 1
Valores do Registro infectados: 0
Ítens do Registro infectados: 0
Pastas infectadas: 0
Arquivos infectados: 0
Processos da Memória infectados:
(Nenhum ítem malicioso foi detectado)
Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)
Chaves do Registro infectadas:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
Valores do Registro infectados:
(Nenhum ítem malicioso foi detectado)
Ítens do Registro infectados:
(Nenhum ítem malicioso foi detectado)
Pastas infectadas:
(Nenhum ítem malicioso foi detectado)
Arquivos infectados:
(Nenhum ítem malicioso foi detectado)
Um abraço Altair e muito obrigado...
Boa Noite! altasena
<!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema.
<!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.
<!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok.
<!> Depois,desmarque novamente! --> Aplicar --> Ok.
<!> Para maiores detalhes,vá em: < Docs >
----------------------------
<!> Não existe mais traços do Vundo. :natal_happy:
<!> Os logs estão limpos!
<!> Tudo Ok?
Abraços!
Boa Noite! altasena
<!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema.
<!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.
<!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok.
<!> Depois,desmarque novamente! --> Aplicar --> Ok.
<!> Para maiores detalhes,vá em: < Docs >
----------------------------
<!> Não existe mais traços do Vundo. :natal_happy:
<!> Os logs estão limpos!
<!> Tudo Ok?
Abraços!
Boa tarde DigRam e muito obrigado pelo seu trabalho,você me tirou de mais um problema no pc dos meus filhos..Que papai do céu te abençoe.Feliz 2009.
PROBLEMA RESOLVIDO!
Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.
Boa Tarde! altasena
<@> Baixe: < ComboFix.exe > ( ...by sUBs )
<@> Salve-o no Desktop!
<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )
<@> Feche todas as janelas e execute a ferramenta!
<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!
<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!
<!> Ps: Nomeie durante o salvamento,e não após salvá-la!
<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link!
<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!
<!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.
<@> Abrir-se-á a janela Auto Scan. --> Aguarde!
<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.
<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!
<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!
<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!
----------------------
<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.
Abraços!