Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
Boa tarde !
Estes ficheiros infra do adobe flash player; podem estarem infectados por rootkits ?
Obs : Perçebo que na varredura do avira antirootkit; estes ficheiros são detectados em D:\recnet .
Avira AntiRootkit Tool (1.1.0.1)
========================================================================================================
- Scan started quarta-feira, 1 de dezembro de 2010 - 18:43:43
========================================================================================================
--------------------------------------------------------------------------------------------------------
Configuration:
--------------------------------------------------------------------------------------------------------
- [X] Scan files
- [X] Scan registry
- [X] Scan processes
- [ ] Fast scan
- Working disk total size : 59.00 GB
- Working disk free size : 32.44 GB (54 %)
--------------------------------------------------------------------------------------------------------
Results:
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\hbin.
Hidden fileHidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\i.s
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\m.r
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\\.5
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\:.f
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\s.\
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\p.e
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\s.e
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\y.0
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\-.1
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\c.1
Hidden file : d:\documents and settings\edsom luis\dados de aplicativos\macro\flash player\macromedia.com\support\flashplayer\\a0z.
--------------------------------------------------------------------------------------------------------
Files: 13/89693
Registry items: 0/254416
Processes: 0/25
Scan time: 00:03:21
--------------------------------------------------------------------------------------------------------
Active processes:
- udaepfpa.exe (PID 3196) (Avira AntiRootkit Tool)
- System (PID 4)
- SMSS.EXE (PID 940)
- CSRSS.EXE (PID 1024)
- WINLOGON.EXE (PID 1048)
- SERVICES.EXE (PID 1096)
- LSASS.EXE (PID 1108)
- SVCHOST.EXE (PID 1284)
- SVCHOST.EXE (PID 1352)
- SVCHOST.EXE (PID 2032)
- SVCHOST.EXE (PID 268)
- SVCHOST.EXE (PID 612)
- SPOOLSV.EXE (PID 976)
- EXPLORER.EXE (PID 1012)
- JUSCHED.EXE (PID 1416)
- CURSORXP.EXE (PID 1436)
- MSNMSGR.EXE (PID 1444)
- JQS.EXE (PID 1700)
- MDM.EXE (PID 1728)
- SEAPORT.EXE (PID 1772)
- ALG.EXE (PID 668)
- FIREFOX.EXE (PID 2760)
- plugin-container.exe (PID 3124)
- WUAUCLT.EXE (PID 3696)
- avirarkd.exe (PID 1492)
========================================================================================================
- Scan finished quarta-feira, 1 de dezembro de 2010 - 18:47:05
========================================================================================================
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:48:43, on 1/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
D:\Arquivos de programas\CursorXP\CursorXP.exe
D:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
D:\Arquivos de programas\Java\jre6\bin\jqs.exe
D:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
D:\Arquivos de programas\Mozilla Firefox\firefox.exe
D:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
D:\WINDOWS\system32\wuauclt.exe
D:\DOCUME~1\EDSOML~1\CONFIG~1\Temp\Diretório temporário 2 para antivir_rootkit.zip\avirarkd.exe
D:\DOCUME~1\EDSOML~1\CONFIG~1\Temp\udaepfpa.exe
D:\Documents and Settings\edsom luis\Meus documentos\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - D:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [sunJavaUpdateSched] "D:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CursorXP] D:\Arquivos de programas\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Arquivos de programas\Messenger\msmsgs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Arquivos de programas\Java\jre6\bin\jqs.exe
--
End of file - 4255 bytes
Obrigado e abraços
Carregando comentários...