Hiro 0 Denunciar post Postado Agosto 23, 2007 Por favor, me ajudem, meu norton ta acusando os trojans C:\WINDOWS\WebAssist.dll e C:\WINDOWS\system32\7628y8S6.exe sendo que este último pipoaca no nortn direto e essa porcaria não consegue reparar nenhum deles. Aí vai meu log:Logfile of HijackThis v1.99.1Scan saved at 01:38:51, on 23/8/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Arquivos de programas\Norton AntiVirus\navapsvc.exeC:\Arquivos de programas\Norton AntiVirus\SAVScan.exeC:\WINDOWS\system32\pctspk.exeC:\WINDOWS\system32\PV92Tray.exeC:\Arquivos de programas\iTunes\iTunesHelper.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exeC:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exeC:\Arquivos de programas\Messenger\msmsgs.exeC:\Arquivos de programas\iPod\bin\iPodService.exeC:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exeC:\Arquivos de programas\Discador iBest\discador.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\winmds.exeC:\Arquivos de programas\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\system32\winmds.exeC:\Documents and Settings\Mauro\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.aspO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dllO2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [PCTVOICE] pctspk.exeO4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exeO4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exeO4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /backgroundO8 - Extra context menu item: Download All by FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htmO8 - Extra context menu item: Download using FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htmO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exeO14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.aspO17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exeO23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exeO23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 23, 2007 Boa Tarde Hiro! >@< Faça o download do ComboFix. >@< Baixe-o para o Desktop! >@< Feche todas as janelas e execute a ferramenta! >@< Abrirá a janela Auto Scan. Aguarde! >@< Digite a opção para continuar < Enter > >@< Aguarde a conclusão! >@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Agosto 26, 2007 ComboFix 07-08-25.2 - "Mauro" 2007-08-26 20:25:14.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.77 [GMT -3:00] * Created a new restore point ((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 ))))))))))))))))))))))))))))))) 2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-25 02:59 356,159 -ra------ C:\WINDOWS\system32\drivers\ptserial.sys 2007-08-25 02:59 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe 2007-08-25 02:59 125,440 -ra------ C:\WINDOWS\system32\runpct.exe 2007-08-25 02:59 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat 2007-08-25 02:54 <DIR> d-------- C:\WINDOWS\PCTEL 2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe 2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe 2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe 2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe 2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe 2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe 2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet 2007-08-23 02:06 <DIR> d-------- C:\VundoFix Backups 2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy 2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007 2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio 2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv 2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus 2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2007-08-20 00:32 11,342 --a------ C:\WINDOWS\system32\winmds.exe 2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule 2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS 2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-08-16 07:39 <DIR> d-------- C:\WINDOWS\system32\PreInstall 2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$ 2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData 2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead 2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2007-08-14 14:36 <DIR> d-------- C:\WINDOWS\RegisteredPackages 2007-08-14 14:24 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution 2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update 2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys 2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys 2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys 2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software 2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools 2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer 2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information 2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime 2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod 2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield 2007-08-14 12:56 <DIR> d-------- C:\WINDOWS\Downloaded Installations 2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent 2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent 2007-08-14 01:25 <DIR> d-------- C:\Downloads 2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda 2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet 2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest 2007-08-14 01:12 <DIR> d--hs---- C:\RECYCLER 2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21 2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll 2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys 2007-08-13 23:53 801,778 -ra------ C:\WINDOWS\system32\drivers\vpctcom.sys 2007-08-13 23:53 703,673 -ra------ C:\WINDOWS\system32\drivers\vmodem.sys 2007-08-13 23:53 70,320 -ra------ C:\WINDOWS\system32\drivers\vvoice.sys 2007-08-13 23:53 50,040 --------- C:\WINDOWS\system32\ptPTT.dat 2007-08-13 23:53 308 --a------ C:\WINDOWS\system32\pthsp.dat 2007-08-13 23:53 180,224 -ra------ C:\WINDOWS\system32\pctspk.exe 2007-08-13 23:53 155,648 -ra------ C:\WINDOWS\system32\ptsetup.dll 2007-08-13 23:53 131,072 -ra------ C:\WINDOWS\system32\ptuninst.exe 2007-08-13 23:50 2,097,152 --ah----- C:\DOCUME~1\Mauro\NTUSER.DAT 2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo 2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais 2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\SoftwareDistribution 2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\Prefetch 2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Dados de aplicativos 2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Dados de aplicativos 2007-08-13 23:44 10,240 --a------ C:\WINDOWS\system32\change.exe 2007-08-13 23:42 229,376 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-08-13 23:42 0 -rahs---- C:\MSDOS.SYS 2007-08-13 23:42 0 -rahs---- C:\IO.SYS 2007-08-13 23:42 0 --a------ C:\CONFIG.SYS 2007-08-13 23:42 0 --a------ C:\AUTOEXEC.BAT 2007-08-13 23:42 <DIR> d-------- C:\WINDOWS\system32\xircom 2007-08-13 23:42 <DIR> d-------- C:\Arquivos de programas\microsoft frontpage 2007-08-13 23:41 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-08-13 23:40 <DIR> dr------- C:\WINDOWS\Offline Web Pages (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll 2007-08-14 23:54 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin 2007-08-14 23:52 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin --------- C:\Arquivos de programas\Serviços on-line --------- C:\Arquivos de programas\Arquivos comuns\Serviços ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59] "NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23] "Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-08-21 20:24] "PCTVOICE"="pctspk.exe" [2003-10-30 09:12 C:\WINDOWS\system32\pctspk.exe] "PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" [] "iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56] R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys *Newly Created Service* - CATCHME Contents of the 'Scheduled Tasks' folder 2007-08-23 03:01:04 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-24 15:00:00 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 16:00:00 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 17:00:00 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 18:00:00 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 19:00:00 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 20:00:00 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 21:00:00 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-25 04:00:00 C:\WINDOWS\Tasks\At2.job 2007-08-26 22:00:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-21 23:01:03 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-25 02:00:00 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-23 11:25:13 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 04:39:06 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 05:47:43 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 06:42:25 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 17:50:35 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 05:00:00 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-23 11:25:13 C:\WINDOWS\Tasks\At30.job 2007-08-23 11:25:13 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe 2007-08-23 11:25:13 C:\WINDOWS\Tasks\At32.job 2007-08-20 03:32:35 C:\WINDOWS\Tasks\At33.job 2007-08-20 03:32:35 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe 2007-08-20 03:32:35 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe 2007-08-20 03:32:35 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe 2007-08-24 17:39:14 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe 2007-08-26 21:03:05 C:\WINDOWS\Tasks\At38.job 2007-08-26 21:03:06 C:\WINDOWS\Tasks\At39.job 2007-08-25 06:00:00 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-26 21:03:06 C:\WINDOWS\Tasks\At40.job 2007-08-26 21:03:06 C:\WINDOWS\Tasks\At41.job 2007-08-26 20:00:00 C:\WINDOWS\Tasks\At42.job 2007-08-26 21:00:00 C:\WINDOWS\Tasks\At43.job 2007-08-26 22:24:54 C:\WINDOWS\Tasks\At44.job 2007-08-21 23:30:22 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe 2007-08-20 03:32:36 C:\WINDOWS\Tasks\At46.job - C:\WINDOWS\system32\winmds.exe 2007-08-20 03:32:36 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 03:56:57 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\winmds.exe 2007-08-25 07:00:01 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-23 08:00:01 C:\WINDOWS\Tasks\At6.job 2007-08-23 09:00:02 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-23 10:00:00 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-20 03:21:12 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\system32\7628y8S6.exe 2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe 2007-08-26 23:20:39 C:\WINDOWS\Tasks\Symantec NetDetect.job ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-26 20:27:33 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-26 20:28:56 --- E O F --- Ai o do HJT atualizado: Logfile of HijackThis v1.99.1 Scan saved at 20:30:39, on 26/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Discador iBest\baloon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Reboot.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe Ai Dig obrigado pela ajuda e desculpe pela demora é que meu modem tava com um problema de drive! Abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 28, 2007 Bom Dia Hiro! >@< Faça o download do Clean.zip. >@< Salve-o no Disco Local-C e descompacte-o aí mesmo,enviando o executável ( clean.cmd ),para o Desktop. ( Atalho! ) >@< Mas não rode-o ainda! >@< Faça o download do Avenger. >@< Descompacte-o e crie uma pasta para o programa!Coloque esta pasta no Disco Local-C ou Desktop! >@< Rode o programa e marque Input script manually. >@< Clique no ícone da lupa! Files to delete:C:\WINDOWS\system32\7628y8S6.exe C:\WINDOWS\system32\winmds.exe C:\WINDOWS\Tasks\At1.job C:\WINDOWS\Tasks\At10.job C:\WINDOWS\Tasks\At11.job C:\WINDOWS\Tasks\At12.job C:\WINDOWS\Tasks\At13.job C:\WINDOWS\Tasks\At14.job C:\WINDOWS\Tasks\At15.job C:\WINDOWS\Tasks\At16.job C:\WINDOWS\Tasks\At17.job C:\WINDOWS\Tasks\At18.job C:\WINDOWS\Tasks\At19.job C:\WINDOWS\Tasks\At2.job C:\WINDOWS\Tasks\At20.job C:\WINDOWS\Tasks\At21.job C:\WINDOWS\Tasks\At22.job C:\WINDOWS\Tasks\At23.job C:\WINDOWS\Tasks\At24.job C:\WINDOWS\Tasks\At25.job C:\WINDOWS\Tasks\At26.job C:\WINDOWS\Tasks\At27.job C:\WINDOWS\Tasks\At28.job C:\WINDOWS\Tasks\At29.job C:\WINDOWS\Tasks\At3.job C:\WINDOWS\Tasks\At30.job C:\WINDOWS\Tasks\At31.job C:\WINDOWS\Tasks\At32.job C:\WINDOWS\Tasks\At33.job C:\WINDOWS\Tasks\At34.job C:\WINDOWS\Tasks\At35.job C:\WINDOWS\Tasks\At36.job C:\WINDOWS\Tasks\At37.job C:\WINDOWS\Tasks\At38.job C:\WINDOWS\Tasks\At39.job C:\WINDOWS\Tasks\At4.job C:\WINDOWS\Tasks\At40.job C:\WINDOWS\Tasks\At41.job C:\WINDOWS\Tasks\At42.job C:\WINDOWS\Tasks\At43.job C:\WINDOWS\Tasks\At44.job C:\WINDOWS\Tasks\At45.job C:\WINDOWS\Tasks\At46.job C:\WINDOWS\Tasks\At47.job C:\WINDOWS\Tasks\At48.job C:\WINDOWS\Tasks\At5.job C:\WINDOWS\Tasks\At6.job C:\WINDOWS\Tasks\At7.job C:\WINDOWS\Tasks\At8.job C:\WINDOWS\Tasks\At9.job >@< Na caixa que abrir,cole o que foi copiado na área do quote,logo àcima! >@< Clique em Done. >@< Clique no ícone do semáforo! >@< Clique em Ok. >@< O computador irá reiniciar! >@< Aproveite êste reboot e entre em Modo de Segurança. >@< Execute,agora,a ferramenta de limpeza profunda Clean. >@< Dê um duplo clique em clean.cmd. >@< Abrir-se-á um Prompt com três opções: Escolha o dois ( 2 )! >@< Aperte Enter! >> Aperte Enter,novamente! >> Aguarde! >@< Aperte Enter,novamente! >@< Surgirá um relatório ( rapport_clean ),que voçê deverá copiar e postar para análise. >@< Reinicie,normalmente,o computador! >@< Poste,na sua resposta,um nôvo Log do HijackThis + rapport_clean + Avenger.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Agosto 29, 2007 Olá DigRam, tive um pouco de dificuldade no reboot desculpe a ignorância, é que meu mouse não funcionava e os icones tavam gigantescos e nao conseguia acessar eles no tab entao reiniciei de novo e no modo seguro com o tab acabei conseguindo rodar o clean, espero que nao tenha nada dado errado HIJACK Logfile of HijackThis v1.99.1 Scan saved at 00:23:09, on 29/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Discador iBest\discador.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Mauro\Desktop\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - Global Startup: Reboot.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe REPPORT CLEAN eScript executed in Safe Mode Rapport clean par Malekal_morte - http://www.malekal.com Script executed in Safe Mode qua 29/08/2007 a 0:16:43,28 Microsoft Windows XP [versÆo 5.1.2600] *** Suppression C: *** Suppression C:\WINDOWS\ *** Suppression C:\WINDOWS\system32 *** Suppression C:\Arquivos de programas *** Deletion of the registry keys successful.. *** End of the report ! AVENGER Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\acgfsajm ******************* Script file located at: \??\C:\WINDOWS\system32\kiisgcij.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\WINDOWS\system32\7628y8S6.exe not found! Deletion of file C:\WINDOWS\system32\7628y8S6.exe failed! Could not process line: C:\WINDOWS\system32\7628y8S6.exe Status: 0xc0000034 File C:\WINDOWS\system32\winmds.exe deleted successfully. File C:\WINDOWS\Tasks\At1.job deleted successfully. File C:\WINDOWS\Tasks\At10.job deleted successfully. File C:\WINDOWS\Tasks\At11.job deleted successfully. File C:\WINDOWS\Tasks\At12.job deleted successfully. File C:\WINDOWS\Tasks\At13.job deleted successfully. File C:\WINDOWS\Tasks\At14.job deleted successfully. File C:\WINDOWS\Tasks\At15.job deleted successfully. File C:\WINDOWS\Tasks\At16.job deleted successfully. File C:\WINDOWS\Tasks\At17.job deleted successfully. File C:\WINDOWS\Tasks\At18.job deleted successfully. File C:\WINDOWS\Tasks\At19.job deleted successfully. File C:\WINDOWS\Tasks\At2.job deleted successfully. File C:\WINDOWS\Tasks\At20.job deleted successfully. File C:\WINDOWS\Tasks\At21.job deleted successfully. File C:\WINDOWS\Tasks\At22.job deleted successfully. File C:\WINDOWS\Tasks\At23.job deleted successfully. File C:\WINDOWS\Tasks\At24.job deleted successfully. File C:\WINDOWS\Tasks\At25.job deleted successfully. File C:\WINDOWS\Tasks\At26.job deleted successfully. File C:\WINDOWS\Tasks\At27.job deleted successfully. File C:\WINDOWS\Tasks\At28.job deleted successfully. File C:\WINDOWS\Tasks\At29.job deleted successfully. File C:\WINDOWS\Tasks\At3.job deleted successfully. File C:\WINDOWS\Tasks\At30.job deleted successfully. File C:\WINDOWS\Tasks\At31.job deleted successfully. File C:\WINDOWS\Tasks\At32.job deleted successfully. File C:\WINDOWS\Tasks\At33.job deleted successfully. File C:\WINDOWS\Tasks\At34.job deleted successfully. File C:\WINDOWS\Tasks\At35.job deleted successfully. File C:\WINDOWS\Tasks\At36.job deleted successfully. File C:\WINDOWS\Tasks\At37.job deleted successfully. File C:\WINDOWS\Tasks\At38.job deleted successfully. File C:\WINDOWS\Tasks\At39.job deleted successfully. File C:\WINDOWS\Tasks\At4.job deleted successfully. File C:\WINDOWS\Tasks\At40.job deleted successfully. File C:\WINDOWS\Tasks\At41.job deleted successfully. File C:\WINDOWS\Tasks\At42.job deleted successfully. File C:\WINDOWS\Tasks\At43.job deleted successfully. File C:\WINDOWS\Tasks\At44.job deleted successfully. File C:\WINDOWS\Tasks\At45.job deleted successfully. File C:\WINDOWS\Tasks\At46.job deleted successfully. File C:\WINDOWS\Tasks\At47.job deleted successfully. File C:\WINDOWS\Tasks\At48.job deleted successfully. File C:\WINDOWS\Tasks\At5.job deleted successfully. File C:\WINDOWS\Tasks\At6.job deleted successfully. File C:\WINDOWS\Tasks\At7.job deleted successfully. File C:\WINDOWS\Tasks\At8.job deleted successfully. File C:\WINDOWS\Tasks\At9.job deleted successfully. Completed script processing. ******************* Finished! Terminate. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 29, 2007 Bom Dia Hiro! Por favor, me ajudem, meu norton ta acusando os trojans C:\WINDOWS\WebAssist.dll e C:\WINDOWS\system32\7628y8S6.exe sendo que este último pipoaca no nortn direto e essa porcaria não consegue reparar nenhum deles. >@< Esse problema,ainda,lhe ocorre? >@< Procure atualizar o seu Antivírus ( Norton ),pois falhas ocorridas no LiveUpdate,ocasionam essas pop-ups. >@< Caso não possua suporte ( Assistência Remota da Symantec ),para baixar as últimas atualizações,do LiveUpdate,esses problemas,tendem à piorar. >@< Sugiro que instale um bom Antivírus,Free,e desinstale o Norton.Se o mesmo estiver sem suporte,é claro! ____________________ >@< Abra o HijackThis e,com todas as janelas fechadas,dê Fix,nesta entrada: O4 - Global Startup: Reboot.exe >@< Faça uma busca aos arquivos,em destaque: Reboot.exe C:\WINDOWS\system32\7628y8S6.exe >@< Caso os encontre,pode deletar! ____________________ >@< Execute,novamente,o ComboFix,e poste o relatório + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Setembro 1, 2007 Olá DigRam! O único reboot.exe que u encontrei foi este backup-20070829-182357-799-Reboot que eu acho que foi gerado pelo avenger, me diz se eu tenho que deletar ele? O Outro arquivo não foi encontrado e dei um fix no global.. O meu Live update tá atualizada com a data de 31/08/07, so o liveupdate do windows é que não ta atualizado. Mas foi fazer isso em breve e a unica popup que ainda aparece é uma bem pequenininha e ela é gerada pelo ibest do nada. Ai vão os logs HIJACK Logfile of HijackThis v1.99.1 Scan saved at 06:51:26, on 1/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Discador iBest\baloon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Oi Internet\discaoi.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe COMOBOFIX ComboFix 07-08-25.2 - "Mauro" 2007-09-01 6:52:40.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.110 [GMT -3:00] ((((((((((((((((((((((((( Files Created from 2007-08-01 to 2007-09-01 ))))))))))))))))))))))))))))))) 2007-08-29 00:05 <DIR> d-------- C:\WINDOWS\CSC 2007-08-29 00:03 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-08-29 00:03 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dados de aplicativos 2007-08-29 00:03 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Iniciar 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Modelos 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configura‡äes locais 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de rede 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de impressÆo 2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Meus documentos 2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos 2007-08-28 23:28 <DIR> d-------- C:\clean 2007-08-27 17:42 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat 2007-08-27 17:41 50,040 --------- C:\WINDOWS\system32\ptPTT.dat 2007-08-27 17:41 356,159 --a------ C:\WINDOWS\system32\drivers\ptserial.sys 2007-08-27 17:41 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe 2007-08-27 17:41 308 --a------ C:\WINDOWS\system32\pthsp.dat 2007-08-27 17:41 155,648 --a------ C:\WINDOWS\system32\ptsetup.dll 2007-08-27 17:41 125,440 --a------ C:\WINDOWS\system32\runpct.exe 2007-08-27 17:41 <DIR> d-------- C:\WINDOWS\PCTEL 2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe 2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe 2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe 2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe 2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe 2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe 2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet 2007-08-23 02:06 <DIR> d-------- C:\VundoFix Backups 2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy 2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007 2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio 2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv 2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus 2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule 2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS 2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-08-16 07:39 <DIR> d-------- C:\WINDOWS\system32\PreInstall 2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$ 2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData 2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead 2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2007-08-14 14:36 <DIR> d-------- C:\WINDOWS\RegisteredPackages 2007-08-14 14:24 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution 2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update 2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys 2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys 2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys 2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software 2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools 2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer 2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information 2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime 2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod 2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield 2007-08-14 12:56 <DIR> d-------- C:\WINDOWS\Downloaded Installations 2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent 2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent 2007-08-14 01:25 <DIR> d-------- C:\Downloads 2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda 2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet 2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest 2007-08-14 01:12 <DIR> d--hs---- C:\RECYCLER 2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21 2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll 2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys 2007-08-13 23:53 801,778 --a------ C:\WINDOWS\system32\drivers\vpctcom.sys 2007-08-13 23:53 703,673 --a------ C:\WINDOWS\system32\drivers\vmodem.sys 2007-08-13 23:53 70,320 --a------ C:\WINDOWS\system32\drivers\vvoice.sys 2007-08-13 23:53 180,224 --a------ C:\WINDOWS\system32\pctspk.exe 2007-08-13 23:53 131,072 --a------ C:\WINDOWS\system32\ptuninst.exe 2007-08-13 23:50 3,145,728 --ah----- C:\DOCUME~1\Mauro\NTUSER.DAT 2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo 2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais 2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\SoftwareDistribution 2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\Prefetch 2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Dados de aplicativos 2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Dados de aplicativos (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll 2007-08-14 23:54 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin 2007-08-14 23:52 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin --------- C:\Arquivos de programas\Serviços on-line --------- C:\Arquivos de programas\Arquivos comuns\Serviços ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59] "NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23] "Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-08-21 20:24] "PCTVOICE"="pctspk.exe" [2003-10-30 09:12 C:\WINDOWS\system32\pctspk.exe] "PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" [] "iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56] R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys Contents of the 'Scheduled Tasks' folder 2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe 2007-09-01 06:50:55 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Arquivos de programas\Symantec\LiveUpdate\NDETECT.EXE ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-01 06:54:50 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-09-01 6:56:25 C:\ComboFix2.txt ... 2007-08-29 19:48 C:\ComboFix3.txt ... 2007-08-26 20:28 --- E O F --- Obrigado pela ajuda!! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Setembro 3, 2007 Bom Dia Hiro! O único reboot.exe que u encontrei foi este backup-20070829-182357-799-Reboot que eu acho que foi gerado pelo avenger, me diz se eu tenho que deletar ele? O Outro arquivo não foi encontrado e dei um fix no global.. >@< Pode deletar a pasta,de backups,do Avenger. O meu Live update tá atualizada com a data de 31/08/07, so o liveupdate do windows é que não ta atualizado. Mas foi fazer isso em breve e a unica popup que ainda aparece é uma bem pequenininha e ela é gerada pelo ibest do nada. >@< Tente reconfigurar o Bloqueador de Pop-ups,do IE6,para Médio.Já,em Alto,deverá adicionar os Sites que queira permitir,as Pop-ups. __________________________ >@< Faça o download do CCleaner. >@< Baixe-o para o Desktop! >@< Abra o programa e clique em Executar cleaner. >@< Terminando,clique em Erros >> Procurar erros >> Corrigir erros. __________________________ Estando tudo Ok,com o computador,crie um Ponto de Restauração do Sistema,Limpo!Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok. Depois,desmarque novamente! >> Aplicar >> Ok. Para maiores detalhes,vá em:< Docs > >@< Algum problema,ainda,com o computador? >@< Bom trabalho! >@< Log Limpo! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Setembro 6, 2007 olá DigRam, fiz td o que voce falou mas alguns dias depois me aparece outro virus e esse parece pior pq ele desliga minha conexão e cria um nova e disca um numero que deve ser internacional ai vai o log do hijack e do combofix. Se poder me ajudar td bem se não vou formatar mesmo esse computador e comprar o kaspersky, pq esse norton é mesmo que nada. Logfile of HijackThis v1.99.1 Scan saved at 15:30:02, on 6/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe C:\Arquivos de programas\Discador iBest\baloon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe COMBOFIX ComboFix 07-08-30.3 - "Mauro" 2007-09-06 15:19:01.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.69 [GMT -3:00] * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Arquivos de programas\gbplugin\bank.gbl C:\Arquivos de programas\gbplugin\Bb.gpc C:\Arquivos de programas\gbplugin\Bb.gpc . . . . failed to delete C:\Arquivos de programas\gbplugin\gbieh.gmd C:\WINDOWS\system32\N5hd1t0f.exe C:\WINDOWS\Tasks.\At1.job C:\WINDOWS\Tasks.\At10.job C:\WINDOWS\Tasks.\At11.job C:\WINDOWS\Tasks.\At12.job C:\WINDOWS\Tasks.\At13.job C:\WINDOWS\Tasks.\At14.job C:\WINDOWS\Tasks.\At15.job C:\WINDOWS\Tasks.\At16.job C:\WINDOWS\Tasks.\At17.job C:\WINDOWS\Tasks.\At18.job C:\WINDOWS\Tasks.\At19.job C:\WINDOWS\Tasks.\At2.job C:\WINDOWS\Tasks.\At20.job C:\WINDOWS\Tasks.\At21.job C:\WINDOWS\Tasks.\At22.job C:\WINDOWS\Tasks.\At23.job C:\WINDOWS\Tasks.\At24.job C:\WINDOWS\Tasks.\At3.job C:\WINDOWS\Tasks.\At4.job C:\WINDOWS\Tasks.\At5.job C:\WINDOWS\Tasks.\At6.job C:\WINDOWS\Tasks.\At7.job C:\WINDOWS\Tasks.\At8.job C:\WINDOWS\Tasks.\At9.job ((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 ))))))))))))))))))))))))))))))) 2007-09-06 15:14 11,854 --a------ C:\WINDOWS\system32\winmds.exe 2007-09-04 23:19 <DIR> d--h----- C:\WINDOWS\PIF 2007-09-04 22:49 <DIR> d-------- C:\Arquivos de programas\CCleaner 2007-09-04 13:59 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Help 2007-09-03 08:20 <DIR> d-------- C:\Arquivos de programas\GbPlugin 2007-09-03 08:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\GbPlugin 2007-09-02 11:01 362,878 -ra------ C:\WINDOWS\system32\drivers\ptserial.sys 2007-09-02 11:01 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe 2007-09-02 11:01 125,440 -ra------ C:\WINDOWS\system32\runpct.exe 2007-09-02 11:01 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat 2007-09-02 10:54 308 --a------ C:\WINDOWS\system32\pthsp.dat 2007-09-02 10:54 <DIR> d-------- C:\WINDOWS\PCTEL 2007-08-29 00:03 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dados de aplicativos 2007-08-29 00:03 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Iniciar 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Modelos 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configura‡äes locais 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de rede 2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de impressÆo 2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Meus documentos 2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos 2007-08-28 23:28 <DIR> d-------- C:\clean 2007-08-27 17:41 50,040 --------- C:\WINDOWS\system32\ptPTT.dat 2007-08-27 17:41 159,744 -ra------ C:\WINDOWS\system32\ptsetup.dll 2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe 2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe 2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe 2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe 2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe 2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe 2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet 2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy 2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007 2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio 2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv 2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus 2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec 2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2007-08-18 17:07 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule 2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS 2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$ 2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData 2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead 2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero 2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2007-08-14 13:32 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys 2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update 2007-08-14 13:06 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys 2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys 2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys 2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys 2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software 2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools 2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer 2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information 2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime 2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes 2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod 2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield 2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent 2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent 2007-08-14 01:25 <DIR> d-------- C:\Downloads 2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda 2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet 2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest 2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21 2007-08-13 23:54 175,104 --a--c--- C:\WINDOWS\system32\dllcache\csamsp.dll 2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll 2007-08-13 23:54 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys 2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys 2007-08-13 23:53 86,016 --a--c--- C:\WINDOWS\system32\dllcache\pctspk.exe 2007-08-13 23:53 804,754 -ra------ C:\WINDOWS\system32\drivers\vpctcom.sys 2007-08-13 23:53 703,737 -ra------ C:\WINDOWS\system32\drivers\vmodem.sys 2007-08-13 23:53 70,384 -ra------ C:\WINDOWS\system32\drivers\vvoice.sys 2007-08-13 23:53 64,605 --a--c--- C:\WINDOWS\system32\dllcache\vvoice.sys 2007-08-13 23:53 604,253 --a--c--- C:\WINDOWS\system32\dllcache\vmodem.sys 2007-08-13 23:53 397,502 --a--c--- C:\WINDOWS\system32\dllcache\vpctcom.sys 2007-08-13 23:53 180,224 -ra------ C:\WINDOWS\system32\pctspk.exe 2007-08-13 23:53 131,072 -ra------ C:\WINDOWS\system32\ptuninst.exe 2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar 2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede 2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais 2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll --------- C:\Arquivos de programas\Serviços on-line --------- C:\Arquivos de programas\Arquivos comuns\Serviços ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59] "NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-09-05 21:19] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23] "Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-09-05 21:32] "PCTVOICE"="pctspk.exe" [2004-01-30 08:33 C:\WINDOWS\system32\pctspk.exe] "PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" [] "iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= C:\Arquivos de programas\GbPlugin\gbieh.dll [2007-06-25 09:24 332616] R2 GbpSv;Gbp Service;C:\Arquivos de programas\GbPlugin\GbpSv.exe R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys Contents of the 'Scheduled Tasks' folder 2007-09-05 18:13:04 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:05 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:05 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:05 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:05 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:05 C:\WINDOWS\Tasks\At30.job 2007-09-04 16:55:25 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 16:55:25 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:55 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 17:00:03 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:00:01 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 22:58:33 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:56 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 22:58:36 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\winmds.exe 2007-09-04 03:25:56 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 16:37:17 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 00:00:11 C:\WINDOWS\Tasks\At46.job 2007-09-05 18:13:07 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe 2007-09-05 18:13:07 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:02 C:\WINDOWS\Tasks\At49.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At50.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At51.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At52.job 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At53.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At54.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At55.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At56.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At57.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At58.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At59.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At60.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At61.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At62.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At63.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At64.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At65.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At66.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At67.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At68.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At69.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At70.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At71.job - C:\WINDOWS\system32\winmds.exe 2007-09-06 18:15:03 C:\WINDOWS\Tasks\At72.job - C:\WINDOWS\system32\winmds.exe 2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe 2007-09-06 18:23:41 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Arquivos de programas\Symantec\LiveUpdate\NDETECT.EXE ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-06 15:24:20 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-09-06 15:26:24 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-09-06 15:26 --- E O F --- Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Setembro 8, 2007 Bom Dia Hiro! >@< Delete o antigo relatório do Avenger. >@< Rode o programa e marque Input script manually. >@< Clique no ícone da lupa! Files to delete:C:\WINDOWS\system32\winmds.exe C:\WINDOWS\Tasks\At25.job C:\WINDOWS\Tasks\At26.job C:\WINDOWS\Tasks\At27.job C:\WINDOWS\Tasks\At28.job C:\WINDOWS\Tasks\At29.job C:\WINDOWS\Tasks\At30.job C:\WINDOWS\Tasks\At31.job C:\WINDOWS\Tasks\At32.job C:\WINDOWS\Tasks\At33.job C:\WINDOWS\Tasks\At34.job C:\WINDOWS\Tasks\At35.job C:\WINDOWS\Tasks\At36.job C:\WINDOWS\Tasks\At37.job C:\WINDOWS\Tasks\At38.job C:\WINDOWS\Tasks\At39.job C:\WINDOWS\Tasks\At40.job C:\WINDOWS\Tasks\At41.job C:\WINDOWS\Tasks\At42.job C:\WINDOWS\Tasks\At43.job C:\WINDOWS\Tasks\At44.job C:\WINDOWS\Tasks\At45.job C:\WINDOWS\Tasks\At46.job C:\WINDOWS\Tasks\At47.job C:\WINDOWS\Tasks\At48.job C:\WINDOWS\Tasks\At49.job C:\WINDOWS\Tasks\At50.job C:\WINDOWS\Tasks\At51.job C:\WINDOWS\Tasks\At52.job C:\WINDOWS\Tasks\At53.job C:\WINDOWS\Tasks\At54.job C:\WINDOWS\Tasks\At55.job C:\WINDOWS\Tasks\At56.job C:\WINDOWS\Tasks\At57.job C:\WINDOWS\Tasks\At58.job C:\WINDOWS\Tasks\At59.job C:\WINDOWS\Tasks\At60.job C:\WINDOWS\Tasks\At61.job C:\WINDOWS\Tasks\At62.job C:\WINDOWS\Tasks\At63.job C:\WINDOWS\Tasks\At64.job C:\WINDOWS\Tasks\At65.job C:\WINDOWS\Tasks\At66.job C:\WINDOWS\Tasks\At67.job C:\WINDOWS\Tasks\At68.job C:\WINDOWS\Tasks\At69.job C:\WINDOWS\Tasks\At70.job C:\WINDOWS\Tasks\At71.job C:\WINDOWS\Tasks\At72.job >@< Na caixa que abrir,cole o que foi copiado na área do quote,logo àcima! >@< Clique em Done. >@< Clique no ícone do semáforo! >@< Clique em Ok. >@< O computador irá reiniciar! ________________________ >@< Faça um escaneamento OnLine,pelo Panda. >@< Na página,clique no botão Scan you PC. >@< Clique em Next. >@< Digite o seu E-Mail. >@< Clique em Send. >@< Finalize clicando em All PC. ( All My Computer ) >@< Aguarde!Pois vai demorar um pouco para concluir o scan. >@< Terminando,copie o relatório e poste,na sua resposta + HJT,atualizado + Avenger.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Setembro 13, 2007 olá DigRam aí vão os logs: Incidência Estado Localização Ferramenta potencialmente indesejada:Application/Pskill.K Não desinfectado C:\clean\pskill.exe Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\ComboFix\nircmd.cfexe Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\ComboFix\nircmd.exe Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@acesso.uol.com[1].txt Spyware:Cookie/YieldManager Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@ad.yieldmanager[2].txt Spyware:Cookie/Atlas DMT Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@atdmt[1].txt Spyware:Cookie/Casalemedia Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@casalemedia[2].txt Spyware:Cookie/Cgi-bin Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@cgi-bin[2].txt Spyware:Cookie/Sextracker Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@counter14.sextracker[1].txt Spyware:Cookie/Doubleclick Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@doubleclick[1].txt Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@ig.com[1].txt Spyware:Cookie/Sextracker Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@sextracker[2].txt Spyware:Cookie/Statcounter Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@statcounter[1].txt Spyware:Cookie/Tribalfusion Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@tribalfusion[1].txt Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@uol.com[1].txt Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\Documents and Settings\Mauro\Desktop\ComboFix.exe[nircmd.exe] Ferramenta potencialmente indesejada:Application/Pskill.K Não desinfectado C:\Documents and Settings\Mauro\Desktop\Programas\clean.zip[clean/pskill.exe] Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\Documents and Settings\Mauro\Desktop\Programas\ComboFix.exe[nircmd.exe] Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\WINDOWS\nircmd.exe HIJACK Logfile of HijackThis v1.99.1 Scan saved at 15:52:08, on 12/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Discador iBest\discador.exe C:\Arquivos de programas\Oi Internet\discaoi.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Mauro\Desktop\HijackThis.exe O1 - Hosts: 170.66.1.60 www14.bancobrasil.com.br # GbPlugin O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe AVENGER Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\wkilvajm ******************* Script file located at: \??\C:\WINDOWS\skryneqm.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\WINDOWS\system32\winmds.exe deleted successfully. File C:\WINDOWS\Tasks\At25.job deleted successfully. File C:\WINDOWS\Tasks\At26.job deleted successfully. File C:\WINDOWS\Tasks\At27.job deleted successfully. File C:\WINDOWS\Tasks\At28.job deleted successfully. File C:\WINDOWS\Tasks\At29.job deleted successfully. File C:\WINDOWS\Tasks\At30.job deleted successfully. File C:\WINDOWS\Tasks\At31.job deleted successfully. File C:\WINDOWS\Tasks\At32.job deleted successfully. File C:\WINDOWS\Tasks\At33.job deleted successfully. File C:\WINDOWS\Tasks\At34.job deleted successfully. File C:\WINDOWS\Tasks\At35.job deleted successfully. File C:\WINDOWS\Tasks\At36.job deleted successfully. File C:\WINDOWS\Tasks\At37.job deleted successfully. File C:\WINDOWS\Tasks\At38.job deleted successfully. File C:\WINDOWS\Tasks\At39.job deleted successfully. File C:\WINDOWS\Tasks\At40.job deleted successfully. File C:\WINDOWS\Tasks\At41.job deleted successfully. File C:\WINDOWS\Tasks\At42.job deleted successfully. File C:\WINDOWS\Tasks\At43.job deleted successfully. File C:\WINDOWS\Tasks\At44.job deleted successfully. File C:\WINDOWS\Tasks\At45.job deleted successfully. File C:\WINDOWS\Tasks\At46.job deleted successfully. File C:\WINDOWS\Tasks\At47.job deleted successfully. File C:\WINDOWS\Tasks\At48.job deleted successfully. File C:\WINDOWS\Tasks\At49.job deleted successfully. File C:\WINDOWS\Tasks\At50.job deleted successfully. File C:\WINDOWS\Tasks\At51.job deleted successfully. File C:\WINDOWS\Tasks\At52.job deleted successfully. File C:\WINDOWS\Tasks\At53.job deleted successfully. File C:\WINDOWS\Tasks\At54.job deleted successfully. File C:\WINDOWS\Tasks\At55.job deleted successfully. File C:\WINDOWS\Tasks\At56.job deleted successfully. File C:\WINDOWS\Tasks\At57.job deleted successfully. File C:\WINDOWS\Tasks\At58.job deleted successfully. File C:\WINDOWS\Tasks\At59.job deleted successfully. File C:\WINDOWS\Tasks\At60.job deleted successfully. File C:\WINDOWS\Tasks\At61.job deleted successfully. File C:\WINDOWS\Tasks\At62.job deleted successfully. File C:\WINDOWS\Tasks\At63.job deleted successfully. File C:\WINDOWS\Tasks\At64.job deleted successfully. File C:\WINDOWS\Tasks\At65.job deleted successfully. File C:\WINDOWS\Tasks\At66.job deleted successfully. File C:\WINDOWS\Tasks\At67.job deleted successfully. File C:\WINDOWS\Tasks\At68.job deleted successfully. File C:\WINDOWS\Tasks\At69.job deleted successfully. File C:\WINDOWS\Tasks\At70.job deleted successfully. File C:\WINDOWS\Tasks\At71.job deleted successfully. File C:\WINDOWS\Tasks\At72.job deleted successfully. Completed script processing. ******************* Finished! Terminate. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Setembro 14, 2007 Bom Dia Hiro! >@< Crie um ponto de restauração,antes de executar êstes procedimentos! >@< Configure o Windows para que mostre: Ver todos os Arquivos,até os ocultos! >@< Desabilite as proteções residentes de AntiVírus e AntiSpywares! >@< Faça o download da EliStarA. >@< Baixe-a para o Desktop! >@< Faça o download do EliTriIP. >@< Baixe-o para o Desktop! >@< Ps: Ambas,as ferramentas,estarão na página descargas ( Descargas > Utilidades SATINFO ). >@< Selecione as ferramentas ( Uma por vez! ) e clique no pé da página,no botão Descargar xxx.Onde xxx é a denominação da ferramenta escolhida! >@< Faça o download do Clean. >@< Salve-o no Disco Local-C e descompacte-o aí mesmo,enviando o executável para o Desktop! ( Atalho. ) >@< O executável é um ícone denominado: clean.cmd >@< Reinicie o computador e entre em Modo de Segurança. >@< Execute,primeiro,a ferramenta: EliStartA. >@< Vá ao seu ícone e execute-a! >@< Aceite as condições propostas e aguarde o término do scan.Aguarde!Pois,pode demorar alguns minutos. >@< Terminando,execute a ferramenta EliTriIP. >@< O scan desta ferramenta é mais rápido! >@< Terminando,execute o programa de limpeza profunda ( clean ) com um duplo clique no seu executável. >@< Abrir-se-á um prompt com três opções: Escolha o dois ( 2 )! >@< Aperte Enter! >> Aperte Enter,novamente! >> Aguarde! >@< Aperte Enter,novamente! >@< Surgirá um relatório ( rapport_clean ),que voçê deverá copiar e postar para análise. ____________________________ >@< Poste o relatório infoSAT.txt que está na raíz C:\ ( Disco Local-C ) + rapport_clean. >@< Poste,também,um nôvo Log do HijackThis,feito em Modo Normal,na sua resposta. >@< Ps: A ferramenta EliStarA,deletará (Opcional! ) a sua página inicial!Posteriormente,voçê à configurará novamente. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Setembro 15, 2007 Bom dia DigRam! Aí vão os logs: Logfile of HijackThis v1.99.1 Scan saved at 10:57:47, on 15/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\Comodo\Firewall\CPF.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Discador iBest\discador.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Oi Internet\discaOi.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe INFOSAT Logfile of HijackThis v1.99.1 Scan saved at 10:57:47, on 15/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\Arquivos de programas\Comodo\Firewall\CPF.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Discador iBest\discador.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Oi Internet\discaOi.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe RAPPORTCLEAN Script executed in Safe Mode Rapport clean par Malekal_morte - http://www.malekal.com Script executed in Safe Mode --- 14/09/2007 a 20:39:32,07 Microsoft Windows XP [versÆo 5.1.2600] *** Suppression C: *** Suppression C:\WINDOWS\ *** Suppression C:\WINDOWS\system32 *** Suppression C:\Arquivos de programas *** Deletion of the registry keys successful.. *** End of the report ! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Setembro 16, 2007 Bom Dia Hiro! >@< Faltou postar infoSat.txt e,no lugar do mesmo,foi repetido o Log do HijackThis. >@< Caso não mais o possua,não rode as ferramentas para obtê-lo! ____________________ >@< Faça êste escaneamento de limpeza. >@< Faça um escaneamento OnLine em < BitDefender > e poste o relatório. >@< Clique em BitDefender ( Scan OnLine ). >@< Abrirá a página: < BitDefender OnLine Scanner > >@< Clique em I Agree. >@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan. >@< Poste,então: Relatório do scan OnLine + infoSat.txt + Log do HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Hiro 0 Denunciar post Postado Setembro 18, 2007 Olá DigRam, ai vao os logs: Logfile of HijackThis v1.99.1 Scan saved at 21:55:49, on 17/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe C:\Arquivos de programas\Comodo\Firewall\CPF.exe C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe C:\Arquivos de programas\Discador iBest\discador.exe C:\Arquivos de programas\Oi Internet\discaOi.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Documents and Settings\Mauro\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing) O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe INFOSAT Fri Sep 14 20:26:03 2007 EliStartPage v14.64 ©2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Acción Directa): Eliminado Servicio, "GbpSv" No detectado Parche MS06-001 de Microsoft instalado. (WMF) No detectado Parche MS06-070 de Microsoft instalado. (SServidor) ALERTA. WindowsUpdate Incompleto. Eliminadas las Paginas de Inicio y de Busqueda del IE Eliminados Ficheros Temporales del IE Fri Sep 14 20:27:35 2007 EliStartPage v14.64 ©2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\ComboFix\NIRCMD.EXE --> Eliminado, Tool-NirCmd C:\WINDOWS\NIRCMD.EXE --> Eliminado, Tool-NirCmd Fri Sep 14 20:35:54 2007 EliTriIP v3.88 ©2007 S.G.H. / Satinfo S.L. --------------------------------------------- Lista de Acciones (por Acción Directa): No detectado Parche MS06-001 de Microsoft instalado. (WMF) No detectado Parche MS06-070 de Microsoft instalado. (SServidor) ALERTA. WindowsUpdate Incompleto. Fri Sep 14 20:36:00 2007 EliTriIP v3.88 ©2007 S.G.H. / Satinfo S.L. --------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Arquivos de programas\Motorola Phone Tools\widcomm\Autorun.inf --> Eliminado, BackDoor.CMQ (inf) SCAN ONLINE BitDefender Online Scanner Scan report generated at: Mon, Sep 17, 2007 - 21:49:27 Scan path: A:\;C:\;D:\;E:\;F:\; Statistics Time 01:03:02 Files 93015 Folders 2451 Boot Sectors 2 Archives 1186 Packed Files 3583 Results Identified Viruses 5 Infected Files 12 Suspect Files 0 Warnings 0 Disinfected 0 Deleted Files 14 Engines Info Virus Definitions 810674 Engine build AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22) Scan plugins 14 Archive plugins 38 Unpack plugins 7 E-mail plugins 6 System plugins 1 Scan Settings First Action Disinfect Second Action Delete Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2) Infected with: Trojan.Dialer.AEN C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2) Disinfection failed C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2) Deleted C:\avenger\backup.zip=>avenger/winmds.exe Infected with: MemScan:Trojan.Dialer.VUB C:\avenger\backup.zip=>avenger/winmds.exe Disinfection failed C:\avenger\backup.zip=>avenger/winmds.exe Deleted C:\avenger\backup.zip Updated C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe Infected with: Win32.Cuter.A C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe Infected with: Win32.Cuter.A C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe Infected with: Trojan.Dialer.AEN C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe Infected with: GenPack:Trojan.Downloader.JIYC C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe Infected with: GenPack:Trojan.Downloader.JIYC C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2) Infected with: Trojan.Dialer.AEN C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2) Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2) Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe Infected with: GenPack:Trojan.Downloader.JIYC C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe Infected with: MemScan:Trojan.Dialer.VUB C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe Deleted C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2) Infected with: Trojan.Dialer.AEN C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2) Disinfection failed C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2) Deleted D:\Backup\Programas e recibos\btlite.exe Infected with: Trojan.Dropper.Agent.LA D:\Backup\Programas e recibos\btlite.exe Disinfection failed D:\Backup\Programas e recibos\btlite.exe Delete failed Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Setembro 18, 2007 Boa Noite Hiro! >@< Reinicie o computador,e entre em Modo Seguro. D:\Backup\Programas e recibos\btlite.exe << Delete êste arquivo! >@< Reinicie em Modo Normal. _______________________________ BAIXE < Advanced WindowsCare > >@< Salve-o no Desktop ou Arquivos de Programa. >@< Este programa de limpeza,é fantástico,pois além de remover: Cookies,históricos e temporários.Procura,também,otimizar o SO e remover alguns Spywares. >@< Recomendo o programa,a todos àqueles que têm problemas de lentidão,sem nenhuma causa aparente! TUTORIAL >1< Antes de rodar o programa,atualize o Banco de Dados: Clique em Estado. >2< Clique em Atualizar Agora. >> Aguarde! >3< Terminando,vá em Mais >> Clique em Limpador de Memória. >@< Abrir-se-á a janela: Limpador de Memória. >@< Clique em Limpar agora! Aguarde... >@< Surgirá uma mensagem,após o término,informando a quantidade de memória liberada. >@< Clique em Sair. >4< Agora,o utilitário está pronto para limpar e otimizar o seu computador. >5< Abra o programa e clique em Start >> Clique em Scan. ( Analisar ) >6< Terminando,aparecerão em vermelho,os ítens a serem removidos. >7< Clique,agora,no botão Care. ( Reparar ) >8< Caso queira monitorar,o que será removido,clique para cada ítem,em: Show Details,antes de clicar em Reparar. >9< Terminando,reinicie o computador e execute,novamente,o Advanced WindowsCare. ___________________ >@< Poste,na sua resposta,um novo Log do HJT e,informe com está o PC. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Sam Spade 2 Denunciar post Postado Março 21, 2008 Tópico Arquivado Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites