Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Hiro

[Arquivado]C:\WINDOWS\system32\7628y8S6.exe

Recommended Posts

Por favor, me ajudem, meu norton ta acusando os trojans C:\WINDOWS\WebAssist.dll e C:\WINDOWS\system32\7628y8S6.exe sendo que este último pipoaca no nortn direto e essa porcaria não consegue reparar nenhum deles. Aí vai meu log:Logfile of HijackThis v1.99.1Scan saved at 01:38:51, on 23/8/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Arquivos de programas\Norton AntiVirus\navapsvc.exeC:\Arquivos de programas\Norton AntiVirus\SAVScan.exeC:\WINDOWS\system32\pctspk.exeC:\WINDOWS\system32\PV92Tray.exeC:\Arquivos de programas\iTunes\iTunesHelper.exeC:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exeC:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exeC:\Arquivos de programas\Messenger\msmsgs.exeC:\Arquivos de programas\iPod\bin\iPodService.exeC:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exeC:\Arquivos de programas\Discador iBest\discador.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\winmds.exeC:\Arquivos de programas\Internet Explorer\IEXPLORE.EXEC:\WINDOWS\system32\winmds.exeC:\Documents and Settings\Mauro\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.aspO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dllO2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [PCTVOICE] pctspk.exeO4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exeO4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exeO4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /backgroundO8 - Extra context menu item: Download All by FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htmO8 - Extra context menu item: Download using FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htmO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exeO14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.aspO17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exeO23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exeO23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde Hiro!

 

>@< Faça o download do ComboFix.

>@< Baixe-o para o Desktop!

>@< Feche todas as janelas e execute a ferramenta!

>@< Abrirá a janela Auto Scan. Aguarde!

>@< Digite a opção para continuar < Enter >

>@< Aguarde a conclusão!

>@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 07-08-25.2 - "Mauro" 2007-08-26 20:25:14.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.77 [GMT -3:00]

* Created a new restore point

 

 

((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))

 

 

2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-08-25 02:59 356,159 -ra------ C:\WINDOWS\system32\drivers\ptserial.sys

2007-08-25 02:59 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe

2007-08-25 02:59 125,440 -ra------ C:\WINDOWS\system32\runpct.exe

2007-08-25 02:59 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat

2007-08-25 02:54 <DIR> d-------- C:\WINDOWS\PCTEL

2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe

2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe

2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe

2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe

2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe

2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe

2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe

2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet

2007-08-23 02:06 <DIR> d-------- C:\VundoFix Backups

2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy

2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007

2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio

2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv

2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus

2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL

2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2007-08-20 00:32 11,342 --a------ C:\WINDOWS\system32\winmds.exe

2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule

2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS

2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

2007-08-16 07:39 <DIR> d-------- C:\WINDOWS\system32\PreInstall

2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$

2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData

2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead

2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2007-08-14 14:36 <DIR> d-------- C:\WINDOWS\RegisteredPackages

2007-08-14 14:24 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution

2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update

2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys

2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys

2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys

2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys

2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software

2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools

2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer

2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information

2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime

2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod

2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield

2007-08-14 12:56 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent

2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent

2007-08-14 01:25 <DIR> d-------- C:\Downloads

2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda

2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet

2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest

2007-08-14 01:12 <DIR> d--hs---- C:\RECYCLER

2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21

2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll

2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys

2007-08-13 23:53 801,778 -ra------ C:\WINDOWS\system32\drivers\vpctcom.sys

2007-08-13 23:53 703,673 -ra------ C:\WINDOWS\system32\drivers\vmodem.sys

2007-08-13 23:53 70,320 -ra------ C:\WINDOWS\system32\drivers\vvoice.sys

2007-08-13 23:53 50,040 --------- C:\WINDOWS\system32\ptPTT.dat

2007-08-13 23:53 308 --a------ C:\WINDOWS\system32\pthsp.dat

2007-08-13 23:53 180,224 -ra------ C:\WINDOWS\system32\pctspk.exe

2007-08-13 23:53 155,648 -ra------ C:\WINDOWS\system32\ptsetup.dll

2007-08-13 23:53 131,072 -ra------ C:\WINDOWS\system32\ptuninst.exe

2007-08-13 23:50 2,097,152 --ah----- C:\DOCUME~1\Mauro\NTUSER.DAT

2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo

2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT

2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais

2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\SoftwareDistribution

2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\Prefetch

2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Dados de aplicativos

2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Dados de aplicativos

2007-08-13 23:44 10,240 --a------ C:\WINDOWS\system32\change.exe

2007-08-13 23:42 229,376 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT

2007-08-13 23:42 0 -rahs---- C:\MSDOS.SYS

2007-08-13 23:42 0 -rahs---- C:\IO.SYS

2007-08-13 23:42 0 --a------ C:\CONFIG.SYS

2007-08-13 23:42 0 --a------ C:\AUTOEXEC.BAT

2007-08-13 23:42 <DIR> d-------- C:\WINDOWS\system32\xircom

2007-08-13 23:42 <DIR> d-------- C:\Arquivos de programas\microsoft frontpage

2007-08-13 23:41 112,128 --a------ C:\WINDOWS\system32\mapi32.dll

2007-08-13 23:40 <DIR> dr------- C:\WINDOWS\Offline Web Pages

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll

2007-08-14 23:54 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin

2007-08-14 23:52 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin

--------- C:\Arquivos de programas\Serviços on-line

--------- C:\Arquivos de programas\Arquivos comuns\Serviços

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45]

"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59]

"NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]

"ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23]

"Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-08-21 20:24]

"PCTVOICE"="pctspk.exe" [2003-10-30 09:12 C:\WINDOWS\system32\pctspk.exe]

"PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" []

"iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56]

 

R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys

R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys

 

*Newly Created Service* - CATCHME

 

Contents of the 'Scheduled Tasks' folder

2007-08-23 03:01:04 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-24 15:00:00 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 16:00:00 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 17:00:00 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 18:00:00 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 19:00:00 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 20:00:00 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 21:00:00 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-25 04:00:00 C:\WINDOWS\Tasks\At2.job

2007-08-26 22:00:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-21 23:01:03 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-25 02:00:00 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-23 11:25:13 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 04:39:06 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 05:47:43 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 06:42:25 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 17:50:35 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 05:00:00 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-23 11:25:13 C:\WINDOWS\Tasks\At30.job

2007-08-23 11:25:13 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe

2007-08-23 11:25:13 C:\WINDOWS\Tasks\At32.job

2007-08-20 03:32:35 C:\WINDOWS\Tasks\At33.job

2007-08-20 03:32:35 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe

2007-08-20 03:32:35 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe

2007-08-20 03:32:35 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe

2007-08-24 17:39:14 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe

2007-08-26 21:03:05 C:\WINDOWS\Tasks\At38.job

2007-08-26 21:03:06 C:\WINDOWS\Tasks\At39.job

2007-08-25 06:00:00 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-26 21:03:06 C:\WINDOWS\Tasks\At40.job

2007-08-26 21:03:06 C:\WINDOWS\Tasks\At41.job

2007-08-26 20:00:00 C:\WINDOWS\Tasks\At42.job

2007-08-26 21:00:00 C:\WINDOWS\Tasks\At43.job

2007-08-26 22:24:54 C:\WINDOWS\Tasks\At44.job

2007-08-21 23:30:22 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe

2007-08-20 03:32:36 C:\WINDOWS\Tasks\At46.job - C:\WINDOWS\system32\winmds.exe

2007-08-20 03:32:36 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 03:56:57 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\winmds.exe

2007-08-25 07:00:01 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-23 08:00:01 C:\WINDOWS\Tasks\At6.job

2007-08-23 09:00:02 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-23 10:00:00 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-20 03:21:12 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\system32\7628y8S6.exe

2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe

2007-08-26 23:20:39 C:\WINDOWS\Tasks\Symantec NetDetect.job

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-08-26 20:27:33

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-08-26 20:28:56

 

--- E O F ---

 

 

 

Ai o do HJT atualizado:

 

Logfile of HijackThis v1.99.1

Scan saved at 20:30:39, on 26/8/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Discador iBest\baloon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Reboot.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

Ai Dig obrigado pela ajuda e desculpe pela demora é que meu modem tava com um problema de drive!

Abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

>@< Faça o download do Clean.zip.

>@< Salve-o no Disco Local-C e descompacte-o aí mesmo,enviando o executável ( clean.cmd ),para o Desktop. ( Atalho! )

>@< Mas não rode-o ainda!

>@< Faça o download do Avenger.

>@< Descompacte-o e crie uma pasta para o programa!Coloque esta pasta no Disco Local-C ou Desktop!

>@< Rode o programa e marque Input script manually.

>@< Clique no ícone da lupa!

 

Files to delete:

C:\WINDOWS\system32\7628y8S6.exe

C:\WINDOWS\system32\winmds.exe

C:\WINDOWS\Tasks\At1.job

C:\WINDOWS\Tasks\At10.job

C:\WINDOWS\Tasks\At11.job

C:\WINDOWS\Tasks\At12.job

C:\WINDOWS\Tasks\At13.job

C:\WINDOWS\Tasks\At14.job

C:\WINDOWS\Tasks\At15.job

C:\WINDOWS\Tasks\At16.job

C:\WINDOWS\Tasks\At17.job

C:\WINDOWS\Tasks\At18.job

C:\WINDOWS\Tasks\At19.job

C:\WINDOWS\Tasks\At2.job

C:\WINDOWS\Tasks\At20.job

C:\WINDOWS\Tasks\At21.job

C:\WINDOWS\Tasks\At22.job

C:\WINDOWS\Tasks\At23.job

C:\WINDOWS\Tasks\At24.job

C:\WINDOWS\Tasks\At25.job

C:\WINDOWS\Tasks\At26.job

C:\WINDOWS\Tasks\At27.job

C:\WINDOWS\Tasks\At28.job

C:\WINDOWS\Tasks\At29.job

C:\WINDOWS\Tasks\At3.job

C:\WINDOWS\Tasks\At30.job

C:\WINDOWS\Tasks\At31.job

C:\WINDOWS\Tasks\At32.job

C:\WINDOWS\Tasks\At33.job

C:\WINDOWS\Tasks\At34.job

C:\WINDOWS\Tasks\At35.job

C:\WINDOWS\Tasks\At36.job

C:\WINDOWS\Tasks\At37.job

C:\WINDOWS\Tasks\At38.job

C:\WINDOWS\Tasks\At39.job

C:\WINDOWS\Tasks\At4.job

C:\WINDOWS\Tasks\At40.job

C:\WINDOWS\Tasks\At41.job

C:\WINDOWS\Tasks\At42.job

C:\WINDOWS\Tasks\At43.job

C:\WINDOWS\Tasks\At44.job

C:\WINDOWS\Tasks\At45.job

C:\WINDOWS\Tasks\At46.job

C:\WINDOWS\Tasks\At47.job

C:\WINDOWS\Tasks\At48.job

C:\WINDOWS\Tasks\At5.job

C:\WINDOWS\Tasks\At6.job

C:\WINDOWS\Tasks\At7.job

C:\WINDOWS\Tasks\At8.job

C:\WINDOWS\Tasks\At9.job

>@< Na caixa que abrir,cole o que foi copiado na área do quote,logo àcima!

>@< Clique em Done.

>@< Clique no ícone do semáforo!

>@< Clique em Ok.

>@< O computador irá reiniciar!

>@< Aproveite êste reboot e entre em Modo de Segurança.

>@< Execute,agora,a ferramenta de limpeza profunda Clean.

>@< Dê um duplo clique em clean.cmd.

>@< Abrir-se-á um Prompt com três opções: Escolha o dois ( 2 )!

>@< Aperte Enter! >> Aperte Enter,novamente! >> Aguarde!

>@< Aperte Enter,novamente!

>@< Surgirá um relatório ( rapport_clean ),que voçê deverá copiar e postar para análise.

>@< Reinicie,normalmente,o computador!

>@< Poste,na sua resposta,um nôvo Log do HijackThis + rapport_clean + Avenger.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá DigRam, tive um pouco de dificuldade no reboot desculpe a ignorância, é que meu mouse não funcionava e os icones tavam gigantescos e nao conseguia acessar eles no tab entao reiniciei de novo e no modo seguro com o tab acabei conseguindo rodar o clean, espero que nao tenha nada dado errado

 

HIJACK

 

Logfile of HijackThis v1.99.1

Scan saved at 00:23:09, on 29/8/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Discador iBest\discador.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: Reboot.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

REPPORT CLEAN

 

eScript executed in Safe Mode

Rapport clean par Malekal_morte - http://www.malekal.com

Script executed in Safe Mode qua 29/08/2007 a 0:16:43,28

 

Microsoft Windows XP [versÆo 5.1.2600]

 

*** Suppression C:

 

*** Suppression C:\WINDOWS\

 

*** Suppression C:\WINDOWS\system32

 

*** Suppression C:\Arquivos de programas

 

*** Deletion of the registry keys successful..

*** End of the report !

 

 

 

AVENGER

 

Logfile of The Avenger version 1, by Swandog46

Running from registry key:

\Registry\Machine\System\CurrentControlSet\Services\acgfsajm

 

*******************

 

Script file located at: \??\C:\WINDOWS\system32\kiisgcij.txt

Script file opened successfully.

 

Script file read successfully

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

 

 

File C:\WINDOWS\system32\7628y8S6.exe not found!

Deletion of file C:\WINDOWS\system32\7628y8S6.exe failed!

 

Could not process line:

C:\WINDOWS\system32\7628y8S6.exe

Status: 0xc0000034

 

File C:\WINDOWS\system32\winmds.exe deleted successfully.

File C:\WINDOWS\Tasks\At1.job deleted successfully.

File C:\WINDOWS\Tasks\At10.job deleted successfully.

File C:\WINDOWS\Tasks\At11.job deleted successfully.

File C:\WINDOWS\Tasks\At12.job deleted successfully.

File C:\WINDOWS\Tasks\At13.job deleted successfully.

File C:\WINDOWS\Tasks\At14.job deleted successfully.

File C:\WINDOWS\Tasks\At15.job deleted successfully.

File C:\WINDOWS\Tasks\At16.job deleted successfully.

File C:\WINDOWS\Tasks\At17.job deleted successfully.

File C:\WINDOWS\Tasks\At18.job deleted successfully.

File C:\WINDOWS\Tasks\At19.job deleted successfully.

File C:\WINDOWS\Tasks\At2.job deleted successfully.

File C:\WINDOWS\Tasks\At20.job deleted successfully.

File C:\WINDOWS\Tasks\At21.job deleted successfully.

File C:\WINDOWS\Tasks\At22.job deleted successfully.

File C:\WINDOWS\Tasks\At23.job deleted successfully.

File C:\WINDOWS\Tasks\At24.job deleted successfully.

File C:\WINDOWS\Tasks\At25.job deleted successfully.

File C:\WINDOWS\Tasks\At26.job deleted successfully.

File C:\WINDOWS\Tasks\At27.job deleted successfully.

File C:\WINDOWS\Tasks\At28.job deleted successfully.

File C:\WINDOWS\Tasks\At29.job deleted successfully.

File C:\WINDOWS\Tasks\At3.job deleted successfully.

File C:\WINDOWS\Tasks\At30.job deleted successfully.

File C:\WINDOWS\Tasks\At31.job deleted successfully.

File C:\WINDOWS\Tasks\At32.job deleted successfully.

File C:\WINDOWS\Tasks\At33.job deleted successfully.

File C:\WINDOWS\Tasks\At34.job deleted successfully.

File C:\WINDOWS\Tasks\At35.job deleted successfully.

File C:\WINDOWS\Tasks\At36.job deleted successfully.

File C:\WINDOWS\Tasks\At37.job deleted successfully.

File C:\WINDOWS\Tasks\At38.job deleted successfully.

File C:\WINDOWS\Tasks\At39.job deleted successfully.

File C:\WINDOWS\Tasks\At4.job deleted successfully.

File C:\WINDOWS\Tasks\At40.job deleted successfully.

File C:\WINDOWS\Tasks\At41.job deleted successfully.

File C:\WINDOWS\Tasks\At42.job deleted successfully.

File C:\WINDOWS\Tasks\At43.job deleted successfully.

File C:\WINDOWS\Tasks\At44.job deleted successfully.

File C:\WINDOWS\Tasks\At45.job deleted successfully.

File C:\WINDOWS\Tasks\At46.job deleted successfully.

File C:\WINDOWS\Tasks\At47.job deleted successfully.

File C:\WINDOWS\Tasks\At48.job deleted successfully.

File C:\WINDOWS\Tasks\At5.job deleted successfully.

File C:\WINDOWS\Tasks\At6.job deleted successfully.

File C:\WINDOWS\Tasks\At7.job deleted successfully.

File C:\WINDOWS\Tasks\At8.job deleted successfully.

File C:\WINDOWS\Tasks\At9.job deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

Por favor, me ajudem, meu norton ta acusando os trojans C:\WINDOWS\WebAssist.dll e C:\WINDOWS\system32\7628y8S6.exe sendo que este último pipoaca no nortn direto e essa porcaria não consegue reparar nenhum deles.

>@< Esse problema,ainda,lhe ocorre?

>@< Procure atualizar o seu Antivírus ( Norton ),pois falhas ocorridas no LiveUpdate,ocasionam essas pop-ups.

>@< Caso não possua suporte ( Assistência Remota da Symantec ),para baixar as últimas atualizações,do LiveUpdate,esses problemas,tendem à piorar.

>@< Sugiro que instale um bom Antivírus,Free,e desinstale o Norton.Se o mesmo estiver sem suporte,é claro!

____________________

 

>@< Abra o HijackThis e,com todas as janelas fechadas,dê Fix,nesta entrada:

 

O4 - Global Startup: Reboot.exe

 

>@< Faça uma busca aos arquivos,em destaque:

 

Reboot.exe

 

C:\WINDOWS\system32\7628y8S6.exe

 

>@< Caso os encontre,pode deletar!

____________________

 

>@< Execute,novamente,o ComboFix,e poste o relatório + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá DigRam!

O único reboot.exe que u encontrei foi este backup-20070829-182357-799-Reboot que eu acho que foi gerado pelo avenger, me diz se eu tenho que deletar ele? O Outro arquivo não foi encontrado e dei um fix no global..

 

O meu Live update tá atualizada com a data de 31/08/07, so o liveupdate do windows é que não ta atualizado. Mas foi fazer isso em breve e a unica popup que ainda aparece é uma bem pequenininha e ela é gerada pelo ibest do nada.

 

Ai vão os logs

 

HIJACK

 

Logfile of HijackThis v1.99.1

Scan saved at 06:51:26, on 1/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Discador iBest\baloon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Oi Internet\discaoi.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

COMOBOFIX

 

ComboFix 07-08-25.2 - "Mauro" 2007-09-01 6:52:40.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.110 [GMT -3:00]

 

 

((((((((((((((((((((((((( Files Created from 2007-08-01 to 2007-09-01 )))))))))))))))))))))))))))))))

 

 

2007-08-29 00:05 <DIR> d-------- C:\WINDOWS\CSC

2007-08-29 00:03 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT

2007-08-29 00:03 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dados de aplicativos

2007-08-29 00:03 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Iniciar

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Modelos

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configura‡äes locais

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de rede

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de impressÆo

2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Meus documentos

2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos

2007-08-28 23:28 <DIR> d-------- C:\clean

2007-08-27 17:42 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat

2007-08-27 17:41 50,040 --------- C:\WINDOWS\system32\ptPTT.dat

2007-08-27 17:41 356,159 --a------ C:\WINDOWS\system32\drivers\ptserial.sys

2007-08-27 17:41 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe

2007-08-27 17:41 308 --a------ C:\WINDOWS\system32\pthsp.dat

2007-08-27 17:41 155,648 --a------ C:\WINDOWS\system32\ptsetup.dll

2007-08-27 17:41 125,440 --a------ C:\WINDOWS\system32\runpct.exe

2007-08-27 17:41 <DIR> d-------- C:\WINDOWS\PCTEL

2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe

2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe

2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe

2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe

2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe

2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe

2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe

2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet

2007-08-23 02:06 <DIR> d-------- C:\VundoFix Backups

2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy

2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007

2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio

2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv

2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus

2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL

2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule

2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS

2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

2007-08-16 07:39 <DIR> d-------- C:\WINDOWS\system32\PreInstall

2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$

2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData

2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead

2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2007-08-14 14:36 <DIR> d-------- C:\WINDOWS\RegisteredPackages

2007-08-14 14:24 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution

2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update

2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys

2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys

2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys

2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys

2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software

2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools

2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer

2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information

2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime

2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod

2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield

2007-08-14 12:56 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent

2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent

2007-08-14 01:25 <DIR> d-------- C:\Downloads

2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda

2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet

2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest

2007-08-14 01:12 <DIR> d--hs---- C:\RECYCLER

2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21

2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll

2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys

2007-08-13 23:53 801,778 --a------ C:\WINDOWS\system32\drivers\vpctcom.sys

2007-08-13 23:53 703,673 --a------ C:\WINDOWS\system32\drivers\vmodem.sys

2007-08-13 23:53 70,320 --a------ C:\WINDOWS\system32\drivers\vvoice.sys

2007-08-13 23:53 180,224 --a------ C:\WINDOWS\system32\pctspk.exe

2007-08-13 23:53 131,072 --a------ C:\WINDOWS\system32\ptuninst.exe

2007-08-13 23:50 3,145,728 --ah----- C:\DOCUME~1\Mauro\NTUSER.DAT

2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo

2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT

2007-08-13 23:48 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais

2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\SoftwareDistribution

2007-08-13 23:48 <DIR> d-------- C:\WINDOWS\Prefetch

2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Dados de aplicativos

2007-08-13 23:48 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Dados de aplicativos

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll

2007-08-14 23:54 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin

2007-08-14 23:52 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin

--------- C:\Arquivos de programas\Serviços on-line

--------- C:\Arquivos de programas\Arquivos comuns\Serviços

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45]

"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59]

"NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]

"ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23]

"Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-08-21 20:24]

"PCTVOICE"="pctspk.exe" [2003-10-30 09:12 C:\WINDOWS\system32\pctspk.exe]

"PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" []

"iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56]

 

R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys

R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys

 

 

Contents of the 'Scheduled Tasks' folder

2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe

2007-09-01 06:50:55 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Arquivos de programas\Symantec\LiveUpdate\NDETECT.EXE

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-09-01 06:54:50

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-09-01 6:56:25

C:\ComboFix2.txt ... 2007-08-29 19:48

C:\ComboFix3.txt ... 2007-08-26 20:28

 

--- E O F ---

 

 

Obrigado pela ajuda!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

O único reboot.exe que u encontrei foi este backup-20070829-182357-799-Reboot que eu acho que foi gerado pelo avenger, me diz se eu tenho que deletar ele? O Outro arquivo não foi encontrado e dei um fix no global..

>@< Pode deletar a pasta,de backups,do Avenger.

 

O meu Live update tá atualizada com a data de 31/08/07, so o liveupdate do windows é que não ta atualizado. Mas foi fazer isso em breve e a unica popup que ainda aparece é uma bem pequenininha e ela é gerada pelo ibest do nada.

>@< Tente reconfigurar o Bloqueador de Pop-ups,do IE6,para Médio.Já,em Alto,deverá adicionar os Sites que queira permitir,as Pop-ups.

__________________________

 

>@< Faça o download do CCleaner.

>@< Baixe-o para o Desktop!

>@< Abra o programa e clique em Executar cleaner.

>@< Terminando,clique em Erros >> Procurar erros >> Corrigir erros.

__________________________

 

Estando tudo Ok,com o computador,crie um Ponto de Restauração do Sistema,Limpo!

Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok.

Depois,desmarque novamente! >> Aplicar >> Ok.

Para maiores detalhes,vá em:< Docs >

>@< Algum problema,ainda,com o computador?

>@< Bom trabalho!

>@< Log Limpo!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá DigRam, fiz td o que voce falou mas alguns dias depois me aparece outro virus e esse parece pior pq ele desliga minha conexão e cria um nova e disca um numero que deve ser internacional ai vai o log do hijack e do combofix. Se poder me ajudar td bem se não vou formatar mesmo esse computador e comprar o kaspersky, pq esse norton é mesmo que nada.

 

 

Logfile of HijackThis v1.99.1

Scan saved at 15:30:02, on 6/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe

C:\Arquivos de programas\Discador iBest\baloon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

 

COMBOFIX

 

ComboFix 07-08-30.3 - "Mauro" 2007-09-06 15:19:01.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.69 [GMT -3:00]

* Created a new restore point

 

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\Arquivos de programas\gbplugin\bank.gbl

C:\Arquivos de programas\gbplugin\Bb.gpc

C:\Arquivos de programas\gbplugin\Bb.gpc . . . . failed to delete

C:\Arquivos de programas\gbplugin\gbieh.gmd

C:\WINDOWS\system32\N5hd1t0f.exe

C:\WINDOWS\Tasks.\At1.job

C:\WINDOWS\Tasks.\At10.job

C:\WINDOWS\Tasks.\At11.job

C:\WINDOWS\Tasks.\At12.job

C:\WINDOWS\Tasks.\At13.job

C:\WINDOWS\Tasks.\At14.job

C:\WINDOWS\Tasks.\At15.job

C:\WINDOWS\Tasks.\At16.job

C:\WINDOWS\Tasks.\At17.job

C:\WINDOWS\Tasks.\At18.job

C:\WINDOWS\Tasks.\At19.job

C:\WINDOWS\Tasks.\At2.job

C:\WINDOWS\Tasks.\At20.job

C:\WINDOWS\Tasks.\At21.job

C:\WINDOWS\Tasks.\At22.job

C:\WINDOWS\Tasks.\At23.job

C:\WINDOWS\Tasks.\At24.job

C:\WINDOWS\Tasks.\At3.job

C:\WINDOWS\Tasks.\At4.job

C:\WINDOWS\Tasks.\At5.job

C:\WINDOWS\Tasks.\At6.job

C:\WINDOWS\Tasks.\At7.job

C:\WINDOWS\Tasks.\At8.job

C:\WINDOWS\Tasks.\At9.job

 

 

((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))

 

 

2007-09-06 15:14 11,854 --a------ C:\WINDOWS\system32\winmds.exe

2007-09-04 23:19 <DIR> d--h----- C:\WINDOWS\PIF

2007-09-04 22:49 <DIR> d-------- C:\Arquivos de programas\CCleaner

2007-09-04 13:59 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Help

2007-09-03 08:20 <DIR> d-------- C:\Arquivos de programas\GbPlugin

2007-09-03 08:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\GbPlugin

2007-09-02 11:01 362,878 -ra------ C:\WINDOWS\system32\drivers\ptserial.sys

2007-09-02 11:01 323,584 --a------ C:\WINDOWS\system32\PV92Tray.exe

2007-09-02 11:01 125,440 -ra------ C:\WINDOWS\system32\runpct.exe

2007-09-02 11:01 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat

2007-09-02 10:54 308 --a------ C:\WINDOWS\system32\pthsp.dat

2007-09-02 10:54 <DIR> d-------- C:\WINDOWS\PCTEL

2007-08-29 00:03 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dados de aplicativos

2007-08-29 00:03 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Iniciar

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Modelos

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configura‡äes locais

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de rede

2007-08-29 00:03 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ambiente de impressÆo

2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Meus documentos

2007-08-29 00:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos

2007-08-28 23:28 <DIR> d-------- C:\clean

2007-08-27 17:41 50,040 --------- C:\WINDOWS\system32\ptPTT.dat

2007-08-27 17:41 159,744 -ra------ C:\WINDOWS\system32\ptsetup.dll

2007-08-26 20:24 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-08-25 02:35 532,480 --a------ C:\WINDOWS\system32\DeleteFiles.exe

2007-08-25 02:35 387,584 --a------ C:\WINDOWS\system32\LostRun.exe

2007-08-25 02:35 382,464 --a------ C:\WINDOWS\system32\Restart.exe

2007-08-25 02:35 374,784 --a------ C:\WINDOWS\system32\RunAP.exe

2007-08-25 02:35 351,232 --a------ C:\WINDOWS\system32\CheckPath.exe

2007-08-25 02:35 306,688 --a------ C:\WINDOWS\IsUninst.exe

2007-08-25 02:34 327,168 --a------ C:\WINDOWS\IsUn0816.exe

2007-08-24 15:45 <DIR> d-------- C:\Arquivos de programas\Oi Internet

2007-08-22 19:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy

2007-08-22 00:54 <DIR> d-------- C:\Arquivos de programas\Enem2007

2007-08-22 00:42 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SWF Studio

2007-08-21 20:24 <DIR> d-------- C:\Arquivos de programas\SymNetDrv

2007-08-21 17:55 <DIR> d-------- C:\Arquivos de programas\Norton AntiVirus

2007-08-21 17:54 83,208 --a------ C:\WINDOWS\system32\S32EVNT1.DLL

2007-08-21 17:54 82,136 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Symantec

2007-08-21 17:54 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2007-08-18 17:07 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys

2007-08-18 17:07 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2007-08-18 15:18 <DIR> d-------- C:\Arquivos de programas\eMule

2007-08-18 14:28 <DIR> d-------- C:\MUSICAS And STUFFS

2007-08-16 07:39 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

2007-08-16 01:10 <DIR> d--h----- C:\WINDOWS\$hf_mig$

2007-08-15 20:39 <DIR> d---s---- C:\DOCUME~1\Mauro\UserData

2007-08-14 14:43 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Ahead

2007-08-14 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Nero

2007-08-14 14:38 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2007-08-14 13:32 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys

2007-08-14 13:07 <DIR> d-------- C:\Arquivos de programas\Avanquest update

2007-08-14 13:06 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys

2007-08-14 13:06 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys

2007-08-14 13:05 24,192 --a------ C:\DOCUME~1\Mauro\usbsermptxp.sys

2007-08-14 13:05 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys

2007-08-14 13:05 22,768 --a------ C:\DOCUME~1\Mauro\usbsermpt.sys

2007-08-14 13:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\BVRP Software

2007-08-14 13:05 <DIR> d-------- C:\Arquivos de programas\Motorola Phone Tools

2007-08-14 13:00 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\Apple Computer

2007-08-14 12:59 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information

2007-08-14 12:59 <DIR> d-------- C:\Arquivos de programas\QuickTime

2007-08-14 12:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Apple Computer

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iTunes

2007-08-14 12:58 <DIR> d-------- C:\Arquivos de programas\iPod

2007-08-14 12:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield

2007-08-14 01:27 <DIR> d-------- C:\DOCUME~1\Mauro\DADOSD~1\uTorrent

2007-08-14 01:27 <DIR> d-------- C:\Arquivos de programas\uTorrent

2007-08-14 01:25 <DIR> d-------- C:\Downloads

2007-08-14 01:20 <DIR> d-------- C:\WINDOWS\system32\ajuda

2007-08-14 01:18 <DIR> d-------- C:\Arquivos de programas\FlashGet

2007-08-14 01:17 <DIR> d-------- C:\Arquivos de programas\Discador iBest

2007-08-13 23:59 <DIR> d-------- C:\Arquivos de programas\Click21

2007-08-13 23:54 175,104 --a--c--- C:\WINDOWS\system32\dllcache\csamsp.dll

2007-08-13 23:54 175,104 --a------ C:\WINDOWS\system32\csamsp.dll

2007-08-13 23:54 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys

2007-08-13 23:54 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys

2007-08-13 23:53 86,016 --a--c--- C:\WINDOWS\system32\dllcache\pctspk.exe

2007-08-13 23:53 804,754 -ra------ C:\WINDOWS\system32\drivers\vpctcom.sys

2007-08-13 23:53 703,737 -ra------ C:\WINDOWS\system32\drivers\vmodem.sys

2007-08-13 23:53 70,384 -ra------ C:\WINDOWS\system32\drivers\vvoice.sys

2007-08-13 23:53 64,605 --a--c--- C:\WINDOWS\system32\dllcache\vvoice.sys

2007-08-13 23:53 604,253 --a--c--- C:\WINDOWS\system32\dllcache\vmodem.sys

2007-08-13 23:53 397,502 --a--c--- C:\WINDOWS\system32\dllcache\vpctcom.sys

2007-08-13 23:53 180,224 -ra------ C:\WINDOWS\system32\pctspk.exe

2007-08-13 23:53 131,072 -ra------ C:\WINDOWS\system32\ptuninst.exe

2007-08-13 23:50 <DIR> dr-h----- C:\DOCUME~1\Mauro\Dados de aplicativos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Meus documentos

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Menu Iniciar

2007-08-13 23:50 <DIR> dr------- C:\DOCUME~1\Mauro\Favoritos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Modelos

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Configura‡äes locais

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de rede

2007-08-13 23:50 <DIR> d--h----- C:\DOCUME~1\Mauro\Ambiente de impressÆo

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\NETWOR~1\Configura‡äes locais

2007-08-13 23:48 <DIR> d--h----- C:\DOCUME~1\LOCALS~1\Configura‡äes locais

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-08-22 00:42 1386496 --a------ C:\WINDOWS\system32\msvbvm60.dll

--------- C:\Arquivos de programas\Serviços on-line

--------- C:\Arquivos de programas\Arquivos comuns\Serviços

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"iTunesHelper"="C:\Arquivos de programas\iTunes\iTunesHelper.exe" [2006-02-23 15:45]

"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-08-14 12:59]

"NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-09-05 21:19]

"ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2003-08-19 16:23]

"Symantec NetDriver Monitor"="C:\ARQUIV~1\SYMNET~1\SNDMon.exe" [2007-09-05 21:32]

"PCTVOICE"="pctspk.exe" [2004-01-30 08:33 C:\WINDOWS\system32\pctspk.exe]

"PV92TRAY"="PV92Tray.exe" [2003-10-30 13:09 C:\WINDOWS\system32\PV92Tray.exe]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UltraDiscador iBest"="C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe" []

"iBest.baloon"="C:\Arquivos de programas\Discador iBest\baloon.exe" [2005-03-14 21:14]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:56]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= C:\Arquivos de programas\GbPlugin\gbieh.dll [2007-06-25 09:24 332616]

 

R2 GbpSv;Gbp Service;C:\Arquivos de programas\GbPlugin\GbpSv.exe

R3 SiS300i;SiS300i;C:\WINDOWS\system32\DRIVERS\sis300ip.sys

R3 SiS7018;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\ac97sis.sys

 

 

Contents of the 'Scheduled Tasks' folder

2007-09-05 18:13:04 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:05 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:05 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:05 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:05 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:05 C:\WINDOWS\Tasks\At30.job

2007-09-04 16:55:25 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 16:55:25 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:55 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 17:00:03 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:00:01 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 22:58:33 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:56 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 22:58:36 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\winmds.exe

2007-09-04 03:25:56 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 16:37:17 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 00:00:11 C:\WINDOWS\Tasks\At46.job

2007-09-05 18:13:07 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe

2007-09-05 18:13:07 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:02 C:\WINDOWS\Tasks\At49.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At50.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At51.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At52.job

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At53.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At54.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At55.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At56.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At57.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At58.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At59.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At60.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At61.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At62.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At63.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At64.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At65.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At66.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At67.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At68.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At69.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At70.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At71.job - C:\WINDOWS\system32\winmds.exe

2007-09-06 18:15:03 C:\WINDOWS\Tasks\At72.job - C:\WINDOWS\system32\winmds.exe

2007-08-21 22:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Verificar o meu computador.job - C:\ARQUIV~1\NORTON~1\Navw32.exe

2007-09-06 18:23:41 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Arquivos de programas\Symantec\LiveUpdate\NDETECT.EXE

 

**************************************************************************

 

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2007-09-06 15:24:20

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-09-06 15:26:24 - machine was rebooted

C:\ComboFix-quarantined-files.txt ... 2007-09-06 15:26

 

--- E O F ---

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

>@< Delete o antigo relatório do Avenger.

>@< Rode o programa e marque Input script manually.

>@< Clique no ícone da lupa!

 

Files to delete:

C:\WINDOWS\system32\winmds.exe

C:\WINDOWS\Tasks\At25.job

C:\WINDOWS\Tasks\At26.job

C:\WINDOWS\Tasks\At27.job

C:\WINDOWS\Tasks\At28.job

C:\WINDOWS\Tasks\At29.job

C:\WINDOWS\Tasks\At30.job

C:\WINDOWS\Tasks\At31.job

C:\WINDOWS\Tasks\At32.job

C:\WINDOWS\Tasks\At33.job

C:\WINDOWS\Tasks\At34.job

C:\WINDOWS\Tasks\At35.job

C:\WINDOWS\Tasks\At36.job

C:\WINDOWS\Tasks\At37.job

C:\WINDOWS\Tasks\At38.job

C:\WINDOWS\Tasks\At39.job

C:\WINDOWS\Tasks\At40.job

C:\WINDOWS\Tasks\At41.job

C:\WINDOWS\Tasks\At42.job

C:\WINDOWS\Tasks\At43.job

C:\WINDOWS\Tasks\At44.job

C:\WINDOWS\Tasks\At45.job

C:\WINDOWS\Tasks\At46.job

C:\WINDOWS\Tasks\At47.job

C:\WINDOWS\Tasks\At48.job

C:\WINDOWS\Tasks\At49.job

C:\WINDOWS\Tasks\At50.job

C:\WINDOWS\Tasks\At51.job

C:\WINDOWS\Tasks\At52.job

C:\WINDOWS\Tasks\At53.job

C:\WINDOWS\Tasks\At54.job

C:\WINDOWS\Tasks\At55.job

C:\WINDOWS\Tasks\At56.job

C:\WINDOWS\Tasks\At57.job

C:\WINDOWS\Tasks\At58.job

C:\WINDOWS\Tasks\At59.job

C:\WINDOWS\Tasks\At60.job

C:\WINDOWS\Tasks\At61.job

C:\WINDOWS\Tasks\At62.job

C:\WINDOWS\Tasks\At63.job

C:\WINDOWS\Tasks\At64.job

C:\WINDOWS\Tasks\At65.job

C:\WINDOWS\Tasks\At66.job

C:\WINDOWS\Tasks\At67.job

C:\WINDOWS\Tasks\At68.job

C:\WINDOWS\Tasks\At69.job

C:\WINDOWS\Tasks\At70.job

C:\WINDOWS\Tasks\At71.job

C:\WINDOWS\Tasks\At72.job

>@< Na caixa que abrir,cole o que foi copiado na área do quote,logo àcima!

>@< Clique em Done.

>@< Clique no ícone do semáforo!

>@< Clique em Ok.

>@< O computador irá reiniciar!

________________________

 

>@< Faça um escaneamento OnLine,pelo Panda.

>@< Na página,clique no botão Scan you PC.

>@< Clique em Next.

>@< Digite o seu E-Mail.

>@< Clique em Send.

>@< Finalize clicando em All PC. ( All My Computer )

>@< Aguarde!Pois vai demorar um pouco para concluir o scan.

>@< Terminando,copie o relatório e poste,na sua resposta + HJT,atualizado + Avenger.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

olá DigRam aí vão os logs:

 

 

Incidência Estado Localização

 

Ferramenta potencialmente indesejada:Application/Pskill.K Não desinfectado C:\clean\pskill.exe

Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\ComboFix\nircmd.cfexe

Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\ComboFix\nircmd.exe

Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@acesso.uol.com[1].txt

Spyware:Cookie/YieldManager Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@ad.yieldmanager[2].txt

Spyware:Cookie/Atlas DMT Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@atdmt[1].txt

Spyware:Cookie/Casalemedia Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@casalemedia[2].txt

Spyware:Cookie/Cgi-bin Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@cgi-bin[2].txt

Spyware:Cookie/Sextracker Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@counter14.sextracker[1].txt

Spyware:Cookie/Doubleclick Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@doubleclick[1].txt

Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@ig.com[1].txt

Spyware:Cookie/Sextracker Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@sextracker[2].txt

Spyware:Cookie/Statcounter Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@statcounter[1].txt

Spyware:Cookie/Tribalfusion Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@tribalfusion[1].txt

Spyware:Cookie/Com.com Não desinfectado C:\Documents and Settings\Mauro\Cookies\mauro@uol.com[1].txt

Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\Documents and Settings\Mauro\Desktop\ComboFix.exe[nircmd.exe]

Ferramenta potencialmente indesejada:Application/Pskill.K Não desinfectado C:\Documents and Settings\Mauro\Desktop\Programas\clean.zip[clean/pskill.exe]

Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\Documents and Settings\Mauro\Desktop\Programas\ComboFix.exe[nircmd.exe]

Ferramenta potencialmente indesejada:Application/NirCmd.A Não desinfectado C:\WINDOWS\nircmd.exe

 

 

HIJACK

 

Logfile of HijackThis v1.99.1

Scan saved at 15:52:08, on 12/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Discador iBest\discador.exe

C:\Arquivos de programas\Oi Internet\discaoi.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

O1 - Hosts: 170.66.1.60 www14.bancobrasil.com.br # GbPlugin

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

AVENGER

 

Logfile of The Avenger version 1, by Swandog46

Running from registry key:

\Registry\Machine\System\CurrentControlSet\Services\wkilvajm

 

*******************

 

Script file located at: \??\C:\WINDOWS\skryneqm.txt

Script file opened successfully.

 

Script file read successfully

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

File C:\WINDOWS\system32\winmds.exe deleted successfully.

File C:\WINDOWS\Tasks\At25.job deleted successfully.

File C:\WINDOWS\Tasks\At26.job deleted successfully.

File C:\WINDOWS\Tasks\At27.job deleted successfully.

File C:\WINDOWS\Tasks\At28.job deleted successfully.

File C:\WINDOWS\Tasks\At29.job deleted successfully.

File C:\WINDOWS\Tasks\At30.job deleted successfully.

File C:\WINDOWS\Tasks\At31.job deleted successfully.

File C:\WINDOWS\Tasks\At32.job deleted successfully.

File C:\WINDOWS\Tasks\At33.job deleted successfully.

File C:\WINDOWS\Tasks\At34.job deleted successfully.

File C:\WINDOWS\Tasks\At35.job deleted successfully.

File C:\WINDOWS\Tasks\At36.job deleted successfully.

File C:\WINDOWS\Tasks\At37.job deleted successfully.

File C:\WINDOWS\Tasks\At38.job deleted successfully.

File C:\WINDOWS\Tasks\At39.job deleted successfully.

File C:\WINDOWS\Tasks\At40.job deleted successfully.

File C:\WINDOWS\Tasks\At41.job deleted successfully.

File C:\WINDOWS\Tasks\At42.job deleted successfully.

File C:\WINDOWS\Tasks\At43.job deleted successfully.

File C:\WINDOWS\Tasks\At44.job deleted successfully.

File C:\WINDOWS\Tasks\At45.job deleted successfully.

File C:\WINDOWS\Tasks\At46.job deleted successfully.

File C:\WINDOWS\Tasks\At47.job deleted successfully.

File C:\WINDOWS\Tasks\At48.job deleted successfully.

File C:\WINDOWS\Tasks\At49.job deleted successfully.

File C:\WINDOWS\Tasks\At50.job deleted successfully.

File C:\WINDOWS\Tasks\At51.job deleted successfully.

File C:\WINDOWS\Tasks\At52.job deleted successfully.

File C:\WINDOWS\Tasks\At53.job deleted successfully.

File C:\WINDOWS\Tasks\At54.job deleted successfully.

File C:\WINDOWS\Tasks\At55.job deleted successfully.

File C:\WINDOWS\Tasks\At56.job deleted successfully.

File C:\WINDOWS\Tasks\At57.job deleted successfully.

File C:\WINDOWS\Tasks\At58.job deleted successfully.

File C:\WINDOWS\Tasks\At59.job deleted successfully.

File C:\WINDOWS\Tasks\At60.job deleted successfully.

File C:\WINDOWS\Tasks\At61.job deleted successfully.

File C:\WINDOWS\Tasks\At62.job deleted successfully.

File C:\WINDOWS\Tasks\At63.job deleted successfully.

File C:\WINDOWS\Tasks\At64.job deleted successfully.

File C:\WINDOWS\Tasks\At65.job deleted successfully.

File C:\WINDOWS\Tasks\At66.job deleted successfully.

File C:\WINDOWS\Tasks\At67.job deleted successfully.

File C:\WINDOWS\Tasks\At68.job deleted successfully.

File C:\WINDOWS\Tasks\At69.job deleted successfully.

File C:\WINDOWS\Tasks\At70.job deleted successfully.

File C:\WINDOWS\Tasks\At71.job deleted successfully.

File C:\WINDOWS\Tasks\At72.job deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

>@< Crie um ponto de restauração,antes de executar êstes procedimentos!

>@< Configure o Windows para que mostre: Ver todos os Arquivos,até os ocultos!

>@< Desabilite as proteções residentes de AntiVírus e AntiSpywares!

>@< Faça o download da EliStarA.

>@< Baixe-a para o Desktop!

>@< Faça o download do EliTriIP.

>@< Baixe-o para o Desktop!

>@< Ps: Ambas,as ferramentas,estarão na página descargas ( Descargas > Utilidades SATINFO ).

>@< Selecione as ferramentas ( Uma por vez! ) e clique no pé da página,no botão Descargar xxx.Onde xxx é a denominação da ferramenta escolhida!

>@< Faça o download do Clean.

>@< Salve-o no Disco Local-C e descompacte-o aí mesmo,enviando o executável para o Desktop! ( Atalho. )

>@< O executável é um ícone denominado: clean.cmd

>@< Reinicie o computador e entre em Modo de Segurança.

>@< Execute,primeiro,a ferramenta: EliStartA.

>@< Vá ao seu ícone e execute-a!

>@< Aceite as condições propostas e aguarde o término do scan.Aguarde!Pois,pode demorar alguns minutos.

>@< Terminando,execute a ferramenta EliTriIP.

>@< O scan desta ferramenta é mais rápido!

>@< Terminando,execute o programa de limpeza profunda ( clean ) com um duplo clique no seu executável.

>@< Abrir-se-á um prompt com três opções: Escolha o dois ( 2 )!

>@< Aperte Enter! >> Aperte Enter,novamente! >> Aguarde!

>@< Aperte Enter,novamente!

>@< Surgirá um relatório ( rapport_clean ),que voçê deverá copiar e postar para análise.

____________________________

 

>@< Poste o relatório infoSAT.txt que está na raíz C:\ ( Disco Local-C ) + rapport_clean.

>@< Poste,também,um nôvo Log do HijackThis,feito em Modo Normal,na sua resposta.

>@< Ps: A ferramenta EliStarA,deletará (Opcional! ) a sua página inicial!Posteriormente,voçê à configurará novamente.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam! Aí vão os logs:

 

Logfile of HijackThis v1.99.1

Scan saved at 10:57:47, on 15/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\Comodo\Firewall\CPF.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Discador iBest\discador.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Oi Internet\discaOi.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

INFOSAT

 

 

Logfile of HijackThis v1.99.1

Scan saved at 10:57:47, on 15/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\Arquivos de programas\Comodo\Firewall\CPF.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Discador iBest\discador.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Oi Internet\discaOi.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

RAPPORTCLEAN

 

Script executed in Safe Mode

Rapport clean par Malekal_morte - http://www.malekal.com

Script executed in Safe Mode --- 14/09/2007 a 20:39:32,07

 

Microsoft Windows XP [versÆo 5.1.2600]

 

*** Suppression C:

 

*** Suppression C:\WINDOWS\

 

*** Suppression C:\WINDOWS\system32

 

*** Suppression C:\Arquivos de programas

 

*** Deletion of the registry keys successful..

*** End of the report !

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia Hiro!

 

>@< Faltou postar infoSat.txt e,no lugar do mesmo,foi repetido o Log do HijackThis.

>@< Caso não mais o possua,não rode as ferramentas para obtê-lo!

____________________

 

>@< Faça êste escaneamento de limpeza.

>@< Faça um escaneamento OnLine em < BitDefender > e poste o relatório.

>@< Clique em BitDefender ( Scan OnLine ).

>@< Abrirá a página: < BitDefender OnLine Scanner >

>@< Clique em I Agree.

>@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan.

>@< Poste,então: Relatório do scan OnLine + infoSat.txt + Log do HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá DigRam, ai vao os logs:

 

 

Logfile of HijackThis v1.99.1

Scan saved at 21:55:49, on 17/9/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\system32\pctspk.exe

C:\WINDOWS\system32\PV92Tray.exe

C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe

C:\Arquivos de programas\Comodo\Firewall\CPF.exe

C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

C:\Arquivos de programas\Discador iBest\discador.exe

C:\Arquivos de programas\Oi Internet\discaOi.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Documents and Settings\Mauro\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\UltraDiscador iBest\bho.dll (file missing)

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O3 - Toolbar: Discador iBest - {4F869C58-D71D-4850-8BDD-7B5CDF8EC911} - C:\Arquivos de programas\UltraDiscador iBest\ibestbar.dll (file missing)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Arquivos de programas\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\ARQUIV~1\SYMNET~1\SNDMon.exe

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_02\bin\jusched.exe"

O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Arquivos de programas\Comodo\Firewall\CPF.exe" /background

O4 - HKCU\..\Run: [ultraDiscador iBest] "C:\Arquivos de programas\UltraDiscador iBest\autoupdate.exe"

O4 - HKCU\..\Run: [iBest.baloon] "C:\Arquivos de programas\Discador iBest\baloon.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2115EC7C-1724-4DCA-81F5-3E230FE694D7}: NameServer = 200.222.0.34 200.202.193.75

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Arquivos de programas\Comodo\Firewall\cmdagent.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Serviço de proteção automática do Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\navapsvc.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Arquivos de programas\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

 

 

 

INFOSAT

 

 

Fri Sep 14 20:26:03 2007

EliStartPage v14.64 ©2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Eliminado Servicio, "GbpSv"

No detectado Parche MS06-001 de Microsoft instalado. (WMF)

No detectado Parche MS06-070 de Microsoft instalado. (SServidor)

ALERTA. WindowsUpdate Incompleto.

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

 

Fri Sep 14 20:27:35 2007

EliStartPage v14.64 ©2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

C:\ComboFix\NIRCMD.EXE --> Eliminado, Tool-NirCmd

C:\WINDOWS\NIRCMD.EXE --> Eliminado, Tool-NirCmd

 

Fri Sep 14 20:35:54 2007

EliTriIP v3.88 ©2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Acción Directa):

No detectado Parche MS06-001 de Microsoft instalado. (WMF)

No detectado Parche MS06-070 de Microsoft instalado. (SServidor)

ALERTA. WindowsUpdate Incompleto.

 

Fri Sep 14 20:36:00 2007

EliTriIP v3.88 ©2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

C:\Arquivos de programas\Motorola Phone Tools\widcomm\Autorun.inf --> Eliminado, BackDoor.CMQ (inf)

 

 

 

SCAN ONLINE

 

BitDefender Online Scanner

 

 

 

Scan report generated at: Mon, Sep 17, 2007 - 21:49:27

 

 

 

 

 

Scan path: A:\;C:\;D:\;E:\;F:\;

 

 

 

 

 

 

 

Statistics

 

Time

01:03:02

 

Files

93015

 

Folders

2451

 

Boot Sectors

2

 

Archives

1186

 

Packed Files

3583

 

 

 

 

Results

 

Identified Viruses

5

 

Infected Files

12

 

Suspect Files

0

 

Warnings

0

 

Disinfected

0

 

Deleted Files

14

 

 

 

 

Engines Info

 

Virus Definitions

810674

 

Engine build

AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

 

Scan plugins

14

 

Archive plugins

38

 

Unpack plugins

7

 

E-mail plugins

6

 

System plugins

1

 

 

 

 

Scan Settings

 

First Action

Disinfect

 

Second Action

Delete

 

Heuristics

Yes

 

Enable Warnings

Yes

 

Scanned Extensions

*;

 

Exclude Extensions

 

 

Scan Emails

Yes

 

Scan Archives

Yes

 

Scan Packed

Yes

 

Scan Files

Yes

 

Scan Boot

Yes

 

 

 

 

Scanned File

Status

 

C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2)

Infected with: Trojan.Dialer.AEN

 

C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2)

Disinfection failed

 

C:\Arquivos de programas\Norton AntiVirus\Quarantine\4F4A23D0.exe=>(Quarantine-2)

Deleted

 

C:\avenger\backup.zip=>avenger/winmds.exe

Infected with: MemScan:Trojan.Dialer.VUB

 

C:\avenger\backup.zip=>avenger/winmds.exe

Disinfection failed

 

C:\avenger\backup.zip=>avenger/winmds.exe

Deleted

 

C:\avenger\backup.zip

Updated

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe

Infected with: Win32.Cuter.A

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020152.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe

Infected with: Win32.Cuter.A

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020153.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe

Infected with: Trojan.Dialer.AEN

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP58\A0020159.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe

Infected with: GenPack:Trojan.Downloader.JIYC

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP59\A0020198.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe

Infected with: GenPack:Trojan.Downloader.JIYC

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020347.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2)

Infected with: Trojan.Dialer.AEN

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2)

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020379.exe=>(Quarantine-2)

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe

Infected with: GenPack:Trojan.Downloader.JIYC

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020394.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe

Infected with: MemScan:Trojan.Dialer.VUB

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP60\A0020509.exe

Deleted

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2)

Infected with: Trojan.Dialer.AEN

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2)

Disinfection failed

 

C:\System Volume Information\_restore{682ED665-028B-4525-BBD4-08624CB3DD24}\RP67\A0023931.exe=>(Quarantine-2)

Deleted

 

D:\Backup\Programas e recibos\btlite.exe

Infected with: Trojan.Dropper.Agent.LA

 

D:\Backup\Programas e recibos\btlite.exe

Disinfection failed

 

D:\Backup\Programas e recibos\btlite.exe

Delete failed

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite Hiro!

 

>@< Reinicie o computador,e entre em Modo Seguro.

 

D:\Backup\Programas e recibos\btlite.exe << Delete êste arquivo!

 

>@< Reinicie em Modo Normal.

_______________________________

 

BAIXE

 

< Advanced WindowsCare >

 

>@< Salve-o no Desktop ou Arquivos de Programa.

>@< Este programa de limpeza,é fantástico,pois além de remover: Cookies,históricos e temporários.Procura,também,otimizar o SO e remover alguns Spywares.

>@< Recomendo o programa,a todos àqueles que têm problemas de lentidão,sem nenhuma causa aparente!

 

TUTORIAL

 

>1< Antes de rodar o programa,atualize o Banco de Dados: Clique em Estado.

>2< Clique em Atualizar Agora. >> Aguarde!

>3< Terminando,vá em Mais >> Clique em Limpador de Memória.

>@< Abrir-se-á a janela: Limpador de Memória.

>@< Clique em Limpar agora! Aguarde...

>@< Surgirá uma mensagem,após o término,informando a quantidade de memória liberada.

>@< Clique em Sair.

>4< Agora,o utilitário está pronto para limpar e otimizar o seu computador.

>5< Abra o programa e clique em Start >> Clique em Scan. ( Analisar )

>6< Terminando,aparecerão em vermelho,os ítens a serem removidos.

>7< Clique,agora,no botão Care. ( Reparar )

>8< Caso queira monitorar,o que será removido,clique para cada ítem,em: Show Details,antes de clicar em Reparar.

>9< Terminando,reinicie o computador e execute,novamente,o Advanced WindowsCare.

___________________

 

>@< Poste,na sua resposta,um novo Log do HJT e,informe com está o PC.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.