Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

MOROCK

[Arquivado] verificação do log Hijack... possibilidade de vi

Recommended Posts

Aê Galera, eu tava fazendo um scan em meu PC com o antivirus Symantec so para ver se meu PC tava OK, mas ele acusou um BACKDOOR TROJAN, aê eu botei pra deletar, mas podem haver outras coisas... Por isso vou postar o log do Hijack akí pra vcs analisarem e para ver se ha possiveis riscos...

 

 

Log do Hijack...

 

 

Logfile of HijackThis v1.99.1

Scan saved at 19:32:14, on 12/2/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe

C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\nvsvc32.exe

C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe

C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\ARQUIV~1\SYMANT~1\VPTray.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe

C:\Arquivos de programas\D-Tools\daemon.exe

C:\Arquivos de programas\Winamp\winampa.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\Arquivos de programas\Netropa\Onscreen Display\OSD.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\ARQUIV~1\iGv6\sysbrand.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\DNA\btdna.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\MSN Messenger\usnsvc.exe

C:\Hijack\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdmcks.dll

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll

O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [siteAdvisor] C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [Discador iG] "C:\Arquivos de programas\iGv6\Discador iG.exe" boot

O4 - HKLM\..\Run: [MSF_Monitor] RunDll32.exe C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll,Start

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [WinampAgent] C:\Arquivos de programas\Winamp\winampa.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [sysBrand] "C:\ARQUIV~1\iGv6\sysbrand.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Arquivos de programas\DNA\btdna.exe"

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Discador Oi Internet.lnk = C:\Arquivos de programas\Oi Internet\DiscaOi.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Adicionar a AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 3.70\AMVConverter\grab.html

O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Translate with &Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx'>http://qs130.pair.com/webprim4/mathshop/livemath/download/activex/AXTNS.ocx"]http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136242443671'>http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136242443671"]http://update.microsoft.com/windowsupdate/...b?1136242443671

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"]http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{59BF1E7E-779D-4E5D-BB46-DED219CF412D}: NameServer = 10.5.1.1,10.5.1.2

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe

O23 - Service: Serviço SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

 

 

 

Flws

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa MOROCK,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

2) Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir. O processo vai durar, em média, 10 minutos;

3) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção);

4) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt;

5) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco);

6) Para parar ou sair do ComboFix, tecle "N";

7) Reabilite o seu anti-vírus;

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta, juntamente com um novo log do HijackThis.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olha jgarcia, estive olhando aki e parece q não há mais problema, da uma olhada no meu novo log (Eu não cheguei a fazer o que você disse), mas se necessitar fazer eu faço, mas so por precaussão...

 

Vai aê o log...

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 11:17:50, on 18/2/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\ARQUIV~1\SYMANT~1\VPTray.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe

C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe

C:\Arquivos de programas\D-Tools\daemon.exe

C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe

C:\Arquivos de programas\Winamp\winampa.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\Netropa\Onscreen Display\OSD.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\ARQUIV~1\iGv6\sysbrand.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\DNA\btdna.exe

C:\Arquivos de programas\CursorXP\CursorXP.exe

C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\MSN Messenger\usnsvc.exe

C:\Hijack\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdmcks.dll

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll

O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [siteAdvisor] C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [Discador iG] "C:\Arquivos de programas\iGv6\Discador iG.exe" boot

O4 - HKLM\..\Run: [MSF_Monitor] RunDll32.exe C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll,Start

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [WinampAgent] C:\Arquivos de programas\Winamp\winampa.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [sysBrand] "C:\ARQUIV~1\iGv6\sysbrand.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Arquivos de programas\DNA\btdna.exe"

O4 - HKCU\..\Run: [CursorXP] C:\Arquivos de programas\CursorXP\CursorXP.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Discador Oi Internet.lnk = C:\Arquivos de programas\Oi Internet\DiscaOi.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Adicionar a AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 3.70\AMVConverter\grab.html

O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Translate with &Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136242443671

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{59BF1E7E-779D-4E5D-BB46-DED219CF412D}: NameServer = 10.5.1.1,10.5.1.2

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe

O23 - Service: Serviço SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

 

 

 

Flws

Compartilhar este post


Link para o post
Compartilhar em outros sites
Olha jgarcia, estive olhando aki e parece q não há mais problema, da uma olhada no meu novo log (Eu não cheguei a fazer o que você disse), mas se necessitar fazer eu faço, mas so por precaussão...

Execute o ComboFix (por precaução mesmo). :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi jgarcia, td bom? eu ja executei o ComboFix, tá aê o log gerado...

 

 

 

 

ComboFix 08-02-18.1 - Gilberto 2008-02-18 21:59:52.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.169 [GMT -3:00]

Executando de: C:\Documents and Settings\Gilberto\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-01-19 to 2008-02-19 ))))))))))))))))))))))))))))))))

.

 

2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab

2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Kaspersky Lab

2008-02-17 20:51 . 2008-02-17 20:51 <DIR> d-------- C:\Arquivos de programas\OpenVideoJoiner

2008-02-16 14:33 . 2008-02-17 14:16 <DIR> d-------- C:\WINDOWS\Lhsp

2008-02-16 14:04 . 2008-02-16 14:04 <DIR> d-------- C:\WINDOWS\speech

2008-02-16 07:09 . 2008-02-16 07:09 <DIR> d-------- C:\Disquetes

2008-02-14 10:11 . 2008-02-14 10:11 <DIR> d-------- C:\Arquivos de programas\CursorXP

2008-02-13 10:24 . 2008-02-13 10:33 <DIR> d--h----- C:\Illusion

2008-02-11 14:57 . 2008-02-11 14:57 4,096 --a------ C:\WINDOWS\d3dx.dat

2008-02-10 17:00 . 2008-02-10 17:00 <DIR> d-------- C:\Arquivos de programas\LD-Anime

2008-02-10 13:23 . 2008-02-10 13:23 <DIR> d-------- C:\Arquivos de programas\LittleFighter2

2008-02-05 12:49 . 2008-02-05 12:49 26 --a------ C:\WINDOWS\SYMGAMES.INI

2008-02-04 10:50 . 2008-02-05 10:20 <DIR> d-------- C:\CD

2008-02-03 18:08 . 2008-02-04 21:27 <DIR> dr------- C:\Thaiany

2008-02-03 16:20 . 2008-02-03 16:27 <DIR> d-------- C:\Arquivos de programas\Badongo

2008-02-01 20:47 . 2008-02-01 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WinZip

2008-02-01 20:46 . 2007-09-24 22:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-02-01 20:45 . 2008-02-01 20:46 <DIR> d-------- C:\Arquivos de programas\Java

2008-02-01 20:45 . 2008-02-01 20:45 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Java

2008-02-01 16:28 . 2008-02-18 21:59 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\DNA

2008-02-01 16:28 . 2008-02-18 21:57 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\BitTorrent

2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\DNA

2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\BitTorrent

2008-02-01 15:30 . 2008-02-01 15:30 <DIR> d-------- C:\Arquivos de programas\Custom Icons

2008-02-01 13:18 . 2008-02-01 13:25 <DIR> d--h----- C:\WINDOWS\Icons

2008-02-01 09:28 . 2008-02-01 09:28 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software

2008-02-01 09:28 . 2008-02-01 09:29 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008

2008-02-01 09:28 . 2008-02-01 09:28 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-02-01 09:28 . 2007-12-20 09:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-02-01 09:27 . 2008-02-01 09:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-02-01 08:42 . 2008-02-01 08:42 <DIR> d-------- C:\Arquivos de programas\Babylon

2008-02-01 08:41 . 2008-02-17 19:37 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Babylon

2008-02-01 08:41 . 2008-02-17 19:24 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Babylon

2008-02-01 08:26 . 2008-02-13 17:18 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\uTorrent

2008-02-01 08:26 . 2008-02-01 08:34 <DIR> d-------- C:\Arquivos de programas\uTorrent

2008-01-31 10:18 . 2008-01-31 10:18 <DIR> d-------- C:\Arquivos de programas\SourceTec

2008-01-30 15:53 . 2008-01-30 15:53 <DIR> d-------- C:\Arquivos de programas\GameVicio

2008-01-30 14:42 . 2008-01-30 14:42 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Atari

2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Leadertech

2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PocketSoft

2008-01-30 14:40 . 2002-02-27 17:50 197,120 --a------ C:\WINDOWS\patchw32.dll

2008-01-30 14:36 . 2008-01-30 14:36 <DIR> d-------- C:\Arquivos de programas\Atari

2008-01-30 13:02 . 2008-01-30 13:02 <DIR> d-------- C:\Arquivos de programas\LClock

2008-01-30 12:49 . 2008-01-30 12:49 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\TuneUp Software

2008-01-30 12:42 . 2008-02-08 10:22 <DIR> d-------- C:\Arquivos de programas\Styler

2008-01-30 11:50 . 2008-01-30 11:50 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Styler

2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\Xvid

2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\DsNET Corp

2008-01-27 09:57 . 2008-01-27 09:57 37,888 --a------ C:\Acompanhe seu Processo.doc

2008-01-26 21:05 . 2008-01-28 11:09 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\AveDesk

2008-01-20 12:18 . 2008-01-20 12:18 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\xing shared

2008-01-20 00:36 . 2006-10-04 11:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb

2008-01-20 00:36 . 2006-10-04 11:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb

2008-01-20 00:36 . 2004-08-03 23:45 221,184 --a------ C:\WINDOWS\system32\wmpns.dll

2008-01-20 00:36 . 2006-10-04 11:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb

2008-01-20 00:35 . 2008-01-20 00:35 <DIR> d-------- C:\Arquivos de programas\Windows Media Connect 2

2008-01-20 00:33 . 2008-01-20 00:33 <DIR> d-------- C:\WINDOWS\system32\LogFiles

2008-01-20 00:33 . 2008-01-20 00:34 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF

2008-01-19 18:23 . 1999-09-10 07:06 45,056 --a------ C:\WINDOWS\system32\wnaspi32.dll

2008-01-19 18:23 . 1999-09-10 07:06 25,244 --a------ C:\WINDOWS\system32\drivers\aspi32.sys

2008-01-19 18:23 . 1999-09-10 07:06 5,600 --a------ C:\WINDOWS\system\winaspi.dll

2008-01-19 18:23 . 1999-09-10 07:06 4,672 --a------ C:\WINDOWS\system\wowpost.exe

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-19 00:58 --------- d-----w C:\Arquivos de programas\Symantec AntiVirus

2008-02-18 23:41 --------- d-----w C:\Arquivos de programas\Oi Internet

2008-02-18 17:55 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\LimeWire

2008-02-16 14:08 --------- d-----w C:\Arquivos de programas\Analog Devices

2008-02-16 12:39 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink

2008-02-14 16:03 --------- d-----w C:\Arquivos de programas\eMule

2008-02-13 21:30 --------- d-----w C:\Arquivos de programas\Positivo

2008-02-11 17:31 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Free Download Manager

2008-02-03 09:43 --------- d-----w C:\Arquivos de programas\SiteAdvisor

2008-02-01 19:40 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Skype

2008-01-30 17:36 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

2008-01-28 22:27 --------- d-----w C:\Arquivos de programas\Soulseek-Test

2008-01-28 18:27 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\SiteAdvisor

2008-01-27 13:14 --------- d-----w C:\Arquivos de programas\Aurélio - Século XXI

2008-01-21 22:05 --------- d-----w C:\Arquivos de programas\Ubisoft

2008-01-20 15:17 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Real

2008-01-19 17:41 --------- d-----w C:\Arquivos de programas\Rapidown

2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll

2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll

2004-10-01 17:00 40,960 ---ha-w C:\Arquivos de programas\Uninstall_CDS.exe

.

<pre>----a-w		 1,020,510 2007-10-08 01:15:06  C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exe----a-w		 1,355,913 2007-10-11 00:40:09  C:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe</pre>

 

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{0BF43445-2F28-4351-9252-17FE6E806AA0}

{7EEF1E3D-FD97-4401-BCDB-5827F2D11709}

{965B54B0-71E0-4611-8DE7-F73FA0B20E26}

 

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]

[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 13:42 267488]

 

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]

[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24 1694208]

"SysBrand"="C:\ARQUIV~1\iGv6\sysbrand.exe" [2004-12-08 18:23 36864]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:45 15360]

"BitTorrent DNA"="C:\Arquivos de programas\DNA\btdna.exe" [2008-02-12 08:04 287040]

"CursorXP"="C:\Arquivos de programas\CursorXP\CursorXP.exe" [2005-01-19 15:34 128000]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMAXPnP"="C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe" [2005-05-20 06:11 925696]

"SoundMAX"="C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 14:35 716800]

"SiteAdvisor"="C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe" [2006-12-21 17:50 35928]

"ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2005-04-08 14:52 48752]

"vptray"="C:\ARQUIV~1\SYMANT~1\VPTray.exe" [2005-04-17 11:30 85184]

"Discador iG"="C:\Arquivos de programas\iGv6\Discador iG.exe" [2007-03-03 14:27 1329664]

"MSF_Monitor"="C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll" [2007-01-23 15:45 577536]

"nwiz"="nwiz.exe" [2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe]

"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-04-28 14:47 7573504]

"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-04-28 14:47 86016]

"HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]

"MULTIMEDIA KEYBOARD"="C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-19 11:50 180224]

"DAEMON Tools-1033"="C:\Arquivos de programas\D-Tools\daemon.exe" [2004-08-22 17:05 81920]

"WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-05-14 19:22 35328]

"TkBellExe"="C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-01-20 12:17 185632]

"Babylon Client"="C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 06:20 3116768]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:45 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

Discador Oi Internet.lnk - C:\Arquivos de programas\Oi Internet\DiscaOi.exe [2005-02-10 17:45:42 1271808]

HP Digital Imaging Monitor.lnk - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]

--------- 2004-10-27 14:21 61952 C:\WINDOWS\system32\HdAShCut.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

--------- 2006-03-13 23:06 1397760 C:\Arquivos de programas\Ahead\InCD\InCD.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2006-04-28 14:47 7573504 C:\WINDOWS\System32\NvCpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2006-04-28 14:47 86016 C:\WINDOWS\System32\NvMcTray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

--------- 2004-11-02 19:24 32768 C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

--a------ 2006-10-18 10:50 20058152 C:\Arquivos de programas\Skype\Phone\Skype.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2005-06-06 06:40 544768 C:\WINDOWS\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

--a------ 2008-01-20 12:17 185632 C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

 

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02]

R2 MSF32;MSF32;C:\Here David's Things\Game Boy Advanced\Etc\MySecretFolder\MSF32.SYS [2004-05-23 02:00]

R2 nhksrv;Netropa NHK Server;C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41]

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:45]

S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-02-01 09:28]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-02-15 19:44:18 C:\WINDOWS\Tasks\1-Click Maintenance.job"

- C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-18 22:03:49

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-02-18 22:05:51

.

2008-02-13 13:50:09 --- E O F ---

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa MOROCK,

 

Você está infectado com a nova variante do Trojan Vundo, a qual infecta e renomeia arquivos de programas legítimos, substituindo-os por arquivos infectados. O procedimento que abaixo segue é o único, até o momento, capaz de neutralizar esta nova infecção.

 

Bem, explicações dadas, siga as instruções.

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

RENV::

----a-w 1,020,510 2007-10-08 01:15:06 C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exe

----a-w 1,355,913 2007-10-11 00:40:09 C:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    645i642.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tipow, esse endereço q ta aê é a pasta de SAVES de um jogo q eu jogo a um tempão, e esses nomes Trojans 2 - 1 e Trojans 3 - 1 fui eu que coloquei no save, pq o jogo é uma campanha dos Troianos, aê eu coloquei esses nomes pra distinguirs dos outros SAVES, ta ligado? , mas você acha que ta mesmo infectado? ou so poderia ser por causa dos nomes?

 

ta aê uma imagem da pasta...

 

thesettlerscg6.png

Compartilhar este post


Link para o post
Compartilhar em outros sites
Tipow, esse endereço q ta aê é a pasta de SAVES de um jogo q eu jogo a um tempão, e esses nomes Trojans 2 - 1 e Trojans 3 - 1 fui eu que coloquei no save, pq o jogo é uma campanha dos Troianos, aê eu coloquei esses nomes pra distinguirs dos outros SAVES, ta ligado? , mas você acha que ta mesmo infectado? ou so poderia ser por causa dos nomes?

A infecção existe:

C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exe

C:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe

Note o espaço entre o 1 e o .exe. Os arquivos legítimos foram substituídos. Você precisa executar a ação solicitada em meu post anterior.

 

Fico no aguardo.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa jgarcia, td bom? fiz o q você disse, ta aê o log gerado...

 

ComboFix 08-02-24.4 - Gilberto 2008-02-24 14:19:18.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.223 [GMT -3:00]

Executando de: C:\Documents and Settings\Gilberto\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Gilberto\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-01-24 to 2008-02-24 ))))))))))))))))))))))))))))))))

.

 

2008-02-21 13:46 . 2008-02-21 13:46 28,288 --a------ C:\WINDOWS\system32\xjis.nls

2008-02-21 13:46 . 2008-02-21 13:46 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls

2008-02-20 08:33 . 2008-02-20 08:33 <DIR> d-------- C:\Arquivos de programas\WinAVI Video Converter

2008-02-19 14:44 . 2008-02-19 14:44 <DIR> d-------- C:\Arquivos de programas\Peer2Mail

2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab

2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Kaspersky Lab

2008-02-17 20:51 . 2008-02-17 20:51 <DIR> d-------- C:\Arquivos de programas\OpenVideoJoiner

2008-02-16 14:33 . 2008-02-18 23:25 <DIR> d-------- C:\WINDOWS\Lhsp

2008-02-16 14:04 . 2008-02-16 14:04 <DIR> d-------- C:\WINDOWS\speech

2008-02-16 07:09 . 2008-02-16 07:09 <DIR> d-------- C:\Disquetes

2008-02-14 10:11 . 2008-02-14 10:11 <DIR> d-------- C:\Arquivos de programas\CursorXP

2008-02-13 10:24 . 2008-02-22 14:53 <DIR> d--h----- C:\Illusion

2008-02-11 14:57 . 2008-02-11 14:57 4,096 --a------ C:\WINDOWS\d3dx.dat

2008-02-10 17:00 . 2008-02-10 17:00 <DIR> d-------- C:\Arquivos de programas\LD-Anime

2008-02-10 13:23 . 2008-02-10 13:23 <DIR> d-------- C:\Arquivos de programas\LittleFighter2

2008-02-05 12:49 . 2008-02-05 12:49 26 --a------ C:\WINDOWS\SYMGAMES.INI

2008-02-04 10:50 . 2008-02-05 10:20 <DIR> d-------- C:\CD

2008-02-03 18:08 . 2008-02-04 21:27 <DIR> dr------- C:\Thaiany

2008-02-03 16:20 . 2008-02-03 16:27 <DIR> d-------- C:\Arquivos de programas\Badongo

2008-02-01 20:47 . 2008-02-01 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WinZip

2008-02-01 20:46 . 2007-09-24 22:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-02-01 20:45 . 2008-02-01 20:46 <DIR> d-------- C:\Arquivos de programas\Java

2008-02-01 20:45 . 2008-02-01 20:45 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Java

2008-02-01 16:28 . 2008-02-24 14:22 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\DNA

2008-02-01 16:28 . 2008-02-21 12:00 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\BitTorrent

2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\DNA

2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\BitTorrent

2008-02-01 15:30 . 2008-02-01 15:30 <DIR> d-------- C:\Arquivos de programas\Custom Icons

2008-02-01 13:18 . 2008-02-01 13:25 <DIR> d--h----- C:\WINDOWS\Icons

2008-02-01 09:28 . 2008-02-01 09:28 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software

2008-02-01 09:28 . 2008-02-01 09:29 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008

2008-02-01 09:28 . 2008-02-01 09:28 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe

2008-02-01 09:28 . 2007-12-20 09:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll

2008-02-01 09:27 . 2008-02-01 09:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-02-01 08:42 . 2008-02-01 08:42 <DIR> d-------- C:\Arquivos de programas\Babylon

2008-02-01 08:41 . 2008-02-22 13:46 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Babylon

2008-02-01 08:41 . 2008-02-22 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Babylon

2008-02-01 08:26 . 2008-02-13 17:18 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\uTorrent

2008-02-01 08:26 . 2008-02-01 08:34 <DIR> d-------- C:\Arquivos de programas\uTorrent

2008-01-31 10:18 . 2008-01-31 10:18 <DIR> d-------- C:\Arquivos de programas\SourceTec

2008-01-30 15:53 . 2008-01-30 15:53 <DIR> d-------- C:\Arquivos de programas\GameVicio

2008-01-30 14:42 . 2008-01-30 14:42 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Atari

2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Leadertech

2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PocketSoft

2008-01-30 14:40 . 2002-02-27 17:50 197,120 --a------ C:\WINDOWS\patchw32.dll

2008-01-30 14:36 . 2008-01-30 14:36 <DIR> d-------- C:\Arquivos de programas\Atari

2008-01-30 13:02 . 2008-01-30 13:02 <DIR> d-------- C:\Arquivos de programas\LClock

2008-01-30 12:49 . 2008-01-30 12:49 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\TuneUp Software

2008-01-30 12:42 . 2008-02-08 10:22 <DIR> d-------- C:\Arquivos de programas\Styler

2008-01-30 11:50 . 2008-01-30 11:50 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Styler

2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\Xvid

2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\DsNET Corp

2008-01-27 09:57 . 2008-01-27 09:57 37,888 --a------ C:\Acompanhe seu Processo.doc

2008-01-26 21:05 . 2008-01-28 11:09 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\AveDesk

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-24 13:26 --------- d-----w C:\Arquivos de programas\Oi Internet

2008-02-24 12:32 --------- d-----w C:\Arquivos de programas\Symantec AntiVirus

2008-02-23 01:38 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\LimeWire

2008-02-23 01:04 --------- d-----w C:\Arquivos de programas\eMule

2008-02-20 13:03 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink

2008-02-19 22:41 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Free Download Manager

2008-02-16 14:08 --------- d-----w C:\Arquivos de programas\Analog Devices

2008-02-13 21:30 --------- d-----w C:\Arquivos de programas\Positivo

2008-02-03 09:43 --------- d-----w C:\Arquivos de programas\SiteAdvisor

2008-02-01 19:40 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Skype

2008-01-30 17:36 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

2008-01-28 22:27 --------- d-----w C:\Arquivos de programas\Soulseek-Test

2008-01-28 18:27 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\SiteAdvisor

2008-01-27 13:14 --------- d-----w C:\Arquivos de programas\Aurélio - Século XXI

2008-01-21 22:05 --------- d-----w C:\Arquivos de programas\Ubisoft

2008-01-20 15:18 --------- d-----w C:\Arquivos de programas\Arquivos comuns\xing shared

2008-01-20 15:17 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Real

2008-01-20 03:35 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2

2008-01-19 17:41 --------- d-----w C:\Arquivos de programas\Rapidown

2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll

2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll

2004-10-01 17:00 40,960 ---ha-w C:\Arquivos de programas\Uninstall_CDS.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{0BF43445-2F28-4351-9252-17FE6E806AA0}

{7EEF1E3D-FD97-4401-BCDB-5827F2D11709}

{965B54B0-71E0-4611-8DE7-F73FA0B20E26}

 

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]

[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]

"{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 13:42 267488]

 

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]

[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]

[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24 1694208]

"SysBrand"="C:\ARQUIV~1\iGv6\sysbrand.exe" [2004-12-08 18:23 36864]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:45 15360]

"BitTorrent DNA"="C:\Arquivos de programas\DNA\btdna.exe" [2008-02-12 08:04 287040]

"CursorXP"="C:\Arquivos de programas\CursorXP\CursorXP.exe" [2005-01-19 15:34 128000]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SoundMAXPnP"="C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe" [2005-05-20 06:11 925696]

"SoundMAX"="C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 14:35 716800]

"SiteAdvisor"="C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe" [2006-12-21 17:50 35928]

"ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2005-04-08 14:52 48752]

"vptray"="C:\ARQUIV~1\SYMANT~1\VPTray.exe" [2005-04-17 11:30 85184]

"Discador iG"="C:\Arquivos de programas\iGv6\Discador iG.exe" [2007-03-03 14:27 1329664]

"MSF_Monitor"="C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll" [2007-01-23 15:45 577536]

"nwiz"="nwiz.exe" [2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe]

"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-04-28 14:47 7573504]

"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-04-28 14:47 86016]

"HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]

"MULTIMEDIA KEYBOARD"="C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-19 11:50 180224]

"DAEMON Tools-1033"="C:\Arquivos de programas\D-Tools\daemon.exe" [2004-08-22 17:05 81920]

"WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-05-14 19:22 35328]

"TkBellExe"="C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-01-20 12:17 185632]

"Babylon Client"="C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 06:20 3116768]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:45 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

Discador Oi Internet.lnk - C:\Arquivos de programas\Oi Internet\DiscaOi.exe [2005-02-10 17:45:42 1271808]

HP Digital Imaging Monitor.lnk - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]

--------- 2004-10-27 14:21 61952 C:\WINDOWS\system32\HdAShCut.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

--------- 2006-03-13 23:06 1397760 C:\Arquivos de programas\Ahead\InCD\InCD.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2006-04-28 14:47 7573504 C:\WINDOWS\System32\NvCpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2006-04-28 14:47 86016 C:\WINDOWS\System32\NvMcTray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

--------- 2004-11-02 19:24 32768 C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]

--a------ 2006-10-18 10:50 20058152 C:\Arquivos de programas\Skype\Phone\Skype.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2005-06-06 06:40 544768 C:\WINDOWS\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

--a------ 2008-01-20 12:17 185632 C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"C:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"C:\\Arquivos de programas\\DNA\\btdna.exe"=

"C:\\Arquivos de programas\\eMule\\emule.exe"=

"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

 

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02]

R2 MSF32;MSF32;C:\Here David's Things\Game Boy Advanced\Etc\MySecretFolder\MSF32.SYS [2004-05-23 02:00]

R2 nhksrv;Netropa NHK Server;C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41]

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:45]

S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-02-01 09:28]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

 

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-02-22 20:18:32 C:\WINDOWS\Tasks\1-Click Maintenance.job"

- C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-24 14:23:40

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-02-24 14:24:40

ComboFix2.txt 2008-02-19 01:05:52

.

2008-02-22 00:05:36 --- E O F ---

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa MOROCK,

 

Fico feliz por saber que o seu problema foi resolvido. :thumbsup:

 

Para finalizar:

 

1. Desabilite e Reabilite a função de Restauração Automática do XP. Clique aqui para ver como;

 

2. Leia o artigo Cuidados ao navegar na net e saiba como evitar novas infecções.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.