MOROCK 0 Denunciar post Postado Fevereiro 12, 2008 Aê Galera, eu tava fazendo um scan em meu PC com o antivirus Symantec so para ver se meu PC tava OK, mas ele acusou um BACKDOOR TROJAN, aê eu botei pra deletar, mas podem haver outras coisas... Por isso vou postar o log do Hijack akí pra vcs analisarem e para ver se ha possiveis riscos... Log do Hijack... Logfile of HijackThis v1.99.1 Scan saved at 19:32:14, on 12/2/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\nvsvc32.exe C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RunDll32.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe C:\Arquivos de programas\D-Tools\daemon.exe C:\Arquivos de programas\Winamp\winampa.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\Arquivos de programas\Netropa\Onscreen Display\OSD.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\ARQUIV~1\iGv6\sysbrand.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\DNA\btdna.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Hijack\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896'>http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157'>http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdmcks.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [siteAdvisor] C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Discador iG] "C:\Arquivos de programas\iGv6\Discador iG.exe" boot O4 - HKLM\..\Run: [MSF_Monitor] RunDll32.exe C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll,Start O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [WinampAgent] C:\Arquivos de programas\Winamp\winampa.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [sysBrand] "C:\ARQUIV~1\iGv6\sysbrand.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Arquivos de programas\DNA\btdna.exe" O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Discador Oi Internet.lnk = C:\Arquivos de programas\Oi Internet\DiscaOi.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Adicionar a AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 3.70\AMVConverter\grab.html O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Translate with &Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx'>http://qs130.pair.com/webprim4/mathshop/livemath/download/activex/AXTNS.ocx"]http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136242443671'>http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136242443671"]http://update.microsoft.com/windowsupdate/...b?1136242443671 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"]http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{59BF1E7E-779D-4E5D-BB46-DED219CF412D}: NameServer = 10.5.1.1,10.5.1.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Serviço SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe Flws Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 17, 2008 Opa MOROCK, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir. O processo vai durar, em média, 10 minutos; 3) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção); 4) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt; 5) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco); 6) Para parar ou sair do ComboFix, tecle "N"; 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
MOROCK 0 Denunciar post Postado Fevereiro 18, 2008 Olha jgarcia, estive olhando aki e parece q não há mais problema, da uma olhada no meu novo log (Eu não cheguei a fazer o que você disse), mas se necessitar fazer eu faço, mas so por precaussão... Vai aê o log... Logfile of HijackThis v1.99.1 Scan saved at 11:17:50, on 18/2/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RunDll32.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe C:\Arquivos de programas\D-Tools\daemon.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Winamp\winampa.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Netropa\Onscreen Display\OSD.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\System32\nvsvc32.exe C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\ARQUIV~1\iGv6\sysbrand.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\DNA\btdna.exe C:\Arquivos de programas\CursorXP\CursorXP.exe C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Hijack\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdmcks.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [siteAdvisor] C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Discador iG] "C:\Arquivos de programas\iGv6\Discador iG.exe" boot O4 - HKLM\..\Run: [MSF_Monitor] RunDll32.exe C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll,Start O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [WinampAgent] C:\Arquivos de programas\Winamp\winampa.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [sysBrand] "C:\ARQUIV~1\iGv6\sysbrand.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Arquivos de programas\DNA\btdna.exe" O4 - HKCU\..\Run: [CursorXP] C:\Arquivos de programas\CursorXP\CursorXP.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Discador Oi Internet.lnk = C:\Arquivos de programas\Oi Internet\DiscaOi.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Adicionar a AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 3.70\AMVConverter\grab.html O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Translate with &Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - http://qs130.pair.com/webprim4/mathshop/li...tivex/AXTNS.ocx O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136242443671 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{59BF1E7E-779D-4E5D-BB46-DED219CF412D}: NameServer = 10.5.1.1,10.5.1.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Serviço SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Arquivos de programas\SiteAdvisor\6253\SAService.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe Flws Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 19, 2008 Olha jgarcia, estive olhando aki e parece q não há mais problema, da uma olhada no meu novo log (Eu não cheguei a fazer o que você disse), mas se necessitar fazer eu faço, mas so por precaussão... Execute o ComboFix (por precaução mesmo). :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
MOROCK 0 Denunciar post Postado Fevereiro 19, 2008 Oi jgarcia, td bom? eu ja executei o ComboFix, tá aê o log gerado... ComboFix 08-02-18.1 - Gilberto 2008-02-18 21:59:52.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.169 [GMT -3:00] Executando de: C:\Documents and Settings\Gilberto\Desktop\ComboFix.exe * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((( Ficheiros criados de 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))) . 2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Kaspersky Lab 2008-02-17 20:51 . 2008-02-17 20:51 <DIR> d-------- C:\Arquivos de programas\OpenVideoJoiner 2008-02-16 14:33 . 2008-02-17 14:16 <DIR> d-------- C:\WINDOWS\Lhsp 2008-02-16 14:04 . 2008-02-16 14:04 <DIR> d-------- C:\WINDOWS\speech 2008-02-16 07:09 . 2008-02-16 07:09 <DIR> d-------- C:\Disquetes 2008-02-14 10:11 . 2008-02-14 10:11 <DIR> d-------- C:\Arquivos de programas\CursorXP 2008-02-13 10:24 . 2008-02-13 10:33 <DIR> d--h----- C:\Illusion 2008-02-11 14:57 . 2008-02-11 14:57 4,096 --a------ C:\WINDOWS\d3dx.dat 2008-02-10 17:00 . 2008-02-10 17:00 <DIR> d-------- C:\Arquivos de programas\LD-Anime 2008-02-10 13:23 . 2008-02-10 13:23 <DIR> d-------- C:\Arquivos de programas\LittleFighter2 2008-02-05 12:49 . 2008-02-05 12:49 26 --a------ C:\WINDOWS\SYMGAMES.INI 2008-02-04 10:50 . 2008-02-05 10:20 <DIR> d-------- C:\CD 2008-02-03 18:08 . 2008-02-04 21:27 <DIR> dr------- C:\Thaiany 2008-02-03 16:20 . 2008-02-03 16:27 <DIR> d-------- C:\Arquivos de programas\Badongo 2008-02-01 20:47 . 2008-02-01 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WinZip 2008-02-01 20:46 . 2007-09-24 22:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-02-01 20:45 . 2008-02-01 20:46 <DIR> d-------- C:\Arquivos de programas\Java 2008-02-01 20:45 . 2008-02-01 20:45 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Java 2008-02-01 16:28 . 2008-02-18 21:59 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\DNA 2008-02-01 16:28 . 2008-02-18 21:57 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\BitTorrent 2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\DNA 2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\BitTorrent 2008-02-01 15:30 . 2008-02-01 15:30 <DIR> d-------- C:\Arquivos de programas\Custom Icons 2008-02-01 13:18 . 2008-02-01 13:25 <DIR> d--h----- C:\WINDOWS\Icons 2008-02-01 09:28 . 2008-02-01 09:28 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software 2008-02-01 09:28 . 2008-02-01 09:29 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008 2008-02-01 09:28 . 2008-02-01 09:28 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-02-01 09:28 . 2007-12-20 09:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-02-01 09:27 . 2008-02-01 09:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-02-01 08:42 . 2008-02-01 08:42 <DIR> d-------- C:\Arquivos de programas\Babylon 2008-02-01 08:41 . 2008-02-17 19:37 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Babylon 2008-02-01 08:41 . 2008-02-17 19:24 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Babylon 2008-02-01 08:26 . 2008-02-13 17:18 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\uTorrent 2008-02-01 08:26 . 2008-02-01 08:34 <DIR> d-------- C:\Arquivos de programas\uTorrent 2008-01-31 10:18 . 2008-01-31 10:18 <DIR> d-------- C:\Arquivos de programas\SourceTec 2008-01-30 15:53 . 2008-01-30 15:53 <DIR> d-------- C:\Arquivos de programas\GameVicio 2008-01-30 14:42 . 2008-01-30 14:42 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Atari 2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Leadertech 2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PocketSoft 2008-01-30 14:40 . 2002-02-27 17:50 197,120 --a------ C:\WINDOWS\patchw32.dll 2008-01-30 14:36 . 2008-01-30 14:36 <DIR> d-------- C:\Arquivos de programas\Atari 2008-01-30 13:02 . 2008-01-30 13:02 <DIR> d-------- C:\Arquivos de programas\LClock 2008-01-30 12:49 . 2008-01-30 12:49 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\TuneUp Software 2008-01-30 12:42 . 2008-02-08 10:22 <DIR> d-------- C:\Arquivos de programas\Styler 2008-01-30 11:50 . 2008-01-30 11:50 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Styler 2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\Xvid 2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\DsNET Corp 2008-01-27 09:57 . 2008-01-27 09:57 37,888 --a------ C:\Acompanhe seu Processo.doc 2008-01-26 21:05 . 2008-01-28 11:09 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\AveDesk 2008-01-20 12:18 . 2008-01-20 12:18 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\xing shared 2008-01-20 00:36 . 2006-10-04 11:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb 2008-01-20 00:36 . 2006-10-04 11:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb 2008-01-20 00:36 . 2004-08-03 23:45 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2008-01-20 00:36 . 2006-10-04 11:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb 2008-01-20 00:35 . 2008-01-20 00:35 <DIR> d-------- C:\Arquivos de programas\Windows Media Connect 2 2008-01-20 00:33 . 2008-01-20 00:33 <DIR> d-------- C:\WINDOWS\system32\LogFiles 2008-01-20 00:33 . 2008-01-20 00:34 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF 2008-01-19 18:23 . 1999-09-10 07:06 45,056 --a------ C:\WINDOWS\system32\wnaspi32.dll 2008-01-19 18:23 . 1999-09-10 07:06 25,244 --a------ C:\WINDOWS\system32\drivers\aspi32.sys 2008-01-19 18:23 . 1999-09-10 07:06 5,600 --a------ C:\WINDOWS\system\winaspi.dll 2008-01-19 18:23 . 1999-09-10 07:06 4,672 --a------ C:\WINDOWS\system\wowpost.exe . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-19 00:58 --------- d-----w C:\Arquivos de programas\Symantec AntiVirus 2008-02-18 23:41 --------- d-----w C:\Arquivos de programas\Oi Internet 2008-02-18 17:55 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\LimeWire 2008-02-16 14:08 --------- d-----w C:\Arquivos de programas\Analog Devices 2008-02-16 12:39 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink 2008-02-14 16:03 --------- d-----w C:\Arquivos de programas\eMule 2008-02-13 21:30 --------- d-----w C:\Arquivos de programas\Positivo 2008-02-11 17:31 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Free Download Manager 2008-02-03 09:43 --------- d-----w C:\Arquivos de programas\SiteAdvisor 2008-02-01 19:40 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Skype 2008-01-30 17:36 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-01-28 22:27 --------- d-----w C:\Arquivos de programas\Soulseek-Test 2008-01-28 18:27 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\SiteAdvisor 2008-01-27 13:14 --------- d-----w C:\Arquivos de programas\Aurélio - Século XXI 2008-01-21 22:05 --------- d-----w C:\Arquivos de programas\Ubisoft 2008-01-20 15:17 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Real 2008-01-19 17:41 --------- d-----w C:\Arquivos de programas\Rapidown 2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll 2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll 2004-10-01 17:00 40,960 ---ha-w C:\Arquivos de programas\Uninstall_CDS.exe . <pre>----a-w 1,020,510 2007-10-08 01:15:06 C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exe----a-w 1,355,913 2007-10-11 00:40:09 C:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe</pre> (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {0BF43445-2F28-4351-9252-17FE6E806AA0} {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} {965B54B0-71E0-4611-8DE7-F73FA0B20E26} [HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1] [HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 13:42 267488] [HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1] [HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24 1694208] "SysBrand"="C:\ARQUIV~1\iGv6\sysbrand.exe" [2004-12-08 18:23 36864] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:45 15360] "BitTorrent DNA"="C:\Arquivos de programas\DNA\btdna.exe" [2008-02-12 08:04 287040] "CursorXP"="C:\Arquivos de programas\CursorXP\CursorXP.exe" [2005-01-19 15:34 128000] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe" [2005-05-20 06:11 925696] "SoundMAX"="C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 14:35 716800] "SiteAdvisor"="C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe" [2006-12-21 17:50 35928] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2005-04-08 14:52 48752] "vptray"="C:\ARQUIV~1\SYMANT~1\VPTray.exe" [2005-04-17 11:30 85184] "Discador iG"="C:\Arquivos de programas\iGv6\Discador iG.exe" [2007-03-03 14:27 1329664] "MSF_Monitor"="C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll" [2007-01-23 15:45 577536] "nwiz"="nwiz.exe" [2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-04-28 14:47 7573504] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-04-28 14:47 86016] "HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "MULTIMEDIA KEYBOARD"="C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-19 11:50 180224] "DAEMON Tools-1033"="C:\Arquivos de programas\D-Tools\daemon.exe" [2004-08-22 17:05 81920] "WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-05-14 19:22 35328] "TkBellExe"="C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-01-20 12:17 185632] "Babylon Client"="C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 06:20 3116768] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Discador Oi Internet.lnk - C:\Arquivos de programas\Oi Internet\DiscaOi.exe [2005-02-10 17:45:42 1271808] HP Digital Imaging Monitor.lnk - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --------- 2004-10-27 14:21 61952 C:\WINDOWS\system32\HdAShCut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] --------- 2006-03-13 23:06 1397760 C:\Arquivos de programas\Ahead\InCD\InCD.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-04-28 14:47 7573504 C:\WINDOWS\System32\NvCpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-04-28 14:47 86016 C:\WINDOWS\System32\NvMcTray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --------- 2004-11-02 19:24 32768 C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] --a------ 2006-10-18 10:50 20058152 C:\Arquivos de programas\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2005-06-06 06:40 544768 C:\WINDOWS\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2008-01-20 12:17 185632 C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02] R2 MSF32;MSF32;C:\Here David's Things\Game Boy Advanced\Etc\MySecretFolder\MSF32.SYS [2004-05-23 02:00] R2 nhksrv;Netropa NHK Server;C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41] R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:45] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-02-01 09:28] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Conteúdo da pasta 'Tarefas Agendadas' "2008-02-15 19:44:18 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-18 22:03:49 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-02-18 22:05:51 . 2008-02-13 13:50:09 --- E O F --- Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 20, 2008 Opa MOROCK, Você está infectado com a nova variante do Trojan Vundo, a qual infecta e renomeia arquivos de programas legítimos, substituindo-os por arquivos infectados. O procedimento que abaixo segue é o único, até o momento, capaz de neutralizar esta nova infecção. Bem, explicações dadas, siga as instruções. 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": RENV:: ----a-w 1,020,510 2007-10-08 01:15:06 C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exe ----a-w 1,355,913 2007-10-11 00:40:09 C:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
MOROCK 0 Denunciar post Postado Fevereiro 24, 2008 Tipow, esse endereço q ta aê é a pasta de SAVES de um jogo q eu jogo a um tempão, e esses nomes Trojans 2 - 1 e Trojans 3 - 1 fui eu que coloquei no save, pq o jogo é uma campanha dos Troianos, aê eu coloquei esses nomes pra distinguirs dos outros SAVES, ta ligado? , mas você acha que ta mesmo infectado? ou so poderia ser por causa dos nomes? ta aê uma imagem da pasta... Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 24, 2008 Tipow, esse endereço q ta aê é a pasta de SAVES de um jogo q eu jogo a um tempão, e esses nomes Trojans 2 - 1 e Trojans 3 - 1 fui eu que coloquei no save, pq o jogo é uma campanha dos Troianos, aê eu coloquei esses nomes pra distinguirs dos outros SAVES, ta ligado? , mas você acha que ta mesmo infectado? ou so poderia ser por causa dos nomes? A infecção existe: C:\BlueByte\The Settlers IV\Save\Trojans 2 - 1 .exeC:\BlueByte\The Settlers IV\Save\Trojans 3 - 1 .exe Note o espaço entre o 1 e o .exe. Os arquivos legítimos foram substituídos. Você precisa executar a ação solicitada em meu post anterior. Fico no aguardo. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
MOROCK 0 Denunciar post Postado Fevereiro 24, 2008 Opa jgarcia, td bom? fiz o q você disse, ta aê o log gerado... ComboFix 08-02-24.4 - Gilberto 2008-02-24 14:19:18.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.223 [GMT -3:00] Executando de: C:\Documents and Settings\Gilberto\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Gilberto\Desktop\CFScript.txt * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((( Ficheiros criados de 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))) . 2008-02-21 13:46 . 2008-02-21 13:46 28,288 --a------ C:\WINDOWS\system32\xjis.nls 2008-02-21 13:46 . 2008-02-21 13:46 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls 2008-02-20 08:33 . 2008-02-20 08:33 <DIR> d-------- C:\Arquivos de programas\WinAVI Video Converter 2008-02-19 14:44 . 2008-02-19 14:44 <DIR> d-------- C:\Arquivos de programas\Peer2Mail 2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-02-18 11:49 . 2008-02-18 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Kaspersky Lab 2008-02-17 20:51 . 2008-02-17 20:51 <DIR> d-------- C:\Arquivos de programas\OpenVideoJoiner 2008-02-16 14:33 . 2008-02-18 23:25 <DIR> d-------- C:\WINDOWS\Lhsp 2008-02-16 14:04 . 2008-02-16 14:04 <DIR> d-------- C:\WINDOWS\speech 2008-02-16 07:09 . 2008-02-16 07:09 <DIR> d-------- C:\Disquetes 2008-02-14 10:11 . 2008-02-14 10:11 <DIR> d-------- C:\Arquivos de programas\CursorXP 2008-02-13 10:24 . 2008-02-22 14:53 <DIR> d--h----- C:\Illusion 2008-02-11 14:57 . 2008-02-11 14:57 4,096 --a------ C:\WINDOWS\d3dx.dat 2008-02-10 17:00 . 2008-02-10 17:00 <DIR> d-------- C:\Arquivos de programas\LD-Anime 2008-02-10 13:23 . 2008-02-10 13:23 <DIR> d-------- C:\Arquivos de programas\LittleFighter2 2008-02-05 12:49 . 2008-02-05 12:49 26 --a------ C:\WINDOWS\SYMGAMES.INI 2008-02-04 10:50 . 2008-02-05 10:20 <DIR> d-------- C:\CD 2008-02-03 18:08 . 2008-02-04 21:27 <DIR> dr------- C:\Thaiany 2008-02-03 16:20 . 2008-02-03 16:27 <DIR> d-------- C:\Arquivos de programas\Badongo 2008-02-01 20:47 . 2008-02-01 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WinZip 2008-02-01 20:46 . 2007-09-24 22:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-02-01 20:45 . 2008-02-01 20:46 <DIR> d-------- C:\Arquivos de programas\Java 2008-02-01 20:45 . 2008-02-01 20:45 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Java 2008-02-01 16:28 . 2008-02-24 14:22 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\DNA 2008-02-01 16:28 . 2008-02-21 12:00 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\BitTorrent 2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\DNA 2008-02-01 16:28 . 2008-02-01 16:28 <DIR> d-------- C:\Arquivos de programas\BitTorrent 2008-02-01 15:30 . 2008-02-01 15:30 <DIR> d-------- C:\Arquivos de programas\Custom Icons 2008-02-01 13:18 . 2008-02-01 13:25 <DIR> d--h----- C:\WINDOWS\Icons 2008-02-01 09:28 . 2008-02-01 09:28 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software 2008-02-01 09:28 . 2008-02-01 09:29 <DIR> d-------- C:\Arquivos de programas\TuneUp Utilities 2008 2008-02-01 09:28 . 2008-02-01 09:28 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-02-01 09:28 . 2007-12-20 09:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-02-01 09:27 . 2008-02-01 09:27 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-02-01 08:42 . 2008-02-01 08:42 <DIR> d-------- C:\Arquivos de programas\Babylon 2008-02-01 08:41 . 2008-02-22 13:46 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Babylon 2008-02-01 08:41 . 2008-02-22 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Babylon 2008-02-01 08:26 . 2008-02-13 17:18 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\uTorrent 2008-02-01 08:26 . 2008-02-01 08:34 <DIR> d-------- C:\Arquivos de programas\uTorrent 2008-01-31 10:18 . 2008-01-31 10:18 <DIR> d-------- C:\Arquivos de programas\SourceTec 2008-01-30 15:53 . 2008-01-30 15:53 <DIR> d-------- C:\Arquivos de programas\GameVicio 2008-01-30 14:42 . 2008-01-30 14:42 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Atari 2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Leadertech 2008-01-30 14:40 . 2008-01-30 14:40 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PocketSoft 2008-01-30 14:40 . 2002-02-27 17:50 197,120 --a------ C:\WINDOWS\patchw32.dll 2008-01-30 14:36 . 2008-01-30 14:36 <DIR> d-------- C:\Arquivos de programas\Atari 2008-01-30 13:02 . 2008-01-30 13:02 <DIR> d-------- C:\Arquivos de programas\LClock 2008-01-30 12:49 . 2008-01-30 12:49 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\TuneUp Software 2008-01-30 12:42 . 2008-02-08 10:22 <DIR> d-------- C:\Arquivos de programas\Styler 2008-01-30 11:50 . 2008-01-30 11:50 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\Styler 2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\Xvid 2008-01-27 14:21 . 2008-01-27 14:21 <DIR> d-------- C:\Arquivos de programas\DsNET Corp 2008-01-27 09:57 . 2008-01-27 09:57 37,888 --a------ C:\Acompanhe seu Processo.doc 2008-01-26 21:05 . 2008-01-28 11:09 <DIR> d-------- C:\Documents and Settings\Gilberto\Dados de aplicativos\AveDesk . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-24 13:26 --------- d-----w C:\Arquivos de programas\Oi Internet 2008-02-24 12:32 --------- d-----w C:\Arquivos de programas\Symantec AntiVirus 2008-02-23 01:38 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\LimeWire 2008-02-23 01:04 --------- d-----w C:\Arquivos de programas\eMule 2008-02-20 13:03 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink 2008-02-19 22:41 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Free Download Manager 2008-02-16 14:08 --------- d-----w C:\Arquivos de programas\Analog Devices 2008-02-13 21:30 --------- d-----w C:\Arquivos de programas\Positivo 2008-02-03 09:43 --------- d-----w C:\Arquivos de programas\SiteAdvisor 2008-02-01 19:40 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\Skype 2008-01-30 17:36 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-01-28 22:27 --------- d-----w C:\Arquivos de programas\Soulseek-Test 2008-01-28 18:27 --------- d-----w C:\Documents and Settings\Gilberto\Dados de aplicativos\SiteAdvisor 2008-01-27 13:14 --------- d-----w C:\Arquivos de programas\Aurélio - Século XXI 2008-01-21 22:05 --------- d-----w C:\Arquivos de programas\Ubisoft 2008-01-20 15:18 --------- d-----w C:\Arquivos de programas\Arquivos comuns\xing shared 2008-01-20 15:17 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Real 2008-01-20 03:35 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2008-01-19 17:41 --------- d-----w C:\Arquivos de programas\Rapidown 2007-12-07 02:09 824,832 ----a-w C:\WINDOWS\system32\wininet.dll 2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll 2004-10-01 17:00 40,960 ---ha-w C:\Arquivos de programas\Uninstall_CDS.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {0BF43445-2F28-4351-9252-17FE6E806AA0} {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} {965B54B0-71E0-4611-8DE7-F73FA0B20E26} [HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1] [HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Arquivos de programas\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 13:42 267488] [HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1] [HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}] [HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 13:24 1694208] "SysBrand"="C:\ARQUIV~1\iGv6\sysbrand.exe" [2004-12-08 18:23 36864] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:45 15360] "BitTorrent DNA"="C:\Arquivos de programas\DNA\btdna.exe" [2008-02-12 08:04 287040] "CursorXP"="C:\Arquivos de programas\CursorXP\CursorXP.exe" [2005-01-19 15:34 128000] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe" [2005-05-20 06:11 925696] "SoundMAX"="C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 14:35 716800] "SiteAdvisor"="C:\Arquivos de programas\SiteAdvisor\6253\SiteAdv.exe" [2006-12-21 17:50 35928] "ccApp"="C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2005-04-08 14:52 48752] "vptray"="C:\ARQUIV~1\SYMANT~1\VPTray.exe" [2005-04-17 11:30 85184] "Discador iG"="C:\Arquivos de programas\iGv6\Discador iG.exe" [2007-03-03 14:27 1329664] "MSF_Monitor"="C:\HEREDA~1\GAMEBO~1\Etc\MYSECR~1\MSF32.dll" [2007-01-23 15:45 577536] "nwiz"="nwiz.exe" [2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-04-28 14:47 7573504] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-04-28 14:47 86016] "HP Software Update"="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152] "MULTIMEDIA KEYBOARD"="C:\Arquivos de programas\Netropa\Multimedia Keyboard\MMKeybd.exe" [2002-06-19 11:50 180224] "DAEMON Tools-1033"="C:\Arquivos de programas\D-Tools\daemon.exe" [2004-08-22 17:05 81920] "WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-05-14 19:22 35328] "TkBellExe"="C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-01-20 12:17 185632] "Babylon Client"="C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 06:20 3116768] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-03 23:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] Discador Oi Internet.lnk - C:\Arquivos de programas\Oi Internet\DiscaOi.exe [2005-02-10 17:45:42 1271808] HP Digital Imaging Monitor.lnk - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --------- 2004-10-27 14:21 61952 C:\WINDOWS\system32\HdAShCut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] --------- 2006-03-13 23:06 1397760 C:\Arquivos de programas\Ahead\InCD\InCD.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2006-04-28 14:47 7573504 C:\WINDOWS\System32\NvCpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2006-04-28 14:47 86016 C:\WINDOWS\System32\NvMcTray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2006-04-28 14:47 1519616 C:\WINDOWS\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --------- 2004-11-02 19:24 32768 C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] --a------ 2006-10-18 10:50 20058152 C:\Arquivos de programas\Skype\Phone\Skype.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2005-06-06 06:40 544768 C:\WINDOWS\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] --a------ 2008-01-20 12:17 185632 C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= "C:\\Arquivos de programas\\DNA\\btdna.exe"= "C:\\Arquivos de programas\\eMule\\emule.exe"= "C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02] R2 MSF32;MSF32;C:\Here David's Things\Game Boy Advanced\Etc\MySecretFolder\MSF32.SYS [2004-05-23 02:00] R2 nhksrv;Netropa NHK Server;C:\Arquivos de programas\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41] R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:45] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-02-01 09:28] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Conteúdo da pasta 'Tarefas Agendadas' "2008-02-22 20:18:32 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-24 14:23:40 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-02-24 14:24:40 ComboFix2.txt 2008-02-19 01:05:52 . 2008-02-22 00:05:36 --- E O F --- Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 2, 2008 Opa MOROCK, O log parece limpo. Ainda há algum problema? Compartilhar este post Link para o post Compartilhar em outros sites
MOROCK 0 Denunciar post Postado Março 4, 2008 Não há mais problema, VLW!!!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 4, 2008 Opa MOROCK, Fico feliz por saber que o seu problema foi resolvido. :thumbsup: Para finalizar: 1. Desabilite e Reabilite a função de Restauração Automática do XP. Clique aqui para ver como; 2. Leia o artigo Cuidados ao navegar na net e saiba como evitar novas infecções. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Junho 13, 2008 Tópico Arquivado Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites