REDENTOR 0 Denunciar post Postado Março 28, 2008 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 03:41:48, on 28/03/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16609) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\OEM02Mon.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Windows\System32\mobsync.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fornecido por Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O13 - Gopher Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 8089 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Abril 4, 2008 Opa REDENTOR, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir. O processo vai durar, em média, 10 minutos; 3) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção); 4) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt; 5) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco); 6) Para parar ou sair do ComboFix, tecle "N"; 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Abril 4, 2008 Rodei o Combofix como você pediu. Qdo ele termina, abre-se uma janela do bloco de notas com a msg: [.ShellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787, que nunca tinha aparecido... Seguem os logs, abraços. ComboFix 08-03-30.4 - CRIS 2008-04-04 4:44:56.2 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.102 [GMT -3:00] Executando de: C:\Users\CRIS\Desktop\ComboFix.exe . TimedOut: Windir.dat ((((((((((((((((((((((( Ficheiros criados de 2008-03-04 to 2008-04-04 )))))))))))))))))))))))))))))))) . 2008-04-04 03:21 . 2008-04-04 03:21 <DIR> d-------- C:\Program Files\Programas RFB 2008-04-04 03:20 . 2008-04-04 04:25 <DIR> d-------- C:\Program Files\SpywareGuard 2008-04-03 22:07 . 2008-04-03 22:07 <DIR> d-------- C:\Windows\System32\Kaspersky Lab 2008-03-31 13:49 . 2008-03-31 13:49 8,627 --a------ C:\Windows\System32\PAV_FOG.OPC 2008-03-31 13:13 . 2008-03-31 13:13 <DIR> d-------- C:\Users\All Users\sentinel 2008-03-31 13:13 . 2008-03-31 13:13 <DIR> d-------- C:\ProgramData\sentinel 2008-03-31 12:58 . 2008-03-31 12:58 <DIR> d-------- C:\Users\All Users\Backup 2008-03-31 12:58 . 2008-03-31 12:58 <DIR> d-------- C:\ProgramData\Backup 2008-03-31 12:56 . 2008-03-31 12:56 <DIR> d-------- C:\Program Files\Panda Security 2008-03-31 06:17 . 2008-04-02 01:11 <DIR> d-------- C:\Program Files\Common Files\Panda Software 2008-03-31 04:04 . 2008-03-31 04:11 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\U3 2008-03-30 21:04 . 2007-09-20 14:12 12,800 --a------ C:\Windows\System32\drivers\elrawdsk.sys 2008-03-30 20:52 . 2008-03-30 20:52 74,703 --a------ C:\Windows\System32\mfc45.dll 2008-03-30 19:27 . 2008-03-30 19:27 <DIR> d-------- C:\Program Files\GbPlugin 2008-03-30 19:26 . 2008-03-30 19:27 <DIR> d-------- C:\Users\All Users\GbPlugin 2008-03-30 19:26 . 2008-03-30 19:27 <DIR> d-------- C:\ProgramData\GbPlugin 2008-03-30 19:20 . 2008-04-02 01:17 <DIR> d-------- C:\Program Files\Trend Micro 2008-03-30 17:29 . 2008-03-30 19:58 <DIR> d-------- C:\Users\CRIS\.housecall6.6 2008-03-28 16:00 . 2008-03-28 16:00 194,560 --a------ C:\Windows\System32\WebClnt.dll 2008-03-28 16:00 . 2008-03-28 16:00 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys 2008-03-28 15:50 . 2008-03-28 15:50 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\VSRevoGroup 2008-03-28 15:20 . 2008-03-28 15:20 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\TuneUp Software 2008-03-28 14:53 . 2008-03-28 14:53 63 --a------ C:\Windows\system\SysSD.dll 2008-03-28 14:03 . 2008-03-30 22:01 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\iolo 2008-03-28 14:03 . 2008-03-31 03:27 <DIR> d-------- C:\Users\All Users\iolo 2008-03-28 14:03 . 2008-03-31 03:27 <DIR> d-------- C:\ProgramData\iolo 2008-03-28 14:03 . 2008-03-31 03:30 <DIR> d-------- C:\Program Files\iolo 2008-03-28 14:03 . 2008-03-28 14:03 406 --a------ C:\Windows\System32\ioloBootDefrag.cfg 2008-03-28 04:12 . 2008-03-28 08:57 <DIR> d-------- C:\Windows\BDOSCAN8 2008-03-28 03:39 . 2007-06-28 14:36 401,720 --a------ C:\HijackThis.exe 2008-03-27 14:03 . 2008-03-27 14:03 <DIR> d-------- C:\Users\All Users\Kaspersky Lab 2008-03-27 14:03 . 2008-03-27 14:03 <DIR> d-------- C:\ProgramData\Kaspersky Lab 2008-03-27 13:59 . 2008-03-27 13:59 <DIR> d-------- C:\Windows\Sun 2008-03-27 03:18 . 2008-03-27 23:42 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Vso 2008-03-27 01:24 . 2008-03-27 14:37 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\CyberLink 2008-03-26 23:26 . 2008-03-26 23:32 <DIR> d-------- C:\Program Files\Windows Live Toolbar 2008-03-26 05:40 . 2008-03-27 02:28 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Skype 2008-03-26 05:39 . 2007-12-15 00:54 180,224 --a------ C:\Windows\System32\igfxres.dll 2008-03-26 05:14 . 2002-07-07 23:14 1,294,336 --a------ C:\Windows\System32\vorbis.acm 2008-03-26 05:14 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll 2008-03-26 05:12 . 2007-12-24 13:49 7,680 --a------ C:\Windows\System32\ff_vfw.dll 2008-03-26 05:12 . 2007-07-10 17:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest 2008-03-26 05:11 . 2008-03-26 05:15 <DIR> d-------- C:\Program Files\K-Lite Codec Pack 2008-03-26 05:10 . 2008-04-02 23:35 3,082 --a------ C:\Windows\System32\affv208325p1now.sys 2008-03-26 04:59 . 2008-03-26 23:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-26 04:55 . 2008-03-27 00:34 <DIR> d-------- C:\Program Files\Windows Live 2008-03-26 04:35 . 2008-03-26 04:35 <DIR> d-------- C:\Program Files\URUSoft 2008-03-26 04:32 . 2008-03-26 04:34 <DIR> d-------- C:\Program Files\Picasa2 2008-03-26 04:20 . 2008-03-26 04:24 <DIR> d-------- C:\Program Files\Skype 2008-03-26 04:17 . 2008-03-26 04:18 <DIR> d-------- C:\Program Files\Common Files\Skype 2008-03-26 04:10 . 2001-03-08 18:30 24,064 --------- C:\Windows\System32\msxml3a.dll 2008-03-26 02:36 . 2008-03-28 00:14 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\F-Secure 2008-03-26 00:49 . 2008-04-02 23:36 <DIR> d-------- C:\Program Files\WinAVIVideoConverter 2008-03-26 00:49 . 2007-05-25 10:15 572,784 --a------ C:\Windows\System32\msvcp50.dll 2008-03-26 00:48 . 2008-03-26 00:48 <DIR> d-------- C:\Program Files\Common Files\xing shared 2008-03-26 00:47 . 2008-04-04 04:36 <DIR> d-------- C:\Users\All Users\F-Secure 2008-03-26 00:47 . 2008-04-04 04:36 <DIR> d-------- C:\ProgramData\F-Secure 2008-03-26 00:45 . 2008-03-26 00:45 <DIR> d-------- C:\Program Files\Real 2008-03-26 00:45 . 2008-04-04 04:41 <DIR> d-------- C:\Program Files\F-Secure Internet Security 2008-03-26 00:45 . 2008-03-26 00:48 <DIR> d-------- C:\Program Files\Common Files\Real 2008-03-25 23:57 . 2008-03-25 23:57 <DIR> d-------- C:\Program Files\VS Revo Group 2008-03-25 23:54 . 2008-04-04 03:32 <DIR> d-------- C:\Users\All Users\fssg 2008-03-25 23:54 . 2008-04-04 03:32 <DIR> d-------- C:\ProgramData\fssg 2008-03-25 23:48 . 2008-03-25 23:51 <DIR> d-------- C:\Program Files\Opera 2008-03-25 23:43 . 2008-03-26 04:21 <DIR> d-------- C:\Users\All Users\Skype 2008-03-25 23:43 . 2008-03-26 04:21 <DIR> d-------- C:\ProgramData\Skype 2008-03-25 23:41 . 2008-03-25 23:42 <DIR> d-------- C:\Program Files\DVD Decrypter 2008-03-25 23:17 . 2007-04-09 13:23 28,040 --a------ C:\Windows\System32\mdimon.dll 2008-03-25 23:17 . 2008-03-25 23:17 418 --a------ C:\Windows\ODBC.INI 2008-03-25 23:14 . 2008-03-25 23:15 <DIR> d-------- C:\Windows\SHELLNEW 2008-03-25 23:14 . 2008-03-25 23:14 <DIR> d-------- C:\Windows\PCHEALTH 2008-03-25 23:14 . 2008-03-25 23:14 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-03-25 23:05 . 2008-03-25 23:05 <DIR> d-------- C:\Users\All Users\eMule 2008-03-25 23:05 . 2008-03-25 23:05 <DIR> d-------- C:\ProgramData\eMule 2008-03-25 23:04 . 2008-03-25 23:04 <DIR> dr-h----- C:\MSOCache 2008-03-25 14:03 . 2008-03-25 14:03 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Creative 2008-03-25 14:03 . 2008-03-25 14:03 595,456 --a------ C:\Windows\System32\schedsvc.dll 2008-03-25 14:03 . 2008-03-25 14:03 115,200 --a------ C:\Windows\System32\loadperf.dll 2008-03-25 14:03 . 2008-03-25 14:03 39,424 --a------ C:\Windows\System32\lodctr.exe 2008-03-25 14:03 . 2008-03-25 14:03 32,256 --a------ C:\Windows\System32\unlodctr.exe 2008-03-25 14:03 . 2008-03-25 14:03 17,408 --a------ C:\Windows\System32\prflbmsg.dll 2008-03-25 14:02 . 2008-03-25 14:02 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe 2008-03-25 14:02 . 2008-03-25 14:02 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe 2008-03-25 14:02 . 2008-03-25 14:02 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys 2008-03-25 14:02 . 2008-03-25 14:02 41,984 --a------ C:\Windows\System32\drivers\monitor.sys 2008-03-25 14:00 . 2008-03-25 14:00 11,776 --a------ C:\Windows\System32\sbunattend.exe 2008-03-25 13:59 . 2008-03-27 00:24 <DIR> d-------- C:\Users\All Users\WLInstaller 2008-03-25 13:59 . 2008-03-27 00:24 <DIR> d-------- C:\ProgramData\WLInstaller 2008-03-25 13:58 . 2008-03-25 13:58 <DIR> d-------- C:\Program Files\MSXML 4.0 2008-03-25 13:54 . 2008-03-25 13:54 1,383,424 --a------ C:\Windows\System32\mshtml.tlb 2008-03-25 13:39 . 2008-03-25 13:39 <DIR> d-------- C:\Program Files\YourWare Solutions 2008-03-25 13:38 . 2008-04-03 00:44 <DIR> d-------- C:\Users\All Users\DVD Shrink 2008-03-25 13:38 . 2008-04-03 00:44 <DIR> d-------- C:\ProgramData\DVD Shrink 2008-03-25 13:38 . 2008-03-31 05:50 <DIR> d-------- C:\Program Files\Marcos Velasco Security 2008-03-25 13:38 . 2008-03-25 13:38 <DIR> d-------- C:\Program Files\DVD Shrink 2008-03-25 13:36 . 2008-03-25 13:36 <DIR> d-------- C:\Program Files\eMule 2008-03-25 13:36 . 2008-03-25 13:36 <DIR> d-------- C:\Program Files\7-Zip 2008-03-25 13:35 . 2008-03-25 13:35 <DIR> d-------- C:\Program Files\CCleaner 2008-03-25 13:22 . 2008-03-25 13:22 1,712,984 --a------ C:\Windows\System32\wuaueng.dll 2008-03-25 13:22 . 2008-03-25 13:22 1,524,224 --a------ C:\Windows\System32\wucltux.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-03-25 17:16 --------- d-----w C:\Program Files\Windows Sidebar 2008-03-25 17:16 --------- d-----w C:\Program Files\Windows Mail 2008-03-25 17:04 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys 2008-03-25 17:04 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys 2008-03-25 17:04 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys 2008-03-25 17:04 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys 2008-03-25 17:04 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys 2008-03-25 17:04 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys 2008-03-25 17:04 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys 2008-03-25 17:01 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys 2008-03-25 17:01 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-03-25 17:01 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-03-25 17:01 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-03-25 17:01 217,144 ----a-w C:\Windows\system32\drivers\netio.sys 2008-03-25 17:01 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-03-25 17:01 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys 2008-03-25 17:01 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-03-25 17:01 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-03-25 17:01 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-03-25 17:01 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys 2008-03-25 17:01 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys 2008-03-25 16:53 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Modelos 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Menu Iniciar 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Favoritos 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Documentos 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Desktop 2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Dados de aplicativos 2008-03-25 16:00 --------- d-sh--w C:\Program Files\Common Files\Sistema 2008-03-25 16:00 --------- d-sh--w C:\Program Files\Arquivos Comuns 2008-03-19 01:01 25,784 ------w C:\Windows\system32\drivers\msahci.sys 2008-03-19 01:01 20,152 ------w C:\Windows\system32\drivers\viaide.sys 2008-03-19 01:01 19,128 ------w C:\Windows\system32\drivers\cmdide.sys 2008-03-19 01:01 18,104 ------w C:\Windows\system32\drivers\amdide.sys 2008-03-19 01:01 17,592 ----a-w C:\Windows\system32\drivers\intelide.sys 2008-03-19 01:01 17,592 ------w C:\Windows\system32\drivers\aliide.sys 2008-03-19 00:57 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys 2008-03-19 00:57 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys 2008-03-19 00:57 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys 2008-03-19 00:57 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys 2008-03-19 00:57 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys 2008-03-19 00:57 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys 2008-03-19 00:56 --------- d-----w C:\Program Files\Windows Calendar 2008-03-19 00:55 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys 2008-03-19 00:55 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys 2008-03-19 00:55 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys 2008-03-19 00:55 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys 2008-03-19 00:54 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys 2008-03-19 00:54 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys 2008-03-19 00:54 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys 2008-03-19 00:51 --------- d-----w C:\Program Files\Windows Defender 2008-03-19 00:50 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys 2008-03-19 00:50 28,344 ----a-w C:\Windows\system32\drivers\battc.sys 2008-03-19 00:50 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys 2008-03-19 00:50 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys 2008-03-19 00:50 20,920 ------w C:\Windows\system32\drivers\compbatt.sys 2008-03-19 00:50 2,923,520 ----a-w C:\Windows\explorer.exe 2008-03-19 00:50 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS 2008-03-19 00:50 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys 2008-03-19 00:50 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys 2008-03-19 00:47 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys 2008-03-18 17:10 174 --sha-w C:\Program Files\desktop.ini 2008-01-09 18:01 53,248 ----a-w C:\Windows\bdoscandel.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 03:03 17920] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 02:51 36864] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-15 00:54 137752] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-15 00:53 154136] "Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-15 00:53 133656] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-18 14:20:25 50688] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{E37CB5F0-51F5-4395-A808-5FA49E399007}"= C:\Windows\Downloaded Program Files\gbiehabn.dll [2008-03-10 12:19 348072] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{E43D03BF-D0D6-4997-ACE6-270DEE580CB2}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "TCP Query User{E9D3E9CC-3F64-45B9-AB1F-B7A85E4E6FD8}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule "UDP Query User{4176CB75-1AAA-485A-AC26-F4CCB9E10DF3}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule "TCP Query User{F99DA093-21AA-469D-A08B-757E144E91B4}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{F5312FDA-45D9-4E71-9C07-D7EC3908BD2A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-11-12 08:07] R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23] R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 21:39] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-12-15 00:53] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-12-15 00:54] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 02:51] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 02:51] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 02:31] S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-10 00:18] S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 04:36] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc . Conteúdo da pasta 'Tarefas Agendadas' "2008-04-04 07:41:43 C:\Windows\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-03-31 16:58:45 C:\Windows\Tasks\At1.job" - C:\Program Files\Panda Security\Panda Internet Security 2008\PAVJOBS.EXEn/PROGRAMADA PAV5.tsk PAV_FOG.OPC . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-04 04:48:26 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-04-04 4:49:50 ComboFix-quarantined-files.txt 2008-04-04 07:49:45 ComboFix2.txt 2008-04-01 02:59:58 Pre-Run: 61,037,043,712 bytes disponíveis Post-Run: 60,796,727,296 bytes disponíveis . 2008-04-04 01:55:57 --- E O F --- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 05:02:22, on 04/04/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16609) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\SYSTEM32\taskeng.exe C:\Windows\OEM02Mon.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\Explorer.exe C:\Users\CRIS\AppData\Local\Temp\Temp1_HiJackThis.zip\HijackThis.exe C:\Program Files\Internet Explorer\IEUser.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Windows\Downloaded Program Files\gbiehabn.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 6640 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Abril 10, 2008 Opa REDENTOR, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::C:\Windows\system\SysSD.dll C:\Program Files\desktop.ini C:\Windows\Tasks\At1.job Folder:: C:\Program Files\GbPlugin C:\Users\All Users\GbPlugin C:\ProgramData\GbPlugin Registry:: [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000000 ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Abril 14, 2008 Jgarcia, Mil desculpas, estou até envergonhada em dizer, mas aconteceu o seguinte: como em outro fórum (eles responderam mais rápido) disseram que meu log estava limpo, e os problemas continuavam, fiquei nervosa e perdi a paciência, formatei o micro :wacko: . Instalei novamente os programas, alguns a mais e alguns a menos. No entanto, as coisas estão na mesma. A diferença é que agora meu antivirus alerta todo dia umas 9 vezes tentativa de intrusão, e que o Opera abre, assim que eu inicio, várias janelas nomeadas Acrobat plug-in informando que "could not launch Acrobat", e depois o programa pára de responder e fecha. Poderia por gentileza analisar novamente o log? :blush: Muito obrigada! ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 03:22:51, on 14/04/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Program Files\a-squared Free\a2service.exe C:\Windows\system32\aestsrv.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Windows\system32\svchost.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\OEM02Mon.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exe C:\Windows\TEMP\F-Secure\Anti-Virus\fsblsrv.exe C:\Windows\System32\mobsync.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Windows\system32\conime.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\F-Secure Internet Security\Common\FSLAUNCH.EXE C:\HijackThis.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\CRIS\AppData\Local\Temp\Temp1_HiJackThis.zip\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Startup: fsavaui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe O4 - Startup: fsavgui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe O4 - Startup: FsDiagUi - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe O4 - Startup: fsgetwab - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe O4 - Startup: fsguidll - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe O4 - Startup: fssw - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe O4 - Startup: fstlui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe O4 - Startup: postinstall - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe O4 - Startup: quaranti - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\quaranti.exe O4 - Startup: tnbutil - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\tnbutil.exe O4 - Startup: webfiltr - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\webfiltr.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 11894 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Abril 14, 2008 Opa REDENTOR, Poste um novo log do ComboFix. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Abril 15, 2008 Jgarcia, Eu rodei o combofix, mas antes de ele começar ele informou que o sistema não podia encontrar a msg 0x8 e também a 0x2371. Depois de terminar, também fez a mesma referência à mensagem 0x2. Seguem os logs do combofix e do hijackthis: ComboFix 08-04-13.3 - CRIS 2008-04-14 23:59:24.2 - NTFSx86 Executando de: C:\Users\CRIS\Desktop\ComboFix.exe * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_PortProxy ((((((((((((((((((((((( Ficheiros criados de 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))) . Nenhum ficheiro/arquivo criado durante este per¡odo . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-14 08:38 --------- d-----w C:\Program Files\Common Files\Adobe 2008-04-14 06:19 --------- d---a-w C:\ProgramData\TEMP 2008-04-14 04:08 318,369 ----a-w C:\HiJackThis.zip 2008-04-14 03:42 --------- d-----w C:\ProgramData\Google Updater 2008-04-14 03:29 --------- d-----w C:\Program Files\Spyware Doctor 2008-04-14 03:07 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools 2008-04-14 02:41 --------- d-----w C:\Program Files\Google 2008-04-13 20:40 --------- d-----w C:\ProgramData\Spybot - Search & Destroy 2008-04-11 09:50 --------- d-----w C:\Program Files\a-squared Free 2008-04-10 05:44 --------- d-----w C:\Program Files\K-Lite Codec Pack 2008-04-10 05:28 --------- d-----w C:\Program Files\F-Secure Internet Security 2008-04-10 05:05 60,064 ----a-w C:\Windows\system32\drivers\fsdfw.sys 2008-04-10 04:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\DivX 2008-04-10 04:01 --------- d-----w C:\Program Files\DivX 2008-04-10 03:59 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-04-09 17:54 --------- d-----w C:\ProgramData\F-Secure 2008-04-09 17:51 --------- d-----w C:\ProgramData\fssg 2008-04-09 17:42 --------- d-----w C:\Program Files\Real Alternative 2008-04-09 17:42 --------- d-----w C:\Program Files\Media Player Classic 2008-04-09 16:57 --------- d-----w C:\Program Files\K-Lite Video Conversion Pack 2008-04-09 15:14 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-04-09 14:53 --------- d-----w C:\ProgramData\WLInstaller 2008-04-09 14:01 --------- d-----w C:\Program Files\Windows Mail 2008-04-09 13:57 --------- d-----w C:\ProgramData\CyberLink 2008-04-09 13:53 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-04-09 07:18 --------- d-----w C:\Program Files\WinAVI Video Converter 2008-04-09 07:11 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys 2008-04-09 04:42 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio 2008-04-09 04:33 --------- d-----w C:\Users\CRIS\AppData\Roaming\U3 2008-04-08 16:23 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink 2008-04-08 16:07 --------- d-----w C:\Program Files\CyberLink 2008-04-08 08:03 --------- d-----w C:\Program Files\Windows Live Toolbar 2008-04-08 06:48 --------- d-----w C:\Users\CRIS\AppData\Roaming\Skype 2008-04-08 06:31 --------- d-----w C:\Program Files\Spybot - Search & Destroy 2008-04-08 06:31 --------- d-----w C:\Program Files\Opera 2008-04-08 06:31 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-04-08 06:30 --------- d-----w C:\Program Files\eMule 2008-04-08 06:30 --------- d-----w C:\Program Files\DVD Shrink 2008-04-08 06:30 --------- d-----w C:\Program Files\DVD Decrypter 2008-04-08 06:30 --------- d-----w C:\Program Files\Common Files\Skype 2008-04-08 06:30 --------- d-----w C:\Program Files\CCleaner 2008-04-08 06:30 --------- d-----w C:\Program Files\7-Zip 2008-04-08 04:56 --------- d-----w C:\Program Files\Programas RFB 2008-04-08 04:31 --------- d-----w C:\Program Files\Windows Live 2008-04-08 03:18 --------- d-----w C:\ProgramData\Skype 2008-04-08 03:18 --------- d-----w C:\Program Files\Skype 2008-04-07 16:44 --------- d-----w C:\ProgramData\eMule 2008-04-07 16:22 --------- d-----w C:\Program Files\Marcos Velasco Security 2008-04-07 08:03 --------- d-----w C:\Program Files\VS Revo Group 2008-04-07 08:01 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure 2008-04-07 07:36 --------- d-----w C:\Program Files\Common Files\Adobe(2) 2008-04-07 07:34 --------- d-----w C:\Program Files\Adobe(1) 2008-04-07 06:09 --------- d-----w C:\Program Files\MSXML 4.0 2008-04-07 06:08 691,545 ----a-w C:\Windows\unins000.exe 2008-04-07 05:50 --------- d-----w C:\ProgramData\McAfee 2008-04-07 05:48 --------- d-----w C:\Program Files\Windows Sidebar 2008-04-07 03:43 --------- d-----w C:\Program Files\Microsoft.NET 2008-04-07 03:23 --------- d-----w C:\Program Files\Roxio 2008-04-07 03:17 --------- d-----w C:\ProgramData\Roxio 2008-04-07 03:15 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-04-07 03:15 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys 2008-04-07 03:15 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-04-07 03:12 --------- d-----w C:\Program Files\Common Files\SureThing Shared 2008-04-07 03:08 --------- d-----w C:\Program Files\Common Files\Roxio Shared 2008-04-07 03:07 613,888 ----a-w C:\Windows\System32\wpd_ci.dll 2008-04-07 03:07 224,824 ----a-w C:\Windows\System32\clfs.sys 2008-04-07 03:07 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll 2008-04-07 03:07 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll 2008-04-07 03:07 101,888 ----a-w C:\Windows\System32\drvinst.exe 2008-04-07 03:03 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys 2008-04-07 03:03 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys 2008-04-07 03:02 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-04-07 03:02 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-04-07 03:02 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-04-07 03:02 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-04-07 03:02 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys 2008-04-07 03:02 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-04-07 03:02 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys 2008-04-07 03:02 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys 2008-04-07 03:01 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys 2008-04-07 03:01 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-04-07 03:01 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-04-07 03:01 217,144 ----a-w C:\Windows\system32\drivers\netio.sys 2008-04-07 03:01 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-04-07 03:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-04-07 03:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-04-07 03:00 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll 2008-04-07 03:00 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll 2008-04-07 03:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-04-07 03:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-04-07 03:00 1,686,528 ----a-w C:\Windows\System32\gameux.dll 2008-04-07 02:59 11,776 ----a-w C:\Windows\System32\sbunattend.exe 2008-04-07 02:11 53,080 ----a-w C:\Windows\System32\wuauclt.exe 2008-04-07 02:11 43,352 ----a-w C:\Windows\System32\wups2.dll 2008-04-07 02:11 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll 2008-04-07 02:11 1,524,224 ----a-w C:\Windows\System32\wucltux.dll 2008-04-07 02:09 80,896 ----a-w C:\Windows\System32\wudriver.dll 2008-04-07 02:09 549,720 ----a-w C:\Windows\System32\wuapi.dll 2008-04-07 02:09 33,624 ----a-w C:\Windows\System32\wups.dll 2008-04-07 02:08 31,232 ----a-w C:\Windows\System32\wuapp.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 09:34 201728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-07 03:49 159744] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 02:51 36864] "SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 08:07 405504] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-15 00:54 137752] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-15 00:53 154136] "Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-15 00:53 133656] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-03-18 14:19 77824] "DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 16:43 118784] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 22:26 68640] "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 22:17 52256] "F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2007-05-25 10:12 183208] "F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 10:11 740208] C:\Users\CRIS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ fsavaui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe [2008-04-09 14:52:44 1944432] fsavgui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe [2008-04-09 14:52:44 1051504] FsDiagUi - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe [2008-04-09 14:52:45 539504] fsgetwab - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe [2008-04-09 14:52:45 326512] fsguidll - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe [2008-04-09 14:52:45 465776] fssw - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe [2008-04-09 14:52:46 760688] fstlui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe [2008-04-09 14:52:47 609136] postinstall - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe [2008-04-09 14:52:48 535408] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-18 14:20:25 50688] Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-13 23:39:44 124400] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{E43D03BF-D0D6-4997-ACE6-270DEE580CB2}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{89E9B8A9-8B45-46CD-AC7C-EE34E7867DE6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05] R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-04-10 02:04] R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 10:09] R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-04-10 02:05] R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 10:08] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-11-12 08:07] R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 21:39] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 10:08] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-12-15 00:53] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-12-15 00:54] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 02:51] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 02:51] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 02:31] S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 04:36] S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 10:09] S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 10:09] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19026666-0445-11dd-a0c1-001d0941e348}] \shell\AutoRun\command - G:\LaunchU3.exe -a . Conte£do da pasta 'Tarefas Agendadas' "2008-04-15 03:10:13 C:\Windows\Tasks\Scheduled scanning task.job" - C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-15 00:10:52 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Windows\System32\audiodg.exe C:\Windows\System32\wlanext.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\System32\stacsv.exe C:\Windows\System32\drivers\XAudio.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\wbem\unsecapp.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\Windows\System32\igfxsrvc.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\hidfind.exe C:\Program Files\DellTPad\ApntEx.exe C:\Program Files\F-Secure Internet Security\Common\FSLAUNCH.EXE . ************************************************************************** . Tempo para conclusÆo: 2008-04-15 0:18:06 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-15 03:17:39 O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. O sistema nÆo pode encontrar o texto correspondente … mensagem de n£mero 0x2379 no arquivo de mensagens para Application. . 2008-04-11 07:15:37 --- E O F --- ------------------------------------------------------------------------------------------------------------------------------------------------------------------ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:48:03, on 15/04/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Windows\OEM02Mon.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\unsecapp.exe C:\Users\CRIS\AppData\Local\Temp\Temp2_HiJackThis.zip\HijackThis.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Startup: fsavaui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe O4 - Startup: fsavgui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe O4 - Startup: FsDiagUi - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe O4 - Startup: fsgetwab - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe O4 - Startup: fsguidll - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe O4 - Startup: fssw - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe O4 - Startup: fstlui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe O4 - Startup: postinstall - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 9655 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Abril 27, 2008 O autor do tópico formatou a máquina, no entanto o mesmo permanecerá aberto por mais uma semana. Após este prazo o tópico será fechado e considerado resolvido. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Abril 30, 2008 Oi jgarcia, tudo bem? Poderia olhar meu log novamente, por favor? Algumas funções do meu antivirus pararam de funcionar (quando eu mando escanear, antes de começar aparece msg informando que o programa parou de responder) e alguns programas estão travando também... Abraço! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:38:03, on 30/04/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Windows\OEM02Mon.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Norton Ghost\Agent\VProTray.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Windows\system32\aestsrv.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Windows\system32\svchost.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\dllhost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Windows\system32\taskeng.exe C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\Windows\system32\dllhost.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe C:\Windows\System32\msdtc.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\Windows\system32\conime.exe C:\Program Files\iolo\System Mechanic Professional 7\SysMech7.exe C:\HiJackThis\HijackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe" O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O13 - Gopher Prefix: O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u...ows-i586-jc.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: Gerenciador do Google Desktop 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 12445 bytes -------------------------------------------------------------------------------- ComboFix 08-04-29.3 - CRIS 2008-04-30 3:15:57.2 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.1677 [GMT -3:00] Executando de: C:\Users\CRIS\Desktop\ComboFix.exe . ((((((((((((((((((((((( Ficheiros criados de 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))) . Nenhum ficheiro/arquivo criado durante este período . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-30 06:04 --------- d---a-w C:\ProgramData\TEMP 2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip 2008-04-30 05:13 102,664 ----a-w C:\Windows\system32\drivers\tmcomm.sys 2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0 2008-04-30 04:45 --------- d-----w C:\ProgramData\iolo 2008-04-30 04:45 --------- d-----w C:\Program Files\iolo 2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink 2008-04-30 03:45 --------- d-----w C:\Program Files\Opera 2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink 2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink 2008-04-30 01:23 --------- d-----w C:\ProgramData\Google Updater 2008-04-29 17:41 --------- d-----w C:\Users\CRIS\AppData\Roaming\Skype 2008-04-29 17:39 --------- d-----w C:\Program Files\Java 2008-04-29 17:11 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live 2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm 2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller 2008-04-29 07:27 --------- d-----w C:\Program Files\Common Files\Software FX Shared 2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm 2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule 2008-04-29 07:18 --------- d-----w C:\Program Files\K-Lite Codec Pack 2008-04-29 07:04 --------- d-----w C:\Program Files\eMule 2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security 2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec 2008-04-29 05:35 --------- d-----w C:\Program Files\WinAVIVideoConverter 2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys 2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-29 04:37 --------- d-----w C:\Program Files\Norton Ghost 2008-04-29 04:35 --------- d-----w C:\Program Files\7-Zip 2008-04-29 03:19 --------- d-----w C:\Users\CRIS\AppData\Roaming\iolo 2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio 2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro 2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure 2008-04-29 02:08 --------- d-----w C:\ProgramData\Roxio 2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll 2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name 2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared 2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield 2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio 2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-04-29 00:42 --------- d-----w C:\Program Files\Spyware Doctor 2008-04-28 02:03 --------- d-----w C:\Program Files\Sun 2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java 2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe 2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype 2008-04-27 03:28 --------- d-----w C:\Program Files\Skype 2008-04-27 03:28 --------- d-----w C:\Program Files\Common Files\Skype 2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools 2008-04-27 01:58 --------- d-----w C:\Program Files\Picasa2 2008-04-27 01:51 --------- d-----w C:\Program Files\Google 2008-04-27 01:47 --------- d-----w C:\Program Files\CCleaner 2008-04-27 01:38 --------- d-----w C:\Program Files\DVD Shrink 2008-04-27 01:33 --------- d-----w C:\Program Files\DVD Decrypter 2008-04-27 00:58 --------- d-----w C:\Program Files\F-Secure Internet Security 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Mail 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar 2008-04-26 07:14 60,064 ----a-w C:\Windows\system32\drivers\fsdfw.sys 2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll 2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll 2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll 2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll 2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll 2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll 2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll 2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys 2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys 2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll 2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys 2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll 2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic 2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared 2008-04-26 06:40 --------- d-----w C:\ProgramData\F-Secure 2008-04-26 06:39 --------- d-----w C:\ProgramData\fssg 2008-04-26 06:33 --------- d-----w C:\Program Files\Intel 2008-04-26 06:31 174 --sha-w C:\Program Files\desktop.ini 2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar 2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll 2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll 2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys 2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll 2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll 2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll 2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys 2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll 2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll 2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS 2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys 2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys . ((((((((((((((((((((((((((((( snapshot@2008-04-30_ 3.12.45,48 ))))))))))))))))))))))))))))))))))))))))) . - 2008-04-30 06:07:57 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-04-30 06:16:00 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544] "DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424] "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616] "F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2007-05-25 10:12 183208] "F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 10:11 740208] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184] "Norton Ghost 14.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-01-19 20:01 2245984] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400] QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= divxa32.acm "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05] R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12] R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-04-26 04:11] R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 10:09] R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-04-26 04:14] R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 10:08] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31] R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23] R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45] R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39] R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 10:08] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45] R3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22] S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19] S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51] S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 10:09] S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 10:09] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc *Newly Created Service* - CATCHME . Conteúdo da pasta 'Tarefas Agendadas' "2008-04-30 05:02:14 C:\Windows\Tasks\Scheduled scanning task.job" - C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-30 03:17:34 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-04-30 3:18:12 ComboFix-quarantined-files.txt 2008-04-30 06:18:08 ComboFix2.txt 2008-04-30 06:13:06 O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. 212 --- E O F --- 2008-04-30 05:00:34 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Maio 8, 2008 Opa REDENTOR, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::C:\Program Files\desktop.ini ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Maio 8, 2008 Olá jgarcia, Não sei se ajuda informar, mas agora, além dos programas não funcionarem, a minha rede sem fio também não é mais detectada, nem do lado do roteador. E também, tenho programas originais que quando tento instalar de novo, acusam que o serial é inválido :blink: Seguem os logs que você pediu abaixo. Abraço. ComboFix 08-04-29.3 - CRIS 2008-05-08 1:24:21.3 - NTFSx86 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.1556 [GMT -3:00] Executando de: C:\Users\CRIS\Desktop\ComboFix.exe Command switches used :: C:\Users\CRIS\Desktop\CFScript.txt * Criado um novo ponto de restauro FILE :: C:\Program Files\desktop.ini . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\desktop.ini . ((((((((((((((((((((((( Ficheiros criados de 2008-04-08 to 2008-05-08 )))))))))))))))))))))))))))))))) . Nenhum ficheiro/arquivo criado durante este período . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-08 03:35 --------- d---a-w C:\ProgramData\TEMP 2008-05-08 03:32 --------- d-----w C:\ProgramData\Google Updater 2008-05-08 03:17 --------- d-----w C:\Program Files\F-Secure Internet Security 2008-05-08 03:17 --------- d-----w C:\Program Files\Common Files\Software FX Shared 2008-04-30 15:41 --------- d-----w C:\ProgramData\iolo 2008-04-30 15:21 --------- d-----w C:\ProgramData\F-Secure 2008-04-30 15:19 --------- d-----w C:\ProgramData\fssg 2008-04-30 07:09 --------- d-----w C:\Program Files\PCCheckupOnline 2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip 2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0 2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink 2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink 2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink 2008-04-29 17:39 --------- d-----w C:\Program Files\Java 2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live 2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm 2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller 2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm 2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule 2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security 2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec 2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys 2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio 2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro 2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure 2008-04-29 02:08 --------- d-----w C:\ProgramData\Roxio 2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll 2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name 2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared 2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield 2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio 2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-04-28 02:03 --------- d-----w C:\Program Files\Sun 2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java 2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe 2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype 2008-04-27 03:28 --------- d-----w C:\Program Files\Skype 2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar 2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll 2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll 2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll 2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll 2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll 2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll 2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll 2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys 2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys 2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll 2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys 2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll 2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic 2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared 2008-04-26 06:33 --------- d-----w C:\Program Files\Intel 2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar 2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll 2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll 2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys 2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll 2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll 2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll 2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys 2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll 2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll 2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS 2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys 2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys 2008-04-26 06:21 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys 2008-04-26 06:21 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-04-26 06:21 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys 2008-04-26 06:21 104,448 ----a-w C:\Windows\System32\DWWIN.EXE 2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hcrstco.dll 2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hccoin.dll 2008-04-26 06:20 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys 2008-04-26 06:20 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys 2008-04-26 06:20 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys 2008-04-26 06:20 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys 2008-04-26 06:20 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys 2008-04-26 06:20 2,048 ----a-w C:\Windows\System32\msxml3r.dll 2008-04-26 06:20 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys 2008-04-26 06:20 1,191,936 ----a-w C:\Windows\System32\msxml3.dll 2008-04-26 06:19 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys 2008-04-26 06:19 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-04-26 06:19 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-04-26 06:19 216,632 ----a-w C:\Windows\system32\drivers\netio.sys 2008-04-26 06:19 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll 2008-04-26 06:18 1,327,104 ----a-w C:\Windows\System32\quartz.dll . ((((((((((((((((((((((((((((( snapshot@2008-04-30_ 3.12.45,48 ))))))))))))))))))))))))))))))))))))))))) . - 2008-04-30 06:05:13 67,584 --s-a-w C:\Windows\bootstat.dat + 2008-05-08 03:17:50 67,584 --s-a-w C:\Windows\bootstat.dat + 2006-10-27 18:26:40 16,870,712 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\MSO.DLL + 2006-10-27 18:14:34 14,151,456 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OART.DLL + 2006-10-26 23:42:36 8,423,224 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OARTCONV.DLL + 2006-10-27 18:18:36 1,658,152 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OGL.DLL + 2006-10-27 00:08:00 1,764,112 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\PPCNV.DLL + 2006-10-27 00:07:50 67,920 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\PXBCOM.EXE - 2008-04-26 05:34:52 49,936 ----a-r C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe + 2008-04-30 07:57:56 49,936 ----a-r C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe + 2008-04-30 15:18:14 32,768 ----a-r C:\Windows\Installer\{C523D256-313D-4866-B36A-F3DE528246EF}\icon.exe - 2008-04-30 06:05:14 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2008-05-08 03:17:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2008-04-30 06:05:14 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2008-05-08 03:17:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2008-04-30 06:07:58 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-08 03:39:09 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat - 2008-04-30 06:07:29 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT + 2008-05-08 03:20:25 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT + 2008-05-08 03:20:25 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 - 2008-04-30 06:07:57 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-08 04:23:58 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat - 2008-04-30 06:07:24 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2008-05-08 03:20:20 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT + 2008-05-08 03:20:20 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 - 2008-04-30 06:06:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-05-08 03:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2008-04-30 06:06:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-05-08 03:35:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-04-26 04:58:06 262,144 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-05-05 06:13:53 262,144 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat - 2008-04-30 06:06:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-05-08 03:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-04-30 06:09:57 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat + 2008-05-08 03:11:04 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat - 2008-04-26 07:14:18 60,064 ----a-w C:\Windows\System32\drivers\fsdfw.sys + 2007-05-25 13:10:00 67,120 ----a-w C:\Windows\System32\drivers\fsdfw.sys - 2008-04-30 05:13:03 102,664 ----a-w C:\Windows\System32\drivers\tmcomm.sys + 2007-12-24 20:37:00 138,384 ----a-w C:\Windows\System32\drivers\tmcomm.sys - 2007-05-08 18:03:04 1,275,392 ----a-w C:\Windows\System32\msxml4.dll + 2007-08-24 21:08:24 1,275,392 ----a-w C:\Windows\System32\msxml4.dll - 2008-04-29 02:13:21 106,908 ----a-w C:\Windows\System32\perfc009.dat + 2008-04-30 15:21:01 105,138 ----a-w C:\Windows\System32\perfc009.dat - 2008-04-29 02:13:21 616,832 ----a-w C:\Windows\System32\perfh009.dat + 2008-04-30 15:21:01 612,758 ----a-w C:\Windows\System32\perfh009.dat - 2008-04-29 02:13:21 85,962 ----a-w C:\Windows\System32\prfc0416.dat + 2008-04-30 15:21:01 84,192 ----a-w C:\Windows\System32\prfc0416.dat - 2008-04-29 02:13:21 512,288 ----a-w C:\Windows\System32\prfh0416.dat + 2008-04-30 15:21:01 508,214 ----a-w C:\Windows\System32\prfh0416.dat - 2008-04-30 05:01:13 6,029,312 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT + 2008-04-30 07:58:08 6,029,312 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat - 2008-04-30 06:07:43 6,036 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-879540782-419363104-1388336070-1000_UserData.bin + 2008-05-08 03:21:05 6,704 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-879540782-419363104-1388336070-1000_UserData.bin - 2008-04-30 06:07:43 58,474 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2008-05-08 03:21:04 62,312 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2008-04-30 06:07:40 38,788 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-05-08 02:55:09 40,214 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin - 2008-04-30 05:00:31 139,732 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin + 2008-04-30 15:18:28 155,189 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin + 2008-04-30 15:18:19 1,275,392 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7\msxml4.dll . -- Snapshot reset to current date -- . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544] "DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424] "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184] "Norton Ghost 14.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-01-19 20:01 2245984] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568] "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400] QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= divxa32.acm "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05] R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12] R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2007-05-25 10:10] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31] R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23] R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39] R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45] R3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22] S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45] S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19] S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc *Newly Created Service* - ELRAWDISK . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-08 01:26:09 Windows 6.0.6000 NTFS detected NTDLL code modification: ZwClose Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-05-08 1:26:57 ComboFix-quarantined-files.txt 2008-05-08 04:26:53 ComboFix2.txt 2008-04-30 06:13:06 O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. 265 --- E O F --- 2008-04-30 15:18:31 --------------------------------------------------------------------------------------------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:38:01, on 08/05/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\a-squared Free\a2service.exe C:\Windows\system32\aestsrv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\Windows\system32\svchost.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\System32\svchost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe C:\Windows\System32\msdtc.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\WLTRAY.EXE C:\Windows\system32\igfxsrvc.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\OEM02Mon.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Norton Ghost\Agent\VProTray.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\wmiprvse.exe c:\program files\common files\installshield\updateservice\isuspm.exe C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell Support Center\gs_agent\dsc.exe C:\Windows\system32\conime.exe C:\Windows\system32\dllhost.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\Explorer.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\HiJackThis\HijackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe" O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O13 - Gopher Prefix: O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u...ows-i586-jc.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: Gerenciador do Google Desktop 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 11072 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Maio 11, 2008 Opa REDENTOR, O problema não parece possuir relação com malwares. A máquina reinicia ou trava constantemente? Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Maio 12, 2008 Opa REDENTOR, O problema não parece possuir relação com malwares. A máquina reinicia ou trava constantemente? Não, mas os programas páram de responder... antes eu clicava, eles funcionavam e depois travavam, e aí aparecia a msg de que o programa parou de responder... agora tá pior, quando eu clico, o programa nem abre, já aparece direto a msg de que parou de responder e foi fechado. E não funciona mais... Nem o antivirus funciona, nem o windows defender, nem o system mechanic, nem o anti-spyware... e antes de "morrer" de vez o antivirus acusou 2 arquivos maliciosos, e fechou em seguida, sem que eu pudesse colocar em quarentena e/ou excluir. Eu anotei o nome dos arquivos (não eram de sistema), entrei pelo modo de segurança e consegui apagar, mas não sei se ficou resquício. Depois disso nunca mais consegui usar nenhum programa de segurança, nem instalando de novo. O antispyware detectou 1 trojan e 1 backdoor antes de também parar de funcionar... Veja, eu tenho outra partição, com o mesmo sistema operacional, mesmos drives etc. Tudo funciona perfeitamente, a rede sem fio é detectada, e quando vou instalar o system mechanic coloco o serial e entra normalmente , ao contrário do que está acontecendo recentemente com a partição problema... Sinceramente, continuo achando que tem alguma coisa errada com o micro... Ah, fiquei com uma dúvida: o que significa essa linha do log: "detected NTDLL code modification: ZwClose" É algum problema? Abraço!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Maio 14, 2008 Opa REDENTOR, Execute o ComboFix em Modo Seguro e retorne com o resultado. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Maio 15, 2008 Olá jgarcia!! Segue o log, obrigada. ComboFix 08-05-12.1 - CRIS 2008-05-15 6:10:09.4 - NTFSx86 MINIMAL Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.2128 [GMT -3:00] Executando de: C:\Users\CRIS\Desktop\ComboFix.exe . ((((((((((((((((((((((( Ficheiros criados de 2008-04-15 to 2008-05-15 )))))))))))))))))))))))))))))))) . Nenhum ficheiro/arquivo criado durante este período . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-15 09:08 --------- d---a-w C:\ProgramData\TEMP 2008-05-09 02:52 --------- d-----w C:\ProgramData\Roxio 2008-05-09 01:38 --------- d-----w C:\Program Files\Dell Support Center 2008-05-09 01:38 --------- d-----w C:\Program Files\Common Files\supportsoft 2008-05-08 03:32 --------- d-----w C:\ProgramData\Google Updater 2008-05-08 03:17 --------- d-----w C:\Program Files\F-Secure Internet Security 2008-05-08 03:17 --------- d-----w C:\Program Files\Common Files\Software FX Shared 2008-04-30 15:41 --------- d-----w C:\ProgramData\iolo 2008-04-30 15:21 --------- d-----w C:\ProgramData\F-Secure 2008-04-30 15:19 --------- d-----w C:\ProgramData\fssg 2008-04-30 07:09 --------- d-----w C:\Program Files\PCCheckupOnline 2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip 2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0 2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink 2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink 2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink 2008-04-29 17:39 --------- d-----w C:\Program Files\Java 2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live 2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm 2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller 2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm 2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule 2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security 2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec 2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys 2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec 2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio 2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro 2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure 2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll 2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name 2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared 2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield 2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio 2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-04-28 02:03 --------- d-----w C:\Program Files\Sun 2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java 2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe 2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype 2008-04-27 03:28 --------- d-----w C:\Program Files\Skype 2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender 2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar 2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll 2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll 2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll 2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll 2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll 2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll 2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll 2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys 2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys 2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll 2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys 2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll 2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic 2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared 2008-04-26 06:33 --------- d-----w C:\Program Files\Intel 2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar 2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll 2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll 2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys 2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll 2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll 2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll 2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys 2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll 2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll 2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS 2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys 2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys 2008-04-26 06:21 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys 2008-04-26 06:21 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-04-26 06:21 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys 2008-04-26 06:21 104,448 ----a-w C:\Windows\System32\DWWIN.EXE 2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hcrstco.dll 2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hccoin.dll 2008-04-26 06:20 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys 2008-04-26 06:20 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys 2008-04-26 06:20 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys 2008-04-26 06:20 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys 2008-04-26 06:20 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys 2008-04-26 06:20 2,048 ----a-w C:\Windows\System32\msxml3r.dll 2008-04-26 06:20 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys 2008-04-26 06:20 1,191,936 ----a-w C:\Windows\System32\msxml3.dll 2008-04-26 06:19 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys 2008-04-26 06:19 24,064 ----a-w C:\Windows\System32\netcfg.exe 2008-04-26 06:19 22,016 ----a-w C:\Windows\System32\netiougc.exe 2008-04-26 06:19 216,632 ----a-w C:\Windows\system32\drivers\netio.sys . ------- Sigcheck ------- . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544] "DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424] "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656] "Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616] "OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568] "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400] QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= divxa32.acm "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05] S1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2007-05-25 10:10] S2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31] S2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23] S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45] S2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39] S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19] S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51] S3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21] S3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03] S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45] S3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13] S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc *Newly Created Service* - ECACHE . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-15 06:13:20 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-05-15 6:13:44 ComboFix-quarantined-files.txt 2008-05-15 09:13:42 ComboFix2.txt 2008-05-08 04:26:58 O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application. 192 --- E O F --- 2008-04-30 15:18:31 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Maio 18, 2008 Opa REDENTOR, Baixe o F-Secure Blacklight em: F-Secure Blacklight Salve-o em sua área de trabalho (desktop) e o execute. Aceite o acordo. Clique em Scan e aguarde. Se ele encontrar algum arquivo, ignore, pois quero apenas o log. Ao final do scan será gerado o arquivo fsbl-xxxxx.log (onde xxx são números). Preciso que você copie o log e poste em sua próxima resposta. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Maio 20, 2008 Jgarcia, Baixei o arquivo através da outra partição, de onde consigo (por enquanto) acessar a rede. Como fiquei em dúvida se iria escanear o micro todo ou só aquela partição, fiz o seguinte: escaneei a partir dali mesmo, e depois copiei o arquivo pra partição-mais-problema (a outra já está apresentando problemas também) e executei. Assim, o 2o log é o correspondente à partição que estamos tentanto resolver no momento... obs: há uns dias atrás, percebi no "controle de aplicativos" do antivirus (que lista os aplicativos com atividade suspeita), alguns arquivos temporários listados, e que tinham permissão para serem executados. Achei estranho e apaguei todos... e aproveitei pra desinstalar o antivirus também, pois já não funcionava mais mesmo, e também não ia precisar, já que não tenho mais acesso à rede... Obrigada pela ajuda, grande abraço! 05/19/08 21:28:32 [info]: BlackLight Engine 1.0.70 initialized 05/19/08 21:28:32 [info]: OS: 6.0 build 6001 (Service Pack 1) 05/19/08 21:28:33 [Note]: 7019 4 05/19/08 21:28:33 [Note]: 7005 0 05/19/08 21:28:58 [Note]: 7006 0 05/19/08 21:28:58 [Note]: 7027 0 05/19/08 21:28:59 [Note]: 7035 0 05/19/08 21:28:59 [Note]: 7026 0 05/19/08 21:29:00 [Note]: 7026 0 05/19/08 21:29:03 [Note]: FSRAW library version 1.7.1024 05/19/08 21:33:24 [Note]: 4015 1455 05/19/08 21:33:24 [Note]: 4027 1455 65536 05/19/08 21:33:24 [Note]: 4020 553 65536 05/19/08 21:33:24 [Note]: 4018 553 65536 05/19/08 21:40:08 [Note]: 7007 0 05/19/08 21:44:57 [info]: BlackLight Engine 1.0.70 initialized 05/19/08 21:44:57 [info]: OS: 6.0 build 6000 () 05/19/08 21:44:57 [Note]: 7019 4 05/19/08 21:44:57 [Note]: 7005 0 05/19/08 21:45:02 [Note]: 7006 0 05/19/08 21:45:02 [Note]: 7027 0 05/19/08 21:45:02 [Note]: 7035 0 05/19/08 21:45:02 [Note]: 7026 0 05/19/08 21:45:02 [Note]: 7026 0 05/19/08 21:45:05 [Note]: FSRAW library version 1.7.1024 05/19/08 21:54:47 [Note]: 7007 0 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Maio 26, 2008 Opa REDENTOR, Baixe o SilentRunners. Extraia o arquivo SilentRunners.vbs para o C. Dê duplo clique sobre o arquivo para executá-lo. Após executá-lo aguarde até que seja gerado um documento denominado Startup Programs (USUÁRIO) data. Copie o conteúdo deste documento e cole em sua próxima resposta. Abraços. Obs.: Caso o seu AV detecte o arquivo como sendo um script malicioso não se preocupe e autorize a execução. Compartilhar este post Link para o post Compartilhar em outros sites
REDENTOR 0 Denunciar post Postado Maio 26, 2008 jgarcia, Acho que fiz alguma coisa errada, porque eu salvei em c: e extrai em c:, mas quando eu dei duplo clique apareceu apenas uma janela do bloco de notas, falando sobre o silent runners... não aconteceu mais nada... Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Junho 10, 2008 jgarcia, Acho que fiz alguma coisa errada, porque eu salvei em c: e extrai em c:, mas quando eu dei duplo clique apareceu apenas uma janela do bloco de notas, falando sobre o silent runners... não aconteceu mais nada... Baixei aqui e funcionou perfeitamente. Tente executá-lo mais uma vez. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites