Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

REDENTOR

[Arquivado] Micro lento, programas não respondem

Recommended Posts

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 03:41:48, on 28/03/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16609)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\OEM02Mon.exe

C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe

C:\Windows\System32\mobsync.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fornecido por Dell

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE')

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O13 - Gopher Prefix:

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 8089 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

2) Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir. O processo vai durar, em média, 10 minutos;

3) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção);

4) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt;

5) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco);

6) Para parar ou sair do ComboFix, tecle "N";

7) Reabilite o seu anti-vírus;

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta, juntamente com um novo log do HijackThis.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Rodei o Combofix como você pediu. Qdo ele termina, abre-se uma janela do bloco de notas com a msg:

[.ShellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787, que nunca tinha aparecido...

 

Seguem os logs, abraços.

 

 

ComboFix 08-03-30.4 - CRIS 2008-04-04 4:44:56.2 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.102 [GMT -3:00]

Executando de: C:\Users\CRIS\Desktop\ComboFix.exe

.

TimedOut: Windir.dat

 

((((((((((((((((((((((( Ficheiros criados de 2008-03-04 to 2008-04-04 ))))))))))))))))))))))))))))))))

.

 

2008-04-04 03:21 . 2008-04-04 03:21 <DIR> d-------- C:\Program Files\Programas RFB

2008-04-04 03:20 . 2008-04-04 04:25 <DIR> d-------- C:\Program Files\SpywareGuard

2008-04-03 22:07 . 2008-04-03 22:07 <DIR> d-------- C:\Windows\System32\Kaspersky Lab

2008-03-31 13:49 . 2008-03-31 13:49 8,627 --a------ C:\Windows\System32\PAV_FOG.OPC

2008-03-31 13:13 . 2008-03-31 13:13 <DIR> d-------- C:\Users\All Users\sentinel

2008-03-31 13:13 . 2008-03-31 13:13 <DIR> d-------- C:\ProgramData\sentinel

2008-03-31 12:58 . 2008-03-31 12:58 <DIR> d-------- C:\Users\All Users\Backup

2008-03-31 12:58 . 2008-03-31 12:58 <DIR> d-------- C:\ProgramData\Backup

2008-03-31 12:56 . 2008-03-31 12:56 <DIR> d-------- C:\Program Files\Panda Security

2008-03-31 06:17 . 2008-04-02 01:11 <DIR> d-------- C:\Program Files\Common Files\Panda Software

2008-03-31 04:04 . 2008-03-31 04:11 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\U3

2008-03-30 21:04 . 2007-09-20 14:12 12,800 --a------ C:\Windows\System32\drivers\elrawdsk.sys

2008-03-30 20:52 . 2008-03-30 20:52 74,703 --a------ C:\Windows\System32\mfc45.dll

2008-03-30 19:27 . 2008-03-30 19:27 <DIR> d-------- C:\Program Files\GbPlugin

2008-03-30 19:26 . 2008-03-30 19:27 <DIR> d-------- C:\Users\All Users\GbPlugin

2008-03-30 19:26 . 2008-03-30 19:27 <DIR> d-------- C:\ProgramData\GbPlugin

2008-03-30 19:20 . 2008-04-02 01:17 <DIR> d-------- C:\Program Files\Trend Micro

2008-03-30 17:29 . 2008-03-30 19:58 <DIR> d-------- C:\Users\CRIS\.housecall6.6

2008-03-28 16:00 . 2008-03-28 16:00 194,560 --a------ C:\Windows\System32\WebClnt.dll

2008-03-28 16:00 . 2008-03-28 16:00 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys

2008-03-28 15:50 . 2008-03-28 15:50 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\VSRevoGroup

2008-03-28 15:20 . 2008-03-28 15:20 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\TuneUp Software

2008-03-28 14:53 . 2008-03-28 14:53 63 --a------ C:\Windows\system\SysSD.dll

2008-03-28 14:03 . 2008-03-30 22:01 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\iolo

2008-03-28 14:03 . 2008-03-31 03:27 <DIR> d-------- C:\Users\All Users\iolo

2008-03-28 14:03 . 2008-03-31 03:27 <DIR> d-------- C:\ProgramData\iolo

2008-03-28 14:03 . 2008-03-31 03:30 <DIR> d-------- C:\Program Files\iolo

2008-03-28 14:03 . 2008-03-28 14:03 406 --a------ C:\Windows\System32\ioloBootDefrag.cfg

2008-03-28 04:12 . 2008-03-28 08:57 <DIR> d-------- C:\Windows\BDOSCAN8

2008-03-28 03:39 . 2007-06-28 14:36 401,720 --a------ C:\HijackThis.exe

2008-03-27 14:03 . 2008-03-27 14:03 <DIR> d-------- C:\Users\All Users\Kaspersky Lab

2008-03-27 14:03 . 2008-03-27 14:03 <DIR> d-------- C:\ProgramData\Kaspersky Lab

2008-03-27 13:59 . 2008-03-27 13:59 <DIR> d-------- C:\Windows\Sun

2008-03-27 03:18 . 2008-03-27 23:42 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Vso

2008-03-27 01:24 . 2008-03-27 14:37 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\CyberLink

2008-03-26 23:26 . 2008-03-26 23:32 <DIR> d-------- C:\Program Files\Windows Live Toolbar

2008-03-26 05:40 . 2008-03-27 02:28 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Skype

2008-03-26 05:39 . 2007-12-15 00:54 180,224 --a------ C:\Windows\System32\igfxres.dll

2008-03-26 05:14 . 2002-07-07 23:14 1,294,336 --a------ C:\Windows\System32\vorbis.acm

2008-03-26 05:14 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll

2008-03-26 05:12 . 2007-12-24 13:49 7,680 --a------ C:\Windows\System32\ff_vfw.dll

2008-03-26 05:12 . 2007-07-10 17:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest

2008-03-26 05:11 . 2008-03-26 05:15 <DIR> d-------- C:\Program Files\K-Lite Codec Pack

2008-03-26 05:10 . 2008-04-02 23:35 3,082 --a------ C:\Windows\System32\affv208325p1now.sys

2008-03-26 04:59 . 2008-03-26 23:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller

2008-03-26 04:55 . 2008-03-27 00:34 <DIR> d-------- C:\Program Files\Windows Live

2008-03-26 04:35 . 2008-03-26 04:35 <DIR> d-------- C:\Program Files\URUSoft

2008-03-26 04:32 . 2008-03-26 04:34 <DIR> d-------- C:\Program Files\Picasa2

2008-03-26 04:20 . 2008-03-26 04:24 <DIR> d-------- C:\Program Files\Skype

2008-03-26 04:17 . 2008-03-26 04:18 <DIR> d-------- C:\Program Files\Common Files\Skype

2008-03-26 04:10 . 2001-03-08 18:30 24,064 --------- C:\Windows\System32\msxml3a.dll

2008-03-26 02:36 . 2008-03-28 00:14 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\F-Secure

2008-03-26 00:49 . 2008-04-02 23:36 <DIR> d-------- C:\Program Files\WinAVIVideoConverter

2008-03-26 00:49 . 2007-05-25 10:15 572,784 --a------ C:\Windows\System32\msvcp50.dll

2008-03-26 00:48 . 2008-03-26 00:48 <DIR> d-------- C:\Program Files\Common Files\xing shared

2008-03-26 00:47 . 2008-04-04 04:36 <DIR> d-------- C:\Users\All Users\F-Secure

2008-03-26 00:47 . 2008-04-04 04:36 <DIR> d-------- C:\ProgramData\F-Secure

2008-03-26 00:45 . 2008-03-26 00:45 <DIR> d-------- C:\Program Files\Real

2008-03-26 00:45 . 2008-04-04 04:41 <DIR> d-------- C:\Program Files\F-Secure Internet Security

2008-03-26 00:45 . 2008-03-26 00:48 <DIR> d-------- C:\Program Files\Common Files\Real

2008-03-25 23:57 . 2008-03-25 23:57 <DIR> d-------- C:\Program Files\VS Revo Group

2008-03-25 23:54 . 2008-04-04 03:32 <DIR> d-------- C:\Users\All Users\fssg

2008-03-25 23:54 . 2008-04-04 03:32 <DIR> d-------- C:\ProgramData\fssg

2008-03-25 23:48 . 2008-03-25 23:51 <DIR> d-------- C:\Program Files\Opera

2008-03-25 23:43 . 2008-03-26 04:21 <DIR> d-------- C:\Users\All Users\Skype

2008-03-25 23:43 . 2008-03-26 04:21 <DIR> d-------- C:\ProgramData\Skype

2008-03-25 23:41 . 2008-03-25 23:42 <DIR> d-------- C:\Program Files\DVD Decrypter

2008-03-25 23:17 . 2007-04-09 13:23 28,040 --a------ C:\Windows\System32\mdimon.dll

2008-03-25 23:17 . 2008-03-25 23:17 418 --a------ C:\Windows\ODBC.INI

2008-03-25 23:14 . 2008-03-25 23:15 <DIR> d-------- C:\Windows\SHELLNEW

2008-03-25 23:14 . 2008-03-25 23:14 <DIR> d-------- C:\Windows\PCHEALTH

2008-03-25 23:14 . 2008-03-25 23:14 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-03-25 23:05 . 2008-03-25 23:05 <DIR> d-------- C:\Users\All Users\eMule

2008-03-25 23:05 . 2008-03-25 23:05 <DIR> d-------- C:\ProgramData\eMule

2008-03-25 23:04 . 2008-03-25 23:04 <DIR> dr-h----- C:\MSOCache

2008-03-25 14:03 . 2008-03-25 14:03 <DIR> d-------- C:\Users\CRIS\AppData\Roaming\Creative

2008-03-25 14:03 . 2008-03-25 14:03 595,456 --a------ C:\Windows\System32\schedsvc.dll

2008-03-25 14:03 . 2008-03-25 14:03 115,200 --a------ C:\Windows\System32\loadperf.dll

2008-03-25 14:03 . 2008-03-25 14:03 39,424 --a------ C:\Windows\System32\lodctr.exe

2008-03-25 14:03 . 2008-03-25 14:03 32,256 --a------ C:\Windows\System32\unlodctr.exe

2008-03-25 14:03 . 2008-03-25 14:03 17,408 --a------ C:\Windows\System32\prflbmsg.dll

2008-03-25 14:02 . 2008-03-25 14:02 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe

2008-03-25 14:02 . 2008-03-25 14:02 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe

2008-03-25 14:02 . 2008-03-25 14:02 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys

2008-03-25 14:02 . 2008-03-25 14:02 41,984 --a------ C:\Windows\System32\drivers\monitor.sys

2008-03-25 14:00 . 2008-03-25 14:00 11,776 --a------ C:\Windows\System32\sbunattend.exe

2008-03-25 13:59 . 2008-03-27 00:24 <DIR> d-------- C:\Users\All Users\WLInstaller

2008-03-25 13:59 . 2008-03-27 00:24 <DIR> d-------- C:\ProgramData\WLInstaller

2008-03-25 13:58 . 2008-03-25 13:58 <DIR> d-------- C:\Program Files\MSXML 4.0

2008-03-25 13:54 . 2008-03-25 13:54 1,383,424 --a------ C:\Windows\System32\mshtml.tlb

2008-03-25 13:39 . 2008-03-25 13:39 <DIR> d-------- C:\Program Files\YourWare Solutions

2008-03-25 13:38 . 2008-04-03 00:44 <DIR> d-------- C:\Users\All Users\DVD Shrink

2008-03-25 13:38 . 2008-04-03 00:44 <DIR> d-------- C:\ProgramData\DVD Shrink

2008-03-25 13:38 . 2008-03-31 05:50 <DIR> d-------- C:\Program Files\Marcos Velasco Security

2008-03-25 13:38 . 2008-03-25 13:38 <DIR> d-------- C:\Program Files\DVD Shrink

2008-03-25 13:36 . 2008-03-25 13:36 <DIR> d-------- C:\Program Files\eMule

2008-03-25 13:36 . 2008-03-25 13:36 <DIR> d-------- C:\Program Files\7-Zip

2008-03-25 13:35 . 2008-03-25 13:35 <DIR> d-------- C:\Program Files\CCleaner

2008-03-25 13:22 . 2008-03-25 13:22 1,712,984 --a------ C:\Windows\System32\wuaueng.dll

2008-03-25 13:22 . 2008-03-25 13:22 1,524,224 --a------ C:\Windows\System32\wucltux.dll

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-25 17:16 --------- d-----w C:\Program Files\Windows Sidebar

2008-03-25 17:16 --------- d-----w C:\Program Files\Windows Mail

2008-03-25 17:04 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys

2008-03-25 17:04 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys

2008-03-25 17:04 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys

2008-03-25 17:04 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys

2008-03-25 17:04 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys

2008-03-25 17:04 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys

2008-03-25 17:04 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys

2008-03-25 17:01 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-03-25 17:01 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll

2008-03-25 17:01 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-03-25 17:01 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-03-25 17:01 217,144 ----a-w C:\Windows\system32\drivers\netio.sys

2008-03-25 17:01 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys

2008-03-25 17:01 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-03-25 17:01 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-03-25 17:01 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-03-25 17:01 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-03-25 17:01 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys

2008-03-25 17:01 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-03-25 16:53 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Modelos

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Menu Iniciar

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Favoritos

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Documentos

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Desktop

2008-03-25 16:00 --------- d-sh--w C:\ProgramData\Dados de aplicativos

2008-03-25 16:00 --------- d-sh--w C:\Program Files\Common Files\Sistema

2008-03-25 16:00 --------- d-sh--w C:\Program Files\Arquivos Comuns

2008-03-19 01:01 25,784 ------w C:\Windows\system32\drivers\msahci.sys

2008-03-19 01:01 20,152 ------w C:\Windows\system32\drivers\viaide.sys

2008-03-19 01:01 19,128 ------w C:\Windows\system32\drivers\cmdide.sys

2008-03-19 01:01 18,104 ------w C:\Windows\system32\drivers\amdide.sys

2008-03-19 01:01 17,592 ----a-w C:\Windows\system32\drivers\intelide.sys

2008-03-19 01:01 17,592 ------w C:\Windows\system32\drivers\aliide.sys

2008-03-19 00:57 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys

2008-03-19 00:57 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys

2008-03-19 00:57 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys

2008-03-19 00:57 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys

2008-03-19 00:57 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys

2008-03-19 00:57 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys

2008-03-19 00:56 --------- d-----w C:\Program Files\Windows Calendar

2008-03-19 00:55 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys

2008-03-19 00:55 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys

2008-03-19 00:55 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys

2008-03-19 00:55 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys

2008-03-19 00:54 13,312 ------w C:\Windows\system32\drivers\sffdisk.sys

2008-03-19 00:54 12,800 ------w C:\Windows\system32\drivers\sffp_sd.sys

2008-03-19 00:54 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys

2008-03-19 00:51 --------- d-----w C:\Program Files\Windows Defender

2008-03-19 00:50 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys

2008-03-19 00:50 28,344 ----a-w C:\Windows\system32\drivers\battc.sys

2008-03-19 00:50 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys

2008-03-19 00:50 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys

2008-03-19 00:50 20,920 ------w C:\Windows\system32\drivers\compbatt.sys

2008-03-19 00:50 2,923,520 ----a-w C:\Windows\explorer.exe

2008-03-19 00:50 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS

2008-03-19 00:50 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys

2008-03-19 00:50 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys

2008-03-19 00:47 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys

2008-03-18 17:10 174 --sha-w C:\Program Files\desktop.ini

2008-01-09 18:01 53,248 ----a-w C:\Windows\bdoscandel.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-25 03:03 17920]

"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 02:51 36864]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-15 00:54 137752]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-15 00:53 154136]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-15 00:53 133656]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-18 14:20:25 50688]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399007}"= C:\Windows\Downloaded Program Files\gbiehabn.dll [2008-03-10 12:19 348072]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{E43D03BF-D0D6-4997-ACE6-270DEE580CB2}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program

"TCP Query User{E9D3E9CC-3F64-45B9-AB1F-B7A85E4E6FD8}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule

"UDP Query User{4176CB75-1AAA-485A-AC26-F4CCB9E10DF3}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule

"TCP Query User{F99DA093-21AA-469D-A08B-757E144E91B4}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

"UDP Query User{F5312FDA-45D9-4E71-9C07-D7EC3908BD2A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

 

R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12]

R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-11-12 08:07]

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 21:39]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-12-15 00:53]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-12-15 00:54]

R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 02:51]

R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 02:51]

R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 02:31]

S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-10 00:18]

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 04:36]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

 

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-04-04 07:41:43 C:\Windows\Tasks\1-Click Maintenance.job"

- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe

"2008-03-31 16:58:45 C:\Windows\Tasks\At1.job"

- C:\Program Files\Panda Security\Panda Internet Security 2008\PAVJOBS.EXEn/PROGRAMADA PAV5.tsk PAV_FOG.OPC

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-04 04:48:26

Windows 6.0.6000 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-04-04 4:49:50

ComboFix-quarantined-files.txt 2008-04-04 07:49:45

ComboFix2.txt 2008-04-01 02:59:58

Pre-Run: 61,037,043,712 bytes disponíveis

Post-Run: 60,796,727,296 bytes disponíveis

.

2008-04-04 01:55:57 --- E O F ---

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 05:02:22, on 04/04/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16609)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\SYSTEM32\taskeng.exe

C:\Windows\OEM02Mon.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Dell\MediaDirect\PCMService.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\Explorer.exe

C:\Users\CRIS\AppData\Local\Temp\Temp1_HiJackThis.zip\HijackThis.exe

C:\Program Files\Internet Explorer\IEUser.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Windows\Downloaded Program Files\gbiehabn.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr...vex/TmHcmsX.CAB

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 6640 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

C:\Windows\system\SysSD.dll

C:\Program Files\desktop.ini

C:\Windows\Tasks\At1.job

Folder::

C:\Program Files\GbPlugin

C:\Users\All Users\GbPlugin

C:\ProgramData\GbPlugin

Registry::

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000000

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    645i642.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Jgarcia,

 

Mil desculpas, estou até envergonhada em dizer, mas aconteceu o seguinte: como em outro fórum (eles responderam mais rápido) disseram que meu log estava limpo, e os problemas continuavam, fiquei nervosa e perdi a paciência, formatei o micro :wacko: .

 

Instalei novamente os programas, alguns a mais e alguns a menos. No entanto, as coisas estão na mesma. A diferença é que agora meu antivirus alerta todo dia umas 9 vezes tentativa de intrusão, e que o Opera abre, assim que eu inicio, várias janelas nomeadas Acrobat plug-in informando que "could not launch Acrobat", e depois o programa pára de responder e fecha.

 

Poderia por gentileza analisar novamente o log? :blush:

 

Muito obrigada!

 

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 03:22:51, on 14/04/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\System32\smss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe

C:\Program Files\a-squared Free\a2service.exe

C:\Windows\system32\aestsrv.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

C:\Windows\system32\svchost.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

C:\Windows\system32\STacSV.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

C:\Program Files\DellTPad\Apoint.exe

C:\Windows\OEM02Mon.exe

C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Dell\MediaDirect\PCMService.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\HidFind.exe

C:\Program Files\DellTPad\Apntex.exe

C:\Windows\system32\SearchIndexer.exe

C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exe

C:\Windows\TEMP\F-Secure\Anti-Virus\fsblsrv.exe

C:\Windows\System32\mobsync.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Windows\system32\conime.exe

C:\Program Files\Google\Google Updater\GoogleUpdater.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE

C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe

C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\F-Secure Internet Security\Common\FSLAUNCH.EXE

C:\HijackThis.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Users\CRIS\AppData\Local\Temp\Temp1_HiJackThis.zip\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s

O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE')

O4 - Startup: fsavaui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe

O4 - Startup: fsavgui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe

O4 - Startup: FsDiagUi - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe

O4 - Startup: fsgetwab - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe

O4 - Startup: fsguidll - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe

O4 - Startup: fssw - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe

O4 - Startup: fstlui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe

O4 - Startup: postinstall - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe

O4 - Startup: quaranti - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\quaranti.exe

O4 - Startup: tnbutil - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\tnbutil.exe

O4 - Startup: webfiltr - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\webfiltr.exe

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 11894 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Jgarcia,

 

Eu rodei o combofix, mas antes de ele começar ele informou que o sistema não podia encontrar a msg 0x8 e também a 0x2371. Depois de terminar, também fez a mesma referência à mensagem 0x2.

 

Seguem os logs do combofix e do hijackthis:

 

 

ComboFix 08-04-13.3 - CRIS 2008-04-14 23:59:24.2 - NTFSx86

Executando de: C:\Users\CRIS\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_PortProxy

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-03-15 to 2008-04-15 ))))))))))))))))))))))))))))))))

.

 

Nenhum ficheiro/arquivo criado durante este per¡odo

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-14 08:38 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-14 06:19 --------- d---a-w C:\ProgramData\TEMP

2008-04-14 04:08 318,369 ----a-w C:\HiJackThis.zip

2008-04-14 03:42 --------- d-----w C:\ProgramData\Google Updater

2008-04-14 03:29 --------- d-----w C:\Program Files\Spyware Doctor

2008-04-14 03:07 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools

2008-04-14 02:41 --------- d-----w C:\Program Files\Google

2008-04-13 20:40 --------- d-----w C:\ProgramData\Spybot - Search & Destroy

2008-04-11 09:50 --------- d-----w C:\Program Files\a-squared Free

2008-04-10 05:44 --------- d-----w C:\Program Files\K-Lite Codec Pack

2008-04-10 05:28 --------- d-----w C:\Program Files\F-Secure Internet Security

2008-04-10 05:05 60,064 ----a-w C:\Windows\system32\drivers\fsdfw.sys

2008-04-10 04:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\DivX

2008-04-10 04:01 --------- d-----w C:\Program Files\DivX

2008-04-10 03:59 --------- d-----w C:\Program Files\Common Files\PX Storage Engine

2008-04-09 17:54 --------- d-----w C:\ProgramData\F-Secure

2008-04-09 17:51 --------- d-----w C:\ProgramData\fssg

2008-04-09 17:42 --------- d-----w C:\Program Files\Real Alternative

2008-04-09 17:42 --------- d-----w C:\Program Files\Media Player Classic

2008-04-09 16:57 --------- d-----w C:\Program Files\K-Lite Video Conversion Pack

2008-04-09 15:14 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller

2008-04-09 14:53 --------- d-----w C:\ProgramData\WLInstaller

2008-04-09 14:01 --------- d-----w C:\Program Files\Windows Mail

2008-04-09 13:57 --------- d-----w C:\ProgramData\CyberLink

2008-04-09 13:53 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-04-09 07:18 --------- d-----w C:\Program Files\WinAVI Video Converter

2008-04-09 07:11 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys

2008-04-09 04:42 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio

2008-04-09 04:33 --------- d-----w C:\Users\CRIS\AppData\Roaming\U3

2008-04-08 16:23 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink

2008-04-08 16:07 --------- d-----w C:\Program Files\CyberLink

2008-04-08 08:03 --------- d-----w C:\Program Files\Windows Live Toolbar

2008-04-08 06:48 --------- d-----w C:\Users\CRIS\AppData\Roaming\Skype

2008-04-08 06:31 --------- d-----w C:\Program Files\Spybot - Search & Destroy

2008-04-08 06:31 --------- d-----w C:\Program Files\Opera

2008-04-08 06:31 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-04-08 06:30 --------- d-----w C:\Program Files\eMule

2008-04-08 06:30 --------- d-----w C:\Program Files\DVD Shrink

2008-04-08 06:30 --------- d-----w C:\Program Files\DVD Decrypter

2008-04-08 06:30 --------- d-----w C:\Program Files\Common Files\Skype

2008-04-08 06:30 --------- d-----w C:\Program Files\CCleaner

2008-04-08 06:30 --------- d-----w C:\Program Files\7-Zip

2008-04-08 04:56 --------- d-----w C:\Program Files\Programas RFB

2008-04-08 04:31 --------- d-----w C:\Program Files\Windows Live

2008-04-08 03:18 --------- d-----w C:\ProgramData\Skype

2008-04-08 03:18 --------- d-----w C:\Program Files\Skype

2008-04-07 16:44 --------- d-----w C:\ProgramData\eMule

2008-04-07 16:22 --------- d-----w C:\Program Files\Marcos Velasco Security

2008-04-07 08:03 --------- d-----w C:\Program Files\VS Revo Group

2008-04-07 08:01 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure

2008-04-07 07:36 --------- d-----w C:\Program Files\Common Files\Adobe(2)

2008-04-07 07:34 --------- d-----w C:\Program Files\Adobe(1)

2008-04-07 06:09 --------- d-----w C:\Program Files\MSXML 4.0

2008-04-07 06:08 691,545 ----a-w C:\Windows\unins000.exe

2008-04-07 05:50 --------- d-----w C:\ProgramData\McAfee

2008-04-07 05:48 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-07 03:43 --------- d-----w C:\Program Files\Microsoft.NET

2008-04-07 03:23 --------- d-----w C:\Program Files\Roxio

2008-04-07 03:17 --------- d-----w C:\ProgramData\Roxio

2008-04-07 03:15 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-04-07 03:15 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-04-07 03:15 --------- d-----w C:\Program Files\Common Files\Sonic Shared

2008-04-07 03:12 --------- d-----w C:\Program Files\Common Files\SureThing Shared

2008-04-07 03:08 --------- d-----w C:\Program Files\Common Files\Roxio Shared

2008-04-07 03:07 613,888 ----a-w C:\Windows\System32\wpd_ci.dll

2008-04-07 03:07 224,824 ----a-w C:\Windows\System32\clfs.sys

2008-04-07 03:07 221,696 ----a-w C:\Windows\System32\umpnpmgr.dll

2008-04-07 03:07 19,456 ----a-w C:\Windows\System32\cfgmgr32.dll

2008-04-07 03:07 101,888 ----a-w C:\Windows\System32\drvinst.exe

2008-04-07 03:03 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys

2008-04-07 03:03 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys

2008-04-07 03:02 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-04-07 03:02 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-04-07 03:02 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-04-07 03:02 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys

2008-04-07 03:02 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-04-07 03:02 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-04-07 03:02 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys

2008-04-07 03:02 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-04-07 03:01 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-04-07 03:01 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-04-07 03:01 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-04-07 03:01 217,144 ----a-w C:\Windows\system32\drivers\netio.sys

2008-04-07 03:01 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-04-07 03:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll

2008-04-07 03:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-04-07 03:00 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll

2008-04-07 03:00 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll

2008-04-07 03:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-04-07 03:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-04-07 03:00 1,686,528 ----a-w C:\Windows\System32\gameux.dll

2008-04-07 02:59 11,776 ----a-w C:\Windows\System32\sbunattend.exe

2008-04-07 02:11 53,080 ----a-w C:\Windows\System32\wuauclt.exe

2008-04-07 02:11 43,352 ----a-w C:\Windows\System32\wups2.dll

2008-04-07 02:11 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll

2008-04-07 02:11 1,524,224 ----a-w C:\Windows\System32\wucltux.dll

2008-04-07 02:09 80,896 ----a-w C:\Windows\System32\wudriver.dll

2008-04-07 02:09 549,720 ----a-w C:\Windows\System32\wuapi.dll

2008-04-07 02:09 33,624 ----a-w C:\Windows\System32\wups.dll

2008-04-07 02:08 31,232 ----a-w C:\Windows\System32\wuapp.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 09:34 201728]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-07 03:49 159744]

"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 02:51 36864]

"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 08:07 405504]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-15 00:54 137752]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-15 00:53 154136]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-15 00:53 133656]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-03-18 14:19 77824]

"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 16:43 118784]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 13:00 174872]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-08 22:26 68640]

"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 22:17 52256]

"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2007-05-25 10:12 183208]

"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 10:11 740208]

 

C:\Users\CRIS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

fsavaui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe [2008-04-09 14:52:44 1944432]

fsavgui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe [2008-04-09 14:52:44 1051504]

FsDiagUi - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe [2008-04-09 14:52:45 539504]

fsgetwab - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe [2008-04-09 14:52:45 326512]

fsguidll - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe [2008-04-09 14:52:45 465776]

fssw - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe [2008-04-09 14:52:46 760688]

fstlui - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe [2008-04-09 14:52:47 609136]

postinstall - Atalho.lnk - C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe [2008-04-09 14:52:48 535408]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-03-18 14:20:25 50688]

Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-13 23:39:44 124400]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{E43D03BF-D0D6-4997-ACE6-270DEE580CB2}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program

"{89E9B8A9-8B45-46CD-AC7C-EE34E7867DE6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]

R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-04-10 02:04]

R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 10:09]

R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-04-10 02:05]

R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 10:08]

R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-11-12 08:07]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 21:39]

R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 10:08]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-12-15 00:53]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-12-15 00:54]

R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 02:51]

R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 02:51]

R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-29 02:31]

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 04:36]

S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 10:09]

S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 10:09]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19026666-0445-11dd-a0c1-001d0941e348}]

\shell\AutoRun\command - G:\LaunchU3.exe -a

 

.

Conte£do da pasta 'Tarefas Agendadas'

"2008-04-15 03:10:13 C:\Windows\Tasks\Scheduled scanning task.job"

- C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-15 00:10:52

Windows 6.0.6000 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Windows\System32\audiodg.exe

C:\Windows\System32\wlanext.exe

C:\Program Files\a-squared Free\a2service.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32.exe

C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

C:\Windows\System32\stacsv.exe

C:\Windows\System32\drivers\XAudio.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\wbem\unsecapp.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe

C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

C:\Windows\System32\igfxsrvc.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\hidfind.exe

C:\Program Files\DellTPad\ApntEx.exe

C:\Program Files\F-Secure Internet Security\Common\FSLAUNCH.EXE

.

**************************************************************************

.

Tempo para conclusÆo: 2008-04-15 0:18:06 - machine was rebooted

ComboFix-quarantined-files.txt 2008-04-15 03:17:39

 

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

O sistema nÆo pode encontrar o texto correspondente … mensagem de n£mero 0x2379 no arquivo de mensagens para Application.

.

2008-04-11 07:15:37 --- E O F ---

 

 

------------------------------------------------------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:48:03, on 15/04/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\DellTPad\Apoint.exe

C:\Windows\OEM02Mon.exe

C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Dell\MediaDirect\PCMService.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Digital Line Detect\DLG.exe

C:\Program Files\Google\Google Updater\GoogleUpdater.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\HidFind.exe

C:\Program Files\DellTPad\Apntex.exe

C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe

C:\Windows\system32\conime.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Users\CRIS\AppData\Local\Temp\Temp2_HiJackThis.zip\HijackThis.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s

O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE')

O4 - Startup: fsavaui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavaui.exe

O4 - Startup: fsavgui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsavgui.exe

O4 - Startup: FsDiagUi - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\FsDiagUi.exe

O4 - Startup: fsgetwab - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsgetwab.exe

O4 - Startup: fsguidll - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe

O4 - Startup: fssw - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fssw.exe

O4 - Startup: fstlui - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\fstlui.exe

O4 - Startup: postinstall - Atalho.lnk = C:\Program Files\F-Secure Internet Security\FSGUI\postinstall.exe

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O13 - Gopher Prefix:

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 9655 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

O autor do tópico formatou a máquina, no entanto o mesmo permanecerá aberto por mais uma semana. Após este prazo o tópico será fechado e considerado resolvido.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi jgarcia, tudo bem?

Poderia olhar meu log novamente, por favor?

 

Algumas funções do meu antivirus pararam de funcionar (quando eu mando escanear, antes de começar aparece msg informando que o programa parou de responder) e alguns programas estão travando também...

 

Abraço!

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 02:38:03, on 30/04/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\System32\smss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\SLsvc.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\WLTRYSVC.EXE

C:\Windows\System32\bcmwltry.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\System32\WLTRAY.EXE

C:\Program Files\DellTPad\Apoint.exe

C:\Program Files\Dell\MediaDirect\PCMService.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE

C:\Windows\OEM02Mon.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Norton Ghost\Agent\VProTray.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\Program Files\Dell Support Center\bin\sprtcmd.exe

C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\Google Updater\GoogleUpdater.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\HidFind.exe

C:\Program Files\DellTPad\Apntex.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Windows\system32\aestsrv.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE

C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files\Norton Ghost\Agent\VProSvc.exe

C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe

C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE

C:\Windows\system32\svchost.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\Windows\system32\STacSV.exe

C:\Windows\system32\dllhost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe

C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

C:\Windows\system32\dllhost.exe

C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe

C:\Windows\System32\msdtc.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe

C:\Windows\system32\conime.exe

C:\Program Files\iolo\System Mechanic Professional 7\SysMech7.exe

C:\HiJackThis\HijackThis.exe

C:\Windows\system32\wbem\wmiprvse.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash

O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"

O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE')

O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O13 - Gopher Prefix:

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u...ows-i586-jc.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

O23 - Service: Agente de Gerenciamento do F-Secure (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE

O23 - Service: Gerenciador do Google Desktop 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 12445 bytes

 

--------------------------------------------------------------------------------

 

ComboFix 08-04-29.3 - CRIS 2008-04-30 3:15:57.2 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.1677 [GMT -3:00]

Executando de: C:\Users\CRIS\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))))

.

 

Nenhum ficheiro/arquivo criado durante este período

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-30 06:04 --------- d---a-w C:\ProgramData\TEMP

2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip

2008-04-30 05:13 102,664 ----a-w C:\Windows\system32\drivers\tmcomm.sys

2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0

2008-04-30 04:45 --------- d-----w C:\ProgramData\iolo

2008-04-30 04:45 --------- d-----w C:\Program Files\iolo

2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink

2008-04-30 03:45 --------- d-----w C:\Program Files\Opera

2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink

2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink

2008-04-30 01:23 --------- d-----w C:\ProgramData\Google Updater

2008-04-29 17:41 --------- d-----w C:\Users\CRIS\AppData\Roaming\Skype

2008-04-29 17:39 --------- d-----w C:\Program Files\Java

2008-04-29 17:11 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller

2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live

2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm

2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller

2008-04-29 07:27 --------- d-----w C:\Program Files\Common Files\Software FX Shared

2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm

2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule

2008-04-29 07:18 --------- d-----w C:\Program Files\K-Lite Codec Pack

2008-04-29 07:04 --------- d-----w C:\Program Files\eMule

2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security

2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec

2008-04-29 05:35 --------- d-----w C:\Program Files\WinAVIVideoConverter

2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys

2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-04-29 04:37 --------- d-----w C:\Program Files\Norton Ghost

2008-04-29 04:35 --------- d-----w C:\Program Files\7-Zip

2008-04-29 03:19 --------- d-----w C:\Users\CRIS\AppData\Roaming\iolo

2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio

2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro

2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure

2008-04-29 02:08 --------- d-----w C:\ProgramData\Roxio

2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll

2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name

2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared

2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared

2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield

2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio

2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield

2008-04-29 00:42 --------- d-----w C:\Program Files\Spyware Doctor

2008-04-28 02:03 --------- d-----w C:\Program Files\Sun

2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java

2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype

2008-04-27 03:28 --------- d-----w C:\Program Files\Skype

2008-04-27 03:28 --------- d-----w C:\Program Files\Common Files\Skype

2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools

2008-04-27 01:58 --------- d-----w C:\Program Files\Picasa2

2008-04-27 01:51 --------- d-----w C:\Program Files\Google

2008-04-27 01:47 --------- d-----w C:\Program Files\CCleaner

2008-04-27 01:38 --------- d-----w C:\Program Files\DVD Shrink

2008-04-27 01:33 --------- d-----w C:\Program Files\DVD Decrypter

2008-04-27 00:58 --------- d-----w C:\Program Files\F-Secure Internet Security

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Mail

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar

2008-04-26 07:14 60,064 ----a-w C:\Windows\system32\drivers\fsdfw.sys

2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll

2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll

2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll

2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll

2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll

2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll

2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll

2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys

2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll

2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys

2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll

2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic

2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared

2008-04-26 06:40 --------- d-----w C:\ProgramData\F-Secure

2008-04-26 06:39 --------- d-----w C:\ProgramData\fssg

2008-04-26 06:33 --------- d-----w C:\Program Files\Intel

2008-04-26 06:31 174 --sha-w C:\Program Files\desktop.ini

2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL

2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll

2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll

2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll

2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll

2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys

2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll

2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll

2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll

2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys

2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll

2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll

2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS

2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys

2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys

2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

.

 

((((((((((((((((((((((((((((( snapshot@2008-04-30_ 3.12.45,48 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-04-30 06:07:57 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-04-30 06:16:00 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

"DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288]

"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616]

"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2007-05-25 10:12 183208]

"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2007-05-25 10:11 740208]

"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]

"Norton Ghost 14.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-01-19 20:01 2245984]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

"iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400]

QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.divxa32"= divxa32.acm

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program

"{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]

R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12]

R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys [2008-04-26 04:11]

R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-05-25 10:09]

R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2008-04-26 04:14]

R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsvista.sys [2007-05-25 10:08]

R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31]

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23]

R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39]

R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2007-05-25 10:08]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21]

R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03]

R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45]

R3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13]

R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22]

S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19]

S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51]

S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2007-05-25 10:09]

S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2007-05-25 10:09]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

 

*Newly Created Service* - CATCHME

.

Conteúdo da pasta 'Tarefas Agendadas'

"2008-04-30 05:02:14 C:\Windows\Tasks\Scheduled scanning task.job"

- C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeQ /HARD /POLICY /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-30 03:17:34

Windows 6.0.6000 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-04-30 3:18:12

ComboFix-quarantined-files.txt 2008-04-30 06:18:08

ComboFix2.txt 2008-04-30 06:13:06

 

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

 

212 --- E O F --- 2008-04-30 05:00:34

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

C:\Program Files\desktop.ini

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    645i642.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá jgarcia,

 

Não sei se ajuda informar, mas agora, além dos programas não funcionarem, a minha rede sem fio também não é mais detectada, nem do lado do roteador. E também, tenho programas originais que quando tento instalar de novo, acusam que o serial é inválido :blink:

 

Seguem os logs que você pediu abaixo.

Abraço.

 

 

ComboFix 08-04-29.3 - CRIS 2008-05-08 1:24:21.3 - NTFSx86

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.1556 [GMT -3:00]

Executando de: C:\Users\CRIS\Desktop\ComboFix.exe

Command switches used :: C:\Users\CRIS\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

C:\Program Files\desktop.ini

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Program Files\desktop.ini

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-04-08 to 2008-05-08 ))))))))))))))))))))))))))))))))

.

 

Nenhum ficheiro/arquivo criado durante este período

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-08 03:35 --------- d---a-w C:\ProgramData\TEMP

2008-05-08 03:32 --------- d-----w C:\ProgramData\Google Updater

2008-05-08 03:17 --------- d-----w C:\Program Files\F-Secure Internet Security

2008-05-08 03:17 --------- d-----w C:\Program Files\Common Files\Software FX Shared

2008-04-30 15:41 --------- d-----w C:\ProgramData\iolo

2008-04-30 15:21 --------- d-----w C:\ProgramData\F-Secure

2008-04-30 15:19 --------- d-----w C:\ProgramData\fssg

2008-04-30 07:09 --------- d-----w C:\Program Files\PCCheckupOnline

2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip

2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0

2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink

2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink

2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink

2008-04-29 17:39 --------- d-----w C:\Program Files\Java

2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live

2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm

2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller

2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm

2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule

2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security

2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec

2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys

2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio

2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro

2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure

2008-04-29 02:08 --------- d-----w C:\ProgramData\Roxio

2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll

2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name

2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared

2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared

2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield

2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio

2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield

2008-04-28 02:03 --------- d-----w C:\Program Files\Sun

2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java

2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype

2008-04-27 03:28 --------- d-----w C:\Program Files\Skype

2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar

2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll

2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll

2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll

2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll

2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll

2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll

2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll

2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys

2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll

2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys

2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll

2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic

2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared

2008-04-26 06:33 --------- d-----w C:\Program Files\Intel

2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL

2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll

2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll

2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll

2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll

2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys

2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll

2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll

2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll

2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys

2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll

2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll

2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS

2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys

2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys

2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-04-26 06:21 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys

2008-04-26 06:21 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-04-26 06:21 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-04-26 06:21 104,448 ----a-w C:\Windows\System32\DWWIN.EXE

2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hcrstco.dll

2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hccoin.dll

2008-04-26 06:20 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys

2008-04-26 06:20 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys

2008-04-26 06:20 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys

2008-04-26 06:20 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys

2008-04-26 06:20 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys

2008-04-26 06:20 2,048 ----a-w C:\Windows\System32\msxml3r.dll

2008-04-26 06:20 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys

2008-04-26 06:20 1,191,936 ----a-w C:\Windows\System32\msxml3.dll

2008-04-26 06:19 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-04-26 06:19 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-04-26 06:19 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-04-26 06:19 216,632 ----a-w C:\Windows\system32\drivers\netio.sys

2008-04-26 06:19 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll

2008-04-26 06:18 1,327,104 ----a-w C:\Windows\System32\quartz.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-04-30_ 3.12.45,48 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-04-30 06:05:13 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2008-05-08 03:17:50 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2006-10-27 18:26:40 16,870,712 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\MSO.DLL

+ 2006-10-27 18:14:34 14,151,456 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OART.DLL

+ 2006-10-26 23:42:36 8,423,224 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OARTCONV.DLL

+ 2006-10-27 18:18:36 1,658,152 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\OGL.DLL

+ 2006-10-27 00:08:00 1,764,112 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\PPCNV.DLL

+ 2006-10-27 00:07:50 67,920 ----a-r C:\Windows\Installer\$PatchCache$\Managed\00002159FA0090400000000000F01FEC\12.0.4518\PXBCOM.EXE

- 2008-04-26 05:34:52 49,936 ----a-r C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe

+ 2008-04-30 07:57:56 49,936 ----a-r C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe

+ 2008-04-30 15:18:14 32,768 ----a-r C:\Windows\Installer\{C523D256-313D-4866-B36A-F3DE528246EF}\icon.exe

- 2008-04-30 06:05:14 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-05-08 03:17:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2008-04-30 06:05:14 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2008-05-08 03:17:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2008-04-30 06:07:58 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-08 03:39:09 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat

- 2008-04-30 06:07:29 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-05-08 03:20:25 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-05-08 03:20:25 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-04-30 06:07:57 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-08 04:23:58 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat

- 2008-04-30 06:07:24 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-05-08 03:20:20 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-05-08 03:20:20 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-04-30 06:06:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-05-08 03:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-04-30 06:06:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-05-08 03:35:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-04-26 04:58:06 262,144 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat

+ 2008-05-05 06:13:53 262,144 ----a-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat

- 2008-04-30 06:06:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-05-08 03:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-04-30 06:09:57 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

+ 2008-05-08 03:11:04 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

- 2008-04-26 07:14:18 60,064 ----a-w C:\Windows\System32\drivers\fsdfw.sys

+ 2007-05-25 13:10:00 67,120 ----a-w C:\Windows\System32\drivers\fsdfw.sys

- 2008-04-30 05:13:03 102,664 ----a-w C:\Windows\System32\drivers\tmcomm.sys

+ 2007-12-24 20:37:00 138,384 ----a-w C:\Windows\System32\drivers\tmcomm.sys

- 2007-05-08 18:03:04 1,275,392 ----a-w C:\Windows\System32\msxml4.dll

+ 2007-08-24 21:08:24 1,275,392 ----a-w C:\Windows\System32\msxml4.dll

- 2008-04-29 02:13:21 106,908 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-04-30 15:21:01 105,138 ----a-w C:\Windows\System32\perfc009.dat

- 2008-04-29 02:13:21 616,832 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-04-30 15:21:01 612,758 ----a-w C:\Windows\System32\perfh009.dat

- 2008-04-29 02:13:21 85,962 ----a-w C:\Windows\System32\prfc0416.dat

+ 2008-04-30 15:21:01 84,192 ----a-w C:\Windows\System32\prfc0416.dat

- 2008-04-29 02:13:21 512,288 ----a-w C:\Windows\System32\prfh0416.dat

+ 2008-04-30 15:21:01 508,214 ----a-w C:\Windows\System32\prfh0416.dat

- 2008-04-30 05:01:13 6,029,312 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT

+ 2008-04-30 07:58:08 6,029,312 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat

- 2008-04-30 06:07:43 6,036 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-879540782-419363104-1388336070-1000_UserData.bin

+ 2008-05-08 03:21:05 6,704 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-879540782-419363104-1388336070-1000_UserData.bin

- 2008-04-30 06:07:43 58,474 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-05-08 03:21:04 62,312 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-04-30 06:07:40 38,788 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-05-08 02:55:09 40,214 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

- 2008-04-30 05:00:31 139,732 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin

+ 2008-04-30 15:18:28 155,189 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin

+ 2008-04-30 15:18:19 1,275,392 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9849.0_none_b7e911727b2899b7\msxml4.dll

.

-- Snapshot reset to current date --

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

"DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288]

"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616]

"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]

"Norton Ghost 14.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [2008-01-19 20:01 2245984]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

"iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568]

"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400]

QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.divxa32"= divxa32.acm

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program

"{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]

R1 ElRawDisk;ElRawDisk;C:\Windows\system32\drivers\elrawdsk.sys [2007-09-20 14:12]

R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2007-05-25 10:10]

R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31]

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23]

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48]

R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21]

R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03]

R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45]

R3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13]

R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22]

S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45]

S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19]

S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

 

*Newly Created Service* - ELRAWDISK

.

**************************************************************************

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-08 01:26:09

Windows 6.0.6000 NTFS

 

detected NTDLL code modification:

ZwClose

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-05-08 1:26:57

ComboFix-quarantined-files.txt 2008-05-08 04:26:53

ComboFix2.txt 2008-04-30 06:13:06

 

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

 

265 --- E O F --- 2008-04-30 15:18:31

 

---------------------------------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:38:01, on 08/05/2008

Platform: Windows Vista (WinNT 6.00.1904)

MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Boot mode: Normal

 

Running processes:

C:\Windows\System32\smss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\csrss.exe

C:\Windows\system32\wininit.exe

C:\Windows\system32\services.exe

C:\Windows\system32\lsass.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\winlogon.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\svchost.exe

C:\Windows\System32\WLTRYSVC.EXE

C:\Windows\System32\bcmwltry.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\a-squared Free\a2service.exe

C:\Windows\system32\aestsrv.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

C:\Program Files\Norton Ghost\Agent\VProSvc.exe

C:\Windows\system32\svchost.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\Windows\system32\STacSV.exe

C:\Windows\System32\svchost.exe

C:\Windows\system32\DRIVERS\xaudio.exe

C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

C:\Windows\System32\msdtc.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Windows\System32\WLTRAY.EXE

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\DellTPad\Apoint.exe

C:\Program Files\Dell\MediaDirect\PCMService.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Windows\OEM02Mon.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\DellTPad\ApMsgFwd.exe

C:\Program Files\DellTPad\Apntex.exe

C:\Program Files\DellTPad\HidFind.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Norton Ghost\Agent\VProTray.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\Program Files\Dell Support Center\bin\sprtcmd.exe

C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\Google Updater\GoogleUpdater.exe

C:\Program Files\Dell\QuickSet\quickset.exe

C:\Windows\system32\wbem\wmiprvse.exe

c:\program files\common files\installshield\updateservice\isuspm.exe

C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Dell Support Center\gs_agent\dsc.exe

C:\Windows\system32\conime.exe

C:\Windows\system32\dllhost.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\Explorer.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\HiJackThis\HijackThis.exe

C:\Windows\system32\wbem\wmiprvse.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"

O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

O4 - HKCU\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" /s

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE')

O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O13 - Gopher Prefix:

O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u...ows-i586-jc.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe

O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe

O23 - Service: Gerenciador do Google Desktop 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe

O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe

O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

 

--

End of file - 11072 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

O problema não parece possuir relação com malwares. A máquina reinicia ou trava constantemente?

Compartilhar este post


Link para o post
Compartilhar em outros sites
Opa REDENTOR,

 

O problema não parece possuir relação com malwares. A máquina reinicia ou trava constantemente?

 

Não, mas os programas páram de responder... antes eu clicava, eles funcionavam e depois travavam, e aí aparecia a msg de que o programa parou de responder... agora tá pior, quando eu clico, o programa nem abre, já aparece direto a msg de que parou de responder e foi fechado. E não funciona mais...

 

Nem o antivirus funciona, nem o windows defender, nem o system mechanic, nem o anti-spyware... e antes de "morrer" de vez o antivirus acusou 2 arquivos maliciosos, e fechou em seguida, sem que eu pudesse colocar em quarentena e/ou excluir. Eu anotei o nome dos arquivos (não eram de sistema), entrei pelo modo de segurança e consegui apagar, mas não sei se ficou resquício. Depois disso nunca mais consegui usar nenhum programa de segurança, nem instalando de novo.

O antispyware detectou 1 trojan e 1 backdoor antes de também parar de funcionar...

 

Veja, eu tenho outra partição, com o mesmo sistema operacional, mesmos drives etc. Tudo funciona perfeitamente, a rede sem fio é detectada, e quando vou instalar o system mechanic coloco o serial e entra normalmente , ao contrário do que está acontecendo recentemente com a partição problema...

 

Sinceramente, continuo achando que tem alguma coisa errada com o micro...

 

 

Ah, fiquei com uma dúvida:

 

o que significa essa linha do log: "detected NTDLL code modification: ZwClose"

 

É algum problema?

 

 

Abraço!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Execute o ComboFix em Modo Seguro e retorne com o resultado.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá jgarcia!!

 

Segue o log, obrigada.

 

 

ComboFix 08-05-12.1 - CRIS 2008-05-15 6:10:09.4 - NTFSx86 MINIMAL

Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1046.18.2128 [GMT -3:00]

Executando de: C:\Users\CRIS\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-04-15 to 2008-05-15 ))))))))))))))))))))))))))))))))

.

 

Nenhum ficheiro/arquivo criado durante este período

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-05-15 09:08 --------- d---a-w C:\ProgramData\TEMP

2008-05-09 02:52 --------- d-----w C:\ProgramData\Roxio

2008-05-09 01:38 --------- d-----w C:\Program Files\Dell Support Center

2008-05-09 01:38 --------- d-----w C:\Program Files\Common Files\supportsoft

2008-05-08 03:32 --------- d-----w C:\ProgramData\Google Updater

2008-05-08 03:17 --------- d-----w C:\Program Files\F-Secure Internet Security

2008-05-08 03:17 --------- d-----w C:\Program Files\Common Files\Software FX Shared

2008-04-30 15:41 --------- d-----w C:\ProgramData\iolo

2008-04-30 15:21 --------- d-----w C:\ProgramData\F-Secure

2008-04-30 15:19 --------- d-----w C:\ProgramData\fssg

2008-04-30 07:09 --------- d-----w C:\Program Files\PCCheckupOnline

2008-04-30 05:34 318,369 ----a-w C:\HiJackThis.zip

2008-04-30 05:00 --------- d-----w C:\Program Files\MSXML 4.0

2008-04-30 04:19 --------- d-----w C:\ProgramData\DVD Shrink

2008-04-30 03:14 --------- d-----w C:\Users\CRIS\AppData\Roaming\CyberLink

2008-04-30 03:14 --------- d-----w C:\ProgramData\CyberLink

2008-04-29 17:39 --------- d-----w C:\Program Files\Java

2008-04-29 17:11 --------- d-----w C:\Program Files\Windows Live

2008-04-29 16:54 --------- d-----w C:\Users\CRIS\AppData\Roaming\Myfreecomm

2008-04-29 16:38 --------- d-----w C:\ProgramData\WLInstaller

2008-04-29 07:26 --------- d-----w C:\Program Files\Myfreecomm

2008-04-29 07:20 --------- d-----w C:\ProgramData\eMule

2008-04-29 06:01 --------- d-----w C:\Program Files\Marcos Velasco Security

2008-04-29 05:56 --------- d-----w C:\Users\CRIS\AppData\Roaming\Symantec

2008-04-29 05:34 3,082 ----a-w C:\Windows\System32\affv208325p1now.sys

2008-04-29 05:20 --------- d-----w C:\ProgramData\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Symantec

2008-04-29 04:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-04-29 02:49 --------- d-----w C:\Users\CRIS\AppData\Roaming\Roxio

2008-04-29 02:48 --------- d-----w C:\Program Files\Trend Micro

2008-04-29 02:13 --------- d-----w C:\Users\CRIS\AppData\Roaming\F-Secure

2008-04-29 01:51 74,703 ----a-w C:\Windows\System32\mfc45.dll

2008-04-29 01:20 --------- d-----w C:\Program Files\My Company Name

2008-04-29 01:08 --------- d-----w C:\Program Files\Common Files\Sonic Shared

2008-04-29 01:02 --------- d-----w C:\Program Files\Common Files\Roxio Shared

2008-04-29 00:55 --------- d-----w C:\ProgramData\InstallShield

2008-04-29 00:54 --------- d-----w C:\Program Files\Roxio

2008-04-29 00:54 --------- d-----w C:\Program Files\Common Files\InstallShield

2008-04-28 02:03 --------- d-----w C:\Program Files\Sun

2008-04-27 05:01 --------- d-----w C:\Program Files\Common Files\Java

2008-04-27 03:39 --------- d-----w C:\Program Files\Common Files\Adobe

2008-04-27 03:28 --------- d-----w C:\ProgramData\Skype

2008-04-27 03:28 --------- d-----w C:\Program Files\Skype

2008-04-27 03:10 --------- d-----w C:\Users\CRIS\AppData\Roaming\PC Tools

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Defender

2008-04-26 11:22 --------- d-----w C:\Program Files\Windows Calendar

2008-04-26 07:05 67,584 ----a-w C:\Windows\System32\wlanhlp.dll

2008-04-26 07:05 502,784 ----a-w C:\Windows\System32\wlansvc.dll

2008-04-26 07:05 49,664 ----a-w C:\Windows\System32\csrsrv.dll

2008-04-26 07:05 47,104 ----a-w C:\Windows\System32\wlanapi.dll

2008-04-26 07:05 376,320 ----a-w C:\Windows\System32\winsrv.dll

2008-04-26 07:05 297,984 ----a-w C:\Windows\System32\wlansec.dll

2008-04-26 07:05 290,816 ----a-w C:\Windows\System32\wlanmsm.dll

2008-04-26 07:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll

2008-04-26 07:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys

2008-04-26 07:04 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys

2008-04-26 07:04 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll

2008-04-26 07:04 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys

2008-04-26 07:03 414,208 ----a-w C:\Windows\System32\msscp.dll

2008-04-26 06:45 --------- d-----w C:\ProgramData\Sonic

2008-04-26 06:43 --------- d-----w C:\Program Files\Common Files\SureThing Shared

2008-04-26 06:33 --------- d-----w C:\Program Files\Intel

2008-04-26 06:27 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-26 06:23 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL

2008-04-26 06:23 7,680 ----a-w C:\Windows\System32\spwmp.dll

2008-04-26 06:23 4,096 ----a-w C:\Windows\System32\dxmasf.dll

2008-04-26 06:23 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll

2008-04-26 06:22 86,016 ----a-w C:\Windows\System32\icfupgd.dll

2008-04-26 06:22 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys

2008-04-26 06:22 61,952 ----a-w C:\Windows\System32\cmifw.dll

2008-04-26 06:22 396,800 ----a-w C:\Windows\System32\MPSSVC.dll

2008-04-26 06:22 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll

2008-04-26 06:22 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys

2008-04-26 06:22 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll

2008-04-26 06:22 16,896 ----a-w C:\Windows\System32\wfapigp.dll

2008-04-26 06:22 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS

2008-04-26 06:21 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys

2008-04-26 06:21 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-04-26 06:21 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-04-26 06:21 25,656 ----a-w C:\Windows\system32\drivers\msahci.sys

2008-04-26 06:21 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys

2008-04-26 06:21 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys

2008-04-26 06:21 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys

2008-04-26 06:21 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys

2008-04-26 06:21 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys

2008-04-26 06:21 104,448 ----a-w C:\Windows\System32\DWWIN.EXE

2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hcrstco.dll

2008-04-26 06:20 8,704 ----a-w C:\Windows\System32\hccoin.dll

2008-04-26 06:20 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys

2008-04-26 06:20 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys

2008-04-26 06:20 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys

2008-04-26 06:20 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys

2008-04-26 06:20 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys

2008-04-26 06:20 2,048 ----a-w C:\Windows\System32\msxml3r.dll

2008-04-26 06:20 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys

2008-04-26 06:20 1,191,936 ----a-w C:\Windows\System32\msxml3.dll

2008-04-26 06:19 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys

2008-04-26 06:19 24,064 ----a-w C:\Windows\System32\netcfg.exe

2008-04-26 06:19 22,016 ----a-w C:\Windows\System32\netiougc.exe

2008-04-26 06:19 216,632 ----a-w C:\Windows\system32\drivers\netio.sys

.

 

------- Sigcheck -------

 

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

"DELL Webcam Manager"="C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe" [2007-06-07 11:14 118784]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-26 22:39 68856]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-26 04:04 1006264]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-15 09:41 141848]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-15 09:41 166424]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-15 09:41 133656]

"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2007-08-07 15:49 1548288]

"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-07-02 13:29 159744]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]

"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 15:39 189736]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 18:02 174616]

"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-05-09 17:01 36864]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51 29744]

"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

"iolo Startup"="C:\Program Files\iolo\Common\Lib\ioloLManager.exe" [2008-03-31 14:48 307568]

"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" []

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 22:38:55 124400]

QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 16:27:08 1180952]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.divxa32"= divxa32.acm

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{CE6899E9-FDE4-442C-BA97-6E0102B323AC}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program

"{F2AAFEA6-7BBC-4352-AA36-8ECB7F5EF452}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

 

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]

S1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2007-05-25 10:10]

S2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-09-20 15:31]

S2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23]

S2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\system32\dllhost.exe [2006-11-02 06:45]

S2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 16:39]

S3 BCM43XV;Driver de Adaptador de Rede Broadcom 802.11 Extensible;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 12:19]

S3 GoogleDesktopManager-022208-143751;Gerenciador do Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-26 22:51]

S3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-01-02 16:48]

S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;C:\Windows\system32\drivers\IntcHdmi.sys [2007-06-06 23:21]

S3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-10-10 17:03]

S3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-03-05 10:45]

S3 SymSnapService;SymSnapService;"C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe" [2007-12-20 17:13]

S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-17 10:22]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

 

*Newly Created Service* - ECACHE

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-05-15 06:13:20

Windows 6.0.6000 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-05-15 6:13:44

ComboFix-quarantined-files.txt 2008-05-15 09:13:42

ComboFix2.txt 2008-05-08 04:26:58

 

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

O sistema não pode encontrar o texto correspondente à mensagem de número 0x2379 no arquivo de mensagens para Application.

 

192 --- E O F --- 2008-04-30 15:18:31

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Baixe o F-Secure Blacklight em:

F-Secure Blacklight

 

Salve-o em sua área de trabalho (desktop) e o execute. Aceite o acordo. Clique em Scan e aguarde.

 

Se ele encontrar algum arquivo, ignore, pois quero apenas o log.

 

Ao final do scan será gerado o arquivo fsbl-xxxxx.log (onde xxx são números). Preciso que você copie o log e poste em sua próxima resposta.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Jgarcia,

 

Baixei o arquivo através da outra partição, de onde consigo (por enquanto) acessar a rede. Como fiquei em dúvida se iria escanear o micro todo ou só aquela partição, fiz o seguinte: escaneei a partir dali mesmo, e depois copiei o arquivo pra partição-mais-problema (a outra já está apresentando problemas também) e executei. Assim, o 2o log é o correspondente à partição que estamos tentanto resolver no momento...

 

obs: há uns dias atrás, percebi no "controle de aplicativos" do antivirus (que lista os aplicativos com atividade suspeita), alguns arquivos temporários listados, e que tinham permissão para serem executados. Achei estranho e apaguei todos... e aproveitei pra desinstalar o antivirus também, pois já não funcionava mais mesmo, e também não ia precisar, já que não tenho mais acesso à rede...

 

Obrigada pela ajuda, grande abraço!

 

 

05/19/08 21:28:32 [info]: BlackLight Engine 1.0.70 initialized

05/19/08 21:28:32 [info]: OS: 6.0 build 6001 (Service Pack 1)

05/19/08 21:28:33 [Note]: 7019 4

05/19/08 21:28:33 [Note]: 7005 0

05/19/08 21:28:58 [Note]: 7006 0

05/19/08 21:28:58 [Note]: 7027 0

05/19/08 21:28:59 [Note]: 7035 0

05/19/08 21:28:59 [Note]: 7026 0

05/19/08 21:29:00 [Note]: 7026 0

05/19/08 21:29:03 [Note]: FSRAW library version 1.7.1024

05/19/08 21:33:24 [Note]: 4015 1455

05/19/08 21:33:24 [Note]: 4027 1455 65536

05/19/08 21:33:24 [Note]: 4020 553 65536

05/19/08 21:33:24 [Note]: 4018 553 65536

05/19/08 21:40:08 [Note]: 7007 0

 

 

05/19/08 21:44:57 [info]: BlackLight Engine 1.0.70 initialized

05/19/08 21:44:57 [info]: OS: 6.0 build 6000 ()

05/19/08 21:44:57 [Note]: 7019 4

05/19/08 21:44:57 [Note]: 7005 0

05/19/08 21:45:02 [Note]: 7006 0

05/19/08 21:45:02 [Note]: 7027 0

05/19/08 21:45:02 [Note]: 7035 0

05/19/08 21:45:02 [Note]: 7026 0

05/19/08 21:45:02 [Note]: 7026 0

05/19/08 21:45:05 [Note]: FSRAW library version 1.7.1024

05/19/08 21:54:47 [Note]: 7007 0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa REDENTOR,

 

Baixe o SilentRunners.

 

Extraia o arquivo SilentRunners.vbs para o C. Dê duplo clique sobre o arquivo para executá-lo.

 

Após executá-lo aguarde até que seja gerado um documento denominado Startup Programs (USUÁRIO) data. Copie o conteúdo deste documento e cole em sua próxima resposta.

 

Abraços.

 

Obs.: Caso o seu AV detecte o arquivo como sendo um script malicioso não se preocupe e autorize a execução.

Compartilhar este post


Link para o post
Compartilhar em outros sites

jgarcia,

 

Acho que fiz alguma coisa errada, porque eu salvei em c: e extrai em c:, mas quando eu dei duplo clique apareceu apenas uma janela do bloco de notas, falando sobre o silent runners...

 

não aconteceu mais nada...

Compartilhar este post


Link para o post
Compartilhar em outros sites
jgarcia,

 

Acho que fiz alguma coisa errada, porque eu salvei em c: e extrai em c:, mas quando eu dei duplo clique apareceu apenas uma janela do bloco de notas, falando sobre o silent runners...

 

não aconteceu mais nada...

Baixei aqui e funcionou perfeitamente. Tente executá-lo mais uma vez. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.