Edvan 30 Denunciar post Postado Junho 17, 2008 Mouse andando sozinho suspeita de ser virus, analise esse log para mim por favor... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:22:35, on 17/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\RALINK\Common\RaUI.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Documents and Settings\Edvan\Desktop\Windows Live Messenger 8.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Estatísticas do Antivírus da Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O18 - Filter hijack: text/html - {53B95211-7D77-11D2-9F80-00104B107C96} - (no file) O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE -- End of file - 4908 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 17, 2008 Siga as Instruções: Baixe o MSNfix. Salve na área de trabalho, e descompacte ele, após isto, clique duas vezes em MSNFix.bat Vai se abrir a tela MSN_Fix-menu nela aperte a opçãp R, será dado inicio ao scaneamento. Caso o scan detecte algo irá aparecer a seguinte informação: Infection Presente, aperte enter, e prossiga. Caso queira interromper o processo aperte a tecla Q Na finalização vai se abrir o bloco de notas com um log, selecione todo ele e copie, que se encontra na pasta msnfix.txt. Poste juntamente um novo log do Hijackthis Aguardo o retorno. Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 18, 2008 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:40:25, on 17/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\RALINK\Common\RaUI.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Estatísticas do Antivírus da Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O18 - Filter hijack: text/html - {53B95211-7D77-11D2-9F80-00104B107C96} - (no file) O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE -- End of file - 4654 bytes MSNFix 1.724 C:\Documents and Settings\Edvan\Desktop\MSNFix Fix lançado dia ter 17/06/2008 - 21:30:39,10 By Edvan modo normal ************************ Procurando os arquivos presentes Nenhum arquivo encontrado ************************ Procurando as pastas presentes Nenhuma pasta encontrada ************************ Arquivos suspeitos /!\ Estes arquivos necessitam de uma opiniao de alguem competente antes de qualquer intervencao [C:\HJTInstall.exe] AB1C4DEAB684B0D883CFAA82C7BC6D19 ==> Por favor não esqueça de mandar o arquivo C:\DOCUME~1\Edvan\Desktop\Upload_Me.zip no http://upload.changelog.fr ************************ HKLM\...\Winlogon\Userinit Userinit = C:\WINDOWS\system32\userinit.exe, ------------------------------------------------------------------------ Autor : !aur3n7 Contact: http://changelog.fr ------------------------------------------------------------------------ --------------------------------------------- END --------------------------------------------- Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 18, 2008 Baixe o ComboFix e salve na área de trabalho. Feche todos os programas. Clique duas vezes sobre combofix.exe e tecle (1) logo após aperte Enter para continuar. O ComboFix irá reiniciar seu computador automaticamente, isto faz parte do processo de remoção. Ao se encerrar, será gerado um log, que vai estar em C:\ComboFix.txt. Atenção: Não clique em nada enquanto o Combofix estiver rodando, Do contrário seu desktop ficará em branco. Para parar o processo ou sair do ComboFix, tecle "2" e Enter. Aguardo um novo log do HijackThis juntamente com o ComboFix.txt Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 18, 2008 Valeu Silas pela ajuda prestada a minha pessoa, estão os logs que voce me pediu.... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:58:19, on 17/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe C:\Arquivos de programas\Lexmark X74-X75\lxbbbmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\internet explorer\iexplore.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Estatísticas do Antivírus da Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE -- End of file - 4962 bytes ComboFix 08-06-16.5 - Edvan 2008-06-17 22:38:07.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.147 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Arquivos de programas\ActivationManager C:\Arquivos de programas\ActivationManager\Uninstall.exe . ((((((((((((((((((((((( Ficheiros criados de 2008-05-18 to 2008-06-18 )))))))))))))))))))))))))))))))) . 2008-06-17 01:54 . 2008-06-17 16:08 <DIR> d-------- C:\Pessoal 2008-06-13 22:55 . 2008-06-13 22:56 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-11 13:34 . 2008-06-11 13:34 <DIR> d-------- C:\Arquivos de programas\PC Inspector File Recovery 2008-06-11 13:34 . 2002-02-18 18:40 6,200 --a------ C:\WINDOWS\system32\INT13EXT.VXD 2008-06-11 12:11 . 2008-04-14 12:52 272,384 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 12:11 . 2008-04-14 12:52 272,384 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 12:01 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll 2008-06-11 12:01 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll 2008-06-11 12:01 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll 2008-06-08 11:14 . 2008-06-08 11:14 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy 2008-06-08 01:50 . 2008-06-08 01:50 268 --ah----- C:\sqmdata01.sqm 2008-06-08 01:50 . 2008-06-08 01:50 172 --ah----- C:\sqmnoopt01.sqm 2008-06-06 02:10 . 2008-06-06 02:10 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-06 00:23 . 2008-06-06 00:23 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-06-06 00:19 . 2008-06-06 00:22 812,344 --a------ C:\HJTInstall.exe 2008-06-05 13:11 . 2008-06-06 01:39 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-06-05 13:10 . 2008-06-05 13:10 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2008-06-02 21:44 . 2005-07-29 11:44 340,992 --a------ C:\WINDOWS\system32\drivers\rt61.sys 2008-06-02 21:44 . 2005-05-17 16:24 311,296 --a------ C:\WINDOWS\system32\AegisI5.exe 2008-06-02 21:44 . 2005-06-17 19:19 242,048 --a------ C:\WINDOWS\system32\drivers\RT2500.SYS 2008-06-02 21:44 . 2005-08-25 11:15 81,920 --a------ C:\WINDOWS\system32\Install6x.dll 2008-06-02 21:44 . 2005-07-29 11:43 8,192 --a------ C:\WINDOWS\system32\drivers\RT2661.bin 2008-06-02 21:44 . 2005-07-29 11:43 8,192 --a------ C:\WINDOWS\system32\drivers\RT2561s.bin 2008-06-02 21:44 . 2005-07-29 11:43 8,192 --a------ C:\WINDOWS\system32\drivers\RT2561.bin 2008-06-02 21:44 . 2005-06-16 00:30 162 --a------ C:\WINDOWS\filespec6x 2008-06-02 21:40 . 2008-06-02 21:40 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-02 01:15 . 2008-06-02 01:20 588 --a------ C:\WINDOWS\system32\winsys.lng 2008-06-02 01:15 . 2008-06-02 01:20 588 --a------ C:\WINDOWS\system32\kc8evwfj.cdm 2008-06-02 01:14 . 2008-06-02 12:14 <DIR> d-------- C:\Arquivos de programas\LingoCom 2008-06-02 01:14 . 2007-05-03 12:00 81,920 --a------ C:\WINDOWS\system32\GkSui20.EXE 2008-05-27 12:15 . 2008-06-06 02:11 <DIR> d-------- C:\Arquivos de programas\RALINK 2008-05-27 09:38 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-05-27 09:38 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2008-05-27 09:38 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-05-26 20:35 . 2008-05-26 20:35 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller 2008-05-26 20:34 . 2008-06-07 13:06 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-05-25 23:34 . 2008-05-29 09:10 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-05-25 23:34 . 2008-05-29 15:39 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-05-25 23:33 . 2008-05-25 23:33 <DIR> d-------- C:\Arquivos de programas\Kaspersky Lab 2008-05-25 23:33 . 2008-06-17 22:41 4,695,072 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-05-25 23:33 . 2008-06-17 22:41 211,488 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-05-25 23:33 . 2008-06-17 17:35 63,344 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-05-25 23:33 . 2008-06-17 17:35 21,488 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-05-25 10:56 . 2008-05-25 11:08 219 --a------ C:\WINDOWS\LEXSTAT.INI 2008-05-25 10:53 . 2008-05-25 10:54 <DIR> d-------- C:\Arquivos de programas\Lexmark X74-X75 2008-05-25 10:53 . 2001-09-05 23:50 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll 2008-05-25 10:53 . 2001-09-05 23:50 87,040 --a--c--- C:\WINDOWS\system32\dllcache\wiafbdrv.dll 2008-05-25 10:53 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2008-05-25 10:53 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys 2008-05-25 10:52 . 2008-05-25 10:52 <DIR> d-------- C:\Documents and Settings\Edvan\WINDOWS 2008-05-25 10:52 . 1997-04-08 20:08 299,520 --a------ C:\WINDOWS\uninst.exe 2008-05-25 10:52 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2008-05-25 10:52 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys 2008-05-25 10:34 . 2008-05-25 10:52 <DIR> d-------- C:\Lxkx75 2008-05-24 22:31 . 2008-05-24 22:31 1,192 --a------ C:\WINDOWS\mozver.dat 2008-05-24 18:13 . 2008-05-24 18:13 0 --a------ C:\WINDOWS\nsreg.dat 2008-05-22 00:57 . 2008-06-12 23:48 <DIR> d-------- C:\Downloads 2008-05-22 00:57 . 2008-06-17 20:25 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-05-22 00:57 . 2008-05-22 02:56 <DIR> d-------- C:\Arquivos de programas\Orbitdownloader 2008-05-21 12:12 . 2008-05-21 12:12 <DIR> d---s---- C:\Documents and Settings\Edvan\UserData 2008-05-21 07:08 . 2008-05-21 07:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus! 2008-05-21 07:03 . 2008-05-24 09:47 <DIR> d-------- C:\Documents and Settings\Edvan\Contacts 2008-05-21 07:03 . 2008-05-26 20:34 <DIR> d-------- C:\Arquivos de programas\Windows Live 2008-05-21 07:03 . 2008-06-04 09:09 <DIR> d-------- C:\Arquivos de programas\Messenger Plus! Live 2008-05-21 07:02 . 2008-06-06 02:12 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2008-05-21 07:01 . 2008-06-07 13:11 <DIR> d-------- C:\Arquivos de programas\MSN Messenger 2008-05-21 06:51 . 2008-06-11 13:08 <DIR> d--h----- C:\WINDOWS\$hf_mig$ 2008-05-19 13:00 . 2008-06-11 13:34 <DIR> d--h----- C:\Arquivos de programas\InstallShield Installation Information 2008-05-19 13:00 . 2008-05-27 12:16 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-17 23:24 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Kaspersky Lab 2008-05-15 16:27 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys 2008-05-07 05:15 1,292,288 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-04 01:13 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help 2008-05-03 00:52 --------- d-----w C:\Arquivos de programas\Lavalys 2008-05-02 02:04 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Media Player Classic 2008-04-28 01:50 --------- d-----w C:\Arquivos de programas\K-Lite Codec Pack 2008-04-28 01:49 --------- d-----w C:\Arquivos de programas\CCleaner 2008-04-28 01:10 --------- d-----w C:\Arquivos de programas\microsoft frontpage 2008-04-28 01:05 --------- d-----w C:\Arquivos de programas\Serviços on-line 2008-04-28 01:03 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços 2008-04-21 07:02 661,504 ----a-w C:\WINDOWS\system32\wininet.dll 2008-03-25 04:49 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:49 183,072 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Lexmark X74-X75"="C:\Arquivos de programas\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Orbit.lnk - C:\Arquivos de programas\Orbitdownloader\orbitdm.exe [2008-05-22 00:57:41 1678536] Ralink Wireless Utility.lnk - C:\Arquivos de programas\RALINK\Common\RaUI.exe [2008-05-27 12:15:30 2101248] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"= "C:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "C:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "C:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "C:\\WINDOWS\\system32\\LEXPPS.EXE"= "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{517718c2-14a2-11dd-bfae-806d6172696f}] \Shell\AutoRun\command - D:\Autorun\Boot.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-17 22:41:23 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-06-17 22:44:35 ComboFix-quarantined-files.txt 2008-06-18 01:43:29 Pre-Run: 13,056,262,144 bytes disponíveis Post-Run: 13,218,689,024 bytes disponíveis 166 --- E O F --- 2008-06-11 16:16:58 Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Junho 18, 2008 Caso Resolvido Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 19, 2008 Opa, brigadão Silas agora é só esperar um Moderador da area fechar o topico... :joia: :joia: Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Junho 19, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto é necessário enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites