Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

MMQ

[Resolvido!] NTOS.exe e Tela Azul bad pool header

Recommended Posts

Navegando na net recebi mensagem do AVAST apontando infecção. Ocorre que a partir de então o computador fica reinicializando e aparece uma tela azul com a frase "bad pool header" e a indicação de que há algum problema com software ou hardware recém instalado.

 

Fiz vários scaneamentos dos discos com o AVAST. Transfiro para a quarentena os vírus encontrados porém, cada vez que reincio a máquina, o AVAST detecta novamente o MALWARE. Recebi um alerta do AVAST indicando um processo oculto, trazendo o nome do seguinte arquivo NTOS.exe.

 

Colo abaixo o log do Hijackthis.

 

Grato pela ajuda.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:28:19, on 20/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

C:\keuxeg.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\lphcvggj0ev57.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\System32\wbem\wmiprvse.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\ntos.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe

O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot

O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

O4 - HKLM\..\Run: [advap32] "c:\keuxeg.exe" /r

O4 - HKLM\..\Run: [lphcvggj0ev57] C:\WINDOWS\system32\lphcvggj0ev57.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

--

End of file - 6371 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! MMQ

 

<@> Faça o download do ComboFix.

<@> Baixe-o para o Desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e Firewall.

<@> Feche todas as janelas e execute a ferramenta!

 

Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

Salve-a no Desktop,renomeada como: Kombo.exe

Ps: Nomeie durante o salvamento,e não após salvá-la!

Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança.

<@> Abrirá a janela Auto Scan. Aguarde!

<@> Digite a opção para continuar e < Enter >

<@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado!

<@> Para parar ou sair do ComboFix,tecle "N".

---------------------------------------------

<@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Prezado,

 

Seguem os logs do COMBOFIX e do Hijackthis posterior ao uso do COMBOFIX.

 

Grato mais uma vez.

 

 

ComboFix 08-07-21.1 - Márcio 2008-07-21 21:34:06.1 - NTFSx86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1800 [GMT -3:00]

Executando de: C:\Documents and Settings\Márcio\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\LocalService\Dados de aplicativos\wsnpoem

C:\Documents and Settings\LocalService\Dados de aplicativos\wsnpoem\audio.dll

C:\Documents and Settings\NetworkService\Dados de aplicativos\wsnpoem

C:\Documents and Settings\NetworkService\Dados de aplicativos\wsnpoem\audio.dll

C:\WINDOWS\system32\blphcvggj0ev57.scr

C:\WINDOWS\system32\lphcvggj0ev57.exe

C:\WINDOWS\system32\phcvggj0ev57.bmp

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-06-22 to 2008-07-22 ))))))))))))))))))))))))))))))))

.

 

2008-07-21 02:19 . 2008-07-21 02:42 146 --a------ C:\WINDOWS\wininit.ini

2008-07-21 02:04 . 2008-07-21 02:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-07-21 02:04 . 2008-07-21 02:04 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy

2008-07-20 22:28 . 2008-07-20 22:28 <DIR> d-------- C:\Arquivos de programas\Trend Micro

2008-07-20 17:55 . 2008-07-20 17:55 15,360 --a------ C:\keuxeg.exe

2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe

2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe

2008-07-20 12:59 . 2008-07-20 13:01 37 --a------ C:\WINDOWS\ipixActivex.ini

2008-06-27 22:20 . 2008-06-27 22:41 <DIR> d-------- C:\Recnet

2008-06-27 22:20 . 2006-10-31 13:12 128,000 --a------ C:\WINDOWS\DesinstWRecnet.exe

2008-06-27 22:20 . 2008-02-12 14:27 122,880 --a------ C:\WINDOWS\DesinstRecnet.exe

2008-06-27 22:20 . 2006-10-31 13:12 5,361 --a------ C:\WINDOWS\DesinstWRecnet.ini

2008-06-27 22:20 . 2008-06-27 22:20 127 --a------ C:\WINDOWS\REC-NET.INI

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-22 00:28 52,640 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx

2008-07-22 00:28 4,311,072 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat

2008-07-22 00:25 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Google Updater

2008-06-10 01:36 --------- d-----w C:\Arquivos de programas\Programas SRF

2008-06-10 01:25 --------- d-----w C:\Arquivos de programas\Programas RFB

2008-05-02 01:22 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE

2008-04-29 02:27 86,016 ------w C:\WINDOWS\system32\pxwma.dll

2008-04-27 13:26 15,600 ----a-w C:\WINDOWS\gdrv.sys

2008-04-26 00:28 315,392 ----a-w C:\WINDOWS\HideWin.exe

2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:45 1667584]

"swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 10:18 68856]

"SpybotSD TeaTimer"="C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 09:44 36864]

"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 09:08 1953792]

"EasyTuneV"="C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe" [2007-04-26 15:50 24576]

"ISUSPM Startup"="C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 07:15 221184]

"ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-02-17 07:15 81920]

"StartCCC"="C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

"ZoneAlarm Client"="C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 20:19 79224]

"RemoteControl"="C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

"iKeyWorks"="C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe" [2008-05-01 23:39 73728]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 06:33 16132608 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-25 23:31:13 113664]

Google Updater.lnk - C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe [2008-05-01 10:18:46 124400]

Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.xvid"= xvid.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

 

S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 20:20]

S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20:16]

 

*Newly Created Service* - CATCHME

.

- - - - ORPHANS REMOVED - - - -

 

HKLM-Run-lphcvggj0ev57 - C:\WINDOWS\system32\lphcvggj0ev57.exe

 

 

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-21 21:36:25

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-07-21 21:37:12

ComboFix-quarantined-files.txt 2008-07-22 00:37:02

 

Pre-Run: 3,265,318,912 bytes disponíveis

Post-Run: 4,074,160,128 bytes disponíveis

 

113

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:44:58, on 21/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe

O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot

O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

O4 - HKLM\..\RunOnce: [spybotDeletingA372] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

--

End of file - 6425 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! MMQ

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

<!> Para a segurança do PC,vamos providenciar a instalação do Console de Recuperação.

---------------------------------------

<!> Vá ao site da Microsoft: < Link >

 

<!> Selecione o download,que seja adequado,ao seu Sistema Operacional!

 

crecuperacaorz4.jpg

 

<!> Faça o download,do arquivo,e salve-o no seu desktop.

<!> Feche todos os programas,que estejam abertos!

<!> Feche,também,seus programas de proteção! ( Antivírus,Antispywares e Firewall )

<!> Arraste o setup,baixado do site da Microsoft,para o interior do ComboFix.exe

<!> Veja,abaixo,a demonstração!

 

rc1.gif

 

<!> Siga as mensagens que aparecem na tela,para iniciar o ComboFix.

<!> Aceite o contrato da Microsoft,para instalar o "Console de Recuperação da Microsoft".

<!> Na próxima mensagem,clique em "Yes",para realizar um scan com o ComboFix.

 

RC_whatnext.gif

 

<!> Terminando,poste os relatórios:

 

<!> C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Prezado,

 

Quando arrasto o setup para o COMBOFix e o inicio digitando 1 e enter o processo é interrompido com a seguinte mensagem:

 

Erro

 

Installation file - c:\Documents and settings\marcio\desktop\windowsxp-KB3.....exe cannot be find

Botão OK

 

O programa foi salvo no desktop. O que pode estar acontecendo?

 

Grato.

Compartilhar este post


Link para o post
Compartilhar em outros sites
Prezado,

 

Quando arrasto o setup para o COMBOFix e o inicio digitando 1 e enter o processo é interrompido com a seguinte mensagem:

 

Erro

 

Installation file - c:\Documents and settings\marcio\desktop\windowsxp-KB3.....exe cannot be find

Botão OK

 

O programa foi salvo no desktop. O que pode estar acontecendo?

 

Grato.

-------------------------

Opa! MMQ

Bom Dia!

 

<!> Rode um programa de limpeza,antes de executar o procedimento!

<!> Desabilite programas de proteção. ( Proteção Residente do Avast! )

<!> Tente executá-lo em Modo de Segurança!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Rodei o combofix (arrastando o arquivo da MS) em modo de segurança. A mensagem de erro apareceu novamente.

 

Alguma outra dica?

 

Da análise dos últimos logs que enviei, pôde confirmar que a máquina está livre dos virus?

 

Fica faltando o console de recuperação.

 

Muito obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! MMQ

 

Rodei o combofix (arrastando o arquivo da MS) em modo de segurança. A mensagem de erro apareceu novamente.

Alguma outra dica?

<!> Se foi baixado o setup,na versão adequada ao seu SO,e o erro continua...(..)Tente,então,instalar a atualização SP3.

----------------------

Da análise dos últimos logs que enviei, pôde confirmar que a máquina está livre dos virus?

<!> Não! Ainda temos infecções.

----------------------

<@> Abra o Spybot Search & Destroy!

<@> No menu superior,vá em Modo e selecione a opção Avançado. Confirme!

<@> Clique no botão Ferramentas e depois em Residente.

<@> Desmarque a opção: Ativar "TeaTimer" do Residente. ( Proteção geral das configurações de sistema )

<@> Desabilite,também,a proteção residente do Avast!

----------------------

<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.

<@> Salve-o,no Desktop,com o nome: CFScript.txt

 

Files::

C:\keuxeg.exe

C:\Documents and Settings\Márcio\svschost.exe

C:\WINDOWS\ipixActivex.ini

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=-

<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.

<@> Veja a demonstração!

 

35j0br8.gif

 

<@> Reinicie o computador!

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Seguem os logs.

 

Obrigado.

 

ComboFix 08-07-21.1 - Márcio 2008-07-22 23:54:10.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1614 [GMT -3:00]

Executando de: C:\Documents and Settings\Márcio\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Márcio\Desktop\CFScript.txt.txt

* Criado um novo ponto de restauro

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\OPTIONS\CABS\_desktop.ini

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))))))))

.

 

2008-07-21 02:19 . 2008-07-21 02:42 146 --a------ C:\WINDOWS\wininit.ini

2008-07-21 02:04 . 2008-07-21 02:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-07-21 02:04 . 2008-07-21 02:04 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy

2008-07-20 22:28 . 2008-07-20 22:28 <DIR> d-------- C:\Arquivos de programas\Trend Micro

2008-07-20 17:55 . 2008-07-20 17:55 15,360 --a------ C:\keuxeg.exe

2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe

2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe

2008-07-20 12:59 . 2008-07-20 13:01 37 --a------ C:\WINDOWS\ipixActivex.ini

2008-06-27 22:20 . 2008-06-27 22:41 <DIR> d-------- C:\Recnet

2008-06-27 22:20 . 2006-10-31 13:12 128,000 --a------ C:\WINDOWS\DesinstWRecnet.exe

2008-06-27 22:20 . 2008-02-12 14:27 122,880 --a------ C:\WINDOWS\DesinstRecnet.exe

2008-06-27 22:20 . 2006-10-31 13:12 5,361 --a------ C:\WINDOWS\DesinstWRecnet.ini

2008-06-27 22:20 . 2008-06-27 22:20 127 --a------ C:\WINDOWS\REC-NET.INI

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-23 03:03 4,466,720 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat

2008-07-23 02:43 54,176 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx

2008-07-23 01:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Google Updater

2008-06-10 01:36 --------- d-----w C:\Arquivos de programas\Programas SRF

2008-06-10 01:25 --------- d-----w C:\Arquivos de programas\Programas RFB

2008-05-02 01:22 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE

2008-04-29 02:27 86,016 ------w C:\WINDOWS\system32\pxwma.dll

2008-04-27 13:26 15,600 ----a-w C:\WINDOWS\gdrv.sys

2008-04-26 00:28 315,392 ----a-w C:\WINDOWS\HideWin.exe

2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-21_21.36.58.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-07-23 02:44:44 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_7fc.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

"MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:45 1667584]

"swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 10:18 68856]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 09:44 36864]

"36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 09:08 1953792]

"EasyTuneV"="C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe" [2007-04-26 15:50 24576]

"ISUSPM Startup"="C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 07:15 221184]

"ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-02-17 07:15 81920]

"StartCCC"="C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

"ZoneAlarm Client"="C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 20:19 79224]

"RemoteControl"="C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

"iKeyWorks"="C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe" [2008-05-01 23:39 73728]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 06:33 16132608 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-25 23:31:13 113664]

Google Updater.lnk - C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe [2008-05-01 10:18:46 124400]

Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.xvid"= xvid.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 20:20]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20:16]

 

*Newly Created Service* - PROCEXP90

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-23 00:03:00

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-07-23 0:03:25

ComboFix-quarantined-files.txt 2008-07-23 03:03:23

ComboFix2.txt 2008-07-22 00:37:13

 

Pre-Run: 3,901,054,976 bytes disponíveis

Post-Run: 3,888,033,792 bytes disponíveis

 

102

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:11:15, on 23/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe

O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot

O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

--

End of file - 6313 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! MMQ

 

Mantenha,ainda,suas proteções desabilitadas!

<@> Faça o download do SDFix.

<@> Salve-o no Disco Local-C e,descompacte-o aì mesmo.

<@> Reinicie o computador em Modo de Segurança.

<@> Dê um duplo clique em: < runThis.bat >

 

<!> Caso uma janela abra e feche,repentinamente,adote as seguintes medidas:

 

<!> Vá em Iniciar >> Executar >> Digite ou cole: %systemdrive%\SDFix\apps\FixPath.exe /Q --> Clique: OK

<!> Reinicie o computador e execute,novamente,o SDFix!

<!> Caso não funcione,verifique a variável %comspec%.

<!> Clique direito do mouse em Meu Computador >> Propriedades >> Avançadas.

<!> Em: Variáveis do Ambiente >> Verifique se a variável ComSpec,tem o valor para o cmd.exe.

 

<!> Valor: C:\Windows\system32\cmd.exe

<@> Aperte o Y.

<@> Aguarde a conclusão!

<@> Terminando,aperte Enter.( ...ou,qualquer tecla!)

<@> O computador será reiniciado!

<@> Aguarde,ainda,a conclusão da limpeza.

------------------------

<@> Poste,na sua resposta,os relatórios: Report.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Ao rodar o SDFIX apareceu a seguinte mensagem (duas vezes: na primeira execução e após a reinicialização)

 

SUBSISTEMA MSDOS DE 16 BITS

SDFIX

c:\ARQUIV~1\SIMANTEC\S32EVNT1.DLL. UMA DRIVER DE DISPOSITIVO VIRTUAL QUE PODE SER INSTALADO FALHOU AO INICIAR A DLL. ESCOLHA FECHAR PARA FINALIZAR.

 

Prossegui na execução pressionando IGNORAR.

 

Seguem os logs.

 

Grato.

 

 

 

SDFix: Version 1.207

Run by M rcio on 23/07/2008 at 21:23

 

Microsoft Windows XP [versÆo 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

 

Restoring Default Security Values

Restoring Default Hosts File

 

Rebooting

 

 

Checking Files :

 

No Trojan Files Found

 

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-23 21:27:05

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

 

Remaining Files :

 

 

 

Files with Hidden Attributes :

 

Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SDUpdate.exe"

Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SpybotSD.exe"

Mon 7 Jul 2008 2,156,368 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe"

 

Finished!

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:29:38, on 23/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe

O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot

O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

--

End of file - 6289 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! MMQ

 

<@> Submeta estes ficheiros,à uma análise em Sunbelt Sandbox.

 

C:\keuxeg.exe <--

 

C:\Documents and Settings\Márcio\svschost.exe <--

 

C:\WINDOWS\ipixActivex.ini <--

 

<@> No campo,digite o seu E-Mail.

<@> Escolha o relatório,das verificações,em formato de texto!

<@> Clique em: Submit sample for analysis,após indicar o caminho dos ficheiros para upload.

<@> Faça um por vez!

<@> Poste os relatórios dessas análises,que lhe foram enviadas por E-Mail.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Submeti os ficheiros.

 

Ocorre que para o 1º, Keuxeg.exe, eles não enviaram o log p/ o e-mail. Veja a mensagem:

 

Please Note: This file has already been added to the database, Sunbelt Sandbox ID: 5090158.

You can review the log file HERE

 

Encaminho cópia do que aparece nesse link

 

Submission Details

Date 7/22/2008 10:33:55 AM

Sandbox Version 2.0.71

File Name file.exe

Submitting Email

Comment

Summary Findings

Total Number of Processes 5

Termination Reason NormalTermination

Start Time 00:00.172

Stop Time 00:09.219

Start Reason AnalysisTarget

Scanner Results

Scan Engine Version Signature Version Result More Info

Packer Classification 1.0 1.0 Packed Entropy: 7.13037057931

Sunbelt Vipre Antivirus version 3.0 3.0b2

Analysis HighLights

Spawned Processes Found 4 Processes. (View Activity by Process)

Filesystem Changes View File Changes

Registry Changes View Registry Changes

Network Activity View Network Activity

 

Analysis Number 1

Parent ID 0

Process ID 1248

Filename C:\file.exe

Filesize 15360 bytes

MD5 736d5b4d7031022482bc913ff7683e84

Start Reason AnalysisTarget

Termination Reason NormalTermination

Start Time 00:00.172

Stop Time 00:09.219

Detection Packed (Packer Classification)

(Sunbelt Vipre Antivirus version 3.0)

 

DLL-Handling Loaded DLLs

 

 

Filesystem New Files

\\.\Rntm74

C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp

 

Opened Files

\\.\PhysicalDrive0

C:\WINDOWS\AppPatch\sysmain.sdb

C:\WINDOWS\AppPatch\systest.sdb

\Device\NamedPipe\ShimViewer

C:\DOCUME~1\User\LOCALS~1\Temp\

C:\WINDOWS\System32\

 

Chronological order

Create File: \\.\Rntm74

Open File: \\.\PhysicalDrive0 (OPEN_EXISTING)

Create File: C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp

Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING)

Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING)

Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING)

Open File: C:\DOCUME~1\User\LOCALS~1\Temp\ ()

Find File: C:\DOCUME~1\User\LOCALS~1\TempBN1.tmp

Open File: C:\WINDOWS\System32\ ()

Find File: C:\WINDOWS\system32svchost.exe

 

 

Registry Changes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" = C:\file.exe/r

 

Reads

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService ""

HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter ""

 

 

Process Management Creates Process - Filename () CommandLine: (C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp) As User: () Creation Flags: ()

Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\svchost.exe) As User: () Creation Flags: (CREATE_SUSPENDED)

Kill Process - Filename () CommandLine: () Target PID: (1248) As User: () Creation Flags: ()

 

System Sleep - Milliseconds (2000)

 

Threads

Virtual Memory VM Allocate - Target: (1476) Address: ($13140000) Size: (22286336) Protect: (PAGE_EXECUTE_READWRITE) Allocation Type: (MEM_COMMIT,MEM_RESERVE)

VM Protect - Target: (1476) Address: ($13140000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($13140000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($13141000) Size: (61440) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($13141000) Size: (61440) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($13150000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($13150000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($7FFD7000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE)

VM Protect - Target: (1476) Address: ($7FFD7000) Size: (4096) Protect: (PAGE_READWRITE)

VM Read - Target: (1476) Address: ($7FFD7008) Size: (4)

VM Write - Target: (1476) Address: ($13140000) Size: (1024)

VM Write - Target: (1476) Address: ($13141000) Size: (60416)

VM Write - Target: (1476) Address: ($13150000) Size: (2560)

VM Write - Target: (1476) Address: ($7FFD7008) Size: (4)

 

Network Activity Download URLs

http://66.197.167.21/40E800142020202020202...B000530B73CB726 (66.197.167.21)

Outgoing connection to remote server: 66.197.167.21 TCP port 80

 

The following process was started by process: 1

Analysis Number 2

Parent ID 1

Process ID 1336

Filename C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp

Filesize 47616 bytes

MD5 638ac7d84ae7122284aadc4d0737b228

Start Reason CreateProcess

Termination Reason NormalTermination

Start Time 00:06.813

Stop Time 00:14.469

Detection Packed (Packer Classification)

(Sunbelt Vipre Antivirus version 3.0)

 

DLL-Handling Loaded DLLs

 

 

Filesystem New Files

C:\WINDOWS\System32\WinCtrl32.dll

\\.\Rntm74

C:\WINDOWS\System32\drivers\Winlu48.sys

 

Opened Files

C:\WINDOWS\System32\calc.exe

C:\WINDOWS\System32\drivers\Winlu48.sys

C:\WINDOWS\AppPatch\sysmain.sdb

C:\WINDOWS\AppPatch\systest.sdb

\Device\NamedPipe\ShimViewer

C:\WINDOWS\system32\

 

Chronological order

Create File: C:\WINDOWS\System32\WinCtrl32.dll

Create File: \\.\Rntm74

Create File: C:\WINDOWS\System32\drivers\Winlu48.sys

Open File: C:\WINDOWS\System32\calc.exe (OPEN_EXISTING)

Open File: C:\WINDOWS\System32\drivers\Winlu48.sys (OPEN_EXISTING)

Set File Time: C:\WINDOWS\system32\drivers\Winlu48.sys

Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING)

Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING)

Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING)

Open File: C:\WINDOWS\system32\ ()

Find File: C:\WINDOWS\system32cmd.exe

 

 

Registry Changes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WinCtrl32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WLEventStartShell

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Winlu48.sys "" = Driver

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Winlu48.sys "" = Driver

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000001]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = System32\Drivers\Winlu48.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = SCSI Class

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000001]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = System32\Drivers\Winlu48.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = SCSI Class

 

Reads

HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter ""

 

 

Process Management Creates Process - Filename (C:\WINDOWS\system32\cmd.exe) CommandLine: (/c del C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp >> NUL) As User: () Creation Flags: ()

Kill Process - Filename () CommandLine: () Target PID: (1336) As User: () Creation Flags: ()

 

Service Management Open Service Manager - Name: "SCM"

Open Service - Name: "Winlu48"

Create Service - Name: (Winlu48) Display Name: () File Name: (C:\WINDOWS\System32\drivers\Winlu48.sys) Control: () Start Type: (SERVICE_DEMAND_START)

Start Service - Name: (Winlu48) Display Name: () File Name: () Control: () Start Type: ()

 

System Sleep - Milliseconds (500)

 

The following process was started by process: 1

Analysis Number 3

Parent ID 1

Process ID 1476

Filename C:\WINDOWS\System32\svchost.exe

Filesize 14336 bytes

MD5 8f078ae4ed187aaabc0a305146de6716

Start Reason CreateProcess

Termination Reason Timeout

Start Time 00:06.875

Stop Time 01:01.703

Detection Not Packed (Packer Classification)

(Sunbelt Vipre Antivirus version 3.0)

 

DLL-Handling Loaded DLLs

 

 

Filesystem Opened Files

\\.\PIPE\lsarpc

C:\WINDOWS\system32\drivers\etc\hosts

 

Chronological order

Open File: \\.\PIPE\lsarpc (OPEN_EXISTING)

Open File: C:\WINDOWS\system32\drivers\etc\hosts (OPEN_EXISTING)

 

 

Mutexes Creates Mutex: wljs903111mutaga

Creates Mutex: WinEth0Pause

Creates Mutex: mêåð111vertiga

Creates Mutex: mc56î56î11gurtaga

Creates Mutex: crypt32LogoffPortEvent

Creates Mutex: memoryhallocblock

Creates Mutex: zone_zdc_mutex

Creates Mutex: MACLinkForever

Creates Mutex: gangrena

Creates Mutex: germeona

Creates Mutex: garbaga

Creates Mutex: 70ksjhdgdff

Creates Mutex: 7123ohghbdg

Opens Mutex: wljs903111mutaga

 

Registry Changes

HKEY_CURRENT_USER\Software\Microsoft "" = 764826

 

Reads

HKEY_CURRENT_USER\Software\Microsoft ""

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService ""

 

 

System Sleep - Milliseconds (1000)

Sleep - Milliseconds (5)

Sleep - Milliseconds (100)

Sleep - Milliseconds (500)

Sleep - Milliseconds (50)

 

System Info Get System Directory

Get System Time

 

Network Activity UDP Connections

Remote IP Address: 192.58.128.30 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 192.228.79.201 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 128.8.10.90 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 192.33.4.12 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 192.58.128.30 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 202.12.27.33 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 193.0.14.129 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 202.12.27.33 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 192.36.148.17 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 202.12.27.33 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 202.12.27.33 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 245

 

Remote IP Address: 192.228.79.201 Port: 53

Send Datagram: packet(s) of size 21

Recv Datagram: packet(s) of size 411

 

Remote IP Address: 202.12.27.33 Port: 53

Send Datagram: packet(s) of size 20

Recv Datagram: packet(s) of size 278

 

Remote IP Address: captcha225 Port: 53

Send Datagram: packet(s) of size 45

Recv Datagram: packet(s) of size 130

 

Outgoing connection to remote server: 208.72.168.194 TCP port 1913

SMTP: 194.67.23.20:25

SMTP: 74.125.45.27:25

SMTP: 64.233.183.27:25

 

Analysis Number 4

Parent ID 0

Process ID 780

Filename services.exe

Filesize -1 bytes

MD5

Start Reason SCM

Termination Reason Timeout

Start Time 00:09.000

Stop Time 01:01.625

Service Management Load Driver - Name: (\Registry\Machine\System\CurrentControlSet\Services\Winlu48) File Name: ()

 

The following process was started by process: 2

Analysis Number 5

Parent ID 2

Process ID 1696

Filename C:\WINDOWS\system32\cmd.exe /c del C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp >> NUL

Filesize -1 bytes

MD5

Start Reason CreateProcess

Termination Reason NormalTermination

Start Time 00:14.344

Stop Time 00:14.906

Detection Not Packed (Packer Classification)

(Sunbelt Vipre Antivirus version 3.0)

 

DLL-Handling Loaded DLLs

 

 

Process Management Kill Process - Filename () CommandLine: () Target PID: (1696) As User: () Creation Flags: ()

 

 

File Changes by all processes

New Files \\.\Rntm74

C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp

C:\WINDOWS\System32\WinCtrl32.dll

\\.\Rntm74

C:\WINDOWS\System32\drivers\Winlu48.sys

 

Opened Files \\.\PhysicalDrive0

C:\WINDOWS\AppPatch\sysmain.sdb

C:\WINDOWS\AppPatch\systest.sdb

\Device\NamedPipe\ShimViewer

C:\DOCUME~1\User\LOCALS~1\Temp\

C:\WINDOWS\System32\

C:\WINDOWS\System32\calc.exe

C:\WINDOWS\System32\drivers\Winlu48.sys

C:\WINDOWS\AppPatch\sysmain.sdb

C:\WINDOWS\AppPatch\systest.sdb

\Device\NamedPipe\ShimViewer

C:\WINDOWS\system32\

\\.\PIPE\lsarpc

C:\WINDOWS\system32\drivers\etc\hosts

 

Deleted Files

Chronological Order Create File: \\.\Rntm74

Open File: \\.\PhysicalDrive0 (OPEN_EXISTING)

Create File: C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp

Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING)

Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING)

Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING)

Open File: C:\DOCUME~1\User\LOCALS~1\Temp\ ()

Find File: C:\DOCUME~1\User\LOCALS~1\TempBN1.tmp

Open File: C:\WINDOWS\System32\ ()

Find File: C:\WINDOWS\system32svchost.exe

Create File: C:\WINDOWS\System32\WinCtrl32.dll

Create File: \\.\Rntm74

Create File: C:\WINDOWS\System32\drivers\Winlu48.sys

Open File: C:\WINDOWS\System32\calc.exe (OPEN_EXISTING)

Open File: C:\WINDOWS\System32\drivers\Winlu48.sys (OPEN_EXISTING)

Set File Time: C:\WINDOWS\system32\drivers\Winlu48.sys

Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING)

Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING)

Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING)

Open File: C:\WINDOWS\system32\ ()

Find File: C:\WINDOWS\system32cmd.exe

Open File: \\.\PIPE\lsarpc (OPEN_EXISTING)

Open File: C:\WINDOWS\system32\drivers\etc\hosts (OPEN_EXISTING)

 

Registry Changes by all processes

Create or Open

Changes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" = C:\file.exe/r

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WinCtrl32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WLEventStartShell

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Winlu48.sys "" = Driver

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Winlu48.sys "" = Driver

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000001]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = System32\Drivers\Winlu48.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = SCSI Class

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000001]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000000]

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = System32\Drivers\Winlu48.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = SCSI Class

HKEY_CURRENT_USER\Software\Microsoft "" = 764826

 

Reads HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService ""

HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter ""

HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter ""

HKEY_CURRENT_USER\Software\Microsoft ""

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService ""

 

Enums

 

 

 

 

 

Os outros dois ficheiros (logs que recebi por e-mail):

 

________________________________________________________________________________

______________________

<?xml version="1.0" ?>

- <!-- This analysis was created by CWSandbox © CWSE GmbH / Sunbelt Software

-->

- <analysis cwsversion="2.0.71" time="7/4/2004 1:19:43 PM" file="file.exe" md5="8e83193fa4d500808952bd2fd967b6cb" sha1="771271f03ea0dcd136b3e9f4a479417846a583f6" logpath="C:\analysis\log\file.exe\run_1\">

- <calltree>

<process_call index="1" pid="0" filename="C:\file.exe" starttime="00:00.109" startreason="AnalysisTarget" />

</calltree>

- <processes>

<process index="1" pid="0" filename="C:\file.exe" filesize="2548" md5="8e83193fa4d500808952bd2fd967b6cb" sha1="771271f03ea0dcd136b3e9f4a479417846a583f6" parentindex="0" starttime="00:00.109" terminationtime="00:00.000" startreason="AnalysisTarget" terminationreason="Unknown" executionstatus="CouldNotCreateProcess" executionerror="%1 is not a valid Win32 application. (Errorcode: 193)" applicationtype="Win32Application" />

</processes>

<running_processes />

</analysis>

 

________________________________________________________________________________

_____________________

 

<?xml version="1.0" ?>

- <!-- This analysis was created by CWSandbox © CWSE GmbH / Sunbelt Software

-->

- <analysis cwsversion="2.0.71" time="7/23/2008 11:21:02 PM" file="file.exe" md5="84988ecc0aa3a17dd69e8e18d34d69a0" sha1="208396ac5c8e520ae990225b66a50d8b30533203" logpath="C:\analysis\log\file.exe\run_1\">

- <calltree>

<process_call index="1" pid="0" filename="C:\file.exe" starttime="00:00.156" startreason="AnalysisTarget" />

</calltree>

- <processes>

<process index="1" pid="0" filename="C:\file.exe" filesize="37" md5="84988ecc0aa3a17dd69e8e18d34d69a0" sha1="208396ac5c8e520ae990225b66a50d8b30533203" parentindex="0" starttime="00:00.156" terminationtime="00:00.000" startreason="AnalysisTarget" terminationreason="Unknown" executionstatus="CouldNotCreateProcess" applicationtype="Unknown" />

</processes>

<running_processes />

</analysis>

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! MMQ

 

<@> BAIXE: < Kaspersky Virus Removal Tool >

-----------------------------

<@> Faça o download da atualização mais recente! << Observe as datas!

<@> Salve-o em Arquivos de Programas!

<@> Reinicie o computador,em Modo de Segurança! << Importante!

<@> Execute a ferramenta,com um duplo-clique,em seu executável.

<@> Abrir-se-á a seguinte janela:

 

Kaspersky-Virus-Removal-Tool_1.png

 

<@> Na opção: Manual Cure,marque todas as caixas e clique em Scan.

<@> Terminando o scan,copie e poste o relatório.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Segue relatório do Kaspersky. Colo apenas a 1ª parte que mostra o que foi detectado. O relatório é muito grande. Avise-me se for necessário enviar parte do eventos.

Esses dois primeiros arquivos, antes de iniciarmos nosso contato, geravam alerta dos zone alarm de tentativas :unsure: de comunicação que foram negadas por mim.

 

Confirmei o delete quando o Kaspersk sugeriu. Não sei se era para apagá-los???? :unsure:

 

Grato.

 

Scan

----

Scanned: 293953

Detected: 3

Untreated: 0

Start time: 24/07/2008 20:20:58

Duration: 02:25:59

Finish time: 24/07/2008 22:46:57

 

 

Detected

--------

Status Object

------ ------

deleted: Trojan program Trojan-Downloader.Win32.Mutant.apg File: C:\keuxeg.exe

deleted: Trojan program Trojan-Downloader.Win32.Small.ynz File: C:\QooBox\Quarantine\C\WINDOWS\system32\lphcvggj0ev57.exe.vir

deleted: adware not-a-virus:AdWare.Win32.EShoper.d File: E:\Pastas INSTALAÇÃO\INSTALAÇÃO E Micro Prata\Zone Alarm\vtz3f.exe//UPX

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! MMQ

 

Confirmei o delete quando o Kaspersk sugeriu. Não sei se era para apagá-los????

<!> Era para apagá-los!E,não há necessidade da outra parte do relatório.

------------------------

<@> Está todo Ok,com o computador?

------------------------

<@> Poste um novo log do HijackThis.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Não noto mais nenhum problema com o computador.

 

Abaixo o log do hijackthis.

 

Será que podemos encerrar esse tópico?

 

Muito Grato.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:50:49, on 24/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe

C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe

O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot

O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe

O4 - HKLM\..\Run: [is-36JC9] "C:\Arquivos de programas\Kaspersky Lab Tool\is-36JC9\is-36JC9.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: is-36JC9 - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab Tool\is-36JC9\is-36JC9.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

 

--

End of file - 6544 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! MMQ

 

<@> No Executar,digite: ComboFix.exe /u --> Clique: OK

<@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação!

-----------------------

<!> Os logs estão limpos! :thumbsup:

<!> Bom trabalho!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Agradeço imensamente a sua atenção. :clap:

 

Abrirei um nóvo tópico. Tenho um outro desktop, que inclusive esta em rede de cabo com esta máquina, que está travando no Explore e no Iexplorer. O avast não detecta nada. Postarei o log do Hijackthis. Se puder dar uma olhada ....

 

Abraços

Compartilhar este post


Link para o post
Compartilhar em outros sites
DigRam,

 

Agradeço imensamente a sua atenção. :clap:

 

Abrirei um nóvo tópico. Tenho um outro desktop, que inclusive esta em rede de cabo com esta máquina, que está travando no Explore e no Iexplorer. O avast não detecta nada. Postarei o log do Hijackthis. Se puder dar uma olhada ....

 

Abraços

--------------------

Bom Dia! MMQ

 

<!> Poste,em outro Tópico,o relatório do HJT...e veremos o que pode ser feito!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.