MMQ 0 Denunciar post Postado Julho 21, 2008 Navegando na net recebi mensagem do AVAST apontando infecção. Ocorre que a partir de então o computador fica reinicializando e aparece uma tela azul com a frase "bad pool header" e a indicação de que há algum problema com software ou hardware recém instalado. Fiz vários scaneamentos dos discos com o AVAST. Transfiro para a quarentena os vírus encontrados porém, cada vez que reincio a máquina, o AVAST detecta novamente o MALWARE. Recebi um alerta do AVAST indicando um processo oculto, trazendo o nome do seguinte arquivo NTOS.exe. Colo abaixo o log do Hijackthis. Grato pela ajuda. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:28:19, on 20/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe C:\keuxeg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\lphcvggj0ev57.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe,C:\WINDOWS\system32\ntos.exe, O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe O4 - HKLM\..\Run: [advap32] "c:\keuxeg.exe" /r O4 - HKLM\..\Run: [lphcvggj0ev57] C:\WINDOWS\system32\lphcvggj0ev57.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6371 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 21, 2008 Bom Dia! MMQ <@> Faça o download do ComboFix. <@> Baixe-o para o Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e Firewall. <@> Feche todas as janelas e execute a ferramenta! Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.Salve-a no Desktop,renomeada como: Kombo.exe Ps: Nomeie durante o salvamento,e não após salvá-la! Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança. <@> Abrirá a janela Auto Scan. Aguarde! <@> Digite a opção para continuar e < Enter > <@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! <@> Para parar ou sair do ComboFix,tecle "N". --------------------------------------------- <@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 22, 2008 Prezado, Seguem os logs do COMBOFIX e do Hijackthis posterior ao uso do COMBOFIX. Grato mais uma vez. ComboFix 08-07-21.1 - Márcio 2008-07-21 21:34:06.1 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1800 [GMT -3:00] Executando de: C:\Documents and Settings\Márcio\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\LocalService\Dados de aplicativos\wsnpoem C:\Documents and Settings\LocalService\Dados de aplicativos\wsnpoem\audio.dll C:\Documents and Settings\NetworkService\Dados de aplicativos\wsnpoem C:\Documents and Settings\NetworkService\Dados de aplicativos\wsnpoem\audio.dll C:\WINDOWS\system32\blphcvggj0ev57.scr C:\WINDOWS\system32\lphcvggj0ev57.exe C:\WINDOWS\system32\phcvggj0ev57.bmp . ((((((((((((((((((((((( Ficheiros criados de 2008-06-22 to 2008-07-22 )))))))))))))))))))))))))))))))) . 2008-07-21 02:19 . 2008-07-21 02:42 146 --a------ C:\WINDOWS\wininit.ini 2008-07-21 02:04 . 2008-07-21 02:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-07-21 02:04 . 2008-07-21 02:04 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy 2008-07-20 22:28 . 2008-07-20 22:28 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-07-20 17:55 . 2008-07-20 17:55 15,360 --a------ C:\keuxeg.exe 2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe 2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe 2008-07-20 12:59 . 2008-07-20 13:01 37 --a------ C:\WINDOWS\ipixActivex.ini 2008-06-27 22:20 . 2008-06-27 22:41 <DIR> d-------- C:\Recnet 2008-06-27 22:20 . 2006-10-31 13:12 128,000 --a------ C:\WINDOWS\DesinstWRecnet.exe 2008-06-27 22:20 . 2008-02-12 14:27 122,880 --a------ C:\WINDOWS\DesinstRecnet.exe 2008-06-27 22:20 . 2006-10-31 13:12 5,361 --a------ C:\WINDOWS\DesinstWRecnet.ini 2008-06-27 22:20 . 2008-06-27 22:20 127 --a------ C:\WINDOWS\REC-NET.INI . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-22 00:28 52,640 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-07-22 00:28 4,311,072 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-22 00:25 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Google Updater 2008-06-10 01:36 --------- d-----w C:\Arquivos de programas\Programas SRF 2008-06-10 01:25 --------- d-----w C:\Arquivos de programas\Programas RFB 2008-05-02 01:22 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE 2008-04-29 02:27 86,016 ------w C:\WINDOWS\system32\pxwma.dll 2008-04-27 13:26 15,600 ----a-w C:\WINDOWS\gdrv.sys 2008-04-26 00:28 315,392 ----a-w C:\WINDOWS\HideWin.exe 2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:45 1667584] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 10:18 68856] "SpybotSD TeaTimer"="C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 09:44 36864] "36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 09:08 1953792] "EasyTuneV"="C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe" [2007-04-26 15:50 24576] "ISUSPM Startup"="C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 07:15 221184] "ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-02-17 07:15 81920] "StartCCC"="C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112] "ZoneAlarm Client"="C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016] "avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 20:19 79224] "RemoteControl"="C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "iKeyWorks"="C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe" [2008-05-01 23:39 73728] "RTHDCPL"="RTHDCPL.EXE" [2007-04-12 06:33 16132608 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-25 23:31:13 113664] Google Updater.lnk - C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe [2008-05-01 10:18:46 124400] Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.xvid"= xvid.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 20:20] S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20:16] *Newly Created Service* - CATCHME . - - - - ORPHANS REMOVED - - - - HKLM-Run-lphcvggj0ev57 - C:\WINDOWS\system32\lphcvggj0ev57.exe . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-21 21:36:25 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-07-21 21:37:12 ComboFix-quarantined-files.txt 2008-07-22 00:37:02 Pre-Run: 3,265,318,912 bytes disponíveis Post-Run: 4,074,160,128 bytes disponíveis 113 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:44:58, on 21/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe O4 - HKLM\..\RunOnce: [spybotDeletingA372] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6425 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 22, 2008 Boa Noite! MMQ WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! <!> Para a segurança do PC,vamos providenciar a instalação do Console de Recuperação. --------------------------------------- <!> Vá ao site da Microsoft: < Link > <!> Selecione o download,que seja adequado,ao seu Sistema Operacional! <!> Faça o download,do arquivo,e salve-o no seu desktop. <!> Feche todos os programas,que estejam abertos! <!> Feche,também,seus programas de proteção! ( Antivírus,Antispywares e Firewall ) <!> Arraste o setup,baixado do site da Microsoft,para o interior do ComboFix.exe <!> Veja,abaixo,a demonstração! <!> Siga as mensagens que aparecem na tela,para iniciar o ComboFix. <!> Aceite o contrato da Microsoft,para instalar o "Console de Recuperação da Microsoft". <!> Na próxima mensagem,clique em "Yes",para realizar um scan com o ComboFix. <!> Terminando,poste os relatórios: <!> C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 22, 2008 Prezado, Quando arrasto o setup para o COMBOFix e o inicio digitando 1 e enter o processo é interrompido com a seguinte mensagem: Erro Installation file - c:\Documents and settings\marcio\desktop\windowsxp-KB3.....exe cannot be find Botão OK O programa foi salvo no desktop. O que pode estar acontecendo? Grato. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 22, 2008 Prezado, Quando arrasto o setup para o COMBOFix e o inicio digitando 1 e enter o processo é interrompido com a seguinte mensagem: Erro Installation file - c:\Documents and settings\marcio\desktop\windowsxp-KB3.....exe cannot be find Botão OK O programa foi salvo no desktop. O que pode estar acontecendo? Grato. ------------------------- Opa! MMQ Bom Dia! <!> Rode um programa de limpeza,antes de executar o procedimento! <!> Desabilite programas de proteção. ( Proteção Residente do Avast! ) <!> Tente executá-lo em Modo de Segurança! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 22, 2008 DigRam, Rodei o combofix (arrastando o arquivo da MS) em modo de segurança. A mensagem de erro apareceu novamente. Alguma outra dica? Da análise dos últimos logs que enviei, pôde confirmar que a máquina está livre dos virus? Fica faltando o console de recuperação. Muito obrigado. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 22, 2008 Bom Dia! MMQ Rodei o combofix (arrastando o arquivo da MS) em modo de segurança. A mensagem de erro apareceu novamente.Alguma outra dica? <!> Se foi baixado o setup,na versão adequada ao seu SO,e o erro continua...(..)Tente,então,instalar a atualização SP3. ---------------------- Da análise dos últimos logs que enviei, pôde confirmar que a máquina está livre dos virus? <!> Não! Ainda temos infecções. ---------------------- <@> Abra o Spybot Search & Destroy! <@> No menu superior,vá em Modo e selecione a opção Avançado. Confirme! <@> Clique no botão Ferramentas e depois em Residente. <@> Desmarque a opção: Ativar "TeaTimer" do Residente. ( Proteção geral das configurações de sistema ) <@> Desabilite,também,a proteção residente do Avast! ---------------------- <@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas. <@> Salve-o,no Desktop,com o nome: CFScript.txt Files::C:\keuxeg.exe C:\Documents and Settings\Márcio\svschost.exe C:\WINDOWS\ipixActivex.ini Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=- <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Reinicie o computador! <@> Terminando,poste os relatórios: C:\ComboFix.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 23, 2008 DigRam, Seguem os logs. Obrigado. ComboFix 08-07-21.1 - Márcio 2008-07-22 23:54:10.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1614 [GMT -3:00] Executando de: C:\Documents and Settings\Márcio\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Márcio\Desktop\CFScript.txt.txt * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\OPTIONS\CABS\_desktop.ini . ((((((((((((((((((((((( Ficheiros criados de 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))) . 2008-07-21 02:19 . 2008-07-21 02:42 146 --a------ C:\WINDOWS\wininit.ini 2008-07-21 02:04 . 2008-07-21 02:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-07-21 02:04 . 2008-07-21 02:04 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy 2008-07-20 22:28 . 2008-07-20 22:28 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-07-20 17:55 . 2008-07-20 17:55 15,360 --a------ C:\keuxeg.exe 2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe 2008-07-20 17:55 . 2008-07-20 17:55 2,548 --a------ C:\Documents and Settings\Márcio\svschost.exe 2008-07-20 12:59 . 2008-07-20 13:01 37 --a------ C:\WINDOWS\ipixActivex.ini 2008-06-27 22:20 . 2008-06-27 22:41 <DIR> d-------- C:\Recnet 2008-06-27 22:20 . 2006-10-31 13:12 128,000 --a------ C:\WINDOWS\DesinstWRecnet.exe 2008-06-27 22:20 . 2008-02-12 14:27 122,880 --a------ C:\WINDOWS\DesinstRecnet.exe 2008-06-27 22:20 . 2006-10-31 13:12 5,361 --a------ C:\WINDOWS\DesinstWRecnet.ini 2008-06-27 22:20 . 2008-06-27 22:20 127 --a------ C:\WINDOWS\REC-NET.INI . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-23 03:03 4,466,720 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-23 02:43 54,176 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-07-23 01:27 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Google Updater 2008-06-10 01:36 --------- d-----w C:\Arquivos de programas\Programas SRF 2008-06-10 01:25 --------- d-----w C:\Arquivos de programas\Programas RFB 2008-05-02 01:22 45,056 ----a-w C:\WINDOWS\NCUNINST.EXE 2008-04-29 02:27 86,016 ------w C:\WINDOWS\system32\pxwma.dll 2008-04-27 13:26 15,600 ----a-w C:\WINDOWS\gdrv.sys 2008-04-26 00:28 315,392 ----a-w C:\WINDOWS\HideWin.exe 2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe . ((((((((((((((((((((((((((((( snapshot@2008-07-21_21.36.58.01 ))))))))))))))))))))))))))))))))))))))))) . + 2008-07-23 02:44:44 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_7fc.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 00:45 1667584] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-01 10:18 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 09:44 36864] "36X Raid Configurer"="C:\WINDOWS\system32\JMRaidSetup.exe" [2007-02-06 09:08 1953792] "EasyTuneV"="C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe" [2007-04-26 15:50 24576] "ISUSPM Startup"="C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 07:15 221184] "ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-02-17 07:15 81920] "StartCCC"="C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112] "ZoneAlarm Client"="C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016] "avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 20:19 79224] "RemoteControl"="C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] "iKeyWorks"="C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe" [2008-05-01 23:39 73728] "RTHDCPL"="RTHDCPL.EXE" [2007-04-12 06:33 16132608 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-25 23:31:13 113664] Google Updater.lnk - C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe [2008-05-01 10:18:46 124400] Microsoft Office.lnk - C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.xvid"= xvid.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 20:20] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20:16] *Newly Created Service* - PROCEXP90 . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-23 00:03:00 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-07-23 0:03:25 ComboFix-quarantined-files.txt 2008-07-23 03:03:23 ComboFix2.txt 2008-07-22 00:37:13 Pre-Run: 3,901,054,976 bytes disponíveis Post-Run: 3,888,033,792 bytes disponíveis 102 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:11:15, on 23/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6313 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 23, 2008 Bom Dia! MMQ Mantenha,ainda,suas proteções desabilitadas! <@> Faça o download do SDFix. <@> Salve-o no Disco Local-C e,descompacte-o aì mesmo. <@> Reinicie o computador em Modo de Segurança. <@> Dê um duplo clique em: < runThis.bat > <!> Caso uma janela abra e feche,repentinamente,adote as seguintes medidas: <!> Vá em Iniciar >> Executar >> Digite ou cole: %systemdrive%\SDFix\apps\FixPath.exe /Q --> Clique: OK <!> Reinicie o computador e execute,novamente,o SDFix! <!> Caso não funcione,verifique a variável %comspec%. <!> Clique direito do mouse em Meu Computador >> Propriedades >> Avançadas. <!> Em: Variáveis do Ambiente >> Verifique se a variável ComSpec,tem o valor para o cmd.exe. <!> Valor: C:\Windows\system32\cmd.exe <@> Aperte o Y. <@> Aguarde a conclusão! <@> Terminando,aperte Enter.( ...ou,qualquer tecla!) <@> O computador será reiniciado! <@> Aguarde,ainda,a conclusão da limpeza. ------------------------ <@> Poste,na sua resposta,os relatórios: Report.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 24, 2008 DigRam, Ao rodar o SDFIX apareceu a seguinte mensagem (duas vezes: na primeira execução e após a reinicialização) SUBSISTEMA MSDOS DE 16 BITS SDFIX c:\ARQUIV~1\SIMANTEC\S32EVNT1.DLL. UMA DRIVER DE DISPOSITIVO VIRTUAL QUE PODE SER INSTALADO FALHOU AO INICIAR A DLL. ESCOLHA FECHAR PARA FINALIZAR. Prossegui na execução pressionando IGNORAR. Seguem os logs. Grato. SDFix: Version 1.207 Run by M rcio on 23/07/2008 at 21:23 Microsoft Windows XP [versÆo 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-23 21:27:05 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files : Files with Hidden Attributes : Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SDUpdate.exe" Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\SpybotSD.exe" Mon 7 Jul 2008 2,156,368 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" Finished! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:29:38, on 23/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6289 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 24, 2008 Boa Noite! MMQ <@> Submeta estes ficheiros,à uma análise em Sunbelt Sandbox. C:\keuxeg.exe <-- C:\Documents and Settings\Márcio\svschost.exe <-- C:\WINDOWS\ipixActivex.ini <-- <@> No campo,digite o seu E-Mail. <@> Escolha o relatório,das verificações,em formato de texto! <@> Clique em: Submit sample for analysis,após indicar o caminho dos ficheiros para upload. <@> Faça um por vez! <@> Poste os relatórios dessas análises,que lhe foram enviadas por E-Mail. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 24, 2008 DigRam, Submeti os ficheiros. Ocorre que para o 1º, Keuxeg.exe, eles não enviaram o log p/ o e-mail. Veja a mensagem: Please Note: This file has already been added to the database, Sunbelt Sandbox ID: 5090158. You can review the log file HERE Encaminho cópia do que aparece nesse link Submission Details Date 7/22/2008 10:33:55 AM Sandbox Version 2.0.71 File Name file.exe Submitting Email Comment Summary Findings Total Number of Processes 5 Termination Reason NormalTermination Start Time 00:00.172 Stop Time 00:09.219 Start Reason AnalysisTarget Scanner Results Scan Engine Version Signature Version Result More Info Packer Classification 1.0 1.0 Packed Entropy: 7.13037057931 Sunbelt Vipre Antivirus version 3.0 3.0b2 Analysis HighLights Spawned Processes Found 4 Processes. (View Activity by Process) Filesystem Changes View File Changes Registry Changes View Registry Changes Network Activity View Network Activity Analysis Number 1 Parent ID 0 Process ID 1248 Filename C:\file.exe Filesize 15360 bytes MD5 736d5b4d7031022482bc913ff7683e84 Start Reason AnalysisTarget Termination Reason NormalTermination Start Time 00:00.172 Stop Time 00:09.219 Detection Packed (Packer Classification) (Sunbelt Vipre Antivirus version 3.0) DLL-Handling Loaded DLLs Filesystem New Files \\.\Rntm74 C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp Opened Files \\.\PhysicalDrive0 C:\WINDOWS\AppPatch\sysmain.sdb C:\WINDOWS\AppPatch\systest.sdb \Device\NamedPipe\ShimViewer C:\DOCUME~1\User\LOCALS~1\Temp\ C:\WINDOWS\System32\ Chronological order Create File: \\.\Rntm74 Open File: \\.\PhysicalDrive0 (OPEN_EXISTING) Create File: C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING) Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING) Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING) Open File: C:\DOCUME~1\User\LOCALS~1\Temp\ () Find File: C:\DOCUME~1\User\LOCALS~1\TempBN1.tmp Open File: C:\WINDOWS\System32\ () Find File: C:\WINDOWS\system32svchost.exe Registry Changes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" = C:\file.exe/r Reads HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService "" HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter "" Process Management Creates Process - Filename () CommandLine: (C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp) As User: () Creation Flags: () Creates Process - Filename () CommandLine: (C:\WINDOWS\System32\svchost.exe) As User: () Creation Flags: (CREATE_SUSPENDED) Kill Process - Filename () CommandLine: () Target PID: (1248) As User: () Creation Flags: () System Sleep - Milliseconds (2000) Threads Virtual Memory VM Allocate - Target: (1476) Address: ($13140000) Size: (22286336) Protect: (PAGE_EXECUTE_READWRITE) Allocation Type: (MEM_COMMIT,MEM_RESERVE) VM Protect - Target: (1476) Address: ($13140000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($13140000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($13141000) Size: (61440) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($13141000) Size: (61440) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($13150000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($13150000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($7FFD7000) Size: (4096) Protect: (PAGE_EXECUTE_READWRITE) VM Protect - Target: (1476) Address: ($7FFD7000) Size: (4096) Protect: (PAGE_READWRITE) VM Read - Target: (1476) Address: ($7FFD7008) Size: (4) VM Write - Target: (1476) Address: ($13140000) Size: (1024) VM Write - Target: (1476) Address: ($13141000) Size: (60416) VM Write - Target: (1476) Address: ($13150000) Size: (2560) VM Write - Target: (1476) Address: ($7FFD7008) Size: (4) Network Activity Download URLs http://66.197.167.21/40E800142020202020202...B000530B73CB726 (66.197.167.21) Outgoing connection to remote server: 66.197.167.21 TCP port 80 The following process was started by process: 1 Analysis Number 2 Parent ID 1 Process ID 1336 Filename C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp Filesize 47616 bytes MD5 638ac7d84ae7122284aadc4d0737b228 Start Reason CreateProcess Termination Reason NormalTermination Start Time 00:06.813 Stop Time 00:14.469 Detection Packed (Packer Classification) (Sunbelt Vipre Antivirus version 3.0) DLL-Handling Loaded DLLs Filesystem New Files C:\WINDOWS\System32\WinCtrl32.dll \\.\Rntm74 C:\WINDOWS\System32\drivers\Winlu48.sys Opened Files C:\WINDOWS\System32\calc.exe C:\WINDOWS\System32\drivers\Winlu48.sys C:\WINDOWS\AppPatch\sysmain.sdb C:\WINDOWS\AppPatch\systest.sdb \Device\NamedPipe\ShimViewer C:\WINDOWS\system32\ Chronological order Create File: C:\WINDOWS\System32\WinCtrl32.dll Create File: \\.\Rntm74 Create File: C:\WINDOWS\System32\drivers\Winlu48.sys Open File: C:\WINDOWS\System32\calc.exe (OPEN_EXISTING) Open File: C:\WINDOWS\System32\drivers\Winlu48.sys (OPEN_EXISTING) Set File Time: C:\WINDOWS\system32\drivers\Winlu48.sys Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING) Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING) Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING) Open File: C:\WINDOWS\system32\ () Find File: C:\WINDOWS\system32cmd.exe Registry Changes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WinCtrl32.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WLEventStartShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Winlu48.sys "" = Driver HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Winlu48.sys "" = Driver HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000001] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = System32\Drivers\Winlu48.sys HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = SCSI Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000001] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = System32\Drivers\Winlu48.sys HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = SCSI Class Reads HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter "" Process Management Creates Process - Filename (C:\WINDOWS\system32\cmd.exe) CommandLine: (/c del C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp >> NUL) As User: () Creation Flags: () Kill Process - Filename () CommandLine: () Target PID: (1336) As User: () Creation Flags: () Service Management Open Service Manager - Name: "SCM" Open Service - Name: "Winlu48" Create Service - Name: (Winlu48) Display Name: () File Name: (C:\WINDOWS\System32\drivers\Winlu48.sys) Control: () Start Type: (SERVICE_DEMAND_START) Start Service - Name: (Winlu48) Display Name: () File Name: () Control: () Start Type: () System Sleep - Milliseconds (500) The following process was started by process: 1 Analysis Number 3 Parent ID 1 Process ID 1476 Filename C:\WINDOWS\System32\svchost.exe Filesize 14336 bytes MD5 8f078ae4ed187aaabc0a305146de6716 Start Reason CreateProcess Termination Reason Timeout Start Time 00:06.875 Stop Time 01:01.703 Detection Not Packed (Packer Classification) (Sunbelt Vipre Antivirus version 3.0) DLL-Handling Loaded DLLs Filesystem Opened Files \\.\PIPE\lsarpc C:\WINDOWS\system32\drivers\etc\hosts Chronological order Open File: \\.\PIPE\lsarpc (OPEN_EXISTING) Open File: C:\WINDOWS\system32\drivers\etc\hosts (OPEN_EXISTING) Mutexes Creates Mutex: wljs903111mutaga Creates Mutex: WinEth0Pause Creates Mutex: mêåð111vertiga Creates Mutex: mc56î56î11gurtaga Creates Mutex: crypt32LogoffPortEvent Creates Mutex: memoryhallocblock Creates Mutex: zone_zdc_mutex Creates Mutex: MACLinkForever Creates Mutex: gangrena Creates Mutex: germeona Creates Mutex: garbaga Creates Mutex: 70ksjhdgdff Creates Mutex: 7123ohghbdg Opens Mutex: wljs903111mutaga Registry Changes HKEY_CURRENT_USER\Software\Microsoft "" = 764826 Reads HKEY_CURRENT_USER\Software\Microsoft "" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService "" System Sleep - Milliseconds (1000) Sleep - Milliseconds (5) Sleep - Milliseconds (100) Sleep - Milliseconds (500) Sleep - Milliseconds (50) System Info Get System Directory Get System Time Network Activity UDP Connections Remote IP Address: 192.58.128.30 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 192.228.79.201 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 128.8.10.90 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 192.33.4.12 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 192.58.128.30 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 202.12.27.33 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 193.0.14.129 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 202.12.27.33 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 192.36.148.17 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 202.12.27.33 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 202.12.27.33 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 245 Remote IP Address: 192.228.79.201 Port: 53 Send Datagram: packet(s) of size 21 Recv Datagram: packet(s) of size 411 Remote IP Address: 202.12.27.33 Port: 53 Send Datagram: packet(s) of size 20 Recv Datagram: packet(s) of size 278 Remote IP Address: captcha225 Port: 53 Send Datagram: packet(s) of size 45 Recv Datagram: packet(s) of size 130 Outgoing connection to remote server: 208.72.168.194 TCP port 1913 SMTP: 194.67.23.20:25 SMTP: 74.125.45.27:25 SMTP: 64.233.183.27:25 Analysis Number 4 Parent ID 0 Process ID 780 Filename services.exe Filesize -1 bytes MD5 Start Reason SCM Termination Reason Timeout Start Time 00:09.000 Stop Time 01:01.625 Service Management Load Driver - Name: (\Registry\Machine\System\CurrentControlSet\Services\Winlu48) File Name: () The following process was started by process: 2 Analysis Number 5 Parent ID 2 Process ID 1696 Filename C:\WINDOWS\system32\cmd.exe /c del C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp >> NUL Filesize -1 bytes MD5 Start Reason CreateProcess Termination Reason NormalTermination Start Time 00:14.344 Stop Time 00:14.906 Detection Not Packed (Packer Classification) (Sunbelt Vipre Antivirus version 3.0) DLL-Handling Loaded DLLs Process Management Kill Process - Filename () CommandLine: () Target PID: (1696) As User: () Creation Flags: () File Changes by all processes New Files \\.\Rntm74 C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp C:\WINDOWS\System32\WinCtrl32.dll \\.\Rntm74 C:\WINDOWS\System32\drivers\Winlu48.sys Opened Files \\.\PhysicalDrive0 C:\WINDOWS\AppPatch\sysmain.sdb C:\WINDOWS\AppPatch\systest.sdb \Device\NamedPipe\ShimViewer C:\DOCUME~1\User\LOCALS~1\Temp\ C:\WINDOWS\System32\ C:\WINDOWS\System32\calc.exe C:\WINDOWS\System32\drivers\Winlu48.sys C:\WINDOWS\AppPatch\sysmain.sdb C:\WINDOWS\AppPatch\systest.sdb \Device\NamedPipe\ShimViewer C:\WINDOWS\system32\ \\.\PIPE\lsarpc C:\WINDOWS\system32\drivers\etc\hosts Deleted Files Chronological Order Create File: \\.\Rntm74 Open File: \\.\PhysicalDrive0 (OPEN_EXISTING) Create File: C:\DOCUME~1\User\LOCALS~1\Temp\BN1.tmp Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING) Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING) Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING) Open File: C:\DOCUME~1\User\LOCALS~1\Temp\ () Find File: C:\DOCUME~1\User\LOCALS~1\TempBN1.tmp Open File: C:\WINDOWS\System32\ () Find File: C:\WINDOWS\system32svchost.exe Create File: C:\WINDOWS\System32\WinCtrl32.dll Create File: \\.\Rntm74 Create File: C:\WINDOWS\System32\drivers\Winlu48.sys Open File: C:\WINDOWS\System32\calc.exe (OPEN_EXISTING) Open File: C:\WINDOWS\System32\drivers\Winlu48.sys (OPEN_EXISTING) Set File Time: C:\WINDOWS\system32\drivers\Winlu48.sys Open File: C:\WINDOWS\AppPatch\sysmain.sdb (OPEN_EXISTING) Open File: C:\WINDOWS\AppPatch\systest.sdb (OPEN_EXISTING) Open File: \Device\NamedPipe\ShimViewer (OPEN_EXISTING) Open File: C:\WINDOWS\system32\ () Find File: C:\WINDOWS\system32cmd.exe Open File: \\.\PIPE\lsarpc (OPEN_EXISTING) Open File: C:\WINDOWS\system32\drivers\etc\hosts (OPEN_EXISTING) Registry Changes by all processes Create or Open Changes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" = C:\file.exe/r HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WinCtrl32.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = WLEventStartShell HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinCtrl32 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\Winlu48.sys "" = Driver HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\Winlu48.sys "" = Driver HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000001] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = System32\Drivers\Winlu48.sys HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Winlu48 "" = SCSI Class HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000001] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = [REG_DWORD, value: 00000000] HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = System32\Drivers\Winlu48.sys HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Winlu48 "" = SCSI Class HKEY_CURRENT_USER\Software\Microsoft "" = 764826 Reads HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService "" HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter "" HKEY_LOCAL_MACHINE\SYSTEM\WPA\MediaCenter "" HKEY_CURRENT_USER\Software\Microsoft "" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService "" Enums Os outros dois ficheiros (logs que recebi por e-mail): ________________________________________________________________________________ ______________________ <?xml version="1.0" ?> - <!-- This analysis was created by CWSandbox © CWSE GmbH / Sunbelt Software --> - <analysis cwsversion="2.0.71" time="7/4/2004 1:19:43 PM" file="file.exe" md5="8e83193fa4d500808952bd2fd967b6cb" sha1="771271f03ea0dcd136b3e9f4a479417846a583f6" logpath="C:\analysis\log\file.exe\run_1\"> - <calltree> <process_call index="1" pid="0" filename="C:\file.exe" starttime="00:00.109" startreason="AnalysisTarget" /> </calltree> - <processes> <process index="1" pid="0" filename="C:\file.exe" filesize="2548" md5="8e83193fa4d500808952bd2fd967b6cb" sha1="771271f03ea0dcd136b3e9f4a479417846a583f6" parentindex="0" starttime="00:00.109" terminationtime="00:00.000" startreason="AnalysisTarget" terminationreason="Unknown" executionstatus="CouldNotCreateProcess" executionerror="%1 is not a valid Win32 application. (Errorcode: 193)" applicationtype="Win32Application" /> </processes> <running_processes /> </analysis> ________________________________________________________________________________ _____________________ <?xml version="1.0" ?> - <!-- This analysis was created by CWSandbox © CWSE GmbH / Sunbelt Software --> - <analysis cwsversion="2.0.71" time="7/23/2008 11:21:02 PM" file="file.exe" md5="84988ecc0aa3a17dd69e8e18d34d69a0" sha1="208396ac5c8e520ae990225b66a50d8b30533203" logpath="C:\analysis\log\file.exe\run_1\"> - <calltree> <process_call index="1" pid="0" filename="C:\file.exe" starttime="00:00.156" startreason="AnalysisTarget" /> </calltree> - <processes> <process index="1" pid="0" filename="C:\file.exe" filesize="37" md5="84988ecc0aa3a17dd69e8e18d34d69a0" sha1="208396ac5c8e520ae990225b66a50d8b30533203" parentindex="0" starttime="00:00.156" terminationtime="00:00.000" startreason="AnalysisTarget" terminationreason="Unknown" executionstatus="CouldNotCreateProcess" applicationtype="Unknown" /> </processes> <running_processes /> </analysis> Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 24, 2008 Bom Dia! MMQ <@> BAIXE: < Kaspersky Virus Removal Tool > ----------------------------- <@> Faça o download da atualização mais recente! << Observe as datas! <@> Salve-o em Arquivos de Programas! <@> Reinicie o computador,em Modo de Segurança! << Importante! <@> Execute a ferramenta,com um duplo-clique,em seu executável. <@> Abrir-se-á a seguinte janela: <@> Na opção: Manual Cure,marque todas as caixas e clique em Scan. <@> Terminando o scan,copie e poste o relatório. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 25, 2008 DigRam, Segue relatório do Kaspersky. Colo apenas a 1ª parte que mostra o que foi detectado. O relatório é muito grande. Avise-me se for necessário enviar parte do eventos. Esses dois primeiros arquivos, antes de iniciarmos nosso contato, geravam alerta dos zone alarm de tentativas :unsure: de comunicação que foram negadas por mim. Confirmei o delete quando o Kaspersk sugeriu. Não sei se era para apagá-los???? :unsure: Grato. Scan ---- Scanned: 293953 Detected: 3 Untreated: 0 Start time: 24/07/2008 20:20:58 Duration: 02:25:59 Finish time: 24/07/2008 22:46:57 Detected -------- Status Object ------ ------ deleted: Trojan program Trojan-Downloader.Win32.Mutant.apg File: C:\keuxeg.exe deleted: Trojan program Trojan-Downloader.Win32.Small.ynz File: C:\QooBox\Quarantine\C\WINDOWS\system32\lphcvggj0ev57.exe.vir deleted: adware not-a-virus:AdWare.Win32.EShoper.d File: E:\Pastas INSTALAÇÃO\INSTALAÇÃO E Micro Prata\Zone Alarm\vtz3f.exe//UPX Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 25, 2008 Boa Noite! MMQ Confirmei o delete quando o Kaspersk sugeriu. Não sei se era para apagá-los???? <!> Era para apagá-los!E,não há necessidade da outra parte do relatório. ------------------------ <@> Está todo Ok,com o computador? ------------------------ <@> Poste um novo log do HijackThis. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 25, 2008 DigRam, Não noto mais nenhum problema com o computador. Abaixo o log do hijackthis. Será que podemos encerrar esse tópico? Muito Grato. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:50:49, on 24/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify...=br&.src=ym R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Arquivos de programas\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\JMRaidSetup.exe boot O4 - HKLM\..\Run: [EasyTuneV] C:\Arquivos de programas\Gigabyte\ET5\ETcall.exe O4 - HKLM\..\Run: [iSUSPM Startup] C:\ARQUIV~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [startCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [iKeyWorks] C:\ARQUIV~1\A4Tech\Keyboard\Ikeymain.exe O4 - HKLM\..\Run: [is-36JC9] "C:\Arquivos de programas\Kaspersky Lab Tool\is-36JC9\is-36JC9.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Google Updater.lnk = C:\Arquivos de programas\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: is-36JC9 - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab Tool\is-36JC9\is-36JC9.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6544 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 25, 2008 Bom Dia! MMQ <@> No Executar,digite: ComboFix.exe /u --> Clique: OK <@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação! ----------------------- <!> Os logs estão limpos! :thumbsup: <!> Bom trabalho! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
MMQ 0 Denunciar post Postado Julho 25, 2008 DigRam, Agradeço imensamente a sua atenção. :clap: Abrirei um nóvo tópico. Tenho um outro desktop, que inclusive esta em rede de cabo com esta máquina, que está travando no Explore e no Iexplorer. O avast não detecta nada. Postarei o log do Hijackthis. Se puder dar uma olhada .... Abraços Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 25, 2008 DigRam, Agradeço imensamente a sua atenção. :clap: Abrirei um nóvo tópico. Tenho um outro desktop, que inclusive esta em rede de cabo com esta máquina, que está travando no Explore e no Iexplorer. O avast não detecta nada. Postarei o log do Hijackthis. Se puder dar uma olhada .... Abraços -------------------- Bom Dia! MMQ <!> Poste,em outro Tópico,o relatório do HJT...e veremos o que pode ser feito! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites