Edvan 30 Denunciar post Postado Julho 29, 2008 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:39:03, on 28/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Ralink Wireless Utility.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing) O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4267 bytes ComboFix 08-07-28.4 - Edvan 2008-07-28 23:25:28.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.175 [GMT -3:00]Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\d3doutf.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_NPF ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))) . 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\ hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Hamachi\\hamachi.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] S2 snss;snss;C:\WINDOWS\system32\snss.exe [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com . . ------- Ccan Suplementar ------- . R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/ R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore O8 -: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-28 23:31:13 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . ------------------------ Outros Processos em Execu‡Æo ------------------------ . C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\RealVNC\VNC4\winvnc4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Tempo para conclusÆo: 2008-07-28 23:38:01 - Maquina reiniciou ComboFix-quarantined-files.txt 2008-07-29 02:37:36 Pre-Run: 8 pasta(s) 14,206,410,752 bytes disponíveis Post-Run: 12 pasta(s) 14,211,608,576 bytes dispon¡veis 114 --- E O F --- 2008-07-27 14:11:22 Espero ajuda... :thumbsup: :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Julho 29, 2008 Opa Edvan, <!> Antes de qualquer medida, faça a instalação do RC! --------------------------------------- • Vá ao site da Microsoft: < Link > • Selecione o download, que seja adequado, ao seu Sistema Operacional! • Faça o download, do arquivo, e salve-o no seu desktop. • Feche todos os programas, que estejam abertos! • Feche, também, seus programas de proteção! ( Antivírus,Antispywares e Firewall ) • Arraste o setup, baixado do site da Microsoft, para o interior do ComboFix.exe • Veja, abaixo, a demonstração! • Siga as mensagens que aparecem na tela,para iniciar o ComboFix. • Aceite o contrato da Microsoft, para instalar o "Console de Recuperação da Microsoft". • Na próxima mensagem, clique em "Yes", para realizar um scan com o ComboFix. • Terminando, poste os relatórios: • C:\ComboFix.txt mais o log do HijackThis, atualizado. Abraços Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Julho 29, 2008 Baixei o arquivo vou fazer os procedimentos volto em 5 minutos.. Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Julho 29, 2008 Olha eu aqui novamente!! Log atualizado do HijackThis.. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:25:48, on 29/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Ralink Wireless Utility.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing) O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4355 bytes LOg atualizado do combofix: ComboFix 08-07-28.4 - Edvan 2008-07-29 0:19:16.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.172 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-PTB.exe * Criado um novo ponto de restauro . ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))) . 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\ hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Hamachi\\hamachi.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] S2 snss;snss;C:\WINDOWS\system32\snss.exe [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com . . ------- Ccan Suplementar ------- . R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/ R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore O8 -: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-29 00:21:25 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-07-29 0:24:49 ComboFix-quarantined-files.txt 2008-07-29 03:23:43 Pre-Run: 7 pasta(s) 14,214,033,408 bytes disponíveis Post-Run: 12 pasta(s) 14,188,183,552 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTB.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 108 --- E O F --- 2008-07-27 14:11:22 Valeu cara pela ajuda... :thumbsup: :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Julho 29, 2008 No log do combofix mostra infecções por unidades removivéis. Caso use algum pendrive formate-o para que não haja uma nova reinficção, ok? Vamos lá. Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com Registry:: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Julho 29, 2008 Novo log do HijackThis.. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:07:41, on 29/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Ralink Wireless Utility.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing) O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4388 bytes Novo log do combofix: ComboFix 08-07-28.4 - Edvan 2008-07-29 1:01:17.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.164 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt * Criado um novo ponto de restauro FILE :: D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com . ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))) . 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\ hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Hamachi\\hamachi.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] S2 snss;snss;C:\WINDOWS\system32\snss.exe [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-29 01:03:24 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-07-29 1:07:07 ComboFix-quarantined-files.txt 2008-07-29 04:06:02 Pre-Run: 8 pasta(s) 14,184,435,712 bytes disponíveis Post-Run: 12 pasta(s) 14,176,370,688 bytes disponíveis 98 --- E O F --- 2008-07-27 14:11:22 Aguardo retorno.. valeu Sr. Perfect :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Julho 29, 2008 - Digite no Executar combofix /u e clique em Ok e aguarde a remoção do combofix. Remova o log anterior que estar em C:\ComboFix.txt. Faça o download do combofix novamente Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com Registry:: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Julho 29, 2008 Fiz todos os procedimentos que você pediu, segue os dois logs.... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:06:59, on 29/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\explorer.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Ralink Wireless Utility.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing) O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4115 bytes ComboFix 08-07-28.4 - Edvan 2008-07-29 1:56:04.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.97 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt * Criado um novo ponto de restauro FILE :: D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com . ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 )))))))))))))))))))))))))))))))) . 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-29 04:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] S2 snss;snss;C:\WINDOWS\system32\snss.exe [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-29 02:01:15 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-07-29 2:05:32 ComboFix-quarantined-files.txt 2008-07-29 05:04:25 Pre-Run: 8 pasta(s) 15,982,485,504 bytes disponíveis Post-Run: 12 pasta(s) 15,981,457,408 bytes disponíveis 95 --- E O F --- 2008-07-27 14:11:22 OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio.. :blink: Vou dar continuidade a esse poste só quarta-feira quando chegar de viagem... :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Julho 29, 2008 Opa Edvan, • Baixe o PenClean e salve-o em seu desktop; • Execute o programa; • Conecte o seu pendrive ao computador; • Selecione a opção Verificar todas as unidades e clique sobre o botão Verificar; <<Aguarde alguns instantes, o exame é bem rápido>> • Se algo for encontrado será solicitada a reinicialização da máquina. Clique sobre Sim. O computador será reiniciado; • Um relatório sobre a execução será gerado e salvo em C:\PenClean\PenClean.txt. • Poste o conteúdo do relatório em sua próxima resposta. ---------- Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::C:\WINDOWS\system32\snss.exe Driver:: snss - Reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização); Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. Clique em Executar, digite "1" e pressione "Enter" quando solicitado para iniciar o processo de remoção; Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando terminar, será gerado um log, que estará em C:\ComboFix.txt. Obs: Se o Combofix não reiniciar seu computador automaticamente, faça-o manualmente. Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Julho 31, 2008 OLa Sr. Perfect, tenha uma boa noite e muito obrigado por vossa ajuda.. :thumbsup: :thumbsup: Vamos lá aos procedimentos: Rodei o PenClean como você me mandou com pendrive espetado mais pelo que o mesmo mostrou não pegou nemhum malwares.. :blink: Olha só: Iniciando relatório do PenClean 2.0.3 Por Renato Victor Mejias renatomejias@yahoo.com.br 30/7/2008 22:55:51 ----------------------------------------------------------- Arquivos e chaves excluídos da unidade escolhida: Malware não detectado em nenhuma unidade! ----------------------------------------------------------- Fim da análise, a unidade verificada foi: "Todas as unidades" ----------------------------------------------------------- Arquivos excluídos da unidade escolhida: Malware não detectado na unidade escolhida! ----------------------------------------------------------- Fim da análise, a unidade verificada foi E: ----------------------------------------------------------- Arquivos e chaves excluídos da unidade escolhida: Malware não detectado em nenhuma unidade! ----------------------------------------------------------- Fim da análise, a unidade verificada foi: "Todas as unidades" ----------------------------------------------------------- Fiz o procedimento do combofix em Modo Seguro e segue o relatorio.. ComboFix 08-07-28.4 - Edvan 2008-07-30 23:03:37.6 - NTFSx86 MINIMAL Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt FILE :: C:\WINDOWS\system32\snss.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_SNSS -------\Service_snss ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))) . 2008-07-30 22:55 . 2008-07-30 22:56 <DIR> d-------- C:\PenClean 2008-07-30 18:57 . 2008-07-30 18:58 <DIR> d-------- C:\Arquivos de programas\Hamachi 2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configurações locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configurações locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configurações locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configurações locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configurações locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared 2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK 2008-06-19 01:16 . 2008-06-19 01:25 1,440,054 --a--c--- C:\WINDOWS\Wallpaper.bmp 2008-06-19 01:16 . 2007-07-27 16:59 427,520 --a------ C:\WINDOWS\system32\smsrs.exe 2008-06-19 00:37 . 2007-06-06 08:56 660,992 --ah----- C:\WINDOWS\system32\d3dinf.dll 2008-06-18 23:43 . 2008-06-18 23:43 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-18 21:39 . 2002-10-25 10:53 1,044,480 -ra------ C:\WINDOWS\system32\Roboex32.dll 2008-06-18 21:39 . 2002-10-25 10:53 40,960 -ra------ C:\WINDOWS\system32\wh2robo.dll 2008-06-18 21:36 . 2008-06-18 21:36 <DIR> d-------- C:\Arquivos de programas\Watchtower 2008-06-17 01:54 . 2002-05-07 00:13 <DIR> d-------- C:\Pessoal 2008-06-13 22:55 . 2008-06-13 22:56 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-11 12:11 . 2008-06-14 14:59 272,384 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 12:11 . 2008-06-14 14:59 272,384 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 12:01 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll 2008-06-11 12:01 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll 2008-06-11 12:01 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll 2008-06-11 12:01 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll 2008-06-08 11:14 . 2008-06-08 11:14 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy 2008-06-08 01:50 . 2008-06-08 01:50 268 --ah----- C:\sqmdata01.sqm 2008-06-08 01:50 . 2008-06-08 01:50 172 --ah----- C:\sqmnoopt01.sqm 2008-06-06 00:23 . 2008-06-06 00:23 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-06-06 00:19 . 2008-06-06 00:22 812,344 --a------ C:\HJTInstall.exe 2008-06-05 13:11 . 2008-07-30 23:08 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-06-05 13:10 . 2008-07-30 18:57 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2008-06-02 21:40 . 2008-07-10 21:33 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-06-02 01:15 . 2008-06-02 01:20 588 --a--c--- C:\WINDOWS\system32\winsys.lng 2008-06-02 01:15 . 2008-06-02 01:20 588 --a--c--- C:\WINDOWS\system32\kc8evwfj.cdm 2008-06-02 01:14 . 2008-06-02 12:14 <DIR> d-------- C:\Arquivos de programas\LingoCom 2008-06-02 01:14 . 2007-05-03 12:00 81,920 --a--c--- C:\WINDOWS\system32\GkSui20.EXE . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll 2008-04-21 07:02 661,504 ----a-w C:\WINDOWS\system32\wininet.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\ hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-30 18:57:20 624416] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-30 23:08:38 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . ------------------------ Outros Processos em Execu‡Æo ------------------------ . C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\Arquivos de programas\RealVNC\VNC4\winvnc4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Tempo para conclusÆo: 2008-07-30 23:15:44 - Maquina reiniciou ComboFix-quarantined-files.txt 2008-07-31 02:15:25 Pre-Run: 9 pasta(s) 16,363,761,664 bytes disponíveis Post-Run: 13 pasta(s) 15,964,561,408 bytes dispon¡veis 136 --- E O F --- 2008-07-27 14:11:22 Ha! coloquei um log novo do HijackThis... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:17:43, on 30/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Ralink Wireless Utility.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4139 bytes OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio. Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Julho 31, 2008 Baixe a EliStarA = no final da página clique no botão Descargar EliStarA. Sugiro que imprima ou salve os procedimentos abaixo, e não utilize a internet até terminado o procedimento. Reinicie em Modo Seguro (pressione repetidamente a tecla F8 durante a inicialização, até que apareça o menu, onde você deverá selecionar Modo Seguro). Execute o EliStarA.exe e aguarde, pois o scan é um pouco demorado. Terminado o processo, reinicie e poste o log (ele estará em C:\infoSat.txt). PS.: Esses procedimentos devem ser feito com o pendrive conectado OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio. Veja nas configurações do seu antivirus se a opção de iniciar junto com o windows não estar desmarcada. :) Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Agosto 3, 2008 Nenhum fecheiro infecados: (Nº de Ficheros Infectados: 0)... Sun Aug 03 00:33:24 2008 EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008) -------------------------------------------------- Lista de Acciones (por Acción Directa): Eliminada Carpeta "%WinDir%\PeerNet" No detectado SP3 de Windows XP Eliminadas las Paginas de Inicio y de Busqueda del IE Eliminados Ficheros Temporales del IE Sun Aug 03 00:34:22 2008 EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008) -------------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ Nº Total de Directorios: 2335 Nº Total de Ficheros: 19632 Nº de Ficheros Analizados: 9177 Nº de Ficheros Infectados: 0 Nº de Ficheros Limpiados: 0 Sun Aug 03 00:49:24 2008 EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008) -------------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad E:\ Nº Total de Directorios: 332 Nº Total de Ficheros: 1410 Nº de Ficheros Analizados: 777 Nº de Ficheros Infectados: 0 Nº de Ficheros Limpiados: 0 OBS: Nas configurações do Avast Não vi essa opção de iniciar junto com o sistema :blink: :blink: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Agosto 3, 2008 Faça o download do combofix novamente. Poste-o junto com um novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Agosto 3, 2008 Baixei novamente o COMBOFIX que você tinha me pedido.. :thumbsup: :thumbsup: ComboFix 08-08-01.05 - Edvan 2008-08-03 10:36:20.7 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.198 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\HJTInstall.exe C:\InfoSat.txt . ((((((((((((((((((((((( Ficheiros criados de 2008-07-03 to 2008-08-03 )))))))))))))))))))))))))))))))) . 2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet 2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead 2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK 2008-08-01 00:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-30 21:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com *Newly Created Service* - CATCHME . . ------- Ccan Suplementar ------- . FireFox -: Profile - C:\Documents and Settings\Edvan\Dados de aplicativos\Mozilla\Firefox\Profiles\2s6v1nxx.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.br/ ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-03 10:38:51 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-08-03 10:42:44 ComboFix-quarantined-files.txt 2008-08-03 13:41:38 Pre-Run: 7 pasta(s) 15,606,591,488 bytes disponíveis Post-Run: 11 pasta(s) 15,600,287,744 bytes disponíveis 111 --- E O F --- 2008-07-27 14:11:22 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:44:59, on 3/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\explorer.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4020 bytes OBS: Nas configurações do Avast não vi essa opção de iniciar o Anti..junto com o sistema... :mellow: Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Agosto 3, 2008 Opa Edvan, Faça o download do Flash_Disinfector.exe e salve no seu desktop (Ambiente de Trabalho): ◘ Primeiramente conecte seu pendrive infectado ao computador ◘ Duplo clique em Flash_Disinfector.exe. ◘ Ao aparecer uma mensagem na tela, confirme no OK ◘ Aguarde, o desktop irá sumir por alguns segundos. ◘ Quando a execução concluir, irá aparecer na tela a mensagem "Done" ◘ Reinicie o seu computador. Obs. Após a execução do Flash Disinfector, será criado em seu pendrive ou unidade removível uma pasta chamada C:\autorun.inf. O motivo de tal criação é proteger seu pendrive contra futuras infecções. Se tiver um Pendrive ou um drive de MP3 ou MP4, conecte no PC (se tiver mais de um, tem de conectar todos). Não os tire até completar todas as instruções. Delete a pasta qoobox que está localizada em C:\, delete também o Log ComboFix.txt também localizado em C:\. Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com Registry:: [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis OBS: Nas configurações do Avast não vi essa opção de iniciar o Anti..junto com o sistema... Depois de tratarmos das infecções em seu MICRO, cuidaremos disso, ok? :) Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Agosto 4, 2008 OLa Sr. Perfect, tem como você ajeitar os procedimentos que você mandou para mim pois todo o Texto está como LINK, não dar para fazer nenhum procedimento.. :thumbsup: Fico esperando.. <_< Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Agosto 4, 2008 OLa Sr. Perfect, tem como você ajeitar os procedimentos que você mandou para mim pois todo o Texto está como LINK, não dar para fazer nenhum procedimento.. :thumbsup: Fico esperando.. <_< Pronto Edvan o poste ja foi corrigido, não tinha feito isso por que não estava consiguindo editar os meus tópicos; :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Agosto 4, 2008 fiz os procedimentos conforme sugerido... :thumbsup: :thumbsup: Antes de colocar os logs me diz uma coisa que danado de virus é esse que nao sai? :blink: ComboFix 08-08-01.05 - Edvan 2008-08-04 0:20:53.8 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.196 [GMT -3:00] Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! FILE :: C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com . ((((((((((((((((((((((( Ficheiros criados de 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))) . 2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet 2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead 2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-04 03:02 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK 2008-08-01 00:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-07-30 21:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe 2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger 2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller 2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro 2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] \Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] \Shell\AutoRun\command - E:\ino6.com \Shell\explore\Command - E:\ino6.com \Shell\open\Command - E:\ino6.com . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-04 00:23:21 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-08-04 0:27:18 ComboFix-quarantined-files.txt 2008-08-04 03:26:10 Pre-Run: 7 pasta(s) 15,584,108,544 bytes disponíveis Post-Run: 12 pasta(s) 15,576,182,784 bytes disponíveis 106 --- E O F --- 2008-07-27 14:11:22 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:27:57, on 4/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\explorer.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4020 bytes Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Agosto 4, 2008 Antes de colocar os logs me diz uma coisa que danado de virus é esse que nao sai? Calma temos apenas agora um virus de pendrive. Se tiver um Pendrive ou um drive de MP3 ou MP4, conecte no PC (se tiver mais de um, tem de conectar todos). Não os tire até completar todas as instruções. Delete a pasta qoobox que está localizada em C:\, delete também o Log ComboFix.txt também localizado em C:\. Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::E:\ino6.com D:\CDSAMPLE\AUTORUN\AUTORUN.EXE Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Agosto 12, 2008 OLa Sr. Perfect, beleza cara? Rapaz desculpe a demora em postar, minha NET esta pessima cara, estava respondendo alguns topicos lá em Hadoware com maior luta e download sem pensar nao dar para fazer download com a NET desse jeito.. Mais vamos lá aos procedimentos: ComboFix 08-08-11.01 - Edvan 2008-08-12 12:32:16.9 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.133 [GMT -3:00]Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! FILE :: D:\CDSAMPLE\AUTORUN\AUTORUN.EXE E:\ino6.com . ((((((((((((((((((((((( Ficheiros criados de 2008-07-12 to 2008-08-12 )))))))))))))))))))))))))))))))) . 2008-08-06 17:10 . 2008-08-10 22:43 69 --a------ C:\WINDOWS\NeroDigital.ini 2008-08-06 17:08 . 2004-08-04 00:45 91,136 --a------ C:\WINDOWS\system32\kswdmcap.ax 2008-08-06 17:08 . 2004-08-04 00:45 91,136 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax 2008-08-06 17:08 . 2004-08-04 00:45 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax 2008-08-06 17:08 . 2004-08-04 00:45 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax 2008-08-06 17:08 . 2004-08-04 00:45 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2008-08-06 17:08 . 2004-08-04 00:45 54,784 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll 2008-08-06 17:08 . 2005-01-14 09:32 53,248 --a------ C:\WINDOWS\system32\PAStiSvc.exe 2008-08-06 17:08 . 2004-08-04 00:45 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax 2008-08-06 17:08 . 2004-08-04 00:45 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax 2008-08-06 17:08 . 2004-08-04 00:45 28,672 --a------ C:\WINDOWS\system32\vidcap.ax 2008-08-06 17:08 . 2004-08-04 00:45 28,672 --a--c--- C:\WINDOWS\system32\dllcache\vidcap.ax 2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\WINDOWS\PixArt 2008-08-06 17:07 . 2008-08-10 11:20 <DIR> d-------- C:\WINDOWS\Album 2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\Arquivos de programas\VideoCAM GF112 2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PCCamera 2008-08-06 17:05 . 2008-08-06 17:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations 2008-08-06 14:21 . 2004-11-29 16:51 122,928 --a------ C:\WINDOWS\system32\drivers\spca561.bak.sys 2008-08-06 11:38 . 2008-08-06 11:38 <DIR> d--hs---- C:\WINDOWS\ftpcache 2008-08-06 11:27 . 2008-08-06 16:39 <DIR> d-------- C:\Arquivos de programas\PhoTags Express 2008-08-06 11:22 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2008-08-06 11:22 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet 2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead 2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead 2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais 2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais 2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC 2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec 2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec 2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-09 01:57 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi 2008-08-09 01:10 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2008-08-06 20:08 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information 2008-08-06 20:05 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield 2008-08-04 03:02 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2 2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK 2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield 2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys 2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit 2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower 2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower 2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37] R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41] S3 PAC207;VideoCAM GF112;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 10:46] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-12 12:35:06 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . Tempo para conclusão: 2008-08-12 12:39:03 ComboFix-quarantined-files.txt 2008-08-12 15:37:57 Pre-Run: 7 pasta(s) 14,959,489,024 bytes disponíveis Post-Run: 12 pasta(s) 14,962,225,152 bytes disponíveis 115 --- E O F --- 2008-07-27 14:11:22 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:40:26, on 12/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\explorer.exe C:\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe -- End of file - 4136 bytes Fico no aguardo.. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites