Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Edvan

[Resolvido!]  Algumas infecções!

Recommended Posts

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:39:03, on 28/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing)

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4267 bytes

 

 

ComboFix 08-07-28.4 - Edvan 2008-07-28 23:25:28.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.175 [GMT -3:00]Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\system32\d3doutf.dll

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_NPF

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))

.

 

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\

hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Hamachi\\hamachi.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

S2 snss;snss;C:\WINDOWS\system32\snss.exe []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

.

.

------- Ccan Suplementar -------

.

R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/

R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore

O8 -: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-28 23:31:13

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

------------------------ Outros Processos em Execu‡Æo ------------------------

.

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\Arquivos de programas\RealVNC\VNC4\winvnc4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-07-28 23:38:01 - Maquina reiniciou

ComboFix-quarantined-files.txt 2008-07-29 02:37:36

 

Pre-Run: 8 pasta(s) 14,206,410,752 bytes disponíveis

Post-Run: 12 pasta(s) 14,211,608,576 bytes dispon¡veis

 

114 --- E O F --- 2008-07-27 14:11:22

 

 

Espero ajuda... :thumbsup: :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Edvan,

 

<!> Antes de qualquer medida, faça a instalação do RC!

---------------------------------------

• Vá ao site da Microsoft: < Link >

 

• Selecione o download, que seja adequado, ao seu Sistema Operacional!

 

crecuperacaorz4.jpg

 

• Faça o download, do arquivo, e salve-o no seu desktop.

• Feche todos os programas, que estejam abertos!

• Feche, também, seus programas de proteção! ( Antivírus,Antispywares e Firewall )

• Arraste o setup, baixado do site da Microsoft, para o interior do ComboFix.exe

• Veja, abaixo, a demonstração!

 

rc1.gif

 

• Siga as mensagens que aparecem na tela,para iniciar o ComboFix.

Aceite o contrato da Microsoft, para instalar o "Console de Recuperação da Microsoft".

• Na próxima mensagem, clique em "Yes", para realizar um scan com o ComboFix.

 

RC_whatnext.gif

 

• Terminando, poste os relatórios:

 

• C:\ComboFix.txt mais o log do HijackThis, atualizado.

 

Abraços

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixei o arquivo vou fazer os procedimentos volto em 5 minutos..

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olha eu aqui novamente!!

 

Log atualizado do HijackThis..

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:25:48, on 29/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing)

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4355 bytes

 

 

LOg atualizado do combofix:

 

 

ComboFix 08-07-28.4 - Edvan 2008-07-29 0:19:16.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.172 [GMT -3:00]

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-PTB.exe

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))

.

 

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\

hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Hamachi\\hamachi.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

S2 snss;snss;C:\WINDOWS\system32\snss.exe []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

.

.

------- Ccan Suplementar -------

.

R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/

R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore

O8 -: E&xportar para o Microsoft Excel - C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-29 00:21:25

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-07-29 0:24:49

ComboFix-quarantined-files.txt 2008-07-29 03:23:43

 

Pre-Run: 7 pasta(s) 14,214,033,408 bytes disponíveis

Post-Run: 12 pasta(s) 14,188,183,552 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTB.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

 

108 --- E O F --- 2008-07-27 14:11:22

 

 

Valeu cara pela ajuda... :thumbsup: :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

No log do combofix mostra infecções por unidades removivéis. Caso use algum pendrive formate-o para que não haja uma nova reinficção, ok?

 

Vamos lá.

 

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

Registry::

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

645i642ef2.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

Novo log do HijackThis..

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:07:41, on 29/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing)

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4388 bytes

 

 

Novo log do combofix:

 

ComboFix 08-07-28.4 - Edvan 2008-07-29 1:01:17.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.164 [GMT -3:00]

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))

.

 

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 23:08 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\Hamachi

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-29 02:31 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\

hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-27 23:08:22 624416]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Hamachi\\hamachi.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

S2 snss;snss;C:\WINDOWS\system32\snss.exe []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-29 01:03:24

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-07-29 1:07:07

ComboFix-quarantined-files.txt 2008-07-29 04:06:02

 

Pre-Run: 8 pasta(s) 14,184,435,712 bytes disponíveis

Post-Run: 12 pasta(s) 14,176,370,688 bytes disponíveis

 

98 --- E O F --- 2008-07-27 14:11:22

 

 

Aguardo retorno.. valeu Sr. Perfect :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

- Digite no Executar combofix /u e clique em Ok e aguarde a remoção do combofix.

 

Remova o log anterior que estar em C:\ComboFix.txt.

 

Faça o download do combofix novamente

 

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

Registry::

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

645i642ef2.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz todos os procedimentos que você pediu, segue os dois logs....

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 02:06:59, on 29/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\explorer.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: snss - Unknown owner - C:\WINDOWS\system32\snss.exe (file missing)

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4115 bytes

 

 

ComboFix 08-07-28.4 - Edvan 2008-07-29 1:56:04.5 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.97 [GMT -3:00]

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt

* Criado um novo ponto de restauro

 

FILE ::

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))

.

 

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-29 04:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-28 02:08 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-06 03:22 812,344 ----a-w C:\HJTInstall.exe

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-06-02 15:14 --------- d-----w C:\Arquivos de programas\LingoCom

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

S2 snss;snss;C:\WINDOWS\system32\snss.exe []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

 

*Newly Created Service* - CATCHME

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-29 02:01:15

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-07-29 2:05:32

ComboFix-quarantined-files.txt 2008-07-29 05:04:25

 

Pre-Run: 8 pasta(s) 15,982,485,504 bytes disponíveis

Post-Run: 12 pasta(s) 15,981,457,408 bytes disponíveis

 

95 --- E O F --- 2008-07-27 14:11:22

 

 

OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio.. :blink:

 

Vou dar continuidade a esse poste só quarta-feira quando chegar de viagem... :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Edvan,

 

• Baixe o PenClean e salve-o em seu desktop;

• Execute o programa;

• Conecte o seu pendrive ao computador;

• Selecione a opção Verificar todas as unidades e clique sobre o botão Verificar;

<<Aguarde alguns instantes, o exame é bem rápido>>

• Se algo for encontrado será solicitada a reinicialização da máquina. Clique sobre Sim. O computador será reiniciado;

• Um relatório sobre a execução será gerado e salvo em C:\PenClean\PenClean.txt.

• Poste o conteúdo do relatório em sua próxima resposta.

----------

 

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

C:\WINDOWS\system32\snss.exe

Driver::

snss

 

- Reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização);

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

645i642ef2.gif

 

Clique em Executar, digite "1" e pressione "Enter" quando solicitado para iniciar o processo de remoção;

 

Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando terminar, será gerado um log, que estará em C:\ComboFix.txt.

 

Obs: Se o Combofix não reiniciar seu computador automaticamente, faça-o manualmente.

 

Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

OLa Sr. Perfect, tenha uma boa noite e muito obrigado por vossa ajuda.. :thumbsup: :thumbsup:

 

Vamos lá aos procedimentos:

 

Rodei o PenClean como você me mandou com pendrive espetado mais pelo que o mesmo mostrou não pegou nemhum malwares.. :blink:

 

Olha só:

Iniciando relatório do PenClean 2.0.3

Por Renato Victor Mejias

renatomejias@yahoo.com.br

30/7/2008 22:55:51

-----------------------------------------------------------

Arquivos e chaves excluídos da unidade escolhida:

 

Malware não detectado em nenhuma unidade!

 

-----------------------------------------------------------

Fim da análise, a unidade verificada foi: "Todas as unidades"

 

-----------------------------------------------------------

Arquivos excluídos da unidade escolhida:

 

Malware não detectado na unidade escolhida!

 

-----------------------------------------------------------

Fim da análise, a unidade verificada foi E:

 

-----------------------------------------------------------

Arquivos e chaves excluídos da unidade escolhida:

 

Malware não detectado em nenhuma unidade!

 

-----------------------------------------------------------

Fim da análise, a unidade verificada foi: "Todas as unidades"

 

-----------------------------------------------------------

 

 

Fiz o procedimento do combofix em Modo Seguro e segue o relatorio..

 

ComboFix 08-07-28.4 - Edvan 2008-07-30 23:03:37.6 - NTFSx86 MINIMAL

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt

 

FILE ::

C:\WINDOWS\system32\snss.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_SNSS

-------\Service_snss

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))))

.

 

2008-07-30 22:55 . 2008-07-30 22:56 <DIR> d-------- C:\PenClean

2008-07-30 18:57 . 2008-07-30 18:58 <DIR> d-------- C:\Arquivos de programas\Hamachi

2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configurações locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\NetworkService\Configurações locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configurações locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Edvan\Configurações locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\Administrador\Configurações locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-06-30 22:21 . 2008-06-30 22:21 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 10:01 . 2008-06-30 10:01 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-30 02:56 . 2008-07-26 18:56 <DIR> d-------- C:\Arquivos de programas\RALINK

2008-06-19 01:16 . 2008-06-19 01:25 1,440,054 --a--c--- C:\WINDOWS\Wallpaper.bmp

2008-06-19 01:16 . 2007-07-27 16:59 427,520 --a------ C:\WINDOWS\system32\smsrs.exe

2008-06-19 00:37 . 2007-06-06 08:56 660,992 --ah----- C:\WINDOWS\system32\d3dinf.dll

2008-06-18 23:43 . 2008-06-18 23:43 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-18 21:39 . 2002-10-25 10:53 1,044,480 -ra------ C:\WINDOWS\system32\Roboex32.dll

2008-06-18 21:39 . 2002-10-25 10:53 40,960 -ra------ C:\WINDOWS\system32\wh2robo.dll

2008-06-18 21:36 . 2008-06-18 21:36 <DIR> d-------- C:\Arquivos de programas\Watchtower

2008-06-17 01:54 . 2002-05-07 00:13 <DIR> d-------- C:\Pessoal

2008-06-13 22:55 . 2008-06-13 22:56 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-11 12:11 . 2008-06-14 14:59 272,384 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-11 12:11 . 2008-06-14 14:59 272,384 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-11 12:01 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll

2008-06-11 12:01 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll

2008-06-11 12:01 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll

2008-06-11 12:01 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll

2008-06-11 12:01 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll

2008-06-11 12:01 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll

2008-06-11 12:01 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll

2008-06-11 12:01 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll

2008-06-08 11:14 . 2008-06-08 11:14 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy

2008-06-08 01:50 . 2008-06-08 01:50 268 --ah----- C:\sqmdata01.sqm

2008-06-08 01:50 . 2008-06-08 01:50 172 --ah----- C:\sqmnoopt01.sqm

2008-06-06 00:23 . 2008-06-06 00:23 <DIR> d-------- C:\Arquivos de programas\Trend Micro

2008-06-06 00:19 . 2008-06-06 00:22 812,344 --a------ C:\HJTInstall.exe

2008-06-05 13:11 . 2008-07-30 23:08 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-06-05 13:10 . 2008-07-30 18:57 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

2008-06-02 21:40 . 2008-07-10 21:33 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-06-02 01:15 . 2008-06-02 01:20 588 --a--c--- C:\WINDOWS\system32\winsys.lng

2008-06-02 01:15 . 2008-06-02 01:20 588 --a--c--- C:\WINDOWS\system32\kc8evwfj.cdm

2008-06-02 01:14 . 2008-06-02 12:14 <DIR> d-------- C:\Arquivos de programas\LingoCom

2008-06-02 01:14 . 2007-05-03 12:00 81,920 --a--c--- C:\WINDOWS\system32\GkSui20.EXE

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

2008-04-21 07:02 661,504 ----a-w C:\WINDOWS\system32\wininet.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

C:\Documents and Settings\Edvan\Menu Iniciar\Programas\Inicializar\

hamachi.lnk - C:\Arquivos de programas\Hamachi\hamachi.exe [2008-07-30 18:57:20 624416]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-30 23:08:38

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

------------------------ Outros Processos em Execu‡Æo ------------------------

.

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\Arquivos de programas\RealVNC\VNC4\winvnc4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-07-30 23:15:44 - Maquina reiniciou

ComboFix-quarantined-files.txt 2008-07-31 02:15:25

 

Pre-Run: 9 pasta(s) 16,363,761,664 bytes disponíveis

Post-Run: 13 pasta(s) 15,964,561,408 bytes dispon¡veis

 

136 --- E O F --- 2008-07-27 14:11:22

 

 

 

Ha! coloquei um log novo do HijackThis...

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:17:43, on 30/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: hamachi.lnk = C:\Arquivos de programas\Hamachi\hamachi.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = ?

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4139 bytes

 

 

OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe a EliStarA = no final da página clique no botão Descargar EliStarA.

 

Sugiro que imprima ou salve os procedimentos abaixo, e não utilize a internet até terminado o procedimento.

 

Reinicie em Modo Seguro (pressione repetidamente a tecla F8 durante a inicialização, até que apareça o menu, onde você deverá selecionar Modo Seguro).

 

Execute o EliStarA.exe e aguarde, pois o scan é um pouco demorado.

 

Terminado o processo, reinicie e poste o log (ele estará em C:\infoSat.txt).

 

PS.: Esses procedimentos devem ser feito com o pendrive conectado

 

 

OBS: Meu antivirus não está mais ativado no canto da tela perto do relogio, ele está instalado e tudo mais não esta mais como ativo perto do relogio.

 

Veja nas configurações do seu antivirus se a opção de iniciar junto com o windows não estar desmarcada.

 

:)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Nenhum fecheiro infecados: (Nº de Ficheros Infectados: 0)...

 

 

Sun Aug 03 00:33:24 2008

EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008)

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Eliminada Carpeta "%WinDir%\PeerNet"

No detectado SP3 de Windows XP

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

 

Sun Aug 03 00:34:22 2008

EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008)

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

 

Nº Total de Directorios: 2335

Nº Total de Ficheros: 19632

Nº de Ficheros Analizados: 9177

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0

 

Sun Aug 03 00:49:24 2008

EliStartPage v16.84 ©2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008)

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad E:\

 

Nº Total de Directorios: 332

Nº Total de Ficheros: 1410

Nº de Ficheros Analizados: 777

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0

 

 

 

OBS: Nas configurações do Avast Não vi essa opção de iniciar junto com o sistema :blink: :blink:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Faça o download do combofix novamente.

 

Poste-o junto com um novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixei novamente o COMBOFIX que você tinha me pedido.. :thumbsup: :thumbsup:

 

 

 

ComboFix 08-08-01.05 - Edvan 2008-08-03 10:36:20.7 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.198 [GMT -3:00]

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\HJTInstall.exe

C:\InfoSat.txt

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-07-03 to 2008-08-03 ))))))))))))))))))))))))))))))))

.

 

2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet

2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead

2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll

2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll

2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll

2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll

2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe

2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll

2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK

2008-08-01 00:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-30 21:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

 

*Newly Created Service* - CATCHME

.

.

------- Ccan Suplementar -------

.

FireFox -: Profile - C:\Documents and Settings\Edvan\Dados de aplicativos\Mozilla\Firefox\Profiles\2s6v1nxx.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.br/

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-03 10:38:51

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-08-03 10:42:44

ComboFix-quarantined-files.txt 2008-08-03 13:41:38

 

Pre-Run: 7 pasta(s) 15,606,591,488 bytes disponíveis

Post-Run: 11 pasta(s) 15,600,287,744 bytes disponíveis

 

111 --- E O F --- 2008-07-27 14:11:22

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:44:59, on 3/8/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\explorer.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4020 bytes

 

 

 

 

OBS: Nas configurações do Avast não vi essa opção de iniciar o Anti..junto com o sistema... :mellow:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Edvan,

 

Faça o download do Flash_Disinfector.exe e salve no seu desktop (Ambiente de Trabalho):

 

◘ Primeiramente conecte seu pendrive infectado ao computador

◘ Duplo clique em Flash_Disinfector.exe.

◘ Ao aparecer uma mensagem na tela, confirme no OK

◘ Aguarde, o desktop irá sumir por alguns segundos.

◘ Quando a execução concluir, irá aparecer na tela a mensagem "Done"

◘ Reinicie o seu computador.

 

Obs. Após a execução do Flash Disinfector, será criado em seu pendrive ou unidade removível uma pasta chamada C:\autorun.inf. O motivo de tal criação é proteger seu pendrive contra futuras infecções.

 

 

Se tiver um Pendrive ou um drive de MP3 ou MP4, conecte no PC (se tiver mais de um, tem de conectar todos). Não os tire até completar todas as instruções.

 

Delete a pasta qoobox que está localizada em C:\, delete também o Log ComboFix.txt também localizado em C:\.

 

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

Registry::

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

645i642ef2.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

 

 

OBS: Nas configurações do Avast não vi essa opção de iniciar o Anti..junto com o sistema...

 

Depois de tratarmos das infecções em seu MICRO, cuidaremos disso, ok?

 

:)

Compartilhar este post


Link para o post
Compartilhar em outros sites

OLa Sr. Perfect, tem como você ajeitar os procedimentos que você mandou para mim pois todo o Texto está como LINK, não dar para fazer nenhum procedimento.. :thumbsup:

 

 

Fico esperando.. <_<

Compartilhar este post


Link para o post
Compartilhar em outros sites
OLa Sr. Perfect, tem como você ajeitar os procedimentos que você mandou para mim pois todo o Texto está como LINK, não dar para fazer nenhum procedimento.. :thumbsup:

 

 

Fico esperando.. <_<

 

Pronto Edvan o poste ja foi corrigido, não tinha feito isso por que não estava consiguindo editar os meus tópicos;

 

:thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

fiz os procedimentos conforme sugerido... :thumbsup: :thumbsup:

 

Antes de colocar os logs me diz uma coisa que danado de virus é esse que nao sai? :blink:

 

 

ComboFix 08-08-01.05 - Edvan 2008-08-04 0:20:53.8 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.196 [GMT -3:00]

Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt

* Criado um novo ponto de restauro

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

 

FILE ::

C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-07-04 to 2008-08-04 ))))))))))))))))))))))))))))))))

.

 

2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet

2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead

2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll

2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll

2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll

2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll

2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe

2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll

2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-04 03:02 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2

2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK

2008-08-01 00:51 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-07-30 21:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-11 00:33 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

2008-06-07 16:11 --------- d-----w C:\Arquivos de programas\MSN Messenger

2008-06-07 16:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-06-06 03:23 --------- d-----w C:\Arquivos de programas\Trend Micro

2008-06-04 12:09 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2008-05-07 05:15 1,292,288 -c--a-w C:\WINDOWS\system32\quartz.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

\Shell\AutoRun\command - D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

\Shell\AutoRun\command - E:\ino6.com

\Shell\explore\Command - E:\ino6.com

\Shell\open\Command - E:\ino6.com

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-04 00:23:21

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-08-04 0:27:18

ComboFix-quarantined-files.txt 2008-08-04 03:26:10

 

Pre-Run: 7 pasta(s) 15,584,108,544 bytes disponíveis

Post-Run: 12 pasta(s) 15,576,182,784 bytes disponíveis

 

106 --- E O F --- 2008-07-27 14:11:22

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:27:57, on 4/8/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\explorer.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4020 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites
Antes de colocar os logs me diz uma coisa que danado de virus é esse que nao sai?

 

Calma temos apenas agora um virus de pendrive.

 

Se tiver um Pendrive ou um drive de MP3 ou MP4, conecte no PC (se tiver mais de um, tem de conectar todos). Não os tire até completar todas as instruções.

 

Delete a pasta qoobox que está localizada em C:\, delete também o Log ComboFix.txt também localizado em C:\.

 

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

E:\ino6.com

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a520388a-61ae-11d6-a4e4-000795308f87}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f51ba30-196d-11dd-b047-806d6172696f}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20b55103-2b7d-11dd-9ddb-000ee8eb8ec4}]

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

645i642ef2.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

OLa Sr. Perfect, beleza cara?

 

Rapaz desculpe a demora em postar, minha NET esta pessima cara, estava respondendo alguns topicos lá em Hadoware com maior luta e download sem pensar nao dar para fazer download com a NET desse jeito..

 

Mais vamos lá aos procedimentos:

 

ComboFix 08-08-11.01 - Edvan 2008-08-12 12:32:16.9 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.133 [GMT -3:00]Executando de: C:\Documents and Settings\Edvan\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Edvan\Desktop\CFScript.txt..txt

* Criado um novo ponto de restauro

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

 

FILE ::

D:\CDSAMPLE\AUTORUN\AUTORUN.EXE

E:\ino6.com

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-07-12 to 2008-08-12 ))))))))))))))))))))))))))))))))

.

 

2008-08-06 17:10 . 2008-08-10 22:43 69 --a------ C:\WINDOWS\NeroDigital.ini

2008-08-06 17:08 . 2004-08-04 00:45 91,136 --a------ C:\WINDOWS\system32\kswdmcap.ax

2008-08-06 17:08 . 2004-08-04 00:45 91,136 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax

2008-08-06 17:08 . 2004-08-04 00:45 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax

2008-08-06 17:08 . 2004-08-04 00:45 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax

2008-08-06 17:08 . 2004-08-04 00:45 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll

2008-08-06 17:08 . 2004-08-04 00:45 54,784 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll

2008-08-06 17:08 . 2005-01-14 09:32 53,248 --a------ C:\WINDOWS\system32\PAStiSvc.exe

2008-08-06 17:08 . 2004-08-04 00:45 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax

2008-08-06 17:08 . 2004-08-04 00:45 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax

2008-08-06 17:08 . 2004-08-04 00:45 28,672 --a------ C:\WINDOWS\system32\vidcap.ax

2008-08-06 17:08 . 2004-08-04 00:45 28,672 --a--c--- C:\WINDOWS\system32\dllcache\vidcap.ax

2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\WINDOWS\PixArt

2008-08-06 17:07 . 2008-08-10 11:20 <DIR> d-------- C:\WINDOWS\Album

2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\Arquivos de programas\VideoCAM GF112

2008-08-06 17:07 . 2008-08-06 17:07 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\PCCamera

2008-08-06 17:05 . 2008-08-06 17:05 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2008-08-06 14:21 . 2004-11-29 16:51 122,928 --a------ C:\WINDOWS\system32\drivers\spca561.bak.sys

2008-08-06 11:38 . 2008-08-06 11:38 <DIR> d--hs---- C:\WINDOWS\ftpcache

2008-08-06 11:27 . 2008-08-06 16:39 <DIR> d-------- C:\Arquivos de programas\PhoTags Express

2008-08-06 11:22 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2008-08-06 11:22 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys

2008-08-03 00:53 . 2008-08-03 00:53 <DIR> d-------- C:\WINDOWS\peernet

2008-07-31 18:02 . 2008-07-31 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Ahead

2008-07-31 17:59 . 2008-07-31 17:59 <DIR> d-------- C:\Arquivos de programas\Ahead

2008-07-31 17:59 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll

2008-07-31 17:59 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll

2008-07-31 17:59 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll

2008-07-31 17:59 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll

2008-07-31 17:59 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe

2008-07-31 17:59 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll

2008-07-29 02:06 . 2008-07-29 02:06 396,288 --a------ C:\HijackThis.exe

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\NetworkService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-28 23:38 <DIR> d-------- C:\Documents and Settings\LocalService\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Edvan\Configuraþ§es locais

2008-07-28 23:38 . 2008-07-30 23:15 <DIR> d-------- C:\Documents and Settings\Administrador\Configuraþ§es locais

2008-07-27 23:09 . 2008-07-27 23:09 <DIR> d-------- C:\Arquivos de programas\RealVNC

2008-07-27 22:38 . 2008-07-27 22:38 <DIR> d-------- C:\Documents and Settings\Edvan\Dados de aplicativos\Symantec

2008-07-27 22:38 . 1999-06-10 14:50 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Symantec

2008-07-27 22:37 . 2008-07-28 01:08 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-09 01:57 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Hamachi

2008-08-09 01:10 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys

2008-08-06 20:08 --------- d--h--w C:\Arquivos de programas\InstallShield Installation Information

2008-08-06 20:05 --------- d-----w C:\Arquivos de programas\Arquivos comuns\InstallShield

2008-08-04 03:02 --------- d-----w C:\Arquivos de programas\Windows Media Connect 2

2008-08-02 18:56 --------- d-----w C:\Arquivos de programas\RALINK

2008-07-01 01:21 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\InstallShield

2008-06-30 13:01 21,419 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys

2008-06-29 15:19 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Orbit

2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-19 02:43 --------- d-----w C:\Documents and Settings\Edvan\Dados de aplicativos\Watchtower

2008-06-19 00:36 --------- d-----w C:\Arquivos de programas\Watchtower

2008-06-14 17:59 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-14 01:56 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Adobe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Adobe Reader Speed Launcher"="C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:45 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 11:35]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 11:37]

R3 TNET1130;IEEE 802.11g Wireless Cardbus/PCI Adapter;C:\WINDOWS\system32\DRIVERS\tnet1130.sys [2004-06-17 23:41]

S3 PAC207;VideoCAM GF112;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 10:46]

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-12 12:35:06

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

**************************************************************************

.

Tempo para conclusão: 2008-08-12 12:39:03

ComboFix-quarantined-files.txt 2008-08-12 15:37:57

 

Pre-Run: 7 pasta(s) 14,959,489,024 bytes disponíveis

Post-Run: 12 pasta(s) 14,962,225,152 bytes disponíveis

 

115 --- E O F --- 2008-07-27 14:11:22

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:40:26, on 12/8/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\explorer.exe

C:\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Translate - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra 'Tools' menuitem: LingoWare Translator... - {87680762-4A83-11B4-885B-0000E8ECA40F} - C:\Arquivos de programas\LingoCom\Translator.lnk

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

 

--

End of file - 4136 bytes

 

 

Fico no aguardo.. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.