Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

GBruno

[Resolvido!] Notebook infectado e muito lento

Recommended Posts

Bom, estou com o PC extremamente lento e verifiquei que existem alguns processos estranhos rodando, como o IEXPLORE.EXE rodando mesmo que o Internet Explorer não esteja realmente aberto.

Passei o AVG e o mesmo não aponta nada de errado, mas essa situação não é a normal.

Então, segue abaixo o log do Hijackthis. Por favor, espero contar com a ajuda de vocês.

 

Logfile of HijackThis v1.99.1

Scan saved at 16:04:59, on 29/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\system32\wbem\unsecapp.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE

C:\WINDOWS\msagent\AgentSvr.exe

C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

O4 - HKLM\..\Run: [boot] C:\Acer\Empowering Technology\ePower\Boot.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! GBruno

 

<@> Faça o download do LopS&D.

<@> Salve-o no Disco Local-C!.

<@> Instale o programa e clique em: LopSD.cmd

<@> Na janela que abrir,aperte o "p" >> Aperte Enter.

<@> Em outra janela,aperte a opção 2 >> Aperte Enter >> Aguarde!

<@> Terminando,salve e poste o relatório. ( C:\lopR.txt )

<@> Poste,também,HJT atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam

 

Obrigado pela ajuda, estava realmente sem saber o que fazer. Bom, seguem abaixo os relatorios do LopS&D e do HijackThis.

 

Abraços

 

 

--------------------\\ Lop S&D 4.2.2-4 XP/Vista

 

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]

[ USER : Nataly Lopes ] [ "C:\Lop SD" ] [ Selection : 2 ]

[ qua 30/07/2008 | 14:42:44,23 ] [ PC : NATALY ]

[ MAJ : 25-07-2008 | 17:45 ]

 

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS ////////////////////////////////

 

Deletado! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\ford more.exe

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@adultfriendfinder[1].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[2].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[3].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[4].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[1].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[5].txt

Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@www.lop[1].txt

Deletado! - C:\DOCUME~1\NATALY~1\LOCALS~1\Temp\bisB8.exe

Deletado! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag

Arquivos/Ficheiros Hosts RESTAURADO

 

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

--------------------\\ Lista de pastas em APPLIC~1

 

[01/06/2006|16:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI

[01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini

[01/06/2006|16:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities

[01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

 

[17/05/2008|20:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe

[08/02/2007|13:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead

[15/07/2008|23:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

[23/06/2007|00:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer

[13/07/2008|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg8

[04/01/2007|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink

[01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp

[31/03/2008|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GbPlugin

[02/03/2007|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google

[19/02/2007|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield

[01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft

[10/02/2007|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy

[05/03/2008|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PKP_DLec.DAT

[19/07/2007|23:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache

[02/03/2007|17:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype

[05/03/2007|00:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15

[30/03/2007|23:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[02/03/2007|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar

[12/06/2007|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller

[10/07/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

[12/06/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

 

[01/06/2006|16:16] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

 

[01/06/2006|16:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

 

[04/01/2007|21:57] C:\DOCUME~1\NATALY~1\APPLIC~1\Adobe

[05/01/2007|18:23] C:\DOCUME~1\NATALY~1\APPLIC~1\AdobeUM

[23/06/2007|01:12] C:\DOCUME~1\NATALY~1\APPLIC~1\Apple Computer

[16/01/2007|20:07] C:\DOCUME~1\NATALY~1\APPLIC~1\ArcSoft

[01/06/2006|16:41] C:\DOCUME~1\NATALY~1\APPLIC~1\ATI

[13/07/2008|15:36] C:\DOCUME~1\NATALY~1\APPLIC~1\AVGTOOLBAR

[09/05/2007|13:12] C:\DOCUME~1\NATALY~1\APPLIC~1\BitTorrent

[13/07/2008|13:05] C:\DOCUME~1\NATALY~1\APPLIC~1\Bolt error second

[26/05/2008|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\CmapTools

[19/02/2007|21:42] C:\DOCUME~1\NATALY~1\APPLIC~1\Corel

[04/01/2007|16:37] C:\DOCUME~1\NATALY~1\APPLIC~1\CyberLink

[01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\desktop.ini

[11/07/2007|13:04] C:\DOCUME~1\NATALY~1\APPLIC~1\fretsonfire

[01/04/2008|18:01] C:\DOCUME~1\NATALY~1\APPLIC~1\G-Force Prefs (WindowsMediaPlayer).txt

[02/03/2007|18:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Google

[01/06/2006|16:31] C:\DOCUME~1\NATALY~1\APPLIC~1\Identities

[05/01/2007|05:19] C:\DOCUME~1\NATALY~1\APPLIC~1\Macromedia

[03/03/2007|01:28] C:\DOCUME~1\NATALY~1\APPLIC~1\Media Player Classic

[01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Microsoft

[26/05/2008|14:07] C:\DOCUME~1\NATALY~1\APPLIC~1\Mozilla

[02/03/2007|17:20] C:\DOCUME~1\NATALY~1\APPLIC~1\MSNInstaller

[16/01/2007|19:41] C:\DOCUME~1\NATALY~1\APPLIC~1\Nikon

[07/01/2007|13:34] C:\DOCUME~1\NATALY~1\APPLIC~1\Nokia

[05/03/2008|10:47] C:\DOCUME~1\NATALY~1\APPLIC~1\Otto

[26/05/2008|14:05] C:\DOCUME~1\NATALY~1\APPLIC~1\SecondLife

[02/03/2007|17:49] C:\DOCUME~1\NATALY~1\APPLIC~1\Skype

[18/06/2008|22:23] C:\DOCUME~1\NATALY~1\APPLIC~1\SSH

[08/04/2007|02:56] C:\DOCUME~1\NATALY~1\APPLIC~1\Sun

[12/05/2007|02:47] C:\DOCUME~1\NATALY~1\APPLIC~1\U3

[12/07/2008|16:18] C:\DOCUME~1\NATALY~1\APPLIC~1\uTorrent

[13/07/2008|10:30] C:\DOCUME~1\NATALY~1\APPLIC~1\WinRAR

 

--------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks

 

[28/07/2008 11:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[30/07/2008 13:46][--ah-----] C:\WINDOWS\tasks\SA.DAT

[10/08/2004 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

 

--------------------\\ Lista de pastas em C:\Program Files

 

[01/06/2006|16:47] C:\Program Files\Acer Inc

[12/07/2007|19:47] C:\Program Files\Acro Software

[01/06/2006|16:48] C:\Program Files\Adobe

[14/03/2007|22:27] C:\Program Files\Ahead

[23/06/2007|00:57] C:\Program Files\Apple Software Update

[01/06/2006|16:32] C:\Program Files\ATI Technologies

[17/06/2008|12:51] C:\Program Files\AVG

[09/05/2007|13:12] C:\Program Files\BitTorrent

[23/07/2008|14:14] C:\Program Files\Bolt error second

[01/06/2006|16:16] C:\Program Files\Common Files

[01/06/2006|16:21] C:\Program Files\ComPlus Applications

[01/06/2006|16:45] C:\Program Files\CONEXANT

[19/02/2007|21:29] C:\Program Files\Corel

[01/06/2006|16:50] C:\Program Files\CyberLink

[01/06/2006|17:29] C:\Program Files\DIFX

[20/12/2007|20:42] C:\Program Files\Discador itelefonica

[31/03/2008|13:29] C:\Program Files\GbPlugin

[01/06/2006|17:43] C:\Program Files\GemMaster

[12/03/2007|00:22] C:\Program Files\GizmoPlugin

[02/03/2007|17:48] C:\Program Files\Google

[12/07/2007|19:51] C:\Program Files\GPLGS

[26/05/2008|16:14] C:\Program Files\IHMC CmapTools

[01/06/2006|16:32] C:\Program Files\InstallShield Installation Information

[01/06/2006|16:23] C:\Program Files\Internet Explorer

[07/04/2007|22:27] C:\Program Files\Java

[05/01/2007|05:35] C:\Program Files\Launch Manager

[18/04/2007|19:35] C:\Program Files\LimeWire

[01/06/2006|16:21] C:\Program Files\Messenger

[12/05/2007|03:06] C:\Program Files\Microsoft CAPICOM 2.1.0.2

[01/06/2006|16:26] C:\Program Files\microsoft frontpage

[24/06/2008|16:13] C:\Program Files\Microsoft Office

[31/03/2008|10:12] C:\Program Files\Microsoft SQL Server Compact Edition

[08/01/2007|23:23] C:\Program Files\Microsoft Visual Studio

[24/06/2008|16:14] C:\Program Files\Microsoft Works

[24/06/2008|16:13] C:\Program Files\Microsoft.NET

[01/06/2006|16:21] C:\Program Files\Movie Maker

[29/07/2008|09:37] C:\Program Files\Mozilla Firefox

[01/06/2006|16:20] C:\Program Files\MSN

[01/06/2006|16:21] C:\Program Files\MSN Gaming Zone

[01/06/2006|16:23] C:\Program Files\NetMeeting

[01/06/2006|16:55] C:\Program Files\NewTech Infosystems

[16/03/2007|00:51] C:\Program Files\OnGame

[01/06/2006|16:21] C:\Program Files\Online Services

[01/06/2006|16:23] C:\Program Files\Outlook Express

[12/07/2007|21:48] C:\Program Files\Plus!

[19/01/2007|23:09] C:\Program Files\Positivo

[21/07/2008|11:53] C:\Program Files\QuickTime

[01/06/2006|16:41] C:\Program Files\Realtek

[03/03/2007|01:28] C:\Program Files\Recode Media

[21/07/2008|12:11] C:\Program Files\Safari

[02/03/2007|17:47] C:\Program Files\Skype

[18/06/2008|22:22] C:\Program Files\SSH Communications Security

[05/01/2007|05:34] C:\Program Files\Synaptics

[20/12/2007|20:54] C:\Program Files\Terra Discador - VersÆo Compacta

[01/06/2006|16:31] C:\Program Files\Uninstall Information

[12/07/2008|16:18] C:\Program Files\uTorrent

[12/06/2007|10:58] C:\Program Files\Windows Live

[02/03/2007|17:16] C:\Program Files\Windows Live Toolbar

[07/05/2007|21:54] C:\Program Files\Windows Media Connect 2

[01/06/2006|16:21] C:\Program Files\Windows Media Player

[01/06/2006|16:20] C:\Program Files\Windows NT

[01/06/2006|16:21] C:\Program Files\Windows Plus

[01/06/2006|16:23] C:\Program Files\WindowsUpdate

[13/07/2008|10:06] C:\Program Files\WinRAR

[24/02/2008|16:10] C:\Program Files\wt3d.ini

[01/06/2006|16:26] C:\Program Files\xerox

[26/05/2008|16:14] C:\Program Files\Zero G Registry

 

--------------------\\ Lista de pastas em C:\Program Files\Common Files

 

[17/05/2008|20:58] C:\Program Files\Common Files\Adobe

[08/02/2007|13:57] C:\Program Files\Common Files\Ahead

[01/06/2006|16:36] C:\Program Files\Common Files\ATI Technologies

[19/02/2007|21:29] C:\Program Files\Common Files\Corel

[08/01/2007|23:24] C:\Program Files\Common Files\DESIGNER

[01/06/2006|16:32] C:\Program Files\Common Files\InstallShield

[07/04/2007|22:27] C:\Program Files\Common Files\Java

[01/06/2006|16:56] C:\Program Files\Common Files\LightScribe

[01/06/2006|16:16] C:\Program Files\Common Files\Microsoft Shared

[01/06/2006|16:23] C:\Program Files\Common Files\MSSoap

[01/06/2006|16:56] C:\Program Files\Common Files\muvee Technologies

[08/02/2007|13:59] C:\Program Files\Common Files\Nero

[16/01/2007|19:37] C:\Program Files\Common Files\Nikon

[01/06/2006|16:16] C:\Program Files\Common Files\ODBC

[01/06/2006|16:23] C:\Program Files\Common Files\Services

[01/06/2006|16:16] C:\Program Files\Common Files\SpeechEngines

[05/03/2007|00:09] C:\Program Files\Common Files\Symantec Shared

[01/06/2006|16:23] C:\Program Files\Common Files\System

[31/03/2008|09:52] C:\Program Files\Common Files\WindowsLiveInstaller

 

--------------------\\ Process

 

( 42 Processus )

 

... OK !

 

--------------------\\ Procura pelo S_Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura no Registro

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

 

..... OK !

 

--------------------\\ Verificando o Arquivos/Ficheiros Hosts

 

Arquivos/Ficheiros Hosts LIMPO

 

 

--------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-30 14:44:54

Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden files ...

scan completed successfully

hidden processes: 0

hidden files: 0

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

[F:2725][D:29]-> C:\DOCUME~1\NATALY~1\LOCALS~1\Temp

[F:876][D:0]-> C:\DOCUME~1\NATALY~1\Cookies

[F:18415][D:37]-> C:\DOCUME~1\NATALY~1\LOCALS~1\TEMPOR~1\content.IE5

[F:3][D:0]-> C:\Recycled

 

--------------------\\ Verificação completa em 14:46:00,09

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 14:50:32, on 30/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\ehome\mcrdsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wbem\unsecapp.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Documents and Settings\Nataly Lopes\Local Settings\Temp\jkos-Nataly Lopes\binaries\ScanningProcess.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\DOCUME~1\NATALY~1\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

O4 - HKLM\..\Run: [boot] C:\Acer\Empowering Technology\ePower\Boot.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! GBruno

 

<@> Faça o download do ComboFix.

<@> Baixe-o para o Desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e Firewall.( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

 

Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

Salve-a no Desktop,renomeada como: Kombo.exe

Ps: Nomeie durante o salvamento,e não após salvá-la!

Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança.

<@> Abrirá a janela Auto Scan. Aguarde!

<@> Digite a opção para continuar e < Enter >

<@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado!

<@> Para parar ou sair do ComboFix,tecle "N".

-------------------------

<@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam!

 

Depois de muitos resets e tendo que inicializar o computador no Modo de Segurança, consegui rodar o ComboFix.

Segue abaixo os logs gerados pelo ComboFix e pelo HJT.

 

Muito obrigado pela ajuda!

 

Abraço!

 

ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 18:39:06.3 - FAT32x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.262 [GMT -3:00]

Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\temp\perflib_perfdata_1cc.dat

 

.

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 )))))))))))))))))))))))))))))))

.

 

2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004

2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix

2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD

2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe

2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003

2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf

2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups

2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk

2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second

2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari

2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime

2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple

2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR

2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old

2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4

2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe

2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second

2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe

2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe

2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8

2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3

2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent

2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH

2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security

2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG

2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll

2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll

2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll

2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini

2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT

2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]

"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]

"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952]

"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk

backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk]

path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk

backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]

--a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

--a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]

--a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

--------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]

--a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]

--a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]

--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]

--a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]

--a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

-ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

"C:\\Program Files\\LimeWire\\LimeWire.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\WINDOWS\\System32\\rtcshare.exe"=

"C:\\Program Files\\uTorrent\\uTorrent.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"12906:TCP"= 12906:TCP:NortonAV

"12246:TCP"= 12246:TCP:NortonAV

"13054:TCP"= 13054:TCP:NortonAV

"13615:TCP"= 13615:TCP:NortonAV

"16921:TCP"= 16921:TCP:NortonAV

"16448:TCP"= 16448:TCP:NortonAV

"18072:TCP"= 18072:TCP:NortonAV

"14289:TCP"= 14289:TCP:NortonAV

"18236:TCP"= 18236:TCP:NortonAV

"17716:TCP"= 17716:TCP:NortonAV

"16499:TCP"= 16499:TCP:NortonAV

"13614:TCP"= 13614:TCP:NortonAV

"15771:TCP"= 15771:TCP:NortonAV

"12826:TCP"= 12826:TCP:NortonAV

"17920:TCP"= 17920:TCP:NortonAV

"18169:TCP"= 18169:TCP:NortonAV

"12225:TCP"= 12225:TCP:NortonAV

"15538:TCP"= 15538:TCP:NortonAV

"17800:TCP"= 17800:TCP:NortonAV

"15248:TCP"= 15248:TCP:NortonAV

"13460:TCP"= 13460:TCP:NortonAV

"14692:TCP"= 14692:TCP:NortonAV

"12992:TCP"= 12992:TCP:NortonAV

"13451:TCP"= 13451:TCP:NortonAV

"15587:TCP"= 15587:TCP:NortonAV

"14010:TCP"= 14010:TCP:NortonAV

"18590:TCP"= 18590:TCP:NortonAV

"14344:TCP"= 14344:TCP:NortonAV

"14495:TCP"= 14495:TCP:NortonAV

"13352:TCP"= 13352:TCP:NortonAV

"15965:TCP"= 15965:TCP:NortonAV

"17150:TCP"= 17150:TCP:NortonAV

"18255:TCP"= 18255:TCP:NortonAV

"16963:TCP"= 16963:TCP:NortonAV

"14939:TCP"= 14939:TCP:NortonAV

"16279:TCP"= 16279:TCP:NortonAV

"13122:TCP"= 13122:TCP:NortonAV

"13437:TCP"= 13437:TCP:NortonAV

"13954:TCP"= 13954:TCP:NortonAV

"14221:TCP"= 14221:TCP:NortonAV

"16577:TCP"= 16577:TCP:NortonAV

"14580:TCP"= 14580:TCP:NortonAV

"14908:TCP"= 14908:TCP:NortonAV

"16930:TCP"= 16930:TCP:NortonAV

"14196:TCP"= 14196:TCP:NortonAV

"17932:TCP"= 17932:TCP:NortonAV

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39]

S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []

S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

\Shell\Auto\command - F:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\Auto\command - G:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]

\Shell\Auto\command - H:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

.

Contents of the 'Scheduled Tasks' folder

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

.

- - - - ORPHANS REMOVED - - - -

 

HKLM-Explorer_Run-winlogon - C:\heap41a\svchost.exe

MSConfigStartUp-Base frag grid bows - C:\Documents and Settings\All Users\Application Data\Cast ping base frag\ford more.exe

MSConfigStartUp-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe

MSConfigStartUp-RavAV - C:\WINDOWS\AdobeR.exe

MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

 

 

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

 

O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

C:\WINDOWS\Downloaded Program Files\gbpdist.inf

C:\WINDOWS\Downloaded Program Files\gbpdist.dll

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-30 18:52:29

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\ehome\mcrdsvc.exe

C:\WINDOWS\system32\fxssvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

.

**************************************************************************

.

Completion time: 2008-07-30 19:00:51 - machine was rebooted [Nataly Lopes]

ComboFix-quarantined-files.txt 2008-07-30 21:59:22

 

Pre-Run: 7,786,315,776 bytes free

Post-Run: 9,309,306,880 bytes free

 

277 --- E O F --- 2008-07-30 00:42:35

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 19:04:48, on 30/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\fxssvc.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! GBruno

 

<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.

<@> Salve-o,no Desktop,com o nome: CFScript.txt

 

File::

C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

F:\AdobeR.exe

G:\AdobeR.exe

H:\AdobeR.exe

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nurbsize"=-

Folder::

C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second

C:\FOUND.004

C:\FOUND.003

<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.

<@> Veja a demonstração!

 

35j0br8.gif

 

<@> Reinicie o computador!

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam!

 

Fiz o que foi pedido e o PC ficou resetando algumas vezes até conseguir rodar o ComboFix (somente no Modo de Segurança). Segue abaixo os logs do Combofix e HijackThis. Muito obrigado pela ajuda!

 

Abraços.

 

 

 

ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 21:28:31.5 - FAT32x86 MINIMAL

Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

F:\ntdelect.com

 

.

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))

.

 

2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004

2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix

2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD

2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe

2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003

2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf

2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups

2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk

2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second

2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari

2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime

2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple

2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR

2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old

2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4

2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe

2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second

2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe

2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe

2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8

2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3

2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent

2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH

2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security

2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG

2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll

2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll

2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll

2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini

2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT

2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]

"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]

"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952]

"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk

backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk]

path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk

backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]

--a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

--a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]

--a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

--------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]

--a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]

--a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]

--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]

--a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]

--a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

-ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

"C:\\Program Files\\LimeWire\\LimeWire.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\WINDOWS\\System32\\rtcshare.exe"=

"C:\\Program Files\\uTorrent\\uTorrent.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"12906:TCP"= 12906:TCP:NortonAV

"12246:TCP"= 12246:TCP:NortonAV

"13054:TCP"= 13054:TCP:NortonAV

"13615:TCP"= 13615:TCP:NortonAV

"16921:TCP"= 16921:TCP:NortonAV

"16448:TCP"= 16448:TCP:NortonAV

"18072:TCP"= 18072:TCP:NortonAV

"14289:TCP"= 14289:TCP:NortonAV

"18236:TCP"= 18236:TCP:NortonAV

"17716:TCP"= 17716:TCP:NortonAV

"16499:TCP"= 16499:TCP:NortonAV

"13614:TCP"= 13614:TCP:NortonAV

"15771:TCP"= 15771:TCP:NortonAV

"12826:TCP"= 12826:TCP:NortonAV

"17920:TCP"= 17920:TCP:NortonAV

"18169:TCP"= 18169:TCP:NortonAV

"12225:TCP"= 12225:TCP:NortonAV

"15538:TCP"= 15538:TCP:NortonAV

"17800:TCP"= 17800:TCP:NortonAV

"15248:TCP"= 15248:TCP:NortonAV

"13460:TCP"= 13460:TCP:NortonAV

"14692:TCP"= 14692:TCP:NortonAV

"12992:TCP"= 12992:TCP:NortonAV

"13451:TCP"= 13451:TCP:NortonAV

"15587:TCP"= 15587:TCP:NortonAV

"14010:TCP"= 14010:TCP:NortonAV

"18590:TCP"= 18590:TCP:NortonAV

"14344:TCP"= 14344:TCP:NortonAV

"14495:TCP"= 14495:TCP:NortonAV

"13352:TCP"= 13352:TCP:NortonAV

"15965:TCP"= 15965:TCP:NortonAV

"17150:TCP"= 17150:TCP:NortonAV

"18255:TCP"= 18255:TCP:NortonAV

"16963:TCP"= 16963:TCP:NortonAV

"14939:TCP"= 14939:TCP:NortonAV

"16279:TCP"= 16279:TCP:NortonAV

"13122:TCP"= 13122:TCP:NortonAV

"13437:TCP"= 13437:TCP:NortonAV

"13954:TCP"= 13954:TCP:NortonAV

"14221:TCP"= 14221:TCP:NortonAV

"16577:TCP"= 16577:TCP:NortonAV

"14580:TCP"= 14580:TCP:NortonAV

"14908:TCP"= 14908:TCP:NortonAV

"16930:TCP"= 16930:TCP:NortonAV

"14196:TCP"= 14196:TCP:NortonAV

"17932:TCP"= 17932:TCP:NortonAV

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39]

S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []

S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

\Shell\Auto\command - F:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\Auto\command - G:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]

\Shell\Auto\command - H:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

.

Contents of the 'Scheduled Tasks' folder

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

.

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

 

O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

C:\WINDOWS\Downloaded Program Files\gbpdist.inf

C:\WINDOWS\Downloaded Program Files\gbpdist.dll

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-30 21:42:07

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\WINDOWS\ehome\mcrdsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Internet Explorer\iexplore.exe

.

**************************************************************************

.

Completion time: 2008-07-30 21:51:40 - machine was rebooted [Nataly Lopes]

ComboFix-quarantined-files.txt 2008-07-31 00:50:56

ComboFix2.txt 2008-07-30 22:00:58

 

Pre-Run: 9,734,651,904 bytes free

Post-Run: 9,246,261,248 bytes free

 

269 --- E O F --- 2008-07-30 00:42:35

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 21:13, on 2008-07-30

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! GBruno

 

<!> O relatório postado,não é o ComboFix.txt após o script.

<!> Caso não o possua,recomendo a desinstalação do ComboFix.exe,e o download de uma nova ferramenta.

-------------------------

<@> No Executar,digite: ComboFix.exe /u --> Clique: OK

<@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação!

-------------------------

<@> Faça o download do ComboFix.exe e arraste o CFScript.txt,para o seu ícone.

<@> Poste: ComboFix.txt + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam,

 

Parece que o relatório postado anteriormente não era mesmo o ComboFix.txt, mas ao abrir esse arquivo em C: percebi que se trata da mesma coisa, aparentemente. Segue o arquivo C:/ComboFix.txt

Bom, to meio sem saber o que fazer, uma ajudinha é bem vinda =).

Muito Obrigado

 

Abraços

 

ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 21:28:31.5 - FAT32x86 MINIMAL

Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

F:\ntdelect.com

 

.

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))

.

 

2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004

2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix

2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD

2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe

2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003

2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf

2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups

2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk

2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second

2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari

2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime

2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple

2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR

2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old

2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4

2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe

2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second

2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe

2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe

2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8

2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3

2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent

2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET

2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH

2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security

2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG

2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys

2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys

2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll

2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll

2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll

2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini

2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT

2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]

"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]

"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952]

"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk

backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk]

path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk

backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]

--a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

--a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]

--a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

--------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]

--a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]

--a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]

--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]

--a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]

--a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

-ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

"C:\\Program Files\\LimeWire\\LimeWire.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\WINDOWS\\System32\\rtcshare.exe"=

"C:\\Program Files\\uTorrent\\uTorrent.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"12906:TCP"= 12906:TCP:NortonAV

"12246:TCP"= 12246:TCP:NortonAV

"13054:TCP"= 13054:TCP:NortonAV

"13615:TCP"= 13615:TCP:NortonAV

"16921:TCP"= 16921:TCP:NortonAV

"16448:TCP"= 16448:TCP:NortonAV

"18072:TCP"= 18072:TCP:NortonAV

"14289:TCP"= 14289:TCP:NortonAV

"18236:TCP"= 18236:TCP:NortonAV

"17716:TCP"= 17716:TCP:NortonAV

"16499:TCP"= 16499:TCP:NortonAV

"13614:TCP"= 13614:TCP:NortonAV

"15771:TCP"= 15771:TCP:NortonAV

"12826:TCP"= 12826:TCP:NortonAV

"17920:TCP"= 17920:TCP:NortonAV

"18169:TCP"= 18169:TCP:NortonAV

"12225:TCP"= 12225:TCP:NortonAV

"15538:TCP"= 15538:TCP:NortonAV

"17800:TCP"= 17800:TCP:NortonAV

"15248:TCP"= 15248:TCP:NortonAV

"13460:TCP"= 13460:TCP:NortonAV

"14692:TCP"= 14692:TCP:NortonAV

"12992:TCP"= 12992:TCP:NortonAV

"13451:TCP"= 13451:TCP:NortonAV

"15587:TCP"= 15587:TCP:NortonAV

"14010:TCP"= 14010:TCP:NortonAV

"18590:TCP"= 18590:TCP:NortonAV

"14344:TCP"= 14344:TCP:NortonAV

"14495:TCP"= 14495:TCP:NortonAV

"13352:TCP"= 13352:TCP:NortonAV

"15965:TCP"= 15965:TCP:NortonAV

"17150:TCP"= 17150:TCP:NortonAV

"18255:TCP"= 18255:TCP:NortonAV

"16963:TCP"= 16963:TCP:NortonAV

"14939:TCP"= 14939:TCP:NortonAV

"16279:TCP"= 16279:TCP:NortonAV

"13122:TCP"= 13122:TCP:NortonAV

"13437:TCP"= 13437:TCP:NortonAV

"13954:TCP"= 13954:TCP:NortonAV

"14221:TCP"= 14221:TCP:NortonAV

"16577:TCP"= 16577:TCP:NortonAV

"14580:TCP"= 14580:TCP:NortonAV

"14908:TCP"= 14908:TCP:NortonAV

"16930:TCP"= 16930:TCP:NortonAV

"14196:TCP"= 14196:TCP:NortonAV

"17932:TCP"= 17932:TCP:NortonAV

 

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39]

R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39]

S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []

S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

\Shell\Auto\command - F:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

\Shell\Auto\command - G:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]

\Shell\Auto\command - H:\AdobeR.exe e

\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

.

Contents of the 'Scheduled Tasks' folder

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

.

.

------- Supplementary Scan -------

.

R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

 

O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

C:\WINDOWS\Downloaded Program Files\gbpdist.inf

C:\WINDOWS\Downloaded Program Files\gbpdist.dll

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-30 21:42:07

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\PROGRA~1\GbPlugin\GbpSv.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Program Files\AVG\AVG8\avgrsx.exe

C:\WINDOWS\ehome\mcrdsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Internet Explorer\iexplore.exe

.

**************************************************************************

.

Completion time: 2008-07-30 21:51:40 - machine was rebooted [Nataly Lopes]

ComboFix-quarantined-files.txt 2008-07-31 00:50:56

ComboFix2.txt 2008-07-30 22:00:58

 

Pre-Run: 9,734,651,904 bytes free

Post-Run: 9,246,261,248 bytes free

 

269 --- E O F --- 2008-07-30 00:42:35

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! GBruno

 

<@> Execute,novamente,o Lop S&D e poste o relatório. ( C:\LopR.txt )

------------------------

>@< Faça o download do PenClean.

 

<!> Link alternativo: < PenClean >

 

>@< Salve-o no Desktop!

>@< Insira suas unidades removíveis,na entrada USB. ( pendrive,mp3,mp4,etc... )

>@< Rode o utilitário,em Modo de Segurança,e selecione a opção: Verificar o computador

>@< Clique no botão Verificar.Aguarde!

>@< Caso haja necessidade,atenda a solicitação para reiniciar o computador.

>@< Clique em Sim!

>@< Ps: Não remova,ainda,essas unidades!

>@< Poste,o relatório do PenClean: C:\PenClean\PenClean.txt + LopR.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite, DigRam!

 

Mais uma vez obrigado pela ajuda. Rodei novamente o LopS&D e também o PenClean. Segue abaixo os relatórios.

 

Abraços.

 

 

--------------------\\ Lop S&D 4.2.2-4 XP/Vista

 

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]

[ USER : Nataly Lopes ] [ "C:\Lop SD" ] [ Selection : 2 ]

[ qui 31/07/2008 | 20:18:44,85 ] [ PC : NATALY ]

[ MAJ : 25-07-2008 | 17:45 ]

 

 

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

--------------------\\ Lista de pastas em APPLIC~1

 

[01/06/2006|16:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI

[01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini

[01/06/2006|16:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities

[01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

 

[17/05/2008|20:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe

[08/02/2007|13:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead

[15/07/2008|23:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

[23/06/2007|00:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer

[13/07/2008|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg8

[04/01/2007|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink

[01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp

[31/03/2008|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GbPlugin

[02/03/2007|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google

[19/02/2007|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield

[01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft

[10/02/2007|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy

[05/03/2008|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PKP_DLec.DAT

[19/07/2007|23:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache

[02/03/2007|17:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype

[05/03/2007|00:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec

[16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15

[30/03/2007|23:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[02/03/2007|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar

[12/06/2007|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller

[10/07/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

[12/06/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

 

[01/06/2006|16:16] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

 

[01/06/2006|16:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

 

[04/01/2007|21:57] C:\DOCUME~1\NATALY~1\APPLIC~1\Adobe

[05/01/2007|18:23] C:\DOCUME~1\NATALY~1\APPLIC~1\AdobeUM

[23/06/2007|01:12] C:\DOCUME~1\NATALY~1\APPLIC~1\Apple Computer

[16/01/2007|20:07] C:\DOCUME~1\NATALY~1\APPLIC~1\ArcSoft

[01/06/2006|16:41] C:\DOCUME~1\NATALY~1\APPLIC~1\ATI

[13/07/2008|15:36] C:\DOCUME~1\NATALY~1\APPLIC~1\AVGTOOLBAR

[09/05/2007|13:12] C:\DOCUME~1\NATALY~1\APPLIC~1\BitTorrent

[26/05/2008|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\CmapTools

[19/02/2007|21:42] C:\DOCUME~1\NATALY~1\APPLIC~1\Corel

[04/01/2007|16:37] C:\DOCUME~1\NATALY~1\APPLIC~1\CyberLink

[01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\desktop.ini

[11/07/2007|13:04] C:\DOCUME~1\NATALY~1\APPLIC~1\fretsonfire

[01/04/2008|18:01] C:\DOCUME~1\NATALY~1\APPLIC~1\G-Force Prefs (WindowsMediaPlayer).txt

[02/03/2007|18:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Google

[01/06/2006|16:31] C:\DOCUME~1\NATALY~1\APPLIC~1\Identities

[05/01/2007|05:19] C:\DOCUME~1\NATALY~1\APPLIC~1\Macromedia

[03/03/2007|01:28] C:\DOCUME~1\NATALY~1\APPLIC~1\Media Player Classic

[01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Microsoft

[26/05/2008|14:07] C:\DOCUME~1\NATALY~1\APPLIC~1\Mozilla

[02/03/2007|17:20] C:\DOCUME~1\NATALY~1\APPLIC~1\MSNInstaller

[16/01/2007|19:41] C:\DOCUME~1\NATALY~1\APPLIC~1\Nikon

[07/01/2007|13:34] C:\DOCUME~1\NATALY~1\APPLIC~1\Nokia

[05/03/2008|10:47] C:\DOCUME~1\NATALY~1\APPLIC~1\Otto

[26/05/2008|14:05] C:\DOCUME~1\NATALY~1\APPLIC~1\SecondLife

[02/03/2007|17:49] C:\DOCUME~1\NATALY~1\APPLIC~1\Skype

[18/06/2008|22:23] C:\DOCUME~1\NATALY~1\APPLIC~1\SSH

[08/04/2007|02:56] C:\DOCUME~1\NATALY~1\APPLIC~1\Sun

[12/05/2007|02:47] C:\DOCUME~1\NATALY~1\APPLIC~1\U3

[12/07/2008|16:18] C:\DOCUME~1\NATALY~1\APPLIC~1\uTorrent

[13/07/2008|10:30] C:\DOCUME~1\NATALY~1\APPLIC~1\WinRAR

 

--------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks

 

[28/07/2008 11:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[31/07/2008 18:36][--ah-----] C:\WINDOWS\tasks\SA.DAT

[10/08/2004 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

 

--------------------\\ Lista de pastas em C:\Program Files

 

[01/06/2006|16:47] C:\Program Files\Acer Inc

[12/07/2007|19:47] C:\Program Files\Acro Software

[01/06/2006|16:48] C:\Program Files\Adobe

[14/03/2007|22:27] C:\Program Files\Ahead

[23/06/2007|00:57] C:\Program Files\Apple Software Update

[01/06/2006|16:32] C:\Program Files\ATI Technologies

[17/06/2008|12:51] C:\Program Files\AVG

[09/05/2007|13:12] C:\Program Files\BitTorrent

[01/06/2006|16:16] C:\Program Files\Common Files

[01/06/2006|16:21] C:\Program Files\ComPlus Applications

[01/06/2006|16:45] C:\Program Files\CONEXANT

[19/02/2007|21:29] C:\Program Files\Corel

[01/06/2006|16:50] C:\Program Files\CyberLink

[01/06/2006|17:29] C:\Program Files\DIFX

[20/12/2007|20:42] C:\Program Files\Discador itelefonica

[31/03/2008|13:29] C:\Program Files\GbPlugin

[01/06/2006|17:43] C:\Program Files\GemMaster

[12/03/2007|00:22] C:\Program Files\GizmoPlugin

[02/03/2007|17:48] C:\Program Files\Google

[12/07/2007|19:51] C:\Program Files\GPLGS

[26/05/2008|16:14] C:\Program Files\IHMC CmapTools

[01/06/2006|16:32] C:\Program Files\InstallShield Installation Information

[01/06/2006|16:23] C:\Program Files\Internet Explorer

[07/04/2007|22:27] C:\Program Files\Java

[05/01/2007|05:35] C:\Program Files\Launch Manager

[18/04/2007|19:35] C:\Program Files\LimeWire

[01/06/2006|16:21] C:\Program Files\Messenger

[12/05/2007|03:06] C:\Program Files\Microsoft CAPICOM 2.1.0.2

[01/06/2006|16:26] C:\Program Files\microsoft frontpage

[24/06/2008|16:13] C:\Program Files\Microsoft Office

[31/03/2008|10:12] C:\Program Files\Microsoft SQL Server Compact Edition

[08/01/2007|23:23] C:\Program Files\Microsoft Visual Studio

[24/06/2008|16:14] C:\Program Files\Microsoft Works

[24/06/2008|16:13] C:\Program Files\Microsoft.NET

[01/06/2006|16:21] C:\Program Files\Movie Maker

[29/07/2008|09:37] C:\Program Files\Mozilla Firefox

[01/06/2006|16:20] C:\Program Files\MSN

[01/06/2006|16:21] C:\Program Files\MSN Gaming Zone

[01/06/2006|16:23] C:\Program Files\NetMeeting

[01/06/2006|16:55] C:\Program Files\NewTech Infosystems

[16/03/2007|00:51] C:\Program Files\OnGame

[01/06/2006|16:21] C:\Program Files\Online Services

[01/06/2006|16:23] C:\Program Files\Outlook Express

[12/07/2007|21:48] C:\Program Files\Plus!

[19/01/2007|23:09] C:\Program Files\Positivo

[21/07/2008|11:53] C:\Program Files\QuickTime

[01/06/2006|16:41] C:\Program Files\Realtek

[03/03/2007|01:28] C:\Program Files\Recode Media

[21/07/2008|12:11] C:\Program Files\Safari

[02/03/2007|17:47] C:\Program Files\Skype

[18/06/2008|22:22] C:\Program Files\SSH Communications Security

[05/01/2007|05:34] C:\Program Files\Synaptics

[20/12/2007|20:54] C:\Program Files\Terra Discador - VersÆo Compacta

[01/06/2006|16:31] C:\Program Files\Uninstall Information

[12/07/2008|16:18] C:\Program Files\uTorrent

[12/06/2007|10:58] C:\Program Files\Windows Live

[02/03/2007|17:16] C:\Program Files\Windows Live Toolbar

[07/05/2007|21:54] C:\Program Files\Windows Media Connect 2

[01/06/2006|16:21] C:\Program Files\Windows Media Player

[01/06/2006|16:20] C:\Program Files\Windows NT

[01/06/2006|16:21] C:\Program Files\Windows Plus

[01/06/2006|16:23] C:\Program Files\WindowsUpdate

[13/07/2008|10:06] C:\Program Files\WinRAR

[24/02/2008|16:10] C:\Program Files\wt3d.ini

[01/06/2006|16:26] C:\Program Files\xerox

[26/05/2008|16:14] C:\Program Files\Zero G Registry

 

--------------------\\ Lista de pastas em C:\Program Files\Common Files

 

[17/05/2008|20:58] C:\Program Files\Common Files\Adobe

[08/02/2007|13:57] C:\Program Files\Common Files\Ahead

[01/06/2006|16:36] C:\Program Files\Common Files\ATI Technologies

[19/02/2007|21:29] C:\Program Files\Common Files\Corel

[08/01/2007|23:24] C:\Program Files\Common Files\DESIGNER

[01/06/2006|16:32] C:\Program Files\Common Files\InstallShield

[07/04/2007|22:27] C:\Program Files\Common Files\Java

[01/06/2006|16:56] C:\Program Files\Common Files\LightScribe

[01/06/2006|16:16] C:\Program Files\Common Files\Microsoft Shared

[01/06/2006|16:23] C:\Program Files\Common Files\MSSoap

[01/06/2006|16:56] C:\Program Files\Common Files\muvee Technologies

[08/02/2007|13:59] C:\Program Files\Common Files\Nero

[16/01/2007|19:37] C:\Program Files\Common Files\Nikon

[01/06/2006|16:16] C:\Program Files\Common Files\ODBC

[01/06/2006|16:23] C:\Program Files\Common Files\Services

[01/06/2006|16:16] C:\Program Files\Common Files\SpeechEngines

[05/03/2007|00:09] C:\Program Files\Common Files\Symantec Shared

[01/06/2006|16:23] C:\Program Files\Common Files\System

[31/03/2008|09:52] C:\Program Files\Common Files\WindowsLiveInstaller

 

--------------------\\ Process

 

( 35 Processus )

 

... OK !

 

--------------------\\ Procura pelo S_Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura no Registro

 

..... OK !

 

--------------------\\ Verificando o Arquivos/Ficheiros Hosts

 

Arquivos/Ficheiros Hosts LIMPO

 

 

--------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-31 20:20:40

Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden files ...

scan completed successfully

hidden processes: 0

hidden files: 0

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

[F:48][D:6]-> C:\DOCUME~1\NATALY~1\LOCALS~1\Temp

[F:876][D:0]-> C:\DOCUME~1\NATALY~1\Cookies

[F:112][D:4]-> C:\DOCUME~1\NATALY~1\LOCALS~1\TEMPOR~1\content.IE5

[F:2][D:0]-> C:\Recycled

 

--------------------\\ Verificação completa em 20:21:08,09

 

 

 

Iniciando relatório do PenClean 2.0.0.2

Por Renato Victor Mejias

renatomejias@yahoo.com.br

31/7/2008 21:39:41

-----------------------------------------------------------

Arquivos e chaves excluídos do computador:

 

Malware não detectado no computador!

 

-----------------------------------------------------------

Fim da análise no computador.

 

-----------------------------------------------------------

Arquivos e chaves excluídos do computador:

 

Malware não detectado no computador!

 

-----------------------------------------------------------

Fim da análise no computador.

 

-----------------------------------------------------------

Arquivos e chaves excluídos da unidade escolhida:

 

-----------------------------------------------------------

Arquivos excluídos da unidade C: (Resik):

 

Pasta Recycled deletada com sucesso!

-----------------------------------------------------------

Arquivos excluídos da unidade D: (Resik):

 

Pasta Recycled deletada com sucesso!

Autorun.inf foi deletado com sucesso!

-----------------------------------------------------------

Fim da análise, a unidade verificada foi: "Todas as unidades"

 

-----------------------------------------------------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! GBruno

 

<!> Repita o procedimento do Post #6,e poste: ComboFix.txt

<!> Ps: Faça-o,estando em Modo de Segurança.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite, DigRam!

 

Repetindo o procedimento do post #6, seguem os logs do ComboFix e HJT.

 

Abraços.

 

ComboFix 08-07-29.1 - Nataly Lopes 2008-07-31 23:26:39.6 - FAT32x86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.268 [GMT -3:00]

Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe

Command switches used :: C:\Documents and Settings\Nataly Lopes\Desktop\CFScript.txt

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

 

FILE ::

C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe

F:\AdobeR.exe

G:\AdobeR.exe

H:\AdobeR.exe

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\FOUND.003

C:\FOUND.003\FILE0000.CHK

C:\FOUND.004

C:\FOUND.004\FILE0000.CHK

C:\FOUND.004\FILE0001.CHK

C:\FOUND.004\FILE0002.CHK

C:\FOUND.004\FILE0003.CHK

C:\FOUND.004\FILE0004.CHK

C:\FOUND.004\FILE0005.CHK

C:\FOUND.004\FILE0006.CHK

C:\FOUND.004\FILE0007.CHK

C:\FOUND.004\FILE0008.CHK

C:\FOUND.004\FILE0009.CHK

C:\FOUND.004\FILE0010.CHK

C:\FOUND.004\FILE0011.CHK

C:\FOUND.004\FILE0012.CHK

C:\FOUND.004\FILE0013.CHK

C:\FOUND.004\FILE0014.CHK

C:\FOUND.004\FILE0015.CHK

C:\FOUND.004\FILE0016.CHK

C:\FOUND.004\FILE0017.CHK

C:\FOUND.004\FILE0018.CHK

 

.

((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))

.

 

2008-07-31 21:31 . 2008-07-31 21:31 <DIR> d-------- C:\PenClean

2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix

2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD

2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe

2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf

2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups

2008-07-28 11:11 . 2008-07-31 22:05 324 --a------ C:\Shortcut to My Documents.lnk

2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari

2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime

2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple

2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg

2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR

2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys

2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old

2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll

2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4

2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe

2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe

2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe

2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8

2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3

2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent

2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-06-24 19:14 --------- d-----w C:\Program Files\Microsoft Works

2008-06-24 19:13 --------- d-----w C:\Program Files\Microsoft.NET

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll

2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll

2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys

2008-06-19 01:23 --------- d-----w C:\Documents and Settings\Nataly Lopes\Application Data\SSH

2008-06-19 01:22 --------- d-----w C:\Program Files\SSH Communications Security

2008-06-17 15:51 --------- d-----w C:\Program Files\AVG

2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll

2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll

2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini

2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT

.

 

((((((((((((((((((((((((((((( snapshot@2008-07-30_18.57.47.82 )))))))))))))))))))))))))))))))))))))))))

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]

"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]

"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952]

"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512]

"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"GbPluginBb"="C:\PROGRA~1\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles

"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk

backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk]

path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk

backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD]

--a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]

--a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]

--a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

--------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot]

--a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC]

--a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]

--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]

--a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]

--a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

--a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

--a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

-ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

"C:\\Program Files\\LimeWire\\LimeWire.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\WINDOWS\\System32\\rtcshare.exe"=

"C:\\Program Files\\uTorrent\\uTorrent.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"12906:TCP"= 12906:TCP:NortonAV

"12246:TCP"= 12246:TCP:NortonAV

"13054:TCP"= 13054:TCP:NortonAV

"13615:TCP"= 13615:TCP:NortonAV

"16921:TCP"= 16921:TCP:NortonAV

"16448:TCP"= 16448:TCP:NortonAV

"18072:TCP"= 18072:TCP:NortonAV

"14289:TCP"= 14289:TCP:NortonAV

"18236:TCP"= 18236:TCP:NortonAV

"17716:TCP"= 17716:TCP:NortonAV

"16499:TCP"= 16499:TCP:NortonAV

"13614:TCP"= 13614:TCP:NortonAV

"15771:TCP"= 15771:TCP:NortonAV

"12826:TCP"= 12826:TCP:NortonAV

"17920:TCP"= 17920:TCP:NortonAV

"18169:TCP"= 18169:TCP:NortonAV

"12225:TCP"= 12225:TCP:NortonAV

"15538:TCP"= 15538:TCP:NortonAV

"17800:TCP"= 17800:TCP:NortonAV

"15248:TCP"= 15248:TCP:NortonAV

"13460:TCP"= 13460:TCP:NortonAV

"14692:TCP"= 14692:TCP:NortonAV

"12992:TCP"= 12992:TCP:NortonAV

"13451:TCP"= 13451:TCP:NortonAV

"15587:TCP"= 15587:TCP:NortonAV

"14010:TCP"= 14010:TCP:NortonAV

"18590:TCP"= 18590:TCP:NortonAV

"14344:TCP"= 14344:TCP:NortonAV

"14495:TCP"= 14495:TCP:NortonAV

"13352:TCP"= 13352:TCP:NortonAV

"15965:TCP"= 15965:TCP:NortonAV

"17150:TCP"= 17150:TCP:NortonAV

"18255:TCP"= 18255:TCP:NortonAV

"16963:TCP"= 16963:TCP:NortonAV

"14939:TCP"= 14939:TCP:NortonAV

"16279:TCP"= 16279:TCP:NortonAV

"13122:TCP"= 13122:TCP:NortonAV

"13437:TCP"= 13437:TCP:NortonAV

"13954:TCP"= 13954:TCP:NortonAV

"14221:TCP"= 14221:TCP:NortonAV

"16577:TCP"= 16577:TCP:NortonAV

"14580:TCP"= 14580:TCP:NortonAV

"14908:TCP"= 14908:TCP:NortonAV

"16930:TCP"= 16930:TCP:NortonAV

"14196:TCP"= 14196:TCP:NortonAV

"17932:TCP"= 17932:TCP:NortonAV

 

S1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39]

S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39]

S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys []

S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys []

.

Contents of the 'Scheduled Tasks' folder

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-31 23:36:12

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-07-31 23:39:09 - machine was rebooted

ComboFix-quarantined-files.txt 2008-08-01 02:39:02

ComboFix3.txt 2008-07-30 22:00:58

ComboFix2.txt 2008-07-31 00:51:56

 

Pre-Run: 9,721,692,160 bytes free

Post-Run: 9,707,552,768 bytes free

 

252 --- E O F --- 2008-07-31 02:06:29

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 23:39:51, on 31/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\RunOnce: [ GbPluginBb] RunDll32.exe C:\PROGRA~1\GBPLUGIN\gbieh.dll,Gbieh

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - AppInit_DLLs: avgrsstx.dll

O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\PROGRA~1\GbPlugin\GbpSv.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! GBruno

 

<@> No Executar,digite: ComboFix.exe /u --> Clique: OK

<@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação!

--------------------------

<!> Os logs estão limpos! :thumbsup:

<!> Caso,ainda,tenha problemas de lentidão,sugiro que faça manutenção do computador.

--------------------------

<@> Faça o download do TuneUp Utilities 2008.

<@> Para baixar,digite o seu E-Mail e clique em Start download.

<@> Salve o executável: TU2008TrialEN.exe,em Arquivos de Programas.

<@> O programa é Trial,mas...haverá tempo suficiente,para a otimização do computador.

<@> Procure desfragmentar o Disco e Registro.

<@> Posteriormente voçê descobrirá que este utilitário realizará outras funções,que são úteis ao computador.

--------------------------

<!> Bom trabalho!

<!> Log limpo! ( HJT )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia, DigRam!

 

Sim, o PC ainda está um pouco lento, mas irei rodar o TuneUp.

Muito obrigado mesmo pela ajuda!! :thumbsup:

 

Abraços!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.