GBruno 0 Denunciar post Postado Julho 30, 2008 Bom, estou com o PC extremamente lento e verifiquei que existem alguns processos estranhos rodando, como o IEXPLORE.EXE rodando mesmo que o Internet Explorer não esteja realmente aberto. Passei o AVG e o mesmo não aponta nada de errado, mas essa situação não é a normal. Então, segue abaixo o log do Hijackthis. Por favor, espero contar com a ajuda de vocês. Logfile of HijackThis v1.99.1 Scan saved at 16:04:59, on 29/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Acer\Empowering Technology\eRecovery\eRAgent.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\WINDOWS\msagent\AgentSvr.exe C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe O4 - HKLM\..\Run: [boot] C:\Acer\Empowering Technology\ePower\Boot.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 30, 2008 Bom Dia! GBruno <@> Faça o download do LopS&D. <@> Salve-o no Disco Local-C!. <@> Instale o programa e clique em: LopSD.cmd <@> Na janela que abrir,aperte o "p" >> Aperte Enter. <@> Em outra janela,aperte a opção 2 >> Aperte Enter >> Aguarde! <@> Terminando,salve e poste o relatório. ( C:\lopR.txt ) <@> Poste,também,HJT atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Julho 30, 2008 Boa tarde DigRam Obrigado pela ajuda, estava realmente sem saber o que fazer. Bom, seguem abaixo os relatorios do LopS&D e do HijackThis. Abraços --------------------\\ Lop S&D 4.2.2-4 XP/Vista [ Windows XP (NT 5.1) Build 2600, Service Pack 2 ] [ USER : Nataly Lopes ] [ "C:\Lop SD" ] [ Selection : 2 ] [ qua 30/07/2008 | 14:42:44,23 ] [ PC : NATALY ] [ MAJ : 25-07-2008 | 17:45 ] \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS //////////////////////////////// Deletado! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\ford more.exe Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@adultfriendfinder[1].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[2].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[3].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[4].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[1].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@advertising[5].txt Deletado! - C:\DOCUME~1\NATALY~1\Cookies\nataly_lopes@www.lop[1].txt Deletado! - C:\DOCUME~1\NATALY~1\LOCALS~1\Temp\bisB8.exe Deletado! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag Arquivos/Ficheiros Hosts RESTAURADO //////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Lista de pastas em APPLIC~1 [01/06/2006|16:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI [01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini [01/06/2006|16:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities [01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [17/05/2008|20:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [08/02/2007|13:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead [15/07/2008|23:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple [23/06/2007|00:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer [13/07/2008|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg8 [04/01/2007|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink [01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp [31/03/2008|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GbPlugin [02/03/2007|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google [19/02/2007|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield [01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [10/02/2007|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy [05/03/2008|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PKP_DLec.DAT [19/07/2007|23:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache [02/03/2007|17:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype [05/03/2007|00:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15 [30/03/2007|23:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [02/03/2007|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar [12/06/2007|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller [10/07/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [12/06/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [01/06/2006|16:16] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [01/06/2006|16:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [04/01/2007|21:57] C:\DOCUME~1\NATALY~1\APPLIC~1\Adobe [05/01/2007|18:23] C:\DOCUME~1\NATALY~1\APPLIC~1\AdobeUM [23/06/2007|01:12] C:\DOCUME~1\NATALY~1\APPLIC~1\Apple Computer [16/01/2007|20:07] C:\DOCUME~1\NATALY~1\APPLIC~1\ArcSoft [01/06/2006|16:41] C:\DOCUME~1\NATALY~1\APPLIC~1\ATI [13/07/2008|15:36] C:\DOCUME~1\NATALY~1\APPLIC~1\AVGTOOLBAR [09/05/2007|13:12] C:\DOCUME~1\NATALY~1\APPLIC~1\BitTorrent [13/07/2008|13:05] C:\DOCUME~1\NATALY~1\APPLIC~1\Bolt error second [26/05/2008|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\CmapTools [19/02/2007|21:42] C:\DOCUME~1\NATALY~1\APPLIC~1\Corel [04/01/2007|16:37] C:\DOCUME~1\NATALY~1\APPLIC~1\CyberLink [01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\desktop.ini [11/07/2007|13:04] C:\DOCUME~1\NATALY~1\APPLIC~1\fretsonfire [01/04/2008|18:01] C:\DOCUME~1\NATALY~1\APPLIC~1\G-Force Prefs (WindowsMediaPlayer).txt [02/03/2007|18:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Google [01/06/2006|16:31] C:\DOCUME~1\NATALY~1\APPLIC~1\Identities [05/01/2007|05:19] C:\DOCUME~1\NATALY~1\APPLIC~1\Macromedia [03/03/2007|01:28] C:\DOCUME~1\NATALY~1\APPLIC~1\Media Player Classic [01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Microsoft [26/05/2008|14:07] C:\DOCUME~1\NATALY~1\APPLIC~1\Mozilla [02/03/2007|17:20] C:\DOCUME~1\NATALY~1\APPLIC~1\MSNInstaller [16/01/2007|19:41] C:\DOCUME~1\NATALY~1\APPLIC~1\Nikon [07/01/2007|13:34] C:\DOCUME~1\NATALY~1\APPLIC~1\Nokia [05/03/2008|10:47] C:\DOCUME~1\NATALY~1\APPLIC~1\Otto [26/05/2008|14:05] C:\DOCUME~1\NATALY~1\APPLIC~1\SecondLife [02/03/2007|17:49] C:\DOCUME~1\NATALY~1\APPLIC~1\Skype [18/06/2008|22:23] C:\DOCUME~1\NATALY~1\APPLIC~1\SSH [08/04/2007|02:56] C:\DOCUME~1\NATALY~1\APPLIC~1\Sun [12/05/2007|02:47] C:\DOCUME~1\NATALY~1\APPLIC~1\U3 [12/07/2008|16:18] C:\DOCUME~1\NATALY~1\APPLIC~1\uTorrent [13/07/2008|10:30] C:\DOCUME~1\NATALY~1\APPLIC~1\WinRAR --------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks [28/07/2008 11:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job [30/07/2008 13:46][--ah-----] C:\WINDOWS\tasks\SA.DAT [10/08/2004 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Lista de pastas em C:\Program Files [01/06/2006|16:47] C:\Program Files\Acer Inc [12/07/2007|19:47] C:\Program Files\Acro Software [01/06/2006|16:48] C:\Program Files\Adobe [14/03/2007|22:27] C:\Program Files\Ahead [23/06/2007|00:57] C:\Program Files\Apple Software Update [01/06/2006|16:32] C:\Program Files\ATI Technologies [17/06/2008|12:51] C:\Program Files\AVG [09/05/2007|13:12] C:\Program Files\BitTorrent [23/07/2008|14:14] C:\Program Files\Bolt error second [01/06/2006|16:16] C:\Program Files\Common Files [01/06/2006|16:21] C:\Program Files\ComPlus Applications [01/06/2006|16:45] C:\Program Files\CONEXANT [19/02/2007|21:29] C:\Program Files\Corel [01/06/2006|16:50] C:\Program Files\CyberLink [01/06/2006|17:29] C:\Program Files\DIFX [20/12/2007|20:42] C:\Program Files\Discador itelefonica [31/03/2008|13:29] C:\Program Files\GbPlugin [01/06/2006|17:43] C:\Program Files\GemMaster [12/03/2007|00:22] C:\Program Files\GizmoPlugin [02/03/2007|17:48] C:\Program Files\Google [12/07/2007|19:51] C:\Program Files\GPLGS [26/05/2008|16:14] C:\Program Files\IHMC CmapTools [01/06/2006|16:32] C:\Program Files\InstallShield Installation Information [01/06/2006|16:23] C:\Program Files\Internet Explorer [07/04/2007|22:27] C:\Program Files\Java [05/01/2007|05:35] C:\Program Files\Launch Manager [18/04/2007|19:35] C:\Program Files\LimeWire [01/06/2006|16:21] C:\Program Files\Messenger [12/05/2007|03:06] C:\Program Files\Microsoft CAPICOM 2.1.0.2 [01/06/2006|16:26] C:\Program Files\microsoft frontpage [24/06/2008|16:13] C:\Program Files\Microsoft Office [31/03/2008|10:12] C:\Program Files\Microsoft SQL Server Compact Edition [08/01/2007|23:23] C:\Program Files\Microsoft Visual Studio [24/06/2008|16:14] C:\Program Files\Microsoft Works [24/06/2008|16:13] C:\Program Files\Microsoft.NET [01/06/2006|16:21] C:\Program Files\Movie Maker [29/07/2008|09:37] C:\Program Files\Mozilla Firefox [01/06/2006|16:20] C:\Program Files\MSN [01/06/2006|16:21] C:\Program Files\MSN Gaming Zone [01/06/2006|16:23] C:\Program Files\NetMeeting [01/06/2006|16:55] C:\Program Files\NewTech Infosystems [16/03/2007|00:51] C:\Program Files\OnGame [01/06/2006|16:21] C:\Program Files\Online Services [01/06/2006|16:23] C:\Program Files\Outlook Express [12/07/2007|21:48] C:\Program Files\Plus! [19/01/2007|23:09] C:\Program Files\Positivo [21/07/2008|11:53] C:\Program Files\QuickTime [01/06/2006|16:41] C:\Program Files\Realtek [03/03/2007|01:28] C:\Program Files\Recode Media [21/07/2008|12:11] C:\Program Files\Safari [02/03/2007|17:47] C:\Program Files\Skype [18/06/2008|22:22] C:\Program Files\SSH Communications Security [05/01/2007|05:34] C:\Program Files\Synaptics [20/12/2007|20:54] C:\Program Files\Terra Discador - VersÆo Compacta [01/06/2006|16:31] C:\Program Files\Uninstall Information [12/07/2008|16:18] C:\Program Files\uTorrent [12/06/2007|10:58] C:\Program Files\Windows Live [02/03/2007|17:16] C:\Program Files\Windows Live Toolbar [07/05/2007|21:54] C:\Program Files\Windows Media Connect 2 [01/06/2006|16:21] C:\Program Files\Windows Media Player [01/06/2006|16:20] C:\Program Files\Windows NT [01/06/2006|16:21] C:\Program Files\Windows Plus [01/06/2006|16:23] C:\Program Files\WindowsUpdate [13/07/2008|10:06] C:\Program Files\WinRAR [24/02/2008|16:10] C:\Program Files\wt3d.ini [01/06/2006|16:26] C:\Program Files\xerox [26/05/2008|16:14] C:\Program Files\Zero G Registry --------------------\\ Lista de pastas em C:\Program Files\Common Files [17/05/2008|20:58] C:\Program Files\Common Files\Adobe [08/02/2007|13:57] C:\Program Files\Common Files\Ahead [01/06/2006|16:36] C:\Program Files\Common Files\ATI Technologies [19/02/2007|21:29] C:\Program Files\Common Files\Corel [08/01/2007|23:24] C:\Program Files\Common Files\DESIGNER [01/06/2006|16:32] C:\Program Files\Common Files\InstallShield [07/04/2007|22:27] C:\Program Files\Common Files\Java [01/06/2006|16:56] C:\Program Files\Common Files\LightScribe [01/06/2006|16:16] C:\Program Files\Common Files\Microsoft Shared [01/06/2006|16:23] C:\Program Files\Common Files\MSSoap [01/06/2006|16:56] C:\Program Files\Common Files\muvee Technologies [08/02/2007|13:59] C:\Program Files\Common Files\Nero [16/01/2007|19:37] C:\Program Files\Common Files\Nikon [01/06/2006|16:16] C:\Program Files\Common Files\ODBC [01/06/2006|16:23] C:\Program Files\Common Files\Services [01/06/2006|16:16] C:\Program Files\Common Files\SpeechEngines [05/03/2007|00:09] C:\Program Files\Common Files\Symantec Shared [01/06/2006|16:23] C:\Program Files\Common Files\System [31/03/2008|09:52] C:\Program Files\Common Files\WindowsLiveInstaller --------------------\\ Process ( 42 Processus ) ... OK ! --------------------\\ Procura pelo S_Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura no Registro [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ..... OK ! --------------------\\ Verificando o Arquivos/Ficheiros Hosts Arquivos/Ficheiros Hosts LIMPO --------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-30 14:44:54 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. [F:2725][D:29]-> C:\DOCUME~1\NATALY~1\LOCALS~1\Temp [F:876][D:0]-> C:\DOCUME~1\NATALY~1\Cookies [F:18415][D:37]-> C:\DOCUME~1\NATALY~1\LOCALS~1\TEMPOR~1\content.IE5 [F:3][D:0]-> C:\Recycled --------------------\\ Verificação completa em 14:46:00,09 Logfile of HijackThis v1.99.1 Scan saved at 14:50:32, on 30/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Acer\Empowering Technology\ePower\ePower_DMC.exe C:\WINDOWS\eHome\ehRecvr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Acer\Empowering Technology\eRecovery\eRAgent.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Documents and Settings\Nataly Lopes\Local Settings\Temp\jkos-Nataly Lopes\binaries\ScanningProcess.exe C:\WINDOWS\explorer.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\DOCUME~1\NATALY~1\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe O4 - HKLM\..\Run: [boot] C:\Acer\Empowering Technology\ePower\Boot.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 30, 2008 Boa Tarde! GBruno <@> Faça o download do ComboFix. <@> Baixe-o para o Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e Firewall.( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.Salve-a no Desktop,renomeada como: Kombo.exe Ps: Nomeie durante o salvamento,e não após salvá-la! Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança. <@> Abrirá a janela Auto Scan. Aguarde! <@> Digite a opção para continuar e < Enter > <@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! <@> Para parar ou sair do ComboFix,tecle "N". ------------------------- <@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Julho 30, 2008 Boa noite DigRam! Depois de muitos resets e tendo que inicializar o computador no Modo de Segurança, consegui rodar o ComboFix. Segue abaixo os logs gerados pelo ComboFix e pelo HJT. Muito obrigado pela ajuda! Abraço! ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 18:39:06.3 - FAT32x86 NETWORK Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.262 [GMT -3:00] Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\temp\perflib_perfdata_1cc.dat . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-30 ))))))))))))))))))))))))))))))) . 2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004 2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix 2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD 2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe 2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003 2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf 2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups 2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk 2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second 2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari 2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime 2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR 2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old 2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4 2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe 2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second 2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe 2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe 2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8 2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3 2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent 2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH 2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security 2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG 2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini 2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD] --a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] --a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] --a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel] --------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot] --a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC] --a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService] --a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] --a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002] --a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] -ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\System32\\rtcshare.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "12906:TCP"= 12906:TCP:NortonAV "12246:TCP"= 12246:TCP:NortonAV "13054:TCP"= 13054:TCP:NortonAV "13615:TCP"= 13615:TCP:NortonAV "16921:TCP"= 16921:TCP:NortonAV "16448:TCP"= 16448:TCP:NortonAV "18072:TCP"= 18072:TCP:NortonAV "14289:TCP"= 14289:TCP:NortonAV "18236:TCP"= 18236:TCP:NortonAV "17716:TCP"= 17716:TCP:NortonAV "16499:TCP"= 16499:TCP:NortonAV "13614:TCP"= 13614:TCP:NortonAV "15771:TCP"= 15771:TCP:NortonAV "12826:TCP"= 12826:TCP:NortonAV "17920:TCP"= 17920:TCP:NortonAV "18169:TCP"= 18169:TCP:NortonAV "12225:TCP"= 12225:TCP:NortonAV "15538:TCP"= 15538:TCP:NortonAV "17800:TCP"= 17800:TCP:NortonAV "15248:TCP"= 15248:TCP:NortonAV "13460:TCP"= 13460:TCP:NortonAV "14692:TCP"= 14692:TCP:NortonAV "12992:TCP"= 12992:TCP:NortonAV "13451:TCP"= 13451:TCP:NortonAV "15587:TCP"= 15587:TCP:NortonAV "14010:TCP"= 14010:TCP:NortonAV "18590:TCP"= 18590:TCP:NortonAV "14344:TCP"= 14344:TCP:NortonAV "14495:TCP"= 14495:TCP:NortonAV "13352:TCP"= 13352:TCP:NortonAV "15965:TCP"= 15965:TCP:NortonAV "17150:TCP"= 17150:TCP:NortonAV "18255:TCP"= 18255:TCP:NortonAV "16963:TCP"= 16963:TCP:NortonAV "14939:TCP"= 14939:TCP:NortonAV "16279:TCP"= 16279:TCP:NortonAV "13122:TCP"= 13122:TCP:NortonAV "13437:TCP"= 13437:TCP:NortonAV "13954:TCP"= 13954:TCP:NortonAV "14221:TCP"= 14221:TCP:NortonAV "16577:TCP"= 16577:TCP:NortonAV "14580:TCP"= 14580:TCP:NortonAV "14908:TCP"= 14908:TCP:NortonAV "16930:TCP"= 16930:TCP:NortonAV "14196:TCP"= 14196:TCP:NortonAV "17932:TCP"= 17932:TCP:NortonAV R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39] S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys [] S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\Auto\command - F:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G] \Shell\Auto\command - G:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\Auto\command - H:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57] . - - - - ORPHANS REMOVED - - - - HKLM-Explorer_Run-winlogon - C:\heap41a\svchost.exe MSConfigStartUp-Base frag grid bows - C:\Documents and Settings\All Users\Application Data\Cast ping base frag\ford more.exe MSConfigStartUp-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe MSConfigStartUp-RavAV - C:\WINDOWS\AdobeR.exe MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe . ------- Supplementary Scan ------- . R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab C:\WINDOWS\Downloaded Program Files\gbpdist.inf C:\WINDOWS\Downloaded Program Files\gbpdist.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-30 18:52:29 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe . ************************************************************************** . Completion time: 2008-07-30 19:00:51 - machine was rebooted [Nataly Lopes] ComboFix-quarantined-files.txt 2008-07-30 21:59:22 Pre-Run: 7,786,315,776 bytes free Post-Run: 9,309,306,880 bytes free 277 --- E O F --- 2008-07-30 00:42:35 Logfile of HijackThis v1.99.1 Scan saved at 19:04:48, on 30/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 30, 2008 Boa Noite! GBruno <@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas. <@> Salve-o,no Desktop,com o nome: CFScript.txt File::C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe F:\AdobeR.exe G:\AdobeR.exe H:\AdobeR.exe Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nurbsize"=- Folder:: C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second C:\FOUND.004 C:\FOUND.003 <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Reinicie o computador! <@> Terminando,poste os relatórios: C:\ComboFix.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Julho 31, 2008 Bom dia DigRam! Fiz o que foi pedido e o PC ficou resetando algumas vezes até conseguir rodar o ComboFix (somente no Modo de Segurança). Segue abaixo os logs do Combofix e HijackThis. Muito obrigado pela ajuda! Abraços. ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 21:28:31.5 - FAT32x86 MINIMAL Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . F:\ntdelect.com . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))) . 2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004 2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix 2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD 2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe 2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003 2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf 2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups 2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk 2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second 2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari 2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime 2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR 2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old 2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4 2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe 2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second 2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe 2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe 2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8 2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3 2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent 2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH 2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security 2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG 2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini 2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD] --a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] --a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] --a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel] --------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot] --a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC] --a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService] --a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] --a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002] --a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] -ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\System32\\rtcshare.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "12906:TCP"= 12906:TCP:NortonAV "12246:TCP"= 12246:TCP:NortonAV "13054:TCP"= 13054:TCP:NortonAV "13615:TCP"= 13615:TCP:NortonAV "16921:TCP"= 16921:TCP:NortonAV "16448:TCP"= 16448:TCP:NortonAV "18072:TCP"= 18072:TCP:NortonAV "14289:TCP"= 14289:TCP:NortonAV "18236:TCP"= 18236:TCP:NortonAV "17716:TCP"= 17716:TCP:NortonAV "16499:TCP"= 16499:TCP:NortonAV "13614:TCP"= 13614:TCP:NortonAV "15771:TCP"= 15771:TCP:NortonAV "12826:TCP"= 12826:TCP:NortonAV "17920:TCP"= 17920:TCP:NortonAV "18169:TCP"= 18169:TCP:NortonAV "12225:TCP"= 12225:TCP:NortonAV "15538:TCP"= 15538:TCP:NortonAV "17800:TCP"= 17800:TCP:NortonAV "15248:TCP"= 15248:TCP:NortonAV "13460:TCP"= 13460:TCP:NortonAV "14692:TCP"= 14692:TCP:NortonAV "12992:TCP"= 12992:TCP:NortonAV "13451:TCP"= 13451:TCP:NortonAV "15587:TCP"= 15587:TCP:NortonAV "14010:TCP"= 14010:TCP:NortonAV "18590:TCP"= 18590:TCP:NortonAV "14344:TCP"= 14344:TCP:NortonAV "14495:TCP"= 14495:TCP:NortonAV "13352:TCP"= 13352:TCP:NortonAV "15965:TCP"= 15965:TCP:NortonAV "17150:TCP"= 17150:TCP:NortonAV "18255:TCP"= 18255:TCP:NortonAV "16963:TCP"= 16963:TCP:NortonAV "14939:TCP"= 14939:TCP:NortonAV "16279:TCP"= 16279:TCP:NortonAV "13122:TCP"= 13122:TCP:NortonAV "13437:TCP"= 13437:TCP:NortonAV "13954:TCP"= 13954:TCP:NortonAV "14221:TCP"= 14221:TCP:NortonAV "16577:TCP"= 16577:TCP:NortonAV "14580:TCP"= 14580:TCP:NortonAV "14908:TCP"= 14908:TCP:NortonAV "16930:TCP"= 16930:TCP:NortonAV "14196:TCP"= 14196:TCP:NortonAV "17932:TCP"= 17932:TCP:NortonAV R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39] S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys [] S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\Auto\command - F:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G] \Shell\Auto\command - G:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\Auto\command - H:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57] . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab C:\WINDOWS\Downloaded Program Files\gbpdist.inf C:\WINDOWS\Downloaded Program Files\gbpdist.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-30 21:42:07 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\AVG\AVG8\avgrsx.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe . ************************************************************************** . Completion time: 2008-07-30 21:51:40 - machine was rebooted [Nataly Lopes] ComboFix-quarantined-files.txt 2008-07-31 00:50:56 ComboFix2.txt 2008-07-30 22:00:58 Pre-Run: 9,734,651,904 bytes free Post-Run: 9,246,261,248 bytes free 269 --- E O F --- 2008-07-30 00:42:35 Logfile of HijackThis v1.99.1 Scan saved at 21:13, on 2008-07-30 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKCU\..\Run: [nurbsize] C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 31, 2008 Bom Dia! GBruno <!> O relatório postado,não é o ComboFix.txt após o script. <!> Caso não o possua,recomendo a desinstalação do ComboFix.exe,e o download de uma nova ferramenta. ------------------------- <@> No Executar,digite: ComboFix.exe /u --> Clique: OK <@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação! ------------------------- <@> Faça o download do ComboFix.exe e arraste o CFScript.txt,para o seu ícone. <@> Poste: ComboFix.txt + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Julho 31, 2008 Boa tarde DigRam, Parece que o relatório postado anteriormente não era mesmo o ComboFix.txt, mas ao abrir esse arquivo em C: percebi que se trata da mesma coisa, aparentemente. Segue o arquivo C:/ComboFix.txt Bom, to meio sem saber o que fazer, uma ajudinha é bem vinda =). Muito Obrigado Abraços ComboFix 08-07-29.1 - Nataly Lopes 2008-07-30 21:28:31.5 - FAT32x86 MINIMAL Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . F:\ntdelect.com . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))) . 2008-07-30 17:18 . 2008-07-30 17:18 <DIR> d--hs---- C:\FOUND.004 2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix 2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD 2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe 2008-07-30 13:42 . 2008-07-30 13:42 <DIR> d--hs---- C:\FOUND.003 2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf 2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups 2008-07-28 11:11 . 2008-07-28 11:11 384 --a------ C:\Shortcut to My Documents.lnk 2008-07-23 14:14 . 2008-07-23 14:14 <DIR> d-------- C:\Program Files\Bolt error second 2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari 2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime 2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR 2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old 2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4 2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe 2008-07-13 13:05 . 2008-07-13 13:05 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\Bolt error second 2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe 2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe 2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8 2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3 2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent 2008-06-24 16:14 . 2008-06-24 16:14 <DIR> d-------- C:\Program Files\Microsoft Works 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\WINDOWS\SHELLNEW 2008-06-24 16:13 . 2008-06-24 16:13 <DIR> d-------- C:\Program Files\Microsoft.NET 2008-06-18 22:23 . 2008-06-18 22:23 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\SSH 2008-06-18 22:22 . 2008-06-18 22:22 <DIR> d-------- C:\Program Files\SSH Communications Security 2008-06-17 12:51 . 2008-06-17 12:51 <DIR> d-------- C:\Program Files\AVG 2008-06-17 12:49 . 2008-06-17 12:52 8,192 --a------ C:\Documents and Settings\ADMINI~1 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-15 12:16 . 2008-06-13 10:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-10 22:56 . 2008-06-10 22:56 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\.eclipse . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 04:16 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2008-04-23 04:16 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2008-04-23 04:16 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-04-23 04:16 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2008-04-23 04:16 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-04-23 04:16 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini 2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT 2007-07-21 01:13 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nurbsize"="C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe" [2008-07-23 14:13 498688] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD] --a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] --a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] --a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel] --------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot] --a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC] --a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService] --a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] --a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002] --a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] -ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\System32\\rtcshare.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "12906:TCP"= 12906:TCP:NortonAV "12246:TCP"= 12246:TCP:NortonAV "13054:TCP"= 13054:TCP:NortonAV "13615:TCP"= 13615:TCP:NortonAV "16921:TCP"= 16921:TCP:NortonAV "16448:TCP"= 16448:TCP:NortonAV "18072:TCP"= 18072:TCP:NortonAV "14289:TCP"= 14289:TCP:NortonAV "18236:TCP"= 18236:TCP:NortonAV "17716:TCP"= 17716:TCP:NortonAV "16499:TCP"= 16499:TCP:NortonAV "13614:TCP"= 13614:TCP:NortonAV "15771:TCP"= 15771:TCP:NortonAV "12826:TCP"= 12826:TCP:NortonAV "17920:TCP"= 17920:TCP:NortonAV "18169:TCP"= 18169:TCP:NortonAV "12225:TCP"= 12225:TCP:NortonAV "15538:TCP"= 15538:TCP:NortonAV "17800:TCP"= 17800:TCP:NortonAV "15248:TCP"= 15248:TCP:NortonAV "13460:TCP"= 13460:TCP:NortonAV "14692:TCP"= 14692:TCP:NortonAV "12992:TCP"= 12992:TCP:NortonAV "13451:TCP"= 13451:TCP:NortonAV "15587:TCP"= 15587:TCP:NortonAV "14010:TCP"= 14010:TCP:NortonAV "18590:TCP"= 18590:TCP:NortonAV "14344:TCP"= 14344:TCP:NortonAV "14495:TCP"= 14495:TCP:NortonAV "13352:TCP"= 13352:TCP:NortonAV "15965:TCP"= 15965:TCP:NortonAV "17150:TCP"= 17150:TCP:NortonAV "18255:TCP"= 18255:TCP:NortonAV "16963:TCP"= 16963:TCP:NortonAV "14939:TCP"= 14939:TCP:NortonAV "16279:TCP"= 16279:TCP:NortonAV "13122:TCP"= 13122:TCP:NortonAV "13437:TCP"= 13437:TCP:NortonAV "13954:TCP"= 13954:TCP:NortonAV "14221:TCP"= 14221:TCP:NortonAV "16577:TCP"= 16577:TCP:NortonAV "14580:TCP"= 14580:TCP:NortonAV "14908:TCP"= 14908:TCP:NortonAV "16930:TCP"= 16930:TCP:NortonAV "14196:TCP"= 14196:TCP:NortonAV "17932:TCP"= 17932:TCP:NortonAV R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39] S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys [] S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\Auto\command - F:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G] \Shell\Auto\command - G:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\Auto\command - H:\AdobeR.exe e \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57] . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 O8 -: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 -: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 -: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab C:\WINDOWS\Downloaded Program Files\gbpdist.inf C:\WINDOWS\Downloaded Program Files\gbpdist.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-30 21:42:07 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\AVG\AVG8\avgrsx.exe C:\WINDOWS\ehome\mcrdsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe . ************************************************************************** . Completion time: 2008-07-30 21:51:40 - machine was rebooted [Nataly Lopes] ComboFix-quarantined-files.txt 2008-07-31 00:50:56 ComboFix2.txt 2008-07-30 22:00:58 Pre-Run: 9,734,651,904 bytes free Post-Run: 9,246,261,248 bytes free 269 --- E O F --- 2008-07-30 00:42:35 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 31, 2008 Boa Noite! GBruno <@> Execute,novamente,o Lop S&D e poste o relatório. ( C:\LopR.txt ) ------------------------ >@< Faça o download do PenClean. <!> Link alternativo: < PenClean > >@< Salve-o no Desktop! >@< Insira suas unidades removíveis,na entrada USB. ( pendrive,mp3,mp4,etc... ) >@< Rode o utilitário,em Modo de Segurança,e selecione a opção: Verificar o computador >@< Clique no botão Verificar.Aguarde! >@< Caso haja necessidade,atenda a solicitação para reiniciar o computador. >@< Clique em Sim! >@< Ps: Não remova,ainda,essas unidades! >@< Poste,o relatório do PenClean: C:\PenClean\PenClean.txt + LopR.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Agosto 1, 2008 Boa noite, DigRam! Mais uma vez obrigado pela ajuda. Rodei novamente o LopS&D e também o PenClean. Segue abaixo os relatórios. Abraços. --------------------\\ Lop S&D 4.2.2-4 XP/Vista [ Windows XP (NT 5.1) Build 2600, Service Pack 2 ] [ USER : Nataly Lopes ] [ "C:\Lop SD" ] [ Selection : 2 ] [ qui 31/07/2008 | 20:18:44,85 ] [ PC : NATALY ] [ MAJ : 25-07-2008 | 17:45 ] //////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Lista de pastas em APPLIC~1 [01/06/2006|16:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI [01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini [01/06/2006|16:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities [01/06/2006|16:16] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [17/05/2008|20:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [08/02/2007|13:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead [15/07/2008|23:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple [23/06/2007|00:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer [13/07/2008|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg8 [04/01/2007|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink [01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp [31/03/2008|13:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GbPlugin [02/03/2007|17:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google [19/02/2007|21:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield [01/06/2006|16:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [10/02/2007|23:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy [05/03/2008|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Otto [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PKP_DLec.DAT [19/07/2007|23:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache [02/03/2007|17:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype [05/03/2007|00:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec [16/01/2007|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15 [30/03/2007|23:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [02/03/2007|17:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar [12/06/2007|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller [10/07/2007|20:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip [12/06/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [01/06/2006|16:16] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [01/06/2006|16:16] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [04/01/2007|21:57] C:\DOCUME~1\NATALY~1\APPLIC~1\Adobe [05/01/2007|18:23] C:\DOCUME~1\NATALY~1\APPLIC~1\AdobeUM [23/06/2007|01:12] C:\DOCUME~1\NATALY~1\APPLIC~1\Apple Computer [16/01/2007|20:07] C:\DOCUME~1\NATALY~1\APPLIC~1\ArcSoft [01/06/2006|16:41] C:\DOCUME~1\NATALY~1\APPLIC~1\ATI [13/07/2008|15:36] C:\DOCUME~1\NATALY~1\APPLIC~1\AVGTOOLBAR [09/05/2007|13:12] C:\DOCUME~1\NATALY~1\APPLIC~1\BitTorrent [26/05/2008|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\CmapTools [19/02/2007|21:42] C:\DOCUME~1\NATALY~1\APPLIC~1\Corel [04/01/2007|16:37] C:\DOCUME~1\NATALY~1\APPLIC~1\CyberLink [01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\desktop.ini [11/07/2007|13:04] C:\DOCUME~1\NATALY~1\APPLIC~1\fretsonfire [01/04/2008|18:01] C:\DOCUME~1\NATALY~1\APPLIC~1\G-Force Prefs (WindowsMediaPlayer).txt [02/03/2007|18:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Google [01/06/2006|16:31] C:\DOCUME~1\NATALY~1\APPLIC~1\Identities [05/01/2007|05:19] C:\DOCUME~1\NATALY~1\APPLIC~1\Macromedia [03/03/2007|01:28] C:\DOCUME~1\NATALY~1\APPLIC~1\Media Player Classic [01/06/2006|16:16] C:\DOCUME~1\NATALY~1\APPLIC~1\Microsoft [26/05/2008|14:07] C:\DOCUME~1\NATALY~1\APPLIC~1\Mozilla [02/03/2007|17:20] C:\DOCUME~1\NATALY~1\APPLIC~1\MSNInstaller [16/01/2007|19:41] C:\DOCUME~1\NATALY~1\APPLIC~1\Nikon [07/01/2007|13:34] C:\DOCUME~1\NATALY~1\APPLIC~1\Nokia [05/03/2008|10:47] C:\DOCUME~1\NATALY~1\APPLIC~1\Otto [26/05/2008|14:05] C:\DOCUME~1\NATALY~1\APPLIC~1\SecondLife [02/03/2007|17:49] C:\DOCUME~1\NATALY~1\APPLIC~1\Skype [18/06/2008|22:23] C:\DOCUME~1\NATALY~1\APPLIC~1\SSH [08/04/2007|02:56] C:\DOCUME~1\NATALY~1\APPLIC~1\Sun [12/05/2007|02:47] C:\DOCUME~1\NATALY~1\APPLIC~1\U3 [12/07/2008|16:18] C:\DOCUME~1\NATALY~1\APPLIC~1\uTorrent [13/07/2008|10:30] C:\DOCUME~1\NATALY~1\APPLIC~1\WinRAR --------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks [28/07/2008 11:30][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job [31/07/2008 18:36][--ah-----] C:\WINDOWS\tasks\SA.DAT [10/08/2004 20:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Lista de pastas em C:\Program Files [01/06/2006|16:47] C:\Program Files\Acer Inc [12/07/2007|19:47] C:\Program Files\Acro Software [01/06/2006|16:48] C:\Program Files\Adobe [14/03/2007|22:27] C:\Program Files\Ahead [23/06/2007|00:57] C:\Program Files\Apple Software Update [01/06/2006|16:32] C:\Program Files\ATI Technologies [17/06/2008|12:51] C:\Program Files\AVG [09/05/2007|13:12] C:\Program Files\BitTorrent [01/06/2006|16:16] C:\Program Files\Common Files [01/06/2006|16:21] C:\Program Files\ComPlus Applications [01/06/2006|16:45] C:\Program Files\CONEXANT [19/02/2007|21:29] C:\Program Files\Corel [01/06/2006|16:50] C:\Program Files\CyberLink [01/06/2006|17:29] C:\Program Files\DIFX [20/12/2007|20:42] C:\Program Files\Discador itelefonica [31/03/2008|13:29] C:\Program Files\GbPlugin [01/06/2006|17:43] C:\Program Files\GemMaster [12/03/2007|00:22] C:\Program Files\GizmoPlugin [02/03/2007|17:48] C:\Program Files\Google [12/07/2007|19:51] C:\Program Files\GPLGS [26/05/2008|16:14] C:\Program Files\IHMC CmapTools [01/06/2006|16:32] C:\Program Files\InstallShield Installation Information [01/06/2006|16:23] C:\Program Files\Internet Explorer [07/04/2007|22:27] C:\Program Files\Java [05/01/2007|05:35] C:\Program Files\Launch Manager [18/04/2007|19:35] C:\Program Files\LimeWire [01/06/2006|16:21] C:\Program Files\Messenger [12/05/2007|03:06] C:\Program Files\Microsoft CAPICOM 2.1.0.2 [01/06/2006|16:26] C:\Program Files\microsoft frontpage [24/06/2008|16:13] C:\Program Files\Microsoft Office [31/03/2008|10:12] C:\Program Files\Microsoft SQL Server Compact Edition [08/01/2007|23:23] C:\Program Files\Microsoft Visual Studio [24/06/2008|16:14] C:\Program Files\Microsoft Works [24/06/2008|16:13] C:\Program Files\Microsoft.NET [01/06/2006|16:21] C:\Program Files\Movie Maker [29/07/2008|09:37] C:\Program Files\Mozilla Firefox [01/06/2006|16:20] C:\Program Files\MSN [01/06/2006|16:21] C:\Program Files\MSN Gaming Zone [01/06/2006|16:23] C:\Program Files\NetMeeting [01/06/2006|16:55] C:\Program Files\NewTech Infosystems [16/03/2007|00:51] C:\Program Files\OnGame [01/06/2006|16:21] C:\Program Files\Online Services [01/06/2006|16:23] C:\Program Files\Outlook Express [12/07/2007|21:48] C:\Program Files\Plus! [19/01/2007|23:09] C:\Program Files\Positivo [21/07/2008|11:53] C:\Program Files\QuickTime [01/06/2006|16:41] C:\Program Files\Realtek [03/03/2007|01:28] C:\Program Files\Recode Media [21/07/2008|12:11] C:\Program Files\Safari [02/03/2007|17:47] C:\Program Files\Skype [18/06/2008|22:22] C:\Program Files\SSH Communications Security [05/01/2007|05:34] C:\Program Files\Synaptics [20/12/2007|20:54] C:\Program Files\Terra Discador - VersÆo Compacta [01/06/2006|16:31] C:\Program Files\Uninstall Information [12/07/2008|16:18] C:\Program Files\uTorrent [12/06/2007|10:58] C:\Program Files\Windows Live [02/03/2007|17:16] C:\Program Files\Windows Live Toolbar [07/05/2007|21:54] C:\Program Files\Windows Media Connect 2 [01/06/2006|16:21] C:\Program Files\Windows Media Player [01/06/2006|16:20] C:\Program Files\Windows NT [01/06/2006|16:21] C:\Program Files\Windows Plus [01/06/2006|16:23] C:\Program Files\WindowsUpdate [13/07/2008|10:06] C:\Program Files\WinRAR [24/02/2008|16:10] C:\Program Files\wt3d.ini [01/06/2006|16:26] C:\Program Files\xerox [26/05/2008|16:14] C:\Program Files\Zero G Registry --------------------\\ Lista de pastas em C:\Program Files\Common Files [17/05/2008|20:58] C:\Program Files\Common Files\Adobe [08/02/2007|13:57] C:\Program Files\Common Files\Ahead [01/06/2006|16:36] C:\Program Files\Common Files\ATI Technologies [19/02/2007|21:29] C:\Program Files\Common Files\Corel [08/01/2007|23:24] C:\Program Files\Common Files\DESIGNER [01/06/2006|16:32] C:\Program Files\Common Files\InstallShield [07/04/2007|22:27] C:\Program Files\Common Files\Java [01/06/2006|16:56] C:\Program Files\Common Files\LightScribe [01/06/2006|16:16] C:\Program Files\Common Files\Microsoft Shared [01/06/2006|16:23] C:\Program Files\Common Files\MSSoap [01/06/2006|16:56] C:\Program Files\Common Files\muvee Technologies [08/02/2007|13:59] C:\Program Files\Common Files\Nero [16/01/2007|19:37] C:\Program Files\Common Files\Nikon [01/06/2006|16:16] C:\Program Files\Common Files\ODBC [01/06/2006|16:23] C:\Program Files\Common Files\Services [01/06/2006|16:16] C:\Program Files\Common Files\SpeechEngines [05/03/2007|00:09] C:\Program Files\Common Files\Symantec Shared [01/06/2006|16:23] C:\Program Files\Common Files\System [31/03/2008|09:52] C:\Program Files\Common Files\WindowsLiveInstaller --------------------\\ Process ( 35 Processus ) ... OK ! --------------------\\ Procura pelo S_Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop Não foram encontradas pastas com o Lop! --------------------\\ Procura no Registro ..... OK ! --------------------\\ Verificando o Arquivos/Ficheiros Hosts Arquivos/Ficheiros Hosts LIMPO --------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-31 20:20:40 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. [F:48][D:6]-> C:\DOCUME~1\NATALY~1\LOCALS~1\Temp [F:876][D:0]-> C:\DOCUME~1\NATALY~1\Cookies [F:112][D:4]-> C:\DOCUME~1\NATALY~1\LOCALS~1\TEMPOR~1\content.IE5 [F:2][D:0]-> C:\Recycled --------------------\\ Verificação completa em 20:21:08,09 Iniciando relatório do PenClean 2.0.0.2 Por Renato Victor Mejias renatomejias@yahoo.com.br 31/7/2008 21:39:41 ----------------------------------------------------------- Arquivos e chaves excluídos do computador: Malware não detectado no computador! ----------------------------------------------------------- Fim da análise no computador. ----------------------------------------------------------- Arquivos e chaves excluídos do computador: Malware não detectado no computador! ----------------------------------------------------------- Fim da análise no computador. ----------------------------------------------------------- Arquivos e chaves excluídos da unidade escolhida: ----------------------------------------------------------- Arquivos excluídos da unidade C: (Resik): Pasta Recycled deletada com sucesso! ----------------------------------------------------------- Arquivos excluídos da unidade D: (Resik): Pasta Recycled deletada com sucesso! Autorun.inf foi deletado com sucesso! ----------------------------------------------------------- Fim da análise, a unidade verificada foi: "Todas as unidades" ----------------------------------------------------------- Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 1, 2008 Boa Noite! GBruno <!> Repita o procedimento do Post #6,e poste: ComboFix.txt <!> Ps: Faça-o,estando em Modo de Segurança. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Agosto 1, 2008 Boa noite, DigRam! Repetindo o procedimento do post #6, seguem os logs do ComboFix e HJT. Abraços. ComboFix 08-07-29.1 - Nataly Lopes 2008-07-31 23:26:39.6 - FAT32x86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.268 [GMT -3:00] Running from: C:\Documents and Settings\Nataly Lopes\Desktop\Kombo.exe Command switches used :: C:\Documents and Settings\Nataly Lopes\Desktop\CFScript.txt WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\DOCUME~1\NATALY~1\APPLIC~1\BOLTER~1\debug long pop.exe F:\AdobeR.exe G:\AdobeR.exe H:\AdobeR.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\FOUND.003 C:\FOUND.003\FILE0000.CHK C:\FOUND.004 C:\FOUND.004\FILE0000.CHK C:\FOUND.004\FILE0001.CHK C:\FOUND.004\FILE0002.CHK C:\FOUND.004\FILE0003.CHK C:\FOUND.004\FILE0004.CHK C:\FOUND.004\FILE0005.CHK C:\FOUND.004\FILE0006.CHK C:\FOUND.004\FILE0007.CHK C:\FOUND.004\FILE0008.CHK C:\FOUND.004\FILE0009.CHK C:\FOUND.004\FILE0010.CHK C:\FOUND.004\FILE0011.CHK C:\FOUND.004\FILE0012.CHK C:\FOUND.004\FILE0013.CHK C:\FOUND.004\FILE0014.CHK C:\FOUND.004\FILE0015.CHK C:\FOUND.004\FILE0016.CHK C:\FOUND.004\FILE0017.CHK C:\FOUND.004\FILE0018.CHK . ((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 ))))))))))))))))))))))))))))))) . 2008-07-31 21:31 . 2008-07-31 21:31 <DIR> d-------- C:\PenClean 2008-07-30 16:30 . 2008-07-30 16:30 <DIR> d-------- C:\ComboFix 2008-07-30 14:37 . 2008-07-30 14:37 <DIR> d-------- C:\Lop SD 2008-07-30 14:36 . 2008-07-30 14:36 450,109 --a------ C:\LopSD.exe 2008-07-29 10:44 . 2008-07-29 10:44 230 --a------ C:\WINDOWS\system32\spupdsvc.inf 2008-07-29 09:39 . 2008-07-29 09:39 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-29 08:24 . 2008-07-29 08:24 <DIR> d-------- C:\NoLopBackups 2008-07-28 11:11 . 2008-07-31 22:05 324 --a------ C:\Shortcut to My Documents.lnk 2008-07-21 12:11 . 2008-07-21 12:11 <DIR> d-------- C:\Program Files\Safari 2008-07-21 11:53 . 2008-07-21 11:53 <DIR> d-------- C:\Program Files\QuickTime 2008-07-15 23:04 . 2008-07-15 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2008-07-13 16:00 . 2008-07-13 16:00 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-13 15:36 . 2008-07-13 15:36 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\AVGTOOLBAR 2008-07-13 15:36 . 2008-07-15 08:39 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-13 15:36 . 2008-07-13 15:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old 2008-07-13 15:36 . 2008-07-15 08:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-13 15:34 . 2008-07-13 15:36 262,144 --a------ C:\Documents and Settings\ADMINI~4 2008-07-13 14:00 . 2008-07-13 14:00 47,787,248 --a------ C:\14656_avg_antivirus_free_80100.exe 2008-07-13 12:22 . 2008-07-13 12:22 4,780,368 --a------ C:\MsgPlusLive-460.exe 2008-07-13 12:05 . 2008-07-13 12:05 2,403,344 --a------ C:\WLinstaller.exe 2008-07-13 09:58 . 2008-07-13 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8 2008-07-13 09:58 . 2008-07-13 09:58 262,144 --a------ C:\Documents and Settings\ADMINI~3 2008-07-13 09:54 . 2008-07-13 09:54 262,144 --a------ C:\Documents and Settings\ADMINI~2 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Program Files\uTorrent 2008-07-12 16:18 . 2008-07-12 16:18 <DIR> d-------- C:\Documents and Settings\Nataly Lopes\Application Data\uTorrent . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-24 19:14 --------- d-----w C:\Program Files\Microsoft Works 2008-06-24 19:13 --------- d-----w C:\Program Files\Microsoft.NET 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-19 01:23 --------- d-----w C:\Documents and Settings\Nataly Lopes\Application Data\SSH 2008-06-19 01:22 --------- d-----w C:\Program Files\SSH Communications Security 2008-06-17 15:51 --------- d-----w C:\Program Files\AVG 2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys 2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll 2008-02-24 19:10 251 ----a-w C:\Program Files\wt3d.ini 2007-01-16 22:49 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT . ((((((((((((((((((((((((((((( snapshot@2008-07-30_18.57.47.82 ))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 20:00 208952] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56 64512] "SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-06-27 23:54 16248320 C:\WINDOWS\RTHDCPL.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GbPluginBb"="C:\PROGRA~1\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 20:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\PROGRAM FILES\GBPLUGIN\gbieh.dll" [2008-04-15 09:37 378696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2008-04-15 09:37 378696 C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer Empowering Technology.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Nataly Lopes^Start Menu^Programs^Startup^LimeWire On Startup.lnk] path=C:\Documents and Settings\Nataly Lopes\Start Menu\Programs\Startup\LimeWire On Startup.lnk backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer ePresentation HPD] --a------ 2006-03-31 16:39 204800 C:\Acer\Empowering Technology\ePresentation\ePresentation.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] --a------ 2006-05-10 11:12 90112 C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY] --a------ 2008-07-15 08:39 1232152 C:\PROGRA~1\AVG\AVG8\avgtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel] --------- 2006-04-14 22:35 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boot] --a------ 2006-03-15 22:12 579584 C:\Acer\Empowering Technology\ePower\Boot.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-10 20:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ePower_DMC] --a------ 2006-05-30 12:11 421888 C:\Acer\Empowering Technology\ePower\ePower_DMC.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService] --a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager] --a------ 2006-06-23 06:59 602112 C:\PROGRA~1\LAUNCH~1\LManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002] --a------ 2004-08-10 20:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync] --a------ 2004-08-10 20:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-03-03 13:07 761946 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] -ra------ 2006-03-30 16:45 313472 c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\System32\\rtcshare.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "12906:TCP"= 12906:TCP:NortonAV "12246:TCP"= 12246:TCP:NortonAV "13054:TCP"= 13054:TCP:NortonAV "13615:TCP"= 13615:TCP:NortonAV "16921:TCP"= 16921:TCP:NortonAV "16448:TCP"= 16448:TCP:NortonAV "18072:TCP"= 18072:TCP:NortonAV "14289:TCP"= 14289:TCP:NortonAV "18236:TCP"= 18236:TCP:NortonAV "17716:TCP"= 17716:TCP:NortonAV "16499:TCP"= 16499:TCP:NortonAV "13614:TCP"= 13614:TCP:NortonAV "15771:TCP"= 15771:TCP:NortonAV "12826:TCP"= 12826:TCP:NortonAV "17920:TCP"= 17920:TCP:NortonAV "18169:TCP"= 18169:TCP:NortonAV "12225:TCP"= 12225:TCP:NortonAV "15538:TCP"= 15538:TCP:NortonAV "17800:TCP"= 17800:TCP:NortonAV "15248:TCP"= 15248:TCP:NortonAV "13460:TCP"= 13460:TCP:NortonAV "14692:TCP"= 14692:TCP:NortonAV "12992:TCP"= 12992:TCP:NortonAV "13451:TCP"= 13451:TCP:NortonAV "15587:TCP"= 15587:TCP:NortonAV "14010:TCP"= 14010:TCP:NortonAV "18590:TCP"= 18590:TCP:NortonAV "14344:TCP"= 14344:TCP:NortonAV "14495:TCP"= 14495:TCP:NortonAV "13352:TCP"= 13352:TCP:NortonAV "15965:TCP"= 15965:TCP:NortonAV "17150:TCP"= 17150:TCP:NortonAV "18255:TCP"= 18255:TCP:NortonAV "16963:TCP"= 16963:TCP:NortonAV "14939:TCP"= 14939:TCP:NortonAV "16279:TCP"= 16279:TCP:NortonAV "13122:TCP"= 13122:TCP:NortonAV "13437:TCP"= 13437:TCP:NortonAV "13954:TCP"= 13954:TCP:NortonAV "14221:TCP"= 14221:TCP:NortonAV "16577:TCP"= 16577:TCP:NortonAV "14580:TCP"= 14580:TCP:NortonAV "14908:TCP"= 14908:TCP:NortonAV "16930:TCP"= 16930:TCP:NortonAV "14196:TCP"= 14196:TCP:NortonAV "17932:TCP"= 17932:TCP:NortonAV S1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 08:39] S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 08:39] S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;C:\WINDOWS\system32\eLock2BurnerLockDriver.sys [] S2 eLock2FSCTLDriver;eLock2FSCTLDriver;C:\WINDOWS\system32\eLock2FSCTLDriver.sys [] . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-31 23:36:12 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-31 23:39:09 - machine was rebooted ComboFix-quarantined-files.txt 2008-08-01 02:39:02 ComboFix3.txt 2008-07-30 22:00:58 ComboFix2.txt 2008-07-31 00:51:56 Pre-Run: 9,721,692,160 bytes free Post-Run: 9,707,552,768 bytes free 252 --- E O F --- 2008-07-31 02:06:29 Logfile of HijackThis v1.99.1 Scan saved at 23:39:51, on 31/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Nataly Lopes\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\RunOnce: [ GbPluginBb] RunDll32.exe C:\PROGRA~1\GBPLUGIN\gbieh.dll,Gbieh O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.76\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.76\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: GbPluginBb - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\PROGRA~1\GbPlugin\GbpSv.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 1, 2008 Bom Dia! GBruno <@> No Executar,digite: ComboFix.exe /u --> Clique: OK <@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação! -------------------------- <!> Os logs estão limpos! :thumbsup: <!> Caso,ainda,tenha problemas de lentidão,sugiro que faça manutenção do computador. -------------------------- <@> Faça o download do TuneUp Utilities 2008. <@> Para baixar,digite o seu E-Mail e clique em Start download. <@> Salve o executável: TU2008TrialEN.exe,em Arquivos de Programas. <@> O programa é Trial,mas...haverá tempo suficiente,para a otimização do computador. <@> Procure desfragmentar o Disco e Registro. <@> Posteriormente voçê descobrirá que este utilitário realizará outras funções,que são úteis ao computador. -------------------------- <!> Bom trabalho! <!> Log limpo! ( HJT ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GBruno 0 Denunciar post Postado Agosto 1, 2008 Bom dia, DigRam! Sim, o PC ainda está um pouco lento, mas irei rodar o TuneUp. Muito obrigado mesmo pela ajuda!! :thumbsup: Abraços!! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 1, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico. Compartilhar este post Link para o post Compartilhar em outros sites