Noxe 0 Denunciar post Postado Agosto 1, 2008 Boas a todos antes mais queria pedir desculpa porque de certeza que nao é aqui que se posta isto mas estou mesmo a precisar de ajuda por iso se nao for aqui o lugar indicado os moderadores que mudem sff. Em relacao ao meu problema é o seguinte devo ter clicado em algum sitio ou ter feito algum download que me alterou o pc deixado muito lento, quando estou a navegar o internet explorer abre paginas de publicidade sozinho. Ja passei o anti-virus acusou só alguns trojans. Andei a ver na net e encontrei o vosso forum utilizei o programa hijackthis como diziam e keria postar aki o relatorio para verem. O anti virus que uso é o Kaspersky 2009. o meu pc é um P4 3.00 Ghz 1 GB de ram, geforce 8500 Gt 512 mb. Relatorio hijackthis http://www.hdd.pt/download/1186370059/hijackthis.log.html --------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:13:30, on 01-08-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\System32\cmd.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Programas\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Programas\Windows Live\Messenger\msnmsgr.exe C:\Programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Programas\Internet Explorer\IEXPLORE.EXE C:\Programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\rundll32.exe C:\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [AVP] "C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" O4 - HKLM\..\Run: [cc9320b1] rundll32.exe "C:\WINDOWS\system32\hdylcpna.dll",b O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKLM\..\Policies\Explorer\Run: [sFJTc2FXvg] C:\WINDOWS\gxunqhwx.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1 O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll O21 - SSODL: UnknownCD - {6ba9e57b-996a-421f-9afa-d678cd75d8b7} - C:\WINDOWS\Installer\{6ba9e57b-996a-421f-9afa-d678cd75d8b7}\UnknownCD.dll (file missing) O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing) O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe -- End of file - 6587 bytes Espero que me ajudem e mais uma vez peço desculpa mas é um pouco urgente Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 1, 2008 Bom Dia! Noxe <@> Baixe: < ComboFix > <@> Salve-o no Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e Firewall.( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.Salve-a no Desktop,renomeada como: Kombo.exe Ps: Nomeie durante o salvamento,e não após salvá-la! Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança. <@> Abrirá a janela Auto Scan. Aguarde! <@> Digite a opção para continuar e < Enter > <@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado! <@> Para parar ou sair do ComboFix,tecle "N". ------------------------- <@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 1, 2008 Boas fiz tudo como disse aqui esta o relatorio ComboFix 08-07-31.06 - Bruno 2008-08-01 22:14:55.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.653 [GMT 1:00] Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Bruno\Ambiente de trabalhoblackbird.jpg C:\Documents and Settings\Bruno\Ambiente de trabalhoEditorFKWP1.5.exe C:\Documents and Settings\Bruno\Ambiente de trabalhoEditorFKWP2.0.exe C:\Documents and Settings\Bruno\Ambiente de trabalhofilemanagerclient.exe C:\Documents and Settings\Bruno\Ambiente de trabalhofkwp1.5.exe C:\Documents and Settings\Bruno\Ambiente de trabalhofkwp2.0.exe C:\Documents and Settings\Bruno\Ambiente de trabalhofwebd.exe C:\Documents and Settings\Bruno\Ambiente de trabalhoFWebdEditor.exe C:\Documents and Settings\Bruno\Ambiente de trabalhoTrojan.Win32.BlackBird.exe C:\Documents and Settings\Bruno\Ambiente de trabalhovirii C:\Documents and Settings\Bruno\Application Data\Anti-Virus-Pro.com C:\Programas\PCHealthCenter C:\Programas\PCHealthCenter\0.exe C:\Programas\PCHealthCenter\0.gif C:\Programas\PCHealthCenter\1.exe C:\Programas\PCHealthCenter\1.gif C:\Programas\PCHealthCenter\2.exe C:\Programas\PCHealthCenter\2.gif C:\Programas\PCHealthCenter\3.exe C:\Programas\PCHealthCenter\3.gif C:\Programas\PCHealthCenter\5.exe C:\Programas\PCHealthCenter\sex1.ico C:\Programas\PCHealthCenter\sex2.ico C:\WINDOWS\BMcfa0132d.txt C:\WINDOWS\BMcfa0132d.xml C:\WINDOWS\cookies.ini C:\WINDOWS\Installer\{6ba9e57b-996a-421f-9afa-d678cd75d8b7}\UnknownCD.dll C:\WINDOWS\mslagent C:\WINDOWS\pskt.ini C:\WINDOWS\Sys10.exe C:\WINDOWS\Sys11.exe C:\WINDOWS\SysF.exe C:\WINDOWS\system32\dacovgdb.ini C:\WINDOWS\system32\hjkkj.ini2 C:\WINDOWS\system32\hjkmp.ini C:\WINDOWS\system32\hjkmp.ini2 C:\WINDOWS\system32\ijkkdigh.ini C:\WINDOWS\system32\jhofswta.ini C:\WINDOWS\system32\ljympk.dll C:\WINDOWS\system32\msgb.dll C:\WINDOWS\system32\mWxbayxx.ini C:\WINDOWS\system32\mWxbayxx.ini2 C:\WINDOWS\system32\packet.dll C:\WINDOWS\system32\pguycc.dll C:\WINDOWS\system32\qpgril.bmp C:\WINDOWS\system32\sex2.ico C:\WINDOWS\system32\shpiuptf.ini C:\WINDOWS\system32\shpiuptf.ini2 C:\WINDOWS\system32\tpthouba.ini C:\WINDOWS\system32\uddwnvju.ini C:\WINDOWS\system32\uddwnvju.ini2 C:\WINDOWS\system32\uddwnvju.tmp C:\WINDOWS\system32\vav.cpl C:\WINDOWS\system32\wpcap.dll C:\WINDOWS\system32\wsun32.dll C:\WINDOWS\system32\xjtugghq.ini C:\WINDOWS\system32\xxxryvpq.dll C:\WINDOWS\system32\xxyabxWm.dll C:\WINDOWS\system32\yxxqhtgx.ini C:\WINDOWS\system32akttzn.exe C:\WINDOWS\system32anticipator.dll C:\WINDOWS\system32awtoolb.dll C:\WINDOWS\system32bdn.com C:\WINDOWS\system32bsva-egihsg52.exe C:\WINDOWS\system32dpcproxy.exe C:\WINDOWS\system32emesx.dll C:\WINDOWS\system32h@tkeysh@@k.dll C:\WINDOWS\system32hoproxy.dll C:\WINDOWS\system32hxiwlgpm.dat C:\WINDOWS\system32hxiwlgpm.exe C:\WINDOWS\system32medup012.dll C:\WINDOWS\system32medup020.dll C:\WINDOWS\system32msgp.exe C:\WINDOWS\system32msnbho.dll C:\WINDOWS\system32mssecu.exe C:\WINDOWS\system32msvchost.exe C:\WINDOWS\system32mtr2.exe C:\WINDOWS\system32mwin32.exe C:\WINDOWS\system32netode.exe C:\WINDOWS\system32newsd32.exe C:\WINDOWS\system32ps1.exe C:\WINDOWS\system32psof1.exe C:\WINDOWS\system32psoft1.exe C:\WINDOWS\system32regc64.dll C:\WINDOWS\system32regm64.dll C:\WINDOWS\system32Rundl1.exe C:\WINDOWS\system32smp C:\WINDOWS\system32smp\msrc.exe C:\WINDOWS\system32sncntr.exe C:\WINDOWS\system32ssurf022.dll C:\WINDOWS\system32ssvchost.com C:\WINDOWS\system32ssvchost.exe C:\WINDOWS\system32sysreq.exe C:\WINDOWS\system32taack.dat C:\WINDOWS\system32taack.exe C:\WINDOWS\system32temp#01.exe C:\WINDOWS\system32thun.dll C:\WINDOWS\system32thun32.dll C:\WINDOWS\system32VBIEWER.OCX C:\WINDOWS\system32vbsys2.dll C:\WINDOWS\system32vcatchpi.dll C:\WINDOWS\system32winlogonpc.exe C:\WINDOWS\system32winsystem.exe C:\WINDOWS\system32WINWGPX.EXE . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NPF -------\Service_new_drv -------\Service_NPF ((((((((((((((((((((((( Ficheiros criados de 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))) . 2008-08-01 22:57 . 2008-08-01 22:57 294 ---hs---- C:\WINDOWS\system32\jhofswta.ini 2008-08-01 22:04 . 2008-08-01 22:04 99,712 --a------ C:\WINDOWS\system32\atwsfohj.dll 2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\tdpolidk.dll 2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\ilugcf.dll 2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\yexwgtll.dll 2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\pjwktx.dll 2008-08-01 14:10 . 2008-08-01 14:13 <DIR> d-------- C:\HiJackThis 2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp 2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO 2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack 2008-07-30 18:49 . 2008-07-30 19:01 96,559 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-07-30 18:49 . 2008-07-30 19:01 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-07-30 18:47 . 2008-08-01 22:41 3,279,392 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-30 18:47 . 2008-08-01 22:56 335,904 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-07-30 18:47 . 2008-08-01 22:41 26,700 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-07-30 18:47 . 2008-08-01 22:57 2,256 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-07-30 17:47 . 2008-07-30 17:47 99,712 --a------ C:\WINDOWS\system32\divhidtv.dll 2008-07-30 17:44 . 2008-07-30 17:44 99,712 --a------ C:\WINDOWS\system32\bxnusres.dll 2008-07-30 16:49 . 2008-07-30 16:49 99,712 --a------ C:\WINDOWS\system32\rtgmpehj.dll 2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat 2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword 2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4 2008-07-29 11:39 . 2008-07-31 23:13 <DIR> d-------- C:\Programas\Everest Poker 2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade 2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi 2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-01 21:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-08-01 12:13 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent 2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent 2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab 2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files 2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live 2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire 2008-07-29 21:58 --------- d-----w C:\Programas\DAP 2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire 2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire 2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games 2008-07-23 10:41 --------- d-----w C:\Programas\Java 2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series 2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real 2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire 2008-07-01 17:11 --------- d--h--w C:\Programas\InstallShield Installation Information 2008-06-28 12:11 --------- d-----w C:\Programas\Real 2008-06-19 14:22 --------- d-----w C:\Programas\TI Education 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx 2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard 2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3 2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech 2008-06-10 11:01 --------- d-----w C:\Programas\Logitech 2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution 2008-03-25 00:14 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll 2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys . ------- Sigcheck ------- 2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe 2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e}] 2008-08-01 22:02 129920 --a------ C:\WINDOWS\system32\ilugcf.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360] "DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856] "msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568] "SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472] "NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648] "Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344] "cc9320b1"="C:\WINDOWS\system32\atwsfohj.dll" [2008-08-01 22:04 99712] "AVP"="C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992] "RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "AllowLegacyWebView"= 1 (0x1) "AllowUnhashedWebView"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-06-29 06:24 286720 C:\Programas\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programas\\BT Next Evolution\\btnext.exe"= "C:\\Programas\\Messenger\\msmsgs.exe"= "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programas\\uTorrent\\uTorrent.exe"= "C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"= "C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"= "C:\\RF PoA\\RF Online\\RF.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "13000:TCP"= 13000:TCP:btnext R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29] R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07] R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37] S2 Anyplace Control Security;Anyplace Control Security;C:\WINDOWS\svcadmin.exe [] S3 ServicoMonitoring;NET Monitoring;c:\netmonit\abrir.exe [2007-09-19 23:50] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] \Shell\AutoRun\command - D:\autorun.exe . Conte£do da pasta 'Tarefas Agendadas' 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programas\Apple Software Update\SoftwareUpdate.exe [] 2008-07-31 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job - C:\Programas\RegistrySmart\RegistrySmart.exe [] 2008-07-31 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job - C:\Programas\RegistrySmart [] 2008-08-01 C:\WINDOWS\Tasks\started.job - c:\autoexec.bat [2008-01-27 11:54] . - - - - ORFAOS REMOVIDOS - - - - BHO-{FBF85A20-FF88-4C46-90FB-B023E5C4ECA0} - C:\WINDOWS\system32\iifCVOFX.dll HKLM-Explorer_Run-SFJTc2FXvg - C:\WINDOWS\gxunqhwx.exe ShellExecuteHooks-{FBF85A20-FF88-4C46-90FB-B023E5C4ECA0} - C:\WINDOWS\system32\iifCVOFX.dll Notify-iifCVOFX - iifCVOFX.dll MSConfigStartUp-AVP - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe MSConfigStartUp-cc9320b1 - C:\WINDOWS\system32\ujvnwddu.dll . ------- Ccan Suplementar ------- . FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/ ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-01 22:57:06 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... C:\WINDOWS\system32\jhofswta.ini 1382137 bytes Varredura completada com sucesso Ficheiros ocultos: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\e67gdfg] "ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds" . --------------------- DLLs Carregadas Sob os Processos em Execu‡ao --------------------- PROCESSOS: C:\WINDOWS\explorer.exe -> C:\WINDOWS\system32\atwsfohj.dll . ------------------------ Outros Processos em Execu‡Æo ------------------------ . C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\Programas\Ficheiros comuns\Logitech\LVMVFM\LVPrcSrv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\Programas\Lexmark X1100 Series\lxbkbmon.exe C:\WINDOWS\system32\verclsid.exe . ************************************************************************** . Tempo para conclusÆo: 2008-08-01 23:00:38 - Maquina reiniciou ComboFix-quarantined-files.txt 2008-08-01 22:00:34 Pre-Run: 13,861,433,344 bytes livres Post-Run: 21,029,838,848 bytes livres 319 --- E O F --- 2008-05-15 20:56:13 Fico aguardando uma resposta E obrigado por atender á minha questao Abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 2, 2008 Bom Dia! Noxe ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! <!> Para a segurança do PC,vamos providenciar a instalação do Console de Recuperação. ------------------------ <!> Vá ao site da Microsoft: < Link > <!> Selecione o download,que seja adequado,ao seu Sistema Operacional! <!> Faça o download,do arquivo,e salve-o no seu desktop. <!> Feche todos os programas,que estejam abertos! <!> Feche,também,seus programas de proteção! ( Antivírus,Antispywares e Firewall ) <!> Arraste o setup,baixado do site da Microsoft,para o interior do ComboFix.exe <!> Veja,abaixo,a demonstração! <!> Siga as mensagens que aparecem na tela,para iniciar o ComboFix. <!> Aceite o contrato da Microsoft,para instalar o "Console de Recuperação da Microsoft". <!> Na próxima mensagem,clique em "Yes",para realizar um scan com o ComboFix. <!> Terminando,poste os relatórios: <!> C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 2, 2008 Boas fiz tudo como disse nao sei bem é o segundo passo porque a imagem nao se ve mas arastei o programa da console para o combofix e resultou bem aceitei tudo e aqui esta o relatorio: ComboFix 08-07-31.06 - Bruno 2008-08-02 12:00:20.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.686 [GMT 1:00] Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe Command switches used :: C:\Documents and Settings\Bruno\Ambiente de trabalho\WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\jhofswta.ini . ((((((((((((((((((((((( Ficheiros criados de 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))) . 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\NetworkService\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\LocalService\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Bruno\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Administrador\Definiþ§es locais 2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\tdpolidk.dll 2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\ilugcf.dll 2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\yexwgtll.dll 2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\pjwktx.dll 2008-08-01 14:10 . 2008-08-01 14:13 <DIR> d-------- C:\HiJackThis 2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp 2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO 2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack 2008-07-30 18:49 . 2008-07-30 19:01 96,559 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-07-30 18:49 . 2008-07-30 19:01 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-07-30 18:47 . 2008-08-02 11:56 3,408,416 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-30 18:47 . 2008-08-02 11:56 385,056 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-07-30 18:47 . 2008-08-02 11:56 27,708 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-07-30 18:47 . 2008-08-02 11:56 2,396 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-07-30 17:47 . 2008-07-30 17:47 99,712 --a------ C:\WINDOWS\system32\divhidtv.dll 2008-07-30 17:44 . 2008-07-30 17:44 99,712 --a------ C:\WINDOWS\system32\bxnusres.dll 2008-07-30 16:49 . 2008-07-30 16:49 99,712 --a------ C:\WINDOWS\system32\rtgmpehj.dll 2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat 2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword 2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4 2008-07-29 11:39 . 2008-08-01 23:14 <DIR> d-------- C:\Programas\Everest Poker 2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade 2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi 2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-02 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-08-01 23:22 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-08-01 23:22 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent 2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent 2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab 2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files 2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live 2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire 2008-07-29 21:58 --------- d-----w C:\Programas\DAP 2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire 2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire 2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games 2008-07-23 10:41 --------- d-----w C:\Programas\Java 2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-07-16 18:51 2,041,363 ----a-w C:\WINDOWS\system32\x264vfw.dll 2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series 2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real 2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire 2008-07-01 17:11 --------- d--h--w C:\Programas\InstallShield Installation Information 2008-06-28 12:11 --------- d-----w C:\Programas\Real 2008-06-19 14:22 --------- d-----w C:\Programas\TI Education 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx 2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard 2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3 2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech 2008-06-10 11:01 --------- d-----w C:\Programas\Logitech 2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution 2008-05-31 14:49 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll 2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll 2008-05-25 18:20 407,047 ----a-w C:\WINDOWS\system32\mioengine.exe 2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-03-25 00:14 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll 2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys . ------- Sigcheck ------- 2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe 2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e}] 2008-08-01 22:02 129920 --a------ C:\WINDOWS\system32\ilugcf.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360] "DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856] "msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568] "SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472] "NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648] "Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344] "AVP"="C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992] "QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2007-06-29 06:24 286720] "RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "AllowLegacyWebView"= 1 (0x1) "AllowUnhashedWebView"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programas\\BT Next Evolution\\btnext.exe"= "C:\\Programas\\Messenger\\msmsgs.exe"= "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programas\\uTorrent\\uTorrent.exe"= "C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"= "C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"= "C:\\RF PoA\\RF Online\\RF.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "13000:TCP"= 13000:TCP:btnext [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] \Shell\AutoRun\command - D:\autorun.exe *Newly Created Service* - CATCHME . Conteúdo da pasta 'Tarefas Agendadas' 2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Programas\Apple Software Update\SoftwareUpdate.exe [] 2008-08-02 C:\WINDOWS\Tasks\started.job - c:\autoexec.bat [2008-01-27 11:54] . - - - - ORFAOS REMOVIDOS - - - - HKLM-Run-cc9320b1 - C:\WINDOWS\system32\atwsfohj.dll . ------- Ccan Suplementar ------- . FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/ ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-02 12:17:34 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Htƒž [936] 0x7C920738 Htƒž [936] 0x86C517C8 Htƒž [936] 0xBA353CDC Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet002\Services\e67gdfg] "ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds" . Tempo para conclusão: 2008-08-02 12:46:15 ComboFix-quarantined-files.txt 2008-08-02 11:45:08 ComboFix2.txt 2008-08-01 22:00:40 Pre-Run: 20,885,147,648 bytes livres Post-Run: 20,883,718,144 bytes livres WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 196 --- E O F --- 2008-05-15 20:56:13 Depois usei o hijackthis e esta aqui o relatorio: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:04:47, on 02-08-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\System32\cmd.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Programas\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: {e533e479-96cd-f799-dc84-3ec86a5c2c76} - {67c2c5a6-8ce3-48cd-997f-dc69974e335e} - C:\WINDOWS\system32\ilugcf.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [AVP] "C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1 O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing) O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe -- End of file - 6075 bytes Aguardo por resposta obrigado e abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 2, 2008 Bom Dia! Noxe >@< Configure o Windows à mostrar,pastas e arquivos ocultos. >@< Vá em Iniciar >> Painel de controle >> Opções de pasta. >@< Clique na aba: Modo de exibição. >@< Nas Configurações Avançadas,vá em Pastas e arquivos ocultos. >@< Marque o botão: Mostrar pastas e arquivos ocultos >> Aplicar >> Ok. ----------------------- <@> Vá a este Link,e baixe: < Malwarebytes > <@> Salve-o em Arquivos de Programa. <@> Atualize o Malwarebytes! <@> Escolha o escaneamento Completo! ( Full Scan ) <@> Desabilite programas de proteção,ao executar o malwarebytes. <!> Para maiores detalhes,leia o Tutorial: < Link > <@> Terminando,procure enviar os ficheiros detectados para a quarentena. <-- Importante! ----------------------- <@> Poste,os relatórios: <!> mbam.(..).txt + HijackThis,atualizado. <!> Ps: Pode ocultar,novamente,as pastas! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 2, 2008 Ja tinha essa opcao activada dos ficheiros ocultos, nao tenho nenhum pasta de arquivos de progamas crio uma? tenho é uma que se chama Programas é essa? é que eu sou portugues E ja agora o que é o mbam.(..).txt Abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 3, 2008 Boa Noite! Noxe Ja tinha essa opcao activada dos ficheiros ocultos, nao tenho nenhum pasta de arquivos de progamas crio uma? tenho é uma que se chama Programas é essa? é que eu sou portugues <!> Salve em Programas! ---------------------- E ja agora o que é o mbam.(..).txt <!> É o relatório do Malwarebytes! <!> Segundo o Tutorial,busque o relatório em: O programa guarda os logs das verificações feitas na pasta C:\Programas\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 3, 2008 Boas ja fiz tudo esta aqui os relatorios: Malwarebytes' Anti-Malware 1.24 Versão do banco de dados: 1018 Windows 5.1.2600 Service Pack 2 12:31:23 03-08-2008 mbam-log-8-3-2008 (12-31-23).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 115054 Tempo decorrido: 28 minute(s), 35 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 1 Chaves do Registo infectadas: 38 Valores do Registo infectados: 0 Ítens do Registo infectados: 0 Pastas infectadas: 3 Ficheiros infectados: 36 Processos da Memória infectados: (Nenhum item malicioso foi detectado) Módulos de Memória Infectados: C:\WINDOWS\system32\ilugcf.dll (Trojan.Vundo) -> Delete on reboot. Chaves do Registo infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{67c2c5a6-8ce3-48cd-997f-dc69974e335e} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07ef06d7-8ba8-4f5a-886b-84cc38fcdf5f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{10f07e10-ba78-4162-82e9-4caad2d18478} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{11df24a1-a106-4c7f-bf2c-f7d5411fe74e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2036b120-bd5d-4e50-b82f-d4d6d522f68e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{215f19fd-a509-4e03-958e-ea3b3f9b2ff9} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{280c7289-8caf-446a-98fe-c0f9217cee1e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2dd00c35-ae7f-4b96-912d-1a991b66f363} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2fa9e9a6-5956-4977-9bef-a067b996f96f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{305dbf41-6179-4d97-87a8-bb23b0ff74fe} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e755986-4cd0-4cfe-bfa5-23cdfd354288} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4463934e-005b-4b73-8881-9e58603b2dcb} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4f8252da-ddbd-4e3f-a84d-6d4ef8bacd4e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4fdbc56b-873e-4663-ae52-0a60f2bf2053} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{58da7d32-ce59-4e58-9b6e-295ed4986dd3} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{5e6ae9e1-1495-4ade-b94c-9416458f75b7} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6788fa7b-f9fb-4d97-a631-11171519ec47} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{68579fa8-3b04-49c1-9cc7-6f36f71e17dc} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{9f18caba-442d-4ab9-82f7-db4c7a93dc3c} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{afe2f1ad-488f-4845-8707-76b31e6aa7ff} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{bfe95ca1-4501-48e3-813d-ff5cbc335d0d} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{c6b25ff9-9788-4377-840f-e6990f990b56} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cd959f6a-3083-42cd-8b9a-e5a79897f071} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d0da99db-1661-464d-ad36-52f0d03b959f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d2bed334-77e8-47fe-b68c-ff7179114ee4} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d4b336b9-03d5-47df-984d-1135d4a10999} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{db29e08e-bc52-40a7-8099-0935d7dbee63} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e359a09a-6e50-4e21-8079-329efa21db86} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f14759bd-36b5-4c42-9451-00db471ab5c2} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fff85aa2-8c3e-43f5-934b-31eeab0258bc} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{ada69949-6704-425c-808e-cf86f5666aba} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\VAV (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. Valores do Registo infectados: (Nenhum item malicioso foi detectado) Ítens do Registo infectados: (Nenhum item malicioso foi detectado) Pastas infectadas: C:\Documents and Settings\Bruno\Application Data\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> Quarantined and deleted successfully. Ficheiros infectados: C:\WINDOWS\system32\ilugcf.dll (Trojan.Vundo) -> Delete on reboot. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127485.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127486.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127487.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127488.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127537.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127548.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127550.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127551.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127563.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127564.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127535.cpl (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\divhidtv.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pjwktx.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tdpolidk.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bxnusres.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rtgmpehj.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yexwgtll.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\twain_32\e67gdfg.ds (Backdoor.Rustok) -> Delete on reboot. C:\QooBox\Quarantine\C\Programas\PCHealthCenter\1.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\Programas\PCHealthCenter\2.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\Programas\PCHealthCenter\3.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\Programas\PCHealthCenter\5.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\Sys10.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\Sys11.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\SysF.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\ljympk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\vav.cpl.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\xxxryvpq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\xxyabxWm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_49_38 AM_593.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_49_49 AM_937.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_54_42 AM_781.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_54_52 AM_609.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Registry Backups\2008-01-27_10-51-49.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll (Trojan.Agent) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:42:22, on 03-08-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\System32\cmd.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Programas\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1 O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe -- End of file - 5550 bytes Fico aguardando abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 3, 2008 Bom Dia! Noxe <!> Limpe a quarentena do Malwarebytes. ----------------------- <!> Reinicie o computador,em Modo de Segurança. <!> Vá em Iniciar ->> Executar ->> Digite: cmd >> Clique em Ok. <!> Na janela DOS,que surgir,digite o que está sob o QUOTE. SC STOP "Anyplace Control Security " ->> Aperte Enter. SC DELETE "Anyplace Control Security " ->> Aperte Enter. exit ->> Aperte Enter. <!> Para cada linha digitada,aperte Enter. ----------------------- <!> Reinicie em Modo Normal. <!> Faça outro scan,com o ComboFix.exe,e poste o relatório. ( ComboFix.txt ) <-- Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 4, 2008 Boas quando escrevo o 1 comando no dos ele diz que o ficheiro nao se encontra instalado. Abraço Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 4, 2008 Boas quando escrevo o 1 comando no dos ele diz que o ficheiro nao se encontra instalado.Abraço ---------------------- Opa! Noxe Bom Dia! >@< Vá em Iniciar >> Executar >> Digite: services.msc >> Ok. >@< Localize: Anyplace Control Security . >@< Em,Tipo de inicialização,deixe: Desativado >@< Se estiver em Manual ou Automático,clique em Parar o serviço. >@< Abra o HijackThis,clique em: Open the misc tools section >@< Clique em: Delete an NT Service >@< Coloque o nome do Serviço: Anyplace Control Security ,na caixa. >@< Clique em Ok. >@< Reinicie o computador! >@< Faça um novo scan,com o ComboFix,e poste o relatório. --------------------- >@< Poste: ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 5, 2008 Aqui esta os relatorios ComboFix 08-07-31.06 - Bruno 2008-08-05 14:17:50.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.699 [GMT 1:00] Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe . ((((((((((((((((((((((( Ficheiros criados de 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))) . 2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Programas\Malwarebytes' Anti-Malware 2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Malwarebytes 2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-08-03 11:57 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-08-03 11:57 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-08-02 16:06 . 2008-08-02 16:06 <DIR> d-------- C:\Programas\Gabest 2008-08-02 15:01 . 2008-08-02 15:01 1,885,120 --a------ C:\Programas\mbam-setup.exe 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\NetworkService\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\LocalService\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Bruno\Definiþ§es locais 2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Administrador\Definiþ§es locais 2008-08-01 14:10 . 2008-08-05 14:13 <DIR> d-------- C:\HiJackThis 2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp 2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO 2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack 2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat 2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat 2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword 2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4 2008-07-29 11:39 . 2008-08-03 21:00 <DIR> d-------- C:\Programas\Everest Poker 2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade 2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi 2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-04 11:52 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-08-04 11:52 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-08-02 14:20 --------- d--h--w C:\Programas\InstallShield Installation Information 2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent 2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent 2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab 2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files 2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live 2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire 2008-07-29 21:58 --------- d-----w C:\Programas\DAP 2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire 2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire 2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games 2008-07-23 10:41 --------- d-----w C:\Programas\Java 2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-07-16 18:51 2,041,363 ----a-w C:\WINDOWS\system32\x264vfw.dll 2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series 2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real 2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire 2008-06-28 12:11 --------- d-----w C:\Programas\Real 2008-06-19 14:22 --------- d-----w C:\Programas\TI Education 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared 2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx 2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard 2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3 2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech 2008-06-10 11:01 --------- d-----w C:\Programas\Logitech 2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution 2008-05-31 14:49 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll 2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll 2008-05-25 18:20 407,047 ----a-w C:\WINDOWS\system32\mioengine.exe 2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys . ------- Sigcheck ------- 2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys 2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS 2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe 2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe . ((((((((((((((((((((((((((((( snapshot@2008-08-01_23.00.12.05 ))))))))))))))))))))))))))))))))))))))))) . - 2007-09-04 16:56:10 164,352 ----a-w C:\WINDOWS\system32\unrar.dll + 2002-10-15 22:54:04 153,088 ----a-w C:\WINDOWS\system32\unrar.dll + 2002-12-11 08:19:32 368,640 ----a-w C:\WINDOWS\system32\vobsub.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360] "DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856] "msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568] "SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784] "PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472] "NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648] "Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344] "QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2007-06-29 06:24 286720] "RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "AllowLegacyWebView"= 1 (0x1) "AllowUnhashedWebView"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.XFR1"= xfcodec.dll "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "VIDC.YV12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programas\\BT Next Evolution\\btnext.exe"= "C:\\Programas\\Messenger\\msmsgs.exe"= "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programas\\uTorrent\\uTorrent.exe"= "C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"= "C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"= "C:\\RF PoA\\RF Online\\RF.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"= "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"= "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "13000:TCP"= 13000:TCP:btnext S1 e67gdfg;e67gdfg;C:\WINDOWS\twain_32\e67gdfg.ds [] . Conteúdo da pasta 'Tarefas Agendadas' 2008-08-05 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job - C:\Programas\RegistrySmart\RegistrySmart.exe [] 2008-08-05 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job - C:\Programas\RegistrySmart [] . . ------- Ccan Suplementar ------- . FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/ ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-05 14:35:10 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet002\Services\e67gdfg] "ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds" . Tempo para conclusão: 2008-08-05 14:49:28 ComboFix-quarantined-files.txt 2008-08-05 13:48:29 ComboFix2.txt 2008-08-02 11:46:44 ComboFix3.txt 2008-08-01 22:00:40 Pre-Run: 19,909,971,968 bytes livres Post-Run: 20,007,518,208 bytes livres 172 --- E O F --- 2008-05-15 20:56:13 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:54:06, on 05-08-2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\System32\cmd.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\LVCOMSX.EXE C:\Programas\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\HiJackThis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe -- End of file - 5451 bytes Fico aguardando abraço :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 5, 2008 Boa Tarde! Noxe <!> Voçê,ainda,possui o Rustock rodando no PC! ( e67gdfg.ds ) < Rustock > <@> Baixe: < SDFix > <@> Salve-o no Disco Local-C e,descompacte-o aì mesmo. <@> Reinicie o computador em Modo de Segurança. <@> Dê um duplo clique em: < runThis.bat > <!> Caso uma janela abra e feche,repentinamente,adote as seguites medidas: <!> Vá em Iniciar >> Executar >> Digite ou cole: %systemdrive%\SDFix\apps\FixPath.exe /Q <!> Reinicie o computador e execute,novamente,o SDFix! <!> Caso não funcione,verifique a variável %comspec%. <!> Clique direito do mouse em Meu Computador >> Propriedades >> Avançadas. <!> Em: Variáveis do Ambiente >> Verifique se a variável ComSpec,tem o valor para o cmd.exe. <!> Valor: %SystemRoot%\system32\cmd.exe <@> Aperte o Y. <@> Aguarde a conclusão! <@> Terminando,aperte Enter.( ...ou,qualquer tecla!) <@> O computador será reiniciado! <@> Aguarde,ainda,a conclusão da limpeza. ------------------------ <@> Poste,na sua resposta,o relatório: Report.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Noxe 0 Denunciar post Postado Agosto 6, 2008 Aqui esta o relatorio SDFix: Version 1.213 Run by Bruno on 06-08-2008 at 13:37 Microsoft Windows XP [VersÆo 5.1.2600] Running From: C:\SDFix Checking Services : Name : e67gdfg Path : \??\C:\WINDOWS\twain_32\e67gdfg.ds e67gdfg - Deleted Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\-86277~1 - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-06 13:48:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Programas\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,.. "khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:46,d7,44,68,96,34,d0,d2,9c,87,4f,d4,5c,07,0f,8b,d9,8e,73,77,3d,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] "khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 "h0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Programas\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,.. "khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:41,d1,e9,e7,4d,44,de,7c,51,2a,e2,22,c8,73,ef,01,a0,e8,3b,9f,c1,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] "khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Programas\DAEMON Tools Lite\" "h0"=dword:00000000 "khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,.. "khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:41,d1,e9,e7,4d,44,de,7c,51,2a,e2,22,c8,73,ef,01,a0,e8,3b,9f,c1,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41] "khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,.. scanning hidden registry entries ... [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D22B9093-77E1-84ED-8FA9-1CEF0D6FF176}] "iahpogehfemcefhchg"=hex:6a,61,64,6d,63,64,68,68,6c,70,63,6a,63,62,64,6c,65,62,64,6d,00,.. "hanpeffomafoobpf"=hex:6a,61,64,6d,67,65,64,6f,67,6d,70,6e,61,70,65,6a,62,68,6b,68,00,.. "gagaialcbbhice"=hex:6b,61,64,6d,63,64,67,68,65,61,6b,70,64,67,6d,62,6b,61,6a,69,64,.. scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Programas\\BT Next Evolution\\btnext.exe"="C:\\Programas\\BT Next Evolution\\btnext.exe:*:Enabled:btnext" "C:\\Programas\\Messenger\\msmsgs.exe"="C:\\Programas\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"="C:\\Programas\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\Programas\\uTorrent\\uTorrent.exe"="C:\\Programas\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent" "C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe:*:Disabled:Nero ShowTime" "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB" "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"="C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe:*:Disabled:iw3mp(1.4cracked)" "C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Enabled:Football Manager 2008" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0" "C:\\RF PoA\\RF Online\\RF.exe"="C:\\RF PoA\\RF Online\\RF.exe:*:Enabled:RFLauncher" "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup" "C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare " "C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"="C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe:*:Enabled:THE SETTLERS - Rise of an Empire" "C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe:*:Enabled:Kaspersky Internet Security 2009 Setup" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Programas\\Windows Live\\Messenger\\livecall.exe"="C:\\Programas\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Fri 1 Aug 2008 1,382,275 A.SH. --- "C:\WINDOWS\system32\anpclydh.tmp" Sun 27 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Sun 27 Jan 2008 871,896 A.SH. --- "C:\Programas\True Sword 4\backuped\11\IEXPLORE.EXE" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT2.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT1.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT5.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2b7e61047c183e810714f3a963759d04\BIT4.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3ac8e349a4ba66571483f7d34d6d922c\BIT3.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\72f9fd1477d8323acfe21712c4d56121\BIT7.tmp" Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ce69a63a41543779f2e365a64b240c23\BIT6.tmp" Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT6.tmp" Finished! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 6, 2008 Boa Tarde! Noxe <@> No Executar,digite: ComboFix.exe /u --> Clique: OK <@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação! ----------------------- <!> Ps: Devido ao volume infectado,voçê terá que executar um escaneamento online! <!> O log do HijackThis,está praticamente,limpo! :thumbsup: ----------------------- >@< Faça um scan on line em: < Kaspersky > <!> Acesse o site,utilizando o IE e clique em: < > >@< Na próxima página,clique em: I Accept >@< Isto,para que se instale o controle activeX e,em seguida,atualize o banco de dados. >@< Na próxima página,clique em: My Computer e faça o scan. >@< Tenha paciência! Aguarde a atualização da base de dados,e o próprio exame que é demorado. >@< Terminando,salve e poste o relatório. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Setembro 8, 2008 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites