Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Noxe

[Arquivado] Problema com vírus

Recommended Posts

Boas a todos antes mais queria pedir desculpa porque de certeza que nao é aqui que se posta isto mas estou mesmo a precisar de ajuda por iso se nao for aqui o lugar indicado os moderadores que mudem sff.

Em relacao ao meu problema é o seguinte devo ter clicado em algum sitio ou ter feito algum download que me alterou o pc deixado muito lento, quando estou a navegar o internet explorer abre paginas de publicidade sozinho. Ja passei o anti-virus acusou só alguns trojans. Andei a ver na net e encontrei o vosso forum utilizei o programa hijackthis como diziam e keria postar aki o relatorio para verem.

O anti virus que uso é o Kaspersky 2009. o meu pc é um P4 3.00 Ghz 1 GB de ram, geforce 8500 Gt 512 mb.

 

Relatorio hijackthis

http://www.hdd.pt/download/1186370059/hijackthis.log.html

 

---------------------------

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:13:30, on 01-08-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\System32\cmd.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\spoolsv.exe

c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Programas\Java\jre1.6.0_07\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programas\Windows Live\Messenger\msnmsgr.exe

C:\Programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Programas\Internet Explorer\IEXPLORE.EXE

C:\Programas\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\rundll32.exe

C:\HiJackThis\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [AVP] "C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"

O4 - HKLM\..\Run: [cc9320b1] rundll32.exe "C:\WINDOWS\system32\hdylcpna.dll",b

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKLM\..\Policies\Explorer\Run: [sFJTc2FXvg] C:\WINDOWS\gxunqhwx.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1

O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll

O21 - SSODL: UnknownCD - {6ba9e57b-996a-421f-9afa-d678cd75d8b7} - C:\WINDOWS\Installer\{6ba9e57b-996a-421f-9afa-d678cd75d8b7}\UnknownCD.dll (file missing)

O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing)

O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe

 

--

End of file - 6587 bytes

 

Espero que me ajudem e mais uma vez peço desculpa mas é um pouco urgente

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Noxe

 

<@> Baixe: < ComboFix >

<@> Salve-o no Desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e Firewall.( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

 

Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

Salve-a no Desktop,renomeada como: Kombo.exe

Ps: Nomeie durante o salvamento,e não após salvá-la!

Ps: Caso ocorra alguma mensagem de erro,rode o ComboFix em Modo de Segurança.

<@> Abrirá a janela Auto Scan. Aguarde!

<@> Digite a opção para continuar e < Enter >

<@> Aguarde a conclusão! Durante o scan,evite tocar no mouse ou teclado!

<@> Para parar ou sair do ComboFix,tecle "N".

-------------------------

<@> Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boas fiz tudo como disse aqui esta o relatorio

 

ComboFix 08-07-31.06 - Bruno 2008-08-01 22:14:55.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.653 [GMT 1:00]

Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe

* Criado um novo ponto de restauro

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\Bruno\Ambiente de trabalhoblackbird.jpg

C:\Documents and Settings\Bruno\Ambiente de trabalhoEditorFKWP1.5.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhoEditorFKWP2.0.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhofilemanagerclient.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhofkwp1.5.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhofkwp2.0.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhofwebd.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhoFWebdEditor.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhoTrojan.Win32.BlackBird.exe

C:\Documents and Settings\Bruno\Ambiente de trabalhovirii

C:\Documents and Settings\Bruno\Application Data\Anti-Virus-Pro.com

C:\Programas\PCHealthCenter

C:\Programas\PCHealthCenter\0.exe

C:\Programas\PCHealthCenter\0.gif

C:\Programas\PCHealthCenter\1.exe

C:\Programas\PCHealthCenter\1.gif

C:\Programas\PCHealthCenter\2.exe

C:\Programas\PCHealthCenter\2.gif

C:\Programas\PCHealthCenter\3.exe

C:\Programas\PCHealthCenter\3.gif

C:\Programas\PCHealthCenter\5.exe

C:\Programas\PCHealthCenter\sex1.ico

C:\Programas\PCHealthCenter\sex2.ico

C:\WINDOWS\BMcfa0132d.txt

C:\WINDOWS\BMcfa0132d.xml

C:\WINDOWS\cookies.ini

C:\WINDOWS\Installer\{6ba9e57b-996a-421f-9afa-d678cd75d8b7}\UnknownCD.dll

C:\WINDOWS\mslagent

C:\WINDOWS\pskt.ini

C:\WINDOWS\Sys10.exe

C:\WINDOWS\Sys11.exe

C:\WINDOWS\SysF.exe

C:\WINDOWS\system32\dacovgdb.ini

C:\WINDOWS\system32\hjkkj.ini2

C:\WINDOWS\system32\hjkmp.ini

C:\WINDOWS\system32\hjkmp.ini2

C:\WINDOWS\system32\ijkkdigh.ini

C:\WINDOWS\system32\jhofswta.ini

C:\WINDOWS\system32\ljympk.dll

C:\WINDOWS\system32\msgb.dll

C:\WINDOWS\system32\mWxbayxx.ini

C:\WINDOWS\system32\mWxbayxx.ini2

C:\WINDOWS\system32\packet.dll

C:\WINDOWS\system32\pguycc.dll

C:\WINDOWS\system32\qpgril.bmp

C:\WINDOWS\system32\sex2.ico

C:\WINDOWS\system32\shpiuptf.ini

C:\WINDOWS\system32\shpiuptf.ini2

C:\WINDOWS\system32\tpthouba.ini

C:\WINDOWS\system32\uddwnvju.ini

C:\WINDOWS\system32\uddwnvju.ini2

C:\WINDOWS\system32\uddwnvju.tmp

C:\WINDOWS\system32\vav.cpl

C:\WINDOWS\system32\wpcap.dll

C:\WINDOWS\system32\wsun32.dll

C:\WINDOWS\system32\xjtugghq.ini

C:\WINDOWS\system32\xxxryvpq.dll

C:\WINDOWS\system32\xxyabxWm.dll

C:\WINDOWS\system32\yxxqhtgx.ini

C:\WINDOWS\system32akttzn.exe

C:\WINDOWS\system32anticipator.dll

C:\WINDOWS\system32awtoolb.dll

C:\WINDOWS\system32bdn.com

C:\WINDOWS\system32bsva-egihsg52.exe

C:\WINDOWS\system32dpcproxy.exe

C:\WINDOWS\system32emesx.dll

C:\WINDOWS\system32h@tkeysh@@k.dll

C:\WINDOWS\system32hoproxy.dll

C:\WINDOWS\system32hxiwlgpm.dat

C:\WINDOWS\system32hxiwlgpm.exe

C:\WINDOWS\system32medup012.dll

C:\WINDOWS\system32medup020.dll

C:\WINDOWS\system32msgp.exe

C:\WINDOWS\system32msnbho.dll

C:\WINDOWS\system32mssecu.exe

C:\WINDOWS\system32msvchost.exe

C:\WINDOWS\system32mtr2.exe

C:\WINDOWS\system32mwin32.exe

C:\WINDOWS\system32netode.exe

C:\WINDOWS\system32newsd32.exe

C:\WINDOWS\system32ps1.exe

C:\WINDOWS\system32psof1.exe

C:\WINDOWS\system32psoft1.exe

C:\WINDOWS\system32regc64.dll

C:\WINDOWS\system32regm64.dll

C:\WINDOWS\system32Rundl1.exe

C:\WINDOWS\system32smp

C:\WINDOWS\system32smp\msrc.exe

C:\WINDOWS\system32sncntr.exe

C:\WINDOWS\system32ssurf022.dll

C:\WINDOWS\system32ssvchost.com

C:\WINDOWS\system32ssvchost.exe

C:\WINDOWS\system32sysreq.exe

C:\WINDOWS\system32taack.dat

C:\WINDOWS\system32taack.exe

C:\WINDOWS\system32temp#01.exe

C:\WINDOWS\system32thun.dll

C:\WINDOWS\system32thun32.dll

C:\WINDOWS\system32VBIEWER.OCX

C:\WINDOWS\system32vbsys2.dll

C:\WINDOWS\system32vcatchpi.dll

C:\WINDOWS\system32winlogonpc.exe

C:\WINDOWS\system32winsystem.exe

C:\WINDOWS\system32WINWGPX.EXE

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_NPF

-------\Service_new_drv

-------\Service_NPF

 

 

((((((((((((((((((((((( Ficheiros criados de 2008-07-01 to 2008-08-01 ))))))))))))))))))))))))))))))))

.

 

2008-08-01 22:57 . 2008-08-01 22:57 294 ---hs---- C:\WINDOWS\system32\jhofswta.ini

2008-08-01 22:04 . 2008-08-01 22:04 99,712 --a------ C:\WINDOWS\system32\atwsfohj.dll

2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\tdpolidk.dll

2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\ilugcf.dll

2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\yexwgtll.dll

2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\pjwktx.dll

2008-08-01 14:10 . 2008-08-01 14:13 <DIR> d-------- C:\HiJackThis

2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp

2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO

2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack

2008-07-30 18:49 . 2008-07-30 19:01 96,559 --a------ C:\WINDOWS\system32\drivers\klin.dat

2008-07-30 18:49 . 2008-07-30 19:01 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat

2008-07-30 18:47 . 2008-08-01 22:41 3,279,392 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat

2008-07-30 18:47 . 2008-08-01 22:56 335,904 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat

2008-07-30 18:47 . 2008-08-01 22:41 26,700 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx

2008-07-30 18:47 . 2008-08-01 22:57 2,256 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx

2008-07-30 17:47 . 2008-07-30 17:47 99,712 --a------ C:\WINDOWS\system32\divhidtv.dll

2008-07-30 17:44 . 2008-07-30 17:44 99,712 --a------ C:\WINDOWS\system32\bxnusres.dll

2008-07-30 16:49 . 2008-07-30 16:49 99,712 --a------ C:\WINDOWS\system32\rtgmpehj.dll

2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat

2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword

2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4

2008-07-29 11:39 . 2008-07-31 23:13 <DIR> d-------- C:\Programas\Everest Poker

2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade

2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi

2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-01 21:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-08-01 12:13 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys

2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent

2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent

2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab

2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files

2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live

2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire

2008-07-29 21:58 --------- d-----w C:\Programas\DAP

2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire

2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire

2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games

2008-07-23 10:41 --------- d-----w C:\Programas\Java

2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys

2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series

2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real

2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire

2008-07-01 17:11 --------- d--h--w C:\Programas\InstallShield Installation Information

2008-06-28 12:11 --------- d-----w C:\Programas\Real

2008-06-19 14:22 --------- d-----w C:\Programas\TI Education

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx

2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard

2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3

2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech

2008-06-10 11:01 --------- d-----w C:\Programas\Logitech

2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution

2008-03-25 00:14 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll

2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys

.

 

------- Sigcheck -------

 

2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys

2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS

 

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe

2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e}]

2008-08-01 22:02 129920 --a------ C:\WINDOWS\system32\ilugcf.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360]

"DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856]

"msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568]

"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]

"NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]

"Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344]

"cc9320b1"="C:\WINDOWS\system32\atwsfohj.dll" [2008-08-01 22:04 99712]

"AVP"="C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992]

"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"AllowLegacyWebView"= 1 (0x1)

"AllowUnhashedWebView"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.XFR1"= xfcodec.dll

"msacm.l3fhg"= mp3fhg.acm

"msacm.divxa32"= divxa32.acm

"VIDC.X264"= x264vfw.dll

"VIDC.HFYU"= huffyuv.dll

"vidc.i263"= i263_32.drv

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

--a------ 2007-06-29 06:24 286720 C:\Programas\QuickTime\QTTask.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programas\\BT Next Evolution\\btnext.exe"=

"C:\\Programas\\Messenger\\msmsgs.exe"=

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programas\\uTorrent\\uTorrent.exe"=

"C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"C:\\WINDOWS\\system32\\PnkBstrA.exe"=

"C:\\WINDOWS\\system32\\PnkBstrB.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"=

"C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=

"C:\\RF PoA\\RF Online\\RF.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

"C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"13000:TCP"= 13000:TCP:btnext

 

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]

R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]

R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 15:37]

S2 Anyplace Control Security;Anyplace Control Security;C:\WINDOWS\svcadmin.exe []

S3 ServicoMonitoring;NET Monitoring;c:\netmonit\abrir.exe [2007-09-19 23:50]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - D:\autorun.exe

.

Conte£do da pasta 'Tarefas Agendadas'

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Programas\Apple Software Update\SoftwareUpdate.exe []

 

2008-07-31 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job

- C:\Programas\RegistrySmart\RegistrySmart.exe []

 

2008-07-31 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job

- C:\Programas\RegistrySmart []

 

2008-08-01 C:\WINDOWS\Tasks\started.job

- c:\autoexec.bat [2008-01-27 11:54]

.

- - - - ORFAOS REMOVIDOS - - - -

 

BHO-{FBF85A20-FF88-4C46-90FB-B023E5C4ECA0} - C:\WINDOWS\system32\iifCVOFX.dll

HKLM-Explorer_Run-SFJTc2FXvg - C:\WINDOWS\gxunqhwx.exe

ShellExecuteHooks-{FBF85A20-FF88-4C46-90FB-B023E5C4ECA0} - C:\WINDOWS\system32\iifCVOFX.dll

Notify-iifCVOFX - iifCVOFX.dll

MSConfigStartUp-AVP - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe

MSConfigStartUp-cc9320b1 - C:\WINDOWS\system32\ujvnwddu.dll

 

 

.

------- Ccan Suplementar -------

.

FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-01 22:57:06

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

 

C:\WINDOWS\system32\jhofswta.ini 1382137 bytes

 

Varredura completada com sucesso

Ficheiros ocultos: 1

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\e67gdfg]

"ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds"

.

--------------------- DLLs Carregadas Sob os Processos em Execu‡ao ---------------------

 

PROCESSOS: C:\WINDOWS\explorer.exe

-> C:\WINDOWS\system32\atwsfohj.dll

.

------------------------ Outros Processos em Execu‡Æo ------------------------

.

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\LEXPPS.EXE

C:\Programas\Ficheiros comuns\Logitech\LVMVFM\LVPrcSrv.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\rundll32.exe

C:\Programas\Lexmark X1100 Series\lxbkbmon.exe

C:\WINDOWS\system32\verclsid.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-08-01 23:00:38 - Maquina reiniciou

ComboFix-quarantined-files.txt 2008-08-01 22:00:34

 

Pre-Run: 13,861,433,344 bytes livres

Post-Run: 21,029,838,848 bytes livres

 

319 --- E O F --- 2008-05-15 20:56:13

 

 

Fico aguardando uma resposta

E obrigado por atender á minha questao

Abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Noxe

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

<!> Para a segurança do PC,vamos providenciar a instalação do Console de Recuperação.

------------------------

<!> Vá ao site da Microsoft: < Link >

 

<!> Selecione o download,que seja adequado,ao seu Sistema Operacional!

 

crecuperacaorz4.jpg

 

<!> Faça o download,do arquivo,e salve-o no seu desktop.

<!> Feche todos os programas,que estejam abertos!

<!> Feche,também,seus programas de proteção! ( Antivírus,Antispywares e Firewall )

<!> Arraste o setup,baixado do site da Microsoft,para o interior do ComboFix.exe

<!> Veja,abaixo,a demonstração!

 

rc1.gif

 

<!> Siga as mensagens que aparecem na tela,para iniciar o ComboFix.

<!> Aceite o contrato da Microsoft,para instalar o "Console de Recuperação da Microsoft".

<!> Na próxima mensagem,clique em "Yes",para realizar um scan com o ComboFix.

 

RC_whatnext.gif

 

<!> Terminando,poste os relatórios:

 

<!> C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boas fiz tudo como disse nao sei bem é o segundo passo porque a imagem nao se ve mas arastei o programa da console para o combofix e resultou bem aceitei tudo e aqui esta o relatorio:

 

ComboFix 08-07-31.06 - Bruno 2008-08-02 12:00:20.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.686 [GMT 1:00]

Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe

Command switches used :: C:\Documents and Settings\Bruno\Ambiente de trabalho\WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\system32\jhofswta.ini

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-07-02 to 2008-08-02 ))))))))))))))))))))))))))))))))

.

 

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\NetworkService\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\LocalService\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Bruno\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Administrador\Definiþ§es locais

2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\tdpolidk.dll

2008-08-01 22:02 . 2008-08-01 22:02 129,920 --a------ C:\WINDOWS\system32\ilugcf.dll

2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\yexwgtll.dll

2008-08-01 21:58 . 2008-08-01 21:58 129,920 --a------ C:\WINDOWS\system32\pjwktx.dll

2008-08-01 14:10 . 2008-08-01 14:13 <DIR> d-------- C:\HiJackThis

2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp

2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO

2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack

2008-07-30 18:49 . 2008-07-30 19:01 96,559 --a------ C:\WINDOWS\system32\drivers\klin.dat

2008-07-30 18:49 . 2008-07-30 19:01 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat

2008-07-30 18:47 . 2008-08-02 11:56 3,408,416 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat

2008-07-30 18:47 . 2008-08-02 11:56 385,056 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat

2008-07-30 18:47 . 2008-08-02 11:56 27,708 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx

2008-07-30 18:47 . 2008-08-02 11:56 2,396 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx

2008-07-30 17:47 . 2008-07-30 17:47 99,712 --a------ C:\WINDOWS\system32\divhidtv.dll

2008-07-30 17:44 . 2008-07-30 17:44 99,712 --a------ C:\WINDOWS\system32\bxnusres.dll

2008-07-30 16:49 . 2008-07-30 16:49 99,712 --a------ C:\WINDOWS\system32\rtgmpehj.dll

2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat

2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword

2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4

2008-07-29 11:39 . 2008-08-01 23:14 <DIR> d-------- C:\Programas\Everest Poker

2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade

2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi

2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-02 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

2008-08-01 23:22 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys

2008-08-01 23:22 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe

2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent

2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent

2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab

2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files

2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live

2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire

2008-07-29 21:58 --------- d-----w C:\Programas\DAP

2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire

2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire

2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games

2008-07-23 10:41 --------- d-----w C:\Programas\Java

2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys

2008-07-16 18:51 2,041,363 ----a-w C:\WINDOWS\system32\x264vfw.dll

2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series

2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real

2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire

2008-07-01 17:11 --------- d--h--w C:\Programas\InstallShield Installation Information

2008-06-28 12:11 --------- d-----w C:\Programas\Real

2008-06-19 14:22 --------- d-----w C:\Programas\TI Education

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx

2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard

2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll

2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3

2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech

2008-06-10 11:01 --------- d-----w C:\Programas\Logitech

2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution

2008-05-31 14:49 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll

2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll

2008-05-25 18:20 407,047 ----a-w C:\WINDOWS\system32\mioengine.exe

2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll

2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll

2008-03-25 00:14 118,784 ----a-w C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll

2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys

.

 

------- Sigcheck -------

 

2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys

2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS

 

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe

2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e}]

2008-08-01 22:02 129920 --a------ C:\WINDOWS\system32\ilugcf.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360]

"DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856]

"msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568]

"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]

"NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]

"Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344]

"AVP"="C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 18:21 201992]

"QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2007-06-29 06:24 286720]

"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"AllowLegacyWebView"= 1 (0x1)

"AllowUnhashedWebView"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.XFR1"= xfcodec.dll

"msacm.l3fhg"= mp3fhg.acm

"msacm.divxa32"= divxa32.acm

"VIDC.X264"= x264vfw.dll

"VIDC.HFYU"= huffyuv.dll

"vidc.i263"= i263_32.drv

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programas\\BT Next Evolution\\btnext.exe"=

"C:\\Programas\\Messenger\\msmsgs.exe"=

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programas\\uTorrent\\uTorrent.exe"=

"C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"C:\\WINDOWS\\system32\\PnkBstrA.exe"=

"C:\\WINDOWS\\system32\\PnkBstrB.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"=

"C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=

"C:\\RF PoA\\RF Online\\RF.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

"C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"13000:TCP"= 13000:TCP:btnext

 

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - D:\autorun.exe

 

*Newly Created Service* - CATCHME

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-07-28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Programas\Apple Software Update\SoftwareUpdate.exe []

 

2008-08-02 C:\WINDOWS\Tasks\started.job

- c:\autoexec.bat [2008-01-27 11:54]

.

- - - - ORFAOS REMOVIDOS - - - -

 

HKLM-Run-cc9320b1 - C:\WINDOWS\system32\atwsfohj.dll

 

 

.

------- Ccan Suplementar -------

.

FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-02 12:17:34

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Htƒž [936] 0x7C920738

Htƒž [936] 0x86C517C8

Htƒž [936] 0xBA353CDC

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\e67gdfg]

"ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds"

.

Tempo para conclusão: 2008-08-02 12:46:15

ComboFix-quarantined-files.txt 2008-08-02 11:45:08

ComboFix2.txt 2008-08-01 22:00:40

 

Pre-Run: 20,885,147,648 bytes livres

Post-Run: 20,883,718,144 bytes livres

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

 

196 --- E O F --- 2008-05-15 20:56:13

 

 

 

Depois usei o hijackthis e esta aqui o relatorio:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:04:47, on 02-08-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\System32\cmd.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Programas\Java\jre1.6.0_07\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\HiJackThis\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: {e533e479-96cd-f799-dc84-3ec86a5c2c76} - {67c2c5a6-8ce3-48cd-997f-dc69974e335e} - C:\WINDOWS\system32\ilugcf.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [AVP] "C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1

O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing)

O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programas\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe

 

--

End of file - 6075 bytes

 

 

Aguardo por resposta obrigado e abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Noxe

 

>@< Configure o Windows à mostrar,pastas e arquivos ocultos.

>@< Vá em Iniciar >> Painel de controle >> Opções de pasta.

>@< Clique na aba: Modo de exibição.

>@< Nas Configurações Avançadas,vá em Pastas e arquivos ocultos.

>@< Marque o botão: Mostrar pastas e arquivos ocultos >> Aplicar >> Ok.

-----------------------

<@> Vá a este Link,e baixe:

 

< Malwarebytes >

 

<@> Salve-o em Arquivos de Programa.

<@> Atualize o Malwarebytes!

<@> Escolha o escaneamento Completo! ( Full Scan )

<@> Desabilite programas de proteção,ao executar o malwarebytes.

 

<!> Para maiores detalhes,leia o Tutorial: < Link >

 

<@> Terminando,procure enviar os ficheiros detectados para a quarentena. <-- Importante!

-----------------------

<@> Poste,os relatórios:

 

<!> mbam.(..).txt + HijackThis,atualizado.

<!> Ps: Pode ocultar,novamente,as pastas!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ja tinha essa opcao activada dos ficheiros ocultos, nao tenho nenhum pasta de arquivos de progamas crio uma? tenho é uma que se chama Programas é essa? é que eu sou portugues

 

E ja agora o que é o mbam.(..).txt

 

Abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Noxe

 

Ja tinha essa opcao activada dos ficheiros ocultos, nao tenho nenhum pasta de arquivos de progamas crio uma? tenho é uma que se chama Programas é essa? é que eu sou portugues

<!> Salve em Programas!

----------------------

E ja agora o que é o mbam.(..).txt

<!> É o relatório do Malwarebytes!

<!> Segundo o Tutorial,busque o relatório em:

 

O programa guarda os logs das verificações feitas na pasta C:\Programas\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boas ja fiz tudo esta aqui os relatorios:

 

Malwarebytes' Anti-Malware 1.24

Versão do banco de dados: 1018

Windows 5.1.2600 Service Pack 2

 

12:31:23 03-08-2008

mbam-log-8-3-2008 (12-31-23).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 115054

Tempo decorrido: 28 minute(s), 35 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 1

Chaves do Registo infectadas: 38

Valores do Registo infectados: 0

Ítens do Registo infectados: 0

Pastas infectadas: 3

Ficheiros infectados: 36

 

Processos da Memória infectados:

(Nenhum item malicioso foi detectado)

 

Módulos de Memória Infectados:

C:\WINDOWS\system32\ilugcf.dll (Trojan.Vundo) -> Delete on reboot.

 

Chaves do Registo infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67c2c5a6-8ce3-48cd-997f-dc69974e335e} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{67c2c5a6-8ce3-48cd-997f-dc69974e335e} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{07ef06d7-8ba8-4f5a-886b-84cc38fcdf5f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{10f07e10-ba78-4162-82e9-4caad2d18478} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{11df24a1-a106-4c7f-bf2c-f7d5411fe74e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{2036b120-bd5d-4e50-b82f-d4d6d522f68e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{215f19fd-a509-4e03-958e-ea3b3f9b2ff9} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{280c7289-8caf-446a-98fe-c0f9217cee1e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{2dd00c35-ae7f-4b96-912d-1a991b66f363} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{2fa9e9a6-5956-4977-9bef-a067b996f96f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{305dbf41-6179-4d97-87a8-bb23b0ff74fe} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{3e755986-4cd0-4cfe-bfa5-23cdfd354288} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{4463934e-005b-4b73-8881-9e58603b2dcb} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{4f8252da-ddbd-4e3f-a84d-6d4ef8bacd4e} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{4fdbc56b-873e-4663-ae52-0a60f2bf2053} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{58da7d32-ce59-4e58-9b6e-295ed4986dd3} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{5e6ae9e1-1495-4ade-b94c-9416458f75b7} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{6788fa7b-f9fb-4d97-a631-11171519ec47} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{68579fa8-3b04-49c1-9cc7-6f36f71e17dc} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{9f18caba-442d-4ab9-82f7-db4c7a93dc3c} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{afe2f1ad-488f-4845-8707-76b31e6aa7ff} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{bfe95ca1-4501-48e3-813d-ff5cbc335d0d} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{c6b25ff9-9788-4377-840f-e6990f990b56} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{cd959f6a-3083-42cd-8b9a-e5a79897f071} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{d0da99db-1661-464d-ad36-52f0d03b959f} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{d2bed334-77e8-47fe-b68c-ff7179114ee4} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{d4b336b9-03d5-47df-984d-1135d4a10999} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{db29e08e-bc52-40a7-8099-0935d7dbee63} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{e359a09a-6e50-4e21-8079-329efa21db86} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{f14759bd-36b5-4c42-9451-00db471ab5c2} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{fff85aa2-8c3e-43f5-934b-31eeab0258bc} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{ada69949-6704-425c-808e-cf86f5666aba} (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\VAV (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Valores do Registo infectados:

(Nenhum item malicioso foi detectado)

 

Ítens do Registo infectados:

(Nenhum item malicioso foi detectado)

 

Pastas infectadas:

C:\Documents and Settings\Bruno\Application Data\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

 

Ficheiros infectados:

C:\WINDOWS\system32\ilugcf.dll (Trojan.Vundo) -> Delete on reboot.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127485.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127486.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127487.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127488.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127537.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127548.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127550.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127551.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127563.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127564.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{F09A8BA5-B23B-4A56-89E0-B0EC314DC392}\RP288\A0127535.cpl (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\divhidtv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\pjwktx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\tdpolidk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\bxnusres.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\rtgmpehj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\yexwgtll.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\twain_32\e67gdfg.ds (Backdoor.Rustok) -> Delete on reboot.

C:\QooBox\Quarantine\C\Programas\PCHealthCenter\1.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\Programas\PCHealthCenter\2.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\Programas\PCHealthCenter\3.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\Programas\PCHealthCenter\5.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\Sys10.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\Sys11.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\SysF.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\system32\ljympk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\system32\vav.cpl.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\system32\xxxryvpq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\QooBox\Quarantine\C\WINDOWS\system32\xxyabxWm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_49_38 AM_593.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_49_49 AM_937.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_54_42 AM_781.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Log\2008 Jan 27 - 10_54_52 AM_609.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\Bruno\Application Data\RegistrySmart\Registry Backups\2008-01-27_10-51-49.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Application Data\dkzonyfa.dll (Trojan.Agent) -> Quarantined and deleted successfully.

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:42:22, on 03-08-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\System32\cmd.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Programas\Java\jre1.6.0_07\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\HiJackThis\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1

O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe

 

--

End of file - 5550 bytes

 

Fico aguardando abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Noxe

 

<!> Limpe a quarentena do Malwarebytes.

-----------------------

<!> Reinicie o computador,em Modo de Segurança.

<!> Vá em Iniciar ->> Executar ->> Digite: cmd >> Clique em Ok.

<!> Na janela DOS,que surgir,digite o que está sob o QUOTE.

 

SC STOP "Anyplace Control Security " ->> Aperte Enter.

SC DELETE "Anyplace Control Security " ->> Aperte Enter.

exit ->> Aperte Enter.

<!> Para cada linha digitada,aperte Enter.

-----------------------

<!> Reinicie em Modo Normal.

<!> Faça outro scan,com o ComboFix.exe,e poste o relatório. ( ComboFix.txt ) <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boas quando escrevo o 1 comando no dos ele diz que o ficheiro nao se encontra instalado.

Abraço

----------------------

Opa! Noxe

Bom Dia!

 

>@< Vá em Iniciar >> Executar >> Digite: services.msc >> Ok.

>@< Localize: Anyplace Control Security .

>@< Em,Tipo de inicialização,deixe: Desativado

>@< Se estiver em Manual ou Automático,clique em Parar o serviço.

>@< Abra o HijackThis,clique em: Open the misc tools section

>@< Clique em: Delete an NT Service

>@< Coloque o nome do Serviço: Anyplace Control Security ,na caixa.

>@< Clique em Ok.

>@< Reinicie o computador!

>@< Faça um novo scan,com o ComboFix,e poste o relatório.

---------------------

>@< Poste: ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui esta os relatorios

 

ComboFix 08-07-31.06 - Bruno 2008-08-05 14:17:50.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.699 [GMT 1:00]

Executando de: C:\Documents and Settings\Bruno\Ambiente de trabalho\ComboFix.exe

.

 

((((((((((((((((((((((( Ficheiros criados de 2008-07-05 to 2008-08-05 ))))))))))))))))))))))))))))))))

.

 

2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Programas\Malwarebytes' Anti-Malware

2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Malwarebytes

2008-08-03 11:57 . 2008-08-03 11:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes

2008-08-03 11:57 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys

2008-08-03 11:57 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys

2008-08-02 16:06 . 2008-08-02 16:06 <DIR> d-------- C:\Programas\Gabest

2008-08-02 15:01 . 2008-08-02 15:01 1,885,120 --a------ C:\Programas\mbam-setup.exe

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\NetworkService\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\LocalService\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Bruno\Definiþ§es locais

2008-08-01 23:00 . 2008-08-01 23:00 <DIR> d-------- C:\Documents and Settings\Administrador\Definiþ§es locais

2008-08-01 14:10 . 2008-08-05 14:13 <DIR> d-------- C:\HiJackThis

2008-08-01 14:10 . 2008-08-01 14:10 1,382,275 --ahs---- C:\WINDOWS\system32\anpclydh.tmp

2008-07-31 16:46 . 2008-07-31 17:05 <DIR> d-------- C:\Programas\MagicISO

2008-07-31 12:51 . 2008-07-31 12:51 <DIR> d-------- C:\Programas\K-Lite Codec Pack

2008-07-30 15:02 . 2008-07-30 15:02 1,169 --a------ C:\WINDOWS\mozver.dat

2008-07-30 14:31 . 2008-07-30 14:31 0 --a------ C:\WINDOWS\nsreg.dat

2008-07-30 13:34 . 2008-07-30 13:34 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\True Sword

2008-07-30 13:16 . 2008-07-30 14:29 <DIR> d-------- C:\Programas\True Sword 4

2008-07-29 11:39 . 2008-08-03 21:00 <DIR> d-------- C:\Programas\Everest Poker

2008-07-27 18:34 . 2008-07-29 22:58 <DIR> d-------- C:\Programas\GameSpy Arcade

2008-07-27 18:09 . 2008-07-29 02:28 <DIR> d-------- C:\Documents and Settings\Bruno\Application Data\Hamachi

2008-07-27 18:08 . 2008-07-27 18:08 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys

2008-07-22 01:42 . 2008-07-22 01:42 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-08-04 11:52 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys

2008-08-04 11:52 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe

2008-08-02 14:20 --------- d--h--w C:\Programas\InstallShield Installation Information

2008-07-31 15:37 --------- d-----w C:\Documents and Settings\Bruno\Application Data\uTorrent

2008-07-30 20:13 --------- d-----w C:\Programas\uTorrent

2008-07-30 17:47 --------- d-----w C:\Programas\Kaspersky Lab

2008-07-30 17:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files

2008-07-30 13:33 --------- d-----w C:\Programas\Windows Live

2008-07-29 21:58 --------- d-----w C:\Programas\LimeWire

2008-07-29 21:58 --------- d-----w C:\Programas\DAP

2008-07-28 10:44 --------- d-s---w C:\Programas\Xfire

2008-07-27 17:23 --------- d-----w C:\Documents and Settings\Bruno\Application Data\Xfire

2008-07-27 17:04 --------- d-----w C:\Programas\Microsoft Games

2008-07-23 10:41 --------- d-----w C:\Programas\Java

2008-07-20 23:16 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys

2008-07-16 18:51 2,041,363 ----a-w C:\WINDOWS\system32\x264vfw.dll

2008-07-11 00:03 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-07-10 17:24 --------- d-----w C:\Programas\Lexmark X1100 Series

2008-07-10 14:00 --------- d-----w C:\Programas\Ficheiros comuns\Real

2008-07-09 16:54 --------- d-----w C:\Documents and Settings\Bruno\Application Data\LimeWire

2008-06-28 12:11 --------- d-----w C:\Programas\Real

2008-06-19 14:22 --------- d-----w C:\Programas\TI Education

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\TI Shared

2008-06-19 14:22 --------- d-----w C:\Programas\Ficheiros comuns\SpellEx

2008-06-19 13:40 --------- d-----w C:\Programas\Ficheiros comuns\Wise Installation Wizard

2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll

2008-06-12 14:28 --------- d-----w C:\Programas\Doom 3

2008-06-10 11:02 --------- d-----w C:\Programas\Ficheiros comuns\Logitech

2008-06-10 11:01 --------- d-----w C:\Programas\Logitech

2008-06-09 23:02 --------- d-----w C:\Programas\BT Next Evolution

2008-05-31 14:49 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll

2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll

2008-05-25 18:20 407,047 ----a-w C:\WINDOWS\system32\mioengine.exe

2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll

2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll

2008-01-15 20:15 22,328 ----a-w C:\Documents and Settings\Bruno\Application Data\PnkBstrK.sys

.

 

------- Sigcheck -------

 

2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys

2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-03-21 23:41 360064 34a663e7f74ae8b2c992c2513343477e C:\WINDOWS\system32\drivers\TCPIP.SYS

 

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\explorer.exe

2007-06-13 14:10 1035264 4b1174a06f3e4bd5341521d151b84dce C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe

2007-06-13 14:22 977920 605f1c805f3c226781d3cafcc074f643 C:\WINDOWS\system32\dllcache\explorer.exe

.

((((((((((((((((((((((((((((( snapshot@2008-08-01_23.00.12.05 )))))))))))))))))))))))))))))))))))))))))

.

- 2007-09-04 16:56:10 164,352 ----a-w C:\WINDOWS\system32\unrar.dll

+ 2002-10-15 22:54:04 153,088 ----a-w C:\WINDOWS\system32\unrar.dll

+ 2002-12-11 08:19:32 368,640 ----a-w C:\WINDOWS\system32\vobsub.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & legítimas por defeito não são mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-21 12:00 15360]

"DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2007-12-19 21:13 486856]

"msnmsgr"="C:\Programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32 225280]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 23:05 8429568]

"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"PDVD8LanguageShortcut"="C:\Programas\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]

"NeroFilterCheck"="C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]

"Lexmark X1100 Series"="C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 12:12 57344]

"QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2007-06-29 06:24 286720]

"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 02:58 16264192 C:\WINDOWS\RTHDCPL.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-21 12:00 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"AllowLegacyWebView"= 1 (0x1)

"AllowUnhashedWebView"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.XFR1"= xfcodec.dll

"msacm.l3fhg"= mp3fhg.acm

"msacm.divxa32"= divxa32.acm

"VIDC.X264"= x264vfw.dll

"VIDC.HFYU"= huffyuv.dll

"vidc.i263"= i263_32.drv

"VIDC.YV12"= yv12vfw.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Programas\\BT Next Evolution\\btnext.exe"=

"C:\\Programas\\Messenger\\msmsgs.exe"=

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Programas\\uTorrent\\uTorrent.exe"=

"C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"C:\\WINDOWS\\system32\\PnkBstrA.exe"=

"C:\\WINDOWS\\system32\\PnkBstrB.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"=

"C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=

"C:\\RF PoA\\RF Online\\RF.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"=

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

"C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"=

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"13000:TCP"= 13000:TCP:btnext

 

S1 e67gdfg;e67gdfg;C:\WINDOWS\twain_32\e67gdfg.ds []

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-08-05 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job

- C:\Programas\RegistrySmart\RegistrySmart.exe []

 

2008-08-05 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job

- C:\Programas\RegistrySmart []

.

.

------- Ccan Suplementar -------

.

FireFox -: Profile - C:\Documents and Settings\Bruno\Application Data\Mozilla\Firefox\Profiles\f3aq3nzh.default\

FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.pt/

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-05 14:35:10

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\e67gdfg]

"ImagePath"="\??\C:\WINDOWS\twain_32\e67gdfg.ds"

.

Tempo para conclusão: 2008-08-05 14:49:28

ComboFix-quarantined-files.txt 2008-08-05 13:48:29

ComboFix2.txt 2008-08-02 11:46:44

ComboFix3.txt 2008-08-01 22:00:40

 

Pre-Run: 19,909,971,968 bytes livres

Post-Run: 20,007,518,208 bytes livres

 

172 --- E O F --- 2008-05-15 20:56:13

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:54:06, on 05-08-2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\System32\cmd.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Programas\Java\jre1.6.0_07\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\explorer.exe

C:\HiJackThis\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.pt/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] C:\Programas\CyberLink\PowerDVD8\Language\Language.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programas\Ficheiros comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programas\Lexmark X1100 Series\lxbkbmgr.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programas\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{9DF3B851-FE87-4C48-BD43-C3240981AA3C}: NameServer = 192.168.1.1

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programas\ficheiros comuns\logitech\lvmvfm\LVPrcSrv.exe

O23 - Service: NBService - Nero AG - C:\Programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: NET Monitoring (ServicoMonitoring) - LCN Tecnologia - c:\netmonit\abrir.exe

 

--

End of file - 5451 bytes

 

 

 

Fico aguardando abraço :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Noxe

 

<!> Voçê,ainda,possui o Rustock rodando no PC! ( e67gdfg.ds )

 

< Rustock >

 

<@> Baixe: < SDFix >

<@> Salve-o no Disco Local-C e,descompacte-o aì mesmo.

<@> Reinicie o computador em Modo de Segurança.

<@> Dê um duplo clique em: < runThis.bat >

 

<!> Caso uma janela abra e feche,repentinamente,adote as seguites medidas:

 

<!> Vá em Iniciar >> Executar >> Digite ou cole: %systemdrive%\SDFix\apps\FixPath.exe /Q

<!> Reinicie o computador e execute,novamente,o SDFix!

<!> Caso não funcione,verifique a variável %comspec%.

<!> Clique direito do mouse em Meu Computador >> Propriedades >> Avançadas.

<!> Em: Variáveis do Ambiente >> Verifique se a variável ComSpec,tem o valor para o cmd.exe.

 

<!> Valor: %SystemRoot%\system32\cmd.exe

<@> Aperte o Y.

<@> Aguarde a conclusão!

<@> Terminando,aperte Enter.( ...ou,qualquer tecla!)

<@> O computador será reiniciado!

<@> Aguarde,ainda,a conclusão da limpeza.

------------------------

<@> Poste,na sua resposta,o relatório: Report.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui esta o relatorio

 

 

SDFix: Version 1.213

Run by Bruno on 06-08-2008 at 13:37

 

Microsoft Windows XP [VersÆo 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

Name :

e67gdfg

 

Path :

\??\C:\WINDOWS\twain_32\e67gdfg.ds

 

e67gdfg - Deleted

 

 

 

Restoring Default Security Values

Restoring Default Hosts File

 

Rebooting

 

 

Checking Files :

 

Trojan Files Found:

 

C:\-86277~1 - Deleted

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-06 13:48:38

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Programas\DAEMON Tools Lite\"

"h0"=dword:00000000

"khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]

"a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,..

"khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]

"khjeh"=hex:46,d7,44,68,96,34,d0,d2,9c,87,4f,d4,5c,07,0f,8b,d9,8e,73,77,3d,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]

"khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]

"s1"=dword:2df9c43f

"s2"=dword:110480d0

"h0"=dword:00000001

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Programas\DAEMON Tools Lite\"

"h0"=dword:00000000

"khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]

"a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,..

"khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]

"khjeh"=hex:41,d1,e9,e7,4d,44,de,7c,51,2a,e2,22,c8,73,ef,01,a0,e8,3b,9f,c1,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]

"khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"p0"="C:\Programas\DAEMON Tools Lite\"

"h0"=dword:00000000

"khjeh"=hex:46,17,90,df,f0,54,29,2e,25,45,2e,b4,9f,c2,92,11,59,6a,a2,05,4a,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]

"a0"=hex:20,01,00,00,06,24,bc,1e,cf,00,8e,d4,b2,25,a6,68,d6,a7,e0,b3,e8,..

"khjeh"=hex:db,af,0f,be,32,a8,e6,0a,29,e9,cf,0f,02,28,ec,67,6c,56,d2,d3,ee,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]

"khjeh"=hex:41,d1,e9,e7,4d,44,de,7c,51,2a,e2,22,c8,73,ef,01,a0,e8,3b,9f,c1,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]

"khjeh"=hex:f8,e1,35,03,f9,2d,48,b3,cf,f5,f9,74,11,3e,49,85,11,e1,cd,b6,83,..

 

scanning hidden registry entries ...

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D22B9093-77E1-84ED-8FA9-1CEF0D6FF176}]

"iahpogehfemcefhchg"=hex:6a,61,64,6d,63,64,68,68,6c,70,63,6a,63,62,64,6c,65,62,64,6d,00,..

"hanpeffomafoobpf"=hex:6a,61,64,6d,67,65,64,6f,67,6d,70,6e,61,70,65,6a,62,68,6b,68,00,..

"gagaialcbbhice"=hex:6b,61,64,6d,63,64,67,68,65,61,6b,70,64,67,6d,62,6b,61,6a,69,64,..

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Programas\\BT Next Evolution\\btnext.exe"="C:\\Programas\\BT Next Evolution\\btnext.exe:*:Enabled:btnext"

"C:\\Programas\\Messenger\\msmsgs.exe"="C:\\Programas\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"="C:\\Programas\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"C:\\Programas\\uTorrent\\uTorrent.exe"="C:\\Programas\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"

"C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="C:\\Programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe:*:Disabled:Nero ShowTime"

"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"

"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe"="C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp(1.4cracked).exe:*:Disabled:iw3mp(1.4cracked)"

"C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Programas\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Enabled:Football Manager 2008"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

"C:\\RF PoA\\RF Online\\RF.exe"="C:\\RF PoA\\RF Online\\RF.exe:*:Enabled:RFLauncher"

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\Portuguese\\setup.exe:*:Enabled:Kaspersky Internet Security 7.0 Setup"

"C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty® 4 - Modern Warfare "

"C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe"="C:\\Programas\\Ubisoft\\THE SETTLERS - Rise of an Empire\\base\\bin\\Settlers6.exe:*:Enabled:THE SETTLERS - Rise of an Empire"

"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe:*:Enabled:Kaspersky Internet Security 2009 Setup"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"="C:\\Programas\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Programas\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

 

Remaining Files :

 

 

File Backups: - C:\SDFix\backups\backups.zip

 

Files with Hidden Attributes :

 

Fri 1 Aug 2008 1,382,275 A.SH. --- "C:\WINDOWS\system32\anpclydh.tmp"

Sun 27 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

Sun 27 Jan 2008 871,896 A.SH. --- "C:\Programas\True Sword 4\backuped\11\IEXPLORE.EXE"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT2.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT1.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT5.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2b7e61047c183e810714f3a963759d04\BIT4.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3ac8e349a4ba66571483f7d34d6d922c\BIT3.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\72f9fd1477d8323acfe21712c4d56121\BIT7.tmp"

Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ce69a63a41543779f2e365a64b240c23\BIT6.tmp"

Sun 13 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT6.tmp"

 

Finished!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Noxe

 

<@> No Executar,digite: ComboFix.exe /u --> Clique: OK

<@> Na solicitação,escolha o dois. ( 2 ) >> Aguarde a desinstalação!

-----------------------

<!> Ps: Devido ao volume infectado,voçê terá que executar um escaneamento online!

<!> O log do HijackThis,está praticamente,limpo! :thumbsup:

-----------------------

>@< Faça um scan on line em: < Kaspersky >

 

<!> Acesse o site,utilizando o IE e clique em: < kasperdx9.jpg >

 

>@< Na próxima página,clique em: I Accept

>@< Isto,para que se instale o controle activeX e,em seguida,atualize o banco de dados.

>@< Na próxima página,clique em: My Computer e faça o scan.

>@< Tenha paciência! Aguarde a atualização da base de dados,e o próprio exame que é demorado.

>@< Terminando,salve e poste o relatório.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.