Annluciap 0 Denunciar post Postado Novembro 20, 2008 Olá, segue log do Hijack. Aguardo ajuda de alguém. Obrigada, um abraço. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:20:13, on 20/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\svchost.exe c:\VV50\sdagt.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.BIN C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rocketdivision.com/search/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 143.54.1.101:3128 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Atalho para a Página de Propriedades do High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [OpwareSE2] "C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: BrOffice.org 2.4.lnk = C:\Arquivos de programas\BrOffice.org 2.4\program\quickstart.exe O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212599824500 O17 - HKLM\System\CCS\Services\Tcpip\..\{5AF71F34-B15D-407D-8866-78A13C59464A}: NameServer = 143.54.1.52,143.54.1.53 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Virtual Vision 5.0 - Logon Agent (VVLogonAgt) - MicroPower Software - c:\VV50\logonagt.exe O23 - Service: Virtual Vision 5.0 - Shutdown Agent (VVSdAgt) - MicroPower Software - c:\VV50\sdagt.exe -- End of file - 5732 bytes Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Novembro 20, 2008 <@> Baixe: < ComboFix.exe > <@> Salve-o no Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter. <@> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" --> Enter. ---------------------- <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Compartilhar este post Link para o post Compartilhar em outros sites
Annluciap 0 Denunciar post Postado Novembro 20, 2008 Seguem os logs. Obrigada. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:38:54, on 20/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.BIN C:\WINDOWS\system32\svchost.exe c:\VV50\sdagt.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ufrgs.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 143.54.1.101:3128 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Atalho para a Página de Propriedades do High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [OpwareSE2] "C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: BrOffice.org 2.4.lnk = C:\Arquivos de programas\BrOffice.org 2.4\program\quickstart.exe O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212599824500 O17 - HKLM\System\CCS\Services\Tcpip\..\{5AF71F34-B15D-407D-8866-78A13C59464A}: NameServer = 143.54.1.52,143.54.1.53 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Virtual Vision 5.0 - Logon Agent (VVLogonAgt) - MicroPower Software - c:\VV50\logonagt.exe O23 - Service: Virtual Vision 5.0 - Shutdown Agent (VVSdAgt) - MicroPower Software - c:\VV50\sdagt.exe -- End of file - 5739 bytes ComboFix 08-11-19.08 - Projeto INCLUIR 2008-11-20 16:33:11.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.205 [GMT -2:00] Executando de: c:\documents and settings\Projeto INCLUIR\Desktop\ComboFix.exe * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\abk.bat C:\Autorun.inf c:\windows\system32\kamsoft.exe c:\windows\system32\tscct1.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))) . 2008-11-20 14:20 . 2008-11-20 13:48 85,504 --------- c:\windows\system32\trz24.tmp 2008-11-20 14:19 . 2008-11-20 14:20 <DIR> d-------- C:\HijackThis 2008-11-20 13:52 . 2008-11-20 13:52 <DIR> d-------- c:\windows\LastGood 2008-11-20 13:52 . 2008-11-20 14:59 <DIR> d-------- c:\windows\BDOSCAN8 2008-11-20 12:52 . 2008-11-20 12:52 <DIR> d-------- c:\arquivos de programas\Alwil Software 2008-11-20 12:52 . 2003-03-18 17:20 1,060,864 --a------ c:\windows\system32\MFC71.dll 2008-11-12 14:13 . 2008-11-12 14:13 24 --a------ c:\windows\cdplayer.ini 2008-11-12 08:38 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-11-12 08:37 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll 2008-11-07 16:42 . 2008-11-07 16:42 23 --a------ c:\windows\CARTAVOX.INI 2008-10-29 11:02 . 2008-10-29 11:02 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-10-29 11:01 . 2008-10-29 11:01 <DIR> d-------- c:\arquivos de programas\Rocket Division Software 2008-10-29 11:01 . 2008-06-27 12:31 93,544 --a------ c:\windows\system32\drivers\StarPortLite.sys 2008-10-24 08:49 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-20 15:48 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\BrOffice.org2 2008-11-20 14:09 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\Skype 2008-11-20 12:46 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\skypePM 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-01 13:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SSScanWizard 2008-10-01 13:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SSScanAppDataDir 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-24 13:32 --------- d-----w c:\arquivos de programas\NextUp-ScanSoft 2008-09-22 16:56 499,712 ----a-w c:\windows\system32\msvcp71.dll 2008-09-22 16:56 348,160 ----a-w c:\windows\system32\msvcr71.dll 2008-09-22 16:56 --------- d-----w c:\arquivos de programas\Arquivos comuns\xing shared 2008-09-22 16:56 --------- d-----w c:\arquivos de programas\Arquivos comuns\Real 2008-09-22 15:09 --------- d-----w c:\arquivos de programas\Mbrola Tools 2008-09-22 11:55 --------- d-----w c:\arquivos de programas\MSECache 2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys 2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll 2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll 2008-08-20 05:09 668,160 ----a-w c:\windows\system32\wininet.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "InCD"="c:\arquivos de programas\Ahead\InCD\InCD.exe" [2003-11-25 1232946] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784] "OpwareSE2"="c:\arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-22 185896] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000] "Atalho para a Página de Propriedades do High Definition Audio"="HDAudPropShortcut.exe" [2004-08-12 c:\windows\system32\Hdaudpropshortcut.exe] "SoundMan"="SOUNDMAN.EXE" [2004-10-21 c:\windows\SOUNDMAN.EXE] "AlcWzrd"="ALCWZRD.EXE" [2004-10-21 c:\windows\ALCWZRD.EXE] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Projeto INCLUIR\Menu Iniciar\Programas\Inicializar\ BrOffice.org 2.4.lnk - c:\arquivos de programas\BrOffice.org 2.4\program\quickstart.exe [2008-01-21 393216] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-20 110160] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys [2008-10-29 93544] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-20 20560] R2 VVSdAgt;Virtual Vision 5.0 - Shutdown Agent;c:\vv50\sdagt.exe [2008-06-04 382976] S3 VVLogonAgt;Virtual Vision 5.0 - Logon Agent;c:\vv50\logonagt.exe [2008-06-04 381952] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e56e35ad-83e5-11dd-88f1-00115bf55d19}] \Shell\AutoRun\command - E:\ggdsii.exe \Shell\explore\Command - E:\ggdsii.exe \Shell\open\Command - E:\ggdsii.exe *Newly Created Service* - AAVMKER4 *Newly Created Service* - ASWFSBLK *Newly Created Service* - ASWMON2 *Newly Created Service* - ASWRDR *Newly Created Service* - ASWSP *Newly Created Service* - ASWTDI *Newly Created Service* - ASWUPDSV *Newly Created Service* - AVAST!_ANTIVIRUS *Newly Created Service* - AVAST!_MAIL_SCANNER *Newly Created Service* - AVAST!_WEB_SCANNER *Newly Created Service* - PROCEXP90 . . ------- Scan Suplementar ------- . FireFox -: Profile - c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\Mozilla\Firefox\Profiles\0dsfke9o.default\ FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.rocketdivision.com/search/ FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll FF -: plugin - c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-20 16:34:25 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-11-20 16:35:21 ComboFix-quarantined-files.txt 2008-11-20 18:35:17 Pré-execução: 17 pasta(s) 70.947.295.232 bytes disponíveis Pós execução: 17 pasta(s) 71,035,232,256 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 130 --- E O F --- 2008-11-12 14:57:56 Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Novembro 20, 2008 Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento. Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt. File::E:\ggdsii.exe Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e56e35ad-83e5-11dd-88f1-00115bf55d19}] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos. Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo. O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Quando acabar, será gerado um log, que estará em C:\ComboFix.txt. Poste-o junto com o novo log do hijackthis Compartilhar este post Link para o post Compartilhar em outros sites
Annluciap 0 Denunciar post Postado Novembro 21, 2008 Seguem novos logs. ComboFix 08-11-19.08 - Projeto INCLUIR 2008-11-21 10:27:04.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.245 [GMT -2:00] Executando de: c:\documents and settings\Projeto INCLUIR\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Projeto INCLUIR\Desktop\CFScript.txt * Criado um novo ponto de restauro FILE :: E:\ggdsii.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))) . 2008-11-20 14:19 . 2008-11-20 16:38 <DIR> d-------- C:\HijackThis 2008-11-20 13:52 . 2008-11-20 14:59 <DIR> d-------- c:\windows\BDOSCAN8 2008-11-20 12:52 . 2008-11-20 12:52 <DIR> d-------- c:\arquivos de programas\Alwil Software 2008-11-20 12:52 . 2003-03-18 17:20 1,060,864 --a------ c:\windows\system32\MFC71.dll 2008-11-12 14:13 . 2008-11-12 14:13 24 --a------ c:\windows\cdplayer.ini 2008-11-12 08:38 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-11-12 08:37 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll 2008-11-07 16:42 . 2008-11-07 16:42 23 --a------ c:\windows\CARTAVOX.INI 2008-10-29 11:02 . 2008-10-29 11:02 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2008-10-29 11:01 . 2008-10-29 11:01 <DIR> d-------- c:\arquivos de programas\Rocket Division Software 2008-10-29 11:01 . 2008-06-27 12:31 93,544 --a------ c:\windows\system32\drivers\StarPortLite.sys 2008-10-24 08:49 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-21 12:22 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\BrOffice.org2 2008-11-20 14:09 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\Skype 2008-11-20 12:46 --------- d-----w c:\documents and settings\Projeto INCLUIR\Dados de aplicativos\skypePM 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-01 13:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SSScanWizard 2008-10-01 13:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SSScanAppDataDir 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-24 13:32 --------- d-----w c:\arquivos de programas\NextUp-ScanSoft 2008-09-22 16:56 499,712 ----a-w c:\windows\system32\msvcp71.dll 2008-09-22 16:56 348,160 ----a-w c:\windows\system32\msvcr71.dll 2008-09-22 16:56 --------- d-----w c:\arquivos de programas\Arquivos comuns\xing shared 2008-09-22 16:56 --------- d-----w c:\arquivos de programas\Arquivos comuns\Real 2008-09-22 15:09 --------- d-----w c:\arquivos de programas\Mbrola Tools 2008-09-22 11:55 --------- d-----w c:\arquivos de programas\MSECache 2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys 2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll 2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll . ((((((((((((((((((((((((((((( snapshot@2008-11-20_16.34.46,73 ))))))))))))))))))))))))))))))))))))))))) . + 2008-11-20 18:37:07 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_5a0.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "InCD"="c:\arquivos de programas\Ahead\InCD\InCD.exe" [2003-11-25 1232946] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784] "OpwareSE2"="c:\arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-22 185896] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000] "Atalho para a Página de Propriedades do High Definition Audio"="HDAudPropShortcut.exe" [2004-08-12 c:\windows\system32\Hdaudpropshortcut.exe] "SoundMan"="SOUNDMAN.EXE" [2004-10-21 c:\windows\SOUNDMAN.EXE] "AlcWzrd"="ALCWZRD.EXE" [2004-10-21 c:\windows\ALCWZRD.EXE] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Projeto INCLUIR\Menu Iniciar\Programas\Inicializar\ BrOffice.org 2.4.lnk - c:\arquivos de programas\BrOffice.org 2.4\program\quickstart.exe [2008-01-21 393216] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-20 110160] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys [2008-10-29 93544] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-20 20560] R2 VVSdAgt;Virtual Vision 5.0 - Shutdown Agent;c:\vv50\sdagt.exe [2008-06-04 382976] S3 VVLogonAgt;Virtual Vision 5.0 - Logon Agent;c:\vv50\logonagt.exe [2008-06-04 381952] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-21 10:28:25 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-11-21 10:29:18 ComboFix-quarantined-files.txt 2008-11-21 12:29:13 ComboFix2.txt 2008-11-20 18:35:22 Pré-execução: 17 pasta(s) 71.033.221.120 bytes disponíveis Pós execução: 17 pasta(s) 71,025,811,456 bytes disponíveis 97 --- E O F --- 2008-11-12 14:57:56 ---------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:32:22, on 21/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\svchost.exe c:\VV50\sdagt.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\ALCWZRD.EXE C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.exe C:\Arquivos de programas\BrOffice.org 2.4\program\soffice.BIN C:\WINDOWS\system32\wuauclt.exe C:\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ufrgs.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 143.54.1.101:3128 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Atalho para a Página de Propriedades do High Definition Audio] HDAudPropShortcut.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [OpwareSE2] "C:\Arquivos de programas\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: BrOffice.org 2.4.lnk = C:\Arquivos de programas\BrOffice.org 2.4\program\quickstart.exe O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212599824500 O17 - HKLM\System\CCS\Services\Tcpip\..\{5AF71F34-B15D-407D-8866-78A13C59464A}: NameServer = 143.54.1.52,143.54.1.53 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Virtual Vision 5.0 - Logon Agent (VVLogonAgt) - MicroPower Software - c:\VV50\logonagt.exe O23 - Service: Virtual Vision 5.0 - Shutdown Agent (VVSdAgt) - MicroPower Software - c:\VV50\sdagt.exe -- End of file - 5739 bytes Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Novembro 21, 2008 O log se encontra limpo, algum problema? Compartilhar este post Link para o post Compartilhar em outros sites
Annluciap 0 Denunciar post Postado Novembro 21, 2008 Olá, eu já imaginava que estivesse limpo, mas estava esperando a confirmação. Muito obrigada pela ajuda!!!! Compartilhar este post Link para o post Compartilhar em outros sites
Annluciap 0 Denunciar post Postado Novembro 21, 2008 Olá, eu já imaginava que estivesse limpo, mas estava esperando a confirmação. Muito obrigada pela ajuda!!!! Compartilhar este post Link para o post Compartilhar em outros sites
PedroN 1 Denunciar post Postado Novembro 21, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites