Tigre13 0 Denunciar post Postado Dezembro 8, 2008 Olá, Demora muito para inicilalizar e desligar, além estar muito, muito, muito lenta para abrir qualquer programa que presico usar, já estou enviando o log do hijack, conforme regra 02. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:18:29, on 8/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.exe C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\csrcs.exe C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\Arquivos de programas\VIA\RAID\raid_tool.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\HiJack\HiJackThis.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\net.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (User '?') O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O4 - Global Startup: VIA RAID TOOL.lnk = C:\Arquivos de programas\VIA\RAID\raid_tool.exe O8 - Extra context menu item: Converter destino de link em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter destino de link em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter links selecionados em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Converter links selecionados em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Converter seleção em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter seleção em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{56A482EE-889F-4B5A-97D5-F22A86B01873}: NameServer = 192.168.1.254 O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\fci.exe.exe:ext.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~2.EXE O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe O23 - Service: PaperCut Print Logger (PCPrintLogger) - GenevaLogic Ltd - C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - (no file) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 9489 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 8, 2008 1ª Etapa Execute o HijackThis e clique em Open the Misc Tools Section. Clique no botão Delete an NT Service. Na caixa que abrir digite: FCI e aperte o botão OK. Reinicie a máquina. 2ª Etapa - Faça o download do ComboFix e salve-o na área de trabalho; ● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus; ● Duplo clique no ícone combofix.exe para iniciar o scan; ● Leia o contrato que aparecerá e clique em Sim para continuar; ● Abrirá uma janela do Console de Recuperação, clique em Sim para instalar. Se aparecer outra janela do Console, clique em OK > Sim; ● Aguarde enquanto o ComboFix faz o scan; ● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento; ● Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta; ● Se quiser sair ou parar o ComboFix, tecle N; ● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde; ● Será gerado um log em C:\ComboFix.txt. Cole este log em sua próxima resposta, juntamente com um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 8, 2008 Olá, já executei sua solicitação, segue abaixo log do ComboFix e novo do HiJack ComboFix 08-12-07.01 - DOIS 2008-12-08 17:41:12.1 - FAT32x86 Executando de: c:\documents and settings\DOIS\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\arquivos de programas\ActivationManager c:\arquivos de programas\ActivationManager\Uninstall.exe c:\windows\system32\AutoRun.inf c:\windows\system32\csrcs.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_FCI -------\Service_FCI (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-08 to 2008-12-08 )))))))))))))))))))))))))))) . 2008-12-08 17:25 . 2008-12-08 17:25 93 --a------ c:\windows\wininit.ini 2008-12-08 15:17 . 2008-12-08 15:17 <DIR> d-------- C:\HiJack 2008-12-07 19:46 . 2008-12-07 19:46 162,308 --a------ C:\ysini.exe 2008-12-07 19:46 . 2008-12-07 19:46 135,936 --a------ c:\windows\system32\drivers\ethyscsp.sys 2008-12-07 19:46 . 2008-12-07 19:46 3,584 --a------ c:\windows\vcvybxmm.exe 2008-12-07 19:45 . 2008-12-07 19:45 88,064 --a------ C:\tirwv.exe 2008-12-07 19:45 . 2008-12-07 19:45 9,728 --a------ c:\windows\system32\ub.exe 2008-12-03 20:44 . 2008-12-03 20:44 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-02 17:52 . 2008-12-02 17:52 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-02 17:52 . 2008-12-02 17:52 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-12-01 10:46 . 2008-12-01 10:46 705 --a------ C:\mggiu.exe 2008-11-30 13:16 . 2008-11-30 13:16 420,596 --a------ c:\windows\system32\cftm.exe 2008-11-30 12:57 . 2008-11-30 12:57 0 -rahs---- C:\khr 2008-11-27 17:07 . 2008-11-27 17:07 29 --a------ c:\windows\system32\qpwaarsq.tmp 2008-11-27 17:00 . 2008-12-01 10:46 705 --a------ C:\kuvj.exe 2008-11-27 17:00 . 2008-12-07 19:46 2 --a------ C:\1171739473 . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-04 16:35 2,776 --sha-w c:\windows\system32\KGyGaAvL.sys 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys 2008-10-19 23:42 87,352 ----a-w c:\windows\system32\LMIinit.dll 2008-10-19 23:42 83,288 ----a-w c:\windows\system32\LMIRfsClientNP.dll 2008-10-19 23:42 47,640 ----a-w c:\windows\system32\drivers\LMIRfsDriver.sys 2008-10-19 23:42 28,984 ----a-w c:\windows\system32\LMIport.dll 2008-10-19 23:42 23,736 ----a-w c:\windows\system32\LMImirr.dll 2008-10-19 23:42 10,040 ----a-w c:\windows\system32\LMImirr2.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll 2008-10-15 16:59 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll 2008-10-03 16:26 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-15 14:40 1,846,144 ----a-w c:\windows\system32\win32k.sys 2008-09-15 14:40 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys 2006-10-12 19:17 3,072 ----a-w c:\arquivos de programas\mozilla firefox\plugins\ractrlkeyhook.dll 2006-02-13 14:07 245,408 ----a-w c:\arquivos de programas\mozilla firefox\plugins\unicows.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Reminder"="c:\arquivos de programas\Microsoft Money\System\reminder.exe" [1998-07-25 36864] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LogMeIn GUI"="c:\arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048] "ccApp"="c:\arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2006-03-07 53408] "vptray"="c:\arquiv~1\SYMANT~1\VPTray.exe" [2006-03-17 124656] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-03 136600] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ SpeedFan.lnk - c:\arquivos de programas\SpeedFan\speedfan.exe [2005-09-13 2469376] VIA RAID TOOL.lnk - c:\arquivos de programas\VIA\RAID\raid_tool.exe [2008-02-08 565248] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\arquiv~1\DVDREG~1\DVDShell.dll" [2004-10-09 49152] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2008-10-19 21:42 87352 c:\windows\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "msacm.l3fhg"= mp3fhg.acm "msacm.imc"= imc32.acm [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Azureus.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Azureus.lnk backup=c:\windows\pss\Azureus.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0] --a------ 2004-12-14 02:12 483328 c:\arquivos de programas\Adobe\Acrobat 7.0\Distillr\acrotray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Agent] --a------ 2002-10-01 15:57 94208 c:\arquivos de programas\CyberLink\PowerVCRII\agent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2005-10-28 16:25 94208 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] --a------ 2004-03-12 22:43 81920 c:\arquivos de programas\D-Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVD43] --a------ 2004-10-22 15:18 278016 c:\arquivos de programas\DVD Region+CSS Free\DVDRegionFree.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2005-08-11 16:30 249856 c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2005-08-11 16:30 81920 c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector] --a------ 2008-02-25 22:23 443968 c:\arquivos de programas\Picasa2\PicasaMediaDetector.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-05-02 18:55 282624 c:\arquivos de programas\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Remote_Agent] --a------ 2002-10-07 10:35 32768 c:\arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp] --a------ 2003-05-05 08:57 143360 c:\arquivos de programas\Analog Devices\SoundMAX\SMTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] --a------ 2005-07-15 19:48 479232 c:\arquivos de programas\Google\Gmail Notifier\gnotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Azureus\\Azureus.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-08 c:\windows\Tasks\XoftSpy.job - c:\arquivos de programas\XoftSpy\XoftSpy.exe [2005-07-06 16:53] 2008-12-05 c:\windows\Tasks\1-Click Maintenance.job - c:\arquivos de programas\TuneUp Utilities 2008\OneClick.exe [2008-01-08 13:31] . - - - - ORFÃOS REMOVIDOS - - - - MSConfigStartUp-MSMSGS - c:\arquivos de programas\Messenger\msmsgs.exe . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Converter destino de link em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter destino de link em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Converter em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Converter links selecionados em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Converter links selecionados em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Converter seleção em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter seleção em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {56A482EE-889F-4B5A-97D5-F22A86B01873} = 192.168.1.254 c:\windows\Downloaded Program Files\zylomgamesplayer.dll - O16 -: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game06.zylom.com/activex/zylomgamesplayer.cab c:\windows\Downloaded Program Files\ZylomGamesPlayer.inf FireFox -: Profile - c:\documents and settings\DOIS\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\ . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-08 17:46:06 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(1312) c:\windows\system32\LMIinit.dll c:\windows\system32\LMIRfsClientNP.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\ARQUIVOS COMUNS\SYMANTEC SHARED\CCSETMGR.EXE c:\arquivos de programas\ARQUIVOS COMUNS\SYMANTEC SHARED\CCEVTMGR.EXE c:\arquivos de programas\ARQUIVOS COMUNS\SYMANTEC SHARED\SPBBC\SPBBCSVC.EXE c:\arquivos de programas\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE c:\arquivos de programas\SYMANTEC ANTIVIRUS\DEFWATCH.EXE c:\arquivos de programas\JAVA\JRE6\BIN\JQS.EXE c:\arquivos de programas\LOGMEIN\X86\RAMAINT.EXE c:\arquivos de programas\LOGMEIN\X86\LOGMEIN.EXE c:\arquivos de programas\LOGMEIN\X86\LMIGUARDIAN.EXE c:\arquivos de programas\PAPERCUT PRINT LOGGER\PCPL.EXE c:\arquivos de programas\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE c:\arquivos de programas\SYMANTEC ANTIVIRUS\RTVSCAN.EXE c:\windows\system32\wscntfy.exe c:\arquivos de programas\LOGMEIN\X86\LMIGUARDIAN.EXE . ************************************************************************** . Tempo para conclusão: 2008-12-08 17:48:50 - Máquina reiniciou ComboFix-quarantined-files.txt 2008-12-08 19:48:48 Pré-execução: 15 pasta(s) 63.193.546.752 bytes disponíveis Pós execução: 15 pasta(s) 63,182,897,152 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 207 --- E O F --- 2008-11-15 12:35:09 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:52:44, on 8/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\Arquivos de programas\VIA\RAID\raid_tool.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\WINDOWS\explorer.exe C:\HiJack\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (User '?') O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O4 - Global Startup: VIA RAID TOOL.lnk = C:\Arquivos de programas\VIA\RAID\raid_tool.exe O8 - Extra context menu item: Converter destino de link em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter destino de link em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter links selecionados em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Converter links selecionados em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Converter seleção em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter seleção em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{56A482EE-889F-4B5A-97D5-F22A86B01873}: NameServer = 192.168.1.254 O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~2.EXE O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe O23 - Service: PaperCut Print Logger (PCPrintLogger) - GenevaLogic Ltd - C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - (no file) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 9139 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 9, 2008 Selecione e copie este texto aqui abaixo. Cole o texto copiado dentro do bloco de notas de seu computador e salve-o na área de trabalho com o nome CFScript.txt File::C:\ysini.exe c:\windows\system32\drivers\ethyscsp.sys c:\windows\vcvybxmm.exe C:\tirwv.exe c:\windows\system32\ub.exe C:\mggiu.exe c:\windows\system32\cftm.exe C:\khr c:\windows\system32\qpwaarsq.tmp C:\kuvj.exe Folder:: C:\1171739473 Arraste o CFScript para o ComboFix como na imagem aqui abaixo e aguarde a execução automática da ferramenta: ● Se for solicitado à você, pressione Enter para iniciar o processo de remoção; ● Não use o mouse nem o teclado quando o ComboFix estiver rodando; ● Quando terminar, será gerado um novo log que estará em C:\ComboFix.txt; ● Seu computador será reiniciado automaticamente; Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 9, 2008 Olá, Segue os relatórios solicitados: ComboFix 08-12-07.01 - DOIS 2008-12-09 10:33:46.2 - FAT32x86 Executando de: c:\documents and settings\DOIS\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\DOIS\Desktop\CFScript.txt FILE :: C:\khr C:\kuvj.exe C:\mggiu.exe C:\tirwv.exe c:\windows\system32\cftm.exe c:\windows\system32\drivers\ethyscsp.sys c:\windows\system32\qpwaarsq.tmp c:\windows\system32\ub.exe c:\windows\vcvybxmm.exe C:\ysini.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\1171739473\ C:\khr C:\kuvj.exe C:\mggiu.exe C:\tirwv.exe c:\windows\system32\cftm.exe c:\windows\system32\drivers\ethyscsp.sys c:\windows\system32\qpwaarsq.tmp c:\windows\system32\ub.exe c:\windows\vcvybxmm.exe C:\ysini.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))) . 2008-12-08 17:25 . 2008-12-08 17:25 93 --a------ c:\windows\wininit.ini 2008-12-08 15:17 . 2008-12-08 15:17 <DIR> d-------- C:\HiJack 2008-12-03 20:44 . 2008-12-03 20:44 410,984 --a------ c:\windows\system32\deploytk.dll 2008-12-02 17:52 . 2008-12-02 17:52 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-02 17:52 . 2008-12-02 17:52 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-11-27 17:00 . 2008-12-07 19:46 2 --a------ C:\1171739473 . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-04 16:35 2,776 --sha-w c:\windows\system32\KGyGaAvL.sys 2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys 2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys 2008-10-19 23:42 87,352 ----a-w c:\windows\system32\LMIinit.dll 2008-10-19 23:42 83,288 ----a-w c:\windows\system32\LMIRfsClientNP.dll 2008-10-19 23:42 47,640 ----a-w c:\windows\system32\drivers\LMIRfsDriver.sys 2008-10-19 23:42 28,984 ----a-w c:\windows\system32\LMIport.dll 2008-10-19 23:42 23,736 ----a-w c:\windows\system32\LMImirr.dll 2008-10-19 23:42 10,040 ----a-w c:\windows\system32\LMImirr2.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll 2008-10-15 16:59 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll 2008-10-03 16:26 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-15 14:40 1,846,144 ----a-w c:\windows\system32\win32k.sys 2008-09-15 14:40 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys 2006-10-12 19:17 3,072 ----a-w c:\arquivos de programas\mozilla firefox\plugins\ractrlkeyhook.dll 2006-02-13 14:07 245,408 ----a-w c:\arquivos de programas\mozilla firefox\plugins\unicows.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-08_17.48.21.39 ))))))))))))))))))))))))))))))))))))))))) . - 2008-12-08 19:45:20 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_390.dat + 2008-12-09 12:24:36 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_390.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Reminder"="c:\arquivos de programas\Microsoft Money\System\reminder.exe" [1998-07-25 36864] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LogMeIn GUI"="c:\arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048] "ccApp"="c:\arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" [2006-03-07 53408] "vptray"="c:\arquiv~1\SYMANT~1\VPTray.exe" [2006-03-17 124656] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-03 136600] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ SpeedFan.lnk - c:\arquivos de programas\SpeedFan\speedfan.exe [2005-09-13 2469376] VIA RAID TOOL.lnk - c:\arquivos de programas\VIA\RAID\raid_tool.exe [2008-02-08 565248] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\arquiv~1\DVDREG~1\DVDShell.dll" [2004-10-09 49152] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2008-10-19 21:42 87352 c:\windows\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "msacm.l3fhg"= mp3fhg.acm "msacm.imc"= imc32.acm [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Azureus.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Azureus.lnk backup=c:\windows\pss\Azureus.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0] --a------ 2004-12-14 02:12 483328 c:\arquivos de programas\Adobe\Acrobat 7.0\Distillr\acrotray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Agent] --a------ 2002-10-01 15:57 94208 c:\arquivos de programas\CyberLink\PowerVCRII\agent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2005-10-28 16:25 94208 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] --a------ 2004-03-12 22:43 81920 c:\arquivos de programas\D-Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVD43] --a------ 2004-10-22 15:18 278016 c:\arquivos de programas\DVD Region+CSS Free\DVDRegionFree.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2005-08-11 16:30 249856 c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2005-08-11 16:30 81920 c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector] --a------ 2008-02-25 22:23 443968 c:\arquivos de programas\Picasa2\PicasaMediaDetector.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-05-02 18:55 282624 c:\arquivos de programas\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Remote_Agent] --a------ 2002-10-07 10:35 32768 c:\arquivos de programas\CyberLink\PowerVCRII\RemoteAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp] --a------ 2003-05-05 08:57 143360 c:\arquivos de programas\Analog Devices\SoundMAX\SMTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] --a------ 2005-07-15 19:48 479232 c:\arquivos de programas\Google\Gmail Notifier\gnotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Azureus\\Azureus.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp *Newly Created Service* - CATCHME . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-08 c:\windows\Tasks\XoftSpy.job - c:\arquivos de programas\XoftSpy\XoftSpy.exe [2005-07-06 16:53] 2008-12-05 c:\windows\Tasks\1-Click Maintenance.job - c:\arquivos de programas\TuneUp Utilities 2008\OneClick.exe [2008-01-08 13:31] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Converter destino de link em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter destino de link em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Converter em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Converter links selecionados em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Converter links selecionados em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Converter seleção em Adobe PDF - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Converter seleção em PDF existente - c:\arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {56A482EE-889F-4B5A-97D5-F22A86B01873} = 192.168.1.254 c:\windows\Downloaded Program Files\zylomgamesplayer.dll - O16 -: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} hxxp://game06.zylom.com/activex/zylomgamesplayer.cab c:\windows\Downloaded Program Files\ZylomGamesPlayer.inf FireFox -: Profile - c:\documents and settings\DOIS\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\ . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-09 10:36:26 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(1312) c:\windows\system32\LMIinit.dll c:\windows\system32\LMIRfsClientNP.dll . Tempo para conclusão: 2008-12-09 10:37:15 ComboFix-quarantined-files.txt 2008-12-09 12:37:14 ComboFix2.txt 2008-12-08 19:48:54 Pré-execução: 15 pasta(s) 63.063.293.952 bytes disponíveis Pós execução: 15 pasta(s) 63,045,009,408 bytes disponíveis 193 --- E O F --- 2008-11-15 12:35:09 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:38:51, on 9/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\VIA\RAID\raid_tool.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\explorer.exe C:\HiJack\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (User '?') O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O4 - Global Startup: VIA RAID TOOL.lnk = C:\Arquivos de programas\VIA\RAID\raid_tool.exe O8 - Extra context menu item: Converter destino de link em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter destino de link em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter links selecionados em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Converter links selecionados em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Converter seleção em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter seleção em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{56A482EE-889F-4B5A-97D5-F22A86B01873}: NameServer = 192.168.1.254 O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~2.EXE O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe O23 - Service: PaperCut Print Logger (PCPrintLogger) - GenevaLogic Ltd - C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - (no file) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 9172 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 10, 2008 - Faça o download do OTMoveIt3 e salve no desktop; ● Dê um duplo clique no ícone do programa (OTMoveIt3) para executá-lo; ● Selecione e copie todo este conteúdo aqui abaixo: :Processesexplorer.exe :Files C:\1171739473 :Commands [purity] [emptytemp] [start explorer] [Reboot] ● Cole o que você copiou no programa (no espaço em branco da janela); ● Clique no botão MoveIt; ● Se aparecer uma mensagem para reiniciar o computador, reinicie-o; ● Na sua proxima resposta, copie e cole o todo o conteúdo que está em Results; ● Se o computador reiniciou vá na pasta C:\_OTMoveIt\MovedFiles, e abra o mais recente arquivo .log presente na pasta. Copie e cole todo o conteúdo desse arquivo em sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 10, 2008 Olá, segue o OTMoveIt3: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== FILES ========== C:\1171739473 moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\DOIS\CONFIG~1\Temp\Perflib_Perfdata_9c0.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2b4.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12102008_105300 Files moved on Reboot... File C:\DOCUME~1\DOIS\CONFIG~1\Temp\Perflib_Perfdata_9c0.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_2b4.dat not found! C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\DOIS\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\2uy7ouar.default\Cache\_CACHE_003_ moved successfully. Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 11, 2008 Delete a pasta C:\_OTMoveIt e a ferramenta OTMoveIt3. Por favor, poste um novo log do HijackThis. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 11, 2008 Olá, Já deletei a pasta e ferramente OTMoveIt antes de log do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:08:16, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe C:\Arquivos de programas\LogMeIn\x86\LMIGuardian.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\Arquivos de programas\VIA\RAID\raid_tool.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Azureus\Azureus.exe C:\HiJack\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?') O4 - HKUS\S-1-5-21-57989841-1614895754-725345543-1003\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (User '?') O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O4 - Global Startup: VIA RAID TOOL.lnk = C:\Arquivos de programas\VIA\RAID\raid_tool.exe O8 - Extra context menu item: Converter destino de link em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter destino de link em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Converter links selecionados em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Converter links selecionados em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Converter seleção em Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Converter seleção em PDF existente - res://C:\Arquivos de programas\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{56A482EE-889F-4B5A-97D5-F22A86B01873}: NameServer = 192.168.1.254 O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~2.EXE O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\RaMaint.exe O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Arquivos de programas\LogMeIn\x86\LogMeIn.exe O23 - Service: PaperCut Print Logger (PCPrintLogger) - GenevaLogic Ltd - C:\Arquivos de programas\PaperCut Print Logger\pcpl.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - (no file) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 9186 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 11, 2008 Seu log está limpo. Vá em Iniciar > Executar, digite: combofix /u e dê um Enter. Delete a pasta C:\Qoobox e o log ComboFix.txt. Há algum problema no PC ainda? Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 11, 2008 Olá, Já executei o solicitado, vamos deixar este PC em observação Enquanto isso segue o log do HijackThis de outro PC que está um pouco lento, acredito que seja virus se precisar mais informações além do log, vou ficar atento para isso. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:16:29, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\windows\System32\smss.exe C:\windows\system32\csrss.exe C:\windows\system32\winlogon.exe C:\windows\system32\services.exe C:\windows\system32\lsass.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\windows\System32\svchost.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\windows\system32\spoolsv.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\windows\system32\nvsvc32.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\windows\Explorer.exe C:\windows\system32\ctfmon.exe C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe C:\windows\system32\RUNDLL32.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\windows\system32\wuauclt.exe C:\windows\System32\alg.exe C:\WINDOWS\system32\csrcs.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\windows\system32\cmd.exe C:\windows\system32\net.exe C:\HiJack\HiJackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [ACORDA] C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O8 - Extra context menu item: Add to EverNote - res://C:\Arquivos de programas\EverNote\EverNote\enbar.dll/2000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\Software\..\Telephony: DomainName = UM O17 - HKLM\System\CCS\Services\Tcpip\..\{3FC3B0ED-1D34-4E79-A979-0B23D10D35BF}: NameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = UM O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\windows\System32\TuneUpDefragService.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe -- End of file - 10114 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 11, 2008 Sugiro que salve ou imprima estas instruções abaixo. - Faça o download do SDFix e salve no desktop; ● Dê um duplo clique no SDFix.exe e a ferramenta será instalada em C:\SDFix. Mas não o execute ainda; ● Reinicie seu computador seu computador em Modo de Segurança (segurando a tecla F8 durante a inicialização do sistema e escolhendo a opção Modo Seguro); ● Entre na pasta do SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat; ● Tecle Y para que a ferramenta inicie o processo de remoção; ● Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar. Então pressione qualquer. Seu computador será reiniciado automaticamente; ● Após reiniciar, a ferramenta ainda será executada novamente e irá terminar o seu trabalho e a palavra Finished irá aparecer. Pressione qualquer tecla novamente; ● Uma janela com o relatório do SDFix irá aparecer; ● O log abrirá automaticamente para você. Estará salvo na pasta do SDFix com o nome Report.txt; Faça um novo log do HijackThis e cole na sua próxima resposta, juntamente com o log do SDFix. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 11, 2008 Olá, Mais um detalhe para analise; costumo usar o explorer configurado com arquivos ocultos e as extensões dos arquivos, porém quando ligo ele perde essa configuração, tenho que alterar toda vez que preciso; Segue o solicitado SDFix: Version 1.240 Run by Administrador on qui 11/12/2008 at 16:40 Microsoft Windows XP [versÆo 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\169669~1 - Deleted C:\windows\lsass.exe - Deleted C:\windows\system32\csrcs.exe - Deleted C:\windows\system32\hs.exe - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-11 16:50:24 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"="C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe:LocalSubNet:Enabled:@xpsp3res.dll,-20000" "C:\\Arquivos de programas\\VideoLAN\\VLC\\vlc.exe"="C:\\Arquivos de programas\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player" "C:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"="C:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox" "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:LocalSubNet:Disabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Arquivos de programas\Messenger\msmsgs.exe" Wed 22 Oct 2008 949,072 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\advcheck.dll" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\Tools.dll" Mon 15 Sep 2008 1,562,960 A.SH. --- "C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll" Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" Finished! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:54:48, on 11/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\windows\System32\smss.exe C:\windows\system32\csrss.exe C:\windows\system32\winlogon.exe C:\windows\system32\services.exe C:\windows\system32\lsass.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\windows\System32\svchost.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\windows\system32\spoolsv.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\windows\system32\nvsvc32.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\windows\System32\alg.exe C:\windows\Explorer.EXE C:\windows\system32\ctfmon.exe C:\windows\system32\notepad.exe C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\windows\System32\svchost.exe C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe C:\windows\system32\RUNDLL32.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\explorer.exe C:\HiJack\HiJackThis.exe C:\WINDOWS\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [ACORDA] C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O8 - Extra context menu item: Add to EverNote - res://C:\Arquivos de programas\EverNote\EverNote\enbar.dll/2000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\Software\..\Telephony: DomainName = UM O17 - HKLM\System\CCS\Services\Tcpip\..\{3FC3B0ED-1D34-4E79-A979-0B23D10D35BF}: NameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = UM O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\windows\System32\TuneUpDefragService.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe -- End of file - 9705 bytes Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 12, 2008 Mais um detalhe para analise;costumo usar o explorer configurado com arquivos ocultos e as extensões dos arquivos, porém quando ligo ele perde essa configuração, tenho que alterar toda vez que preciso; Olha, creio que isso não seja problema com vírus não, posso estar enganado. Quando apenas reinicia a máquina, sem desligar e ligar novamente, isso também ocorre? Delete a pasta C:\SDFix. Foi você quem criou o arquivo em destaque abaixo dentro do quote, ou é de seu conhecimento? C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe Acesse o Kaspersky Online Scanner e prossiga com um scan online, seguindo o tutorial do link abaixo: http://www.linhadefensiva.org/forum/index....showtopic=74159 Ao término do scan, salve o relatório com a extensão .txt (como mostra no final do tutorial) em seu computador e poste-o em sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 12, 2008 Olá, Sobre o explorer, vou observar, pois testei e aparentemente não mudou a configuração, talvez já tenha resolvido. O acorda.exe, é de uma agenda bem simples (despertador), nunca tive problema com ela. -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Friday, December 12, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, December 12, 2008 01:43:40 Records in database: 1453239 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ Scan statistics: Files scanned: 79250 Threat name: 19 Infected objects: 34 Suspicious objects: 1 Duration of the scan: 01:39:04 File name / Threat name / Threats count C:\WINDOWS\system32\cftm.exe Infected: Trojan.Win32.Autoit.gc 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A2C0000\4FEC86F3.VBN Infected: Packed.JS.Agent.n 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AB40000\4AFD8B82.VBN Infected: Backdoor.Win32.Rbot.ils 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CA00000\4CFA495F.VBN Infected: Backdoor.Win32.Rbot.uks 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DDC0000\4DFE4FF5.VBN Infected: Trojan-Dropper.Win32.Mudrop.du 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02140000\4B357F05.VBN Infected: Trojan.Win32.Autoit.fi 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F2C0000\4F3D67EB.VBN Infected: Trojan-Spy.Win32.Agent.cse 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F2C0001\4F3D67F4.VBN Infected: Trojan-Spy.Win32.Agent.cse 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0000\4D3D5E48.VBN Infected: P2P-Worm.Win32.Agent.hc 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0001\4D3D5E52.VBN Infected: P2P-Worm.Win32.Agent.hc 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0002\4D3D5E5C.VBN Infected: P2P-Worm.Win32.Agent.hc 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0003\4D3D5E66.VBN Infected: P2P-Worm.Win32.Agent.hc 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0005\4D3DB34D.VBN Infected: Trojan.Win32.Buzus.aavd 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D2C0006\4D3DB39B.VBN Infected: Trojan.Win32.Buzus.aavd 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EC40000\4FFEC525.VBN Infected: Backdoor.Win32.KeyStart.e 1 C:\Documents and Settings\All Users\Dados de aplicativos\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FDC0000\4FDDF785.VBN Infected: Trojan-Downloader.Win32.Agent.atru 1 C:\Documents and Settings\All Users\Documentos\vinaaj.exe Infected: Trojan.Win32.Autoit.fi 1 C:\Documents and Settings\Um\Configurações locais\Temporary Internet Files\Content.IE5\2WHEPMFS\wssl713fro[1].exe Infected: Backdoor.Win32.KeyStart.m 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP5\A0001348.exe Infected: Trojan.Win32.Autoit.hk 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP5\A0001361.exe Infected: Trojan.Win32.Autoit.fi 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP9\A0003787.exe Infected: Trojan.Win32.Autoit.in 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP9\A0003793.exe Infected: Trojan.Win32.Autoit.gc 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP9\A0003794.exe Infected: Trojan.Win32.Autoit.gc 1 C:\System Volume Information\_restore{7861127C-E3B9-489F-A71F-9422B20404C2}\RP9\A0003795.exe Infected: Trojan.Win32.Autoit.in 1 C:\Recycled\Dc2\backups\backups.zip Infected: Trojan.Win32.Autoit.in 1 C:\Recycled\Dc2\backups\backups.zip Infected: Trojan.Win32.Autoit.gc 1 C:\KomboFix\N_\13700 Infected: EICAR-Test-File 1 D:\Backup\emails\Incred Mail 05-06-2008\IM\Identities\{89740109-BA9F-417F-9018-2AB3A53EAE9F}\Message Store\Message Store\Attachments\LogMeIn.zip Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a 1 D:\Backup\emails\Incred Mail 05-06-2008\IM\Identities\{89740109-BA9F-417F-9018-2AB3A53EAE9F}\Message Store\Message Store\Attachments\LogMeIn.zip Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.c 1 D:\Backup\emails\Outlook Express 02-05-2008\Caixa de entrada.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1 D:\uzdorb.exe Infected: Trojan.Win32.Autoit.fj 1 D:\ddtnvn.exe Infected: Trojan.Win32.Autoit.fi 1 E:\ddtnvn.exe Infected: Trojan.Win32.Autoit.fi 1 F:\ddtnvn.exe Infected: Trojan.Win32.Autoit.fi 1 F:\uzdorb.exe Infected: Trojan.Win32.Autoit.fj 1 The selected area was scanned. Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 12, 2008 1ª Etapa Antes de mais nada, limpe a quarentena do Norton Antivirus. Vá em Iniciar > Executar, digite: sysdm.cpl e dê um Enter. Clique na aba Restauração do Sistema e marque a opção Desativar restauração do sistema. Dê um Aplicar e OK. Após isto, volte lá e desmarque esta opção. 2ª Etapa - Faça o download do ComboFix e salve-o na área de trabalho; ● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus; ● Duplo clique no ícone combofix.exe para iniciar o scan; ● Leia o contrato que aparecerá e clique em Sim para continuar; ● Abrirá uma janela do Console de Recuperação, clique em Sim para instalar. Se aparecer outra janela do Console, clique em OK > Sim; ● Aguarde enquanto o ComboFix faz o scan; ● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento; ● Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta; ● Se quiser sair ou parar o ComboFix, tecle N; ● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde; ● Será gerado um log em C:\ComboFix.txt. Cole este log em sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 13, 2008 Tentei executar o ComboFix conforme orientação, porém no momento que entra a mensagem de alteração do relógio, (que quase não dá para ler) pois entra a tela azul com invalid_Kernel_Handle e a seguinte mensagem no final da tela azul: informação técnica stop: 0x00000093 (0x000005EC, 0x00000000, 0x00000000, 0x00000000), além de outras informações inclusive para tentar no modo de segurança, mesmo quando já o está usando. Devido a esse problema, não tenho como mandar o Log do ComboFix. Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 13, 2008 - Faça o download do RSIT e salve no seu desktop; ● Dê dois cliques em RSIT.exe para executar o programa; ● Na janela que abrir clique no botão Continue para que a ferramenta comece a rodar; ● Quando a ferramenta terminar de rodar, abrirá um log automaticamente no bloco de notas contendo o resultado do scan. Cole o resultado desse log (log.txt) na sua próxima resposta; ● Cole também o conteúdo do arquivo info.txt que estará em C:\rsit\info.txt. Compartilhar este post Link para o post Compartilhar em outros sites
Tigre13 0 Denunciar post Postado Dezembro 13, 2008 Olá, segue os relatórios RSIT Logfile of random's system information tool 1.04 (written by random/random) Run by Um at 2008-12-13 15:30:06 Microsoft Windows XP Professional Service Pack 2 System drive C: has 10 GB (25%) free of 38 GB Total RAM: 1023 MB (60% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:30, on 2008-12-13 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\windows\System32\smss.exe C:\windows\system32\csrss.exe C:\windows\system32\winlogon.exe C:\windows\system32\services.exe C:\windows\system32\lsass.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\windows\System32\svchost.exe C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe C:\windows\system32\svchost.exe C:\windows\system32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\windows\system32\spoolsv.exe C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe C:\windows\system32\nvsvc32.exe C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe C:\windows\Explorer.EXE C:\windows\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe C:\ARQUIV~1\SYMANT~1\VPTray.exe C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe C:\windows\system32\RUNDLL32.EXE C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Microsoft Money\System\reminder.exe C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\SpeedFan\speedfan.exe C:\windows\System32\alg.exe C:\Documents and Settings\Um\Desktop\RSIT.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\HiJack\Um.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [ACORDA] C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Reminder] C:\Arquivos de programas\Microsoft Money\System\reminder.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: SpeedFan.lnk = C:\Arquivos de programas\SpeedFan\speedfan.exe O8 - Extra context menu item: Add to EverNote - res://C:\Arquivos de programas\EverNote\EverNote\enbar.dll/2000 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Arquivos de programas\EverNote\EverNote\enbar.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\Software\..\Telephony: DomainName = UM O17 - HKLM\System\CCS\Services\Tcpip\..\{3FC3B0ED-1D34-4E79-A979-0B23D10D35BF}: NameServer = 192.168.1.254 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = UM O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = UM O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\windows\System32\TuneUpDefragService.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe -- End of file - 9611 bytes ======Scheduled tasks folder====== C:\windows\tasks\1-Click Maintenance.job C:\windows\tasks\GoogleUpdateTaskUser.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] Spybot-S&D IE Protection - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Arquivos de programas\Java\jre6\bin\ssv.dll [2008-12-02 320920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540003}] GbIehObj Class - C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2008-04-01 337992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll [2008-12-02 34816] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-02 73728] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "High Definition Audio Property Page Shortcut"=C:\windows\system32\HDAShCut.exe [2004-10-27 61952] "SoundMAXPnP"=C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696] "SoundMAX"=C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe [2005-09-07 716800] "ACORDA"=C:\Arquivos de programas\Fábrica de Bits\ACORDA\acorda.exe [2004-09-04 483328] "ccApp"=C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe [2006-03-07 53408] "vptray"=C:\ARQUIV~1\SYMANT~1\VPTray.exe [2006-03-17 124656] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Arquivos de programas\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-03 13529088] "nwiz"=nwiz.exe /install [] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-03 86016] "SunJavaUpdateSched"=C:\Arquivos de programas\Java\jre6\bin\jusched.exe [2008-12-02 136600] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Reminder"=C:\Arquivos de programas\Microsoft Money\System\reminder.exe [1998-07-25 36864] "ctfmon.exe"=C:\windows\system32\ctfmon.exe [2004-08-04 15360] "Google Update"=C:\Documents and Settings\Um\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe [2008-09-09 133104] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage] C:\Arquivos de programas\AdVantage\AdVantage.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] C:\Arquivos de programas\DAEMON Tools\daemon.exe [2007-08-16 167368] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVD43] C:\Arquivos de programas\DVD Region+CSS Free\DVDRegionFree.exe [2004-10-22 278016] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe [2005-10-20 871936] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] C:\windows\system32\dumprep 0 -k [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Arquivos de programas\Messenger\msmsgs.exe [2004-10-13 1694208] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^KYESCAN.lnk] C:\ARQUIV~1\ScannerU\KYESCAN.exe [2002-02-01 172032] C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar SpeedFan.lnk - C:\Arquivos de programas\SpeedFan\speedfan.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginCef] C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2008-04-01 337992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit] C:\windows\system32\LMIinit.dll [2007-11-15 87352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] C:\WINDOWS\system32\NavLogon.dll [2006-03-17 43760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{93994DE8-8239-4655-B1D1-5F4E91300429}"=C:\ARQUIV~1\DVDREG~1\DVDShell.dll [2004-10-09 49152] "{E37CB5F0-51F5-4395-A808-5FA49E399003}"=C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2008-04-01 337992] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:LocalSubNet:Enabled:@xpsp3res.dll,-20000" "C:\Arquivos de programas\VideoLAN\VLC\vlc.exe"="C:\Arquivos de programas\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player" "C:\Arquivos de programas\Mozilla Firefox\firefox.exe"="C:\Arquivos de programas\Mozilla Firefox\firefox.exe:*:Enabled:Firefox" "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:LocalSubNet:Disabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##Zero#ARQUIVOS (D)] shell\AutoRun\command - Z:\ddtnvn.exe shell\explore\command - Z:\ddtnvn.exe shell\open\command - Z:\ddtnvn.exe ======List of files/folders created in the last 1 months====== 2008-12-13 15:30:06 ----D---- C:\rsit 2008-12-13 00:21:10 ----SHD---- C:\FOUND.001 2008-12-13 00:16:55 ----D---- C:\ComboFix 2008-12-13 00:16:54 ----A---- C:\windows\system32\CF18637.exe 2008-12-13 00:10:54 ----SHD---- C:\FOUND.000 2008-12-13 00:06:36 ----A---- C:\windows\system32\CF16616.exe 2008-12-11 16:36:12 ----A---- C:\windows\ntbtlog.txt 2008-12-11 11:07:46 ----HD---- C:\windows\$NtUninstallKB952069_WM9$ 2008-12-11 11:07:41 ----HD---- C:\windows\$NtUninstallKB955839$ 2008-12-11 11:06:15 ----HD---- C:\windows\$NtUninstallKB954600$ 2008-12-11 11:06:11 ----A---- C:\windows\imsins.BAK 2008-12-11 11:06:08 ----HD---- C:\windows\$NtUninstallKB956802$ 2008-12-09 16:27:30 ----A---- C:\windows\system32\CF30496.exe 2008-12-09 16:09:57 ----A---- C:\windows\NIRCMD.exe 2008-12-09 16:09:50 ----D---- C:\KomboFix 2008-12-09 16:09:50 ----A---- C:\windows\system32\CF27038.exe 2008-12-09 16:03:19 ----A---- C:\windows\system32\CF25761.exe 2008-12-08 15:49:25 ----D---- C:\HiJack 2008-12-08 15:40:43 ----N---- C:\windows\system32\cftm.exe 2008-12-08 12:05:54 ----A---- C:\windows\wininit.ini 2008-12-07 12:27:58 ----A---- C:\wttrqla.exe 2008-12-04 16:57:50 ----A---- C:\windows\system32\CF1969.exe 2008-12-03 13:44:25 ----A---- C:\windows\system32\CF9606.exe 2008-12-03 13:42:45 ----SHD---- C:\windows\CSC 2008-12-03 13:38:28 ----A---- C:\windows\system32\CF8440.exe 2008-12-02 20:41:46 ----D---- C:\Documents and Settings\Um\Dados de aplicativos\WinRAR 2008-12-02 20:36:49 ----D---- C:\windows\ERUNT 2008-12-02 20:07:50 ----A---- C:\windows\system32\CF31960.exe 2008-12-02 19:05:35 ----A---- C:\windows\system32\CF19760.exe 2008-12-02 17:23:26 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-12-02 17:23:26 ----D---- C:\Arquivos de programas\Spybot - Search & Destroy 2008-12-02 15:51:49 ----D---- C:\cmdcons 2008-12-02 15:49:29 ----A---- C:\windows\zip.exe 2008-12-02 15:49:29 ----A---- C:\windows\VFIND.exe 2008-12-02 15:49:29 ----A---- C:\windows\SWXCACLS.exe 2008-12-02 15:49:29 ----A---- C:\windows\SWSC.exe 2008-12-02 15:49:29 ----A---- C:\windows\SWREG.exe 2008-12-02 15:49:29 ----A---- C:\windows\sed.exe 2008-12-02 15:49:29 ----A---- C:\windows\grep.exe 2008-12-02 15:49:29 ----A---- C:\windows\fdsv.exe 2008-12-02 15:48:52 ----D---- C:\windows\ERDNT 2008-12-02 15:48:51 ----D---- C:\Qoobox 2008-12-02 15:48:51 ----A---- C:\windows\system32\CF13984.exe 2008-11-14 14:22:51 ----D---- C:\Arquivos de programas\MSXML 4.0 ======List of files/folders modified in the last 1 months====== 2008-12-13 11:56:06 ----A---- C:\windows\SchedLgU.Txt 2008-12-09 21:24:38 ----A---- C:\windows\system32\MRT.exe 2008-12-08 02:01:30 ----A---- C:\windows\NeroDigital.ini 2008-12-07 19:16:26 ----A---- C:\windows\DVDRegionFree.INI 2008-12-02 21:08:00 ----A---- C:\windows\system32\javaws.exe 2008-12-02 21:08:00 ----A---- C:\windows\system32\javaw.exe 2008-12-02 21:08:00 ----A---- C:\windows\system32\java.exe 2008-12-02 21:08:00 ----A---- C:\windows\system32\deploytk.dll 2008-11-29 16:24:32 ----RAH---- C:\windows\system32\cdplayer.exe.manifest ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\eeCtrl.sys [] R1 InCDPass;InCDPass; C:\windows\system32\drivers\InCDPass.sys [2005-10-14 29440] R1 incdrm;InCD Reader; C:\windows\system32\drivers\InCDRm.sys [2005-10-14 22016] R1 intelppm;Driver de Processador Intel; C:\windows\system32\DRIVERS\intelppm.sys [2004-08-04 40192] R1 PQNTDrv;PQNTDrv; C:\windows\system32\drivers\PQNTDrv.sys [2002-09-16 4228] R1 SAVRT;SAVRT; \??\C:\Arquivos de programas\Symantec AntiVirus\savrt.sys [] R1 SAVRTPEL;SAVRTPEL; \??\C:\Arquivos de programas\Symantec AntiVirus\Savrtpel.sys [] R1 SPBBCDrv;SPBBCDrv; \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCDrv.sys [] R1 SYMTDI;SYMTDI; C:\windows\System32\Drivers\SYMTDI.SYS [2006-01-24 195776] R2 BulkUsb;Genius ColorPage USB Scanner; C:\windows\system32\DRIVERS\usbscan.sys [2004-08-03 15104] R2 hcmon;VMware hcmon; \??\C:\WINDOWS\system32\Drivers\hcmon.sys [] R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [] R2 VMnetBridge;VMware Bridge Protocol; C:\windows\system32\DRIVERS\vmnetbridge.sys [2007-05-01 28592] R2 VMnetuserif;VMware Network Application Interface; \??\C:\WINDOWS\system32\drivers\vmnetuserif.sys [] R2 VMparport;VMware VMparport; \??\C:\WINDOWS\system32\Drivers\VMparport.sys [] R2 vmx86;VMware vmx86; \??\C:\WINDOWS\system32\Drivers\vmx86.sys [] R2 vstor2;Vstor2 Virtual Storage Driver; \??\C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vstor2.sys [] R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\C:\Arquivos de programas\VMware\VMware Workstation\vstor2-ws60.sys [] R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\ADIHdAud.sys [2005-10-05 141312] R3 AEAudioService;AEAudio Service; C:\windows\system32\drivers\AEAudio.sys [2005-03-04 127872] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [] R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\windows\system32\DRIVERS\fetnd5.sys [2001-08-17 27165] R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240] R3 lmimirr;lmimirr; C:\windows\system32\DRIVERS\lmimirr.sys [2007-08-03 10144] R3 MTsensor;ATK0110 ACPI UTILITY; C:\windows\system32\DRIVERS\ASACPI.sys [2004-08-12 5810] R3 NAVENG;NAVENG; \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20081212.004\naveng.sys [] R3 NAVEX15;NAVEX15; \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20081212.004\navex15.sys [] R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496] R3 SenFiltService;SenFilt Service; C:\windows\system32\drivers\Senfilt.sys [2005-08-11 393088] R3 SymEvent;SymEvent; \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS [] R3 SYMREDRV;SYMREDRV; C:\windows\System32\Drivers\SYMREDRV.SYS [2006-01-24 24768] R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2 Enabled Hub; C:\windows\system32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbuhci.sys [2004-08-04 20480] R3 vmkbd;VMware kbd; \??\C:\WINDOWS\system32\drivers\VMkbd.sys [] R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\windows\system32\DRIVERS\vmnetadapter.sys [2007-05-01 16816] R4 InCDfs;InCD File System; C:\windows\system32\drivers\InCDFs.sys [2005-10-14 101760] S2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Arquivos de programas\LogMeIn\x86\RaInfo.sys [] S3 Asushwio;Asushwio; \??\C:\WINDOWS\system32\drivers\Asushwio.sys [] S3 ayu9e8sz;ayu9e8sz; C:\windows\system32\drivers\ayu9e8sz.sys [] S3 catchme;catchme; \??\C:\DOCUME~1\Um\CONFIG~1\Temp\catchme.sys [] S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\HdAudio.sys [2004-10-27 145920] S3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2004-08-03 25856] S3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496] S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys [] S4 LMIRfsClientNP;LMIRfsClientNP; C:\windows\system32\drivers\LMIRfsClientNP.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ccEvtMgr;Symantec Event Manager; C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe [2006-03-07 192160] R2 ccSetMgr;Symantec Settings Manager; C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe [2006-03-07 169632] R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe [2006-03-17 30448] R2 InCDsrv;InCD Helper; C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe [2005-10-14 670208] R2 JavaQuickStarterService;Java Quick Starter; C:\Arquivos de programas\Java\jre6\bin\jqs.exe [2008-12-02 152984] R2 NMSAccessU;NMSAccessU; C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe [2007-10-12 71096] R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2008-05-02 159812] R2 SPBBCSvc;Symantec SPBBCSvc; C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe [2006-02-06 1160848] R2 Symantec AntiVirus;Symantec AntiVirus; C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe [2006-03-17 1799408] R2 UxTuneUp;TuneUp Theme Extension; C:\windows\System32\svchost.exe [2004-08-04 14336] R2 VMAuthdService;VMware Authorization Service; C:\Arquivos de programas\VMware\VMware Workstation\vmware-authd.exe [2007-05-01 109360] R2 VMnetDHCP;VMware DHCP Service; C:\WINDOWS\system32\vmnetdhcp.exe [2007-05-01 121648] R2 vmount2;VMware Virtual Mount Manager Extended; C:\Arquivos de programas\Arquivos comuns\VMware\VMware Virtual Image Editing\vmount2.exe [2007-03-23 269104] R2 VMware NAT Service;VMware NAT Service; C:\WINDOWS\system32\vmnat.exe [2007-05-01 150320] S2 GbpSv;Gbp Service; C:\ARQUIV~1\GbPlugin\GbpSv.exe [2008-04-01 46144] S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256] S3 LiveUpdate;LiveUpdate; C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-02-23 2045632] S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 SavRoam;SAVRoam; C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe [2006-03-17 115952] S3 SNDSrvc;Symantec Network Drivers Service; C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe [2006-01-24 214720] S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\windows\System32\TuneUpDefragService.exe [2008-05-20 306432] S3 ufad-ws60;VMware Agent Service; C:\Arquivos de programas\VMware\VMware Workstation\vmware-ufad.exe [2007-04-09 187184] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880] -----------------EOF----------------- info.txt logfile of random's system information tool 1.04 2008-12-13 15:30:11 ======Uninstall list====== -->C:\Arquivos de programas\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\WINDOWS\NuNInst.exe /UNINSTALL -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL -->C:\WINDOWS\UNRecode.exe /UNINSTALL -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 18 Wheels of Steel: American Long Haul -->C:\Arquivos de programas\18 Wheels of Steel American Long Haul\uninst.exe 7-Zip 4.43 alpha 3-->"C:\Arquivos de programas\7-Zip\Uninstall.exe" Acorda 1.0.5-->C:\WINDOWS\iun6002.exe "C:\Arquivos de programas\Fábrica de Bits\SGEA\irunin.ini" Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Photoshop CS-->RunDll32 C:\ARQUIV~1\ARQUIV~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Arquivos de programas\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x416 Adobe Shockwave Player-->C:\WINDOWS\system32\ADOBE\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\ADOBE\SHOCKW~1\INSTALL.LOG Alien Skin Image Doctor 1.0-->C:\ARQUIV~1\ADOBE\PHOTOS~1\PLUG-INS\IMAGED~1\UNWISE.EXE C:\ARQUIV~1\ADOBE\PHOTOS~1\PLUG-INS\IMAGED~1\INSTALL.LOG Arquivo do WinRAR-->C:\Arquivos de programas\WinRAR\uninstall.exe Atualização de Segurança para o Windows Media Player (KB952069)-->"C:\windows\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows Internet Explorer 7 (KB958215)-->"C:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe" Atualização de Segurança para Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf Atualização de Segurança para Windows XP (KB954600)-->"C:\windows\$NtUninstallKB954600$\spuninst\spuninst.exe" Atualização de Segurança para Windows XP (KB956802)-->"C:\windows\$NtUninstallKB956802$\spuninst\spuninst.exe" Atualização para Windows XP (KB955839)-->"C:\windows\$NtUninstallKB955839$\spuninst\spuninst.exe" BS.Player FREE powered by AdVantage-->"C:\Arquivos de programas\Webteh\BSplayer\uninstall.exe" CCleaner (remove only)-->"C:\Arquivos de programas\CCleaner\uninst.exe" CDBurnerXP-->"C:\Arquivos de programas\CDBurnerXP\unins000.exe" Coleção 18 Wheel of Steel v1.2.1-->"C:\Jogos\unins000.exe" CorelDRAW Graphics Suite 12-->MsiExec.exe /I{505AFDC0-5E72-4928-8368-5DEA385E3647} CuteFTP 7 Professional-->RunDll32 C:\ARQUIV~1\ARQUIV~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Arquivos de programas\InstallShield Installation Information\{1CCBCF78-EF12-4137-B3CA-99F30A2E7D21}\Setup.exe" -l0x9 DVD Region+CSS Free 5.58-->"C:\Arquivos de programas\DVD Region+CSS Free\unins000.exe" EVEREST Corporate Edition v3.50-->"C:\Arquivos de programas\Lavalys\EVEREST Corporate Edition\unins000.exe" EverNote-->C:\Arquivos de programas\InstallShield Installation Information\{00C297B1-02F3-4BEE-8B57-7BCA695A41DA}\setup.exe -runfromtemp -l0x0009 -removeonly FTP Commander-->C:\Arquivos de programas\FTP Commander\uninstall.exe Genius Scanner-->RunDll32 C:\ARQUIV~1\ARQUIV~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Arquivos de programas\InstallShield Installation Information\{CCEB2144-5F5D-49E8-AADC-05CA48AE9AA5}\setup.exe" Google Gmail Notifier-->"C:\Arquivos de programas\Google\Gmail Notifier\UninstallGmail.exe" HijackThis 2.0.2-->"C:\HiJack\HijackThis.exe" /uninstall Hotfix para Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe" Image Resizer Powertoy for Windows XP-->MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29} Java 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF} Java 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} K-Lite Mega Codec Pack 4.0.0-->"C:\Arquivos de programas\K-Lite Codec Pack\unins001.exe" L&H Power Translator Pro 7.0-->C:\WINDOWS\ISUN0416.EXE -f"C:\Arquivos de programas\LHSP\L&H Power Translator Pro\Uninst.isu" -c"C:\Arquivos de programas\LHSP\L&H Power Translator Pro\Uninstall.dll" LiveUpdate 3.0 (Symantec Corporation)-->"C:\Arquivos de programas\Symantec\LiveUpdate\LSETUP.EXE" /U Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783} Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40} Microsoft Money 99-->C:\Arquivos de programas\Microsoft Money\setup\setup.exe Microsoft Office OneNote 2003-->MsiExec.exe /I{90A10416-6000-11D3-8CFE-0150048383C9} Microsoft Office Professional Edição 2003-->MsiExec.exe /I{90110416-6000-11D3-8CFE-0150048383C9} Mozilla Firefox (2.0.0.17)-->C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96} Nero 7 Demo-->MsiExec.exe /I{D32F9C0D-6B15-5DCC-3AAD-EC3E7B611046} NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI PowerQuest PartitionMagic 8.0-->C:\ARQUIV~1\ARQUIV~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6BE2A4A4-99FB-48ED-AE1E-4E850389F804} Real Alternative 1.7.5-->"C:\Arquivos de programas\Real Alternative\unins000.exe" SoundMAX-->RunDll32 C:\ARQUIV~1\ARQUIV~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Arquivos de programas\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x416 -removeonly SpeedFan (remove only)-->"C:\Arquivos de programas\SpeedFan\uninstall.exe" Sprint & FineReader 5.0 Office Try&Buy-->C:\WINDOWS\bitdein2.exe C:\ARQUIV~1\SPRINT~1.0OF\bitdeins.ini Spybot - Search & Destroy-->"C:\Arquivos de programas\Spybot - Search & Destroy\unins000.exe" Symantec AntiVirus-->MsiExec.exe /I{A011A1DC-7F1D-4EA8-BD11-0C5F9718E428} System Requirements Lab-->C:\Arquivos de programas\SystemRequirementsLab\Uninstall.exe TuneUp Utilities 2008-->MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA} Unlocker 1.7.5-->C:\Arquivos de programas\Unlocker\uninst.exe VideoLAN VLC media player 0.8.6d-->C:\Arquivos de programas\VideoLAN\VLC\uninstall.exe VMware Workstation-->MsiExec.exe /I{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA} Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe" Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} winLAME prerelease4-->MsiExec.exe /I{062BFFA1-0CCC-400B-B840-F162328D8C00} XnView 1.93.1-->"C:\Arquivos de programas\XnView\unins000.exe" ======Hosts File====== 127.0.0.1 localhost ======Security center information====== AV: Symantec AntiVirus Corporate Edition ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel "PROCESSOR_REVISION"=0604 "NUMBER_OF_PROCESSORS"=2 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP -----------------EOF----------------- Compartilhar este post Link para o post Compartilhar em outros sites
MGuitar 11 Denunciar post Postado Dezembro 13, 2008 Acesse o VirusTotal e envie o arquivo em destaque abaixo para uma análise. C:\windows\system32\drivers\ayu9e8sz.sys Copie o link que estará em frente ao nome Permalink e cole-o aqui. - Faça o download do OTMoveIt3 e salve no desktop; ● Dê um duplo clique no ícone do programa (OTMoveIt3) para executá-lo; ● Selecione e copie todo este conteúdo aqui abaixo: :Processesexplorer.exe:FilesC:\Arquivos de programas\AdVantageC:\Arquivos de programas\AdVantage\AdVantage.exeZ:\ddtnvn.exeC:\FOUND.001C:\FOUND.000C:\windows\system32\cftm.exeC:\wttrqla.exeC:\Qoobox:Reg[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage][-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##Zero#ARQUIVOS (D)]:Commands [purity][emptytemp][start explorer][Reboot] ● Cole o que você copiou no programa (no espaço em branco da janela); ● Clique no botão MoveIt; ● Se aparecer uma mensagem para reiniciar o computador, reinicie-o; ● Na sua proxima resposta, copie e cole o todo o conteúdo que está em Results; ● Se o computador reiniciou, vá na pasta C:\_OTMoveIt\MovedFiles, e abra o mais recente arquivo .log presente. Copie e cole todo o conteúdo desse arquivo. Cole também com o resultado da análise do VirusTotal. Compartilhar este post Link para o post Compartilhar em outros sites