altasena 0 Denunciar post Postado Dezembro 27, 2008 Olá, pessoal estou novamente precisando da ajuda de vcs!!! Não sei mais o que fazer!! Grato Altair! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:44:23, on 27/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe C:\Arquivos de programas\D-Tools\daemon.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\QuickTime\QTTask.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\WINDOWS\vsnpstd.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Skype\Phone\Skype.exe C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe C:\WINDOWS\system32\twumk.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\LightSurf\Common\IconMgr.exe C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\system32\SearchIndexer.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\Altair.HOME\Configurações locais\Temporary Internet Files\Content.IE5\TIGEHO6T\HiJackThis[2].exe C:\WINDOWS\system32\HPZipm12.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXNHWQK.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll O2 - BHO: {b2755231-0b14-6dc9-be34-bedbe901145c} - {c541109e-bdeb-43eb-9cd6-41b01325572b} - C:\WINDOWS\system32\tefmey.dll O2 - BHO: (no name) - {C7EF6252-DF2E-4622-B55A-D25E0736DFF3} - C:\WINDOWS\system32\cbXOFvUK.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing) O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [84af38f1] rundll32.exe "C:\WINDOWS\system32\swuwcsdo.dll",b O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Sumário do OneNote.onetoc2 O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: c:\arquiv~1\bandoo\bndhook.dll,avgrsstx.dll tefmey.dll O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll (file missing) O20 - Winlogon Notify: cbXNHWQK - C:\WINDOWS\SYSTEM32\cbXNHWQK.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe -- End of file - 12214 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 28, 2008 Boa Tarde! altasena <@> Baixe: < ComboFix.exe > ( ...by sUBs ) <@> Salve-o no Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link! <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter! ---------------------- <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
altasena 0 Denunciar post Postado Dezembro 28, 2008 Boa Tarde! altasena <@> Baixe: < ComboFix.exe > ( ...by sUBs ) <@> Salve-o no Desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link! <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter! ---------------------- <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Olá amigo fiz o que você pediu!!! Muito grato !! UM abraço! ComboFix 08-12-28.01 - Altair 2008-12-28 18:16:47.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.452 [GMT -2:00] Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\arquivos de programas\Antivirus 2009 c:\arquivos de programas\Antivirus 2009\av2009.exe c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat c:\windows\pi.exe c:\windows\system32\amjgjc.dll c:\windows\system32\Cache c:\windows\system32\cbXNHWQK.dll c:\windows\system32\cbXOFvUK.dll c:\windows\system32\cmifrr.dll c:\windows\system32\efcBrOhh.dll c:\windows\system32\eijscg.dll c:\windows\system32\erkfykas.dll c:\windows\system32\fluqfwcb.dll c:\windows\system32\gbiehuni.dll , GBIEHCEF.DLL , gbiehabn.dll, GBIEHABN.DLL, SCPSSSH2.DLL c:\windows\system32\gegsvdwq.dll c:\windows\system32\ieupdates.exe c:\windows\system32\Implode.dll c:\windows\system32\jmgnlsib.dll c:\windows\system32\KUvFOXbc.ini c:\windows\system32\KUvFOXbc.ini2 c:\windows\system32\odscwuws.ini c:\windows\system32\ogkdymgg.ini c:\windows\system32\qwdvsgeg.ini c:\windows\system32\tefmey.dll c:\windows\system32\xywgaeve.dll ----- BITS: Sites possivelmente infetados ----- hxxp://childhe.com . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_GBPSV -------\Service_GbpSv (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-28 )))))))))))))))))))))))))))) . 2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft 2008-12-27 12:26 . 2008-12-27 12:25 401,720 --a------ C:\HiJackThis.exe 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon 2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll 2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-12-22 18:09 . 2008-12-24 19:49 <DIR> d-------- c:\windows\system32\Prefetchxs 2008-12-22 18:09 . 2008-12-28 14:28 <DIR> d-------- c:\windows\system32\CatRoot_3 2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe 2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe 2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm 2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm 2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao 2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD 2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX 2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL 2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL 2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386 2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386 2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI 2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY 2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV 2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE 2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL 2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL 2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL 2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games 2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl 2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm 2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm 2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll 2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft 2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft 2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule 2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin 2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express 2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java 2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help 2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype 2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist 2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin 2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8 2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2 2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe 2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed 2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus! 2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller 2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live 2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector 2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft 2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr 2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe 2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys 2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys 2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys 2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys 2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys 2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys 2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys 2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys 2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys 2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152] "PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992] "twumk.exe"="c:\windows\system32\twumk.exe" [2008-12-22 478064] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064] "ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768] "SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544] "DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152] "QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696] "iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600] c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] Sum rio do OneNote.onetoc2 [2008-04-15 3656] c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\ ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768] HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472] LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304] Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Valve\\hlds.exe"= "c:\\Arquivos de programas\\Valve\\hl.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"= "c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"= "c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"= "c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928] R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704] R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040] S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys [] S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys [] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34] 2008-12-28 c:\windows\Tasks\okvtgigf.job - c:\windows\system32\rundll32.exe [2008-04-14 00:21] . - - - - ORFÃOS REMOVIDOS - - - - BHO-{4c956910-c391-4da7-8b81-3a2feefd6a37} - c:\windows\system32\amjgjc.dll BHO-{C025DEA7-A297-406D-9FA7-A62C66973A3D} - c:\windows\system32\cbXOFvUK.dll HKCU-Run-Nero PhotoShow Media Manager - c:\arquiv~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe HKCU-Run-ares - c:\arquivos de programas\Ares\Ares.exe HKLM-Run-WinampAgent - c:\arquivos de programas\Winamp\winampa.exe HKLM-Run-NWEReboot - (no file) ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399007} - c:\arquiv~1\GbPlugin\gbiehabn.dll Notify- GbPluginAbn - c:\arquiv~1\GbPlugin\gbiehabn.dll . ------- Scan Suplementar ------- . uStart Page = hxxp://www.globo.com.br/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} uInternet Connection Wizard,ShellNext = iexplore IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A} hxxp://www.powerchallenge.com/applet/PowerLoader.cab c:\windows\Downloaded Program Files\PowerLoader.inf O16 -: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab c:\windows\Downloaded Program Files\GbPluginABN.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-28 18:24:53 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(688) c:\windows\system32\Ati2evxx.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\windows\system32\ati2evxx.exe c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe c:\windows\system32\ati2evxx.exe c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\arquivos de programas\Bonjour\mDNSResponder.exe c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\UAService7.exe c:\windows\system32\searchindexer.exe c:\arquivos de programas\AVG\AVG8\avgrsx.exe c:\arquivos de programas\iPod\bin\iPodService.exe c:\windows\system32\wbem\wmiapsrv.exe . ************************************************************************** . Tempo para conclusão: 2008-12-28 18:29:36 - Máquina reiniciou [Altair] ComboFix-quarantined-files.txt 2008-12-28 20:29:11 Pré-execução: 41 pasta(s) 19.734.994.944 bytes disponíveis Pós execução: 41 pasta(s) 20,452,155,392 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 276 --- E O F --- 2008-12-19 21:40:20 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:35:05, on 28/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\D-Tools\daemon.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\QuickTime\QTTask.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Skype\Phone\Skype.exe C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe C:\WINDOWS\system32\twumk.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\LightSurf\Common\IconMgr.exe C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\system32\SearchIndexer.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Altair.HOME\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing) O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Sumário do OneNote.onetoc2 O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe -- End of file - 10892 bytes Um abraço!!! Te aguardo! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 29, 2008 Boa Noite! altasena <@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas. <@> Salve-o,no Desktop,com o nome: CFScript.txt Files::c:\windows\system32\jkkjIbxy.dll c:\windows\system32\twumk.exe c:\windows\system32\jumps.exe c:\windows\Tasks\okvtgigf.job C:\sqmdata18.sqm C:\sqmnoopt18.sqm C:\sqmdata17.sqm C:\sqmnoopt17.sqm Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "twumk.exe"=- Folder:: c:\windows\system32\Prefetchxs c:\windows\system32\CatRoot_3 <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix. <@> Ps: Faça o arraste,até surgir essa solicitação! ( janela ) <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
altasena 0 Denunciar post Postado Dezembro 29, 2008 Boa Noite! altasena <@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas. <@> Salve-o,no Desktop,com o nome: CFScript.txt Files::c:\windows\system32\jkkjIbxy.dll c:\windows\system32\twumk.exe c:\windows\system32\jumps.exe c:\windows\Tasks\okvtgigf.job C:\sqmdata18.sqm C:\sqmnoopt18.sqm C:\sqmdata17.sqm C:\sqmnoopt17.sqm Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "twumk.exe"=- Folder:: c:\windows\system32\Prefetchxs c:\windows\system32\CatRoot_3 <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix. <@> Ps: Faça o arraste,até surgir essa solicitação! ( janela ) <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Olá DigRam, desde já quero lhe agradecer a atenção!! Abaixo posto o que você pede!! Um abraço!! Altair!! ComboFix 08-12-28.01 - Altair 2008-12-29 15:03:04.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.473 [GMT -2:00] Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\CatRoot_3 c:\windows\system32\CatRoot_3\edb.chk c:\windows\system32\CatRoot_3\TimeStemp c:\windows\system32\Prefetchxs c:\windows\system32\Prefetchxs\euzinho.rifle@gmail.com c:\windows\system32\Prefetchxs\paulaa1968@gmail.com c:\windows\system32\Prefetchxs\ruan1995@globo.com c:\windows\system32\Prefetchxs\uid=10073878566382367689 c:\windows\system32\Prefetchxs\uid=10093758571540450781 c:\windows\system32\Prefetchxs\uid=10318076534728906346 c:\windows\system32\Prefetchxs\uid=10376206228721919992 c:\windows\system32\Prefetchxs\uid=1037826073188409423 c:\windows\system32\Prefetchxs\uid=1051980406115856981 c:\windows\system32\Prefetchxs\uid=1055921848046133103 c:\windows\system32\Prefetchxs\uid=10721037389106661121 c:\windows\system32\Prefetchxs\uid=10728788135134822204 c:\windows\system32\Prefetchxs\uid=10753374287914678364 c:\windows\system32\Prefetchxs\uid=10877353640376038936 c:\windows\system32\Prefetchxs\uid=10918111566442582744 c:\windows\system32\Prefetchxs\uid=10950601282798126008 c:\windows\system32\Prefetchxs\uid=10956919542720223358 c:\windows\system32\Prefetchxs\uid=11016391003574553870 c:\windows\system32\Prefetchxs\uid=11020678768250863806 c:\windows\system32\Prefetchxs\uid=11036436431735649852 c:\windows\system32\Prefetchxs\uid=11199477647029985133 c:\windows\system32\Prefetchxs\uid=11262391093952789965 c:\windows\system32\Prefetchxs\uid=11280594305607972052 c:\windows\system32\Prefetchxs\uid=11358131272357950205 c:\windows\system32\Prefetchxs\uid=11443970396258807410 c:\windows\system32\Prefetchxs\uid=11484878243886469514 c:\windows\system32\Prefetchxs\uid=11571005024792751819 c:\windows\system32\Prefetchxs\uid=11745451256050003900 c:\windows\system32\Prefetchxs\uid=11749763375533333310 c:\windows\system32\Prefetchxs\uid=11797652174971255140 c:\windows\system32\Prefetchxs\uid=11813171764432298374 c:\windows\system32\Prefetchxs\uid=11830588709266355629 c:\windows\system32\Prefetchxs\uid=11839414164978064914 c:\windows\system32\Prefetchxs\uid=11874960705434815573 c:\windows\system32\Prefetchxs\uid=11916729235859937679 c:\windows\system32\Prefetchxs\uid=12010613158930182566 c:\windows\system32\Prefetchxs\uid=1205304755662828404 c:\windows\system32\Prefetchxs\uid=12096663257902347545 c:\windows\system32\Prefetchxs\uid=1213353535175675734 c:\windows\system32\Prefetchxs\uid=12199251504948993038 c:\windows\system32\Prefetchxs\uid=12201939323992660801 c:\windows\system32\Prefetchxs\uid=12235547070827549821 c:\windows\system32\Prefetchxs\uid=12244952592532755868 c:\windows\system32\Prefetchxs\uid=12270485368898448011 c:\windows\system32\Prefetchxs\uid=12284256882460730488 c:\windows\system32\Prefetchxs\uid=12286974763530794004 c:\windows\system32\Prefetchxs\uid=12297297778612910959 c:\windows\system32\Prefetchxs\uid=12343713330503194813 c:\windows\system32\Prefetchxs\uid=12369969336459853282 c:\windows\system32\Prefetchxs\uid=12461194792458146462 c:\windows\system32\Prefetchxs\uid=12593241567072277950 c:\windows\system32\Prefetchxs\uid=12646740765483213484 c:\windows\system32\Prefetchxs\uid=12656349530278003562 c:\windows\system32\Prefetchxs\uid=12759868615278858725 c:\windows\system32\Prefetchxs\uid=12785222156104882519 c:\windows\system32\Prefetchxs\uid=12926907381779125893 c:\windows\system32\Prefetchxs\uid=12979005293491328285 c:\windows\system32\Prefetchxs\uid=13004242084970453072 c:\windows\system32\Prefetchxs\uid=13248116689144518380 c:\windows\system32\Prefetchxs\uid=13319763956901222665 c:\windows\system32\Prefetchxs\uid=13408001446782127852 c:\windows\system32\Prefetchxs\uid=13575821045996628990 c:\windows\system32\Prefetchxs\uid=13578932015319581870 c:\windows\system32\Prefetchxs\uid=13586797816265553385 c:\windows\system32\Prefetchxs\uid=13618910123000198975 c:\windows\system32\Prefetchxs\uid=1368406374434022710 c:\windows\system32\Prefetchxs\uid=13708106737354049354 c:\windows\system32\Prefetchxs\uid=14033681777567248755 c:\windows\system32\Prefetchxs\uid=14154274315834407116 c:\windows\system32\Prefetchxs\uid=14345836480146051042 c:\windows\system32\Prefetchxs\uid=14391558695245912892 c:\windows\system32\Prefetchxs\uid=14397424949232815178 c:\windows\system32\Prefetchxs\uid=14517859927662358394 c:\windows\system32\Prefetchxs\uid=14621169681292567846 c:\windows\system32\Prefetchxs\uid=14758020743406156925 c:\windows\system32\Prefetchxs\uid=14758331840854850809 c:\windows\system32\Prefetchxs\uid=14788114409140444079 c:\windows\system32\Prefetchxs\uid=14836681653344905388 c:\windows\system32\Prefetchxs\uid=14837581274728878233 c:\windows\system32\Prefetchxs\uid=15099378276452038829 c:\windows\system32\Prefetchxs\uid=15139606282167918330 c:\windows\system32\Prefetchxs\uid=15227835053411261543 c:\windows\system32\Prefetchxs\uid=15319911708974642101 c:\windows\system32\Prefetchxs\uid=15333671415825547775 c:\windows\system32\Prefetchxs\uid=15443312399709093574 c:\windows\system32\Prefetchxs\uid=15591697453809545723 c:\windows\system32\Prefetchxs\uid=15610140654977286660 c:\windows\system32\Prefetchxs\uid=15631772112373874146 c:\windows\system32\Prefetchxs\uid=15650598175424752713 c:\windows\system32\Prefetchxs\uid=1572516361401864176 c:\windows\system32\Prefetchxs\uid=15779539878669013717 c:\windows\system32\Prefetchxs\uid=15986415852703340375 c:\windows\system32\Prefetchxs\uid=16045898512434157296 c:\windows\system32\Prefetchxs\uid=16089154660527986624 c:\windows\system32\Prefetchxs\uid=16092442136748431046 c:\windows\system32\Prefetchxs\uid=16098201787268449689 c:\windows\system32\Prefetchxs\uid=16203958252952290316 c:\windows\system32\Prefetchxs\uid=16459392728856169014 c:\windows\system32\Prefetchxs\uid=16537765680623062569 c:\windows\system32\Prefetchxs\uid=16541748872158314859 c:\windows\system32\Prefetchxs\uid=16752773174491741816 c:\windows\system32\Prefetchxs\uid=16815558688181237951 c:\windows\system32\Prefetchxs\uid=16849388344701797543 c:\windows\system32\Prefetchxs\uid=1695625355352171933 c:\windows\system32\Prefetchxs\uid=17007434935122131458 c:\windows\system32\Prefetchxs\uid=17026999308948241214 c:\windows\system32\Prefetchxs\uid=17087965737943822296 c:\windows\system32\Prefetchxs\uid=17104061258941128375 c:\windows\system32\Prefetchxs\uid=17149192978996363067 c:\windows\system32\Prefetchxs\uid=17283461571260786246 c:\windows\system32\Prefetchxs\uid=17371238549052410729 c:\windows\system32\Prefetchxs\uid=17409921102459049983 c:\windows\system32\Prefetchxs\uid=17453284220659407758 c:\windows\system32\Prefetchxs\uid=17470466962151896115 c:\windows\system32\Prefetchxs\uid=17572219506996396869 c:\windows\system32\Prefetchxs\uid=17594411983989541530 c:\windows\system32\Prefetchxs\uid=17611956217266136712 c:\windows\system32\Prefetchxs\uid=17630906075949467253 c:\windows\system32\Prefetchxs\uid=17725963066297716235 c:\windows\system32\Prefetchxs\uid=17774204340009323036 c:\windows\system32\Prefetchxs\uid=17832459778107465151 c:\windows\system32\Prefetchxs\uid=17840185582919609449 c:\windows\system32\Prefetchxs\uid=18033996669212227995 c:\windows\system32\Prefetchxs\uid=18092516642475707604 c:\windows\system32\Prefetchxs\uid=18094354364943314380 c:\windows\system32\Prefetchxs\uid=18135830265463537323 c:\windows\system32\Prefetchxs\uid=18164650581172002042 c:\windows\system32\Prefetchxs\uid=18181004936305455425 c:\windows\system32\Prefetchxs\uid=18264835970928276117 c:\windows\system32\Prefetchxs\uid=18363885718008299196 c:\windows\system32\Prefetchxs\uid=1857279662614826226 c:\windows\system32\Prefetchxs\uid=2130968248785583708 c:\windows\system32\Prefetchxs\uid=216482689323116115 c:\windows\system32\Prefetchxs\uid=2399042952424672621 c:\windows\system32\Prefetchxs\uid=2476615765253753718 c:\windows\system32\Prefetchxs\uid=2678703094997445236 c:\windows\system32\Prefetchxs\uid=2787885661403679677 c:\windows\system32\Prefetchxs\uid=2803487434741902881 c:\windows\system32\Prefetchxs\uid=2833342090580429834 c:\windows\system32\Prefetchxs\uid=2858862162027413768 c:\windows\system32\Prefetchxs\uid=2864067739441436794 c:\windows\system32\Prefetchxs\uid=2899585598435687001 c:\windows\system32\Prefetchxs\uid=2969901922060825967 c:\windows\system32\Prefetchxs\uid=3043016122715034243 c:\windows\system32\Prefetchxs\uid=3063404058926592050 c:\windows\system32\Prefetchxs\uid=3098975966941828863 c:\windows\system32\Prefetchxs\uid=3144168639184154694 c:\windows\system32\Prefetchxs\uid=3285559606333028835 c:\windows\system32\Prefetchxs\uid=3347575097387378572 c:\windows\system32\Prefetchxs\uid=355052566428888648 c:\windows\system32\Prefetchxs\uid=3566026570809483114 c:\windows\system32\Prefetchxs\uid=3624645770535521750 c:\windows\system32\Prefetchxs\uid=3710671789055322065 c:\windows\system32\Prefetchxs\uid=3753167318627965364 c:\windows\system32\Prefetchxs\uid=3854783922219264407 c:\windows\system32\Prefetchxs\uid=3902194959107196915 c:\windows\system32\Prefetchxs\uid=3918931612567757498 c:\windows\system32\Prefetchxs\uid=4014980926181728886 c:\windows\system32\Prefetchxs\uid=4022627279217337851 c:\windows\system32\Prefetchxs\uid=4056639853220268424 c:\windows\system32\Prefetchxs\uid=4093857205928726547 c:\windows\system32\Prefetchxs\uid=4167717884913735448 c:\windows\system32\Prefetchxs\uid=4242227188048141702 c:\windows\system32\Prefetchxs\uid=4243016045489330693 c:\windows\system32\Prefetchxs\uid=4422922577410055706 c:\windows\system32\Prefetchxs\uid=4510223448302285363 c:\windows\system32\Prefetchxs\uid=4545892322993955079 c:\windows\system32\Prefetchxs\uid=4731658822392730112 c:\windows\system32\Prefetchxs\uid=4853723186040484838 c:\windows\system32\Prefetchxs\uid=5143566996177373149 c:\windows\system32\Prefetchxs\uid=5163557574071812023 c:\windows\system32\Prefetchxs\uid=5186846842581322570 c:\windows\system32\Prefetchxs\uid=520169805547905569 c:\windows\system32\Prefetchxs\uid=5259498052295135294 c:\windows\system32\Prefetchxs\uid=5408626071421062022 c:\windows\system32\Prefetchxs\uid=5449234284126105896 c:\windows\system32\Prefetchxs\uid=5467250980643862831 c:\windows\system32\Prefetchxs\uid=549321652507702352 c:\windows\system32\Prefetchxs\uid=5521397596668568035 c:\windows\system32\Prefetchxs\uid=5629875623574554170 c:\windows\system32\Prefetchxs\uid=583320514511203722 c:\windows\system32\Prefetchxs\uid=5845373145314677688 c:\windows\system32\Prefetchxs\uid=5910815741967626367 c:\windows\system32\Prefetchxs\uid=591289038084055870 c:\windows\system32\Prefetchxs\uid=5939472925834161514 c:\windows\system32\Prefetchxs\uid=6010620053536081532 c:\windows\system32\Prefetchxs\uid=6187802616734630159 c:\windows\system32\Prefetchxs\uid=6392425348096693941 c:\windows\system32\Prefetchxs\uid=6479605176319772615 c:\windows\system32\Prefetchxs\uid=64885662926306312 c:\windows\system32\Prefetchxs\uid=6516552060363860497 c:\windows\system32\Prefetchxs\uid=6597658775284147558 c:\windows\system32\Prefetchxs\uid=659792742321439189 c:\windows\system32\Prefetchxs\uid=6640759388682189402 c:\windows\system32\Prefetchxs\uid=6678949085630121456 c:\windows\system32\Prefetchxs\uid=6696289611759756857 c:\windows\system32\Prefetchxs\uid=6708085563630436084 c:\windows\system32\Prefetchxs\uid=6769778535346891805 c:\windows\system32\Prefetchxs\uid=6832904718025177134 c:\windows\system32\Prefetchxs\uid=6884213501064563330 c:\windows\system32\Prefetchxs\uid=6976390535963747801 c:\windows\system32\Prefetchxs\uid=7183318946386091091 c:\windows\system32\Prefetchxs\uid=7247856382081566212 c:\windows\system32\Prefetchxs\uid=727995930909720907 c:\windows\system32\Prefetchxs\uid=7417978813562875197 c:\windows\system32\Prefetchxs\uid=7447859970100521944 c:\windows\system32\Prefetchxs\uid=7479574837620946000 c:\windows\system32\Prefetchxs\uid=7547919322998424447 c:\windows\system32\Prefetchxs\uid=7649585037296408922 c:\windows\system32\Prefetchxs\uid=7689447059690104835 c:\windows\system32\Prefetchxs\uid=7713853776959622769 c:\windows\system32\Prefetchxs\uid=7743603295177440899 c:\windows\system32\Prefetchxs\uid=7899684907037879963 c:\windows\system32\Prefetchxs\uid=7916152784990654420 c:\windows\system32\Prefetchxs\uid=798948828211733739 c:\windows\system32\Prefetchxs\uid=8001925070752697414 c:\windows\system32\Prefetchxs\uid=8059680416395077494 c:\windows\system32\Prefetchxs\uid=8120382425132161521 c:\windows\system32\Prefetchxs\uid=8135391379948449263 c:\windows\system32\Prefetchxs\uid=8175479418631985633 c:\windows\system32\Prefetchxs\uid=8177403549451759729 c:\windows\system32\Prefetchxs\uid=8205100703250754696 c:\windows\system32\Prefetchxs\uid=82434288492434776 c:\windows\system32\Prefetchxs\uid=8271340054378194125 c:\windows\system32\Prefetchxs\uid=8316336335839885650 c:\windows\system32\Prefetchxs\uid=8335288639516210566 c:\windows\system32\Prefetchxs\uid=8357388538391273941 c:\windows\system32\Prefetchxs\uid=8466853291579384225 c:\windows\system32\Prefetchxs\uid=8484094847063476271 c:\windows\system32\Prefetchxs\uid=8513840659578531302 c:\windows\system32\Prefetchxs\uid=8551955857254593212 c:\windows\system32\Prefetchxs\uid=870702175526869565 c:\windows\system32\Prefetchxs\uid=8765030040314685288 c:\windows\system32\Prefetchxs\uid=8801447007258465991 c:\windows\system32\Prefetchxs\uid=8821179526365770801 c:\windows\system32\Prefetchxs\uid=8858581735769172969 c:\windows\system32\Prefetchxs\uid=8928734603918484442 c:\windows\system32\Prefetchxs\uid=9004109795273719271 c:\windows\system32\Prefetchxs\uid=9214622304138349084 c:\windows\system32\Prefetchxs\uid=9215459002929603959 c:\windows\system32\Prefetchxs\uid=9254453388885949959 c:\windows\system32\Prefetchxs\uid=9313112675929779222 c:\windows\system32\Prefetchxs\uid=9381675108527649814 c:\windows\system32\Prefetchxs\uid=9384431913903158521 c:\windows\system32\Prefetchxs\uid=9554252579906789770 c:\windows\system32\Prefetchxs\uid=9605882217387355497 c:\windows\system32\Prefetchxs\uid=961808341291469650 c:\windows\system32\Prefetchxs\uid=9635350036978112307 c:\windows\system32\Prefetchxs\uid=9663001314758677592 c:\windows\system32\Prefetchxs\uid=9664000623637542800 c:\windows\system32\Prefetchxs\uid=980085587220775764 c:\windows\system32\Prefetchxs\uid=9853152139065298060 c:\windows\system32\Prefetchxs\uid=9951860571554449712 c:\windows\system32\Prefetchxs\uid=9953917749837968090 . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))) . 2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe 2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon 2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll 2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe 2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe 2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm 2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm 2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao 2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD 2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX 2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL 2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL 2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386 2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386 2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI 2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY 2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV 2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE 2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL 2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL 2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL 2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games 2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl 2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm 2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm 2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll 2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft 2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft 2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule 2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin 2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express 2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java 2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help 2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype 2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist 2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin 2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys 2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8 2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2 2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe 2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed 2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus! 2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller 2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live 2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector 2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft 2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr 2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe 2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys 2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys 2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys 2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys 2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys 2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys 2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys 2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys 2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys 2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-29 17:12:11 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_9d4.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152] "PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064] "ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768] "SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544] "DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152] "QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696] "iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600] c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] Sum rio do OneNote.onetoc2 [2008-04-15 3656] c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\ ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768] HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472] LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304] Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Valve\\hlds.exe"= "c:\\Arquivos de programas\\Valve\\hl.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"= "c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"= "c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"= "c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928] R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704] R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040] S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys [] S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys [] . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34] 2008-12-29 c:\windows\Tasks\okvtgigf.job - c:\windows\system32\rundll32.exe [2008-04-14 00:21] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.globo.com.br/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} uInternet Connection Wizard,ShellNext = iexplore IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147 c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A} hxxp://www.powerchallenge.com/applet/PowerLoader.cab c:\windows\Downloaded Program Files\PowerLoader.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-29 15:12:22 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(688) c:\windows\system32\Ati2evxx.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\windows\system32\ati2evxx.exe c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe c:\windows\system32\ati2evxx.exe c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\arquivos de programas\Bonjour\mDNSResponder.exe c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\UAService7.exe c:\windows\system32\searchindexer.exe c:\arquivos de programas\AVG\AVG8\avgrsx.exe c:\arquivos de programas\iPod\bin\iPodService.exe . ************************************************************************** . Tempo para conclusão: 2008-12-29 15:18:17 - Máquina reiniciou ComboFix-quarantined-files.txt 2008-12-29 17:17:53 ComboFix2.txt 2008-12-28 20:29:42 Pré-execução: 41 pasta(s) 20.478.480.384 bytes disponíveis Pós execução: 41 pasta(s) 20,421,996,544 bytes disponíveis 488 --- E O F --- 2008-12-19 21:40:20 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:28:31, on 29/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe C:\Arquivos de programas\D-Tools\daemon.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\QuickTime\QTTask.exe C:\Arquivos de programas\iTunes\iTunesHelper.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Skype\Phone\Skype.exe C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\LightSurf\Common\IconMgr.exe C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\UAService7.exe C:\WINDOWS\system32\SearchIndexer.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\Arquivos de programas\iPod\bin\iPodService.exe C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing) O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Sumário do OneNote.onetoc2 O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe O24 - Desktop Component 0: (no name) - http://www.google-analytics.com/urchin.js -- End of file - 10892 bytes Um abraço!!! Aguardo!!! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 30, 2008 Bom Dia! altasena <@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas. <@> Salve-as,no desktop,como: CFScript <-- Texto! XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX File:: c:\windows\system32\jkkjIbxy.dll c:\windows\Tasks\okvtgigf.job C:\sqmdata18.sqm C:\sqmnoopt18.sqm C:\sqmdata17.sqm C:\sqmnoopt17.sqm XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX <@> Arraste o CFScript.txt,para o ícone do ComboFix. <@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe. <@> Terminando,poste: ComboFix.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
altasena 0 Denunciar post Postado Dezembro 30, 2008 Bom Dia! altasena <@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas. <@> Salve-as,no desktop,como: CFScript <-- Texto! XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX File:: c:\windows\system32\jkkjIbxy.dll c:\windows\Tasks\okvtgigf.job C:\sqmdata18.sqm C:\sqmnoopt18.sqm C:\sqmdata17.sqm C:\sqmnoopt17.sqm XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX <@> Arraste o CFScript.txt,para o ícone do ComboFix. <@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe. <@> Terminando,poste: ComboFix.txt Abraços! OLá Digram, boa tarde, mais uma vez muito obrigada pela atenção!!! UM abraço!! ComboFix 08-12-29.02 - Altair 2008-12-30 15:22:57.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.558 [GMT -2:00] Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt * Criado um novo ponto de restauro FILE :: C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm c:\windows\system32\jkkjIbxy.dll c:\windows\Tasks\okvtgigf.job . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm c:\windows\system32\jkkjIbxy.dll c:\windows\Tasks\okvtgigf.job ----- BITS: Sites possivelmente infetados ----- hxxp://childhe.com . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))) . 2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe 2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon 2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon 2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe 2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe 2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao 2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD 2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE 2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX 2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL 2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL 2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386 2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386 2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI 2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY 2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV 2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE 2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL 2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL 2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL 2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games 2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl 2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll 2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe 2008-11-26 21:42 . 2008-11-26 21:43 <DIR> d-------- c:\arquivos de programas\weblin 2008-11-26 21:40 . 2008-11-26 21:43 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist 2008-11-24 12:14 . 2008-12-30 14:20 <DIR> d-------- c:\windows\system32\drivers\Avg 2008-11-24 12:14 . 2008-11-24 12:14 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8 2008-11-24 12:14 . 2008-11-24 12:14 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys 2008-11-24 12:14 . 2008-11-24 12:14 10,520 --a------ c:\windows\system32\avgrsstx.dll 2008-11-14 08:50 . 2008-11-14 09:40 <DIR> d-------- c:\arquivos de programas\O Resgate dos Bichos - CD 2 2008-11-14 08:50 . 2008-11-14 08:50 90,112 --a------ c:\windows\Cuninst.exe 2008-11-14 08:01 . 2008-11-14 08:04 1,385 --a------ c:\windows\disney.ini 2008-11-14 08:01 . 2008-11-14 08:01 205 --a------ c:\windows\disneysy.ini 2008-11-12 09:47 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll 2008-11-12 09:47 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys 2008-11-05 18:45 . 2008-11-05 18:45 224 --a------ c:\documents and settings\ALTAIR~1.xml 2008-11-05 18:22 . 2008-11-05 18:30 119,001 --a------ c:\windows\hpoins11.dat 2008-11-02 21:41 . 2008-11-03 18:35 <DIR> d-------- c:\arquivos de programas\gamespeed 2008-11-02 21:41 . 2005-12-08 10:09 49,152 --a------ c:\windows\system32\mydll.dll . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-30 16:56 --------- d-----w c:\arquivos de programas\MegaJogos 2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft 2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft 2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule 2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin 2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express 2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java 2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help 2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype 2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus! 2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger 2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller 2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live 2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector 2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft 2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2008-10-23 12:37 286,720 ----a-w c:\windows\system32\gdi32.dll 2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr 2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe 2008-10-16 20:23 826,368 ----a-w c:\windows\system32\wininet.dll 2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll 2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll 2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll 2008-09-27 14:12 94,578 ----a-w c:\windows\FreeOCR.net Uninstaller.exe 2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys 2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll 2008-09-08 16:57 126,976 ----a-w c:\windows\system32\UAService7.exe 2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll 2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys 2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys 2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys 2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys 2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys 2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys 2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys 2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys 2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys 2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll 2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll 2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll 2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll 2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat + 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat.bak - 2008-12-28 20:00:33 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat + 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat + 2008-12-29 18:01:05 78,924 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat - 2008-12-28 20:00:33 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat + 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat - 2008-12-28 20:00:33 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat + 2008-12-29 18:01:00 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat + 2008-12-30 17:18:41 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_948.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152] "PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064] "ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768] "SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544] "DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152] "QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696] "iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600] c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440] Sum rio do OneNote.onetoc2 [2008-04-15 3656] c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\ ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768] HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472] LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304] Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Valve\\hlds.exe"= "c:\\Arquivos de programas\\Valve\\hl.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"= "c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"= "c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"= "c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928] R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704] R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040] S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys [] S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys [] *Newly Created Service* - CATCHME . Conteúdo da pasta 'Tarefas Agendadas' 2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.globo.com.br/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} uInternet Connection Wizard,ShellNext = iexplore IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147 c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A} hxxp://www.powerchallenge.com/applet/PowerLoader.cab c:\windows\Downloaded Program Files\PowerLoader.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-30 15:26:22 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(688) c:\windows\system32\Ati2evxx.dll . Tempo para conclusão: 2008-12-30 15:28:51 ComboFix-quarantined-files.txt 2008-12-30 17:27:48 ComboFix2.txt 2008-12-29 17:18:19 ComboFix3.txt 2008-12-28 20:29:42 Pré-execução: 41 pasta(s) 20.443.369.472 bytes disponíveis Pós execução: 41 pasta(s) 20,439,085,056 bytes disponíveis 259 --- E O F --- 2008-12-19 21:40:20 Grato Altair!! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 31, 2008 Bom Dia! altasena <@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK. <@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança ) <@> Clique em Executar --> Aguarde! <@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. <@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! ---------------------------- <@> Vá a este Link,e baixe: < Malwarebytes > <@> Atualize o programa! <@> Escolha o escaneamento Rápido! <@> Desabilite programas de proteção,ao executar o malwarebytes. <@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. <@> Para maiores detalhes: < Link > ----------------------- <@> Poste: mbam-log-2008-xx-xx (00-00-00).txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
altasena 0 Denunciar post Postado Janeiro 1, 2009 Bom Dia! altasena <@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK. <@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança ) <@> Clique em Executar --> Aguarde! <@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. <@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! ---------------------------- <@> Vá a este Link,e baixe: < Malwarebytes > <@> Atualize o programa! <@> Escolha o escaneamento Rápido! <@> Desabilite programas de proteção,ao executar o malwarebytes. <@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. <@> Para maiores detalhes: < Link > ----------------------- <@> Poste: mbam-log-2008-xx-xx (00-00-00).txt Abraços! Boa Tarde e feilz 2009 DigRam Malwarebytes' Anti-Malware 1.31 Versão do banco de dados: 1590 Windows 5.1.2600 Service Pack 3 1/1/2009 17:58:09 mbam-log-2009-01-01 (17-58-09).txt Tipo de Verificação: Rápida Objetos verificados: 73565 Tempo decorrido: 6 minute(s), 12 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 1 Valores do Registro infectados: 0 Ítens do Registro infectados: 0 Pastas infectadas: 0 Arquivos infectados: 0 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: (Nenhum ítem malicioso foi detectado) Um abraço Altair e muito obrigado... Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 1, 2009 Boa Noite! altasena <!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema. <!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema. <!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok. <!> Depois,desmarque novamente! --> Aplicar --> Ok. <!> Para maiores detalhes,vá em: < Docs > ---------------------------- <!> Não existe mais traços do Vundo. :natal_happy: <!> Os logs estão limpos! <!> Tudo Ok? Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
altasena 0 Denunciar post Postado Janeiro 2, 2009 Boa Noite! altasena <!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema. <!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema. <!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok. <!> Depois,desmarque novamente! --> Aplicar --> Ok. <!> Para maiores detalhes,vá em: < Docs > ---------------------------- <!> Não existe mais traços do Vundo. :natal_happy: <!> Os logs estão limpos! <!> Tudo Ok? Abraços! Boa tarde DigRam e muito obrigado pelo seu trabalho,você me tirou de mais um problema no pc dos meus filhos..Que papai do céu te abençoe.Feliz 2009. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 3, 2009 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites