Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Aracari

[Arquivado] System Error Code: 1400

Recommended Posts

Galera, peguei esse vírus de um email (que minha mulher abriu). Ele fica abrindo janelas com a msg "System Error Code: 1400" no IE. Já fiz os procedimentos explicados aqui no forum numa outra msg.

 

1) Baixei o ComboFix e executei em modo de segurança e sem anti-virus ativo.

 

2) O arquivo de log gerado foi esse daqui:

 

ComboFix 09-01-21.04 - Administrador 2009-01-28 8:43:04.1 - FAT32x86 NETWORK

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.833 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\mdm.exe

c:\windows\winhlp32.dat

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-12-28 to 2009-01-28 ))))))))))))))))))))))))))))

.

 

2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7

2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout

2009-01-27 17:12 . 2009-01-27 17:12 1 ---hs---- C:\MSDOS.INF

2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll

2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica

2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso

2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode)

2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache

2009-01-03 15:57 . 2009-01-21 12:54 54,156 --ah----- c:\windows\QTFont.qfn

2009-01-03 15:57 . 2009-01-03 15:57 1,409 --a------ c:\windows\QTFont.for

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-01-18 11:35 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat

2006-07-05 09:56 174,326 --sh--r c:\windows\system32\uwhnk.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FDA784-0154-418F-810B-F1839272C361}]

2009-01-27 17:12 824832 --a------ c:\windows\system32\DirectX\Dinput\diagx3d.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"=

"c:\\WINDOWS\\System32\\dpnsvr.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"= 2879:TCP:unjoupvf

 

S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?]

S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032]

S4 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S4 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S4 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly

uilxddp

bprhgtk

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-Skype - c:\arquivos de programas\Skype\Phone\Skype.exe

HKLM-Run-uebTUBE - c:\arquivos de programas\UEBBI.com\uebTUBE\uebTUBE.exe

HKLM-Run-NWEReboot - (no file)

ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399007} - c:\windows\Downloaded Program Files\gbiehabn.dll

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.uol.com.br/

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab

DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-01-28 08:46:15

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

"WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c,

b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,

fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(624)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\WgaTray.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-01-28 8:48:46 - Máquina reiniciou [Administrador]

ComboFix-quarantined-files.txt 2009-01-28 10:48:46

 

Pré-execução: 6,206,832,640 bytes disponíveis

Pós execução: 7,373,160,448 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

 

138

 

 

 

 

agradeço muito qualquer ajuda!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Aracari,

 

1. Baixe o BankerFix 3.0.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM.

 

4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado.

 

5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos.

 

6. Terminado o scan, leia a mensagem na tela e aperte Enter.

 

7. Habilite o seu anti-vírus.

 

8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

 

PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá jgarcia

 

Eu tentei instalar o bankerfix mas quando clico duas vezes no arquivo exe aparece uma janela com nome de 7-Zip dizendo que "Can not create temp folder archive".

Compartilhar este post


Link para o post
Compartilhar em outros sites

jgarcia, segue abaixo novo log do combofix. Só uma observação, entes do combofiz iniciar ele deu uma msg de "arquivos parasitas" e pediu pra eu anotar os seguintes arquivos, que ele poderia precisar mais tarde:

 

C:\WINDOWS\system32\directx\dinput\msf1f.dll

C:WINDOWS\system32\directx\dinput\msprw.dll

 

LOG do combofix:

 

ComboFix 09-01-21.04 - Administrador 2009-02-02 8:25:37.2 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.753 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

.

- MODO DE FUNCIONALIDADE REDUZIDA -

.

Os seguintes arquivos/ficheiros foram desabilitados durante a execução:

c:\windows\system32\DirectX\Dinput\msf1f.dll

c:\windows\system32\DirectX\Dinput\msprw.dll

 

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\DirectX\Dinput\msf1f.dll

c:\windows\system32\DirectX\Dinput\msprw.dll

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-02 to 2009-02-02 ))))))))))))))))))))))))))))

.

 

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm

2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm

2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7

2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout

2009-01-27 17:12 . 2009-01-27 17:12 1 ---hs---- C:\MSDOS.INF

2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll

2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica

2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso

2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode)

2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache

2009-01-03 15:57 . 2009-01-21 12:54 54,156 --ah----- c:\windows\QTFont.qfn

2009-01-03 15:57 . 2009-01-03 15:57 1,409 --a------ c:\windows\QTFont.for

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat

2006-07-05 09:56 174,326 --sh--r c:\windows\system32\uwhnk.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FDA784-0154-418F-810B-F1839272C361}]

2009-01-27 17:12 824832 --a------ c:\windows\system32\DirectX\Dinput\diagx3d.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"=

"c:\\WINDOWS\\System32\\dpnsvr.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"= 2879:TCP:unjoupvf

 

S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?]

S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032]

S4 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S4 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S4 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly

uilxddp

bprhgtk

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6cbc058e-ebab-11dc-aa72-00032f3c5a27}]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.uol.com.br/

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-02 08:28:18

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

"WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c,

b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,

fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(680)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\SYSTEM32\ATI2EVXX.EXE

c:\windows\SYSTEM32\LEXBCES.EXE

c:\windows\SYSTEM32\LEXPPS.EXE

c:\windows\SYSTEM32\ATI2EVXX.EXE

c:\arquivos de programas\JAVA\JRE6\BIN\JQS.EXE

c:\windows\SYSTEM32\HPZIPM12.EXE

c:\windows\SYSTEM32\WGATRAY.EXE

.

**************************************************************************

.

Tempo para conclusão: 2009-02-02 8:30:23 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-02-02 10:30:22

 

Pré-execução: 3.876.798.464 bytes disponíveis

Pós execução: 4,017,684,480 bytes disponíveis

 

148

Compartilhar este post


Link para o post
Compartilhar em outros sites

Agora eu consegui instalar e rodar o BankerFix. Instalei o Avira anti-virus tbm e ele detectou algumas coisas, eu mandei tudo pra quarentena. Enfim segue o relatório do BankerFix:

 

BankerFix 3.0 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2009-02-02 - 16:39

-------------------------------------------------------

Lista de Definição: 2009-01-21-2 | CORE: 2009-01-21-1

=======================================================

 

Arquivo infectado detectado: C:\MSDOS.INF

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\pagefile.log

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\mssnmsgr.dll

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\sharedapp.reg

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\svchost

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\atualizado.log

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\desktop.inf

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\1\desktop.inf

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\uol.log

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\1

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\2

Arquivo infectado removido com sucesso!

 

 

 

----- Fim -------------------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Aracari,

 

O BankerFix removeu alguns itens maliciosos contidos no log anterior do ComboFix, portanto faz-se necessário que você poste um novo log do ComboFix, a fim de que eu possa analisar se ainda há resquícios da infecção.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue novo log do ComboFix. O erro 1400 não está mais aparecendo, em compensação o Avira está detectando bastante coisa e não consigo acessar o bankline. Digito a agencia e conta mas a janela não muda.

 

 

ComboFix 09-02-04.01 - Administrador 2009-02-04 17:29:42.4 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.720 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-04 to 2009-02-04 ))))))))))))))))))))))))))))

.

 

2009-02-04 17:00 . 2009-02-04 17:00 165,984 --a------ c:\windows\system32\x

2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm

2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm

2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm

2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7

2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout

2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll

2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica

2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso

2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode)

2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat

.

 

((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys

+ 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys

+ 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

+ 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys

+ 2009-02-04 10:09:26 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_220.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"=

"c:\\WINDOWS\\System32\\dpnsvr.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"= 2879:TCP:unjoupvf

 

S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?]

S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly

uilxddp

bprhgtk

doejdr

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.uol.com.br/

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-04 17:32:07

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

"WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c,

b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,

fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(684)

c:\windows\system32\Ati2evxx.dll

.

Tempo para conclusão: 2009-02-04 17:33:18

ComboFix-quarantined-files.txt 2009-02-04 19:33:18

ComboFix3.txt 2009-02-02 10:30:26

ComboFix2.txt 2009-02-03 00:25:40

 

Pré-execução: 4.977.360.896 bytes disponíveis

Pós execução: 5,001,887,744 bytes disponíveis

 

141

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Aracari,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

c:\arquivos de programas\Internet Explorer\uwhnk.dll

c:\windows\system32\uwhnk.dll

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000000

"AntiVirusOverride"=dword:00000000

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"=-

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly=-

uilxddp=-

bprhgtk=-

doejdr=-

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}]

[-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Conforme solicitado, segue 1º o log do ComboFix e depois do HijackThis:

 

ComboFix 09-02-06.01 - Administrador 2009-02-06 16:48:13.5 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.729 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Administrador\Desktop\CFScript.txt

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Criado um novo ponto de restauro

 

FILE ::

c:\arquivos de programas\Internet Explorer\uwhnk.dll

c:\windows\system32\uwhnk.dll

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-06 to 2009-02-06 ))))))))))))))))))))))))))))

.

 

2009-02-05 16:09 . 2009-02-05 16:09 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Google Updater

2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm

2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm

2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm

2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7

2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout

2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll

2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica

2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso

2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode)

2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat

.

 

((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-02-05 18:18:50 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe

+ 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys

+ 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys

+ 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

+ 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys

+ 2009-02-06 09:46:28 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_76c.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"=

"c:\\WINDOWS\\System32\\dpnsvr.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"=

 

S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?]

S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 gupdate1c987bdb7ef45d0;Google Update Service (gupdate1c987bdb7ef45d0);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 133104]

S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly

uilxddp

bprhgtk

doejdr

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-02-06 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 16:15]

 

2009-02-06 c:\windows\Tasks\Google Software Updater.job

- c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 16:09]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.uol.com.br/

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-06 16:50:54

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

"WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c,

b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,

fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(688)

c:\windows\system32\Ati2evxx.dll

.

Tempo para conclusão: 2009-02-06 16:51:49

ComboFix-quarantined-files.txt 2009-02-06 18:51:48

ComboFix4.txt 2009-02-02 10:30:26

ComboFix3.txt 2009-02-03 00:25:40

ComboFix2.txt 2009-02-04 19:33:20

 

Pré-execução: 4.677.287.936 bytes disponíveis

Pós execução: 4,703,043,584 bytes disponíveis

 

154

 

 

 

LOG DO HIJACKTHIS:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:52:57, on 6/2/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\explorer.exe

C:\ZIP Files\HiJackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\WINDOWS\Downloaded Program Files\gbiehabn.dll (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [updateMgr] "C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} (AlamyUploader Class) - http://www.alamy.com/uploader/alamy_uploader.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Google Update Service (gupdate1c987bdb7ef45d0) (gupdate1c987bdb7ef45d0) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe

 

--

End of file - 6204 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

tem sim mas o analista responsavel deve estar muito atarefado fora do forum mas o cantactei para lhe dar o proximo passo da ajuda

Compartilhar este post


Link para o post
Compartilhar em outros sites

Conforme solicitado, segue log do ComboFix:

 

ComboFix 09-02-14.01 - Administrador 2009-02-15 9:23:13.6 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.710 [GMT -2:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-15 to 2009-02-15 ))))))))))))))))))))))))))))

.

 

2009-02-09 10:56 . 2009-02-09 10:56 <DIR> d-------- C:\James Lowen

2009-02-07 11:58 . 2009-02-07 11:58 <DIR> d--hs---- C:\FOUND.001

2009-02-07 09:11 . 2009-02-07 09:11 <DIR> d--hs---- C:\FOUND.000

2009-02-05 16:09 . 2009-02-05 16:09 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Google Updater

2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm

2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira

2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes

2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm

2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm

2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm

2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7

2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout

2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll

2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica

2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso

2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity

2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode)

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat

.

 

((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-02-05 18:18:50 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe

+ 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe

+ 2009-02-09 16:56:50 10,134 ----a-r c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466}\ARPPRODUCTICON.exe

+ 2009-02-09 16:56:50 26,694 ----a-r c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466}\UNINST_Uninstall_G_BCEEAF790189405A8B93BFE1E41FCD64.exe

+ 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys

+ 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys

+ 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

+ 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys

+ 2009-02-15 11:02:00 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_7d0.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"=

"c:\\WINDOWS\\System32\\dpnsvr.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"= 2879:TCP:unjoupvf

 

S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?]

S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 cnjby;Manager Boot;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 gupdate1c987bdb7ef45d0;Google Update Service (gupdate1c987bdb7ef45d0);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 133104]

S2 nbdpnzo;Support Shell;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S2 xxyctzzj;Network Server;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336]

S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032]

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

pjsly

uilxddp

bprhgtk

doejdr

xxyctzzj

nbdpnzo

cnjby

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-02-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 16:15]

 

2009-02-15 c:\windows\Tasks\Google Software Updater.job

- c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 16:09]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.uol.com.br/

uInternet Connection Wizard,ShellNext = iexplore

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-15 09:25:59

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj]

"ServiceDll"="c:\windows\system32\uwhnk.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

"WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c,

b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,

fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(684)

c:\windows\system32\Ati2evxx.dll

.

Tempo para conclusão: 2009-02-15 9:26:56

ComboFix-quarantined-files.txt 2009-02-15 11:26:56

ComboFix4.txt 2009-02-03 00:25:40

ComboFix3.txt 2009-02-04 19:33:20

ComboFix5.txt 2009-02-15 11:22:34

ComboFix2.txt 2009-02-06 18:51:52

 

Pré-execução: 4.381.523.968 bytes disponíveis

Pós execução: 4,484,825,088 bytes disponíveis

 

172

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Aracari,

 

Siga as instruções:

 

1. Reinicie em Modo Seguro;

 

2. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT

c:\arquivos de programas\Internet Explorer\uwhnk.dll

c:\windows\system32\uwhnk.dll

C:\sqmnoopt02.sqm

C:\sqmnoopt03.sqm

C:\sqmnoopt04.sqm

C:\sqmdata01.sqm

C:\sqmdata02.sqm

C:\sqmdata03.sqm

C:\FOUND.000

C:\FOUND.001

Folder::

c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}

c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466}

RegNull::

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*]

Registry::

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2879:TCP"=-

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

-pjsly

-uilxddp

-bprhgtk

-doejdr

-xxyctzzj

-nbdpnzo

-cnjby

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

"ServiceDll"=-

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj]

"ServiceDll"=-

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp]

[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj]

Driver::

"atitray"

"bprhgtk"

"cnjby"

"doejdr"

"nbdpnzo"

"pjsly"

"uilxddp"

"xxyctzzj"

"rxpvbus"

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 3. Salve o arquivo como CFScript.txt;
     
    4. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    5. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.