Aracari 0 Denunciar post Postado Janeiro 28, 2009 Galera, peguei esse vírus de um email (que minha mulher abriu). Ele fica abrindo janelas com a msg "System Error Code: 1400" no IE. Já fiz os procedimentos explicados aqui no forum numa outra msg. 1) Baixei o ComboFix e executei em modo de segurança e sem anti-virus ativo. 2) O arquivo de log gerado foi esse daqui: ComboFix 09-01-21.04 - Administrador 2009-01-28 8:43:04.1 - FAT32x86 NETWORK Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.833 [GMT -2:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\mdm.exe c:\windows\winhlp32.dat . (((((((((((((((( Arquivos/Ficheiros criados de 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))) . 2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7 2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout 2009-01-27 17:12 . 2009-01-27 17:12 1 ---hs---- C:\MSDOS.INF 2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica 2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso 2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode) 2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache 2009-01-03 15:57 . 2009-01-21 12:54 54,156 --ah----- c:\windows\QTFont.qfn 2009-01-03 15:57 . 2009-01-03 15:57 1,409 --a------ c:\windows\QTFont.for . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-18 11:35 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT 2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat 2006-07-05 09:56 174,326 --sh--r c:\windows\system32\uwhnk.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FDA784-0154-418F-810B-F1839272C361}] 2009-01-27 17:12 824832 --a------ c:\windows\system32\DirectX\Dinput\diagx3d.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696] Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"= "c:\\WINDOWS\\System32\\dpnsvr.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"= 2879:TCP:unjoupvf S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?] S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032] S4 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S4 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S4 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly uilxddp bprhgtk . - - - - ORFÃOS REMOVIDOS - - - - HKCU-Run-Skype - c:\arquivos de programas\Skype\Phone\Skype.exe HKLM-Run-uebTUBE - c:\arquivos de programas\UEBBI.com\uebTUBE\uebTUBE.exe HKLM-Run-NWEReboot - (no file) ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399007} - c:\windows\Downloaded Program Files\gbiehabn.dll . ------- Scan Suplementar ------- . uStart Page = hxxp://www.uol.com.br/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-28 08:46:15 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] "WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c, b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] "526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0, fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(624) c:\windows\system32\Ati2evxx.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\windows\system32\WgaTray.exe . ************************************************************************** . Tempo para conclusão: 2009-01-28 8:48:46 - Máquina reiniciou [Administrador] ComboFix-quarantined-files.txt 2009-01-28 10:48:46 Pré-execução: 6,206,832,640 bytes disponíveis Pós execução: 7,373,160,448 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn 138 agradeço muito qualquer ajuda!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Janeiro 29, 2009 Opa Aracari, 1. Baixe o BankerFix 3.0. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM. 4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado. 5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos. 6. Terminado o scan, leia a mensagem na tela e aperte Enter. 7. Habilite o seu anti-vírus. 8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta. Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Janeiro 30, 2009 Olá jgarcia Eu tentei instalar o bankerfix mas quando clico duas vezes no arquivo exe aparece uma janela com nome de 7-Zip dizendo que "Can not create temp folder archive". Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Janeiro 31, 2009 Tem algum outro programa que eu possa usar? Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Janeiro 31, 2009 Opa Aracari, Poste um novo log do ComboFix. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 2, 2009 jgarcia, segue abaixo novo log do combofix. Só uma observação, entes do combofiz iniciar ele deu uma msg de "arquivos parasitas" e pediu pra eu anotar os seguintes arquivos, que ele poderia precisar mais tarde: C:\WINDOWS\system32\directx\dinput\msf1f.dll C:WINDOWS\system32\directx\dinput\msprw.dll LOG do combofix: ComboFix 09-01-21.04 - Administrador 2009-02-02 8:25:37.2 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.753 [GMT -2:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe . - MODO DE FUNCIONALIDADE REDUZIDA - . Os seguintes arquivos/ficheiros foram desabilitados durante a execução: c:\windows\system32\DirectX\Dinput\msf1f.dll c:\windows\system32\DirectX\Dinput\msprw.dll ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\DirectX\Dinput\msf1f.dll c:\windows\system32\DirectX\Dinput\msprw.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-02 to 2009-02-02 )))))))))))))))))))))))))))) . 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm 2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm 2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7 2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout 2009-01-27 17:12 . 2009-01-27 17:12 1 ---hs---- C:\MSDOS.INF 2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica 2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso 2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode) 2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache 2009-01-03 15:57 . 2009-01-21 12:54 54,156 --ah----- c:\windows\QTFont.qfn 2009-01-03 15:57 . 2009-01-03 15:57 1,409 --a------ c:\windows\QTFont.for . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT 2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat 2006-07-05 09:56 174,326 --sh--r c:\windows\system32\uwhnk.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FDA784-0154-418F-810B-F1839272C361}] 2009-01-27 17:12 824832 --a------ c:\windows\system32\DirectX\Dinput\diagx3d.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696] Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"= "c:\\WINDOWS\\System32\\dpnsvr.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"= 2879:TCP:unjoupvf S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?] S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032] S4 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S4 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S4 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly uilxddp bprhgtk [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6cbc058e-ebab-11dc-aa72-00032f3c5a27}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.uol.com.br/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-02 08:28:18 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] "WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c, b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] "526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0, fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(680) c:\windows\system32\Ati2evxx.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\windows\SYSTEM32\ATI2EVXX.EXE c:\windows\SYSTEM32\LEXBCES.EXE c:\windows\SYSTEM32\LEXPPS.EXE c:\windows\SYSTEM32\ATI2EVXX.EXE c:\arquivos de programas\JAVA\JRE6\BIN\JQS.EXE c:\windows\SYSTEM32\HPZIPM12.EXE c:\windows\SYSTEM32\WGATRAY.EXE . ************************************************************************** . Tempo para conclusão: 2009-02-02 8:30:23 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-02-02 10:30:22 Pré-execução: 3.876.798.464 bytes disponíveis Pós execução: 4,017,684,480 bytes disponíveis 148 Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 2, 2009 Agora eu consegui instalar e rodar o BankerFix. Instalei o Avira anti-virus tbm e ele detectou algumas coisas, eu mandei tudo pra quarentena. Enfim segue o relatório do BankerFix: BankerFix 3.0 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2009-02-02 - 16:39 ------------------------------------------------------- Lista de Definição: 2009-01-21-2 | CORE: 2009-01-21-1 ======================================================= Arquivo infectado detectado: C:\MSDOS.INF Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\pagefile.log Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\mssnmsgr.dll Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\sharedapp.reg Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\svchost Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\atualizado.log Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\desktop.inf Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\1\desktop.inf Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\uol.log Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\1 Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\DirectX\Dinput\Driver\2 Arquivo infectado removido com sucesso! ----- Fim ------------------------- Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 2, 2009 Opa Aracari, O BankerFix removeu alguns itens maliciosos contidos no log anterior do ComboFix, portanto faz-se necessário que você poste um novo log do ComboFix, a fim de que eu possa analisar se ainda há resquícios da infecção. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 4, 2009 Segue novo log do ComboFix. O erro 1400 não está mais aparecendo, em compensação o Avira está detectando bastante coisa e não consigo acessar o bankline. Digito a agencia e conta mas a janela não muda. ComboFix 09-02-04.01 - Administrador 2009-02-04 17:29:42.4 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.720 [GMT -2:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))) . 2009-02-04 17:00 . 2009-02-04 17:00 165,984 --a------ c:\windows\system32\x 2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm 2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm 2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm 2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7 2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout 2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica 2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso 2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode) 2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT 2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat . ((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 ))))))))))))))))))))))))))))))))))))))))) . + 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys + 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys + 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys + 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys + 2009-02-04 10:09:26 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_220.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696] Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"= "c:\\WINDOWS\\System32\\dpnsvr.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"= 2879:TCP:unjoupvf S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?] S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly uilxddp bprhgtk doejdr . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.uol.com.br/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-04 17:32:07 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] "WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c, b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] "526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0, fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(684) c:\windows\system32\Ati2evxx.dll . Tempo para conclusão: 2009-02-04 17:33:18 ComboFix-quarantined-files.txt 2009-02-04 19:33:18 ComboFix3.txt 2009-02-02 10:30:26 ComboFix2.txt 2009-02-03 00:25:40 Pré-execução: 4.977.360.896 bytes disponíveis Pós execução: 5,001,887,744 bytes disponíveis 141 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 5, 2009 Opa Aracari, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::c:\arquivos de programas\Internet Explorer\uwhnk.dll c:\windows\system32\uwhnk.dll Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000000 "AntiVirusOverride"=dword:00000000 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"=- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly=- uilxddp=- bprhgtk=- doejdr=- [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}] [-HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 6, 2009 Conforme solicitado, segue 1º o log do ComboFix e depois do HijackThis: ComboFix 09-02-06.01 - Administrador 2009-02-06 16:48:13.5 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.729 [GMT -2:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Administrador\Desktop\CFScript.txt AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) * Criado um novo ponto de restauro FILE :: c:\arquivos de programas\Internet Explorer\uwhnk.dll c:\windows\system32\uwhnk.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))) . 2009-02-05 16:09 . 2009-02-05 16:09 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Google Updater 2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm 2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm 2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm 2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7 2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout 2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica 2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso 2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode) 2009-01-11 17:06 . 2009-01-11 17:06 <DIR> d--hs---- c:\windows\ftpcache . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT 2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat . ((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-05 18:18:50 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe + 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys + 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys + 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys + 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys + 2009-02-06 09:46:28 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_76c.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696] Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"= "c:\\WINDOWS\\System32\\dpnsvr.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"= S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?] S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 gupdate1c987bdb7ef45d0;Google Update Service (gupdate1c987bdb7ef45d0);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 133104] S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly uilxddp bprhgtk doejdr . Conteúdo da pasta 'Tarefas Agendadas' 2009-02-06 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 16:15] 2009-02-06 c:\windows\Tasks\Google Software Updater.job - c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 16:09] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.uol.com.br/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-06 16:50:54 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] "WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c, b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] "526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0, fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(688) c:\windows\system32\Ati2evxx.dll . Tempo para conclusão: 2009-02-06 16:51:49 ComboFix-quarantined-files.txt 2009-02-06 18:51:48 ComboFix4.txt 2009-02-02 10:30:26 ComboFix3.txt 2009-02-03 00:25:40 ComboFix2.txt 2009-02-04 19:33:20 Pré-execução: 4.677.287.936 bytes disponíveis Pós execução: 4,703,043,584 bytes disponíveis 154 LOG DO HIJACKTHIS: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:52:57, on 6/2/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Arquivos de programas\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\explorer.exe C:\ZIP Files\HiJackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\WINDOWS\Downloaded Program Files\gbiehabn.dll (file missing) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [updateMgr] "C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} (AlamyUploader Class) - http://www.alamy.com/uploader/alamy_uploader.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Google Update Service (gupdate1c987bdb7ef45d0) (gupdate1c987bdb7ef45d0) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe -- End of file - 6204 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 13, 2009 Meu caso não tem solução?? Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Fevereiro 13, 2009 tem sim mas o analista responsavel deve estar muito atarefado fora do forum mas o cantactei para lhe dar o proximo passo da ajuda Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 13, 2009 Opa Aracari, Poste um novo log do ComboFix. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Aracari 0 Denunciar post Postado Fevereiro 15, 2009 Conforme solicitado, segue log do ComboFix: ComboFix 09-02-14.01 - Administrador 2009-02-15 9:23:13.6 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1023.710 [GMT -2:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-15 to 2009-02-15 )))))))))))))))))))))))))))) . 2009-02-09 10:56 . 2009-02-09 10:56 <DIR> d-------- C:\James Lowen 2009-02-07 11:58 . 2009-02-07 11:58 <DIR> d--hs---- C:\FOUND.001 2009-02-07 09:11 . 2009-02-07 09:11 <DIR> d--hs---- C:\FOUND.000 2009-02-05 16:09 . 2009-02-05 16:09 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Google Updater 2009-02-02 20:25 . 2009-02-02 20:26 244 --ah----- C:\sqmnoopt04.sqm 2009-02-02 20:25 . 2009-02-02 20:26 232 --ah----- C:\sqmdata03.sqm 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira 2009-02-02 09:14 . 2009-02-02 09:14 <DIR> d-------- c:\arquivos de programas\Avira 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-01-29 19:55 . 2009-01-29 19:55 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-01-29 19:55 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-29 19:55 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-01-28 23:23 . 2009-01-28 23:23 244 --ah----- C:\sqmnoopt03.sqm 2009-01-28 23:23 . 2009-01-28 23:23 232 --ah----- C:\sqmdata02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 244 --ah----- C:\sqmnoopt02.sqm 2009-01-28 23:22 . 2009-01-28 23:22 232 --ah----- C:\sqmdata01.sqm 2009-01-28 08:35 . 2009-01-28 08:35 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avg7 2009-01-27 18:07 . 2009-01-27 18:07 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-01-27 17:42 . 2009-01-27 17:42 <DIR> d-------- C:\fixwareout 2009-01-22 21:14 . 2009-01-22 21:13 410,984 --a------ c:\windows\system32\deploytk.dll 2009-01-22 11:46 . 2009-01-22 11:46 <DIR> d-------- C:\Sons Mata Atlântica 2009-01-20 14:54 . 2009-01-20 14:54 <DIR> d-------- C:\Curso 2009-01-19 08:42 . 2009-01-19 08:42 <DIR> d-------- C:\Sons Campinas 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Audacity 2009-01-18 23:00 . 2009-01-18 23:00 <DIR> d-------- c:\arquivos de programas\Audacity 1.3 Beta (Unicode) . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-29 18:21 20 ---h--w c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT 2006-07-20 23:09 61 --sh--w c:\windows\cnerolf.dat . ((((((((((((((((((((((((((((( snapshot@2009-02-02_ 8.29.45.82 ))))))))))))))))))))))))))))))))))))))))) . + 2009-02-05 18:18:50 363,246 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe + 2009-02-05 18:18:50 25,214 ----a-r c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe + 2009-02-09 16:56:50 10,134 ----a-r c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466}\ARPPRODUCTICON.exe + 2009-02-09 16:56:50 26,694 ----a-r c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466}\UNINST_Uninstall_G_BCEEAF790189405A8B93BFE1E41FCD64.exe + 2008-05-09 14:15:52 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys + 2008-01-21 19:11:30 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys + 2008-10-30 12:21:04 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys + 2007-03-01 11:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys + 2009-02-15 11:02:00 16,384 ----a-w c:\windows\temp\Perflib_Perfdata_7d0.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2005-07-28 98304] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2008-09-03 185896] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-01-22 136600] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ Adobe Reader Speed Launch.lnk - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696] Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-17 113664] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Messenger\\MSMSGS.EXE"= "c:\\WINDOWS\\System32\\dpnsvr.exe"= "c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\iTunes\\iTunes.exe"= "c:\\Arquivos de programas\\Malwarebytes' Anti-Malware\\mbam.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"= 2879:TCP:unjoupvf S1 atitray;atitray;\??\c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys --> c:\arquiv~1\NGOATI~1.7\ATT\atitray.sys [?] S2 bprhgtk;Microsoft Monitor;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 cnjby;Manager Boot;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 doejdr;Shell Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 gupdate1c987bdb7ef45d0;Google Update Service (gupdate1c987bdb7ef45d0);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 133104] S2 nbdpnzo;Support Shell;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 pjsly;Universal Center;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 uilxddp;Network Config;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S2 xxyctzzj;Network Server;c:\windows\system32\svchost.exe -k netsvcs [2001-10-28 14336] S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-06-20 44032] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs pjsly uilxddp bprhgtk doejdr xxyctzzj nbdpnzo cnjby . Conteúdo da pasta 'Tarefas Agendadas' 2009-02-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-05 16:15] 2009-02-15 c:\windows\Tasks\Google Software Updater.job - c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-05 16:09] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.uol.com.br/ uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {3E0D93BD-ABC6-4723-A70F-2A57D33C0186} - hxxp://www.alamy.com/uploader/alamy_uploader.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-15 09:25:59 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"="c:\windows\system32\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"="c:\arquivos de programas\Internet Explorer\uwhnk.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj] "ServiceDll"="c:\windows\system32\uwhnk.dll" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] "WHRUBFTNUT3JMXQXKMKSXOBADA1"=hex:01,00,01,00,00,00,00,00,7d,86,67,30,10,5d,1c, b8,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] "526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0, fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(684) c:\windows\system32\Ati2evxx.dll . Tempo para conclusão: 2009-02-15 9:26:56 ComboFix-quarantined-files.txt 2009-02-15 11:26:56 ComboFix4.txt 2009-02-03 00:25:40 ComboFix3.txt 2009-02-04 19:33:20 ComboFix5.txt 2009-02-15 11:22:34 ComboFix2.txt 2009-02-06 18:51:52 Pré-execução: 4.381.523.968 bytes disponíveis Pós execução: 4,484,825,088 bytes disponíveis 172 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 17, 2009 Opa Aracari, Siga as instruções: 1. Reinicie em Modo Seguro; 2. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::c:\documents and settings\All Users\Dados de aplicativos\PKP_DLea.DAT c:\arquivos de programas\Internet Explorer\uwhnk.dll c:\windows\system32\uwhnk.dll C:\sqmnoopt02.sqm C:\sqmnoopt03.sqm C:\sqmnoopt04.sqm C:\sqmdata01.sqm C:\sqmdata02.sqm C:\sqmdata03.sqm C:\FOUND.000 C:\FOUND.001 Folder:: c:\windows\Installer\{548EAC70-EE00-11DD-908C-005056806466} c:\windows\Installer\{F43C7DE1-CB20-11DD-8D77-005056806466} RegNull:: [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3024A848-7C77-6F90-8B14B36A94BB61F2}\{6CDD5654-07A8-13D8-C2EB636328E10F29}\{AF593ADC-BF32-7E11-B704756686EE805B}*] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A5C981-2676-291A-32EFD4032EA8E33A}\{919E04ED-9AED-1E96-6948A9B454B0D1AB}\{B9D741B0-7F58-31BD-F6CE842C649F7BA8}*] Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2879:TCP"=- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs -pjsly -uilxddp -bprhgtk -doejdr -xxyctzzj -nbdpnzo -cnjby [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] "ServiceDll"=- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj] "ServiceDll"=- [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bprhgtk] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cnjby] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\doejdr] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nbdpnzo] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pjsly] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uilxddp] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxyctzzj] Driver:: "atitray" "bprhgtk" "cnjby" "doejdr" "nbdpnzo" "pjsly" "uilxddp" "xxyctzzj" "rxpvbus" ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 3. Salve o arquivo como CFScript.txt; 4. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 5. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Março 17, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites