drakos 0 Denunciar post Postado Fevereiro 24, 2009 Pessoal estou com outro pc aqui em casa muito lento e com varios mens de erros , agradeço se alguem puder analizar o log ; Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:11:34, on 24/2/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\svchost.exe C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\Arquivos de programas\lg_fwupdate\fwupdate.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\inmbox\smhost.exe C:\svchost.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\ARQUIV~1\AVG\AVG8\aAvgApi.exe C:\hijackthis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: (no name) - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Windows Setup] C:\svchost.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [LGODDFU] "C:\Arquivos de programas\lg_fwupdate\fwupdate.exe" blrun O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [svchostmp] C:\WINDOWS\system32\inmbox\smhost.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [svchost] C:\svchost.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [spyware Doctor] "C:\Arquivos de programas\Spyware Doctor\spydoctor.exe" /Q O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg -- End of file - 7458 bytes desde ja obrigado. Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 26, 2009 Opa drakos, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar. PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO. OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Fevereiro 28, 2009 ok feito ai vai o relatorio do combofix junto com o hijck atualizado ComboFix 09-02-27.02 - DRAKOS 2009-02-28 14:00:05.1 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1637 [GMT -3:00] Executando de: C:\ComboFix.exe * Criado um novo ponto de restauro . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\DRAKOS\CONFIG~1\Temp\svchost.exe C:\svchost.exe c:\windows\system32\drivers\npf.sys c:\windows\system32\packet.dll c:\windows\system32\pthreadVC.dll c:\windows\system32\wanpacket.dll c:\windows\system32\wpcap.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NPF -------\Service_NPF (((((((((((((((( Arquivos/Ficheiros criados de 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))) . 2009-02-28 11:48 . 2009-02-28 11:48 2,926,240 -ra------ C:\ComboFix.exe 2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead 2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-28 03:54 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2009-02-28 03:54 103,736 ----a-w c:\windows\system32\PnkBstrB.exe 2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports 2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio 2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts 2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2008-12-04 03:33 73,216 ----a-w c:\windows\ST6UNST.EXE 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856] "MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "Spyware Doctor"="c:\arquivos de programas\Spyware Doctor\spydoctor.exe" [2004-07-29 1818624] "NBJ"="c:\arquivos de programas\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 1957888] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 81920] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "RemoteControl"="c:\arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "InCD"="c:\arquivos de programas\Ahead\InCD\InCD.exe" [2006-07-12 1397760] "LGODDFU"="c:\arquivos de programas\lg_fwupdate\fwupdate.exe" [2008-10-03 548864] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-10-27 136600] "svchostmp"="c:\windows\system32\inmbox\smhost.exe" [2008-09-30 6905856] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "nwiz"="nwiz.exe" [2007-04-19 c:\windows\system32\nwiz.exe] "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2006-12-19 c:\windows\RTHDCPL.exe] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"= "c:\\WINDOWS\\System32\\dpvsetup.exe"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "28336:TCP"= 28336:TCP:eMule [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}] \Shell\AutoRun\command - rjiybg.exe \Shell\explore\Command - rjiybg.exe \Shell\open\Command - rjiybg.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}] \Shell\AutoRun\command - nl.com \Shell\explore\Command - nl.com \Shell\open\Command - nl.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}] \Shell\AutoRun\command - D:\Autorun.exe . - - - - ORFÃOS REMOVIDOS - - - - BHO-{db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file) HKLM-Run-Media Codec Update Service - c:\arquivos de programas\Essentials Codec Pack\update.exe HKLM-Run-Windows Setup - C:\svchost.exe . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ mStart Page = hxxp://br.yahoo.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-28 14:02:30 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\AHEAD\INCD\INCDSRV.EXE c:\windows\SYSTEM32\RUNDLL32.EXE c:\arquivos de programas\JAVA\JRE6\BIN\JQS.EXE c:\windows\SYSTEM32\NVSVC32.EXE c:\windows\SYSTEM32\PNKBSTRA.EXE c:\windows\system32\wscntfy.exe . ************************************************************************** . Tempo para conclusão: 2009-02-28 14:03:31 - Máquina reiniciou [DRAKOS] ComboFix-quarantined-files.txt 2009-02-28 17:03:30 Pré-execução: 24 pasta(s) 35.258.007.552 bytes disponíveis Pós execução: 24 pasta(s) 40,252,080,128 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer C:\ = "Microsoft Windows" 135 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:10:19, on 28/2/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\Arquivos de programas\lg_fwupdate\fwupdate.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\inmbox\smhost.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\hijackthis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [LGODDFU] "C:\Arquivos de programas\lg_fwupdate\fwupdate.exe" blrun O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [svchostmp] C:\WINDOWS\system32\inmbox\smhost.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [spyware Doctor] "C:\Arquivos de programas\Spyware Doctor\spydoctor.exe" /Q O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe" O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg -- End of file - 6236 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 3, 2009 Opa drakos, 1. Baixe o BankerFix 3.0. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM. 4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado. 5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos. 6. Terminado o scan, leia a mensagem na tela e aperte Enter. 7. Habilite o seu anti-vírus. 8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 3, 2009 feito BankerFix 3.0 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2009-03-01 - 10:52 ------------------------------------------------------- Lista de Definição: 2009-01-21-2 | CORE: 2009-01-21-1 ======================================================= ----- Fim ------------------------- migao ja sumiu as mens de erro e o pc voltou com agilidade ja, pow show de bola parabens a todos vcs, vcs são demais, Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 4, 2009 Opa drakos, O processo de desinfecção ainda não acabou. Poste um novo log do ComboFix. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 4, 2009 opa ok, fiquei tão feliz que queria agradecer antecipado!!! kkkkk aqui vai o log do combofix atualizado: ComboFix 09-02-27.02 - DRAKOS 2009-03-04 3:02:09.2 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1729 [GMT -3:00] Executando de: c:\combofix\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) . (((((((((((((((( Arquivos/Ficheiros criados de 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))) . 2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix 2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8 2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead 2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-04 02:03 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2009-03-04 02:02 201,352 ----a-w c:\windows\system32\PnkBstrB.exe 2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports 2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio 2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts 2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2008-12-04 03:33 73,216 ----a-w c:\windows\ST6UNST.EXE 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe . ((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 ))))))))))))))))))))))))))))))))))))))))) . + 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys + 2009-03-04 01:24:58 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_1e8.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"= "c:\\WINDOWS\\System32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "28336:TCP"= 28336:TCP:eMule R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264] --- --- *NewlyCreated* - PNKBSTRB *NewlyCreated* - PNKBSTRK [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}] \Shell\AutoRun\command - rjiybg.exe \Shell\explore\Command - rjiybg.exe \Shell\open\Command - rjiybg.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}] \Shell\AutoRun\command - nl.com \Shell\explore\Command - nl.com \Shell\open\Command - nl.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}] \Shell\AutoRun\command - D:\Autorun.exe . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ mStart Page = hxxp://br.yahoo.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-04 03:03:03 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2009-03-04 3:03:39 ComboFix-quarantined-files.txt 2009-03-04 06:03:38 Pré-execução: 26 pasta(s) 50.385.453.056 bytes disponíveis Pós execução: 26 pasta(s) 50,780,602,368 bytes disponíveis 109 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 7, 2009 Opa drakos, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::C:\WINDOWS\system32\inmbox\smhost.exe D:\Autorun.exe Folder:: C:\WINDOWS\system32\inmbox Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Obs.: Execute a ação com o seu pendrive conectado ao PC. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 8, 2009 ComboFix 09-03-06.02 - DRAKOS 2009-03-08 1:05:16.3 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1705 [GMT -3:00] Executando de: c:\combofix\ComboFix.exe Comandos utilizados :: c:\combofix\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))) . 2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix 2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8 2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead 2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble 2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-07 23:05 201,352 ----a-w c:\windows\system32\PnkBstrB.exe 2009-03-07 23:05 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports 2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio 2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts 2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe . ((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 ))))))))))))))))))))))))))))))))))))))))) . + 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys + 2009-03-07 12:53:08 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_1b8.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"= "c:\\WINDOWS\\System32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "28336:TCP"= 28336:TCP:eMule R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272] R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960] R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264] --- --- *NewlyCreated* - PNKBSTRB *NewlyCreated* - PNKBSTRK [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}] \Shell\AutoRun\command - rjiybg.exe \Shell\explore\Command - rjiybg.exe \Shell\open\Command - rjiybg.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d66209-2efd-11dd-984e-001bfc6c5c16}] \Shell\auto\command - Knight.exe open \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open \Shell\explore\command - Knight.exe open \Shell\find\command - Knight.exe open \Shell\install\command - Knight.exe open \Shell\open\command - Knight.exe open [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}] \Shell\AutoRun\command - nl.com \Shell\explore\Command - nl.com \Shell\open\Command - nl.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}] \Shell\AutoRun\command - D:\Autorun.exe . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ mStart Page = hxxp://br.yahoo.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-08 01:06:16 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2009-03-08 1:06:54 ComboFix-quarantined-files.txt 2009-03-08 04:06:54 ComboFix2.txt 2009-03-04 06:03:42 Pré-execução: 26 pasta(s) 50.544.279.552 bytes disponíveis Pós execução: 26 pasta(s) 50,960,334,848 bytes disponíveis 116 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:13:10, on 8/3/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Arquivos de programas\Teamspeak2_RC2\TeamSpeak.exe C:\WINDOWS\explorer.exe C:\hijackthis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg -- End of file - 5815 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 15, 2009 Opa drakos, Siga as instruções: 1. Reinicie em Modo Seguro; 2. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::C:\WINDOWS\system32\inmbox\smhost.exe D:\Autorun.exe Folder:: C:\WINDOWS\system32\inmbox Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}] [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 3. Salve o arquivo como CFScript.txt; 4. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 5. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Obs.: Execute a ação com o seu pendrive conectado ao PC. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 16, 2009 feito!!! ComboFix 09-03-15.01 - DRAKOS 2009-03-16 11:44:42.4 - FAT32x86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1811 [GMT -3:00] Executando de: C:\ComboFix.exe Comandos utilizados :: C:\CFScript.txt.txt AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) FILE :: c:\windows\system32\inmbox\smhost.exe D:\Autorun.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\inmbox c:\windows\system32\inmbox\Config.ini c:\windows\system32\inmbox\iData\1064963578\bnanovaes1231969268.xml c:\windows\system32\inmbox\iData\1064963578\c_re_cre2478695893.xml c:\windows\system32\inmbox\iData\1064963578\dione_lindo93395163.xml c:\windows\system32\inmbox\iData\1064963578\f48inho_143676762407.xml c:\windows\system32\inmbox\iData\1064963578\jhonkarodrigues1207478474.xml c:\windows\system32\inmbox\iData\1064963578\MessageLog.xsl c:\windows\system32\inmbox\iData\1846291854\MessageLog.xsl c:\windows\system32\inmbox\iData\2015172395\adilson_coquinho4118579770.xml c:\windows\system32\inmbox\iData\2015172395\dark_manel_sun1326911658.xml c:\windows\system32\inmbox\iData\2015172395\dinho_ibc1929276218.xml c:\windows\system32\inmbox\iData\2015172395\fabiana_hatschbach1390248149.xml c:\windows\system32\inmbox\iData\2015172395\fer_hatschbach1427411480.xml c:\windows\system32\inmbox\iData\2015172395\halvinhoo2782420379.xml c:\windows\system32\inmbox\iData\2015172395\ma-arcelo77694816.xml c:\windows\system32\inmbox\iData\2015172395\MessageLog.xsl c:\windows\system32\inmbox\iData\2015172395\regikk453176616.xml c:\windows\system32\inmbox\iData\2015172395\samucadovalle551705576.xml c:\windows\system32\inmbox\iData\2572751761\MessageLog.xsl c:\windows\system32\inmbox\iData\3514211199\MessageLog.xsl c:\windows\system32\inmbox\iData\3514211199\rikardo_gomes2783706685.xml c:\windows\system32\inmbox\iData\3727050937\giovanna_muito_linda1846291854.xml c:\windows\system32\inmbox\iData\3727050937\MessageLog.xsl c:\windows\system32\inmbox\iData\3727050937\raizzafhatschbach2449466979.xml c:\windows\system32\inmbox\iData\4278423633\kemelem_kemy1221093100.xml c:\windows\system32\inmbox\iData\4278423633\MessageLog.xsl c:\windows\system32\inmbox\iData\Data.msn c:\windows\system32\inmbox\iData\Mail.msm c:\windows\system32\inmbox\iData\Screens\11973199672212200821.JPG c:\windows\system32\inmbox\iData\Screens\1441701221122200916.JPG c:\windows\system32\inmbox\iData\Screens\14772638832212200811.JPG c:\windows\system32\inmbox\iData\Screens\14772638832212200812.JPG c:\windows\system32\inmbox\iData\Screens\1477263883311200801.JPG c:\windows\system32\inmbox\iData\Screens\1508545446112200922.JPG c:\windows\system32\inmbox\iData\Screens\15138665501512200818.JPG c:\windows\system32\inmbox\iData\Screens\15138665501512200819.JPG c:\windows\system32\inmbox\iData\Screens\15138665501712200821.JPG c:\windows\system32\inmbox\iData\Screens\1513866550252200919.JPG c:\windows\system32\inmbox\iData\Screens\1513866550252200920.JPG c:\windows\system32\inmbox\iData\Screens\1546761069511200801.JPG c:\windows\system32\inmbox\iData\Screens\1652872867271200917.JPG c:\windows\system32\inmbox\iData\Screens\1652872867281200915.JPG c:\windows\system32\inmbox\iData\Screens\1652872867281200916.JPG c:\windows\system32\inmbox\iData\Screens\1652872867281200917.JPG c:\windows\system32\inmbox\iData\Screens\1652872867301200919.JPG c:\windows\system32\inmbox\iData\Screens\1652872867301200922.JPG c:\windows\system32\inmbox\iData\Screens\165319589681200913.JPG c:\windows\system32\inmbox\iData\Screens\165319589691200915.JPG c:\windows\system32\inmbox\iData\Screens\1896961315301200922.JPG c:\windows\system32\inmbox\iData\Screens\1997278592301200922.JPG c:\windows\system32\inmbox\iData\Screens\2246109701252200921.JPG c:\windows\system32\inmbox\iData\Screens\2532959197511200823.JPG c:\windows\system32\inmbox\iData\Screens\2914917282511200802.JPG c:\windows\system32\inmbox\iData\Screens\3275389913111200910.JPG c:\windows\system32\inmbox\iData\Screens\3275389913111200911.JPG c:\windows\system32\inmbox\iData\Screens\3275389913231200912.JPG c:\windows\system32\inmbox\iData\Screens\3275389913231200913.JPG c:\windows\system32\inmbox\iData\Screens\3275389913231200914.JPG c:\windows\system32\inmbox\iData\Screens\32782346271111200820.JPG c:\windows\system32\inmbox\iData\Screens\32789735071712200821.JPG c:\windows\system32\inmbox\iData\Screens\33148035032712200817.JPG c:\windows\system32\inmbox\iData\Screens\33148035032712200822.JPG c:\windows\system32\inmbox\iData\Screens\33425628751712200821.JPG c:\windows\system32\inmbox\iData\Screens\37823580081112200811.JPG c:\windows\system32\inmbox\iData\Screens\37823580081211200821.JPG c:\windows\system32\inmbox\iData\Screens\37823580081211200822.JPG c:\windows\system32\inmbox\iData\Screens\37823580081212200800.JPG c:\windows\system32\inmbox\iData\Screens\37823580081311200801.JPG c:\windows\system32\inmbox\iData\Screens\37823580081512200821.JPG c:\windows\system32\inmbox\iData\Screens\37823580081912200816.JPG c:\windows\system32\inmbox\iData\Screens\37823580082012200814.JPG c:\windows\system32\inmbox\iData\Screens\37823580082112200812.JPG c:\windows\system32\inmbox\iData\Screens\37823580082212200812.JPG c:\windows\system32\inmbox\iData\Screens\37823580082212200820.JPG c:\windows\system32\inmbox\iData\Screens\37823580082212200821.JPG c:\windows\system32\inmbox\iData\Screens\3782358008241200915.JPG c:\windows\system32\inmbox\iData\Screens\3782358008241200919.JPG c:\windows\system32\inmbox\iData\Screens\3782358008241200920.JPG c:\windows\system32\inmbox\iData\Screens\37823580082712200817.JPG c:\windows\system32\inmbox\iData\Screens\37823580082912200823.JPG c:\windows\system32\inmbox\iData\Screens\37823580083011200811.JPG c:\windows\system32\inmbox\iData\Screens\3782358008301200911.JPG c:\windows\system32\inmbox\iData\Screens\3782358008312200823.JPG c:\windows\system32\inmbox\iData\Screens\378235800851200911.JPG c:\windows\system32\inmbox\iData\Screens\378235800851200912.JPG c:\windows\system32\inmbox\iData\Screens\3782358008612200823.JPG c:\windows\system32\inmbox\iData\Screens\3782358008712200800.JPG c:\windows\system32\inmbox\iData\Screens\378235800881200913.JPG c:\windows\system32\inmbox\iData\Screens\3782358008812200811.JPG c:\windows\system32\inmbox\iData\Screens\378235800891200912.JPG c:\windows\system32\inmbox\iData\Screens\378235800891200913.JPG c:\windows\system32\inmbox\iData\Screens\38525490551512200818.JPG c:\windows\system32\inmbox\iData\Screens\38525490551512200819.JPG c:\windows\system32\inmbox\iData\Screens\42029310973011200820.JPG c:\windows\system32\inmbox\iData\Screens\72015883241200915.JPG c:\windows\system32\inmbox\iData\Screens\847877238511200823.JPG c:\windows\system32\inmbox\iData\Screens\8513568922212200812.JPG c:\windows\system32\inmbox\iData\Screens\9141287861012200808.JPG c:\windows\system32\inmbox\iData\Screens\9141287861012200809.JPG c:\windows\system32\inmbox\iData\Screens\914128786231200913.JPG c:\windows\system32\inmbox\iData\Screens\914128786512200800.JPG c:\windows\system32\inmbox\iData\Users.msm c:\windows\system32\inmbox\smhost.exe c:\windows\system32\inmbox\unins000.dat c:\windows\system32\inmbox\unins000.exe G:\autorun.inf . (((((((((((((((( Arquivos/Ficheiros criados de 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))) . 2009-03-16 11:39 . 2009-03-16 11:39 2,933,823 -ra------ C:\ComboFix.exe 2009-03-11 05:42 . 2009-03-11 05:42 <DIR> d--h----- C:\$AVG8.VAULT$ 2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix 2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR 2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8 2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner 2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead 2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent 2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-15 21:34 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys 2009-03-15 21:33 201,352 ----a-w c:\windows\system32\PnkBstrB.exe 2009-02-16 02:02 --------- d-----w c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble 2009-02-16 02:02 --------- d-----w c:\arquivos de programas\Mumble 2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe 2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports 2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio 2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts 2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe . ((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 ))))))))))))))))))))))))))))))))))))))))) . + 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568] "AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"= "c:\\WINDOWS\\System32\\dpvsetup.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"= "c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "28336:TCP"= 28336:TCP:eMule S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128] S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272] S2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960] S2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7647903b-3164-11dd-9850-001bfc6c5c16}] \Shell\AutoRun\command - rjiybg.exe \Shell\explore\Command - rjiybg.exe \Shell\open\Command - rjiybg.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d66209-2efd-11dd-984e-001bfc6c5c16}] \Shell\auto\command - Knight.exe open \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open \Shell\explore\command - Knight.exe open \Shell\find\command - Knight.exe open \Shell\install\command - Knight.exe open \Shell\open\command - Knight.exe open . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ mStart Page = hxxp://br.yahoo.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-16 11:45:54 Windows 5.1.2600 Service Pack 2 FAT NTAPI Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2009-03-16 11:46:28 ComboFix-quarantined-files.txt 2009-03-16 14:46:28 ComboFix2.txt 2009-03-04 06:03:42 Pré-execução: 27 pasta(s) 50.197.725.184 bytes disponíveis Pós execução: 27 pasta(s) 50,750,816,256 bytes disponíveis 219 ________________________________________________________________________________ _____________________________________________ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:49:38, on 16/3/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\AVG\AVG8\avgemc.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\hijackthis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg -- End of file - 5856 bytes Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 17, 2009 so um duvida ...não consigo desabilitar meu anti-virus para passar o combofix uso o avg 8.0 Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 20, 2009 so um duvida ...não consigo desabilitar meu anti-virus para passar o combofix uso o avg 8.0 Clique aqui e veja como desabilitar o AVG temporariamente. ;) Como anda a máquina? Os problemas persistem? Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 23, 2009 haa sim eu ja li esse topico porem seguindo os passos que estão ai ainda acusa que a um residende sheri (não sei escrever mas seria +- isso kkkk) enquanto a minha maquina ja nos primeiros progamas que passei melhorou, ficou 100% bem mais rapida pra mim ficou show de bola, e não me canso de agradecer,,, MMMMUUUIIITTOOOOOOO OBRIGADOOOOOOOO!!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 26, 2009 Opa drakos, Fico feliz por saber que o seu problema foi resolvido. :thumbsup: Bem, para finalizar: 1. Desabilite e Reabilite a função de Restauração Automática do XP. Clique aqui e saiba como; 2. Atualize o seu Sistema Operacional urgentemente. Para que tenha uma idéia, já foram lançados 03 (três) grandes pacotes de atualização (SP1, SP2 e SP3) e você só possui o segundo deles instalado (SP2). Utilize o Windows UpDate contido no menu Iniciar para atualizar o seu sistema (SP3) ou clique sobre este link; 3. Leia o artigo Cuidados ao navegar na net para maiores informações sobre como evitar novas infecções. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
drakos 0 Denunciar post Postado Março 31, 2009 jgarcia bom dia! tudo ok aqui so tenho a agradecer msm!!!! por que so eu sei quantas vezes tive que formatar minha maquina por conta de virus e a fins, vcs são realmente demais não sei nem como agradecer ou como expressar minha gratidão perante a vcs, com certeza essa eh umas das partes mais importantes desse forun senão a mais importante, fazer uma utilidade publica como essa..... nem tenho palavras. MUITO OBRIGADO!!!!!!!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Abril 7, 2009 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites