Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

drakos

[Resolvido!] Pc lento e com varias mens de erros.

Recommended Posts

Pessoal estou com outro pc aqui em casa muito lento e com varios mens de erros , agradeço se alguem puder analizar o log ;

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:11:34, on 24/2/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\svchost.exe

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Ahead\InCD\InCD.exe

C:\Arquivos de programas\lg_fwupdate\fwupdate.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\inmbox\smhost.exe

C:\svchost.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\ARQUIV~1\AVG\AVG8\aAvgApi.exe

C:\hijackthis\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: (no name) - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Windows Setup] C:\svchost.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [LGODDFU] "C:\Arquivos de programas\lg_fwupdate\fwupdate.exe" blrun

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [svchostmp] C:\WINDOWS\system32\inmbox\smhost.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [svchost] C:\svchost.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [spyware Doctor] "C:\Arquivos de programas\Spyware Doctor\spydoctor.exe" /Q

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe

O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg

 

--

End of file - 7458 bytes

 

 

desde ja obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar.

 

PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta.

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO.

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ok feito ai vai o relatorio do combofix junto com o hijck atualizado

 

 

ComboFix 09-02-27.02 - DRAKOS 2009-02-28 14:00:05.1 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1637 [GMT -3:00]

Executando de: C:\ComboFix.exe

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\docume~1\DRAKOS\CONFIG~1\Temp\svchost.exe

C:\svchost.exe

c:\windows\system32\drivers\npf.sys

c:\windows\system32\packet.dll

c:\windows\system32\pthreadVC.dll

c:\windows\system32\wanpacket.dll

c:\windows\system32\wpcap.dll

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_NPF

-------\Service_NPF

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-28 to 2009-02-28 ))))))))))))))))))))))))))))

.

 

2009-02-28 11:48 . 2009-02-28 11:48 2,926,240 -ra------ C:\ComboFix.exe

2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead

2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-28 03:54 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys

2009-02-28 03:54 103,736 ----a-w c:\windows\system32\PnkBstrB.exe

2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe

2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports

2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio

2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts

2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2008-12-04 03:33 73,216 ----a-w c:\windows\ST6UNST.EXE

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Spyware Doctor"="c:\arquivos de programas\Spyware Doctor\spydoctor.exe" [2004-07-29 1818624]

"NBJ"="c:\arquivos de programas\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 1957888]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 81920]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"RemoteControl"="c:\arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]

"InCD"="c:\arquivos de programas\Ahead\InCD\InCD.exe" [2006-07-12 1397760]

"LGODDFU"="c:\arquivos de programas\lg_fwupdate\fwupdate.exe" [2008-10-03 548864]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-10-27 136600]

"svchostmp"="c:\windows\system32\inmbox\smhost.exe" [2008-09-30 6905856]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

"nwiz"="nwiz.exe" [2007-04-19 c:\windows\system32\nwiz.exe]

"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 c:\windows\RTHDCPL.exe]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"=

"c:\\WINDOWS\\System32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"=

"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"28336:TCP"= 28336:TCP:eMule

 

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}]

\Shell\AutoRun\command - rjiybg.exe

\Shell\explore\Command - rjiybg.exe

\Shell\open\Command - rjiybg.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}]

\Shell\AutoRun\command - nl.com

\Shell\explore\Command - nl.com

\Shell\open\Command - nl.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}]

\Shell\AutoRun\command - D:\Autorun.exe

.

- - - - ORFÃOS REMOVIDOS - - - -

 

BHO-{db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)

HKLM-Run-Media Codec Update Service - c:\arquivos de programas\Essentials Codec Pack\update.exe

HKLM-Run-Windows Setup - C:\svchost.exe

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

mStart Page = hxxp://br.yahoo.com

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-28 14:02:30

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\AHEAD\INCD\INCDSRV.EXE

c:\windows\SYSTEM32\RUNDLL32.EXE

c:\arquivos de programas\JAVA\JRE6\BIN\JQS.EXE

c:\windows\SYSTEM32\NVSVC32.EXE

c:\windows\SYSTEM32\PNKBSTRA.EXE

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-02-28 14:03:31 - Máquina reiniciou [DRAKOS]

ComboFix-quarantined-files.txt 2009-02-28 17:03:30

 

Pré-execução: 24 pasta(s) 35.258.007.552 bytes disponíveis

Pós execução: 24 pasta(s) 40,252,080,128 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

C:\ = "Microsoft Windows"

 

135

 

 

 

 

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:10:19, on 28/2/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Ahead\InCD\InCD.exe

C:\Arquivos de programas\lg_fwupdate\fwupdate.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\inmbox\smhost.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [inCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [LGODDFU] "C:\Arquivos de programas\lg_fwupdate\fwupdate.exe" blrun

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [svchostmp] C:\WINDOWS\system32\inmbox\smhost.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [spyware Doctor] "C:\Arquivos de programas\Spyware Doctor\spydoctor.exe" /Q

O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe"

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe

O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg

 

--

End of file - 6236 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

1. Baixe o BankerFix 3.0.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM.

 

4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado.

 

5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos.

 

6. Terminado o scan, leia a mensagem na tela e aperte Enter.

 

7. Habilite o seu anti-vírus.

 

8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

 

PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

feito

 

BankerFix 3.0 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2009-03-01 - 10:52

-------------------------------------------------------

Lista de Definição: 2009-01-21-2 | CORE: 2009-01-21-1

=======================================================

 

 

 

----- Fim -------------------------

 

 

 

migao ja sumiu as mens de erro e o pc voltou com agilidade ja, pow show de bola parabens a todos vcs, vcs são demais,

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

O processo de desinfecção ainda não acabou. Poste um novo log do ComboFix.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

opa ok, fiquei tão feliz que queria agradecer antecipado!!! kkkkk

 

aqui vai o log do combofix atualizado:

 

ComboFix 09-02-27.02 - DRAKOS 2009-03-04 3:02:09.2 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1729 [GMT -3:00]

Executando de: c:\combofix\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-04 to 2009-03-04 ))))))))))))))))))))))))))))

.

 

2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix

2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8

2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys

2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys

2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll

2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead

2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-04 02:03 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys

2009-03-04 02:02 201,352 ----a-w c:\windows\system32\PnkBstrB.exe

2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe

2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports

2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio

2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts

2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2008-12-04 03:33 73,216 ----a-w c:\windows\ST6UNST.EXE

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys

+ 2009-03-04 01:24:58 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_1e8.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"=

"c:\\WINDOWS\\System32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"=

"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"28336:TCP"= 28336:TCP:eMule

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128]

R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264]

 

--- ---

 

*NewlyCreated* - PNKBSTRB

*NewlyCreated* - PNKBSTRK

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}]

\Shell\AutoRun\command - rjiybg.exe

\Shell\explore\Command - rjiybg.exe

\Shell\open\Command - rjiybg.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}]

\Shell\AutoRun\command - nl.com

\Shell\explore\Command - nl.com

\Shell\open\Command - nl.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}]

\Shell\AutoRun\command - D:\Autorun.exe

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

mStart Page = hxxp://br.yahoo.com

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-04 03:03:03

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2009-03-04 3:03:39

ComboFix-quarantined-files.txt 2009-03-04 06:03:38

 

Pré-execução: 26 pasta(s) 50.385.453.056 bytes disponíveis

Pós execução: 26 pasta(s) 50,780,602,368 bytes disponíveis

 

109

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

C:\WINDOWS\system32\inmbox\smhost.exe

D:\Autorun.exe

Folder::

C:\WINDOWS\system32\inmbox

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-03-06.02 - DRAKOS 2009-03-08 1:05:16.3 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1705 [GMT -3:00]

Executando de: c:\combofix\ComboFix.exe

Comandos utilizados :: c:\combofix\CFScript.txt

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-08 to 2009-03-08 ))))))))))))))))))))))))))))

.

 

2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix

2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8

2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys

2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys

2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll

2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead

2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble

2009-02-15 23:02 . 2009-02-15 23:02 <DIR> d-------- c:\arquivos de programas\Mumble

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-07 23:05 201,352 ----a-w c:\windows\system32\PnkBstrB.exe

2009-03-07 23:05 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys

2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe

2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports

2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio

2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts

2009-01-09 15:35 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys

+ 2009-03-07 12:53:08 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_1b8.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"=

"c:\\WINDOWS\\System32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"=

"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"28336:TCP"= 28336:TCP:eMule

 

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128]

R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272]

R2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960]

R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264]

 

--- ---

 

*NewlyCreated* - PNKBSTRB

*NewlyCreated* - PNKBSTRK

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}]

\Shell\AutoRun\command - rjiybg.exe

\Shell\explore\Command - rjiybg.exe

\Shell\open\Command - rjiybg.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d66209-2efd-11dd-984e-001bfc6c5c16}]

\Shell\auto\command - Knight.exe open

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open

\Shell\explore\command - Knight.exe open

\Shell\find\command - Knight.exe open

\Shell\install\command - Knight.exe open

\Shell\open\command - Knight.exe open

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}]

\Shell\AutoRun\command - nl.com

\Shell\explore\Command - nl.com

\Shell\open\Command - nl.com

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}]

\Shell\AutoRun\command - D:\Autorun.exe

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

mStart Page = hxxp://br.yahoo.com

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-08 01:06:16

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2009-03-08 1:06:54

ComboFix-quarantined-files.txt 2009-03-08 04:06:54

ComboFix2.txt 2009-03-04 06:03:42

 

Pré-execução: 26 pasta(s) 50.544.279.552 bytes disponíveis

Pós execução: 26 pasta(s) 50,960,334,848 bytes disponíveis

 

116

 

 

 

 

 

 

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:13:10, on 8/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\Arquivos de programas\Teamspeak2_RC2\TeamSpeak.exe

C:\WINDOWS\explorer.exe

C:\hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe

O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg

 

--

End of file - 5815 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

Siga as instruções:

 

1. Reinicie em Modo Seguro;

 

2. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

C:\WINDOWS\system32\inmbox\smhost.exe

D:\Autorun.exe

Folder::

C:\WINDOWS\system32\inmbox

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76479039-3164-11dd-9850-001bfc6c5c16}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db3ba6-55ea-11dd-8aaa-806d6172696f}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0e0c1c3-2e29-11dd-9b03-806d6172696f}]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 3. Salve o arquivo como CFScript.txt;
     
    4. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    5. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

feito!!!

 

 

ComboFix 09-03-15.01 - DRAKOS 2009-03-16 11:44:42.4 - FAT32x86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.2047.1811 [GMT -3:00]

Executando de: C:\ComboFix.exe

Comandos utilizados :: C:\CFScript.txt.txt

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

 

FILE ::

c:\windows\system32\inmbox\smhost.exe

D:\Autorun.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\inmbox

c:\windows\system32\inmbox\Config.ini

c:\windows\system32\inmbox\iData\1064963578\bnanovaes1231969268.xml

c:\windows\system32\inmbox\iData\1064963578\c_re_cre2478695893.xml

c:\windows\system32\inmbox\iData\1064963578\dione_lindo93395163.xml

c:\windows\system32\inmbox\iData\1064963578\f48inho_143676762407.xml

c:\windows\system32\inmbox\iData\1064963578\jhonkarodrigues1207478474.xml

c:\windows\system32\inmbox\iData\1064963578\MessageLog.xsl

c:\windows\system32\inmbox\iData\1846291854\MessageLog.xsl

c:\windows\system32\inmbox\iData\2015172395\adilson_coquinho4118579770.xml

c:\windows\system32\inmbox\iData\2015172395\dark_manel_sun1326911658.xml

c:\windows\system32\inmbox\iData\2015172395\dinho_ibc1929276218.xml

c:\windows\system32\inmbox\iData\2015172395\fabiana_hatschbach1390248149.xml

c:\windows\system32\inmbox\iData\2015172395\fer_hatschbach1427411480.xml

c:\windows\system32\inmbox\iData\2015172395\halvinhoo2782420379.xml

c:\windows\system32\inmbox\iData\2015172395\ma-arcelo77694816.xml

c:\windows\system32\inmbox\iData\2015172395\MessageLog.xsl

c:\windows\system32\inmbox\iData\2015172395\regikk453176616.xml

c:\windows\system32\inmbox\iData\2015172395\samucadovalle551705576.xml

c:\windows\system32\inmbox\iData\2572751761\MessageLog.xsl

c:\windows\system32\inmbox\iData\3514211199\MessageLog.xsl

c:\windows\system32\inmbox\iData\3514211199\rikardo_gomes2783706685.xml

c:\windows\system32\inmbox\iData\3727050937\giovanna_muito_linda1846291854.xml

c:\windows\system32\inmbox\iData\3727050937\MessageLog.xsl

c:\windows\system32\inmbox\iData\3727050937\raizzafhatschbach2449466979.xml

c:\windows\system32\inmbox\iData\4278423633\kemelem_kemy1221093100.xml

c:\windows\system32\inmbox\iData\4278423633\MessageLog.xsl

c:\windows\system32\inmbox\iData\Data.msn

c:\windows\system32\inmbox\iData\Mail.msm

c:\windows\system32\inmbox\iData\Screens\11973199672212200821.JPG

c:\windows\system32\inmbox\iData\Screens\1441701221122200916.JPG

c:\windows\system32\inmbox\iData\Screens\14772638832212200811.JPG

c:\windows\system32\inmbox\iData\Screens\14772638832212200812.JPG

c:\windows\system32\inmbox\iData\Screens\1477263883311200801.JPG

c:\windows\system32\inmbox\iData\Screens\1508545446112200922.JPG

c:\windows\system32\inmbox\iData\Screens\15138665501512200818.JPG

c:\windows\system32\inmbox\iData\Screens\15138665501512200819.JPG

c:\windows\system32\inmbox\iData\Screens\15138665501712200821.JPG

c:\windows\system32\inmbox\iData\Screens\1513866550252200919.JPG

c:\windows\system32\inmbox\iData\Screens\1513866550252200920.JPG

c:\windows\system32\inmbox\iData\Screens\1546761069511200801.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867271200917.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867281200915.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867281200916.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867281200917.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867301200919.JPG

c:\windows\system32\inmbox\iData\Screens\1652872867301200922.JPG

c:\windows\system32\inmbox\iData\Screens\165319589681200913.JPG

c:\windows\system32\inmbox\iData\Screens\165319589691200915.JPG

c:\windows\system32\inmbox\iData\Screens\1896961315301200922.JPG

c:\windows\system32\inmbox\iData\Screens\1997278592301200922.JPG

c:\windows\system32\inmbox\iData\Screens\2246109701252200921.JPG

c:\windows\system32\inmbox\iData\Screens\2532959197511200823.JPG

c:\windows\system32\inmbox\iData\Screens\2914917282511200802.JPG

c:\windows\system32\inmbox\iData\Screens\3275389913111200910.JPG

c:\windows\system32\inmbox\iData\Screens\3275389913111200911.JPG

c:\windows\system32\inmbox\iData\Screens\3275389913231200912.JPG

c:\windows\system32\inmbox\iData\Screens\3275389913231200913.JPG

c:\windows\system32\inmbox\iData\Screens\3275389913231200914.JPG

c:\windows\system32\inmbox\iData\Screens\32782346271111200820.JPG

c:\windows\system32\inmbox\iData\Screens\32789735071712200821.JPG

c:\windows\system32\inmbox\iData\Screens\33148035032712200817.JPG

c:\windows\system32\inmbox\iData\Screens\33148035032712200822.JPG

c:\windows\system32\inmbox\iData\Screens\33425628751712200821.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081112200811.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081211200821.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081211200822.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081212200800.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081311200801.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081512200821.JPG

c:\windows\system32\inmbox\iData\Screens\37823580081912200816.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082012200814.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082112200812.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082212200812.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082212200820.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082212200821.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008241200915.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008241200919.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008241200920.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082712200817.JPG

c:\windows\system32\inmbox\iData\Screens\37823580082912200823.JPG

c:\windows\system32\inmbox\iData\Screens\37823580083011200811.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008301200911.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008312200823.JPG

c:\windows\system32\inmbox\iData\Screens\378235800851200911.JPG

c:\windows\system32\inmbox\iData\Screens\378235800851200912.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008612200823.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008712200800.JPG

c:\windows\system32\inmbox\iData\Screens\378235800881200913.JPG

c:\windows\system32\inmbox\iData\Screens\3782358008812200811.JPG

c:\windows\system32\inmbox\iData\Screens\378235800891200912.JPG

c:\windows\system32\inmbox\iData\Screens\378235800891200913.JPG

c:\windows\system32\inmbox\iData\Screens\38525490551512200818.JPG

c:\windows\system32\inmbox\iData\Screens\38525490551512200819.JPG

c:\windows\system32\inmbox\iData\Screens\42029310973011200820.JPG

c:\windows\system32\inmbox\iData\Screens\72015883241200915.JPG

c:\windows\system32\inmbox\iData\Screens\847877238511200823.JPG

c:\windows\system32\inmbox\iData\Screens\8513568922212200812.JPG

c:\windows\system32\inmbox\iData\Screens\9141287861012200808.JPG

c:\windows\system32\inmbox\iData\Screens\9141287861012200809.JPG

c:\windows\system32\inmbox\iData\Screens\914128786231200913.JPG

c:\windows\system32\inmbox\iData\Screens\914128786512200800.JPG

c:\windows\system32\inmbox\iData\Users.msm

c:\windows\system32\inmbox\smhost.exe

c:\windows\system32\inmbox\unins000.dat

c:\windows\system32\inmbox\unins000.exe

G:\autorun.inf

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-16 to 2009-03-16 ))))))))))))))))))))))))))))

.

 

2009-03-16 11:39 . 2009-03-16 11:39 2,933,823 -ra------ C:\ComboFix.exe

2009-03-11 05:42 . 2009-03-11 05:42 <DIR> d--h----- C:\$AVG8.VAULT$

2009-03-01 10:57 . 2009-03-01 10:57 <DIR> d-------- C:\bankerfix

2009-03-01 10:51 . 2009-03-01 10:51 <DIR> d-------- C:\LinhaDefensiva

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\windows\system32\drivers\Avg

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\AVGTOOLBAR

2009-02-28 15:55 . 2009-02-28 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8

2009-02-28 15:55 . 2009-03-01 10:12 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys

2009-02-28 15:55 . 2009-03-01 10:12 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys

2009-02-28 15:55 . 2009-03-01 10:12 10,520 --a------ c:\windows\system32\avgrsstx.dll

2009-02-28 14:28 . 2009-02-28 14:28 <DIR> d-------- c:\arquivos de programas\RegCleaner

2009-02-25 18:35 . 2009-02-25 18:35 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\Ahead

2009-02-24 13:10 . 2009-02-24 13:10 <DIR> d-------- C:\hijackthis

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\documents and settings\DRAKOS\Dados de aplicativos\BitTorrent

2009-02-19 13:53 . 2009-02-19 13:53 <DIR> d-------- c:\arquivos de programas\BitTorrent

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-15 21:34 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys

2009-03-15 21:33 201,352 ----a-w c:\windows\system32\PnkBstrB.exe

2009-02-16 02:02 --------- d-----w c:\documents and settings\DRAKOS\Dados de aplicativos\Mumble

2009-02-16 02:02 --------- d-----w c:\arquivos de programas\Mumble

2009-01-25 02:43 66,872 ----a-w c:\windows\system32\PnkBstrA.exe

2009-01-24 21:34 --------- d-----w c:\arquivos de programas\EA Sports

2009-01-24 19:51 --------- d-----w c:\arquivos de programas\GameVicio

2009-01-24 19:19 --------- d-----w c:\arquivos de programas\Electronic Arts

2004-10-01 18:00 40,960 ----a-w c:\arquivos de programas\Uninstall_CDS.exe

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-28_14.03.07.00 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-01 13:12:06 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-03-01 10:12 10520 c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\EA GAMES\\Battlefield 2\\BF2.exe"=

"c:\\WINDOWS\\System32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"=

"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"28336:TCP"= 28336:TCP:eMule

 

S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-28 325128]

S1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-28 107272]

S2 avg8emc;AVG8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [2009-02-28 903960]

S2 avg8wd;AVG8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2009-02-28 298264]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7647903b-3164-11dd-9850-001bfc6c5c16}]

\Shell\AutoRun\command - rjiybg.exe

\Shell\explore\Command - rjiybg.exe

\Shell\open\Command - rjiybg.exe

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77d66209-2efd-11dd-984e-001bfc6c5c16}]

\Shell\auto\command - Knight.exe open

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open

\Shell\explore\command - Knight.exe open

\Shell\find\command - Knight.exe open

\Shell\install\command - Knight.exe open

\Shell\open\command - Knight.exe open

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

mStart Page = hxxp://br.yahoo.com

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-16 11:45:54

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2009-03-16 11:46:28

ComboFix-quarantined-files.txt 2009-03-16 14:46:28

ComboFix2.txt 2009-03-04 06:03:42

 

Pré-execução: 27 pasta(s) 50.197.725.184 bytes disponíveis

Pós execução: 27 pasta(s) 50,750,816,256 bytes disponíveis

 

219

________________________________________________________________________________

_____________________________________________

 

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:49:38, on 16/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\system32\PnkBstrB.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe

C:\hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1212113316953

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=24931

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Arquivos de programas\WinPcap\rpcapd.exe

O24 - Desktop Component 0: (no name) - http://www.toymagazine.com.br/images/image.../dvd_carros.jpg

 

--

End of file - 5856 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

haa sim eu ja li esse topico porem seguindo os passos que estão ai ainda acusa que a um residende sheri (não sei escrever mas seria +- isso kkkk)

enquanto a minha maquina ja nos primeiros progamas que passei melhorou, ficou 100% bem mais rapida pra mim ficou show de bola, e não me canso de agradecer,,, MMMMUUUIIITTOOOOOOO OBRIGADOOOOOOOO!!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa drakos,

 

Fico feliz por saber que o seu problema foi resolvido. :thumbsup:

 

Bem, para finalizar:

 

1. Desabilite e Reabilite a função de Restauração Automática do XP. Clique aqui e saiba como;

 

2. Atualize o seu Sistema Operacional urgentemente.

 

Para que tenha uma idéia, já foram lançados 03 (três) grandes pacotes de atualização (SP1, SP2 e SP3) e você só possui o segundo deles instalado (SP2). Utilize o Windows UpDate contido no menu Iniciar para atualizar o seu sistema (SP3) ou clique sobre este link;

 

3. Leia o artigo Cuidados ao navegar na net para maiores informações sobre como evitar novas infecções.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

jgarcia bom dia!

 

tudo ok aqui so tenho a agradecer msm!!!! por que so eu sei quantas vezes tive que formatar minha maquina por conta de virus e a fins, vcs são realmente demais não sei nem como agradecer ou como expressar minha gratidão perante a vcs, com certeza essa eh umas das partes mais importantes desse forun senão a mais importante, fazer uma utilidade publica como essa..... nem tenho palavras.

 

 

 

MUITO OBRIGADO!!!!!!!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.