Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Everaldo Barbosa

[Resolvido!] Vírus Trojan

Recommended Posts

Caros,

Minha máquina está com virus. Mostrou as seguintes mensagens:Infecção: Win32:Trojan-gen, Win32:Vitro e Win32:Swizzor (Trj).

 

Windows-XP e antivírus Avast.

 

 

Segue log abaixo:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:21, on 2009-04-10

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Unable to get Internet Explorer version!

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Vtune\TBPanel.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\WINDOWS\ServicePackFiles\i386\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Temp\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Arquivos de programas\Dealio\kb124\Dealio.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Arquivos de programas\Dealio\kb124\Dealio.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [Gainward] C:\Arquivos de programas\Vtune\TBPanel.exe /A

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [WatchDog] C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

O4 - HKLM\..\Run: [au] C:\Arquivos de programas\Dealio\DealioAU.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\user\Dados de aplicativos\Dealio\kb124\res\DealioSearch.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb124\Dealio.dll

O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb124\Dealio.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{6567EB37-AC23-4A19-BDDE-9FB90E24C01E}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - c:\arquivos de programas\arquivos comuns\logishrd\lvmvfm\LVPrcSrv.exe (file missing)

O23 - Service: LVSrvLauncher - Unknown owner - C:\Arquivos de programas\Arquivos comuns\LogiShrd\SrvLnch\SrvLnch.exe (file missing)

O23 - Service: MySQL - Unknown owner - C:\Arquivos.exe (file missing)

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

 

--

End of file - 12687 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Everaldo Barbosa

 

<@> Baixe: < ToolBar S&D >

<@> Salve-o no Disco Local-C,em uma pasta própria.

<@> Reinicie o computador,em Modo de Segurança. <-- Importante!

<@> Execute o programa,e à seguir,aperte o "p" --> Enter --> Ok.

<@> Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde!

<@> Terminando,poste o relatório. ( C:\ToolBar SD\TB_1.txt )

<><><><><><><><><><>

<@> Vá a este link,e baixe: < Malwarebytes >

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<><><><><><><><><><>

<@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Segue os log's gerados:

 

ToolBar S&D:

 

 

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3

X86-based PC ( Multiprocessor Free : AMD Athlon 64 X2 Dual Core Processor 4000+ )

BIOS : BIOS Date: 12/04/07 17:40:55 Ver: 08.00.12

USER : user ( Administrator )

BOOT : Fail-safe boot

Antivirus : avast! antivirus 4.8.1335 [VPS 090410-0] 4.8.1335 (Not Activated)

A:\ (USB)

C:\ (Local Disk) - NTFS - Total:97 Go (Free:17 Go)

D:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [2] ( 2009-04-11|15:23 )

 

-----------\\ REMOVIDOS

 

Deletado! - C:\DOCUME~1\MIRIAN~1\DADOSD~1\Dealio\kb124

Deletado! - C:\DOCUME~1\user\DADOSD~1\Dealio\kb124

Deletado! - C:\Arquivos de programas\Dealio\DealioAU.exe

Deletado! - C:\Arquivos de programas\Dealio\kb124

Deletado! - C:\DOCUME~1\ALLUSE~1\MENUIN~1\PROGRA~1\Dealio

Deletado! - C:\DOCUME~1\MIRIAN~1\DADOSD~1\Dealio

Deletado! - C:\DOCUME~1\user\DADOSD~1\Dealio

Deletado! - C:\Arquivos de programas\Dealio

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Search Page"="http://www.google.com"

"Search Bar"="http://www.google.com/ie"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://www.google.com/ie"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 2009-04-11|15:25 - Option : [2]

 

 

 

Log Malwarebytes:

 

Malwarebytes' Anti-Malware 1.36

Versão do banco de dados: 1967

Windows 5.1.2600 Service Pack 3

 

2009-04-11 16:30:17

mbam-log-2009-04-11 (16-30-17).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 210232

Tempo decorrido: 43 minute(s), 12 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 1

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

C:\WINDOWS\Downloaded Program Files\GbPluginABN.inf (Trojan.Agent) -> Quarantined and deleted successfully.

 

 

Log HijackThis v2.0.2:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:36, on 2009-04-11

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Unable to get Internet Explorer version!

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Vtune\TBPanel.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Alwil Software\Avast4\setup\avast.setup

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Hijack\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Gainward] C:\Arquivos de programas\Vtune\TBPanel.exe /A

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [WatchDog] C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - c:\arquivos de programas\arquivos comuns\logishrd\lvmvfm\LVPrcSrv.exe (file missing)

O23 - Service: LVSrvLauncher - Unknown owner - C:\Arquivos de programas\Arquivos comuns\LogiShrd\SrvLnch\SrvLnch.exe (file missing)

O23 - Service: MySQL - Unknown owner - C:\Arquivos.exe (file missing)

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

 

--

End of file - 11663 bytes

 

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Everaldo Barbosa

 

<@> Faça um scan online em: < Kaspersky >

<@> Utilize para isso,o navegador Internet Explorer.

<@> Na próxima página,clique em: I Accept

<@> Isto,para que se instale o controle ActiveX e,em seguida,atualize o banco de dados.

<@> Na próxima página,clique em: My Computer e faça o scan.

<@> Tenha paciência!

<@> Aguarde a atualização da base de dados,e também do exame,que é demorado.

<@> Terminando,salve e poste o relatório.

<@> Clique em Save Report As... para salvar o log. ( Kaspersky_Online_Scanner_7_Report.txt )

<@> Salve o resultado como .txt,segundo a imagem abaixo:

 

Kas-Savetxt.gif

 

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam,

 

Segue os log's gerados;

 

 

Log KasperSky:

 

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0 REPORT

Sunday, April 12, 2009

Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)

Kaspersky Online Scanner version: 7.0.26.13

Program database last update: Sunday, April 12, 2009 01:25:21

Records in database: 2035850

--------------------------------------------------------------------------------

 

Scan settings:

Scan using the following database: extended

Scan archives: yes

Scan mail databases: yes

 

Scan area - File:

 

 

Scan statistics:

Files scanned: 123643

Threat name: 2

Infected objects: 118

Suspicious objects: 0

Duration of the scan: 02:30:09

 

 

File name / Threat name / Threats count

C:\Arquivos de programas\Internet Explorer\Connection Wizard\msicw.exe Infected: Packed.Win32.Black.a 1

C:\desen\programas\MyEclipse 6.0\dbexplorer\DBExplorer.exe Infected: Virus.Win32.Virut.ce 1

C:\desen\programas\MyEclipse 6.0\htmldesigner\HtmlDesigner.exe Infected: Virus.Win32.Virut.ce 1

C:\desen\programas\MyEclipse 6.0\imageeditor\ImageEditor.exe Infected: Virus.Win32.Virut.ce 1

C:\desen\programas\MyEclipse 6.0\texteditor\MyTextEditor.exe Infected: Virus.Win32.Virut.ce 1

C:\desen\programas\MyEclipse 6.0\xmleditor\XMLEditor.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\accwiz.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\actmovie.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ahui.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\alg.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\asr_fmt.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\asr_pfu.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\at.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\atmadm.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\auditusr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\blastcln.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cipher.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cisvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cleanmgr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cliconfg.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\clipbrd.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cmd.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cmdl32.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cmmon32.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cmstp.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\comrepl.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\conf.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\conime.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\cscript.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\davcdata.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ddeshare.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\defrag.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dfrgfat.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dfrgntfs.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dialer.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\diantz.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\diskpart.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dmadmin.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dmremote.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dplaysvr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dpnsvr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dpvsetup.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dvdupgrd.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\dxdiag.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\eudcedit.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\evcreate.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\eventcreate.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\evntcmd.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\evntwin.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\explorer.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\extrac32.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\findstr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fltmc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fontview.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fsquirt.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ftp.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fxsclnt.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fxscover.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\fxssvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\gpresult.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\gprslt.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\hh.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\hscupd.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\icwconn1.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\icwconn2.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ie4uinit.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\iedw.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\iexpress.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\iisrstas.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\imapi.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\inetin51.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\inetwiz.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ipconfig.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ipv6.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\ipxroute.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\locator.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\logman.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\logonui.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\lsass.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\magnify.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\makecab.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\migload.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\migregdb.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\migwiz.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mmc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mobsync.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mofcomp.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mplay32.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mqbkup.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mqsvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mqtgsvc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\msconfig.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\msdtc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mshta.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\msiregmv.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\msmsgs.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mspaint.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mstinit.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\mstsc.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\narrator.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\nddeapir.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\net.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\net1.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\netdde.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\$NtServicePackUninstall$\netsh.exe Infected: Virus.Win32.Virut.ce 1

C:\WINDOWS\Installer\{3FADAA19-E595-44CA-A072-58B6B0851768}\Icon3FADAA191.exe Infected: Virus.Win32.Virut.ce 1

 

The selected area was scanned.

 

 

 

Log Hijackthis:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 07:32, on 2009-04-12

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Unable to get Internet Explorer version!

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Vtune\TBPanel.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\WinZip\WZQKPICK.EXE

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\ServicePackFiles\i386\iexplore.exe

C:\Arquivos de programas\Java\jre6\bin\java.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Hijack\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.odia.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Gainward] C:\Arquivos de programas\Vtune\TBPanel.exe /A

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [WatchDog] C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{6567EB37-AC23-4A19-BDDE-9FB90E24C01E}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - c:\arquivos de programas\arquivos comuns\logishrd\lvmvfm\LVPrcSrv.exe (file missing)

O23 - Service: LVSrvLauncher - Unknown owner - C:\Arquivos de programas\Arquivos comuns\LogiShrd\SrvLnch\SrvLnch.exe (file missing)

O23 - Service: MySQL - Unknown owner - C:\Arquivos.exe (file missing)

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

 

--

End of file - 11758 bytes

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Everaldo Barbosa

 

<@> Baixe:

 

< rmvirut.exe >

 

< rmvirut.nt >

 

<!> Ps: Salve-os em uma mesma pasta,por exemplo: C:\Virut

 

<@> Reinicie o computador em Modo de segurança.

<@> Vá até Iniciar --> Executar -> Digite: C:\Virut\rmvirut.exe C: --> Clique em OK.

 

<!> OBS: Caso possua outras unidades de disco,adicione-as ao comando,da seguinte forma:

 

C:\Virut\rmvirut.exe C: D:

 

<@> Aguarde a conclusão! --> Aperte Enter.

<@> O computador será reiniciado!

<><><><><><><><><><><><>

<@> Baixe: < DrWebCureIt >

<@> Salve-o no desktop!

<@> Reinicie o computador em Modo de Segurança.

<@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit.

<@> Na janela que abrir,clique em Iniciar --> OK.

<@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda!

<@> Terminando,marque a caixa de "Verificação Completa".

<@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis".

 

Neste modo são verificados os seguintes objectos:

 

* Sectores de Arranque de Todos os Discos. <--

 

* Todas as Unidades Removíveis. <--

 

* Todos os Discos Locais. <--

<@> Clique em "Iniciar verificação" --> Aguarde!

<@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim.

<@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios".

<@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Texto!

<@> Poste: DrWeb.csv

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam,

 

Segue abaixo o log DrWeb.csv:

 

 

msicw.exe C:\Arquivos de programas\Internet Explorer\Connection Wizard Trojan.Packed.650 Eliminado.

A0024961.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0024970.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0024994.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025024.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025085.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025086.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025087.EXE C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025090.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025091.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025096.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0025101.EXE C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026055.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Trojan.Swizzor.based Eliminado.

A0026056.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026057.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026058.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026059.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026060.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026061.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP54 Win32.Virut.56 Desinfectado.

A0026073.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP55 Win32.Virut.56 Desinfectado.

A0026074.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP55 Win32.Virut.56 Desinfectado.

A0026075.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP55 Win32.Virut.56 Desinfectado.

A0026076.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP55 Win32.Virut.56 Desinfectado.

A0026452.rbf C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026498.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026499.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026500.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026501.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026502.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Win32.Virut.56 Desinfectado.

A0026503.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP57 Trojan.Packed.650 Eliminado.

msiexec.exe C:\WINDOWS\$MSI31Uninstall_KB893803v2$ Win32.Virut.56 Desinfectado.

accwiz.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

actmovie.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

agentsvr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ahui.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

alg.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

asr_fmt.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

asr_pfu.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

at.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

atmadm.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

auditusr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

blastcln.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cipher.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cisvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cleanmgr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cliconfg.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

clipbrd.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

clipsrv.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cmd.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cmdl32.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cmmon32.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cmstp.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

comrepl.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

conf.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

conime.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

cscript.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ctfmon.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

davcdata.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ddeshare.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

defrag.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dfrgfat.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dfrgntfs.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dialer.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

diantz.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

diskpart.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dllhost.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dmadmin.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dmremote.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dplaysvr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dpnsvr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dpvsetup.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dumprep.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dvdupgrd.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

dxdiag.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

eudcedit.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

evcreate.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

eventcreate.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

evntcmd.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

evntwin.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

explorer.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

extrac32.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

findstr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fltmc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fontview.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fsquirt.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ftp.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fxsclnt.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fxscover.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

fxssvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

gpresult.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

gprslt.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

helpctr.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

helpsvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

hh.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

hscupd.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

icwconn1.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

icwconn2.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ie4uinit.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

iedw.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

iexplore.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

iexpress.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

iisrstas.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

imapi.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

inetin51.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

inetwiz.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ipconfig.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ipv6.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

ipxroute.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

locator.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

logman.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

logonui.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

lsass.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

magnify.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

makecab.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

migload.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

migregdb.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

migwiz.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mmc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mnmsrvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mobsync.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mofcomp.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

moviemk.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mplay32.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mqbkup.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mqsvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mqtgsvc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

msconfig.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

msdtc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mshta.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

msiexec.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

msiregmv.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

msmsgs.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mspaint.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mstinit.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

mstsc.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

narrator.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

nddeapir.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

net.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

net1.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

netdde.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

netsh.exe C:\WINDOWS\$NtServicePackUninstall$ Win32.Virut.56 Desinfectado.

Icon3FADAA191.exe C:\WINDOWS\Installer\{3FADAA19-E595-44CA-A072-58B6B0851768} Win32.Virut.56 Desinfectado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Everaldo Barbosa

 

<@> Baixe: < Kaspersky Virus Removal Tool >

<@> Salve-o em Arquivos de Programas,e instale-o aí mesmo!

<@> Reinicie o computador,em Modo de Segurança! <-- Importante!

<@> Dê início ao exame,clicando em "Scan".

<@> A verificação é muito demorada. <-- Aguarde!

<@> Caso seja encontrada infecções,clique em "disinfect".

<@> Terminando,clique na aba Events.

<@> Desmarque a caixa de seleção "Show all events".

<@> Clique em "Save to file".

<@> Nomeie-o e salve-o no desktop! <-- Relatório para postagem!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite DigRam,

 

Segue log do Kaspersky:

 

 

Scan

----

Scanned: 2758567

Detected: 0

Untreated: 0

Start time: 2009-04-14 07:17

Duration: 04:50:06

Finish time: 2009-04-14 12:07

 

 

Detected

--------

Status Object

------ ------

 

 

Events

------

Time Name Status Reason

---- ---- ------ ------

 

 

Statistics

----------

Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted

------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

 

 

Settings

--------

Parameter Value

--------- -----

Security Level Recommended

Action Prompt for action when the scan is complete

Run mode Manually

File types Scan all files

Scan only new and changed files No

Scan archives All

Scan embedded OLE objects All

Skip if object is larger than No

Skip if scan takes longer than No

Parse email formats No

Scan password-protected archives No

Enable iChecker technology No

Enable iSwift technology No

Show detected threats on "Detected" tab Yes

Rootkits search Yes

Deep rootkits search No

Use heuristic analyzer Yes

 

 

Quarantine

----------

Status Object Size Added

------ ------ ---- -----

 

 

Backup

------

Status Object Size

------ ------ ----

 

 

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Everaldo Barbosa

 

<@> Baixe: < Norman Malware Cleaner >

<@> Salve-o no desktop.

<@> Abra o arquivo e clique em Executar --> Accept.

<@> Clique em Add,para adicionar ou Remove,para remover unidades/setores à serem escaneados. ( C:\*.*,D:\*.*,E:\*.*,etc... )

<@> Clique em "Start scan" --> Aguarde!

<@> Terminando,poste o relatório,que estará no desktop. ( NFix_2009-xx-xx_yy-yy-yy.log ) <--

<><><><><><><><><><><><><><>

<@> Baixe: < Flash Disinfector >

<@> Salve-o,diretamente,no Disco Local-C.

<@> Conecte,na entrada USB,suas unidades removíveis!

<@> Dê um duplo clique em: Flash_Disinfector.exe

<@> Espere a conclusão!

<><><><><><><><><><><><><><>

<@> Clique com o botão direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.

<@> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok.

<@> Vá em Iniciar --> Executar --> Digite: cleanmgr --> Ok --> Aguarde!

<@> No Utilitário de limpeza de disco,marque todas as caixas e confirme!

<@> Terminando,vá à Restauração e,novamente,desmarque a caixa.

<@> Clique em Aplicar --> Ok.

<><><><><><><><><><><><><><>

<@> Faça uma verificação com o seu antivírus,no boot,e poste o relatório.

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam,

 

Segue log's abaixo:

 

Log do Norman Malware Cleaner:

 

Norman Malware Cleaner

Copyright © 1990 - 2009, Norman ASA. Built 2009/03/26 05:17:51

 

Norman Scanner Engine Version: 6.00.06

Nvcbin.def Version: 6.00.00, Date: 2009/03/26 05:17:51, Variants: 3045527

 

Scan started: 16/04/2009 23:47:04

 

Running pre-scan cleanup routine:

Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3

Logged on user: USER-B2A31EA60F\user

 

Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000

Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000

Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000

Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000

 

 

Scanning running processes and process memory...

 

Number of processes/threads found: 2138

Number of processes/threads scanned: 2138

Number of processes/threads not scanned: 0

Number of infected processes/threads terminated: 0

Total scanning time: 42s

 

 

Scanning file system...

 

Scanning: C:\*.*

 

C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\BackItUp_ImageTool\root.img/unknown0 (Error whilst scanning file: I/O Error (0x0022000A))

C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\BackItUp_ImageTool\root.img (Possible archive bomb)

 

C:\RECYCLER\S-1-5-21-2000478354-2052111302-839522115-1003\Dc25.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP55\A0026163.sys (Infected with W32/Agent.HHSF)

Deleted file

 

C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP59\A0026686.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

C:\Temp\setuppor.exe (Infected with W32/Smalltroj.MRLH)

Deleted file

 

C:\ToolBar SD\pv.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

Scanning: c:\System Volume Information\*.*

 

c:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP59\A0026687.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

 

Running post-scan cleanup routine:

 

Number of files found: 1161165

Number of archives unpacked: 6693

Number of files scanned: 1161126

Number of files not scanned: 39

Number of files skipped due to exclude list: 0

Number of infected files found: 7

Number of infected files repaired/deleted: 6

Number of infections removed: 6

Total scanning time: 1h 17m 26s

 

 

 

Log do HijackThis:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:05, on 2009-04-17

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Unable to get Internet Explorer version!

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Vtune\TBPanel.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\WinZip\WZQKPICK.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashSimpl.exe

C:\WINDOWS\ServicePackFiles\i386\iexplore.exe

C:\Arquivos de programas\Windows Live Toolbar\msn_sl.exe

C:\Hijack\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.odia.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Gainward] C:\Arquivos de programas\Vtune\TBPanel.exe /A

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "C:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [WatchDog] C:\Arquivos de programas\mobile PhoneTools\WatchDog.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Arquivos de programas\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: is-5V1I6.lnk = C:\Arquivos de programas\Virus Removal Tool\is-5V1I6\startup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{6567EB37-AC23-4A19-BDDE-9FB90E24C01E}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - c:\arquivos de programas\arquivos comuns\logishrd\lvmvfm\LVPrcSrv.exe (file missing)

O23 - Service: LVSrvLauncher - Unknown owner - C:\Arquivos de programas\Arquivos comuns\LogiShrd\SrvLnch\SrvLnch.exe (file missing)

O23 - Service: MySQL - Unknown owner - C:\Arquivos.exe (file missing)

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

 

--

End of file - 12015 bytes

 

 

Dúvida: O que você quis dizer em fazer uma verificação com o meu antivírus,no boot??

 

Desculpe a demora, estive trabalhando até tarde no trabalho.

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Everaldo Barbosa

 

Dúvida: O que você quis dizer em fazer uma verificação com o meu antivírus,no boot??

<!> Nas configurações do Avast,ele pode escanear o PC,durante o boot.

<><><><><><><><><><>

<@> Faça um escaneamento,online,em Eset.

<@> Utilize o navegador Internet Explorer.

<@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar.

<@> Marque a caixa: "YES, I accept the Terms of Use" --> Start.

<@> Aceite a instalação do ActiveX e,ao terminar,salve e poste o relatório. ( C:\Arquivos de programas\EsetOnlineScanner\log )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite DigRam,

 

Eu não consegui encontrar onde se colocar p/ escanear quando enquanto se faz o boot no avast!!

 

 

Segue o log do Eset

 

 

# version=4

# OnlineScanner.ocx=1.0.0.635

# OnlineScannerDLLA.dll=1, 0, 0, 79

# OnlineScannerDLLW.dll=1, 0, 0, 78

# OnlineScannerUninstaller.exe=1, 0, 0, 49

# vers_standard_module=4018 (20090418)

# vers_arch_module=1.064 (20080214)

# vers_adv_heur_module=1.066 (20070917)

# EOSSerial=024239dce1dc7641be0dea0b0cbb6675

# end=finished

# remove_checked=false

# unwanted_checked=true

# utc_time=2009-04-18 03:30:33

# local_time=2009-04-18 12:30:33 (-0300, Hora oficial do Brasil)

# country="Brazil"

# osver=5.1.2600 NT Service Pack 3

# scanned=1401265

# found=6

# scan_time=16673

C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe Win32/Virut.NBM virus 00000000000000000000000000000000

C:\WINDOWS\$NtServicePackUninstall$\eudcedit.exe Win32/Virut.NBM virus 00000000000000000000000000000000

C:\WINDOWS\$NtServicePackUninstall$\fxsclnt.exe Win32/Virut.NBM virus 00000000000000000000000000000000

C:\WINDOWS\$NtServicePackUninstall$\mstsc.exe Win32/Virut.NBM virus 00000000000000000000000000000000

C:\WINDOWS\$NtServicePackUninstall$\nddeapir.exe Win32/Virut.NBM virus 00000000000000000000000000000000

C:\WINDOWS\$NtServicePackUninstall$\net.exe Win32/Virut.NBM virus 00000000000000000000000000000000

 

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Everaldo Barbosa

 

Eu não consegui encontrar onde se colocar p/ escanear quando enquanto se faz o boot no avast!!

<!> Não se preocupe,pois ao final das indicações de ferramentas,será feito e instruído esse agendamento.

<><><><><><><><><><><><>

<@> Baixe: < McAfee Avert Stinger >

<@> Salve-o no Desktop!

<@> Clique em Add,e adicione as demais unidades de disco que possua. ( Por exemplo, a unidade D:\ ).

<@> Em seguida,clique em "Scan now".

<@> Aguarde o término do Scan.

<><><><><><><><><><><><>

<@> Baixe: < Malicious Software Removal Tool >

<@> Instale-a e execute-a!

<><><><><><><><><><><><>

<@> Delete: DrWebCureIt <--

<@> Baixe uma nova versão!

<@> Execute o DrWebCureIt.exe e poste seu relatório. ( DrWeb.csv ) <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite DigRam

 

 

Segue log do DrWebCureIt:

 

 

game.exe C:\Arquivos de programas\KAIZEN Games\Priston Tale Provavelmente DLOADER.Trojan

XTrapVa.dll C:\Arquivos de programas\KAIZEN Games\Priston Tale\XTrap Provavelmente DLOADER.Trojan

PristonTale4131.exe\data014 C:\Documents and Settings\Mirian e Ana Clara\Meus documentos\PristonTale4131.exe Provavelmente DLOADER.Trojan

PristonTale4131.exe C:\Documents and Settings\Mirian e Ana Clara\Meus documentos O arquivo contém objectos infectados Movido.

PristonTale4131.exe\data014 C:\Documents and Settings\user\Configurações locais\Dados de aplicativos\Microsoft\Messenger\matheus-_lessa@hotmail.com\Sharing Provavelmente DLOADER.Trojan

PristonTale4131.exe C:\Documents and Settings\user\Configurações locais\Dados de aplicativos\Microsoft\Messenger\matheus-_lessa@hotmail.com\Sharing O arquivo contém objectos infectados Movido.

A0027906.exe\data014 C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP64\A0027906.exe Provavelmente DLOADER.Trojan

A0027906.exe C:\System Volume Information\_restore{046634D3-0E7E-489B-84B3-6B05ADF42BB7}\RP64 O arquivo contém objectos infectados Movido.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Everaldo Barbosa

 

<@> Baixe: < a-squared Free 4.0 >

 

<!> Link Opcional: < a2ppf_banner.jpg >

 

<@> Salve-o em Arquivos de programas.

<@> Abra o programa e clique em: Atualizar agora --> Aguarde!

<@> Terminando,clique em: "Scan PC"

<@> Escolha a opção: "A fundo" --> Clique,à seguir,em "Analisar".

<@> Terminando,marque as caixinhas dos ítens encontrados e clique em "Enviar marcados à Quarentena".

<@> Salve e poste o relatório desta verificação. ( a2scan_xxyy09-xxxxxx.txt ) <--

<><><><><><><><><><><>

<@> Agende o scan,do Avast,pelo boot.

 

<1> Clique direito no ícone: < avast.gif >

<2> Selecione: "Iniciar o Antivirus Avast!" --> Aguarde!

<3> Clique esquerdo na seta,virada para cima,que fica no canto superior-esquerdo na tela do Avast.

<4> Escolha: "Agendar escaneamento no boot..."

<5> Selecione: "Escanear todos os discos locais" --> "Escanear o conteúdo dos arquivos" --> "Opções avançadas".

<6> Em "Solicitar ação",clique em "Agendar".

<7> Confirme a reinicialização do computador! ( Reboot )

<8> Ao reiniciar o computador,dar-se-á início ao scan do Avast.

<@> Ps: Envie à quarentena,tudo o que for detectado.

<@> Poste o relatório desse scan. <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite DigRam,

 

Segue log do Avast:

 

25/04/2009 13:14

Escaneamento de todos os discos locais

 

Arquivo C:\Documents and Settings\user\Desktop\musicas\(backstreetboys) - greatest hits.mp3\Backstreet Boys - Greatest Hits - Chapter One\14.More Than That.mp3 Erro 42126 {O arquivo RAR está corrompido.}

Número de pastas processadas: 9810

Número de arquivos verificados: 1586757

Número de arquivos infectados: 0

 

 

Segue log do a-squared:

 

a-squared Free - Versão 4.0

Última atualização 2009-04-25 08:41:54

 

Configurações da análise:

 

Objetos: Memória, Rastros, Cookies, C:\

Análise de arquivos: Ligado

Heurística: Desligado

Análise de ADS: Ligado

 

Início da análise: 2009-04-25 08:43:14

 

c:\arquivos de programas\axbx detectado: Trace.Directory.VirusKeeper 2009 Pro!A2

Value: HKEY_USERS\S-1-5-21-2000478354-2052111302-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Emule --> Order detectado: Trace.Registry.Emule 5.0!A2

Value: HKEY_CLASSES_ROOT\CLSID\{79731811-6B9A-4DF0-92CF-991C37D2BCED}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_CLASSES_ROOT\CLSID\{BEEB3409-33FB-493F-AD14-37A2D0329547}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_CLASSES_ROOT\CLSID\{FA525B35-1E10-4747-8CD2-4C837A6F014D}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79731811-6B9A-4DF0-92CF-991C37D2BCED}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEEB3409-33FB-493F-AD14-37A2D0329547}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FA525B35-1E10-4747-8CD2-4C837A6F014D}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Chat Watch 5.0!A2

Key: HKEY_USERS\S-1-5-21-2000478354-2052111302-839522115-1003\software\kazaa detectado: Trace.Registry.KaZaA!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run --> WatchDog detectado: Trace.Registry.WatchDog v8.5!A2

C:\Documents and Settings\user\Cookies\user@2o7[2].txt detectado: Trace.TrackingCookie.2o7!A2

C:\Documents and Settings\user\Cookies\user@adserver.dialhost.com[2].txt detectado: Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@adserver.mundopt[2].txt detectado: Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@adservingml[2].txt detectado: Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@atdmt[1].txt detectado: Trace.TrackingCookie.atdmt!A2

C:\Documents and Settings\user\Cookies\user@bs.serving-sys[1].txt detectado: Trace.TrackingCookie.bs.serving-sys!A2

C:\Documents and Settings\user\Cookies\user@casalemedia[1].txt detectado: Trace.TrackingCookie.casalemedia!A2

C:\Documents and Settings\user\Cookies\user@compredachina[2].txt detectado: Trace.TrackingCookie.com!A2

C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt detectado: Trace.TrackingCookie.doubleclick!A2

C:\Documents and Settings\user\Cookies\user@google.com[2].txt detectado: Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\user\Cookies\user@hitbox[2].txt detectado: Trace.TrackingCookie.hitbox!A2

C:\Documents and Settings\user\Cookies\user@ig.com[1].txt detectado: Trace.TrackingCookie.ig.com!A2

C:\Documents and Settings\user\Cookies\user@linkto.com[2].txt detectado: Trace.TrackingCookie.link!A2

C:\Documents and Settings\user\Cookies\user@media6degrees[1].txt detectado: Trace.TrackingCookie.media!A2

C:\Documents and Settings\user\Cookies\user@serving-sys[1].txt detectado: Trace.TrackingCookie.serving-sys!A2

C:\Documents and Settings\user\Cookies\user@specificclick[2].txt detectado: Trace.TrackingCookie.specificclick!A2

C:\Documents and Settings\user\Cookies\user@statcounter[2].txt detectado: Trace.TrackingCookie.statcounter!A2

C:\Documents and Settings\user\Cookies\user@zedo[1].txt detectado: Trace.TrackingCookie.zedo!A2

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zS18.tmp\setup.exe detectado: Backdoor.Win32.Rbot!IK

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zS9.tmp\setup.exe detectado: Backdoor.Win32.Rbot!IK

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zSA.tmp\setup.exe detectado: Backdoor.Win32.Rbot!IK

C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe detectado: Virus.Win32.Virtob!IK

C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe detectado: Virus.Win32.Virut!IK

C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe detectado: Virus.Win32.Virut.q!IK

C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe detectado: Exploit.Win32.IMG-WMF!IK

C:\WINDOWS\$NtServicePackUninstall$\explorer.exe detectado: Virus.Win32.Virut.q!IK

C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe detectado: Trojan.Win32.Banker!IK

C:\WINDOWS\$NtServicePackUninstall$\magnify.exe detectado: Virus.Win32.Virut!IK

C:\WINDOWS\$NtServicePackUninstall$\mmc.exe detectado: Virus.Win32.Virut!IK

C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe detectado: Virus.Win32.Virut.n!IK

C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe detectado: Trojan-Downloader.Win32.Banload!IK

C:\WINDOWS\$NtServicePackUninstall$\mqsvc.exe detectado: Backdoor.Win32.Frauder!IK

C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe detectado: Virus.Win32.Virtob!IK

 

Analisado

 

Arquivos: 841236

Objetos: 669656

Cookies: 217

Processos: 50

 

Encontrado

 

Arquivos: 15

Objetos: 10

Cookies: 20

Processos: 0

Chaves do registro: 0

 

Fim da análise: 2009-04-25 10:31:30

Duração da análise: 1:48:16

 

C:\WINDOWS\$NtServicePackUninstall$\mqsvc.exe Em quarentena Backdoor.Win32.Frauder!IK

C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe Em quarentena Trojan-Downloader.Win32.Banload!IK

C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe Em quarentena Virus.Win32.Virut.n!IK

C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe Em quarentena Trojan.Win32.Banker!IK

C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe Em quarentena Exploit.Win32.IMG-WMF!IK

C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe Em quarentena Virus.Win32.Virut.q!IK

C:\WINDOWS\$NtServicePackUninstall$\explorer.exe Em quarentena Virus.Win32.Virut.q!IK

C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe Em quarentena Virus.Win32.Virut!IK

C:\WINDOWS\$NtServicePackUninstall$\magnify.exe Em quarentena Virus.Win32.Virut!IK

C:\WINDOWS\$NtServicePackUninstall$\mmc.exe Em quarentena Virus.Win32.Virut!IK

C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe Em quarentena Virus.Win32.Virtob!IK

C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe Em quarentena Virus.Win32.Virtob!IK

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zS18.tmp\setup.exe Em quarentena Backdoor.Win32.Rbot!IK

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zS9.tmp\setup.exe Em quarentena Backdoor.Win32.Rbot!IK

C:\Documents and Settings\Matheus e Filipe\Configurações locais\Temp\7zSA.tmp\setup.exe Em quarentena Backdoor.Win32.Rbot!IK

C:\Documents and Settings\user\Cookies\user@zedo[1].txt Em quarentena Trace.TrackingCookie.zedo!A2

C:\Documents and Settings\user\Cookies\user@statcounter[2].txt Em quarentena Trace.TrackingCookie.statcounter!A2

C:\Documents and Settings\user\Cookies\user@specificclick[2].txt Em quarentena Trace.TrackingCookie.specificclick!A2

C:\Documents and Settings\user\Cookies\user@serving-sys[1].txt Em quarentena Trace.TrackingCookie.serving-sys!A2

C:\Documents and Settings\user\Cookies\user@media6degrees[1].txt Em quarentena Trace.TrackingCookie.media!A2

C:\Documents and Settings\user\Cookies\user@linkto.com[2].txt Em quarentena Trace.TrackingCookie.link!A2

C:\Documents and Settings\user\Cookies\user@ig.com[1].txt Em quarentena Trace.TrackingCookie.ig.com!A2

C:\Documents and Settings\user\Cookies\user@hitbox[2].txt Em quarentena Trace.TrackingCookie.hitbox!A2

C:\Documents and Settings\user\Cookies\user@google.com[2].txt Em quarentena Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt Em quarentena Trace.TrackingCookie.doubleclick!A2

C:\Documents and Settings\user\Cookies\user@compredachina[2].txt Em quarentena Trace.TrackingCookie.com!A2

C:\Documents and Settings\user\Cookies\user@casalemedia[1].txt Em quarentena Trace.TrackingCookie.casalemedia!A2

C:\Documents and Settings\user\Cookies\user@bs.serving-sys[1].txt Em quarentena Trace.TrackingCookie.bs.serving-sys!A2

C:\Documents and Settings\user\Cookies\user@atdmt[1].txt Em quarentena Trace.TrackingCookie.atdmt!A2

C:\Documents and Settings\user\Cookies\user@adserver.dialhost.com[2].txt Em quarentena Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@adserver.mundopt[2].txt Em quarentena Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@adservingml[2].txt Em quarentena Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\user\Cookies\user@2o7[2].txt Em quarentena Trace.TrackingCookie.2o7!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run --> WatchDog Em quarentena Trace.Registry.WatchDog v8.5!A2

Key: HKEY_USERS\S-1-5-21-2000478354-2052111302-839522115-1003\software\kazaa Em quarentena Trace.Registry.KaZaA!A2

Value: HKEY_CLASSES_ROOT\CLSID\{79731811-6B9A-4DF0-92CF-991C37D2BCED}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_CLASSES_ROOT\CLSID\{BEEB3409-33FB-493F-AD14-37A2D0329547}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_CLASSES_ROOT\CLSID\{FA525B35-1E10-4747-8CD2-4C837A6F014D}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79731811-6B9A-4DF0-92CF-991C37D2BCED}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEEB3409-33FB-493F-AD14-37A2D0329547}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FA525B35-1E10-4747-8CD2-4C837A6F014D}\InprocServer32 --> ThreadingModel Em quarentena Trace.Registry.Chat Watch 5.0!A2

Value: HKEY_USERS\S-1-5-21-2000478354-2052111302-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Emule --> Order Em quarentena Trace.Registry.Emule 5.0!A2

c:\arquivos de programas\axbx Em quarentena Trace.Directory.VirusKeeper 2009 Pro!A2

 

Em quarentena

 

Arquivos: 15

Objetos: 10

Cookies: 18

 

 

Abraços,

 

Everaldo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Everaldo Barbosa

 

<@> Baixe:

 

<1> < Kaspersky Kido Killer 3.4.3 >

<2> < F-Downadup Removal Tool > ( ...by F-Secure )

<3> < Downadup.Gen >

<4> < W32.Downadup Removal Tool > ( ...by Symantec )

<5> < MSRT by Microsoft - Malicious Software Removal Tool (KB890830) >

 

<@> Ps: Antes de utilizar as ferramentas,procure instalar esta correção:

 

< MS08-067 >

 

<@> Desabilite:

 

<1> Qualquer conecção com a internet,ou rede.

<2> Auto-executar.

 

<@> Vá em Iniciar --> Executar --> Digite: gpedit.msc

<@> Diretiva Computador Local --> Configurações do Computador --> Modelos Administrativos --> Sistema.

<@> No Painel direito,dê um duplo-clique em Desativar Auto-Executar.

<@> Marque: Ativado --> Selecione: Todas as unidades --> Ok.

<@> Assim,você não será infectado ao conectar o drive infectado.

<@> Recomendo a formatação de suas mídias removíveis.

<3> Restauração do Sistema:

 

<@> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.

<@> Marque: Desativar Restauração do Sistema --> Aplicar --> Aguarde! --> Ok.

<@> Depois,desmarque novamente! --> Aplicar --> Aguarde! --> Ok.

<@> Para maiores detalhes,leia o Tutorial: < Link >

<@> Ps: Rode as ferramentas,tendo atributos administrativos.

<@> Retire-as do zip,ao executá-las!

<><><><><><><><><><><>

<@> Baixe: < PureRa 1.3 > ( ...by RaProducts' )

<@> Salve-o no desktop! <-- Tire-o do zip!

<@> Execute: PureRa.exe --> Clique em Clean.

<@> Á direita,marque a opção: "Check All"

<@> Clique no botão Clean Selected --> Aguarde!

<@> Terminando ( Finished ),clique em Exit.

<><><><><><><><><><><>

<@> Vá a este link,e baixe: < Malwarebytes >

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<><><><><><><><><><><>

<@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Noite DigRam,

 

Eu não consegui baixar o wnadup.Gen pelo link que me mandou, deu erro de "page not found", nem mesmo indo pelo google...achei-o num blog conforme o endereço abaixo:

http://www.bitdefender.com/VIRUS-1000462-e...wnadup.Gen.html

Será que posso utilizá-lo?

 

 

Abraços,

 

 

Everaldo.

<><><><><><><><><>

Opa! Everaldo Barbosa

 

<!> Sim! Pois,pelo visto,trata-se da mesma ferramenta. ( 32bits ) <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.