Charlle 0 Denunciar post Postado Junho 24, 2009 E aí galera, to precisando de uma grande ajuda! Utilizo Wireless- D-Link G Adsl2+ conectado a velox. Meu IE parou de abrir paginas juntamente com o msn parando de funcionar, embora mozilla e google Chrome estejam funcionando! Já googlei muito. Numa dessas descobri que em Opções de internet/conexões/configurações de lan quando desabilito "usar script de configuração automática" o IE dá um pico de leve e para novamente. Quando olho nas configurações Lan a opção "usar script de configuração automática" foi remarcada sem que eu fisesse nada. Com o endereço de http://localhost:9000/proxy.pac. Visto que não estou conectado a nenhuma rede. Tambem descobri que o Internet explorer só funciona no Modo de Segurança. Ai vai o log HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:59:34, on 23/6/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\agrsmsvc.exe C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9000/proxy.pac R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Arquivos de programas\Bywifi\bywifiie.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: GhostStartService - Symantec Corporation - C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 5075 bytes Se alguem puder me ajudar! Desde jah agradeço! Compartilhar este post Link para o post Compartilhar em outros sites
Charlle 0 Denunciar post Postado Junho 24, 2009 Ai vai tbem o log do combofix ComboFix 09-06-22.0E - Administrador 23/06/2009 23:16.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.2038.1545 [GMT -3:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))) . 2009-06-22 16:07 . 2009-04-30 21:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-22 16:07 . 2009-04-30 21:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-22 10:13 . 2009-06-22 10:13 -------- d--h--w- c:\windows\system32\GroupPolicy 2009-06-22 08:20 . 2008-10-16 17:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-06-22 01:59 . 2009-04-06 18:32 15504 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-22 01:59 . 2009-04-06 18:32 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-22 01:59 . 2009-06-22 01:59 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-06-22 01:56 . 2009-06-23 23:54 117760 ----a-w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-22 01:54 . 2009-06-22 01:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\arquivos de programas\SUPERAntiSpyware 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2009-06-22 01:38 . 2009-06-22 01:38 -------- d-----w- c:\arquivos de programas\CCleaner 2009-06-22 01:33 . 2009-06-22 01:33 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-22 01:27 . 2008-04-13 22:20 81920 ------w- c:\windows\system32\ieencode.dll 2009-06-22 01:27 . 2008-04-13 22:19 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2009-06-21 15:07 . 2009-06-21 15:07 -------- d-----w- c:\arquivos de programas\Trend Micro 2009-06-20 22:36 . 2009-06-20 22:39 -------- dc-h--w- c:\windows\ie8 2009-06-20 22:15 . 2009-06-20 22:15 0 ----a-w- c:\windows\nsreg.dat 2009-06-20 21:49 . 2009-06-20 21:49 -------- d-----w- c:\arquivos de programas\SopCast 2009-06-20 19:18 . 2009-06-20 19:18 -------- d-----w- c:\arquivos de programas\Rockstar Games 2009-06-19 21:04 . 2009-06-19 21:04 -------- d-----w- c:\arquivos de programas\Aquiris Olympikus 2009-06-19 04:27 . 2009-03-24 19:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-06-16 23:32 . 2008-06-19 20:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys 2009-06-16 23:32 . 2009-06-16 23:32 -------- d-----w- c:\arquivos de programas\Panda Security 2009-06-15 20:19 . 2009-06-15 21:07 -------- d-----w- c:\arquivos de programas\Project64 v1.5 2009-06-15 01:22 . 2009-06-15 01:22 -------- d-----w- c:\arquivos de programas\SomePDF 2009-06-14 18:58 . 2009-06-14 18:58 -------- d-----w- c:\arquivos de programas\VDOWNLOADER 2009-06-04 20:46 . 2009-06-04 20:46 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ESET 2009-06-02 21:00 . 2009-06-02 21:00 -------- d-----w- c:\arquivos de programas\MSXML 4.0 2009-06-01 22:04 . 2009-06-01 22:04 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\DivX 2009-06-01 22:01 . 2009-06-01 22:04 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Pinnacle VideoSpin 2009-06-01 22:01 . 2009-06-01 22:01 -------- d-----w- c:\arquivos de programas\Pinnacle 2009-06-01 22:01 . 2009-06-01 22:01 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Yahoo! 2009-06-01 21:59 . 2009-06-01 21:59 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Pinnacle 2009-05-31 20:26 . 2009-05-31 20:26 -------- d-----w- c:\windows\Logs 2009-05-31 00:45 . 2009-05-31 00:45 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-05-27 16:08 . 2009-05-27 16:08 -------- d-----w- c:\arquivos de programas\MSECache . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-24 00:21 . 2008-12-11 15:16 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Orbit 2009-06-23 23:27 . 2008-04-14 11:00 77144 ----a-w- c:\windows\system32\perfc016.dat 2009-06-23 23:27 . 2008-04-14 11:00 467160 ----a-w- c:\windows\system32\perfh016.dat 2009-06-23 20:47 . 2009-05-18 14:23 -------- d-----w- c:\arquivos de programas\Yahoo! 2009-06-22 01:50 . 2009-04-28 23:50 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP 2009-06-20 19:18 . 2008-09-16 20:01 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information 2009-06-02 21:48 . 2009-03-24 01:28 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Any Video Converter 2009-06-01 22:12 . 2009-03-24 01:28 -------- d-----w- c:\arquivos de programas\Any Video Converter 2009-06-01 20:36 . 2009-03-17 23:27 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Skype 2009-06-01 20:35 . 2008-12-06 01:07 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\skypePM 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ARPPRODUCTICON.exe 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-05-21 14:14 . 2008-12-11 15:16 -------- d-----w- c:\arquivos de programas\Orbitdownloader 2009-05-18 14:23 . 2009-05-18 14:23 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Yahoo! 2009-05-18 13:36 . 2009-04-29 00:09 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\IObit 2009-05-17 23:53 . 2009-03-26 22:57 -------- d-----w- c:\arquivos de programas\Bywifi 2009-05-17 23:02 . 2009-05-17 23:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\EarMaster 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Borland Shared 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Sisvar 2009-05-13 05:03 . 2008-05-27 21:38 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:33 . 2008-04-14 11:00 347136 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 00:09 . 2009-04-29 00:09 -------- d-----w- c:\arquivos de programas\IObit 2009-04-29 00:08 . 2008-12-12 15:38 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Lavasoft 2009-04-29 00:08 . 2008-09-16 20:10 -------- d-----w- c:\arquivos de programas\Lavasoft 2009-04-27 23:00 . 2009-04-27 23:00 -------- d-----w- c:\arquivos de programas\Unity 2009-04-26 16:49 . 2009-04-26 16:49 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-04-26 16:49 . 2008-09-16 18:18 -------- d-----w- c:\arquivos de programas\Java 2009-04-26 16:48 . 2009-04-26 16:48 152576 ----a-w- c:\documents and settings\Administrador\Dados de aplicativos\Sun\Java\jre1.6.0_13\lzma.dll 2009-04-19 19:50 . 2008-04-14 11:00 1847296 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:53 . 2008-04-14 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\arquivos de programas\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 15:05 356352 ----a-w- c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^BTTray.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\BTTray.lnk backup=c:\windows\pss\BTTray.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Orbit.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Orbit.lnk backup=c:\windows\pss\Orbit.lnkCommon Startup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "c:\\Arquivos de programas\\Bywifi\\bywifi.exe"= "c:\\CS1.6 pod-Bot\\hl.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\Pinnacle\\VideoSpin\\Programs\\RM.exe"= "c:\\Arquivos de programas\\Pinnacle\\VideoSpin\\Programs\\umi.exe"= "c:\\Arquivos de programas\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [16/6/2009 20:32 28544] R1 GhPciScan;GhostPciScanner;c:\arquivos de programas\Symantec\Norton Ghost 2003\GhPciScan.sys [28/5/2003 19:01 5632] R1 SASDIFSV;SASDIFSV;c:\arquivos de programas\SUPERAntiSpyware\sasdifsv.sys [26/5/2009 10:05 9968] R1 SASKUTIL;SASKUTIL;c:\arquivos de programas\SUPERAntiSpyware\SASKUTIL.SYS [26/5/2009 10:05 72944] R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\drivers\hidshim.sys [16/9/2008 16:55 5632] R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\drivers\winbondhidcir.sys [16/9/2008 16:55 21504] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?] S3 CrystalSysInfo;CrystalSysInfo;\??\c:\arquivos de programas\MediaCoder\SysInfo.sys --> c:\arquivos de programas\MediaCoder\SysInfo.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 SASENUM;SASENUM;c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [26/5/2009 10:05 7408] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67EFG7H6-8IJL-56YT-KLH4-76WE8D3RAM87}] c:\system\S-3-7-89-2225458569-9856321456-454423558-8896\\Driver.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\arquivos de programas\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uInternet Settings,ProxyOverride = local FF - ProfilePath - ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . . ------- Associação de arquivos/ficheiros ------- . inifile=%SystemRoot%\System32\NOTEPAD.EXE %1" . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-23 23:18 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-861567501-879983540-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,6b,26,7d,96,9b, b7,5a,a2,e2,63,26,f1,3f,c8,ff,68,92,49,9f,94,20,f0,3c,a4,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b0,e5,6d,c3,37, 4d,5a,7f,6a,9c,d6,61,af,45,84,18,3c,60,7b,fb,eb,2e,83,22,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,88,8b,fc,0f,f7, d6,70,a0,ff,7c,85,e0,43,d4,0e,fe,81,70,34,89,3c,29,fd,4d,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,17,e6,b3,34,96, 48,ce,63,86,8c,21,01,be,91,eb,e7,96,34,c2,cf,c6,fe,73,05,86,8c,21,01,be,91,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,b1,1e,a0,86,cb, 84,aa,45,f5,1d,4d,73,a8,13,5c,05,20,c7,0d,7a,43,dd,d3,5f,f5,1d,4d,73,a8,13,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,c8,48,b9,47,38, 93,c9,0f,df,20,58,62,78,6b,cf,c8,b1,76,c9,de,e6,68,10,40,df,20,58,62,78,6b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,a4,43,19,15,ec, 81,a5,d5,fb,a7,78,e6,12,2f,9a,ea,9d,26,17,46,7a,71,33,c9,fb,a7,78,e6,12,2f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9e,31,89,0e,3f, 1e,76,b7,01,3a,48,fc,e8,04,4a,f1,86,d9,6a,fb,ea,27,68,e6,01,3a,48,fc,e8,04,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,57,22,19,ba,cf, f7,ff,46,f6,0f,4e,58,98,5b,89,c9,c8,96,01,c8,c3,47,25,74,f6,0f,4e,58,98,5b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,1f,12,e8,bb,36, b2,fd,45,3d,ce,ea,26,2d,45,aa,78,f9,97,bb,7b,51,ba,a2,a2,3d,ce,ea,26,2d,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,94,6b,10,65,4a, a2,d2,c3,2a,b7,cc,b5,b9,7f,41,e7,c0,db,50,04,f0,ef,9a,ab,2a,b7,cc,b5,b9,7f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,c9,04,d7,d3,76, 07,cb,52,6c,43,2d,1e,aa,22,2f,9c,1e,97,22,d5,04,4c,ad,cb,6c,43,2d,1e,aa,22,\ . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(748) c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(204) c:\windows\system32\WININET.dll c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroSearchBar.dll c:\arquivos de programas\Arquivos comuns\Ahead\Lib\MFC71U.DLL c:\arquivos de programas\Arquivos comuns\Ahead\Lib\BCGCBPRO800u.dll c:\arquiv~1\WINDOW~2\wmpband.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Tempo para conclusão: 2009-06-24 23:19 ComboFix-quarantined-files.txt 2009-06-24 02:19 ComboFix2.txt 2009-06-20 00:10 ComboFix3.txt 2009-06-15 17:14 ComboFix4.txt 2009-05-29 21:22 ComboFix5.txt 2009-06-24 02:13 Pré-execução: 11 pasta(s) 70.936.702.976 bytes disponíveis Pós execução: 11 pasta(s) 70.954.037.248 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 266 --- E O F --- 2009-06-22 16:13 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 24, 2009 Bom Dia! Charlle <!> O problema pode estar relacionado à DRIVER.EXE. <-- Link! <><><><><><><><><><><> <@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas. <@> Salve-o,no Desktop,com o nome: CFScript.txt Files::c:\system\S-3-7-89-2225458569-9856321456-454423558-8896\\Driver.exe c:\system\s-3-7-89-2225458569-9856321456-454423558-8896\desktop.ini c:\windows\system32\GameMon.des Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67EFG7H6-8IJL-56YT-KLH4-76WE8D3RAM87}] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] DirLook:: c:\windows\system32\GroupPolicy Driver:: "npggsvc" <@> Ps: Não utilizem este script em outra máquina! <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix. <@> Ps: Faça o arraste,até surgir essa solicitação! ( janela ) <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Charlle 0 Denunciar post Postado Junho 25, 2009 Grande Dig Ram! Muito obrigado por atender meu chamado. Aconteceu algo inesperado, após passar o Combofix ontem o IE voltou a funcionar, não entendi pois já havia rodado o combofix antes e não obtive resultados! O que me diz? Mesmo assim devo fazer o que me disse? Desde já lhe agradeço muito! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 25, 2009 Grande Dig Ram! Muito obrigado por atender meu chamado. Aconteceu algo inesperado, após passar o Combofix ontem o IE voltou a funcionar, não entendi pois já havia rodado o combofix antes e não obtive resultados! O que me diz? Mesmo assim devo fazer o que me disse? Desde já lhe agradeço muito! <><><><><><><><> Opa! Charlle <!> Se voçê possui esse novo relatório,da ferramenta,poste-o para vermos o que aconteceu. <!> Provavelmente teremos como cabeçalho: <1> ComboFix xx-yy-zz.0E - Administrador xx/06/2009 xx:xx.2 - NTFSx86 <-- Segunda execução! <2> ComboFix 09-06-22.0E - Administrador 23/06/2009 23:16.1 - NTFSx86 <-- Para este,não houve fix pela ferramenta,de algum malware! ( 1ª execução ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Charlle 0 Denunciar post Postado Julho 2, 2009 Dig Ram, me desculpe pela demora, mas é que o bicho tá pegando na facul e não tava tendo tempo! Mas o que aconteceu foi que o IE voltou a funcionar a partir do scan com combofix que te mandei o log anteriormente, não entendi porque. Mas estou mandando outros logs Para que você possa me dizer se ainda teria que fazer os passos que me disse antes. desde já Obrigado Abraço ComboFix 09-07-01.04 - Administrador 02/07/2009 13:20.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.2038.1476 [GMT -3:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\b5b8.msi . (((((((((((((((( Arquivos/Ficheiros criados de 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))) . 2009-06-24 14:47 . 2009-06-24 14:47 -------- d-----w- C:\Intel 2009-06-24 03:16 . 2009-06-24 03:17 -------- d-----w- c:\arquivos de programas\Google 2009-06-24 02:31 . 2009-03-30 13:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-06-24 02:31 . 2009-02-13 15:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2009-06-24 02:31 . 2009-02-13 15:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2009-06-24 02:31 . 2009-06-24 02:31 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira 2009-06-24 02:31 . 2009-06-24 02:31 -------- d-----w- c:\arquivos de programas\Avira 2009-06-22 16:07 . 2009-04-30 21:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-22 16:07 . 2009-04-30 21:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-22 10:13 . 2009-06-22 10:13 -------- d--h--w- c:\windows\system32\GroupPolicy 2009-06-22 08:20 . 2008-10-16 17:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-06-22 01:59 . 2009-04-06 18:32 15504 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-22 01:59 . 2009-04-06 18:32 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-22 01:59 . 2009-06-22 01:59 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-06-22 01:56 . 2009-07-02 15:11 117760 ----a-w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-22 01:54 . 2009-06-22 01:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-24 02:41 -------- d-----w- c:\arquivos de programas\SUPERAntiSpyware 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2009-06-22 01:38 . 2009-06-22 01:38 -------- d-----w- c:\arquivos de programas\CCleaner 2009-06-22 01:33 . 2009-06-22 01:33 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-22 01:27 . 2008-04-13 22:20 81920 ------w- c:\windows\system32\ieencode.dll 2009-06-22 01:27 . 2008-04-13 22:19 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2009-06-21 15:07 . 2009-06-21 15:07 -------- d-----w- c:\arquivos de programas\Trend Micro 2009-06-20 22:36 . 2009-06-20 22:39 -------- dc-h--w- c:\windows\ie8 2009-06-20 22:15 . 2009-06-20 22:15 0 ----a-w- c:\windows\nsreg.dat 2009-06-20 21:49 . 2009-06-20 21:49 -------- d-----w- c:\arquivos de programas\SopCast 2009-06-20 19:18 . 2009-06-20 19:18 -------- d-----w- c:\arquivos de programas\Rockstar Games 2009-06-19 21:04 . 2009-06-19 21:04 -------- d-----w- c:\arquivos de programas\Aquiris Olympikus 2009-06-19 04:27 . 2009-03-24 19:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-06-16 23:32 . 2008-06-19 20:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys 2009-06-16 23:32 . 2009-06-16 23:32 -------- d-----w- c:\arquivos de programas\Panda Security 2009-06-15 20:19 . 2009-06-15 21:07 -------- d-----w- c:\arquivos de programas\Project64 v1.5 2009-06-15 01:22 . 2009-06-15 01:22 -------- d-----w- c:\arquivos de programas\SomePDF 2009-06-14 18:58 . 2009-06-14 18:58 -------- d-----w- c:\arquivos de programas\VDOWNLOADER 2009-06-04 20:46 . 2009-06-04 20:46 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ESET 2009-06-02 21:00 . 2009-06-02 21:00 -------- d-----w- c:\arquivos de programas\MSXML 4.0 . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 15:11 . 2008-12-11 15:16 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Orbit 2009-06-25 15:48 . 2009-06-01 22:01 -------- d-----w- c:\arquivos de programas\Pinnacle 2009-06-24 14:23 . 2009-03-26 22:57 -------- d-----w- c:\arquivos de programas\Bywifi 2009-06-23 23:27 . 2008-04-14 11:00 77144 ----a-w- c:\windows\system32\perfc016.dat 2009-06-23 23:27 . 2008-04-14 11:00 467160 ----a-w- c:\windows\system32\perfh016.dat 2009-06-23 20:47 . 2009-05-18 14:23 -------- d-----w- c:\arquivos de programas\Yahoo! 2009-06-22 01:50 . 2009-04-28 23:50 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP 2009-06-20 19:18 . 2008-09-16 20:01 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information 2009-06-02 21:48 . 2009-03-24 01:28 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Any Video Converter 2009-06-01 22:12 . 2009-03-24 01:28 -------- d-----w- c:\arquivos de programas\Any Video Converter 2009-06-01 22:04 . 2009-06-01 22:04 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\DivX 2009-06-01 21:59 . 2009-06-01 21:59 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Pinnacle 2009-06-01 20:36 . 2009-03-17 23:27 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Skype 2009-06-01 20:35 . 2008-12-06 01:07 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\skypePM 2009-05-27 16:08 . 2009-05-27 16:08 -------- d-----w- c:\arquivos de programas\MSECache 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ARPPRODUCTICON.exe 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-05-21 14:14 . 2008-12-11 15:16 -------- d-----w- c:\arquivos de programas\Orbitdownloader 2009-05-18 14:23 . 2009-05-18 14:23 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Yahoo! 2009-05-18 13:36 . 2009-04-29 00:09 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\IObit 2009-05-17 23:02 . 2009-05-17 23:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\EarMaster 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Borland Shared 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Sisvar 2009-05-13 05:03 . 2008-05-27 21:38 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:33 . 2008-04-14 11:00 347136 ----a-w- c:\windows\system32\localspl.dll 2009-04-26 16:49 . 2009-04-26 16:49 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-04-19 19:50 . 2008-04-14 11:00 1847296 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:53 . 2008-04-14 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( SnapShot@2009-06-24_02.18.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-02 15:10 . 2009-07-02 15:10 16384 c:\windows\temp\Perflib_Perfdata_cc.dat + 2009-06-24 02:31 . 2009-06-24 02:40 28520 c:\windows\system32\drivers\ssmdrv.sys + 2008-02-28 19:35 . 2008-02-28 19:35 51712 c:\windows\Installer\cb617e.msp + 2008-02-28 19:40 . 2008-02-28 19:40 25088 c:\windows\Installer\cb617a.msp + 2008-12-17 17:57 . 2008-12-17 17:57 81408 c:\windows\Installer\cb6167.msi + 2007-11-08 01:28 . 2007-11-08 01:28 22016 c:\windows\Installer\c9e381.msp + 2007-11-08 01:32 . 2007-11-08 01:32 74240 c:\windows\Installer\c9e37d.msp + 2007-11-08 01:21 . 2007-11-08 01:21 24576 c:\windows\Installer\c9e37a.msp + 2008-12-17 17:54 . 2008-12-17 17:54 86528 c:\windows\Installer\c7b1b4.msi + 2009-06-24 03:16 . 2009-06-24 03:16 24064 c:\windows\Installer\25b739.msi + 2005-11-15 19:42 . 2005-11-15 19:42 73216 c:\windows\Installer\1f52259.msp + 2008-09-16 15:05 . 2009-06-26 16:41 138848 c:\windows\system32\FNTCACHE.DAT + 2008-12-17 17:56 . 2008-12-17 17:56 634368 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\vs_setup.msi + 2008-02-28 21:36 . 2008-02-28 21:36 432128 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - ptb\vs_setup.msi + 2008-11-25 00:09 . 2008-11-25 00:09 289792 c:\windows\Installer\e37f.msi + 2008-12-17 17:58 . 2008-12-17 17:58 428032 c:\windows\Installer\cb6186.msi + 2008-02-28 19:32 . 2008-02-28 19:32 307712 c:\windows\Installer\cb6180.msp + 2008-02-28 19:23 . 2008-02-28 19:23 164864 c:\windows\Installer\cb617f.msp + 2008-02-28 19:18 . 2008-02-28 19:18 711680 c:\windows\Installer\cb617d.msp + 2008-02-28 19:17 . 2008-02-28 19:17 117760 c:\windows\Installer\cb617c.msp + 2008-02-28 19:28 . 2008-02-28 19:28 121344 c:\windows\Installer\cb617b.msp + 2008-02-28 18:36 . 2008-02-28 18:36 352256 c:\windows\Installer\cb616c.msp + 2008-02-28 18:47 . 2008-02-28 18:47 565248 c:\windows\Installer\cb616b.msp + 2008-02-28 18:32 . 2008-02-28 18:32 248320 c:\windows\Installer\cb616a.msp + 2008-02-28 18:43 . 2008-02-28 18:43 355840 c:\windows\Installer\cb6169.msp + 2008-02-28 18:40 . 2008-02-28 18:40 708608 c:\windows\Installer\cb6168.msp + 2008-12-17 17:56 . 2008-12-17 17:56 630272 c:\windows\Installer\cabd71.msi + 2007-11-08 01:34 . 2007-11-08 01:34 273920 c:\windows\Installer\c9e37e.msp + 2008-12-17 17:56 . 2008-12-17 17:56 348160 c:\windows\Installer\c9e377.msi + 2008-09-16 18:37 . 2008-09-16 18:37 265216 c:\windows\Installer\c8c4b.msi + 2007-11-07 23:07 . 2007-11-07 23:07 999936 c:\windows\Installer\c7b1bd.msp + 2007-11-07 22:56 . 2007-11-07 22:56 553472 c:\windows\Installer\c7b1ba.msp + 2007-11-07 22:58 . 2007-11-07 22:58 908800 c:\windows\Installer\c7b1b6.msp + 2007-11-07 22:54 . 2007-11-07 22:54 507392 c:\windows\Installer\c7b1b5.msp + 2009-04-20 18:32 . 2009-04-20 18:32 210432 c:\windows\Installer\8e6f58.msp + 2008-11-26 18:43 . 2008-11-26 18:43 337408 c:\windows\Installer\84da0.msi + 2009-03-30 23:27 . 2009-03-30 23:27 236032 c:\windows\Installer\80e062.msi + 2009-04-26 16:49 . 2009-04-26 16:49 598016 c:\windows\Installer\2031aa.msi + 2009-05-27 16:09 . 2009-05-27 16:09 355328 c:\windows\Installer\1fc04f.msi + 2008-07-23 08:05 . 2008-07-23 08:05 111616 c:\windows\Installer\1f522a9.msp + 2004-08-25 15:45 . 2004-08-25 15:45 129024 c:\windows\Installer\1f52245.msp + 2008-05-07 19:45 . 2008-05-07 19:45 674304 c:\windows\Installer\1f521b2.msp + 2009-06-19 04:25 . 2009-06-19 04:25 228352 c:\windows\Installer\18c67b.msi + 2008-09-16 20:16 . 2008-09-16 20:16 988672 c:\windows\Installer\1774e4.msi + 2008-09-16 20:13 . 2008-09-16 20:13 707072 c:\windows\Installer\1774cd.msi + 2009-06-02 21:00 . 2009-06-02 21:00 432640 c:\windows\Installer\151e879.msi + 2009-02-10 12:22 . 2009-02-10 12:22 533504 c:\windows\Installer\112185.msp + 2009-01-05 18:44 . 2009-01-05 18:44 741376 c:\windows\Downloaded Program Files\CONFLICT.1\ipsupd.dll + 2009-04-17 11:59 . 2009-04-17 11:59 128256 c:\windows\Downloaded Program Files\as2stubie.dll + 2008-01-09 17:01 . 2009-01-05 18:44 741376 c:\windows\BDOSCAN8\ipsupd.dll + 2008-04-14 11:00 . 2008-04-14 11:00 1354752 c:\windows\system32\webfldrs.msi + 2008-12-12 14:31 . 2007-01-01 09:32 1354752 c:\windows\ServicePackFiles\i386\webfldrs.msi + 2008-10-04 23:31 . 2008-10-04 23:31 2298880 c:\windows\Installer\f8018.msi + 2008-11-24 23:57 . 2008-11-24 23:57 4235776 c:\windows\Installer\e376.msi + 2008-10-04 20:45 . 2008-10-04 20:45 2981888 c:\windows\Installer\cf351.msi + 2008-12-17 17:57 . 2008-12-17 17:57 1048064 c:\windows\Installer\cb6179.msi + 2007-11-08 01:30 . 2007-11-08 01:30 3962368 c:\windows\Installer\c9e380.msp + 2007-11-08 01:13 . 2007-11-08 01:13 6766592 c:\windows\Installer\c9e37f.msp + 2007-11-08 01:26 . 2007-11-08 01:26 4340224 c:\windows\Installer\c9e37c.msp + 2007-11-08 01:24 . 2007-11-08 01:24 5353472 c:\windows\Installer\c9e37b.msp + 2007-11-08 01:18 . 2007-11-08 01:18 2059264 c:\windows\Installer\c9e379.msp + 2007-11-08 01:16 . 2007-11-08 01:16 1313280 c:\windows\Installer\c9e378.msp + 2007-11-07 22:50 . 2007-11-07 22:50 6055936 c:\windows\Installer\c7b1bc.msp + 2007-11-07 23:00 . 2007-11-07 23:00 3407360 c:\windows\Installer\c7b1bb.msp + 2007-11-07 22:46 . 2007-11-07 22:46 3010560 c:\windows\Installer\c7b1b9.msp + 2007-11-07 23:02 . 2007-11-07 23:02 6473216 c:\windows\Installer\c7b1b8.msp + 2007-11-07 23:12 . 2007-11-07 23:12 2533376 c:\windows\Installer\c7b1b7.msp + 2008-09-16 18:18 . 2008-09-16 18:18 1067520 c:\windows\Installer\a8fa6.msi + 2009-05-16 21:27 . 2009-05-16 21:27 1145856 c:\windows\Installer\a7e287.msi + 2008-05-06 13:30 . 2008-05-06 13:30 9577984 c:\windows\Installer\94cff8.msp + 2008-06-11 23:13 . 2008-06-11 23:13 7988224 c:\windows\Installer\94cfb7.msp + 2009-04-29 18:03 . 2009-04-29 18:03 8404992 c:\windows\Installer\8e6f44.msp + 2009-03-17 23:25 . 2009-03-17 23:25 1247744 c:\windows\Installer\5a49f7.msi + 2008-11-25 21:03 . 2008-11-25 21:03 1396224 c:\windows\Installer\5676c8.msi + 2009-05-01 02:02 . 2009-05-01 02:02 9628672 c:\windows\Installer\268de2.msp + 2009-03-20 02:42 . 2009-03-20 02:42 4733440 c:\windows\Installer\216f16d.msp + 2009-06-22 01:53 . 2009-06-22 01:53 1516544 c:\windows\Installer\210e1.msi + 2008-10-28 18:59 . 2008-10-28 18:59 8413184 c:\windows\Installer\1f52280.msp + 2008-09-04 18:52 . 2008-09-04 18:52 4337664 c:\windows\Installer\1f5226c.msp + 2008-01-11 17:13 . 2008-01-11 17:13 5862912 c:\windows\Installer\1f5222e.msp + 2008-01-14 17:26 . 2008-01-14 17:26 4478464 c:\windows\Installer\1f52208.msp + 2006-02-27 19:31 . 2006-02-27 19:31 1269248 c:\windows\Installer\1f521f4.msp + 2006-03-28 18:37 . 2006-03-28 18:37 6956032 c:\windows\Installer\1f521e0.msp + 2006-08-29 20:50 . 2006-08-29 20:50 3210240 c:\windows\Installer\1f521c6.msp + 2004-03-11 15:01 . 2004-03-11 15:01 2590720 c:\windows\Installer\1f52199.msp + 2004-09-13 12:21 . 2004-09-13 12:21 3115008 c:\windows\Installer\1f5217d.msp + 2008-03-31 19:35 . 2008-03-31 19:35 8309760 c:\windows\Installer\1f5214a.msp + 2006-02-22 12:25 . 2006-02-22 12:25 1016832 c:\windows\Installer\1f52135.msp + 2008-09-16 20:25 . 2008-09-16 20:25 4709888 c:\windows\Installer\1c523.msi + 2008-09-16 20:18 . 2008-09-16 20:18 3395072 c:\windows\Installer\1774ec.msi + 2008-09-16 20:15 . 2008-09-16 20:15 5956096 c:\windows\Installer\1774df.msi + 2009-05-24 18:00 . 2009-05-24 18:00 1298432 c:\windows\Installer\12ff67d.msi + 2009-05-16 21:26 . 2009-05-16 21:26 8159232 c:\windows\Downloaded Installations\{85D1A20D-BA2D-4FDB-AB14-83A78CBB5949}\Sisvar.msi + 2008-09-16 18:22 . 2008-09-16 18:18 13041664 c:\windows\system32\config\systemprofile\Dados de aplicativos\Sun\Java\jre1.6.0\jre1.6.0.msi + 2008-09-16 20:13 . 2007-01-19 16:21 16841728 c:\windows\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi + 2005-09-25 14:46 . 2005-09-25 14:46 16084480 c:\windows\Installer\94cfe4.msp + 2008-10-28 22:17 . 2008-10-28 22:17 17520128 c:\windows\Installer\94cfcb.msp + 2009-05-05 21:06 . 2009-05-05 21:06 17515008 c:\windows\Installer\8e6f6c.msp + 2004-02-24 13:25 . 2004-02-24 13:25 56876956 c:\windows\Installer\33b6b.msp + 2008-01-24 18:56 . 2008-01-24 18:56 13570560 c:\windows\Installer\1f52295.msp + 2009-03-09 18:55 . 2009-03-09 18:55 17526272 c:\windows\Installer\112199.msp . -- Snapshot resetado para data atual -- . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-24 1830128] "swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-24 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-12 162584] "Google Quick Search Box"="c:\arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-24 68592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-05-28 16132608] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ BTTray.lnk - c:\arquivos de programas\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176] Microsoft Office.lnk - c:\arquivos de programas\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Orbit.lnk - c:\arquivos de programas\Orbitdownloader\orbitdm.exe [2008-12-11 1719496] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\arquivos de programas\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 15:05 356352 ----a-w- c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "c:\\Arquivos de programas\\Bywifi\\bywifi.exe"= "c:\\CS1.6 pod-Bot\\hl.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"= "c:\\Documents and Settings\\Administrador\\Desktop\\Age of Empires II\\age2_x1.exe"= "c:\\Documents and Settings\\Administrador\\Desktop\\Age of Empires II\\empires2.EXE"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [16/6/2009 20:32 28544] R1 GhPciScan;GhostPciScanner;c:\arquivos de programas\Symantec\Norton Ghost 2003\GhPciScan.sys [28/5/2003 19:01 5632] R1 SASDIFSV;SASDIFSV;c:\arquivos de programas\SUPERAntiSpyware\sasdifsv.sys [26/5/2009 10:05 9968] R1 SASKUTIL;SASKUTIL;c:\arquivos de programas\SUPERAntiSpyware\SASKUTIL.SYS [26/5/2009 10:05 72944] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [23/6/2009 23:31 108289] R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\drivers\hidshim.sys [16/9/2008 16:55 5632] R3 SASENUM;SASENUM;c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [26/5/2009 10:05 7408] R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\drivers\winbondhidcir.sys [16/9/2008 16:55 21504] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?] S3 CrystalSysInfo;CrystalSysInfo;\??\c:\arquivos de programas\MediaCoder\SysInfo.sys --> c:\arquivos de programas\MediaCoder\SysInfo.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67EFG7H6-8IJL-56YT-KLH4-76WE8D3RAM87}] c:\system\S-3-7-89-2225458569-9856321456-454423558-8896\\Driver.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\arquivos de programas\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uInternet Settings,ProxyOverride = local FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\km7lq7cu.default\ FF - prefs.js: network.proxy.type - 2 FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: c:\documents and settings\All Users\Dados de aplicativos\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . . ------- Associação de arquivos/ficheiros ------- . inifile=%SystemRoot%\System32\NOTEPAD.EXE %1" . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-02 13:25 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-861567501-879983540-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ "6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,6b,26,7d,96,9b, b7,5a,a2,e2,63,26,f1,3f,c8,ff,68,92,49,9f,94,20,f0,3c,a4,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b0,e5,6d,c3,37, 4d,5a,7f,6a,9c,d6,61,af,45,84,18,3c,60,7b,fb,eb,2e,83,22,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,88,8b,fc,0f,f7, d6,70,a0,ff,7c,85,e0,43,d4,0e,fe,81,70,34,89,3c,29,fd,4d,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,17,e6,b3,34,96, 48,ce,63,86,8c,21,01,be,91,eb,e7,96,34,c2,cf,c6,fe,73,05,86,8c,21,01,be,91,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,b1,1e,a0,86,cb, 84,aa,45,f5,1d,4d,73,a8,13,5c,05,20,c7,0d,7a,43,dd,d3,5f,f5,1d,4d,73,a8,13,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,c8,48,b9,47,38, 93,c9,0f,df,20,58,62,78,6b,cf,c8,b1,76,c9,de,e6,68,10,40,df,20,58,62,78,6b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,a4,43,19,15,ec, 81,a5,d5,fb,a7,78,e6,12,2f,9a,ea,9d,26,17,46,7a,71,33,c9,fb,a7,78,e6,12,2f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9e,31,89,0e,3f, 1e,76,b7,01,3a,48,fc,e8,04,4a,f1,86,d9,6a,fb,ea,27,68,e6,01,3a,48,fc,e8,04,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,57,22,19,ba,cf, f7,ff,46,f6,0f,4e,58,98,5b,89,c9,c8,96,01,c8,c3,47,25,74,f6,0f,4e,58,98,5b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,1f,12,e8,bb,36, b2,fd,45,3d,ce,ea,26,2d,45,aa,78,f9,97,bb,7b,51,ba,a2,a2,3d,ce,ea,26,2d,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,94,6b,10,65,4a, a2,d2,c3,2a,b7,cc,b5,b9,7f,41,e7,c0,db,50,04,f0,ef,9a,ab,2a,b7,cc,b5,b9,7f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,c9,04,d7,d3,76, 07,cb,52,6c,43,2d,1e,aa,22,2f,9c,1e,97,22,d5,04,4c,ad,cb,6c,43,2d,1e,aa,22,\ . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(752) c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll . Tempo para conclusão: 2009-07-02 13:26 ComboFix-quarantined-files.txt 2009-07-02 16:26 ComboFix2.txt 2009-06-24 02:19 ComboFix3.txt 2009-06-20 00:10 ComboFix4.txt 2009-06-15 17:14 ComboFix5.txt 2009-07-02 16:20 Pré-execução: 12 pasta(s) 71.535.005.696 bytes disponíveis Pós execução: 12 pasta(s) 71.629.926.400 bytes disponíveis 367 --- E O F --- 2009-06-22 16:13 Agora HijackThis v2.0.2 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:35:01, on 2/7/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\system32\agrsmsvc.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\hkcmd.exe C:\Arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\WIDCOMM\Bluetooth Software\BTTray.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: GhostStartService - Symantec Corporation - C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 7716 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 2, 2009 Boa Tarde! Charlle Mas o que aconteceu foi que o IE voltou a funcionar a partir do scan com combofix que te mandei o log anteriormente, não entendi porque. <!> Nem eu entendi!Pois a remoção efetuada pelo ComboFix,não deveria ter esse efeito. < c:\windows\Installer\b5b8.msi > Mas estou mandando outros logsPara que você possa me dizer se ainda teria que fazer os passos que me disse antes. desde já Obrigado <!> Sim! Pode realizar os passos,pois o Worm.autorun.tmr,ainda permanece no PC. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Charlle 0 Denunciar post Postado Julho 4, 2009 Boa noite Dig Ram! Não sei se fiz cooretamente pois qndo arrastei o CFScript.txt para o icone do combofix ele se atualizou, se estiver errado me diga que refaço os passo! ai vão os logs Combofix ComboFix 09-07-04.04 - Administrador 04/07/2009 18:14.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.2038.1529 [GMT -3:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Administrador\Desktop\CFScript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . (((((((((((((((( Arquivos/Ficheiros criados de 2009-06-04 to 2009-07-04 )))))))))))))))))))))))))))) . 2009-06-24 14:47 . 2009-06-24 14:47 -------- d-----w- C:\Intel 2009-06-24 03:16 . 2009-06-24 03:17 -------- d-----w- c:\arquivos de programas\Google 2009-06-24 02:31 . 2009-03-30 13:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys 2009-06-24 02:31 . 2009-02-13 15:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2009-06-24 02:31 . 2009-02-13 15:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2009-06-24 02:31 . 2009-06-24 02:31 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira 2009-06-24 02:31 . 2009-06-24 02:31 -------- d-----w- c:\arquivos de programas\Avira 2009-06-22 16:07 . 2009-04-30 21:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-06-22 16:07 . 2009-04-30 21:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-22 10:13 . 2009-06-22 10:13 -------- d--h--w- c:\windows\system32\GroupPolicy 2009-06-22 08:20 . 2008-10-16 17:06 208744 ----a-w- c:\windows\system32\muweb.dll 2009-06-22 01:59 . 2009-04-06 18:32 15504 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-22 01:59 . 2009-04-06 18:32 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-22 01:59 . 2009-06-22 01:59 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-06-22 01:56 . 2009-07-04 21:04 117760 ----a-w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-22 01:54 . 2009-06-22 01:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-24 02:41 -------- d-----w- c:\arquivos de programas\SUPERAntiSpyware 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com 2009-06-22 01:53 . 2009-06-22 01:53 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard 2009-06-22 01:38 . 2009-06-22 01:38 -------- d-----w- c:\arquivos de programas\CCleaner 2009-06-22 01:33 . 2009-06-22 01:33 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-22 01:27 . 2008-04-13 22:20 81920 ------w- c:\windows\system32\ieencode.dll 2009-06-22 01:27 . 2008-04-13 22:19 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2009-06-21 15:07 . 2009-06-21 15:07 -------- d-----w- c:\arquivos de programas\Trend Micro 2009-06-20 22:36 . 2009-06-20 22:39 -------- dc-h--w- c:\windows\ie8 2009-06-20 22:15 . 2009-06-20 22:15 0 ----a-w- c:\windows\nsreg.dat 2009-06-20 21:49 . 2009-06-20 21:49 -------- d-----w- c:\arquivos de programas\SopCast 2009-06-20 19:18 . 2009-06-20 19:18 -------- d-----w- c:\arquivos de programas\Rockstar Games 2009-06-19 21:04 . 2009-06-19 21:04 -------- d-----w- c:\arquivos de programas\Aquiris Olympikus 2009-06-19 04:27 . 2009-03-24 19:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-06-16 23:32 . 2008-06-19 20:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys 2009-06-16 23:32 . 2009-06-16 23:32 -------- d-----w- c:\arquivos de programas\Panda Security 2009-06-15 20:19 . 2009-06-15 21:07 -------- d-----w- c:\arquivos de programas\Project64 v1.5 2009-06-15 01:22 . 2009-06-15 01:22 -------- d-----w- c:\arquivos de programas\SomePDF 2009-06-14 18:58 . 2009-06-14 18:58 -------- d-----w- c:\arquivos de programas\VDOWNLOADER . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-04 21:04 . 2008-12-11 15:16 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Orbit 2009-06-25 15:48 . 2009-06-01 22:01 -------- d-----w- c:\arquivos de programas\Pinnacle 2009-06-24 14:23 . 2009-03-26 22:57 -------- d-----w- c:\arquivos de programas\Bywifi 2009-06-23 23:27 . 2008-04-14 11:00 77144 ----a-w- c:\windows\system32\perfc016.dat 2009-06-23 23:27 . 2008-04-14 11:00 467160 ----a-w- c:\windows\system32\perfh016.dat 2009-06-23 20:47 . 2009-05-18 14:23 -------- d-----w- c:\arquivos de programas\Yahoo! 2009-06-22 01:50 . 2009-04-28 23:50 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP 2009-06-20 19:18 . 2008-09-16 20:01 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information 2009-06-04 20:46 . 2009-06-04 20:46 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ESET 2009-06-02 21:48 . 2009-03-24 01:28 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Any Video Converter 2009-06-02 21:00 . 2009-06-02 21:00 -------- d-----w- c:\arquivos de programas\MSXML 4.0 2009-06-01 22:12 . 2009-03-24 01:28 -------- d-----w- c:\arquivos de programas\Any Video Converter 2009-06-01 22:04 . 2009-06-01 22:04 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\DivX 2009-06-01 21:59 . 2009-06-01 21:59 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Pinnacle 2009-06-01 20:36 . 2009-03-17 23:27 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Skype 2009-06-01 20:35 . 2008-12-06 01:07 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\skypePM 2009-05-27 16:08 . 2009-05-27 16:08 -------- d-----w- c:\arquivos de programas\MSECache 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe 2009-05-24 18:00 . 2009-05-24 18:00 25214 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{9509674F-3972-11DE-806D-005056806466}\ARPPRODUCTICON.exe 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes 2009-05-21 22:00 . 2009-05-21 22:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2009-05-21 14:14 . 2008-12-11 15:16 -------- d-----w- c:\arquivos de programas\Orbitdownloader 2009-05-18 14:23 . 2009-05-18 14:23 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Yahoo! 2009-05-18 13:36 . 2009-04-29 00:09 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\IObit 2009-05-17 23:02 . 2009-05-17 23:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\EarMaster 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Borland Shared 2009-05-16 21:27 . 2009-05-16 21:27 -------- d-----w- c:\arquivos de programas\Sisvar 2009-05-13 05:03 . 2008-05-27 21:38 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:33 . 2008-04-14 11:00 347136 ----a-w- c:\windows\system32\localspl.dll 2009-04-26 16:49 . 2009-04-26 16:49 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-04-19 19:50 . 2008-04-14 11:00 1847296 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:53 . 2008-04-14 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of c:\windows\system32\GroupPolicy ---- 2009-06-22 10:23 . 2009-06-22 10:25 8 ----a-w- c:\windows\system32\GroupPolicy\User\Registry.pol 2009-06-22 10:13 . 2007-09-19 03:11 44940 ----a-w- c:\windows\system32\GroupPolicy\Adm\wuau.adm 2009-06-22 10:13 . 2007-09-19 03:11 72272 ----a-w- c:\windows\system32\GroupPolicy\Adm\wmplayer.adm 2009-06-22 10:13 . 2008-04-14 11:00 43086 ----a-w- c:\windows\system32\GroupPolicy\Adm\conf.adm 2009-06-22 10:13 . 2009-03-08 17:32 2858548 ----a-w- c:\windows\system32\GroupPolicy\Adm\inetres.adm 2009-06-22 10:13 . 2009-06-22 10:13 81 ---h--w- c:\windows\system32\GroupPolicy\Adm\admfiles.ini 2009-06-22 10:13 . 2008-04-14 11:00 1915598 ----a-w- c:\windows\system32\GroupPolicy\Adm\system.adm 2009-06-22 10:13 . 2009-06-22 10:25 79 ----a-w- c:\windows\system32\GroupPolicy\gpt.ini ((((((((((((((((((((((((((((( SnapShot_2009-07-02_16.25.02 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-04 21:04 . 2009-07-04 21:04 16384 c:\windows\temp\Perflib_Perfdata_21c.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-24 1830128] "swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-24 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-12 162584] "Google Quick Search Box"="c:\arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-24 68592] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-05-28 16132608] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ BTTray.lnk - c:\arquivos de programas\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176] Microsoft Office.lnk - c:\arquivos de programas\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Orbit.lnk - c:\arquivos de programas\Orbitdownloader\orbitdm.exe [2008-12-11 1719496] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\arquivos de programas\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 15:05 356352 ----a-w- c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"= "c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"= "c:\\Arquivos de programas\\Bywifi\\bywifi.exe"= "c:\\CS1.6 pod-Bot\\hl.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= "c:\\Arquivos de programas\\EA Sports\\FIFA 08\\FIFA08.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"= "c:\\Documents and Settings\\Administrador\\Desktop\\Age of Empires II\\age2_x1.exe"= "c:\\Documents and Settings\\Administrador\\Desktop\\Age of Empires II\\empires2.EXE"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [16/6/2009 20:32 28544] R1 GhPciScan;GhostPciScanner;c:\arquivos de programas\Symantec\Norton Ghost 2003\GhPciScan.sys [28/5/2003 19:01 5632] R1 SASDIFSV;SASDIFSV;c:\arquivos de programas\SUPERAntiSpyware\sasdifsv.sys [26/5/2009 10:05 9968] R1 SASKUTIL;SASKUTIL;c:\arquivos de programas\SUPERAntiSpyware\SASKUTIL.SYS [26/5/2009 10:05 72944] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [23/6/2009 23:31 108289] R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\drivers\hidshim.sys [16/9/2008 16:55 5632] R3 SASENUM;SASENUM;c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [26/5/2009 10:05 7408] R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\drivers\winbondhidcir.sys [16/9/2008 16:55 21504] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?] S3 CrystalSysInfo;CrystalSysInfo;\??\c:\arquivos de programas\MediaCoder\SysInfo.sys --> c:\arquivos de programas\MediaCoder\SysInfo.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\arquivos de programas\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uInternet Settings,ProxyOverride = local FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\km7lq7cu.default\ FF - prefs.js: network.proxy.type - 2 FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: c:\documents and settings\All Users\Dados de aplicativos\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-04 18:17 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_USERS\S-1-5-21-861567501-879983540-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ "6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fc,e1,93,ab,0e,3d,49,43,93,52,82,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,6b,26,7d,96,9b, b7,5a,a2,e2,63,26,f1,3f,c8,ff,68,92,49,9f,94,20,f0,3c,a4,e2,63,26,f1,3f,c8,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b0,e5,6d,c3,37, 4d,5a,7f,6a,9c,d6,61,af,45,84,18,3c,60,7b,fb,eb,2e,83,22,6a,9c,d6,61,af,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,88,8b,fc,0f,f7, d6,70,a0,ff,7c,85,e0,43,d4,0e,fe,81,70,34,89,3c,29,fd,4d,ff,7c,85,e0,43,d4,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,17,e6,b3,34,96, 48,ce,63,86,8c,21,01,be,91,eb,e7,96,34,c2,cf,c6,fe,73,05,86,8c,21,01,be,91,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,b1,1e,a0,86,cb, 84,aa,45,f5,1d,4d,73,a8,13,5c,05,20,c7,0d,7a,43,dd,d3,5f,f5,1d,4d,73,a8,13,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,c8,48,b9,47,38, 93,c9,0f,df,20,58,62,78,6b,cf,c8,b1,76,c9,de,e6,68,10,40,df,20,58,62,78,6b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,a4,43,19,15,ec, 81,a5,d5,fb,a7,78,e6,12,2f,9a,ea,9d,26,17,46,7a,71,33,c9,fb,a7,78,e6,12,2f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,9e,31,89,0e,3f, 1e,76,b7,01,3a,48,fc,e8,04,4a,f1,86,d9,6a,fb,ea,27,68,e6,01,3a,48,fc,e8,04,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,57,22,19,ba,cf, f7,ff,46,f6,0f,4e,58,98,5b,89,c9,c8,96,01,c8,c3,47,25,74,f6,0f,4e,58,98,5b,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,1f,12,e8,bb,36, b2,fd,45,3d,ce,ea,26,2d,45,aa,78,f9,97,bb,7b,51,ba,a2,a2,3d,ce,ea,26,2d,45,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,94,6b,10,65,4a, a2,d2,c3,2a,b7,cc,b5,b9,7f,41,e7,c0,db,50,04,f0,ef,9a,ab,2a,b7,cc,b5,b9,7f,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*] "ThreadingModel"="Apartment" @="c:\\WINDOWS\\system32\\OLE32.DLL" "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,c9,04,d7,d3,76, 07,cb,52,6c,43,2d,1e,aa,22,2f,9c,1e,97,22,d5,04,4c,ad,cb,6c,43,2d,1e,aa,22,\ . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(752) c:\arquivos de programas\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(3276) c:\windows\system32\WININET.dll c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroSearchBar.dll c:\arquivos de programas\Arquivos comuns\Ahead\Lib\MFC71U.DLL c:\arquivos de programas\Arquivos comuns\Ahead\Lib\BCGCBPRO800u.dll c:\arquiv~1\WINDOW~2\wmpband.dll c:\windows\system32\btmmhook.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Tempo para conclusão: 2009-07-04 18:19 ComboFix-quarantined-files.txt 2009-07-04 21:19 ComboFix2.txt 2009-07-02 16:26 ComboFix3.txt 2009-06-24 02:19 ComboFix4.txt 2009-06-20 00:10 ComboFix5.txt 2009-07-04 21:13 Pré-execução: 10 pasta(s) 69.957.672.960 bytes disponíveis Pós execução: 10 pasta(s) 69.981.069.312 bytes disponíveis 274 --- E O F --- 2009-06-22 16:13 HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:27:13, on 4/7/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\hkcmd.exe C:\Arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\WIDCOMM\Bluetooth Software\BTTray.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\WINDOWS\system32\agrsmsvc.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Arquivos de programas\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Arquivos de programas\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O4 - Global Startup: BTTray.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O20 - Winlogon Notify: !SASWinLogon - C:\Arquivos de programas\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Arquivos de programas\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: GhostStartService - Symantec Corporation - C:\Arquivos de programas\Symantec\Norton Ghost 2003\GhostStartService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Arquivos de programas\Arquivos comuns\LightScribe\LSSrvc.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe -- End of file - 7610 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 5, 2009 Boa Noite! Charlle <@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK. <@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança ) <@> Clique em Executar --> Aguarde! <@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. <@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°° <@> Estando tudo Ok,crie um ponto limpo na Restauração do Sistema. <@> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema. <@> Marque: Desativar Restauração do Sistema --> Aplicar --> Aguarde! --> Ok. <@> Depois,desmarque novamente! --> Aplicar --> Aguarde! --> Ok. <@> Para maiores detalhes,leia o Tutorial: < Link > °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°° <!> O log está limpo! :thumbsup: <!> Bom trabalho! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Charlle 0 Denunciar post Postado Julho 7, 2009 Bom dia Dig Ram! Trabalho feito. Muito obrigado pela atenção. grande trabalho de vcs! Parabens! Abraços Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Julho 8, 2009 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites