Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Lucied

[Resolvido!] Win32/Heur e derivados (Win32/Virut, SHeur2.AMSD) in

Recommended Posts

Olá.

 

Li a respeito desse malware, e sofro de alguns dos "sintomas" que o mesmo causa: conexão lenta, páginas que não carregam, wallpaper sumindo subitamente e aplicativos que não conseguem rodar (inclusive o logonui do Windows, o que gera erros logo na inicialização do sistema). O AVG detecta e supostamente remove o vírus, junto a alguns semelhantes, mas logo depois eles estão lá novamente, nas mesmas pastas. Tenho tido estes problemas desde o início da semana, e descofio que tenha sido infectado através de um pendrive.

 

Meu modem também está sinalizando transição de dados constante, o que me faz temer que dados do meu computador possam estar sendo roubados, ou que algo não agradável possa estar sendo baixado sem meu conhecimento. Preciso muito de ajuda, pois quero evitar ter de formatar este PC.

 

Segue o log do HijackThis:

 

-----------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 19:37:30, on 7/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\System32\svchost.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\spoolsv.exe

H:\WINDOWS\system32\csrcs.exe

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\WINDOWS\system32\servises.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\system32\ctfmon.exe

H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\WINDOWS\system32\servises.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\Explorer.exe

H:\WINDOWS\System32\svchost.exe

H:\ARQUIV~1\AVG\AVG8\avgemc.exe

H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

H:\WINDOWS\system32\svchost.exe

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

O1 - Hosts: 92.241.176.188 advanced-virus-remover2009.com

O1 - Hosts: 92.241.176.188 www.advanced-virus-remover2009.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - HKLM\..\RunOnce: [spybotSnD] "H:\Arquivos de programas\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

-----------------------------------------------------------------------------------

 

Agradeço qualquer ajuda desde já, e aguardo suporte.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Faça o download do ComboFix de um destes locais:

 

Link 1.

Link 2.

Link 3.

 

Importante!

Você não deve usar Combofix a menos que você tenha sido instruído a fazê-lo por um análista de segurança.

Destina-se pelo seu criador para ser utilizado sob orientação e supervisão de um especialista, e não para uso privado.

Utilizando esta ferramenta incorreto poderia levar a desastrosa problemas com o seu sistema operacional.

 

Certifique-se de que você salvou ComboFix.exe para o seu desktop.

 

• Desabilite o seu Antivírus e AntiSpyware , geralmente através de um clique direito sobre o ícone da bandeja do sistema. Eles podem interferir na execução da ferramenta.

 

• Dê um duplo clique no ComboFix.exe & siga as instruções.

 

• Como parte de seu processo, ComboFix irá verificar se o Microsoft Windows Recovery Console está instalado. Como as infecções de malware são hoje, é fortemente recomendado que esteja pré-instalado em sua máquina antes de fazer qualquer remoção de malware. Ela permitirá que você arrancar em especial uma recuperação / reparação modo a permitir-nos-á mais fácil ajudá-lo a seu computador deve ter um problema após uma tentativa de remoção de malware.

 

• Siga as instruções para permitir ComboFix para baixar e instalar o Microsoft Windows Recovery Console e, quando for solicitado, concordar com o End-User License Agreement para instalar o Microsoft Windows Recovery Console.

 

-- Atenção: Se a consola de recuperação do Microsoft Windows já estiver instalado, ComboFix irá continuar a sua remoção malware procedimentos.

 

RcAuto1.gif

 

Uma vez que o Microsoft Windows Recovery Console é instalado usando o ComboFix, você deverá ver a seguinte mensagem:

 

whatnext.png

 

Clique em Sim, para continuar a varredura de malware.

 

Quando terminar, ela deve produzir um log para você. Poste o relatorio do combofix que estar em C: \ ComboFix.txt junto com um log do hijackthis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tentei baixar o ComboFix dos três sites mencionados, e em todas as vezes o mesmo erro ocorreu ao tentar executá-lo:

 

erroj.png

 

Alguma alternativa ao programa sugerido? Obrigado.

~Lucied

 

PS: Está muito difícil acessar qualquer página na internet. Foram quatro ou cinco tentativas em cada um dos links para que finalmente conseguisse baixar o ComboFix, e somente para que esta página de resposta carregasse acho que passaram-se cerca de 4 minutos.

Compartilhar este post


Link para o post
Compartilhar em outros sites

- Faça o download do SDFIX

 

Reinicie seu computador, e aperte a tecla F8 (F5 em alguns casos) intermitentemente durante a inicialização, até aparecer um menu onde você deverá escolher a opção Modo Seguro

 

1. Entre na pasta SDFix que foi instalada no seu computador e dê um duplo clique no arquivo RunThis.bat

2. Tecle Y para que a ferramenta inicie o processo de remoção

3. Quando tudo terminar, você verá um aviso dizendo para apertar qualquer tecla para continuar. Ao pressionar qualquer tecla, o computador será reiniciado automaticamente

4. Após reiniciar, a ferramenta ainda será executada novamente e irá terminar o seu trabalho e a palavra Finished irá aparecer. Pressione qualquer tecla.

5. Uma janela com o relatório do SDFix irá aparecer.

6. Copie e cole este relatório na sua resposta . Caso você tenha fechado a janela, uma cópia do relatório estará na pasta SDFix com o nome Report.txt.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN,

 

Executei o SDFix em modo de segurança como instruído, mas após a reinicialização automática do PC novos programas acusaram erros (DAEMON Tools Lite - DaemonSearchBar.exe - e o Catalyst da minha placa de vídeo ATI - MOM.exe). Também houveram erros ao tentar iniciar esses mesmos programas manualmente, depois do término da inicialização. Parece que ao menos a conexão ficou levemente mais rápida, e o logonui.exe iniciou normalmente (com tela de boas vindas do Windows XP, etc).

 

Segue o log do SDFix:

 

--------------------------------------------------------------------

SDFix: Version 1.153

 

Run by Jorge on ter 07/07/2009 at 21:14

 

Microsoft Windows XP [versão 5.1.2600]

Running From: H:\SDFix

 

Checking Services :

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting

 

 

Checking Files :

 

No Trojan Files Found

 

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-07-07 21:21:30

Windows 5.1.2600 Service Pack 3 NTFS

 

detected NTDLL code modification:

ZwOpenFile

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]

"p0"="H:\Arquivos de programas\Alcohol Soft\Alcohol 120\"

"h0"=dword:00000000

"ujdew"=hex:5f,22,85,7c,fe,d0,3e,07,01,b4,3c,3f,30,04,42,8d,95,92,a6,bd,b5,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"h0"=dword:00000001

"khjeh"=hex:32,85,68,ca,6b,60,44,5d,01,c1,40,0d,8e,dd,e8,9e,67,71,96,7a,13,..

"p0"="H:\Arquivos de programas\DAEMON Tools Lite\"

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]

"khjeh"=hex:5c,a4,a5,39,c9,9d,98,8c,38,97,47,f9,3e,91,0f,a7,57,3d,ab,6b,e7,..

"a0"=hex:20,01,00,00,fa,36,ae,03,03,7f,6b,b6,c6,da,d0,49,4a,de,f7,9a,3c,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]

"khjeh"=hex:c9,80,1d,2b,96,8c,3f,a9,e5,ba,bc,07,24,ff,06,cd,d9,e4,5b,59,33,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]

"khjeh"=hex:b2,b1,60,5e,c3,30,9a,73,8c,c6,99,46,fe,9e,d2,0d,ec,fe,f6,ba,06,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]

"p0"="H:\Arquivos de programas\Alcohol Soft\Alcohol 120\"

"h0"=dword:00000000

"ujdew"=hex:5f,22,85,7c,fe,d0,3e,07,01,b4,3c,3f,30,04,42,8d,95,92,a6,bd,b5,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]

"h0"=dword:00000001

"khjeh"=hex:32,85,68,ca,6b,60,44,5d,01,c1,40,0d,8e,dd,e8,9e,67,71,96,7a,13,..

"p0"="H:\Arquivos de programas\DAEMON Tools Lite\"

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]

"khjeh"=hex:5c,a4,a5,39,c9,9d,98,8c,38,97,47,f9,3e,91,0f,a7,57,3d,ab,6b,e7,..

"a0"=hex:20,01,00,00,fa,36,ae,03,03,7f,6b,b6,c6,da,d0,49,4a,de,f7,9a,3c,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]

"khjeh"=hex:c9,80,1d,2b,96,8c,3f,a9,e5,ba,bc,07,24,ff,06,cd,d9,e4,5b,59,33,..

 

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]

"khjeh"=hex:b2,b1,60,5e,c3,30,9a,73,8c,c6,99,46,fe,9e,d2,0d,ec,fe,f6,ba,06,..

 

scanning hidden registry entries ...

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\27:\xf5wjY\1]

"DisplayName"="\x3da2\x7665\x1200\27\x1340\21\t"

"DeviceDesc"="\x3da2\x7665\x1200\27\x1340\21\t"

"ProviderName"="\xea70\x37e\x24dc\21\xfcb0\x1e2\x2808\21\x9005\x77f7"

"MFG"="\xffff\xffff\x3dbf\x7665\x654f\x7665\x900"

"ReinstallString"=".10.1000.8"

"DeviceInstanceIds"=str(7):"g:\chipset\xp3264\smbus\smbusati.inf"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]

"TracesProcessed"=dword:0000003d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

"DeviceNotSelectedTimeout"="15"

"GDIProcessHandleQuota"=dword:00002710

"Spooler"="yes"

"swapdisk"=""

"TransmissionRetryTimeout"="90"

"USERProcessHandleQuota"=dword:00002710

"LoadAppInit_DLLs"=dword:00000001

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\17_\xe8\x90]

"Order"=hex:08,00,00,00,02,00,00,00,80,00,00,00,01,00,00,00,01,00,00,00,74,..

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\17_\xe8\x90\DEVIL FORCE]

"Order"=hex:08,00,00,00,02,00,00,00,02,02,00,00,01,00,00,00,04,00,00,00,80,..

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"H:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"="H:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"

"H:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"="H:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"

"H:\\Arquivos de programas\\CyberLink\\PowerDVD\\PowerDVD.exe"="H:\\Arquivos de programas\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"

"G:\\CDS\\Nero\\Installation\\SetupX.exe"="G:\\CDS\\Nero\\Installation\\SetupX.exe:*:Enabled:Nero ProductSetup"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"H:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="H:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"H:\\Arquivos de programas\\Macromedia\\Fireworks MX\\Fireworks.exe"="H:\\Arquivos de programas\\Macromedia\\Fireworks MX\\Fireworks.exe:*:Enabled:Fireworks MX"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"

"H:\\Arquivos de programas\\BitComet\\BitComet.exe"="H:\\Arquivos de programas\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"

"H:\\Arquivos de programas\\Macromedia\\Flash MX\\Flash.exe"="H:\\Arquivos de programas\\Macromedia\\Flash MX\\Flash.exe:*:Enabled:Flash 6.0 r51"

"H:\\WINDOWS\\system32\\PnkBstrA.exe"="H:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"

"H:\\WINDOWS\\system32\\PnkBstrB.exe"="H:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"

"H:\\Arquivos de programas\\Instinct\\instinct.exe"="H:\\Arquivos de programas\\Instinct\\instinct.exe:*:Enabled:ds2main"

"H:\\Arquivos de programas\\Lionhead Studios Ltd\\Black & White\\runblack.exe"="H:\\Arquivos de programas\\Lionhead Studios Ltd\\Black & White\\runblack.exe:*:Enabled:lh"

"H:\\Arquivos de programas\\SEGA\\Iron Man\\IronMan.exe"="H:\\Arquivos de programas\\SEGA\\Iron Man\\IronMan.exe:*:Enabled:A2M Game Engine"

"H:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"="H:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"

"H:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"H:\\Arquivos de programas\\Unreal Tournament 3\\Binaries\\UT3.exe"="H:\\Arquivos de programas\\Unreal Tournament 3\\Binaries\\UT3.exe:*:Enabled:Unreal Tournament 3"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"

"H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="H:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

"H:\\Arquivos de programas\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"="H:\\Arquivos de programas\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"

"H:\\Arquivos de programas\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"="H:\\Arquivos de programas\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"

"\\??\\H:\\WINDOWS\\system32\\winlogon.exe"="\\??\\H:\\WINDOWS\\system32\\winlogon.exe:*:enabled:@shell32.dll,-1"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"H:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="H:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"H:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"="H:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"

"H:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"="H:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

 

Remaining Files :

 

 

 

Files with Hidden Attributes :

 

Wed 22 Oct 2008 949,072 A.SHR --- H:\ARQUIV~1\SPYBOT~1\ADVCHECK.DLL

Mon 15 Sep 2008 1,562,960 A.SHR --- H:\ARQUIV~1\SPYBOT~1\SDHELPER.DLL

Thu 14 Aug 2008 1,429,840 A.SHR --- H:\ARQUIV~1\SPYBOT~1\SDUPDATE.EXE

Wed 30 Jul 2008 4,891,984 A.SHR --- H:\ARQUIV~1\SPYBOT~1\SPYBOTSD.EXE

Thu 5 Mar 2009 2,280,448 A.SHR --- H:\ARQUIV~1\SPYBOT~1\TEATIMER.EXE

Wed 22 Oct 2008 962,896 A.SHR --- H:\ARQUIV~1\SPYBOT~1\TOOLS.DLL

Tue 16 Sep 2008 1,833,296 A.SHR --- H:\ARQUIV~1\TEATIM~1\TEATIMER.EXE

Sun 13 Apr 2008 713,010 A.SHR --- H:\WINDOWS\SYSTEM32\CSRCS.EXE

Sat 1 Sep 2007 81,920 A..H. --- H:\ARQUIV~1\SLACKS~1\MACROX~1\CARMLIC.EXE

Thu 2 Oct 2008 0 A.SH. --- H:\DOCUME~1\ALLUSE~1\DRM\CACHE\INDIV01.TMP

Sun 24 Feb 2008 190,976 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL0003.TMP

Tue 4 Mar 2008 191,488 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL0005.TMP

Sun 2 Mar 2008 51,712 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL0250.TMP

Tue 4 Mar 2008 191,488 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL0570.TMP

Tue 4 Mar 2008 194,560 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL0841.TMP

Tue 4 Mar 2008 51,712 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL1187.TMP

Sat 14 Jul 2007 97,280 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL1255.TMP

Tue 4 Mar 2008 192,512 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL1957.TMP

Tue 4 Mar 2008 193,536 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\~WRL2140.TMP

Thu 23 Aug 2007 48,128 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0118.TMP

Wed 18 Jul 2007 27,136 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0141.TMP

Wed 22 Aug 2007 47,616 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0253.TMP

Wed 18 Jul 2007 31,232 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0379.TMP

Wed 22 Aug 2007 47,616 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0785.TMP

Thu 23 Aug 2007 53,248 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL0812.TMP

Thu 23 Aug 2007 49,664 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL1101.TMP

Wed 18 Jul 2007 28,160 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL1804.TMP

Thu 23 Aug 2007 48,128 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL2698.TMP

Thu 23 Aug 2007 49,664 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL2877.TMP

Wed 22 Aug 2007 44,544 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL3062.TMP

Wed 18 Jul 2007 30,208 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL3313.TMP

Wed 18 Jul 2007 31,744 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL3412.TMP

Wed 18 Jul 2007 31,744 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\SISTEM~1\~WRL3552.TMP

Wed 18 Jul 2007 155,136 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\STORYL~1\~WRL0535.TMP

Sun 31 Dec 2006 301,568 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\STORYL~1\~WRL1073.TMP

Sun 31 Dec 2006 300,032 ...H. --- H:\TIGERH~1\_IRUCA~2\TEXTS\STORYL~1\~WRL2924.TMP

Thu 16 Oct 2008 1,471,528 A..H. --- H:\WINDOWS\SOFTWA~1\DOWNLOAD\162671~1\BIT30.TMP

Thu 2 Oct 2008 0 A..H. --- H:\WINDOWS\SOFTWA~1\DOWNLOAD\DB4AF1~1\BIT5.TMP

Fri 17 Oct 2008 2,874,920 A..H. --- H:\WINDOWS\SOFTWA~1\DOWNLOAD\F2EEA5~1\BIT2F.TMP

Wed 24 Jun 2009 4,520 ...HR --- H:\DOCUME~1\JORGE\DADOSD~1\SECUROM\USERDATA\SECURO~1.BAK

Thu 23 Aug 2007 48,128 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0118.TMP

Wed 18 Jul 2007 27,136 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0141.TMP

Wed 22 Aug 2007 47,616 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0253.TMP

Wed 18 Jul 2007 31,232 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0379.TMP

Wed 22 Aug 2007 47,616 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0785.TMP

Thu 23 Aug 2007 53,248 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL0812.TMP

Thu 23 Aug 2007 49,664 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL1101.TMP

Wed 18 Jul 2007 28,160 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL1804.TMP

Thu 23 Aug 2007 48,128 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL2698.TMP

Thu 23 Aug 2007 49,664 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL2877.TMP

Wed 22 Aug 2007 44,544 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL3062.TMP

Wed 18 Jul 2007 30,208 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL3313.TMP

Wed 18 Jul 2007 31,744 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL3412.TMP

Wed 18 Jul 2007 31,744 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\SISTEM~1\~WRL3552.TMP

Wed 18 Jul 2007 155,136 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\STORYL~1\~WRL0535.TMP

Sun 31 Dec 2006 301,568 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\STORYL~1\~WRL1073.TMP

Sun 31 Dec 2006 300,032 A..H. --- H:\DOCUME~1\JORGE\MEUSDO~1\NOVAPA~1\STORYL~1\~WRL2924.TMP

Thu 16 Oct 2008 1,847,941 A..H. --- H:\WINDOWS\SOFTWA~1\DOWNLOAD\C7B96A~1\DOWNLOAD\BIT37.TMP

 

Finished!

--------------------------------------------------------------------

 

....E também um novo log do HijackThis:

 

--------------------------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 21:39:33, on 7/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\System32\svchost.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\spoolsv.exe

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\System32\svchost.exe

H:\ARQUIV~1\AVG\AVG8\avgemc.exe

H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

H:\WINDOWS\system32\svchost.exe

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\system32\ctfmon.exe

H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\explorer.exe

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--------------------------------------------------------------------

 

O modem continua sinalizando transição de dados intermitente. Isso tem algo haver com o vírus afinal? Definitivamente não é normal, e suspeito que tantos dados sendo enviados/recebidos sem autorização possam ser a causa da lentidão da internet...

 

Grato pela ajuda até agora.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

• Baixe: < Kaspersky Virus Removal Tool >

• Salve-o em Arquivos de Programas,e instale-o aí mesmo!

• Reinicie o computador,em Modo de Segurança! <-- Importante!

• Dê início ao exame,clicando em "Scan".

• A verificação é um pouco demorada. Aguarde!

• Caso seja encontrada infecções,clique em "disinfect".

• Terminando,clique na aba Events.

Desmarque a caixa de seleção "Show all events".

• Clique em "Save to file".

Nomeie-o e salve-o no desktop! <-- Relatório para postagem!

Poste,também,HijackThis atualizado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá,

 

depois de horas tentando baixar o Kaspersky Virus Removal Tool sem sucesso (nem pelo link no seu post, nem pelo site oficial, nem por terceiros), finalmente obtive-o através de um contato de MSN que fez o favor de baixá-lo para mim. Rodei o scan em modo de segurança e desinfectei os arquivos nos quais era possível a desinfecção, mas em um deles fui obrigado a deletar o arquivo (csrcs.exe). Pelo que me pareceu, praticamente TODOS os executáveis de meu computador estavam infectados, até mesmo coisas como o notepad.exe e o próprio startup do Kaspersky Virus Removal Tool.

 

Após a reinicialização ocorreram muitos novos erros. Fechei dezenas de caixas de mensagens que acusavam falhas no script no logonui.exe e no svchost.exe, e agora por alguma razão o layout do Windows está no estilo Win 98 (barras cinzas, botões quadrados, fonte do sistema, etc), apesar de configurado para layout de Win XP. Foram tantos erros que tenho medo deste PC não mais ligar na próxima inicialização.

 

O AVG também continua acusando os mesmos vírus a cada restart, e eu continuo deletando-os, mesmo sabendo que retornarão no próximo minuto... Ao menos o wallpaper parou de desaparecer.

 

[EDIT:] O computador não executa nenhum som, nem do sistema nem de nenhum arquivo de áudio ou vídeo, com excessão de um apito a cada mensagem de erro. Também não consigo abrir arquivos de áudio ou texto sem que apareça alguma mensagem de erro (em alguns casos o arquivo nem mesmo abre). Agora sim, há algo de MUITO errado com este computador.

 

Segue o log do Kaspersky Virus Removal Tool:

 

-------------------------------------------------------

Scan

--------

Scanned: 1620

Detected: 122

Untreated: 0

Start time: 8/7/2009 16:48:10

Duration: 00:05:23

Finish time: 8/7/2009 16:53:33

 

 

Detected

--------

Status Object

------ ------

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: H:\WINDOWS\system32\svchost.exe

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: H:\WINDOWS\Explorer.exe

will be deleted when the computer is restarted: Trojan program Packed.Win32.Klone.bj File: H:\WINDOWS\system32\csrcs.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\mshta.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\notepad.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\regedit.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\7-zip\7zfm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\7-zip\7zg.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\accwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows media player\wmplayer.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\rundll32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\outlook express\wab.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\hh.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\clipbrd.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\irpf2009\irpf2009.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\fontview.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\game maker 7.0 pro\game_maker.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\macromedia\fireworks mx\fireworks.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\winhlp32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\winhlp32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows nt\hypertrm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\internet explorer\iexplore.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\wscript.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ntbackup.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\mmc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\rasphone.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\perfmon.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\cyberlink\powerproducer\producer.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows nt\acessórios\wordpad.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\notepad.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\wpnpinst.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\winace\winace.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\userinit.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\cyberlink\powerdvd\language\language.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\idt\wdm\sttray.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\ime\imjp8_1\imjpmig.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ime\pintlgnt\imscinst.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ime\tintlgnt\tintsetp.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\nerocheck.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\ati technologies\ati.ace\core-static\clistart.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\hp\hp software update\hpwuschd2.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\servises.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ctfmon.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\spybot - search & destroy\teatimer.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\daemon tools lite\daemon.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\alg.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ati2evxx.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ati2sgag.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\cisvc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\clipsrv.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\dllhost.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\dmadmin.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\arquivos comuns\installshield\driver\1050\intel 32\idrivert.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\imapi.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\mnmsrvc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\msdtc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\msiexec.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\netdde.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\hpzipm12.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\sessmgr.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\locator.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\rsvp.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\scardsvr.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\spoolsv.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\stacsv.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\alcohol soft\alcohol 120\starwind\starwindservice.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\smlogsvc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\tlntsvr.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ups.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\vssvc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\wbem\wmiapsrv.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows media player\wmpnetwk.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ieudinit.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\inf\unregmp2.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ie4uinit.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\shmgrate.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\regsvr32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\outlook express\setup50.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\progman.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\logon.scr

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\zip.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn gaming zone\windows\bckgzm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn gaming zone\windows\chkrzm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\netmeeting\conf.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows nt\dialer.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\cyberlink\cds\cdsversion.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\pchealth\helpctr\binaries\helpctr.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\hijackthis\hijackthis.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn gaming zone\windows\hrtzzm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\internet explorer\connection wizard\isignup.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\usmt\migwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\movie maker\moviemk.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows media player\mplayer2.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\pchealth\helpctr\binaries\msconfig.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\outlook express\msimn.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\messenger\msmsgs.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn\msncorefiles\msn6.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\ahead\coverdesigner\coverdes.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\ahead\nero\nero.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\ahead\nero startsmart\nerostartsmart.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\mspaint.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\windows nt\pinball\pinball.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\cyberlink\dvd suite\powerstarter.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\real\realplayer\realplay.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\arquivos comuns\real\update_ob\rnxproc.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn gaming zone\windows\rvsezm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\msn gaming zone\windows\shvlzm.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\outlook express\wabmig.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\winrar\winrar.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\winzip\winzip32.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\ahead\wmpburn\wmpburn.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\system32\ntsd.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\windows\network diagnostic\xpnetdiag.exe

disinfected: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\startup.exe

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe

 

 

Events

------

Time Name Status Reason

---- ---- ------ ------

8/7/2009 16:48:47 File: H:\WINDOWS\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:47 File: H:\WINDOWS\system32\svchost.exe not disinfected postponed

8/7/2009 16:48:47 File: H:\WINDOWS\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:47 File: H:\WINDOWS\system32\svchost.exe not disinfected postponed

8/7/2009 16:48:48 File: H:\WINDOWS\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:48 File: H:\WINDOWS\system32\svchost.exe not disinfected postponed

8/7/2009 16:48:50 File: H:\WINDOWS\Explorer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:50 File: H:\WINDOWS\Explorer.exe not disinfected postponed

8/7/2009 16:48:54 File: H:\WINDOWS\system32\csrcs.exe detected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:48:54 File: H:\WINDOWS\system32\csrcs.exe not disinfected postponed

8/7/2009 16:48:55 File: h:\windows\system32\mshta.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:55 File: h:\windows\system32\mshta.exe not disinfected postponed

8/7/2009 16:48:55 File: h:\windows\system32\notepad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:55 File: h:\windows\system32\notepad.exe not disinfected postponed

8/7/2009 16:48:55 File: h:\windows\regedit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:55 File: h:\windows\regedit.exe not disinfected postponed

8/7/2009 16:48:56 File: h:\arquivos de programas\7-zip\7zfm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:56 File: h:\arquivos de programas\7-zip\7zfm.exe not disinfected postponed

8/7/2009 16:48:56 File: h:\arquivos de programas\7-zip\7zg.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:48:56 File: h:\arquivos de programas\7-zip\7zg.exe not disinfected postponed

8/7/2009 16:49:00 File: h:\windows\system32\accwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:00 File: h:\windows\system32\accwiz.exe not disinfected postponed

8/7/2009 16:49:00 File: h:\arquivos de programas\windows media player\wmplayer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:00 File: h:\arquivos de programas\windows media player\wmplayer.exe not disinfected postponed

8/7/2009 16:49:00 File: h:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:00 File: h:\windows\system32\rundll32.exe not disinfected postponed

8/7/2009 16:49:00 File: H:\WINDOWS\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:00 File: H:\WINDOWS\system32\rundll32.exe not disinfected postponed

8/7/2009 16:49:00 File: h:\arquivos de programas\outlook express\wab.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:00 File: h:\arquivos de programas\outlook express\wab.exe not disinfected postponed

8/7/2009 16:49:00 File: h:\windows\hh.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:01 File: h:\windows\hh.exe not disinfected postponed

8/7/2009 16:49:01 File: h:\windows\system32\clipbrd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:01 File: h:\windows\system32\clipbrd.exe not disinfected postponed

8/7/2009 16:49:01 File: h:\arquivos de programas\irpf2009\irpf2009.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:01 File: h:\arquivos de programas\irpf2009\irpf2009.exe not disinfected postponed

8/7/2009 16:49:06 File: h:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:06 File: h:\windows\explorer.exe not disinfected postponed

8/7/2009 16:49:06 File: h:\windows\system32\fontview.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:06 File: h:\windows\system32\fontview.exe not disinfected postponed

8/7/2009 16:49:06 File: h:\arquivos de programas\game maker 7.0 pro\game_maker.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:09 File: h:\arquivos de programas\game maker 7.0 pro\game_maker.exe not disinfected postponed

8/7/2009 16:49:10 File: h:\arquivos de programas\macromedia\fireworks mx\fireworks.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:23 File: h:\arquivos de programas\macromedia\fireworks mx\fireworks.exe not disinfected postponed

8/7/2009 16:49:23 File: h:\windows\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:24 File: h:\windows\winhlp32.exe not disinfected postponed

8/7/2009 16:49:24 File: h:\windows\system32\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:24 File: h:\windows\system32\winhlp32.exe not disinfected postponed

8/7/2009 16:49:24 File: h:\arquivos de programas\windows nt\hypertrm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:24 File: h:\arquivos de programas\windows nt\hypertrm.exe not disinfected postponed

8/7/2009 16:49:24 File: h:\arquivos de programas\internet explorer\iexplore.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:25 File: h:\arquivos de programas\internet explorer\iexplore.exe not disinfected postponed

8/7/2009 16:49:26 File: h:\windows\system32\wscript.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:26 File: h:\windows\system32\wscript.exe not disinfected postponed

8/7/2009 16:49:26 File: h:\windows\system32\ntbackup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:28 File: h:\windows\system32\ntbackup.exe not disinfected postponed

8/7/2009 16:49:28 File: h:\windows\system32\mmc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:29 File: h:\windows\system32\mmc.exe not disinfected postponed

8/7/2009 16:49:30 File: h:\windows\system32\rasphone.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:30 File: h:\windows\system32\rasphone.exe not disinfected postponed

8/7/2009 16:49:30 File: h:\windows\system32\perfmon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:30 File: h:\windows\system32\perfmon.exe not disinfected postponed

8/7/2009 16:49:34 File: h:\arquivos de programas\cyberlink\powerproducer\producer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:36 File: h:\arquivos de programas\cyberlink\powerproducer\producer.exe not disinfected postponed

8/7/2009 16:49:36 File: H:\WINDOWS\regedit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:36 File: H:\WINDOWS\regedit.exe not disinfected postponed

8/7/2009 16:49:36 File: h:\arquivos de programas\windows nt\acessórios\wordpad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:36 File: h:\arquivos de programas\windows nt\acessórios\wordpad.exe not disinfected postponed

8/7/2009 16:49:36 File: h:\windows\notepad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:36 File: h:\windows\notepad.exe not disinfected postponed

8/7/2009 16:49:39 File: h:\windows\system32\wpnpinst.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:39 File: h:\windows\system32\wpnpinst.exe not disinfected postponed

8/7/2009 16:49:39 File: h:\arquivos de programas\winace\winace.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:41 File: h:\arquivos de programas\winace\winace.exe not disinfected postponed

8/7/2009 16:49:47 File: H:\WINDOWS\explorer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:47 File: H:\WINDOWS\explorer.exe not disinfected postponed

8/7/2009 16:49:47 File: h:\windows\system32\csrcs.exe detected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:49:47 File: h:\windows\system32\csrcs.exe not disinfected postponed

8/7/2009 16:49:47 File: h:\windows\system32\userinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:47 File: h:\windows\system32\userinit.exe not disinfected postponed

8/7/2009 16:49:49 File: h:\arquivos de programas\cyberlink\powerdvd\language\language.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:49 File: h:\arquivos de programas\cyberlink\powerdvd\language\language.exe not disinfected postponed

8/7/2009 16:49:49 File: h:\arquivos de programas\idt\wdm\sttray.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:50 File: h:\arquivos de programas\idt\wdm\sttray.exe not disinfected postponed

8/7/2009 16:49:50 File: h:\windows\ime\imjp8_1\imjpmig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:50 File: h:\windows\ime\imjp8_1\imjpmig.exe not disinfected postponed

8/7/2009 16:49:50 File: h:\windows\system32\ime\pintlgnt\imscinst.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:50 File: h:\windows\system32\ime\pintlgnt\imscinst.exe not disinfected postponed

8/7/2009 16:49:51 File: h:\windows\system32\ime\tintlgnt\tintsetp.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:51 File: h:\windows\system32\ime\tintlgnt\tintsetp.exe not disinfected postponed

8/7/2009 16:49:51 File: h:\windows\system32\nerocheck.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:51 File: h:\windows\system32\nerocheck.exe not disinfected postponed

8/7/2009 16:49:52 File: h:\arquivos de programas\ati technologies\ati.ace\core-static\clistart.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:52 File: h:\arquivos de programas\ati technologies\ati.ace\core-static\clistart.exe not disinfected postponed

8/7/2009 16:49:52 File: h:\arquivos de programas\hp\hp software update\hpwuschd2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:52 File: h:\arquivos de programas\hp\hp software update\hpwuschd2.exe not disinfected postponed

8/7/2009 16:49:52 File: h:\windows\system32\servises.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:52 File: h:\windows\system32\servises.exe not disinfected postponed

8/7/2009 16:49:52 File: h:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:53 File: h:\windows\system32\ctfmon.exe not disinfected postponed

8/7/2009 16:49:54 File: h:\arquivos de programas\spybot - search & destroy\teatimer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:55 File: h:\arquivos de programas\spybot - search & destroy\teatimer.exe not disinfected postponed

8/7/2009 16:49:57 File: h:\arquivos de programas\daemon tools lite\daemon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:49:58 File: h:\arquivos de programas\daemon tools lite\daemon.exe not disinfected postponed

8/7/2009 16:50:04 File: h:\windows\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:04 File: h:\windows\system32\svchost.exe not disinfected postponed

8/7/2009 16:50:04 File: h:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:04 File: h:\windows\system32\alg.exe not disinfected postponed

8/7/2009 16:50:04 File: h:\windows\system32\ati2evxx.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:05 File: h:\windows\system32\ati2evxx.exe not disinfected postponed

8/7/2009 16:50:05 File: h:\windows\system32\ati2sgag.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:06 File: h:\windows\system32\ati2sgag.exe not disinfected postponed

8/7/2009 16:50:10 File: h:\windows\system32\cisvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:10 File: h:\windows\system32\cisvc.exe not disinfected postponed

8/7/2009 16:50:10 File: h:\windows\system32\clipsrv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:10 File: h:\windows\system32\clipsrv.exe not disinfected postponed

8/7/2009 16:50:10 File: h:\windows\system32\dllhost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:10 File: h:\windows\system32\dllhost.exe not disinfected postponed

8/7/2009 16:50:10 File: h:\windows\system32\dmadmin.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:11 File: h:\windows\system32\dmadmin.exe not disinfected postponed

8/7/2009 16:50:12 File: h:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:12 File: h:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe not disinfected postponed

8/7/2009 16:50:13 File: h:\arquivos de programas\arquivos comuns\installshield\driver\1050\intel 32\idrivert.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:13 File: h:\arquivos de programas\arquivos comuns\installshield\driver\1050\intel 32\idrivert.exe not disinfected postponed

8/7/2009 16:50:13 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:14 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe not disinfected postponed

8/7/2009 16:50:14 File: h:\windows\system32\imapi.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:15 File: h:\windows\system32\imapi.exe not disinfected postponed

8/7/2009 16:50:16 File: h:\windows\system32\mnmsrvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:16 File: h:\windows\system32\mnmsrvc.exe not disinfected postponed

8/7/2009 16:50:17 File: h:\windows\system32\msdtc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:17 File: h:\windows\system32\msdtc.exe not disinfected postponed

8/7/2009 16:50:17 File: h:\windows\system32\msiexec.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:17 File: h:\windows\system32\msiexec.exe not disinfected postponed

8/7/2009 16:50:23 File: h:\windows\system32\netdde.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:23 File: h:\windows\system32\netdde.exe not disinfected postponed

8/7/2009 16:50:23 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:23 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe not disinfected postponed

8/7/2009 16:50:24 File: h:\windows\system32\hpzipm12.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:24 File: h:\windows\system32\hpzipm12.exe not disinfected postponed

8/7/2009 16:50:25 File: h:\windows\system32\sessmgr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:25 File: h:\windows\system32\sessmgr.exe not disinfected postponed

8/7/2009 16:50:25 File: h:\windows\system32\locator.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:26 File: h:\windows\system32\locator.exe not disinfected postponed

8/7/2009 16:50:26 File: h:\windows\system32\rsvp.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:26 File: h:\windows\system32\rsvp.exe not disinfected postponed

8/7/2009 16:50:26 File: h:\windows\system32\scardsvr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:26 File: h:\windows\system32\scardsvr.exe not disinfected postponed

8/7/2009 16:50:27 File: h:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:27 File: h:\windows\system32\spoolsv.exe not disinfected postponed

8/7/2009 16:50:27 File: h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\stacsv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:28 File: h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\stacsv.exe not disinfected postponed

8/7/2009 16:50:28 File: h:\arquivos de programas\alcohol soft\alcohol 120\starwind\starwindservice.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:28 File: h:\arquivos de programas\alcohol soft\alcohol 120\starwind\starwindservice.exe not disinfected postponed

8/7/2009 16:50:29 File: h:\windows\system32\smlogsvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:29 File: h:\windows\system32\smlogsvc.exe not disinfected postponed

8/7/2009 16:50:29 File: h:\windows\system32\tlntsvr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:29 File: h:\windows\system32\tlntsvr.exe not disinfected postponed

8/7/2009 16:50:29 File: h:\windows\system32\ups.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:30 File: h:\windows\system32\ups.exe not disinfected postponed

8/7/2009 16:50:30 File: h:\windows\system32\vssvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:31 File: h:\windows\system32\vssvc.exe not disinfected postponed

8/7/2009 16:50:31 File: h:\windows\system32\wbem\wmiapsrv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:31 File: h:\windows\system32\wbem\wmiapsrv.exe not disinfected postponed

8/7/2009 16:50:31 File: h:\arquivos de programas\windows media player\wmpnetwk.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:32 File: h:\arquivos de programas\windows media player\wmpnetwk.exe not disinfected postponed

8/7/2009 16:50:35 File: h:\windows\system32\ieudinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:35 File: h:\windows\system32\ieudinit.exe not disinfected postponed

8/7/2009 16:50:35 File: h:\windows\inf\unregmp2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:36 File: h:\windows\inf\unregmp2.exe not disinfected postponed

8/7/2009 16:50:36 File: h:\windows\system32\ie4uinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:36 File: h:\windows\system32\ie4uinit.exe not disinfected postponed

8/7/2009 16:50:36 File: h:\windows\system32\shmgrate.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:36 File: h:\windows\system32\shmgrate.exe not disinfected postponed

8/7/2009 16:50:36 File: h:\windows\system32\regsvr32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:36 File: h:\windows\system32\regsvr32.exe not disinfected postponed

8/7/2009 16:50:37 File: h:\arquivos de programas\outlook express\setup50.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:37 File: h:\arquivos de programas\outlook express\setup50.exe not disinfected postponed

8/7/2009 16:50:38 File: h:\windows\system32\progman.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:38 File: h:\windows\system32\progman.exe not disinfected postponed

8/7/2009 16:50:40 File: h:\windows\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:40 File: h:\windows\system32\logon.scr not disinfected postponed

8/7/2009 16:50:40 File: H:\WINDOWS\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:40 File: H:\WINDOWS\system32\logon.scr not disinfected postponed

8/7/2009 16:50:51 File: h:\windows\system32\zip.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:51 File: h:\windows\system32\zip.exe not disinfected postponed

8/7/2009 16:50:54 File: h:\arquivos de programas\msn gaming zone\windows\bckgzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:54 File: h:\arquivos de programas\msn gaming zone\windows\bckgzm.exe not disinfected postponed

8/7/2009 16:50:54 File: h:\arquivos de programas\msn gaming zone\windows\chkrzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:54 File: h:\arquivos de programas\msn gaming zone\windows\chkrzm.exe not disinfected postponed

8/7/2009 16:50:55 File: h:\arquivos de programas\netmeeting\conf.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:56 File: h:\arquivos de programas\netmeeting\conf.exe not disinfected postponed

8/7/2009 16:50:56 File: h:\arquivos de programas\windows nt\dialer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:57 File: h:\arquivos de programas\windows nt\dialer.exe not disinfected postponed

8/7/2009 16:50:57 File: h:\arquivos de programas\cyberlink\cds\cdsversion.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:50:57 File: h:\arquivos de programas\cyberlink\cds\cdsversion.exe not disinfected postponed

8/7/2009 16:50:59 File: h:\windows\pchealth\helpctr\binaries\helpctr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:00 File: h:\windows\pchealth\helpctr\binaries\helpctr.exe not disinfected postponed

8/7/2009 16:51:00 File: h:\arquivos de programas\hijackthis\hijackthis.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:01 File: h:\arquivos de programas\hijackthis\hijackthis.exe not disinfected postponed

8/7/2009 16:51:01 File: h:\arquivos de programas\msn gaming zone\windows\hrtzzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:01 File: h:\arquivos de programas\msn gaming zone\windows\hrtzzm.exe not disinfected postponed

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe not disinfected postponed

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe not disinfected postponed

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:01 File: h:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe not disinfected postponed

8/7/2009 16:51:04 File: h:\arquivos de programas\internet explorer\connection wizard\isignup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:05 File: h:\arquivos de programas\internet explorer\connection wizard\isignup.exe not disinfected postponed

8/7/2009 16:51:07 File: h:\windows\system32\usmt\migwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:07 File: h:\windows\system32\usmt\migwiz.exe not disinfected postponed

8/7/2009 16:51:08 File: h:\arquivos de programas\movie maker\moviemk.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:12 File: h:\arquivos de programas\movie maker\moviemk.exe not disinfected postponed

8/7/2009 16:51:12 File: h:\arquivos de programas\windows media player\mplayer2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:12 File: h:\arquivos de programas\windows media player\mplayer2.exe not disinfected postponed

8/7/2009 16:51:12 File: h:\windows\pchealth\helpctr\binaries\msconfig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:12 File: h:\windows\pchealth\helpctr\binaries\msconfig.exe not disinfected postponed

8/7/2009 16:51:12 File: h:\arquivos de programas\outlook express\msimn.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:12 File: h:\arquivos de programas\outlook express\msimn.exe not disinfected postponed

8/7/2009 16:51:13 File: h:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:13 File: h:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe not disinfected postponed

8/7/2009 16:51:13 File: h:\arquivos de programas\messenger\msmsgs.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:15 File: h:\arquivos de programas\messenger\msmsgs.exe not disinfected postponed

8/7/2009 16:51:15 File: h:\arquivos de programas\msn\msncorefiles\msn6.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:15 File: h:\arquivos de programas\msn\msncorefiles\msn6.exe not disinfected postponed

8/7/2009 16:51:20 File: h:\arquivos de programas\ahead\coverdesigner\coverdes.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:22 File: h:\arquivos de programas\ahead\coverdesigner\coverdes.exe not disinfected postponed

8/7/2009 16:51:23 File: h:\arquivos de programas\ahead\nero\nero.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:38 File: h:\arquivos de programas\ahead\nero\nero.exe not disinfected postponed

8/7/2009 16:51:39 File: h:\arquivos de programas\ahead\nero startsmart\nerostartsmart.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:41 File: h:\arquivos de programas\ahead\nero startsmart\nerostartsmart.exe not disinfected postponed

8/7/2009 16:51:41 File: h:\windows\system32\mspaint.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:42 File: h:\windows\system32\mspaint.exe not disinfected postponed

8/7/2009 16:51:42 File: h:\arquivos de programas\windows nt\pinball\pinball.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:42 File: h:\arquivos de programas\windows nt\pinball\pinball.exe not disinfected postponed

8/7/2009 16:51:42 File: h:\arquivos de programas\cyberlink\dvd suite\powerstarter.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:42 File: h:\arquivos de programas\cyberlink\dvd suite\powerstarter.exe not disinfected postponed

8/7/2009 16:51:43 File: h:\arquivos de programas\real\realplayer\realplay.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:43 File: h:\arquivos de programas\real\realplayer\realplay.exe not disinfected postponed

8/7/2009 16:51:43 File: h:\arquivos de programas\arquivos comuns\real\update_ob\rnxproc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:43 File: h:\arquivos de programas\arquivos comuns\real\update_ob\rnxproc.exe not disinfected postponed

8/7/2009 16:51:43 File: h:\arquivos de programas\msn gaming zone\windows\rvsezm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:43 File: h:\arquivos de programas\msn gaming zone\windows\rvsezm.exe not disinfected postponed

8/7/2009 16:51:43 File: h:\arquivos de programas\msn gaming zone\windows\shvlzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:43 File: h:\arquivos de programas\msn gaming zone\windows\shvlzm.exe not disinfected postponed

8/7/2009 16:51:44 File: h:\arquivos de programas\outlook express\wabmig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:44 File: h:\arquivos de programas\outlook express\wabmig.exe not disinfected postponed

8/7/2009 16:51:44 File: h:\arquivos de programas\winrar\winrar.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:45 File: h:\arquivos de programas\winrar\winrar.exe not disinfected postponed

8/7/2009 16:51:46 File: h:\arquiv~1\winzip\winzip32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:48 File: h:\arquiv~1\winzip\winzip32.exe not disinfected postponed

8/7/2009 16:51:49 File: h:\arquivos de programas\ahead\wmpburn\wmpburn.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:50 File: h:\arquivos de programas\ahead\wmpburn\wmpburn.exe not disinfected postponed

8/7/2009 16:51:50 File: h:\windows\system32\ntsd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:50 File: h:\windows\system32\ntsd.exe not disinfected postponed

8/7/2009 16:51:51 File: h:\windows\network diagnostic\xpnetdiag.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:51 File: h:\windows\network diagnostic\xpnetdiag.exe not disinfected postponed

8/7/2009 16:51:55 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\startup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:56 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\startup.exe not disinfected postponed

8/7/2009 16:51:56 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:51:56 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe not disinfected postponed

8/7/2009 16:52:16 File: h:\windows\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:25 File: h:\windows\system32\svchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:25 File: h:\windows\system32\svchost.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:25 File: h:\windows\system32\svchost.exe will be disinfected on system restart

8/7/2009 16:52:25 File: h:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:27 File: h:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:27 File: h:\windows\explorer.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:28 File: h:\windows\explorer.exe will be disinfected on system restart

8/7/2009 16:52:28 File: h:\windows\system32\csrcs.exe detected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:52:32 File: h:\windows\system32\csrcs.exe detected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:52:32 File: h:\windows\system32\csrcs.exe not disinfected cannot be disinfected

8/7/2009 16:52:33 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell disinfected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:52:33 Startup object: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\csrcs disinfected Trojan program 'Packed.Win32.Klone.bj'

8/7/2009 16:52:41 File: h:\windows\system32\csrcs.exe will be deleted on system restart

8/7/2009 16:52:41 File: h:\windows\system32\mshta.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\windows\system32\mshta.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\windows\system32\notepad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\windows\system32\notepad.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\windows\regedit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\windows\regedit.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\arquivos de programas\7-zip\7zfm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:41 File: h:\arquivos de programas\7-zip\7zfm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\7-zip\7zg.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\7-zip\7zg.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\accwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\accwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\windows media player\wmplayer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\windows media player\wmplayer.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\rundll32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\outlook express\wab.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\outlook express\wab.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\hh.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\hh.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\clipbrd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\windows\system32\clipbrd.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\irpf2009\irpf2009.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:42 File: h:\arquivos de programas\irpf2009\irpf2009.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\windows\system32\fontview.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\windows\system32\fontview.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\arquivos de programas\game maker 7.0 pro\game_maker.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\arquivos de programas\game maker 7.0 pro\game_maker.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\arquivos de programas\macromedia\fireworks mx\fireworks.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\arquivos de programas\macromedia\fireworks mx\fireworks.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\windows\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:43 File: h:\windows\winhlp32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:44 File: h:\windows\system32\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:44 File: h:\windows\system32\winhlp32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:44 File: h:\arquivos de programas\windows nt\hypertrm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:44 File: h:\arquivos de programas\windows nt\hypertrm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:45 File: h:\arquivos de programas\internet explorer\iexplore.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:45 File: h:\arquivos de programas\internet explorer\iexplore.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:46 File: h:\windows\system32\wscript.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:46 File: h:\windows\system32\wscript.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:47 File: h:\windows\system32\ntbackup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:47 File: h:\windows\system32\ntbackup.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:48 File: h:\windows\system32\mmc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:48 File: h:\windows\system32\mmc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:49 File: h:\windows\system32\rasphone.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:49 File: h:\windows\system32\rasphone.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:50 File: h:\windows\system32\perfmon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:50 File: h:\windows\system32\perfmon.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:50 File: h:\arquivos de programas\cyberlink\powerproducer\producer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\arquivos de programas\cyberlink\powerproducer\producer.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\arquivos de programas\windows nt\acessórios\wordpad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\arquivos de programas\windows nt\acessórios\wordpad.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\windows\notepad.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\windows\notepad.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\windows\system32\wpnpinst.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:51 File: h:\windows\system32\wpnpinst.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:52 File: h:\arquivos de programas\winace\winace.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:52 File: h:\arquivos de programas\winace\winace.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\windows\system32\userinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\windows\system32\userinit.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\arquivos de programas\cyberlink\powerdvd\language\language.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\arquivos de programas\cyberlink\powerdvd\language\language.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\arquivos de programas\idt\wdm\sttray.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:54 File: h:\arquivos de programas\idt\wdm\sttray.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\ime\imjp8_1\imjpmig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\ime\imjp8_1\imjpmig.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\system32\ime\pintlgnt\imscinst.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\system32\ime\pintlgnt\imscinst.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\system32\ime\tintlgnt\tintsetp.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:55 File: h:\windows\system32\ime\tintlgnt\tintsetp.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\windows\system32\nerocheck.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\windows\system32\nerocheck.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\arquivos de programas\ati technologies\ati.ace\core-static\clistart.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\arquivos de programas\ati technologies\ati.ace\core-static\clistart.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\arquivos de programas\hp\hp software update\hpwuschd2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\arquivos de programas\hp\hp software update\hpwuschd2.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\windows\system32\servises.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:56 File: h:\windows\system32\servises.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\windows\system32\ctfmon.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\arquivos de programas\spybot - search & destroy\teatimer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\arquivos de programas\spybot - search & destroy\teatimer.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\arquivos de programas\daemon tools lite\daemon.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:57 File: h:\arquivos de programas\daemon tools lite\daemon.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:58 File: h:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:58 File: h:\windows\system32\alg.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\ati2evxx.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\ati2evxx.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\ati2sgag.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\ati2sgag.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\cisvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:52:59 File: h:\windows\system32\cisvc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\clipsrv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\clipsrv.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\dllhost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\dllhost.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\dmadmin.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\system32\dmadmin.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:00 File: h:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\arquivos de programas\arquivos comuns\installshield\driver\1050\intel 32\idrivert.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\arquivos de programas\arquivos comuns\installshield\driver\1050\intel 32\idrivert.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\system32\imapi.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\system32\imapi.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\system32\mnmsrvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:01 File: h:\windows\system32\mnmsrvc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\msdtc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\msdtc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\msiexec.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\msiexec.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\netdde.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:02 File: h:\windows\system32\netdde.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\hpzipm12.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\hpzipm12.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\sessmgr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\sessmgr.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\locator.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\locator.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\rsvp.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:03 File: h:\windows\system32\rsvp.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\scardsvr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\scardsvr.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\spoolsv.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\stacsv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\stacsv.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\arquivos de programas\alcohol soft\alcohol 120\starwind\starwindservice.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\arquivos de programas\alcohol soft\alcohol 120\starwind\starwindservice.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\smlogsvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:04 File: h:\windows\system32\smlogsvc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\tlntsvr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\tlntsvr.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\ups.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\ups.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\vssvc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\vssvc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\wbem\wmiapsrv.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:05 File: h:\windows\system32\wbem\wmiapsrv.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\arquivos de programas\windows media player\wmpnetwk.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\arquivos de programas\windows media player\wmpnetwk.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\windows\system32\ieudinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\windows\system32\ieudinit.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\windows\inf\unregmp2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:06 File: h:\windows\inf\unregmp2.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\ie4uinit.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\ie4uinit.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\shmgrate.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\shmgrate.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\regsvr32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\windows\system32\regsvr32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\arquivos de programas\outlook express\setup50.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:07 File: h:\arquivos de programas\outlook express\setup50.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\progman.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\progman.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\logon.scr disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\zip.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\windows\system32\zip.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\arquivos de programas\msn gaming zone\windows\bckgzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:08 File: h:\arquivos de programas\msn gaming zone\windows\bckgzm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\msn gaming zone\windows\chkrzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\msn gaming zone\windows\chkrzm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\netmeeting\conf.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\netmeeting\conf.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\windows nt\dialer.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\windows nt\dialer.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\cyberlink\cds\cdsversion.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:09 File: h:\arquivos de programas\cyberlink\cds\cdsversion.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:10 File: h:\windows\pchealth\helpctr\binaries\helpctr.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:10 File: h:\windows\pchealth\helpctr\binaries\helpctr.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:10 File: h:\arquivos de programas\hijackthis\hijackthis.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:10 File: h:\arquivos de programas\hijackthis\hijackthis.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\msn gaming zone\windows\hrtzzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\msn gaming zone\windows\hrtzzm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:11 File: h:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\internet explorer\connection wizard\isignup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\internet explorer\connection wizard\isignup.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\windows\system32\usmt\migwiz.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\windows\system32\usmt\migwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\movie maker\moviemk.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\movie maker\moviemk.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\windows media player\mplayer2.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:12 File: h:\arquivos de programas\windows media player\mplayer2.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:13 File: h:\windows\pchealth\helpctr\binaries\msconfig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:13 File: h:\windows\pchealth\helpctr\binaries\msconfig.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:13 File: h:\arquivos de programas\outlook express\msimn.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:13 File: h:\arquivos de programas\outlook express\msimn.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:14 File: h:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:14 File: h:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:14 File: h:\arquivos de programas\messenger\msmsgs.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:14 File: h:\arquivos de programas\messenger\msmsgs.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:15 File: h:\arquivos de programas\msn\msncorefiles\msn6.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:15 File: h:\arquivos de programas\msn\msncorefiles\msn6.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:15 File: h:\arquivos de programas\ahead\coverdesigner\coverdes.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:15 File: h:\arquivos de programas\ahead\coverdesigner\coverdes.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:15 File: h:\arquivos de programas\ahead\nero\nero.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:17 File: h:\arquivos de programas\ahead\nero\nero.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:19 File: h:\arquivos de programas\ahead\nero startsmart\nerostartsmart.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:19 File: h:\arquivos de programas\ahead\nero startsmart\nerostartsmart.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:20 File: h:\windows\system32\mspaint.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:20 File: h:\windows\system32\mspaint.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:21 File: h:\arquivos de programas\windows nt\pinball\pinball.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:21 File: h:\arquivos de programas\windows nt\pinball\pinball.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:22 File: h:\arquivos de programas\cyberlink\dvd suite\powerstarter.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:22 File: h:\arquivos de programas\cyberlink\dvd suite\powerstarter.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:23 File: h:\arquivos de programas\real\realplayer\realplay.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:23 File: h:\arquivos de programas\real\realplayer\realplay.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:24 File: h:\arquivos de programas\arquivos comuns\real\update_ob\rnxproc.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:24 File: h:\arquivos de programas\arquivos comuns\real\update_ob\rnxproc.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:25 File: h:\arquivos de programas\msn gaming zone\windows\rvsezm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:25 File: h:\arquivos de programas\msn gaming zone\windows\rvsezm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:26 File: h:\arquivos de programas\msn gaming zone\windows\shvlzm.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:26 File: h:\arquivos de programas\msn gaming zone\windows\shvlzm.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:27 File: h:\arquivos de programas\outlook express\wabmig.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:27 File: h:\arquivos de programas\outlook express\wabmig.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:28 File: h:\arquivos de programas\winrar\winrar.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:28 File: h:\arquivos de programas\winrar\winrar.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:29 File: h:\arquivos de programas\winzip\winzip32.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:29 File: h:\arquivos de programas\winzip\winzip32.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:29 File: h:\arquivos de programas\ahead\wmpburn\wmpburn.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:30 File: h:\arquivos de programas\ahead\wmpburn\wmpburn.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:31 File: h:\windows\system32\ntsd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:31 File: h:\windows\system32\ntsd.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\windows\network diagnostic\xpnetdiag.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\windows\network diagnostic\xpnetdiag.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\startup.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\startup.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe detected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:32 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe disinfected virus 'Virus.Win32.Virut.ce'

8/7/2009 16:53:33 File: h:\arquivos de programas\kaspersky virus removal tool\is-c5ibd\is-c5ibd.exe will be disinfected on system restart

 

 

Statistics

----------

Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted

------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

 

 

Settings

--------

Parameter Value

--------- -----

Security Level Recommended

Action Prompt for action when the scan is complete

Run mode Manually

File types Scan all files

Scan only new and changed files No

Scan archives All

Scan embedded OLE objects All

Skip if object is larger than No

Skip if scan takes longer than No

Parse email formats No

Scan password-protected archives No

Enable iChecker technology No

Enable iSwift technology No

Show detected threats on "Detected" tab Yes

Rootkits search Yes

Deep rootkits search No

Use heuristic analyzer Yes

 

 

Quarantine

----------

Status Object Size Added

------ ------ ---- -----

 

 

Backup

------

Status Object Size

------ ------ ----

-------------------------------------------------------

 

...e o log do HijackThis atualizado:

 

-------------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 17:03:45, on 8/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\system32\servises.exe

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\WINDOWS\System32\svchost.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\system32\servises.exe

H:\WINDOWS\explorer.exe

H:\WINDOWS\system32\11.tmp

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - Startup: is-C5IBD.lnk = H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\startup.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

-------------------------------------------------------

 

Não foi suficiente meu PC antigo ter sido infectado pelo Smitfraud.C, agora isso. Estou começando a cogitar uma proibição de pendrives que não sejam o meu próprio neste PC.

Obrigado pelo suporte até o momento, aguardo novas instruções.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

<@> Baixe: < DrWebCureIt >

<@> Caso tenha dificuldades para o download,utilize outro computador.

<@> Salve-o no desktop!

<@> Reinicie o computador em Modo de Segurança.

<@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit.

<@> Na janela que abrir,clique em Iniciar --> OK.

<@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda!

<@> Terminando,marque a caixa de "Verificação Completa".

<@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis".

 

Neste modo são verificados os seguintes objectos:

 

* Sectores de Arranque de Todos os Discos. <--

 

* Todas as Unidades Removíveis. <--

 

* Todos os Discos Locais. <--

<@> Clique em "Iniciar verificação" --> Aguarde!

<@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim.

<@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios".

<@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Texto!

<@> Poste: DrWeb.csv + HijackThis,atualizado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN,

 

após horas de verificação, o Dr.Web encontrou cerca de 280 arquivos infectados no meu computador, dos quais 99% eram executáveis. 3 arquivos tiveram de ser eliminados e outros 3 movidos (inclusive um que foi acusado como "Incurável"), mas acho que finalmente, após a reinicialização e uma verificação automática do HD, o PC demonstrou melhoras.

 

O AVG não acusou ter encontrado os trojans que acusava a cada restart até agora, o estilo Win XP está de volta e o som também. Infelizmente o Catalyst da placa de vídeo e o startup do Daemon Tools continuam acusando erros (será a reinstalação a única solução para estes dois programas?) e o modem ainda transfere dados mesmo quando a internet não está sendo usada. Desconfio muito disso... sinto que a cada página acessada novos arquivos infectados são baixados.

 

Ah, também consegui acessar o site do fórum sem ter de atualizar a página cinco vezes, o que definitivamente é uma melhora na velocidade de conexão. Segue o log do Dr.Web (convertido de planilha de Excel para texto unicode):

 

------------------------------------------------

4E474F0E9B6D0A39[1].da H:\Documents and Settings\Jorge\Configurações locais\Temporary Internet Files\Content.IE5\XP5XZZB9 Win32.HLLW.Autohit.3438 Incurável.Movido.

dap75.exe H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS O arquivo contém objectos infectados Movido.

SDFix.exe H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS O arquivo contém objectos infectados Movido.

explorer.exe h:\windows Win32.Virut.56 Desinfectado.

logonui.exe h:\windows\system32 Win32.Virut.56 Desinfectado.

svchost.exe h:\windows\system32 Win32.Virut.56 Desinfectado.

winmgmt.exe h:\windows\system32\wbem Win32.Virut.56 Desinfectado.

7z.exe H:\Arquivos de programas\7-Zip Win32.Virut.56 Desinfectado.

LogTransport2.exe H:\Arquivos de programas\Adobe\Reader 9.0\Reader Win32.Virut.56 Desinfectado.

DIFxSetup.exe H:\Arquivos de programas\AGEIA Technologies\driver\x86\1.1.1.14 Win32.Virut.56 Desinfectado.

rescanDevNode.exe H:\Arquivos de programas\AGEIA Technologies\driver\x86\1.1.1.14 Win32.Virut.56 Desinfectado.

NeroCmd.exe H:\Arquivos de programas\Ahead\Nero Win32.Virut.56 Desinfectado.

UNNero.exe H:\Arquivos de programas\Ahead\Nero\Uninstall Win32.Virut.56 Desinfectado.

CDSpeed.exe H:\Arquivos de programas\Ahead\Nero Toolkit Win32.Virut.56 Desinfectado.

DMAManager.exe H:\Arquivos de programas\Ahead\Nero Toolkit Win32.Virut.56 Desinfectado.

DriveSpeed.exe H:\Arquivos de programas\Ahead\Nero Toolkit Win32.Virut.56 Desinfectado.

DXEnum.exe H:\Arquivos de programas\Ahead\Nero Wave Editor Win32.Virut.56 Desinfectado.

StarWindIPSecCfg.exe H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\Arquivos comuns\Ahead\Uninstall Win32.Virut.56 Desinfectado.

atixcode.exe H:\Arquivos de programas\Arquivos comuns\ATI Technologies\Multimedia Win32.Virut.56 Desinfectado.

IDriver.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32 Win32.Virut.56 Desinfectado.

IDriver2.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32 Win32.Virut.56 Desinfectado.

IKernel.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\engine\6\Intel 32 Win32.Virut.56 Desinfectado.

DotNetInstaller.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Professional\RunTime\0700\Intel32 Win32.Virut.56 Desinfectado.

DotNetInstaller.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Professional\RunTime\09\01\Intel32 Win32.Virut.56 Desinfectado.

DotNetInstaller.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Professional\RunTime\10\01\Intel32 Win32.Virut.56 Desinfectado.

DotNetInstaller.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Professional\RunTime\11\00\Intel32 Win32.Virut.56 Desinfectado.

DotNetInstaller.exe H:\Arquivos de programas\Arquivos comuns\InstallShield\Professional\RunTime\11\50\Intel32 Win32.Virut.56 Desinfectado.

launcher.exe H:\Arquivos de programas\Arquivos comuns\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05 Win32.Virut.56 Desinfectado.

zipper.exe H:\Arquivos de programas\Arquivos comuns\Java\Update\Base Images\jre1.5.0.b64\patch-jre1.5.0_06.b05 Win32.Virut.56 Desinfectado.

launcher.exe H:\Arquivos de programas\Arquivos comuns\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_07.b06 Win32.Virut.56 Desinfectado.

sapisvr.exe H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Speech Win32.Virut.56 Desinfectado.

r1puninst.exe H:\Arquivos de programas\Arquivos comuns\Real\Update_OB Win32.Virut.56 Desinfectado.

RealOneMessageCenter.exe H:\Arquivos de programas\Arquivos comuns\Real\Update_OB Win32.Virut.56 Desinfectado.

realsched.exe H:\Arquivos de programas\Arquivos comuns\Real\Update_OB Win32.Virut.56 Desinfectado.

upgrdhlp.exe H:\Arquivos de programas\Arquivos comuns\Real\Update_OB Win32.Virut.56 Desinfectado.

AtiCimUn.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11 Win32.Virut.56 Desinfectado.

CheckVer.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11 Win32.Virut.56 Desinfectado.

DrvUI64A.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11 Win32.Virut.56 Desinfectado.

issetup.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11 Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11 Win32.Virut.56 Desinfectado.

atiicdxx.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11\BIN Win32.Virut.56 Desinfectado.

EnumDev.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11\BIN Win32.Virut.56 Desinfectado.

UpdatPnP.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11\BIN Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11\Driver Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\ATI Technologies\ATI Catalyst Control Center\8-11\WDM_ALL Win32.Virut.56 Desinfectado.

CCCInstall.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Branding Win32.Virut.56 Desinfectado.

CLI.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Branding Win32.Virut.56 Desinfectado.

MOM.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Branding Win32.Virut.56 Desinfectado.

LOG.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Implementation Win32.Virut.56 Desinfectado.

atishlx.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-PreInstall Win32.Virut.56 Desinfectado.

CCCInstall.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-PreInstall Win32.Virut.56 Desinfectado.

atishlx.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

CCCInstall.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

CLI.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

installShell.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

installShell64.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

MOM.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static Win32.Virut.56 Desinfectado.

DXStress.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Graphics-Full-Existing Win32.Virut.56 Desinfectado.

MMLoadDrv.exe H:\Arquivos de programas\ATI Technologies\ATI.ACE\Graphics-Full-Existing Win32.Virut.56 Desinfectado.

Grid64.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

HydraDM.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

HydraDM64.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

HydraGrd.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

HydraMD.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

HydraMD64.exe H:\Arquivos de programas\ATI Technologies\HydraVision Win32.Virut.56 Desinfectado.

Oblivion.exe H:\Arquivos de programas\Bethesda Softworks\Oblivion Win32.Virut.56 Desinfectado.

OblivionLauncher.exe H:\Arquivos de programas\Bethesda Softworks\Oblivion Win32.Virut.56 Desinfectado.

cb_console_runner.exe H:\Arquivos de programas\CodeBlocks Win32.Virut.56 Desinfectado.

cb_share_config.exe H:\Arquivos de programas\CodeBlocks Win32.Virut.56 Desinfectado.

codeblocks.exe H:\Arquivos de programas\CodeBlocks Win32.Virut.56 Desinfectado.

addr2line.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

ar.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

as.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

c++.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

c++filt.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

cpp.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

dlltool.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

dllwrap.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

g++.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

gcc.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

gcov.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

gdb.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

gdbserver.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

gprof.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

ld.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

mingw32-c++.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

mingw32-g++.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

mingw32-gcc.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

ranlib.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

size.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

strings.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

strip.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

windmc.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

windres.exe H:\Arquivos de programas\CodeBlocks\MinGW\bin Win32.Virut.56 Desinfectado.

dlltool.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

ld.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

nm.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

objcopy.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

objdump.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

ranlib.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

strip.exe H:\Arquivos de programas\CodeBlocks\MinGW\i686-pc-mingw32\bin Win32.Virut.56 Desinfectado.

cc1.exe H:\Arquivos de programas\CodeBlocks\MinGW\libexec\gcc\mingw32\3.4.5 Win32.Virut.56 Desinfectado.

cc1plus.exe H:\Arquivos de programas\CodeBlocks\MinGW\libexec\gcc\mingw32\3.4.5 Win32.Virut.56 Desinfectado.

collect2.exe H:\Arquivos de programas\CodeBlocks\MinGW\libexec\gcc\mingw32\3.4.5 Win32.Virut.56 Desinfectado.

Bionic Raider.exe H:\Arquivos de programas\CodeBlocks\Projects\BIONIC_RAIDER\bin\Release Win32.Virut.56 Desinfectado.

CLDMA.exe H:\Arquivos de programas\CyberLink\PowerProducer Win32.Virut.56 Desinfectado.

CLDrvChk.exe H:\Arquivos de programas\CyberLink\PowerProducer Win32.Virut.56 Desinfectado.

YASU.exe H:\Arquivos de programas\DAEMON Tools Lite Win32.Virut.56 Desinfectado.

DVDDecrypter.exe H:\Arquivos de programas\DVD Decrypter Win32.Virut.56 Desinfectado.

DVD Shrink 3.1.exe H:\Arquivos de programas\DVD Shrink Win32.Virut.56 Desinfectado.

ePSXe.exe H:\Arquivos de programas\ePSXe Win32.Virut.56 Desinfectado.

DrXJ.exe H:\Arquivos de programas\Game Maker 7.0 Pro Win32.Virut.56 Desinfectado.

XVI32.exe H:\Arquivos de programas\Hexadecimal Editor XVI32\xvi32 Win32.Virut.56 Desinfectado.

hposfx08.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpospd08.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hposvc08.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpqdirec.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpqkygrp.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpqnrs08.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpqpprop.exe H:\Arquivos de programas\HP\Digital Imaging\bin Win32.Virut.56 Desinfectado.

hpzmsi01.exe H:\Arquivos de programas\HP\Digital Imaging\esupport Win32.Virut.56 Desinfectado.

hpzscr01.exe H:\Arquivos de programas\HP\Digital Imaging\esupport Win32.Virut.56 Desinfectado.

FlashPla.exe H:\Arquivos de programas\HP\Digital Imaging\Help\player Win32.Virut.56 Desinfectado.

hprblog.exe H:\Arquivos de programas\HP\Digital Imaging\Product Assistant\bin Win32.Virut.56 Desinfectado.

hprbui.exe H:\Arquivos de programas\HP\Digital Imaging\Product Assistant\bin Win32.Virut.56 Desinfectado.

hprbhelp.exe H:\Arquivos de programas\HP\Digital Imaging\Product Assistant\scache\hprbhelp Win32.Virut.56 Desinfectado.

hpzcdl01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C} Win32.Virut.56 Desinfectado.

hpzsetup.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C} Win32.Virut.56 Desinfectado.

hpzcdl01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzdui01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzmsi01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzpsl01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzshl01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzwrp01.exe H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzscr01.exe H:\Arquivos de programas\HP\Temp\{8B893833-F00F-47d8-A893-72CFA6A7E64C}\setup Win32.Virut.56 Desinfectado.

hpzmsi01.exe H:\Arquivos de programas\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzrcv01.exe H:\Arquivos de programas\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

hpzscr01.exe H:\Arquivos de programas\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup Win32.Virut.56 Desinfectado.

stacsv64.exe H:\Arquivos de programas\IDT\ECSXPV_5762_010208\WDM Win32.Virut.56 Desinfectado.

sttray.exe H:\Arquivos de programas\IDT\ECSXPV_5762_010208\WDM Win32.Virut.56 Desinfectado.

sttray64.exe H:\Arquivos de programas\IDT\ECSXPV_5762_010208\WDM Win32.Virut.56 Desinfectado.

suhlp.exe H:\Arquivos de programas\IDT\ECSXPV_5762_010208\WDM Win32.Virut.56 Desinfectado.

suhlp64.exe H:\Arquivos de programas\IDT\ECSXPV_5762_010208\WDM Win32.Virut.56 Desinfectado.

stacsv.exe H:\Arquivos de programas\IDT\WDM Win32.Virut.56 Desinfectado.

stacsv64.exe H:\Arquivos de programas\IDT\WDM Win32.Virut.56 Desinfectado.

sttray64.exe H:\Arquivos de programas\IDT\WDM Win32.Virut.56 Desinfectado.

suhlp.exe H:\Arquivos de programas\IDT\WDM Win32.Virut.56 Desinfectado.

suhlp64.exe H:\Arquivos de programas\IDT\WDM Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\InstallShield Installation Information\{43801800-CFEE-11D2-A41B-006097B55AD3} Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\InstallShield Installation Information\{631A0B87-B0B7-4B47-00A2-119A4B942EB6} Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\InstallShield Installation Information\{930B2432-43D4-11D5-9871-00C04F8EEB39} Win32.Virut.56 Desinfectado.

Setup.exe H:\Arquivos de programas\InstallShield Installation Information\{9B94BE6F-7CA3-4C40-A266-62667FF746CC} Win32.Virut.56 Desinfectado.

icwrmind.exe H:\Arquivos de programas\Internet Explorer\Connection Wizard Win32.Virut.56 Desinfectado.

icwtutor.exe H:\Arquivos de programas\Internet Explorer\Connection Wizard Win32.Virut.56 Desinfectado.

iv_uninstall.exe H:\Arquivos de programas\IrfanView Win32.Virut.56 Desinfectado.

i_view32.exe H:\Arquivos de programas\IrfanView Win32.Virut.56 Desinfectado.

Slideshow.exe H:\Arquivos de programas\IrfanView\Plugins Win32.Virut.56 Desinfectado.

UNWISE.EXE H:\Arquivos de programas\IRPF2009 Win32.Virut.56 Desinfectado.

java.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

javacpl.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

javaw.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

jucheck.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

jusched.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

keytool.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

kinit.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

orbd.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

pack200.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

policytool.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

rmid.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

rmiregistry.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

servertool.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

tnameserv.exe H:\Arquivos de programas\Java\jre1.5.0_06\bin Win32.Virut.56 Desinfectado.

java-rmi.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

java.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

javaw.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

javaws.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

keytool.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

kinit.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

klist.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

ktab.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

orbd.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

pack200.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

policytool.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

servertool.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

ssvagent.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

tnameserv.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

unpack200.exe H:\Arquivos de programas\Java\jre1.6.0_07\bin Win32.Virut.56 Desinfectado.

minst.exe H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD Win32.Virut.56 Desinfectado.

drvins32.exe H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\drivers Win32.Virut.56 Desinfectado.

MatroskaDiag.exe H:\Arquivos de programas\Matroska Pack\MatroskaDiag Win32.Virut.56 Desinfectado.

msmsgsin.exe H:\Arquivos de programas\Messenger Win32.Virut.56 Desinfectado.

copymar.exe H:\Arquivos de programas\MSN\MSNCoreFiles Win32.Virut.56 Desinfectado.

update.exe H:\Arquivos de programas\MSN\MSNCoreFiles Win32.Virut.56 Desinfectado.

msnunin.exe H:\Arquivos de programas\MSN\MSNCoreFiles\Setup Win32.Virut.56 Desinfectado.

hrtzzm.exe H:\Arquivos de programas\MSN Gaming Zone\Windows Win32.Virut.56 Desinfectado.

zClientm.exe H:\Arquivos de programas\MSN Gaming Zone\Windows Win32.Virut.56 Desinfectado.

cb32.exe H:\Arquivos de programas\NetMeeting Win32.Virut.56 Desinfectado.

wb32.exe H:\Arquivos de programas\NetMeeting Win32.Virut.56 Desinfectado.

NGZoom.exe H:\Arquivos de programas\NGZoom Win32.Virut.56 Desinfectado.

OpenALwEAX.exe H:\Arquivos de programas\OpenAL Win32.Virut.56 Desinfectado.

oemig50.exe H:\Arquivos de programas\Outlook Express Win32.Virut.56 Desinfectado.

uninstall.exe H:\Arquivos de programas\Perfect World International Win32.Virut.56 Desinfectado.

elementclient.exe H:\Arquivos de programas\Perfect World International\element Win32.Virut.56 Desinfectado.

elementlocalize.exe H:\Arquivos de programas\Perfect World International\element Win32.Virut.56 Desinfectado.

pwprotector.exe H:\Arquivos de programas\Perfect World International\element\reportbugs Win32.Virut.56 Desinfectado.

Launcher.exe H:\Arquivos de programas\Perfect World International\launcher Win32.Virut.56 Desinfectado.

patcher.exe H:\Arquivos de programas\Perfect World International\patcher Win32.Virut.56 Desinfectado.

desinstj.exe H:\Arquivos de programas\Programas RFB\Receitanet Java Win32.Virut.56 Desinfectado.

receitanet.exe H:\Arquivos de programas\Programas RFB\Receitanet Java Win32.Virut.56 Desinfectado.

UNWISE.EXE H:\Arquivos de programas\Programas RFB\Receitanet Java Win32.Virut.56 Desinfectado.

fixrjb.exe H:\Arquivos de programas\Real\RealPlayer Win32.Virut.56 Desinfectado.

realjbox.exe H:\Arquivos de programas\Real\RealPlayer Win32.Virut.56 Desinfectado.

rphelperapp.exe H:\Arquivos de programas\Real\RealPlayer Win32.Virut.56 Desinfectado.

LaunchGTAIV.exe H:\Arquivos de programas\Rockstar Games Win32.Virut.56 Desinfectado.

LaunchGTAIV.exe H:\Arquivos de programas\Rockstar Games\Grand Theft Auto IV Win32.Virut.56 Desinfectado.

RPG2003.EXE H:\Arquivos de programas\RPG2003 Win32.Virut.56 Desinfectado.

rpg_rt.exe H:\Arquivos de programas\RPG2003\Project\Project1 Win32.Virut.56 Desinfectado.

RPG_RT.exe H:\Arquivos de programas\RPG2003\Project\Project1\Projeto1 Win32.Virut.56 Desinfectado.

A Conta.exe H:\Arquivos de programas\RPG2003\Project\Project3 Win32.Virut.56 Desinfectado.

rpg_rt.exe H:\Arquivos de programas\RPG2003\Project\ProjectZero Win32.Virut.56 Desinfectado.

RPG_RT.exe H:\Arquivos de programas\RPG2003\Project\ProjectZero\Projeto1 Win32.Virut.56 Desinfectado.

carmlic.exe H:\Arquivos de programas\Slacksoft\Macro XP 4 Win32.Virut.56 Desinfectado.

MacroXP4.exe H:\Arquivos de programas\Slacksoft\Macro XP 4 Win32.Virut.56 Desinfectado.

mXPUtilityStub.exe H:\Arquivos de programas\Slacksoft\Macro XP 4 Win32.Virut.56 Desinfectado.

SDFiles.exe H:\Arquivos de programas\Spybot - Search & Destroy Win32.Virut.56 Desinfectado.

SDShred.exe H:\Arquivos de programas\Spybot - Search & Destroy Win32.Virut.56 Desinfectado.

StarUML.exe H:\Arquivos de programas\StarUML Win32.Virut.56 Desinfectado.

SWFCacheViewer.exe H:\Arquivos de programas\SWF Opener Win32.Virut.56 Desinfectado.

SWFOpener.exe H:\Arquivos de programas\SWF Opener Win32.Virut.56 Desinfectado.

CookerSync.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

ISCopyFiles.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

ueScriptProfiler.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

UnrealConsole.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

UnrealFrontend.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

UT3OSHelper.exe H:\Arquivos de programas\Unreal Tournament 3\Binaries Win32.Virut.56 Desinfectado.

ffmpeg.exe H:\Arquivos de programas\vdownloader Win32.Virut.56 Desinfectado.

vlc.exe H:\Arquivos de programas\VideoLAN\VLC Win32.Virut.56 Desinfectado.

ccrypt.exe H:\Arquivos de programas\WinAce Win32.Virut.56 Desinfectado.

helpinst.exe H:\Arquivos de programas\WinAce Win32.Virut.56 Desinfectado.

order.exe H:\Arquivos de programas\WinAce Win32.Virut.56 Desinfectado.

sxuninst.exe H:\Arquivos de programas\WinAce Win32.Virut.56 Desinfectado.

wb_setup.exe H:\Arquivos de programas\WinAce Win32.Virut.56 Desinfectado.

winampa.exe H:\Arquivos de programas\Winamp Win32.Virut.56 Desinfectado.

wmccds.exe H:\Arquivos de programas\Windows Media Connect 2 Win32.Virut.56 Desinfectado.

WMCCFG.exe H:\Arquivos de programas\Windows Media Connect 2 Win32.Virut.56 Desinfectado.

migrate.exe H:\Arquivos de programas\Windows Media Player Win32.Virut.56 Desinfectado.

setup_wm.exe H:\Arquivos de programas\Windows Media Player Win32.Virut.56 Desinfectado.

wmdbexport.exe H:\Arquivos de programas\Windows Media Player Win32.Virut.56 Desinfectado.

wmpenc.exe H:\Arquivos de programas\Windows Media Player Win32.Virut.56 Desinfectado.

wmpshare.exe H:\Arquivos de programas\Windows Media Player Win32.Virut.56 Desinfectado.

Rar.exe H:\Arquivos de programas\WinRAR Win32.Virut.56 Desinfectado.

Uninstall.exe H:\Arquivos de programas\WinRAR Win32.Virut.56 Desinfectado.

UnRAR.exe H:\Arquivos de programas\WinRAR Win32.Virut.56 Desinfectado.

WZQKPICK.EXE H:\Arquivos de programas\WinZip Win32.Virut.56 Desinfectado.

WZSEPE32.EXE H:\Arquivos de programas\WinZip Win32.Virut.56 Desinfectado.

zsnesw.exe H:\Arquivos de programas\ZSNES Win32.Virut.56 Desinfectado.

SetupUT3.exe H:\Documents and Settings\Jorge\Configurações locais\Temp\{24AC30DE-44C4-451D-A0E7-1DC5627E5597} Win32.Virut.56 Desinfectado.

ersj[1].exe H:\Documents and Settings\Jorge\Configurações locais\Temporary Internet Files\Content.IE5\XP5XZZB9 Win32.Virut.56 Desinfectado.

ersj[1].exe H:\Documents and Settings\Jorge\Configurações locais\Temporary Internet Files\Content.IE5\XP5XZZB9 Win32.Virut.56 Desinfectado.

irfanview423_setup.exe H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS Win32.Virut.56 Desinfectado.

AviMaker.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\AviMaker Win32.Virut.56 Desinfectado.

CM1999.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\CM1999 Win32.Virut.56 Desinfectado.

Idraw3.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\idraw Win32.Virut.56 Desinfectado.

i_view32.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\iview Win32.Virut.56 Desinfectado.

Name.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\name Win32.Virut.56 Desinfectado.

Setup.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\senhas\input_numbers_demo Win32.Virut.56 Desinfectado.

RPG_RT.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\X-Y Win32.Virut.56 Desinfectado.

HJSplit.exe H:\Downloads\Grand Theft Auto IV Win32.Virut.56 Desinfectado.

LaunchGTAIV.exe H:\Downloads\Grand Theft Auto IV\Crack Win32.Virut.56 Desinfectado.

install.exe H:\Downloads\Perfect World International\PW Install Pack Win32.Virut.56 Desinfectado.

dap75.exe/data018\dapiebar.dll H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS\dap75.exe/data018 Adware.IEBar

SDFix.exe\SDFix\apps\Process.exe H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS\SDFix.exe Tool.Prockill

SDFix.exe\SDFix\apps\HPFix.reg H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS\SDFix.exe Trojan.StartPage.1505

SDFix.exe\SDFix\apps\HPFix2.reg H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS\SDFix.exe Trojan.StartPage.1505

RegUBP2b-Jorge.reg H:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Eliminado.

abb[1].txt H:\Documents and Settings\Jorge\Configurações locais\Temporary Internet Files\Content.IE5\XP5XZZB9 Trojan.DownLoad.29459 Eliminado.

Name.exe H:\Documents and Settings\Jorge\Meus documentos\Nova Pasta Texts\Tutorials\Tools\name Trojan.PWS.Systrem.9 Eliminado.

data018 H:\Documents and Settings\Jorge\Meus documentos\NEW PROGRAMS O arquivo contém objectos infectados

------------------------------------------------

 

...e o log do HijackThis atualizado:

 

------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 23:13:35, on 8/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\Explorer.EXE

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [servises] H:\WINDOWS\system32\servises.exe

O4 - Startup: is-C5IBD.lnk = H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\startup.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

------------------------------------------------

 

Muito grato pela paciência e apoio até agora. Aguardo resposta.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

O vírus em questão afeta executáveis como você mesmo percebeu, às vezes programas deixam de funcionar devido a eles.

 

Peço a você que ative e desative a restauração do sistema, será de grande importância.

 

Vamos trabalhar novamente, vou colocar os procedimentos em etapas. Por favor, peço que as respeites.

 

1° Etapa.

 

Baixe:

 

rmvirut.exe:

http://www.grisoft.cz/filedir/util/avg_rem...rut/rmvirut.exe

 

rmvirut.nt

http://www.grisoft.cz/filedir/util/avg_rem...irut/rmvirut.nt

 

Salve-os em uma mesma pasta, por exemplo: H:\Virut <- Crie

 

Reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e selecione a opção de Modo Seguro;

 

Vá até Iniciar --> Executar -> Digite:

 

H:\Virut\rmvirut.exe H:

 

Clique em OK.

 

OBS: Caso possua outras unidades de disco,adicione-as ao comando,da seguinte forma:

 

H:\Virut\rmvirut.exe C: D:

 

Aguarde a conclusão! --> Aperte Enter.

 

O computador será reiniciado.

________________________________

 

Agora execute o Malwarebites.

 

• Vá a este Link,e baixe: < Malwarebytes >

Atualize o programa!

• Escolha a verficação completa <- Importante

Desabilite programas de proteção,ao executar o malwarebytes.

• Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

• Para maiores detalhes: < Link >

-----------------------

• Poste, os relatórios: mbam-log-2008-xx-xx (00-00-00).txt + HijackThis,atualizado.

• O scan pode ser demorado portanto seja paciente.

 

Diga como estar o PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN,

 

executei o rmvirut em modo de segurança através do Executar como instruído, e aparentemente ele não encontrou nenhum arquivo infectado. Após a reinicialização que se seguiu, porém, alguns novos erros apareceram, como o AVG voltando a detectar trojans na inicialização (um trojan diferente desta vez, detectou e deletou o mesmo três vezes seguidas):

 

threati.png

 

Também não consegui desinstalar nem reparar o Catalyst da placa de vídeo nem o Daemon Tools. O segundo resolvi por deletar todas as pastas que o mesmo utilizava no computador, o que aparentemente terminou com as mensagens de erro, mas agora não consigo reinstalá-lo novamente - tentei até mesmo baixar uma nova cópia do Setup, sem sucesso. Vou tentar rodar o CC Cleaner após publicar esse post para ver se resolve. Já quanto ao Catalyst, tenho medo de desinstalá-lo pois é uma parte crucial do software gráfico da placa de vídeo, e não possuo o CD/DVD de instalação da mesma (se é que ela possuía um) já que nunca me fora dado após a compra desta máquina. O erro de script continua acusando o MOM.exe como corrompido.

 

As boas notícias são que, após a verificação do Malwarebytes (desabilitei o AVG para tal), que encontrou alguns arquivos infectados e acredito tê-los removido, a internet voltou completamente ao normal. O modem não mais sinaliza transição de dados constante, e a velocidade está perfeita. Pelo menos este vírus está garantido que foi removido.

 

Segue o log do Malwarebytes (mbam-log-2009-07-09.txt):

 

----------------------------------------------

Malwarebytes' Anti-Malware 1.38

Versão do banco de dados: 2297

Windows 5.1.2600 Service Pack 3

 

9/7/2009 21:24:34

mbam-log-2009-07-09 (21-24-34).txt

 

Tipo de Verificação: Completa (H:\|)

Objetos verificados: 175501

Tempo decorrido: 36 minute(s), 56 second(s)

 

Processos da Memória infectados: 1

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 6

Ítens do Registro infectados: 3

Pastas infectadas: 1

Arquivos infectados: 18

 

Processos da Memória infectados:

H:\WINDOWS\system32\servises.exe (Trojan.Agent) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\servises (Trojan.Agent) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Pastas infectadas:

h:\documents and settings\Jorge\Dados de aplicativos\dxdlls (Worm.Autorun) -> Quarantined and deleted successfully.

 

Arquivos infectados:

H:\WINDOWS\system32\servises.exe (Trojan.FakeAlert.H) -> Delete on reboot.

h:\documents and settings\Jorge\dados de aplicativos\dxdlls\ActMon.ini (Worm.Autorun) -> Quarantined and deleted successfully.

H:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\8.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\9.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\B.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\C.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

h:\WINDOWS\system32\F.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

H:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.

----------------------------------------------

 

...e o Log do HijackThis atualizado:

 

----------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 21:51:46, on 9/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\System32\svchost.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\spoolsv.exe

H:\WINDOWS\Explorer.EXE

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\ctfmon.exe

H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\System32\svchost.exe

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\ARQUIV~1\AVG\AVG8\avgemc.exe

H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

H:\WINDOWS\system32\wscntfy.exe

H:\WINDOWS\system32\svchost.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O1 - Hosts: 92.241.176.188 advanced-virus-remover2009.com

O1 - Hosts: 92.241.176.188 www.advanced-virus-remover2009.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - Startup: is-C5IBD.lnk = H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\startup.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

----------------------------------------------

 

Alguma sugestão quanto ao novo trojan que o AVG passou a detectar? Ou algo à respeito do fato de não conseguir desinstalar/reinstalar os dois softwares que estavam acusando erros? Estou extremamente grato pelo seu apoio até agora, graças à ele vou poder participar sem problemas das aulas de Ensino à Distância da faculdade este mês. Muitíssimo obrigado.

 

No aguardo de novas informações.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Lucied, Tenha uma boa tarde.

 

- Faça o download do Avenger Salve no seu Desktop (área de trabalho).

 

      • Selecione e copie o texto abaixo (Ctrl + C)

 

Files to delete:

H:\WINDOWS\system32\servises.exe

 

      • Execute o programa;

      • Na caixa que se abrir, cole o que foi copiado acima;

      • Clique em "Execute";

      • O PC será reiniciado;

      • Copie o conteúdo do bloco de notas e poste aqui.

 

-- Foi você quem criou esse arquivo host?

 

O1 - Hosts: 92.241.176.188 advanced-virus-remover2009.com

O1 - Hosts: 92.241.176.188 www.advanced-virus-remover2009.com

 

-- Fez os passos da restauração do sistema?

http://forum.imasters.com.br/index.php?showtopic=143766

 

Execute as ferramentas abaixo na ordem por favor.

 

Baixe o Kaspersky AVP Tool

http://downloads5.kaspersky-labs.com/devbuilds/AVPTool/

 

Salve-o em sua área de trabalho.

 

Execute o arquivo e vá seguindo os prompts.

Quando terminar, marque a caixa ao lado de Meu Computador, e depois clique em Scan

 

Tenha paciência, é um pouco demorado.

 

Quando terminar, caso tenha detectado algo, o programa irá lhe perguntar o que fazer.

Clique em Skip (queremos apenas o log).

 

Obs: Talvez seja necessário clicar em Skip várias vezes, caso o programa encontre vários arquivos, portanto seja paciente.

 

Quando o programa exibir a mensagem Scan Completed, clique na aba Events, desmarque a caixa de seleção "Show all events" e depois clique em "Save to file".

Salve o log em local de fácil acesso.

 

Baixe > GMER

 

Extraia os seus arquivos para o desktop.

 

Dê um duplo-clique no gmer.exe. Clique na aba Rootkit e depois no botão Scan.

 

IMPORTANTE: Não marque a caixa Show All.

 

Quando o scan acabar, clique em Copy para copiar o conteúdo para a área de transferência.

Abra o bloco de notas e cole o que copiou, e salve com o nome que desejar.

 

Copie e cole o conteúdo desse bloco de notas na sua resposta + o log do Kaspersky AVP Tool (não precisa colocar os Events deste log).

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá. Desculpe a demora a responder, os scans realmente levaram muitas horas.

 

Primeiro, respondendo à sua pergunta, não fui eu quem criou os arquivos (hosts) citados, mas procurei na internet e parece que podem ser vírus. Quanto à restauração do sistema, também a ativei e em seguida desativei (aliás, está desativada desde de seu penúltimo post).

 

Executei o Avenger com o texto copiado, mas aparentemente ele não encontrou o arquivo especificado (servises.exe). De fato, no último log do HijackThis, que coloquei em meu post anterior a este, o arquivo em questão não estava mais entre os processos correntes, o que me fez entender que ele havia sido eliminado. Até pensei que ele seria o responsável pela internet lenta, e que sua eliminação seria a razão da mesma ter voltado ao normal.

 

Vou colocar o log do Avenger para você averiguar:

 

-----------------------------------------------------

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at H:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

 

Error: file "H:\WINDOWS\system32\servises.exe" not found!

Deletion of file "H:\WINDOWS\system32\servises.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

 

 

Completed script processing.

 

*******************

 

Finished! Terminate.

-----------------------------------------------------

 

...Parece, porém, que um arquivo infectado diferente, de nome semelhante ao servises.exe, foi acusado como ameaça pelo AVG na última inicialização do PC, junto à uma nova infecção de Win32/Heur. O arquivo se chama "services.exe", e este de fato ainda está presente no computador, como mostra o log de HijackThis mais recente que também vou colocar aqui, por precaução:

 

-----------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 19:05:29, on 10/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\System32\svchost.exe

H:\WINDOWS\system32\spoolsv.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\Explorer.EXE

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\ctfmon.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\System32\svchost.exe

H:\ARQUIV~1\AVG\AVG8\avgemc.exe

H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\system32\wuauclt.exe

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O1 - Hosts: 92.241.176.188 advanced-virus-remover2009.com

O1 - Hosts: 92.241.176.188 www.advanced-virus-remover2009.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - Startup: is-C5IBD.lnk = H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\startup.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.ex

-----------------------------------------------------

 

Imagem da detecção de infecção do Resident Shield do AVG:

 

threats.png

 

Quanto aos scans dos outros programas, primeiro tenho uma questão: o Kaspersky AVP Tool por acaso é o mesmo Kaspersky Virus Removal Tool que você me instruiu a baixar anteriormente? Tive problemas com o link que você cedeu, mas baixei por um outro site e aparentemente é o mesmo programa. Aliás, parece que não consigo acessar nenhum site de anti-vírus... Tentei os sites do Kaspersky, AVG, Avast, Avira... Nenhum me permite entrada.

 

Independente disso, rodei o scan do AVP Tool e me assustei com os resultados; mais de 3000 infecções, sendo boa parte delas novos executáveis infectados pelo Win32/Virut e outra parte muitos arquivos de formatos diferentes infectados por um Trojan o qual não sei se é perigoso ou não. Como recomendado, dei skip em todos. O log final ficou longo demais e o fórum não deixou-me postar a mensagem, por esse motivo estou colocando o link de um arquivo texto com o mesmo (sem os eventos):

 

 

LINK: http://rapidshare.com/files/254350039/kasp...vp_log.txt.html

 

 

...Esse enorme número de infecções me deixou muito preocupado, pois pensava estar quase livre dessas pragas. Em seguida, rodei o GMER como instruído e salvei o seguinte log (com a opção "Show All" desmarcada):

 

-----------------------------------------------------

GMER 1.0.15.14972 - http://www.gmer.net

Rootkit scan 2009-07-10 18:26:43

Windows 5.1.2600 Service Pack 3

 

 

---- System - GMER 1.0.15 ----

 

INT 0x62 ? 8A6FFBF8

INT 0x73 ? 8A6FFBF8

INT 0x82 ? 8A6FFBF8

INT 0x83 ? 8A423E68

INT 0x83 ? 8A423E68

INT 0x83 ? 8A423E68

INT 0xA4 ? 8A423E68

INT 0xB4 ? 8A423E68

INT 0xB4 ? 8A423E68

INT 0xB4 ? 8A423E68

 

---- Kernel code sections - GMER 1.0.15 ----

 

? myupflpm.sys O sistema não pode encontrar o arquivo especificado. !

? spch.sys O sistema não pode encontrar o arquivo especificado. !

.text USBPORT.SYS!DllUnload B76C98AC 5 Bytes JMP 8A423448

.text vaxscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 B76684D0 48 Bytes [4B, DA, 5A, 42, 86, 36, 5F, ...]

? H:\WINDOWS\System32\Drivers\vaxscsi.sys O arquivo já está sendo usado por outro processo.

? system32\DRIVERS\11859449.sys O sistema não pode encontrar o caminho especificado. !

 

---- User code sections - GMER 1.0.15 ----

 

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe[180] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.reloc H:\WINDOWS\Explorer.EXE[436] H:\WINDOWS\Explorer.EXE section is executable [0x010FB000, 0x8800, 0xE0000040]

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\Explorer.EXE[436] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\HPZipm12.exe[536] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\ARQUIV~1\AVG\AVG8\avgrsx.exe[556] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe[596] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe[672] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF9484E

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF948DD

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF948EA

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FF94B6E

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF948D3

.text H:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF9492B

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF9484E

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF948DD

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF948EA

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FF94B6E

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF948D3

.text H:\WINDOWS\system32\services.exe[768] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF9492B

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF9484E

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF948DD

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF948EA

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FF94B6E

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF948D3

.text H:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF9492B

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\Ati2evxx.exe[964] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\system32\svchost.exe[984] H:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\svchost.exe[984] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\ARQUIV~1\AVG\AVG8\avgnsx.exe[1008] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\system32\svchost.exe[1052] H:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\svchost.exe[1052] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\System32\svchost.exe[1148] H:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FF9484E

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FF948DD

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FF948EA

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FF94B6E

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FF948D3

.text H:\WINDOWS\System32\svchost.exe[1148] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FF9492B

.rsrc H:\WINDOWS\System32\svchost.exe[1268] H:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\System32\svchost.exe[1268] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe[1288] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\System32\svchost.exe[1304] H:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\System32\svchost.exe[1304] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\ARQUIV~1\AVG\AVG8\avgtray.exe[1324] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe[1364] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\Ati2evxx.exe[1416] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\spoolsv.exe[1452] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\IDT\WDM\sttray.exe[1580] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Documents and Settings\Jorge\Desktop\gmer.exe[1648] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\Java\jre6\bin\jqs.exe[1812] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe[1924] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\Java\jre6\bin\jusched.exe[1976] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[2024] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\ctfmon.exe[2036] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[2116] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\System32\svchost.exe[2128] H:\WINDOWS\System32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\System32\svchost.exe[2128] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\ARQUIV~1\AVG\AVG8\avgemc.exe[2172] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe[2440] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

.rsrc H:\WINDOWS\system32\svchost.exe[3932] H:\WINDOWS\system32\svchost.exe section is executable [0x01005000, 0x5600, 0xE0000040]

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtCreateFile 7C90D090 5 Bytes CALL 7FFA484E

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtCreateProcess 7C90D130 5 Bytes CALL 7FFA48DD

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtCreateProcessEx 7C90D140 5 Bytes CALL 7FFA48EA

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtDeviceIoControlFile 7C90D260 5 Bytes CALL 7FFA4B6E

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtOpenFile 7C90D580 5 Bytes CALL 7FFA48D3

.text H:\WINDOWS\system32\svchost.exe[3932] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes CALL 7FFA492B

 

---- Kernel IAT/EAT - GMER 1.0.15 ----

 

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [b9EA9040] spch.sys

IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [b9EA913C] spch.sys

IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [b9EA90BE] spch.sys

IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [b9EA97FC] spch.sys

IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [b9EA96D2] spch.sys

IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [b9EB9048] spch.sys

 

---- Devices - GMER 1.0.15 ----

 

Device \FileSystem\Ntfs \Ntfs 8A6FE1F8

Device \FileSystem\Fastfat \FatCdrom 8A399500

 

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

 

Device \Driver\usbohci \Device\USBPDO-0 8A45F500

Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A6A01F8

Device \Driver\dmio \Device\DmControl\DmConfig 8A6A01F8

Device \Driver\dmio \Device\DmControl\DmPnP 8A6A01F8

Device \Driver\dmio \Device\DmControl\DmInfo 8A6A01F8

Device \Driver\usbohci \Device\USBPDO-1 8A45F500

Device \Driver\usbohci \Device\USBPDO-2 8A45F500

Device \Driver\usbehci \Device\USBPDO-3 8A40A500

Device \Driver\usbohci \Device\USBPDO-4 8A45F500

 

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

 

Device \Driver\usbohci \Device\USBPDO-5 8A45F500

Device \Driver\usbehci \Device\USBPDO-6 8A40A500

Device \Driver\Ftdisk \Device\HarddiskVolume1 8A7001F8

Device \Driver\Cdrom \Device\CdRom0 8A426500

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

Device \Driver\NetBT \Device\NetBt_Wins_Export 8A401500

Device \Driver\PCI_PNP9342 \Device\0000004a spch.sys

Device \Driver\NetBT \Device\NetbiosSmb 8A401500

Device \Driver\NetBT \Device\NetBT_Tcpip_{11E93C6D-F3FB-419F-BF96-60586D109CC7} 8A401500

 

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

 

Device \Driver\usbohci \Device\USBFDO-0 8A45F500

Device \Driver\usbohci \Device\USBFDO-1 8A45F500

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A44A428

Device \Driver\usbehci \Device\USBFDO-2 8A40A500

Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A44A428

Device \Driver\usbohci \Device\USBFDO-3 8A45F500

Device \Driver\usbohci \Device\USBFDO-4 8A45F500

Device \Driver\Ftdisk \Device\FtControl 8A7001F8

Device \Driver\usbehci \Device\USBFDO-5 8A40A500

Device \Driver\usbohci \Device\USBFDO-6 8A45F500

Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 8A42B3C8

Device \FileSystem\Fastfat \Fat 8A399500

 

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

Device \FileSystem\is-EAK15drv \FileSystem\Filters\is-EAK15drv 11859449.sys

Device \FileSystem\Cdfs \Cdfs 8A374500

 

---- Registry - GMER 1.0.15 ----

 

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 H:\Arquivos de programas\Alcohol Soft\Alcohol 120\

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x5F 0x22 0x85 0x7C ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x88 0xEE 0xDE 0x66 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x16 0xBF 0x9B 0x05 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x32 0x85 0x68 0xCA ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 H:\Arquivos de programas\DAEMON Tools Lite\

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5C 0xA4 0xA5 0x39 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC9 0x80 0x1D 0x2B ...

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB2 0xB1 0x60 0x5E ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 H:\Arquivos de programas\Alcohol Soft\Alcohol 120\

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x5F 0x22 0x85 0x7C ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x88 0xEE 0xDE 0x66 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x16 0xBF 0x9B 0x05 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x32 0x85 0x68 0xCA ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 H:\Arquivos de programas\DAEMON Tools Lite\

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5C 0xA4 0xA5 0x39 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xC9 0x80 0x1D 0x2B ...

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xB2 0xB1 0x60 0x5E ...

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1

 

---- EOF - GMER 1.0.15 ----

-----------------------------------------------------

 

Os problemas pareciam piorar, mas derrepente melhoraram, e agora voltam a piorar. Felizmente o computador parece não estar sofrendo de nenhuma perda de performance. Qual o próximo passo? Obrigado pela ajuda.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o HostsXpert Descompacte, abra o Programa, clique em Restore MS Hosts File.

 

Siga agora os procedimentos abaixo;

 

Primeiramente você deve baixar e instalar o Patch da Microsoft

 

http://www.microsoft.com/technet/security/...n/MS08-067.mspx

Se não conseguir, tente este:

http://mscom-dlcecn.vo.llnwd.net/download/...890830-v2.6.exe

 

Baixe as Ferramentas a seguir e as execute

 

OBS: Após o download, desconecte-se da Rede e da Internet.

 

(Este Vírus tem a capacidade de baixar novos arquivos pela Internet, espalhando-se pela Rede, impossibilitando a desinfecção.)

 

Use sempre a conta de Administrador para a limpeza.

 

Se você estiver em Rede, limpe uma máquina de cada vez

 

McAfee Conficker Detection Tool

 

Sophos Conficker Clean-up Tool 1.3

 

EConfickerRemover.exe

 

W32.Downadup Removal Tool

 

F-Downadup Removal Tool by F-Secure

 

Baixe e descompacte. Execute o .exe e aguarde a limpeza.

 

MSRT by Microsoft - Malicious Software Removal Tool (KB890830)

 

http://www.microsoft.com/downloads/details...b3-75b8eb148356 (32 bits)

http://www.microsoft.com/downloads/details...E7-6349F4EFFC74 (64 bits)

 

Fontes: Baboo, Linha Defensiva, vários Sites/Fóruns de Informática em geral..

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN,

 

baixei o HostXpert, McAfee Conficker Detection Tool, Sophos Conficker Clean-up Tool, EConfickerRemover, W32.Downadup Removal Tool e F-Downadup Removal Tool, mas os links para o patch e MRST da Microsoft levaram para uma página de busca sem resultados.

 

Acredito que as reticências (...) nos links possam ser o problema. Você chegou a verificá-los? Poderia postar links alternativos?

 

Vou esperar até sua resposta sem executar os programas que já baixei. Obrigado.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desculpe amigo.

 

Patch: (So execute as ferramentas depois que baixar esse patch, pois se você não instalá-lo. Será reinfectado).

http://www.microsoft.com/technet/security/...n/MS08-067.mspx

 

MSRT by Microsoft - Malicious Software Removal Tool (Esse procedimento pode ser deixado para depois caso não consiga).

http://www.microsoft.com/security/malwareremove/default.aspx

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá PedroN.

 

Desculpe a demora em responder, estive muito atarefado este fim de semana, mas consegui baixar todas as ferramentas e executá-las como instruído.

 

Instalei o Patch MS08-067, executei o HostXpert e em seguida desabilitei a conexão. Após isso, executei os EConficker Remover e os removers do McAfee, Sophon, Symantec e F-Secure. Nenhum deles encontrou uma infecção por Conficker no meu PC.

 

Finalmente, executei o Malicious Software Removal Tool da Microsoft e, esse sim, achou uma única infecção, a qual supostamente removeu.

 

infection.png

 

Enquanto minha conexão estava desabilitada, o AVG não detectou nenhum vírus na inicialização como estava fazendo antes, mas assim que a reconectei para postar aqui, ele já identificou os mesmos vírus novamente.

 

Acredito que no final isso signifique que meu problema não é o Conficker, mas algo mais, que ainda está presente. Aquele "services.exe" ainda é a minha principal preocupação. Estou postando um novo log do HijackThis, para você averiguar a situação atual:

 

--------------------------------------------------

Logfile of HijackThis v1.99.1

Scan saved at 21:38:05, on 12/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

 

Running processes:

H:\WINDOWS\System32\smss.exe

H:\WINDOWS\system32\winlogon.exe

H:\WINDOWS\system32\services.exe

H:\WINDOWS\system32\lsass.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\svchost.exe

H:\WINDOWS\System32\svchost.exe

H:\WINDOWS\system32\Ati2evxx.exe

H:\WINDOWS\system32\spoolsv.exe

H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

H:\Arquivos de programas\Java\jre6\bin\jqs.exe

H:\ARQUIV~1\AVG\AVG8\avgrsx.exe

H:\ARQUIV~1\AVG\AVG8\avgnsx.exe

H:\WINDOWS\system32\HPZipm12.exe

H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

H:\WINDOWS\System32\svchost.exe

H:\ARQUIV~1\AVG\AVG8\avgemc.exe

H:\WINDOWS\Explorer.exe

H:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

H:\WINDOWS\system32\csrcs.exe

H:\ARQUIV~1\AVG\AVG8\avgtray.exe

H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

H:\Arquivos de programas\IDT\WDM\sttray.exe

H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

H:\Arquivos de programas\Java\jre6\bin\jusched.exe

H:\WINDOWS\system32\ctfmon.exe

H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

H:\Arquivos de programas\Mozilla Firefox\firefox.exe

H:\WINDOWS\system32\svchost.exe

H:\Arquivos de programas\HijackThis\HijackThis.exe

H:\WINDOWS\system32\cmd.exe

H:\WINDOWS\system32\net.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - H:\Arquivos de programas\BitComet\tools\BitCometBHO.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conex? do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [AVG8_TRAY] H:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"

O4 - HKLM\..\Run: [sysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

O4 - HKLM\..\Run: [iMJPMIG8.1] "H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] H:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [startCCC] "H:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE

O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "H:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] H:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iSUSPM] "H:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [DAEMON Tools Lite] "H:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - Startup: is-C5IBD.lnk = H:\Arquivos de programas\Kaspersky Virus Removal Tool\is-C5IBD\startup.exe

O8 - Extra context menu item: Baixar com &BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos com BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Download all videos using BitComet - res://H:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1224693924984

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS1\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O17 - HKLM\System\CS2\Services\Tcpip\..\{11E93C6D-F3FB-419F-BF96-60586D109CC7}: NameServer = 201.10.1.2,201.10.120.3

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - H:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - H:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - h:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)

O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Audio Service (STacSV) - IDT, Inc. - h:\arquivos de programas\idt\ecsxpv_5762_010208\wdm\STacSV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--------------------------------------------------

 

Obrigado, fico no aguardo do próximo passo.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tente agora rodar o comboFix como descrito no Post #2, caso não consiga tente em modo segurança, poste o log do programa.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN,

 

novamente não consegui rodar o ComboFix normalmente, mas o fiz em modo de segurança. Como em tal modo, porém, não há acesso à internet, não fui capaz de baixar um programa o qual o ComboFix recomendou fazer o download (Console de Recuperação). Segue o log:

 

---------------------------------------

ComboFix 09-07-12.03 - Jorge 13/07/2009 2:11.1.4 - NTFSx86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.3327.2961 [GMT -3:00]

Executando de: h:\documents and settings\Jorge\Desktop\Virus Removal Tools\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

 

ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

h:\documents and settings\Jorge\reader_s.exe

h:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb

h:\windows\system32\_id.dat

h:\windows\system32\3.tmp

h:\windows\system32\4.tmp

h:\windows\system32\6.tmp

h:\windows\system32\9.tmp

h:\windows\system32\A.tmp

h:\windows\system32\ATIODCLI.exe

h:\windows\system32\ATIODE.exe

h:\windows\system32\AutoRun.inf

h:\windows\system32\B.tmp

h:\windows\system32\csrcs.exe

h:\windows\system32\E.tmp

h:\windows\system32\F.tmp

h:\windows\system32\reader_s.exe

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-06-13 to 2009-07-13 ))))))))))))))))))))))))))))

.

 

2009-07-13 05:04 . 2009-07-13 05:04 212224 -c--a-w- h:\windows\system32\dllcache\ndis.sys

2009-07-12 19:47 . 2008-10-15 16:36 337408 -c----w- h:\windows\system32\dllcache\netapi32.dll

2009-07-09 23:45 . 2009-07-09 23:45 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\Malwarebytes

2009-07-09 23:45 . 2009-06-17 14:27 38160 ----a-w- h:\windows\system32\drivers\mbamswissarmy.sys

2009-07-09 23:45 . 2009-07-09 23:45 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-07-09 23:45 . 2009-07-09 23:45 -------- d-----w- h:\arquivos de programas\Malwarebytes' Anti-Malware

2009-07-09 23:45 . 2009-06-17 14:27 19096 ----a-w- h:\windows\system32\drivers\mbam.sys

2009-07-09 20:21 . 2009-07-09 20:21 -------- d-----w- H:\Virut

2009-07-08 23:43 . 2009-07-09 00:57 -------- d-----w- h:\documents and settings\Jorge\DoctorWeb

2009-07-08 19:23 . 2009-07-13 05:06 21831712 --sha-w- h:\windows\system32\drivers\fidbox.dat

2009-07-08 19:23 . 2008-07-08 17:54 148496 ----a-w- h:\windows\system32\drivers\02786923.sys

2009-07-08 00:13 . 2008-04-13 22:20 579072 -c--a-w- h:\windows\system32\dllcache\user32.dll

2009-07-08 00:11 . 2009-07-08 00:12 -------- d-----w- h:\windows\ERUNT

2009-07-08 00:07 . 2009-07-08 00:26 -------- d-----w- H:\SDFix

2009-07-07 23:03 . 2009-07-10 19:11 73728 ----a-w- h:\windows\PSEXESVC.EXE

2009-07-07 20:52 . 2009-07-07 20:52 664 ----a-w- h:\windows\system32\d3d9caps.dat

2009-07-07 01:23 . 2009-07-07 01:23 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\GetRightToGo

2009-07-07 00:25 . 2005-05-10 21:54 258352 ----a-w- h:\windows\system32\unicows.dll

2009-07-06 23:47 . 2009-07-08 01:45 -------- d-----w- h:\arquivos de programas\Perfect World International

2009-06-25 20:39 . 2009-06-25 20:39 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\Locktime

2009-06-25 20:33 . 2009-06-25 20:33 107888 ----a-w- h:\windows\system32\CmdLineExt.dll

2009-06-24 19:26 . 2009-06-25 20:41 -------- d-----w- h:\arquivos de programas\Rockstar Games

2009-06-24 18:55 . 2009-06-24 18:55 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\DAEMON Tools Pro

2009-06-24 18:55 . 2009-06-24 18:55 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\DAEMON Tools

2009-06-24 18:54 . 2009-06-24 18:54 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite

2009-06-24 18:50 . 2009-06-24 19:24 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\DAEMON Tools Lite

2009-06-18 23:19 . 2009-06-18 23:19 162432 ----a-w- h:\windows\system32\drivers\ithsgt.sys

2009-06-18 23:19 . 2009-06-18 23:19 12032 ----a-w- h:\windows\system32\drivers\lilsgt.sys

2009-06-16 00:37 . 2009-06-16 00:37 -------- d-----w- h:\arquivos de programas\NVIDIA Corporation

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-07-13 05:06 . 2009-07-08 19:23 256916 --sha-w- h:\windows\system32\drivers\fidbox.idx

2009-07-13 05:04 . 2002-08-29 02:09 212224 ----a-w- h:\windows\system32\drivers\ndis.sys

2009-07-13 05:04 . 2009-07-13 05:04 18432 ----a-w- h:\windows\system32\3B.tmp

2009-07-13 05:04 . 2009-07-13 05:04 84 ----a-w- h:\windows\system32\38.tmp

2009-07-13 04:51 . 2009-07-13 04:51 0 ----a-w- h:\windows\system32\39.tmp

2009-07-13 04:51 . 2009-07-13 04:51 84 ----a-w- h:\windows\system32\36.tmp

2009-07-13 00:27 . 2009-07-13 00:27 0 ----a-w- h:\windows\system32\37.tmp

2009-07-13 00:27 . 2009-07-13 00:27 84 ----a-w- h:\windows\system32\34.tmp

2009-07-12 18:37 . 2009-07-12 18:37 0 ----a-w- h:\windows\system32\35.tmp

2009-07-12 18:37 . 2009-07-12 18:37 84 ----a-w- h:\windows\system32\32.tmp

2009-07-12 18:31 . 2009-07-12 18:31 0 ----a-w- h:\windows\system32\33.tmp

2009-07-12 18:31 . 2009-07-12 18:31 84 ----a-w- h:\windows\system32\30.tmp

2009-07-12 18:27 . 2001-10-28 12:07 98486 ----a-w- h:\windows\system32\perfc016.dat

2009-07-12 18:27 . 2001-10-28 12:07 523582 ----a-w- h:\windows\system32\perfh016.dat

2009-07-12 18:00 . 2009-07-12 18:00 0 ----a-w- h:\windows\system32\31.tmp

2009-07-12 18:00 . 2009-07-12 18:00 84 ----a-w- h:\windows\system32\2D.tmp

2009-07-12 11:39 . 2009-07-12 11:39 0 ----a-w- h:\windows\system32\2F.tmp

2009-07-12 11:39 . 2009-07-12 11:39 48640 ----a-w- h:\windows\system32\2E.tmp

2009-07-12 11:39 . 2009-07-12 11:39 120 ----a-w- h:\windows\system32\2A.tmp

2009-07-12 04:13 . 2009-07-12 04:13 0 ----a-w- h:\windows\system32\2C.tmp

2009-07-12 04:13 . 2009-07-12 04:13 49664 ----a-w- h:\windows\system32\2B.tmp

2009-07-12 04:13 . 2009-07-12 04:13 120 ----a-w- h:\windows\system32\29.tmp

2009-07-12 04:13 . 2002-08-29 01:58 361600 ----a-w- h:\windows\system32\drivers\TCPIP.SYS

2009-07-12 04:04 . 2008-10-08 21:22 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2009-07-11 16:20 . 2009-07-11 16:20 0 ----a-w- h:\windows\system32\28.tmp

2009-07-11 16:20 . 2009-07-11 16:20 49664 ----a-w- h:\windows\system32\27.tmp

2009-07-11 16:20 . 2009-07-11 16:20 1241 ----a-w- h:\windows\system32\26.tmp

2009-07-11 16:20 . 2009-07-11 16:20 120 ----a-w- h:\windows\system32\25.tmp

2009-07-10 22:02 . 2009-07-10 22:02 48640 ----a-w- h:\windows\system32\23.tmp

2009-07-10 22:02 . 2009-07-10 22:02 0 ----a-w- h:\windows\system32\24.tmp

2009-07-10 22:02 . 2009-07-10 22:02 1241 ----a-w- h:\windows\system32\22.tmp

2009-07-10 22:02 . 2009-07-10 22:02 120 ----a-w- h:\windows\system32\21.tmp

2009-07-10 21:59 . 2009-07-10 21:59 0 ----a-w- h:\windows\system32\20.tmp

2009-07-10 21:59 . 2009-07-10 21:59 120 ----a-w- h:\windows\system32\D.tmp

2009-07-10 19:26 . 2008-10-02 13:30 238080 ----a-w- h:\windows\system32\wbem\wmiprvse.exe

2009-07-10 19:26 . 2008-10-02 13:30 385024 ----a-w- h:\windows\system32\wbem\wmic.exe

2009-07-10 19:26 . 2008-10-02 13:30 216576 ----a-w- h:\windows\system32\wbem\wmiadap.exe

2009-07-10 19:26 . 2008-10-02 13:30 138752 ----a-w- h:\windows\system32\wbem\wbemtest.exe

2009-07-10 19:26 . 2008-10-02 13:30 36864 ----a-w- h:\windows\system32\wbem\unsecapp.exe

2009-07-10 19:26 . 2008-10-02 13:30 56320 ----a-w- h:\windows\system32\wbem\scrcons.exe

2009-07-10 19:26 . 2008-10-02 13:30 36352 ----a-w- h:\windows\system32\wbem\mofcomp.exe

2009-07-10 19:22 . 2002-09-09 14:08 40960 ----a-w- h:\windows\system32\ssmarque.scr

2009-07-10 19:21 . 2002-09-09 14:08 62464 ----a-w- h:\windows\system32\net.exe

2009-07-10 19:20 . 2002-09-09 14:08 102912 ----a-w- h:\windows\system32\dfrgfat.exe

2009-07-10 19:19 . 2008-10-02 14:28 559104 ----a-w- h:\windows\system32\spider.exe

2009-07-10 19:19 . 2008-10-02 14:28 152576 ----a-w- h:\windows\system32\sndrec32.exe

2009-07-10 19:18 . 2008-10-02 14:28 365568 ----a-w- h:\windows\system32\mspaint.exe

2009-07-10 19:18 . 2008-10-02 14:28 144384 ----a-w- h:\windows\system32\mplay32.exe

2009-07-10 19:16 . 2008-10-02 14:28 124928 ----a-w- h:\windows\system32\clipbrd.exe

2009-07-10 19:16 . 2008-10-02 14:28 208384 ----a-w- h:\windows\system32\accwiz.exe

2009-07-10 19:16 . 2008-10-02 13:32 171008 ----a-w- h:\windows\PCHealth\UploadLB\Binaries\uploadm.exe

2009-07-10 19:16 . 2008-10-02 13:32 55296 ----a-w- h:\windows\PCHealth\HelpCtr\Binaries\notiflag.exe

2009-07-10 19:16 . 2008-10-02 13:31 38400 ----a-w- h:\windows\PCHealth\HelpCtr\Binaries\hscupd.exe

2009-07-10 19:16 . 2008-10-02 13:31 764416 ----a-w- h:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe

2009-07-10 19:16 . 2008-10-02 13:32 119808 ----a-w- h:\windows\PCHealth\HelpCtr\Binaries\HelpHost.exe

2009-07-10 19:11 . 2008-11-14 20:52 106496 ----a-w- h:\windows\unvise32.exe

2009-07-10 19:11 . 2001-10-28 12:07 45568 ----a-w- h:\windows\twunk_32.exe

2009-07-10 19:11 . 2008-10-02 13:25 35328 ----a-w- h:\windows\TASKMAN.EXE

2009-07-10 19:11 . 2008-10-02 13:49 434176 ----a-w- h:\windows\sttray.exe

2009-07-10 19:11 . 2008-10-02 14:28 53346 ----a-w- h:\windows\slrundll.exe

2009-07-10 19:11 . 2008-10-08 22:27 326656 ----a-w- h:\windows\IsUninst.exe

2009-07-10 19:11 . 2009-05-10 23:04 72704 ----a-w- h:\windows\ipuninst.exe

2009-07-10 19:11 . 2009-05-04 23:59 324096 ----a-w- h:\windows\IsUn0411.exe

2009-07-10 19:11 . 2009-04-23 23:12 270336 ----a-w- h:\windows\eiunin21.exe

2009-07-10 19:09 . 2009-03-22 02:52 65536 ----a-r- h:\documents and settings\Jorge\Dados de aplicativos\Microsoft\Installer\{457791C5-D702-4143-A7B2-2744BE9573F2}\NewShortcut1_5B69D3033CA54B39B5ECE7D051297E77.exe

2009-07-10 19:09 . 2009-03-24 20:34 352256 ----a-w- h:\documents and settings\Jorge\Dados de aplicativos\InstallShield Installation Information\{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}\SetupUT3.exe

2009-07-10 19:07 . 2008-10-02 14:34 614400 ----a-w- h:\windows\system32\ati2sgag.exe

2009-07-10 17:10 . 2009-07-10 17:10 0 ----a-w- h:\windows\system32\C.tmp

2009-07-10 15:58 . 2009-07-10 15:58 0 ----a-w- h:\windows\system32\8.tmp

2009-07-10 15:58 . 2009-07-10 15:58 120 ----a-w- h:\windows\system32\2.tmp

2009-07-10 00:28 . 2009-07-10 00:28 0 ----a-w- h:\windows\system32\7.tmp

2009-07-10 00:28 . 2009-07-10 00:28 84 ----a-w- h:\windows\system32\5.tmp

2009-07-09 22:28 . 2009-07-09 22:28 0 ----a-w- h:\windows\system32\1F.tmp

2009-07-09 22:28 . 2009-07-09 22:28 1241 ----a-w- h:\windows\system32\1E.tmp

2009-07-09 22:28 . 2009-07-09 22:28 84 ----a-w- h:\windows\system32\1D.tmp

2009-07-09 22:25 . 2008-10-02 14:34 -------- d-----w- h:\arquivos de programas\ATI Technologies

2009-07-09 22:13 . 2009-07-09 22:13 0 ----a-w- h:\windows\system32\1C.tmp

2009-07-09 22:13 . 2009-07-09 22:13 1241 ----a-w- h:\windows\system32\1B.tmp

2009-07-09 22:13 . 2009-07-09 22:13 84 ----a-w- h:\windows\system32\1A.tmp

2009-07-09 20:37 . 2009-07-09 20:37 0 ----a-w- h:\windows\system32\19.tmp

2009-07-09 20:37 . 2009-07-09 20:37 1241 ----a-w- h:\windows\system32\18.tmp

2009-07-09 20:37 . 2009-07-09 20:37 84 ----a-w- h:\windows\system32\17.tmp

2009-07-09 19:17 . 2009-07-09 19:17 0 ----a-w- h:\windows\system32\16.tmp

2009-07-09 19:17 . 2009-07-09 19:17 1241 ----a-w- h:\windows\system32\15.tmp

2009-07-09 19:17 . 2009-07-09 19:17 84 ----a-w- h:\windows\system32\14.tmp

2009-07-09 02:22 . 2009-07-09 02:22 0 ----a-w- h:\windows\system32\13.tmp

2009-07-09 02:22 . 2009-07-09 02:21 1241 ----a-w- h:\windows\system32\12.tmp

2009-07-08 23:46 . 2008-10-02 13:30 13312 ----a-w- h:\windows\system32\wbem\winmgmt.exe

2009-07-08 23:46 . 2001-10-28 12:07 34304 ----a-w- h:\windows\system32\svchost.exe

2009-07-08 23:45 . 2002-09-09 14:08 514560 ----a-w- h:\windows\system32\logonui.exe

2009-07-08 23:45 . 2002-09-09 14:08 1055744 ----a-w- h:\windows\explorer.exe

2009-07-08 19:58 . 2009-07-08 19:58 29184 ----a-w- h:\windows\system32\11.tmp

2009-07-08 19:52 . 2001-10-28 12:06 5632 ----a-w- h:\windows\system32\cisvc.exe

2009-07-08 18:01 . 2009-07-08 18:01 29184 ----a-w- h:\windows\system32\10.tmp

2009-07-07 22:18 . 2008-10-02 14:46 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\avg8

2009-07-07 00:41 . 2009-02-19 20:05 -------- d-----w- h:\documents and settings\Jorge\Dados de aplicativos\codeblocks

2009-07-06 18:59 . 2009-07-06 18:59 361600 ----a-w- h:\windows\system32\drivers\TCPIP.SYS.ORIGINAL

2009-07-05 23:00 . 2008-10-08 22:13 -------- d-----w- h:\documents and settings\All Users\Dados de aplicativos\DVD Shrink

2009-06-25 20:11 . 2008-10-02 13:44 -------- d--h--w- h:\arquivos de programas\InstallShield Installation Information

2009-06-25 19:06 . 2008-10-02 14:46 11952 ----a-w- h:\windows\system32\avgrsstx.dll

.

 

------- Sigcheck -------

 

[-] 2009-07-10 19:14 34304 E2BB22A31FE47A75E3CBB28B4A709555 h:\windows\$NtServicePackUninstall$\svchost.exe

[-] 2009-07-10 19:19 34304 8F00675F96601D3DD67D34ED8B737837 h:\windows\ServicePackFiles\i386\svchost.exe

[-] 2009-07-08 23:46 34304 CA84E82B8C847CB2AFFF3C864E2DF621 h:\windows\system32\svchost.exe

 

[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E h:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

[7] 2004-08-04 02:14 359040 9F4B36614A0FC234525BA224957DE55C h:\windows\$NtServicePackUninstall$\tcpip.sys

[7] 2008-04-13 15:20 361344 93EA8D04EC73A85DB02EB8805988F733 h:\windows\$NtUninstallKB951748$\tcpip.sys

[7] 2008-04-13 15:20 361344 93EA8D04EC73A85DB02EB8805988F733 h:\windows\ServicePackFiles\i386\tcpip.sys

[-] 2009-07-12 04:13 361600 A29E1209F925A0E9B330E11DA5FC7BAB h:\windows\system32\dllcache\TCPIP.SYS

[-] 2009-07-12 04:13 361600 A29E1209F925A0E9B330E11DA5FC7BAB h:\windows\system32\drivers\TCPIP.SYS

 

[7] 2004-08-04 02:14 182912 558635D3AF1C7546D26067D5D9B6959E h:\windows\$NtServicePackUninstall$\ndis.sys

[7] 2008-04-13 15:20 182656 1DF7F42665C94B825322FAE71721130D h:\windows\ServicePackFiles\i386\ndis.sys

[-] 2009-07-13 05:04 212224 9DC1CE03E1F1800F659BBE9A3AD00AF3 h:\windows\system32\dllcache\ndis.sys

[-] 2009-07-13 05:04 212224 9DC1CE03E1F1800F659BBE9A3AD00AF3 h:\windows\system32\drivers\ndis.sys

 

[-] 2009-07-08 23:45 1055744 F670A6D4F076B89B0B7A90C0D9D557D8 h:\windows\explorer.exe

[-] 2009-07-10 19:12 1054208 887B41814107FD1DE90BEC7F8EA0F71F h:\windows\$NtServicePackUninstall$\explorer.exe

[-] 2009-07-10 19:17 1055744 68B4C279BE133CB203389F22EA582109 h:\windows\ServicePackFiles\i386\explorer.exe

 

[-] 2009-07-10 19:12 35328 B4E13074D8EE28D0CEBAF5F8CCFAA11C h:\windows\$NtServicePackUninstall$\ctfmon.exe

[-] 2009-07-10 19:16 35328 DFE731194CDA8039E7D014481EAFDEA2 h:\windows\ServicePackFiles\i386\ctfmon.exe

[-] 2009-07-08 19:52 15360 E1BD8BC9E8B028BF758FF853D4711799 h:\windows\system32\ctfmon.exe

 

[-] 2009-07-10 19:14 77824 7510EB1CC91898353642049F824CEDFF h:\windows\$NtServicePackUninstall$\spoolsv.exe

[-] 2009-07-10 19:19 77824 9F2345FCC41F0CED42D9B3CB742CC789 h:\windows\ServicePackFiles\i386\spoolsv.exe

[-] 2009-07-08 19:53 57856 58DD8B3CD3BCDBC924C1D669C33EE933 h:\windows\system32\spoolsv.exe

 

[-] 2009-07-10 19:14 44544 0B1A84780893F3414C099428CC1E3D2B h:\windows\$NtServicePackUninstall$\userinit.exe

[-] 2009-07-10 19:19 46080 6E649D45E57F431F47292824135778E4 h:\windows\ServicePackFiles\i386\userinit.exe

[-] 2009-07-08 19:52 26624 EACC136918EFCB89094675D26A303885 h:\windows\system32\userinit.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="h:\windows\system32\ctfmon.exe" [2009-07-08 15360]

"SpybotSD TeaTimer"="h:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-07-08 2260480]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-06-25 19:06 11952 ----a-w- h:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"h:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"h:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"h:\\Arquivos de programas\\CyberLink\\PowerDVD\\PowerDVD.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"h:\\Arquivos de programas\\Macromedia\\Fireworks MX\\Fireworks.exe"=

"h:\\Arquivos de programas\\BitComet\\BitComet.exe"=

"h:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"h:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"h:\\Arquivos de programas\\Unreal Tournament 3\\Binaries\\UT3.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"h:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"h:\\Arquivos de programas\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=

"h:\\Arquivos de programas\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=

"h:\\WINDOWS\\System32\\wbem\\wmiprvse.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"17768:TCP"= 17768:TCP:BitComet 17768 TCP

"17768:UDP"= 17768:UDP:BitComet 17768 UDP

"7172:TCP"= 7172:TCP:BitComet 7172 TCP

"7172:UDP"= 7172:UDP:BitComet 7172 UDP

"6134:TCP"= 6134:TCP:BitComet 6134 TCP

"6134:UDP"= 6134:UDP:BitComet 6134 UDP

 

S1 AvgLdx86;AVG Free AVI Loader Driver x86;h:\windows\system32\drivers\avgldx86.sys [2/10/2008 11:46 327688]

S1 AvgTdiX;AVG Free8 Network Redirector;h:\windows\system32\drivers\avgtdix.sys [2/10/2008 11:46 108552]

S1 is-C5IBDdrv;is-C5IBDdrv;h:\windows\system32\drivers\02786923.sys [8/7/2009 16:23 148496]

S2 avg8emc;AVG Free8 E-mail Scanner;h:\arquiv~1\AVG\AVG8\avgemc.exe [2/10/2008 11:46 906520]

S2 avg8wd;AVG Free8 WatchDog;h:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2/10/2008 11:46 298776]

S3 ASPI;Advanced SCSI Programming Interface Driver;h:\windows\system32\drivers\ASPI32.SYS [27/1/2009 13:20 16512]

S3 AtiHdmiService;ATI Function Driver for HDMI Service;h:\windows\system32\drivers\AtiHdmi.sys [2/10/2008 11:27 93696]

S3 genmcmnUSB;USB Scroll Mouse Driver;h:\windows\system32\DRIVERS\gflmouhid.sys --> h:\windows\system32\DRIVERS\gflmouhid.sys [?]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-ISUSPM - h:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe

HKCU-Run-DAEMON Tools Lite - h:\arquivos de programas\DAEMON Tools Lite\daemon.exe

HKLM-Run-32232 - h:\windows\system32\3B.tmp.exe

HKU-Default-Run-reader_s - h:\documents and settings\Jorge\reader_s.exe

HKLM-Explorer_Run-csrcs - h:\windows\system32\csrcs.exe

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

IE: Baixar com &BitComet - h:\arquivos de programas\BitComet\BitComet.exe/AddLink.htm

IE: Baixar todos com BitComet - h:\arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

IE: Download all videos using BitComet - h:\arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

IE: E&xportar para o Microsoft Excel - h:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: ƒŠƒ“ƒNæ‚ð &BitComet ‚Ń_ƒEƒ“ƒ[ƒh‚·‚é

IE: ‘S‚ẴŠƒ“ƒN‚ð BitComet ‚Ń_ƒEƒ“ƒ[ƒh‚·‚é

IE: ????? &BitComet ?????????

IE: ??????? BitComet ?????????

TCP: {11E93C6D-F3FB-419F-BF96-60586D109CC7} = 201.10.1.2,201.10.120.3

DPF: DirectAnimation Java Classes - file://h:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://h:\windows\Java\classes\xmldso.cab

FF - ProfilePath - h:\documents and settings\Jorge\Dados de aplicativos\Mozilla\Firefox\Profiles\halnwp14.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/

FF - HiddenExtension: Java Console: No Registry Reference - h:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - h:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - h:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

 

---- FIREFOX POLICIES ----

h:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-07-13 02:19

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]

"DisplayName"="???\17?\11\09"

"DeviceDesc"="???\17?\11\09"

"ProviderName"="?;?\11???\11??"

"MFG"="???????"

"ReinstallString"=".10.1000.8"

"DeviceInstanceIds"=multi:"g:\\chipset\\xp3264\\smbus\\smbusati.inf\00"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(248)

h:\windows\system32\Ati2evxx.dll

.

Tempo para conclusão: 2009-07-13 2:23

ComboFix-quarantined-files.txt 2009-07-13 05:23

 

Pré-execução: 10 pasta(s) 122.958.929.920 bytes disponíveis

Pós execução: 10 pasta(s) 123.004.157.952 bytes disponíveis

 

298 --- E O F --- 2008-10-16 09:54

---------------------------------------

 

Após o término do scan, aparentemente alguns arquivos foram eliminados. Na reinicialização em modo normal, não foram mais acusados erros em relação ao MOM.exe da placa de vídeo ATI, nem detecções de infecções do AVG; houve, porém, um erro com um arquivo chamado "6.tmp", o qual não sei do que se trata. A pior parte é que a internet voltou a ficar lenta, e o modem informa transição de dados sem pausa novamente. Estou postando esta mensagem eu um outro computador, pois não consegui acessar o fórum no infectado.

 

Também foi adicionado um ícone do Internet Explorer na área de trabalho, ícone que não estava lá antes.

 

Aguardo as próximas instruções.

~Lucied

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sugiro que imprima ou salve os procedimentos abaixo, e não use a internet até terminado o procedimento.

 

Selecione e copie o texto dentro do QUOTE (caixa cinza) abaixo. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

h:\windows\PSEXESVC.EXE

h:\windows\system32\3B.tmp

h:\windows\system32\38.tmp

h:\windows\system32\39.tmp

h:\windows\system32\36.tmp

h:\windows\system32\37.tmp

h:\windows\system32\34.tmp

h:\windows\system32\35.tmp

h:\windows\system32\32.tmp

h:\windows\system32\33.tmp

h:\windows\system32\30.tmp

h:\windows\system32\31.tmp

h:\windows\system32\2D.tmp

h:\windows\system32\2F.tmp

h:\windows\system32\2E.tmp

h:\windows\system32\2A.tmp

h:\windows\system32\2C.tmp

h:\windows\system32\2B.tmp

h:\windows\system32\29.tmp

h:\windows\system32\28.tmp

h:\windows\system32\27.tmp

h:\windows\system32\26.tmp

h:\windows\system32\25.tmp

h:\windows\system32\23.tmp

h:\windows\system32\24.tmp

h:\windows\system32\22.tmp

h:\windows\system32\21.tmp

h:\windows\system32\20.tmp

h:\windows\system32\D.tmp

h:\windows\system32\C.tmp

h:\windows\system32\8.tmp

h:\windows\system32\2.tmp

h:\windows\system32\7.tmp

h:\windows\system32\5.tmp

h:\windows\system32\1F.tmp

h:\windows\system32\1E.tmp

h:\windows\system32\1D.tmp

h:\windows\system32\1C.tmp

h:\windows\system32\1B.tmp

h:\windows\system32\1A.tmp

h:\windows\system32\19.tmp

h:\windows\system32\18.tmp

h:\windows\system32\17.tmp

h:\windows\system32\16.tmp

h:\windows\system32\15.tmp

h:\windows\system32\14.tmp

h:\windows\system32\13.tmp

h:\windows\system32\12.tmp

h:\windows\system32\11.tmp

h:\windows\system32\10.tmp

 

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"FirewallOverride"=dword:00000000

"UpdatesDisableNotify"=dword:00000000

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 1 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"17768:TCP"=-

"17768:UDP"=-

"7172:TCP"=-

"7172:UDP"=-

"6134:TCP"=-

"6134:UDP"=-

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes não use-o em outro computador, pos pode trazer danos.

 

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

cfscript.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

Poste-o junto com o novo log do hijackthis

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.