flake21 0 Denunciar post Postado Agosto 4, 2009 Primeiramente saudações a todos do fórum! Meu problema é típico... Ao tentar baixar um "serial" para um programa na net, reparei que ele veio na forma de aplicativo... Dei uma bobeira danada, e iniciei o aplicativo... A princípio, foi como se nada tivesse acontecido... Mas depois de um tempo, reparei que aplicações que antes eram processadas rápidas, tinham se tornado mais lentas... Reparei tb que de vez em quando com a mania que eu tenho de ver todas as aplicações na barra de tarefas, aparecia uma chamada "d.exe"... Toda vez que eu a finalizo ela reaparece depois de um tempo... Outro sintoma, é que algumas páginas do Internet explorer abrem aleatóreamente. Segue meu log do Hajackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 04:04:22, on 4/8/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\msb.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe C:\Program Files\Windows Media Player\setup_wm.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [Monopod] C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user') O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- End of file - 7011 bytes ____________________________________ Aguardo ajuda e agradeço desde já a todos do fórum! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 4, 2009 Bom Dia! flake21 <@> Baixe: < Malwarebytes > <@> Atualize o programa! <@> Escolha o escaneamento Completo! <@> Desabilite programas de proteção,ao executar o malwarebytes. <@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. <@> Para maiores detalhes: < Link > <><><><><><><><><><><> <@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
flake21 0 Denunciar post Postado Agosto 4, 2009 Obrigado pela rapidez com que respondeu Digram! Segue o log do malwarebytes: Malwarebytes' Anti-Malware 1.40 Versão do banco de dados: 2560 Windows 5.1.2600 Service Pack 3 4/8/2009 17:09:00 mbam-log-2009-08-04 (17-09-00).txt Tipo de Verificação: Completa (C:\|D:\|E:\|F:\|) Objetos verificados: 191417 Tempo decorrido: 25 minute(s), 35 second(s) Processos da Memória infectados: 1 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 3 Valores do Registro infectados: 1 Ítens do Registro infectados: 0 Pastas infectadas: 0 Arquivos infectados: 10 Processos da Memória infectados: C:\WINDOWS\msb.exe (Trojan.Agent) -> Unloaded process successfully. Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully. Valores do Registro infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully. Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: C:\WINDOWS\msb.exe (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\Flake21\Local Settings\Temp\d.exe (Trojan.Dropper) -> Delete on reboot. C:\Documents and Settings\Flake21\Local Settings\Temp\e.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Flake21\Local Settings\Temp\i.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Documents and Settings\Flake21\Local Settings\Temp\j.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully. D:\Arquivos\Video Editors -6in1\az-video\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Flake21\Application Data\Microsoft\profile.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully. ______________________________________ Segue o log do hajck this: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:11:35, on 4/8/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wscntfy.exe C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user') O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- End of file - 7076 bytes _________________________________ Aguardo retorno! obrigado mais uma vez! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 5, 2009 Boa Noite! flake21 <!> Repita o scan com o Malwarebytes --> Escolha o escaneamento rápido! --> Poste o resultado! <><><><><><><><><><> <@> Baixe: < > ( ...by sUBs ) <@> Salve-o no desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Ps: A execução,por comando,também é possível:<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\Desktop\Combofix.exe" /killall <@> Clique em Ok. <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link! <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta! <!> Ps: Para evitar problemas,siga todas as recomendações propostas. <!> Ps: O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter! <><><><><><><><><><> <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
flake21 0 Denunciar post Postado Agosto 5, 2009 Obrigado pela ajuda DigRam! Segue o log do malwarebyts Malwarebytes' Anti-Malware 1.40 Versão do banco de dados: 2560 Windows 5.1.2600 Service Pack 3 5/8/2009 04:29:01 mbam-log-2009-08-05 (04-29-01).txt Tipo de Verificação: Rápida Objetos verificados: 106398 Tempo decorrido: 5 minute(s), 44 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 0 Valores do Registro infectados: 0 Ítens do Registro infectados: 0 Pastas infectadas: 0 Arquivos infectados: 0 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: (Nenhum ítem malicioso foi detectado) Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: (Nenhum ítem malicioso foi detectado) _______________________________________ Segue o log do Combofix ComboFix 09-07-23.02 - Flake21 05/08/2009 5:25.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1449 [GMT -3:00] Running from: c:\documents and settings\Flake21\Desktop\Limpeza Malwares\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} . - REDUCED FUNCTIONALITY MODE - . ((((((((((((((((((((((((( Files Created from 2009-07-05 to 2009-08-05 ))))))))))))))))))))))))))))))) . 2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\documents and settings\Flake21\Application Data\Malwarebytes 2009-08-04 19:16 . 2009-08-03 16:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-08-04 19:16 . 2009-08-03 16:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-08-04 06:40 . 2009-08-04 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk 2009-08-04 04:56 . 2009-08-04 04:58 -------- d-----w- C:\DVDVideoSoft 2009-08-04 04:56 . 2009-08-04 04:56 -------- d-----w- c:\program files\Common Files\DVDVideoSoft 2009-08-04 04:56 . 2009-08-04 04:56 -------- d-----w- c:\program files\DVDVideoSoft 2009-08-04 04:56 . 2002-01-05 17:37 344064 ----a-w- c:\windows\system32\msvcr70.dll 2009-08-04 03:53 . 2009-08-04 03:53 -------- d-sh--w- c:\documents and settings\Flake21\PrivacIE 2009-08-04 03:46 . 2009-08-04 03:46 -------- d-----w- c:\program files\VSO 2009-08-04 03:28 . 2009-08-04 03:28 87608 ----a-w- c:\documents and settings\Flake21\Application Data\inst.exe 2009-08-04 03:28 . 2009-08-04 03:28 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys 2009-08-04 03:28 . 2009-08-04 03:28 47360 ----a-w- c:\documents and settings\Flake21\Application Data\pcouffin.sys 2009-08-04 03:28 . 2009-08-04 09:18 -------- d-----w- c:\documents and settings\Flake21\Application Data\Vso 2009-08-04 03:28 . 2007-03-19 00:37 65602 ----a-w- c:\windows\system32\cook3260.dll 2009-08-04 03:28 . 2006-09-29 16:26 176165 ----a-w- c:\windows\system32\drv23260.dll 2009-08-04 03:28 . 2006-09-29 16:25 208935 ----a-w- c:\windows\system32\drv33260.dll 2009-08-04 03:28 . 2006-09-29 16:24 217127 ----a-w- c:\windows\system32\drv43260.dll 2009-08-04 03:28 . 2006-05-20 20:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll 2009-08-04 03:28 . 2006-05-11 23:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll 2009-08-04 03:28 . 2002-12-10 06:20 102439 ----a-w- c:\windows\system32\sipr3260.dll 2009-08-03 20:38 . 2009-08-03 20:38 -------- d-----w- c:\documents and settings\Flake21\Local Settings\Application Data\Ahead 2009-07-30 06:32 . 2009-07-30 06:32 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-07-30 06:32 . 2009-07-30 06:32 -------- d-sh--w- c:\documents and settings\Flake21\IETldCache 2009-07-30 03:45 . 2009-07-19 21:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-07-30 03:45 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-07-30 03:45 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-07-30 03:45 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-07-30 03:45 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-07-30 03:45 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-07-30 03:45 . 2009-07-30 03:45 -------- d-----w- c:\windows\ie8updates 2009-07-30 03:45 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-07-30 03:44 . 2009-07-30 03:45 -------- dc-h--w- c:\windows\ie8 2009-07-28 20:06 . 2009-06-29 16:23 78336 -c----w- c:\windows\system32\dllcache\ieencode.dll 2009-07-28 20:06 . 2009-06-29 16:23 78336 ------w- c:\windows\system32\ieencode.dll 2009-07-28 20:06 . 2009-06-29 16:23 63488 -c----w- c:\windows\system32\dllcache\icardie.dll 2009-07-28 20:06 . 2009-06-29 11:25 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe 2009-07-28 20:06 . 2009-06-29 16:23 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll 2009-07-28 20:06 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat 2009-07-25 18:34 . 2009-07-25 18:41 66872 ----a-w- c:\windows\system32\PnkBstrA.exe 2009-07-25 18:34 . 2009-07-26 05:29 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-07-25 18:34 . 2009-07-26 05:29 183112 ----a-w- c:\windows\system32\PnkBstrB.exe 2009-07-25 17:47 . 2009-07-25 17:47 -------- d-----w- c:\documents and settings\Flake21\Application Data\Leadertech 2009-07-24 22:28 . 2009-07-24 22:28 39200 ----a-w- c:\windows\system32\drivers\TfSysMon.sys 2009-07-24 22:28 . 2009-07-24 22:28 33056 ----a-w- c:\windows\system32\drivers\TfNetMon.sys 2009-07-24 22:28 . 2009-07-24 22:28 51488 ----a-w- c:\windows\system32\drivers\TfFsMon.sys 2009-07-24 22:28 . 2009-07-24 22:28 12576 ----a-w- c:\windows\system32\drivers\TfKbMon.sys 2009-07-24 19:53 . 2008-12-11 11:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-07-24 19:53 . 2009-07-24 22:27 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-07-24 19:53 . 2008-12-18 15:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-07-24 19:53 . 2009-07-24 19:55 -------- d-----w- c:\program files\Common Files\PC Tools 2009-07-24 19:53 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2009-07-24 19:52 . 2009-07-25 00:27 -------- d-----w- c:\program files\Spyware Doctor 2009-07-24 19:52 . 2009-07-24 22:29 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-07-24 19:52 . 2009-07-24 19:52 -------- d-----w- c:\documents and settings\Flake21\Application Data\PC Tools 2009-07-24 02:21 . 2009-06-16 14:36 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll 2009-07-24 02:21 . 2009-06-16 14:36 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll 2009-07-23 23:14 . 2009-07-23 23:14 -------- d--h--w- c:\windows\system32\GroupPolicy 2009-07-23 02:57 . 2009-07-23 02:57 -------- d--h--w- c:\windows\PIF 2009-07-22 20:28 . 2009-07-22 20:30 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-07-16 03:25 . 2009-07-16 03:25 -------- d-----w- c:\documents and settings\Flake21\Local Settings\Application Data\CAPCOM 2009-07-15 23:16 . 2009-07-24 22:30 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-07-15 22:57 . 2009-07-15 22:57 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE 2009-07-14 23:58 . 2009-07-14 23:58 -------- d-----w- c:\documents and settings\Saluzinho\Local Settings\Application Data\Adobe 2009-07-14 03:24 . 2008-04-14 00:11 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll 2009-07-14 03:24 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll 2009-07-14 03:24 . 2008-04-13 18:39 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys 2009-07-14 03:24 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys 2009-07-14 03:24 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys 2009-07-14 03:24 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-04 03:28 . 2009-04-26 01:28 -------- d-----w- c:\documents and settings\Flake21\Application Data\uTorrent 2009-07-24 02:25 . 2009-04-26 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-07-22 21:55 . 2009-04-21 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-03 17:09 . 2007-07-22 13:17 915456 ----a-w- c:\windows\system32\wininet.dll 2009-06-22 12:23 . 2009-06-22 12:23 -------- d-----w- c:\program files\YourWare Solutions 2009-06-21 22:46 . 2009-06-21 22:46 -------- d-----w- c:\documents and settings\Saluzinho\Application Data\DivX 2009-06-21 22:45 . 2009-04-23 01:09 69232 ----a-w- c:\documents and settings\Saluzinho\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-16 14:36 . 2007-07-22 13:31 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-06-16 14:36 . 2007-07-22 13:16 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-16 04:06 . 2009-04-21 21:06 -------- d-----w- c:\documents and settings\Flake21\Application Data\Skype 2009-06-16 04:05 . 2009-04-21 21:08 -------- d-----w- c:\documents and settings\Flake21\Application Data\skypePM 2009-06-14 01:43 . 2009-04-21 19:39 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-14 01:43 . 2009-06-14 01:43 -------- d-----w- c:\program files\USB Vibration 2009-06-13 21:26 . 2009-04-21 16:06 102400 ----a-w- c:\windows\DUMP43b0.tmp 2009-06-11 04:28 . 2009-06-01 14:31 413696 ----a-w- c:\windows\system32\wrap_oal.dll 2009-06-11 04:28 . 2009-06-01 14:31 110592 ----a-w- c:\windows\system32\OpenAL32.dll 2009-06-08 03:10 . 2009-06-08 03:10 -------- d-----w- c:\program files\Noël Danjou 2009-06-08 02:21 . 2009-06-08 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus! 2009-06-03 19:09 . 2007-07-22 13:15 1291264 ----a-w- c:\windows\system32\quartz.dll 2009-06-01 13:40 . 2009-04-21 22:12 721904 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-05-31 23:46 . 2009-04-21 19:34 69232 ----a-w- c:\documents and settings\Flake21\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-31 02:02 . 2009-04-21 22:18 158528 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-05-16 23:16 . 2009-05-16 23:16 0 ----a-w- c:\windows\ativpsrm.bin 2009-05-07 15:32 . 2004-08-04 01:56 345600 ----a-w- c:\windows\system32\localspl.dll 2009-08-04 04:49 . 2009-04-21 21:00 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-25 1397760] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "{1290A33C-85F5-4164-A1BE-7DD299D4986A}"="c:\program files\CyberLink\PowerBackup\PBKScheduler.exe" [2004-06-08 69721] "mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-10 53248] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-01-11 577536] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "ShowDeskFix"="shell32" [X] c:\documents and settings\Flake21\Start Menu\Programs\Startup\ MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-4-21 534016] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "d:\\Download - Setups\\Programas\\utorrent.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "f:\\Garena\\Garena.exe"= "f:\\Left4Dead\\left4dead.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "f:\\Evolved Games\\Terminator Salvation\\TerminatorSalvation.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "f:\\Steam\\steamapps\\flake21\\team fortress 2\\hl2.exe"= "f:\\Street Fighter IV\\StreetFighterIV.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "2151:TCP"= R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [21/4/2009 16:38 16640] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/7/2009 16:53 130936] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [24/7/2009 19:28 51488] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [24/7/2009 19:28 39200] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [24/7/2009 16:53 159600] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [21/4/2009 19:10 108289] S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?] S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [24/7/2009 16:53 64392] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/7/2009 16:52 348752] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [24/7/2009 19:28 33056] S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.oglobo.com.br/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll TCP: {DEE555A9-BC49-4E29-8284-35EFD504FCA7} = 192.168.254.254 FF - ProfilePath - c:\documents and settings\Flake21\Application Data\Mozilla\Firefox\Profiles\o3mmpvd5.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.oglobo.com.br/ FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-05 05:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(812) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'lsass.exe'(868) c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll - - - - - - - > 'explorer.exe'(300) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll . Completion time: 2009-08-05 5:26 ComboFix-quarantined-files.txt 2009-08-05 08:26 ComboFix2.txt 2009-07-24 02:17 ComboFix3.txt 2009-07-23 23:32 Pre-Run: 8.530.411.520 bytes free Post-Run: 8.579.407.872 bytes free 220 --- E O F --- 2009-07-30 03:46 ______________________________________ Segue o log do Hajackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:52:26, on 5/8/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user') O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe -- End of file - 6712 bytes ___________________________ Muito obrigado por toda assistência! um abç! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 5, 2009 Boa Noite! flake21 S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?] <!> Voçê conhece esta aplicação e seu serviço? <><><><><><><><><> <@> Baixe: < DDS > ( ...by sUBs ) <@> Salve-o no desktop! <@> Desabilite seus programas de proteção: antivírus,antimalware,antispyware ou firewall. <@> Estando desconectado,execute a ferramenta! --> Duplo clique em dds.scr. <@> Aguarde o término do scan,até obtermos o relatório. ( DDS.txt ) <-- <@> Surgirá,também,uma nova janela: "D.D.S - Optional_Scan" --> Clique em Sim. <@> O Bloco de Notas irá abrir,com outro relatório. ( Attach.txt ) <-- <@> Ps: Caso o relatório seja incompreensível,renomeie o executável para DDS.exe e repita o scan. <@> Outra janela,finalmente,abrir-se-à! --> Clique em OK. <@> Salve os relatórios: DDS.txt + Attach.txt <-- Poste-os! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
flake21 0 Denunciar post Postado Agosto 10, 2009 Boa noite DigRam! Desculpe pela demora em reponder, tive que viajar esse fds! Obrigado mais uma vez pela rapidez! Olha... Eu não conheço a aplicação citada, e não sei nada sobre seu serviço... Como o orientado, segue o log DDS.txt DDS (Ver_09-07-30.01) - NTFSx86 Run by Flake21 at 0:38:23,09 on seg 10/08/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1521 [GMT -3:00] AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Ahead\InCD\InCDsrv.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wscntfy.exe D:\Download - Setups\Programas\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.oglobo.com.br/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0 me\reader\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [soundMan] SOUNDMAN.EXE mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [inCD] c:\program files\ahead\incd\InCD.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "c:\program files\cyberlink\powerbackup\PBKScheduler.exe" mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 StartupFolder: c:\docume~1\flake21\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab TCP: {DEE555A9-BC49-4E29-8284-35EFD504FCA7} = 192.168.254.254 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\flake21\applic~1\mozilla\firefox\profiles\o3mmpvd5.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.oglobo.com.br/ FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nppl3260.dll FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nprpjplug.dll ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); ============= SERVICES / DRIVERS =============== R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [2009-4-21 16640] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-24 130936] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-7-24 51488] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-7-24 39200] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-4-21 11608] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-7-24 159600] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-4-21 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-4-21 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-4-21 55656] S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?] S3 GarenaPEngine;GarenaPEngine;c:\docume~1\flake21\locals~1\temp\KACC7.tmp [2009-8-5 18704] S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2009-7-24 64392] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-24 348752] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-24 1095560] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-7-24 33056] S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?] =============== Created Last 30 ================ 2009-08-05 05:24 <DIR> --ds---- C:\ComboFix 2009-08-04 16:16 <DIR> --d----- c:\docume~1\flake21\applic~1\Malwarebytes 2009-08-04 16:16 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-04 16:16 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-08-04 16:16 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-08-04 16:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-04 03:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\vsosdk 2009-08-04 01:56 <DIR> --d----- C:\DVDVideoSoft 2009-08-04 01:56 <DIR> --d----- c:\program files\common files\DVDVideoSoft 2009-08-04 01:56 344,064 a------- c:\windows\system32\msvcr70.dll 2009-08-04 01:56 <DIR> --d----- c:\program files\DVDVideoSoft 2009-08-04 00:53 <DIR> --dsh--- c:\documents and settings\flake21\PrivacIE 2009-08-04 00:46 <DIR> --d----- c:\program files\VSO 2009-08-04 00:28 87,608 a------- c:\docume~1\flake21\applic~1\inst.exe 2009-08-04 00:28 47,360 a------- c:\windows\system32\drivers\pcouffin.sys 2009-08-04 00:28 47,360 a------- c:\docume~1\flake21\applic~1\pcouffin.sys 2009-08-04 00:28 1,184,984 a------- c:\windows\system32\wvc1dmod.dll 2009-08-04 00:28 626,688 a------- c:\windows\system32\vp7vfw.dll 2009-08-04 00:28 217,127 a------- c:\windows\system32\drv43260.dll 2009-08-04 00:28 208,935 a------- c:\windows\system32\drv33260.dll 2009-08-04 00:28 176,165 a------- c:\windows\system32\drv23260.dll 2009-08-04 00:28 102,439 a------- c:\windows\system32\sipr3260.dll 2009-08-04 00:28 65,602 a------- c:\windows\system32\cook3260.dll 2009-07-30 03:32 <DIR> --dsh--- c:\documents and settings\flake21\IETldCache 2009-07-30 00:45 11,067,392 -c------ c:\windows\system32\dllcache\ieframe.dll 2009-07-30 00:45 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll 2009-07-30 00:45 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll 2009-07-30 00:45 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll 2009-07-30 00:45 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll 2009-07-30 00:45 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll 2009-07-30 00:45 <DIR> --d----- c:\windows\ie8updates 2009-07-30 00:45 101,376 -c------ c:\windows\system32\dllcache\iecompat.dll 2009-07-30 00:44 <DIR> -cd-h--- c:\windows\ie8 2009-07-28 17:06 78,336 -c------ c:\windows\system32\dllcache\ieencode.dll 2009-07-28 17:06 63,488 -c------ c:\windows\system32\dllcache\icardie.dll 2009-07-28 17:06 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe 2009-07-28 17:06 78,336 -------- c:\windows\system32\ieencode.dll 2009-07-28 17:06 2,452,872 -c------ c:\windows\system32\dllcache\ieapfltr.dat 2009-07-28 17:06 991,232 -c------ c:\windows\system32\dllcache\ieframe.dll.mui 2009-07-28 17:06 380,928 -c------ c:\windows\system32\dllcache\ieapfltr.dll 2009-07-25 15:34 66,872 a------- c:\windows\system32\PnkBstrA.exe 2009-07-25 15:34 138,184 a------- c:\windows\system32\drivers\PnkBstrK.sys 2009-07-25 15:34 183,112 a------- c:\windows\system32\PnkBstrB.exe 2009-07-24 19:28 51,488 a------- c:\windows\system32\drivers\TfFsMon.sys 2009-07-24 19:28 39,200 a------- c:\windows\system32\drivers\TfSysMon.sys 2009-07-24 19:28 33,056 a------- c:\windows\system32\drivers\TfNetMon.sys 2009-07-24 19:28 12,576 a------- c:\windows\system32\drivers\TfKbMon.sys 2009-07-24 16:53 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys 2009-07-24 16:53 130,936 a------- c:\windows\system32\drivers\PCTCore.sys 2009-07-24 16:53 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys 2009-07-24 16:53 <DIR> --d----- c:\program files\common files\PC Tools 2009-07-24 16:53 64,392 a------- c:\windows\system32\drivers\pctplsg.sys 2009-07-24 16:52 <DIR> --d----- c:\program files\Spyware Doctor 2009-07-24 16:52 <DIR> --d----- c:\docume~1\flake21\applic~1\PC Tools 2009-07-24 16:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools 2009-07-23 23:21 119,808 -c------ c:\windows\system32\dllcache\t2embed.dll 2009-07-23 23:21 81,920 -c------ c:\windows\system32\dllcache\fontsub.dll 2009-07-23 21:24 4,096 a------- c:\windows\system32\crash 2009-07-23 20:31 <DIR> -cd----- c:\windows\system32\dllcache\cache 2009-07-23 20:29 <DIR> a-dshr-- C:\cmdcons 2009-07-23 20:25 219,648 a------- c:\windows\PEV.exe 2009-07-23 20:25 161,792 a------- c:\windows\SWREG.exe 2009-07-23 20:25 98,816 a------- c:\windows\sed.exe 2009-07-23 20:14 <DIR> --d-h--- c:\windows\system32\GroupPolicy 2009-07-22 23:57 <DIR> --d-h--- c:\windows\PIF 2009-07-22 17:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy 2009-07-15 20:16 124,688 a------- c:\windows\system32\MSWINSCK.OCX 2009-07-15 19:57 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE 2009-07-14 00:24 21,504 ac------ c:\windows\system32\dllcache\hidserv.dll 2009-07-14 00:24 21,504 a------- c:\windows\system32\hidserv.dll 2009-07-14 00:24 14,592 ac------ c:\windows\system32\dllcache\kbdhid.sys 2009-07-14 00:24 14,592 a------- c:\windows\system32\drivers\kbdhid.sys 2009-07-14 00:24 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys 2009-07-14 00:24 32,128 a------- c:\windows\system32\drivers\usbccgp.sys ==================== Find3M ==================== 2009-08-05 20:00 55,656 a------- c:\windows\system32\drivers\avgntflt.sys 2009-07-03 14:09 915,456 a------- c:\windows\system32\wininet.dll 2009-06-16 11:36 119,808 a------- c:\windows\system32\t2embed.dll 2009-06-16 11:36 81,920 a------- c:\windows\system32\fontsub.dll 2009-06-13 18:26 102,400 a------- c:\windows\DUMP43b0.tmp 2009-06-11 01:28 413,696 a------- c:\windows\system32\wrap_oal.dll 2009-06-11 01:28 110,592 a------- c:\windows\system32\OpenAL32.dll 2009-06-03 16:09 1,291,264 a------- c:\windows\system32\quartz.dll 2009-05-06 03:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009042020090427\index.dat 2009-05-06 03:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009050620090507\index.dat ============= FINISH: 0:38:43,46 =============== _______________________________________ Segue o log Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 21/4/2009 16:28:06 System Uptime: 8/10/2009 00:01:14 (-1416 hours ago) Motherboard: DFI Inc. | | NF UltraII-M2 /NF SLiII-M2 /NFII -M2 Processor: AMD Athlon 64 X2 Dual Core Processor 4800+ | Socket M2 | 2511/201mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 47 GiB total, 7,954 GiB free. D: is FIXED (FAT32) - 69 GiB total, 27,571 GiB free. E: is FIXED (FAT32) - 47 GiB total, 20,684 GiB free. F: is FIXED (NTFS) - 71 GiB total, 6,535 GiB free. G: is CDROM () H: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: PC Camera Device ID: USB\VID_0AC8&PID_301B\5&27A050D6&0&2 Manufacturer: Name: PC Camera PNP Device ID: USB\VID_0AC8&PID_301B\5&27A050D6&0&2 Service: Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: NVIDIA nForce Networking Controller Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&33E880BB&0&01 Manufacturer: Nvidia Name: NVIDIA nForce Networking Controller PNP Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&33E880BB&0&01 Service: NVENETFD ==== System Restore Points =================== RP1: 26/6/2009 17:42:24 - System Checkpoint RP2: 29/6/2009 10:30:49 - System Checkpoint RP3: 30/6/2009 16:20:19 - System Checkpoint RP4: 3/7/2009 21:16:42 - System Checkpoint RP5: 4/7/2009 22:45:15 - System Checkpoint RP6: 8/7/2009 11:30:04 - System Checkpoint RP7: 10/7/2009 22:12:25 - System Checkpoint RP8: 11/7/2009 23:02:45 - System Checkpoint RP9: 12/7/2009 23:51:42 - System Checkpoint RP10: 14/7/2009 12:42:35 - System Checkpoint RP11: 15/7/2009 13:43:16 - System Checkpoint RP12: 15/7/2009 19:57:20 - Installed DirectX RP13: 15/7/2009 19:57:43 - Installed DirectX RP14: 15/7/2009 19:57:54 - Installed STREET FIGHTER IV. RP15: 15/7/2009 23:52:41 - Installed DirectX RP16: 17/7/2009 13:28:50 - System Checkpoint RP17: 20/7/2009 15:34:26 - System Checkpoint RP18: 21/7/2009 16:01:33 - System Checkpoint RP19: 22/7/2009 21:01:10 - System Checkpoint RP20: 23/7/2009 23:00:45 - System Checkpoint RP21: 23/7/2009 23:16:56 - Software Distribution Service 3.0 RP22: 23/7/2009 23:23:57 - Software Distribution Service 3.0 RP23: 24/7/2009 03:00:14 - Software Distribution Service 3.0 RP24: 24/7/2009 20:16:38 - Software Distribution Service 3.0 RP25: 25/7/2009 03:00:13 - Software Distribution Service 3.0 RP26: 25/7/2009 14:48:20 - Installed DirectX RP27: 25/7/2009 15:20:46 - Installed Need for Speed™ Undercover RP28: 25/7/2009 21:54:59 - Software Distribution Service 3.0 RP29: 25/7/2009 23:50:04 - Software Distribution Service 3.0 RP30: 26/7/2009 02:44:00 - Software Distribution Service 3.0 RP31: 26/7/2009 04:19:39 - Software Distribution Service 3.0 RP32: 26/7/2009 18:17:27 - Software Distribution Service 3.0 RP33: 26/7/2009 18:43:21 - Software Distribution Service 3.0 RP34: 28/7/2009 00:38:11 - Software Distribution Service 3.0 RP35: 28/7/2009 02:56:14 - Software Distribution Service 3.0 RP36: 28/7/2009 23:57:47 - Removed Need for Speed™ Undercover RP37: 29/7/2009 03:00:16 - Software Distribution Service 3.0 RP38: 30/7/2009 00:41:22 - Software Distribution Service 3.0 RP39: 31/7/2009 20:50:24 - System Checkpoint RP40: 1/8/2009 22:15:12 - System Checkpoint RP41: 2/8/2009 22:25:41 - System Checkpoint RP42: 3/8/2009 22:37:24 - System Checkpoint RP43: 4/8/2009 22:42:48 - System Checkpoint RP44: 8/8/2009 04:21:36 - System Checkpoint ==== Installed Programs ====================== µTorrent 7-Zip 4.65 Adobe Flash Player 10 Plugin Adobe Reader 6.0.2 ME AMCap Arquivo do WinRAR Assistente de Conexão do Windows Live ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver ATI HydraVision ATI Parental Control & Encoder Avira AntiVir Personal - Free Antivirus AVIVO Codecs biohazard 4 BS.Player FREE powered by AdVantage Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full ccc-core-preinstall ccc-core-static ccc-utility CCC Help English Choice Guard Codec Pack - All In 1 6.0.3.0 ConvertXtoDVD 3.6.9.168 CoreAVC Pro 1.3.0.0 Critical Update for Windows Media Player 11 (KB959772) DAEMON Tools Toolbar Ferramenta de Carregamento do Windows Live Free YouTube to Mp3 Converter version 2.5 Garena Half-Life 2: Episode One Half-Life 2: Episode Two HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) K-Lite Codec Pack 3.2.5 Full Left 4 Dead Standalone Patch Magic ISO Maker v5.4 (build 0239) MagicDisc 2.5.74 Malwarebytes' Anti-Malware Messenger Plus! Live Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft Visual C Runtime Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Mozilla Firefox (3.0.13) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) MUSICMATCH® Jukebox Nero Suite NVIDIA Drivers NVIDIA PhysX OpenAL Portal Power2Go 4.0 PowerBackup 1.0 PowerDirector Express PowerDVD PowerDVD Copy 1.0 PowerProducer PowerStarter PS TO PC CONVERTER RealPlayer Realtek AC'97 Audio Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB960003) Security Update for Microsoft Office Excel 2007 (KB959997) Security Update for Microsoft Office OneNote 2007 (KB950130) Security Update for Microsoft Office PowerPoint 2007 (KB951338) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB956828) Security Update for Microsoft Office Word 2007 (KB956358) Security Update for Outlook 2007 (KB946983) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Segoe UI Skins Skype™ 3.8 Smart Guardian Software Update for Web Folders Spybot - Search & Destroy Spyware Doctor 6.0 Steam STREET FIGHTER IV Team Fortress 2 Terminator Salvation Trials 2 Second Edition Uninstall 1.0.0.0 Update for 2007 Microsoft Office System (KB967642) Update for Office 2007 (KB934391) Update for Outlook 2007 Junk Email Filter (kb971933) Update for Windows Internet Explorer 8 (KB972636) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) VideoLAN VLC media player 0.8.6c Vista Codec Package Windows Genuine Advantage Notifications (KB905474) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Presentation Foundation Windows XP Service Pack 3 XML Paper Specification Shared Components Pack 1.0 XP Codec Pack ==== Event Viewer Messages From Past Week ======== 5/8/2009 05:30:54, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found. 5/8/2009 05:25:52, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. ==== End Of File =========================== _______________________________________ Agradeço desde já mais uma vez! um abraço! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 10, 2009 Bom Dia! flake21 <@> Submeta este(s) ficheiro(s),à uma análise em: < Sunbelt Sandbox > <!> c:\windows\system32\drivers\mrzvn.sys <-- <@> No campo,digite o seu E-Mail. <@> Escolha o relatório,das verificações,no formato texto! <@> Clique em: Submit sample for analysis,após indicar o caminho ao(s) ficheiros para upload. <@> Poste o(s) relatório(s),dessa(s) análise(s),que lhe serão enviadas por E-Mail. <@> Ps: Caso a pesquisa seja inconclusiva,verifique se o arquivo mrzvn.sys encontra-se oculto. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
flake21 0 Denunciar post Postado Agosto 10, 2009 Boa noite DigRram! Obrigado mais uma vez pelo auxílio! Infelizmente, dessa vez, eu não consegui fazer o que foi solicitado! A entrada para o arquivo "c:\windows\system32\drivers\mrzvn.sys" não estava na pasta c:\windows\system32\drivers... Não consegui encontrar o arquivo, mesmo depois de selecionar a opção de visualização de pastas e arquivos ocultos! não pude obter o log! =/ Fico no aguardo! abraços Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 10, 2009 Boa Noite! flake21 <!> Com certeza,não existe mais no PC. <><><><><><><><><> <@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK. <@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança ) <@> Clique em Executar --> Aguarde! <@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. <@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! <><><><><><><><><> <!> Os logs estão limpos! <!> Bom trabalho! :thumbsup: Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
flake21 0 Denunciar post Postado Agosto 10, 2009 Obrigado novamente DigRam! Obrigado pela competência, rapidez e paciência que você teve ao guiar todo o processo! é de pessoas asism que a rede precisa! muito obrigado! Problema mais que resolvido!! :yes: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 11, 2009 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites