Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

flake21

[Resolvido!] d.exe

Recommended Posts

Primeiramente saudações a todos do fórum!

Meu problema é típico... Ao tentar baixar um "serial" para um programa na net, reparei que ele veio na forma de aplicativo...

Dei uma bobeira danada, e iniciei o aplicativo... A princípio, foi como se nada tivesse acontecido... Mas depois de um tempo, reparei que

aplicações que antes eram processadas rápidas, tinham se tornado mais lentas... Reparei tb que de vez em quando com a mania que eu tenho de ver

todas as aplicações na barra de tarefas, aparecia uma chamada "d.exe"... Toda vez que eu a finalizo ela reaparece depois de um tempo...

Outro sintoma, é que algumas páginas do Internet explorer abrem aleatóreamente.

 

Segue meu log do Hajackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 04:04:22, on 4/8/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\msb.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe

C:\Program Files\Windows Media Player\setup_wm.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"

O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [Monopod] C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe

 

--

End of file - 7011 bytes

 

____________________________________

 

Aguardo ajuda e agradeço desde já a todos do fórum!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! flake21

 

<@> Baixe: < Malwarebytes >

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<><><><><><><><><><><>

<@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado pela rapidez com que respondeu Digram!

 

Segue o log do malwarebytes:

 

 

Malwarebytes' Anti-Malware 1.40

Versão do banco de dados: 2560

Windows 5.1.2600 Service Pack 3

 

4/8/2009 17:09:00

mbam-log-2009-08-04 (17-09-00).txt

 

Tipo de Verificação: Completa (C:\|D:\|E:\|F:\|)

Objetos verificados: 191417

Tempo decorrido: 25 minute(s), 35 second(s)

 

Processos da Memória infectados: 1

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 3

Valores do Registro infectados: 1

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 10

 

Processos da Memória infectados:

C:\WINDOWS\msb.exe (Trojan.Agent) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

C:\WINDOWS\msb.exe (Trojan.Agent) -> Delete on reboot.

C:\Documents and Settings\Flake21\Local Settings\Temp\d.exe (Trojan.Dropper) -> Delete on reboot.

C:\Documents and Settings\Flake21\Local Settings\Temp\e.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Flake21\Local Settings\Temp\i.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Documents and Settings\Flake21\Local Settings\Temp\j.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.

D:\Arquivos\Video Editors -6in1\az-video\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Flake21\Application Data\Microsoft\profile.dat (Malware.Trace) -> Quarantined and deleted successfully.

C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

 

______________________________________

 

Segue o log do hajck this:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 17:11:35, on 4/8/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wscntfy.exe

C:\DOCUME~1\Flake21\LOCALS~1\Temp\d.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"

O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe

 

--

End of file - 7076 bytes

 

_________________________________

 

Aguardo retorno! obrigado mais uma vez!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! flake21

 

<!> Repita o scan com o Malwarebytes --> Escolha o escaneamento rápido! --> Poste o resultado!

<><><><><><><><><><>

<@> Baixe: < desktopicon.png > ( ...by sUBs )

<@> Salve-o no desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

 

<@> Ps: A execução,por comando,também é possível:

<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\Desktop\Combofix.exe" /killall

<@> Clique em Ok.

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link!

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!

<!> Ps: Para evitar problemas,siga todas as recomendações propostas.

<!> Ps: O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

<><><><><><><><><><>

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado pela ajuda DigRam!

Segue o log do malwarebyts

 

Malwarebytes' Anti-Malware 1.40

Versão do banco de dados: 2560

Windows 5.1.2600 Service Pack 3

 

5/8/2009 04:29:01

mbam-log-2009-08-05 (04-29-01).txt

 

Tipo de Verificação: Rápida

Objetos verificados: 106398

Tempo decorrido: 5 minute(s), 44 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 0

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

(Nenhum ítem malicioso foi detectado)

 

_______________________________________

 

Segue o log do Combofix

 

ComboFix 09-07-23.02 - Flake21 05/08/2009 5:25.1.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1449 [GMT -3:00]

Running from: c:\documents and settings\Flake21\Desktop\Limpeza Malwares\ComboFix.exe

AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

.

- REDUCED FUNCTIONALITY MODE -

.

 

((((((((((((((((((((((((( Files Created from 2009-07-05 to 2009-08-05 )))))))))))))))))))))))))))))))

.

 

2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\documents and settings\Flake21\Application Data\Malwarebytes

2009-08-04 19:16 . 2009-08-03 16:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-08-04 19:16 . 2009-08-04 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-08-04 19:16 . 2009-08-03 16:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-04 06:40 . 2009-08-04 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk

2009-08-04 04:56 . 2009-08-04 04:58 -------- d-----w- C:\DVDVideoSoft

2009-08-04 04:56 . 2009-08-04 04:56 -------- d-----w- c:\program files\Common Files\DVDVideoSoft

2009-08-04 04:56 . 2009-08-04 04:56 -------- d-----w- c:\program files\DVDVideoSoft

2009-08-04 04:56 . 2002-01-05 17:37 344064 ----a-w- c:\windows\system32\msvcr70.dll

2009-08-04 03:53 . 2009-08-04 03:53 -------- d-sh--w- c:\documents and settings\Flake21\PrivacIE

2009-08-04 03:46 . 2009-08-04 03:46 -------- d-----w- c:\program files\VSO

2009-08-04 03:28 . 2009-08-04 03:28 87608 ----a-w- c:\documents and settings\Flake21\Application Data\inst.exe

2009-08-04 03:28 . 2009-08-04 03:28 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys

2009-08-04 03:28 . 2009-08-04 03:28 47360 ----a-w- c:\documents and settings\Flake21\Application Data\pcouffin.sys

2009-08-04 03:28 . 2009-08-04 09:18 -------- d-----w- c:\documents and settings\Flake21\Application Data\Vso

2009-08-04 03:28 . 2007-03-19 00:37 65602 ----a-w- c:\windows\system32\cook3260.dll

2009-08-04 03:28 . 2006-09-29 16:26 176165 ----a-w- c:\windows\system32\drv23260.dll

2009-08-04 03:28 . 2006-09-29 16:25 208935 ----a-w- c:\windows\system32\drv33260.dll

2009-08-04 03:28 . 2006-09-29 16:24 217127 ----a-w- c:\windows\system32\drv43260.dll

2009-08-04 03:28 . 2006-05-20 20:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll

2009-08-04 03:28 . 2006-05-11 23:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll

2009-08-04 03:28 . 2002-12-10 06:20 102439 ----a-w- c:\windows\system32\sipr3260.dll

2009-08-03 20:38 . 2009-08-03 20:38 -------- d-----w- c:\documents and settings\Flake21\Local Settings\Application Data\Ahead

2009-07-30 06:32 . 2009-07-30 06:32 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2009-07-30 06:32 . 2009-07-30 06:32 -------- d-sh--w- c:\documents and settings\Flake21\IETldCache

2009-07-30 03:45 . 2009-07-19 21:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll

2009-07-30 03:45 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2009-07-30 03:45 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2009-07-30 03:45 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2009-07-30 03:45 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll

2009-07-30 03:45 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2009-07-30 03:45 . 2009-07-30 03:45 -------- d-----w- c:\windows\ie8updates

2009-07-30 03:45 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll

2009-07-30 03:44 . 2009-07-30 03:45 -------- dc-h--w- c:\windows\ie8

2009-07-28 20:06 . 2009-06-29 16:23 78336 -c----w- c:\windows\system32\dllcache\ieencode.dll

2009-07-28 20:06 . 2009-06-29 16:23 78336 ------w- c:\windows\system32\ieencode.dll

2009-07-28 20:06 . 2009-06-29 16:23 63488 -c----w- c:\windows\system32\dllcache\icardie.dll

2009-07-28 20:06 . 2009-06-29 11:25 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe

2009-07-28 20:06 . 2009-06-29 16:23 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll

2009-07-28 20:06 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat

2009-07-25 18:34 . 2009-07-25 18:41 66872 ----a-w- c:\windows\system32\PnkBstrA.exe

2009-07-25 18:34 . 2009-07-26 05:29 138184 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys

2009-07-25 18:34 . 2009-07-26 05:29 183112 ----a-w- c:\windows\system32\PnkBstrB.exe

2009-07-25 17:47 . 2009-07-25 17:47 -------- d-----w- c:\documents and settings\Flake21\Application Data\Leadertech

2009-07-24 22:28 . 2009-07-24 22:28 39200 ----a-w- c:\windows\system32\drivers\TfSysMon.sys

2009-07-24 22:28 . 2009-07-24 22:28 33056 ----a-w- c:\windows\system32\drivers\TfNetMon.sys

2009-07-24 22:28 . 2009-07-24 22:28 51488 ----a-w- c:\windows\system32\drivers\TfFsMon.sys

2009-07-24 22:28 . 2009-07-24 22:28 12576 ----a-w- c:\windows\system32\drivers\TfKbMon.sys

2009-07-24 19:53 . 2008-12-11 11:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2009-07-24 19:53 . 2009-07-24 22:27 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-07-24 19:53 . 2008-12-18 15:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-07-24 19:53 . 2009-07-24 19:55 -------- d-----w- c:\program files\Common Files\PC Tools

2009-07-24 19:53 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2009-07-24 19:52 . 2009-07-25 00:27 -------- d-----w- c:\program files\Spyware Doctor

2009-07-24 19:52 . 2009-07-24 22:29 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools

2009-07-24 19:52 . 2009-07-24 19:52 -------- d-----w- c:\documents and settings\Flake21\Application Data\PC Tools

2009-07-24 02:21 . 2009-06-16 14:36 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll

2009-07-24 02:21 . 2009-06-16 14:36 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll

2009-07-23 23:14 . 2009-07-23 23:14 -------- d--h--w- c:\windows\system32\GroupPolicy

2009-07-23 02:57 . 2009-07-23 02:57 -------- d--h--w- c:\windows\PIF

2009-07-22 20:28 . 2009-07-22 20:30 -------- d-----w- c:\program files\Spybot - Search & Destroy

2009-07-16 03:25 . 2009-07-16 03:25 -------- d-----w- c:\documents and settings\Flake21\Local Settings\Application Data\CAPCOM

2009-07-15 23:16 . 2009-07-24 22:30 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-07-15 22:57 . 2009-07-15 22:57 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE

2009-07-14 23:58 . 2009-07-14 23:58 -------- d-----w- c:\documents and settings\Saluzinho\Local Settings\Application Data\Adobe

2009-07-14 03:24 . 2008-04-14 00:11 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll

2009-07-14 03:24 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll

2009-07-14 03:24 . 2008-04-13 18:39 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys

2009-07-14 03:24 . 2008-04-13 18:39 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys

2009-07-14 03:24 . 2008-04-13 18:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys

2009-07-14 03:24 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-04 03:28 . 2009-04-26 01:28 -------- d-----w- c:\documents and settings\Flake21\Application Data\uTorrent

2009-07-24 02:25 . 2009-04-26 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-07-22 21:55 . 2009-04-21 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

2009-07-03 17:09 . 2007-07-22 13:17 915456 ----a-w- c:\windows\system32\wininet.dll

2009-06-22 12:23 . 2009-06-22 12:23 -------- d-----w- c:\program files\YourWare Solutions

2009-06-21 22:46 . 2009-06-21 22:46 -------- d-----w- c:\documents and settings\Saluzinho\Application Data\DivX

2009-06-21 22:45 . 2009-04-23 01:09 69232 ----a-w- c:\documents and settings\Saluzinho\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-06-16 14:36 . 2007-07-22 13:31 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-06-16 14:36 . 2007-07-22 13:16 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-06-16 04:06 . 2009-04-21 21:06 -------- d-----w- c:\documents and settings\Flake21\Application Data\Skype

2009-06-16 04:05 . 2009-04-21 21:08 -------- d-----w- c:\documents and settings\Flake21\Application Data\skypePM

2009-06-14 01:43 . 2009-04-21 19:39 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-06-14 01:43 . 2009-06-14 01:43 -------- d-----w- c:\program files\USB Vibration

2009-06-13 21:26 . 2009-04-21 16:06 102400 ----a-w- c:\windows\DUMP43b0.tmp

2009-06-11 04:28 . 2009-06-01 14:31 413696 ----a-w- c:\windows\system32\wrap_oal.dll

2009-06-11 04:28 . 2009-06-01 14:31 110592 ----a-w- c:\windows\system32\OpenAL32.dll

2009-06-08 03:10 . 2009-06-08 03:10 -------- d-----w- c:\program files\Noël Danjou

2009-06-08 02:21 . 2009-06-08 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!

2009-06-03 19:09 . 2007-07-22 13:15 1291264 ----a-w- c:\windows\system32\quartz.dll

2009-06-01 13:40 . 2009-04-21 22:12 721904 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-05-31 23:46 . 2009-04-21 19:34 69232 ----a-w- c:\documents and settings\Flake21\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-05-31 02:02 . 2009-04-21 22:18 158528 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2009-05-16 23:16 . 2009-05-16 23:16 0 ----a-w- c:\windows\ativpsrm.bin

2009-05-07 15:32 . 2004-08-04 01:56 345600 ----a-w- c:\windows\system32\localspl.dll

2009-08-04 04:49 . 2009-04-21 21:00 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]

"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-25 1397760]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]

"{1290A33C-85F5-4164-A1BE-7DD299D4986A}"="c:\program files\CyberLink\PowerBackup\PBKScheduler.exe" [2004-06-08 69721]

"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-10 53248]

"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-01-11 577536]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"ShowDeskFix"="shell32" [X]

 

c:\documents and settings\Flake21\Start Menu\Programs\Startup\

MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-4-21 534016]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

@=""

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

@=""

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\mmc.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"d:\\Download - Setups\\Programas\\utorrent.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"f:\\Garena\\Garena.exe"=

"f:\\Left4Dead\\left4dead.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"f:\\Evolved Games\\Terminator Salvation\\TerminatorSalvation.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"f:\\Steam\\steamapps\\flake21\\team fortress 2\\hl2.exe"=

"f:\\Street Fighter IV\\StreetFighterIV.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"2151:TCP"=

 

R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [21/4/2009 16:38 16640]

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [24/7/2009 16:53 130936]

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [24/7/2009 19:28 51488]

R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [24/7/2009 19:28 39200]

R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [24/7/2009 16:53 159600]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [21/4/2009 19:10 108289]

S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?]

S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [24/7/2009 16:53 64392]

S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [24/7/2009 16:52 348752]

S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [24/7/2009 19:28 33056]

S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.oglobo.com.br/

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

TCP: {DEE555A9-BC49-4E29-8284-35EFD504FCA7} = 192.168.254.254

FF - ProfilePath - c:\documents and settings\Flake21\Application Data\Mozilla\Firefox\Profiles\o3mmpvd5.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.oglobo.com.br/

FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll

 

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-05 05:25

Windows 5.1.2600 Service Pack 3 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

- - - - - - - > 'winlogon.exe'(812)

c:\windows\system32\Ati2evxx.dll

 

- - - - - - - > 'lsass.exe'(868)

c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

 

- - - - - - - > 'explorer.exe'(300)

c:\windows\system32\WININET.dll

c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll

c:\progra~1\WINDOW~2\wmpband.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

Completion time: 2009-08-05 5:26

ComboFix-quarantined-files.txt 2009-08-05 08:26

ComboFix2.txt 2009-07-24 02:17

ComboFix3.txt 2009-07-23 23:32

 

Pre-Run: 8.530.411.520 bytes free

Post-Run: 8.579.407.872 bytes free

 

220 --- E O F --- 2009-07-30 03:46

 

______________________________________

 

Segue o log do Hajackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:52:26, on 5/8/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Flake21\Desktop\Limpeza Malwares\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oglobo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 ME\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"

O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{DEE555A9-BC49-4E29-8284-35EFD504FCA7}: NameServer = 192.168.254.254

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe

 

--

End of file - 6712 bytes

 

___________________________

 

Muito obrigado por toda assistência!

um abç!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! flake21

 

S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?]

<!> Voçê conhece esta aplicação e seu serviço?

<><><><><><><><><>

<@> Baixe: < DDS > ( ...by sUBs )

<@> Salve-o no desktop!

<@> Desabilite seus programas de proteção: antivírus,antimalware,antispyware ou firewall.

<@> Estando desconectado,execute a ferramenta! --> Duplo clique em dds.scr.

<@> Aguarde o término do scan,até obtermos o relatório. ( DDS.txt ) <--

<@> Surgirá,também,uma nova janela: "D.D.S - Optional_Scan" --> Clique em Sim.

<@> O Bloco de Notas irá abrir,com outro relatório. ( Attach.txt ) <--

<@> Ps: Caso o relatório seja incompreensível,renomeie o executável para DDS.exe e repita o scan.

<@> Outra janela,finalmente,abrir-se-à! --> Clique em OK.

<@> Salve os relatórios: DDS.txt + Attach.txt <-- Poste-os!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam!

Desculpe pela demora em reponder, tive que viajar esse fds!

Obrigado mais uma vez pela rapidez!

Olha... Eu não conheço a aplicação citada, e não sei nada sobre seu serviço...

Como o orientado, segue o log DDS.txt

 

DDS (Ver_09-07-30.01) - NTFSx86

Run by Flake21 at 0:38:23,09 on seg 10/08/2009

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1521 [GMT -3:00]

 

AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

 

============== Running Processes ===============

 

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\Program Files\Ahead\InCD\InCDsrv.exe

svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wscntfy.exe

D:\Download - Setups\Programas\dds.scr

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://www.oglobo.com.br/

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0 me\reader\activex\AcroIEHelper.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win

uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe

mRun: [soundMan] SOUNDMAN.EXE

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [inCD] c:\program files\ahead\incd\InCD.exe

mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"

mRun: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "c:\program files\cyberlink\powerbackup\PBKScheduler.exe"

mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [startCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRunOnce: [showDeskFix] regsvr32 /s /n /i:u shell32

StartupFolder: c:\docume~1\flake21\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll

LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll

DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

TCP: {DEE555A9-BC49-4E29-8284-35EFD504FCA7} = 192.168.254.254

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Notify: AtiExtEvent - Ati2evxx.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\flake21\applic~1\mozilla\firefox\profiles\o3mmpvd5.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.oglobo.com.br/

FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nprpjplug.dll

 

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

 

============= SERVICES / DRIVERS ===============

 

R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [2009-4-21 16640]

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-24 130936]

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-7-24 51488]

R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-7-24 39200]

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-4-21 11608]

R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-7-24 159600]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-4-21 108289]

R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-4-21 185089]

R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-4-21 55656]

S0 kimx;kimx;c:\windows\system32\drivers\mrzvn.sys --> c:\windows\system32\drivers\mrzvn.sys [?]

S3 GarenaPEngine;GarenaPEngine;c:\docume~1\flake21\locals~1\temp\KACC7.tmp [2009-8-5 18704]

S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2009-7-24 64392]

S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-24 348752]

S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-24 1095560]

S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-7-24 33056]

S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]

 

=============== Created Last 30 ================

 

2009-08-05 05:24 <DIR> --ds---- C:\ComboFix

2009-08-04 16:16 <DIR> --d----- c:\docume~1\flake21\applic~1\Malwarebytes

2009-08-04 16:16 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-04 16:16 19,096 a------- c:\windows\system32\drivers\mbam.sys

2009-08-04 16:16 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware

2009-08-04 16:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes

2009-08-04 03:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\vsosdk

2009-08-04 01:56 <DIR> --d----- C:\DVDVideoSoft

2009-08-04 01:56 <DIR> --d----- c:\program files\common files\DVDVideoSoft

2009-08-04 01:56 344,064 a------- c:\windows\system32\msvcr70.dll

2009-08-04 01:56 <DIR> --d----- c:\program files\DVDVideoSoft

2009-08-04 00:53 <DIR> --dsh--- c:\documents and settings\flake21\PrivacIE

2009-08-04 00:46 <DIR> --d----- c:\program files\VSO

2009-08-04 00:28 87,608 a------- c:\docume~1\flake21\applic~1\inst.exe

2009-08-04 00:28 47,360 a------- c:\windows\system32\drivers\pcouffin.sys

2009-08-04 00:28 47,360 a------- c:\docume~1\flake21\applic~1\pcouffin.sys

2009-08-04 00:28 1,184,984 a------- c:\windows\system32\wvc1dmod.dll

2009-08-04 00:28 626,688 a------- c:\windows\system32\vp7vfw.dll

2009-08-04 00:28 217,127 a------- c:\windows\system32\drv43260.dll

2009-08-04 00:28 208,935 a------- c:\windows\system32\drv33260.dll

2009-08-04 00:28 176,165 a------- c:\windows\system32\drv23260.dll

2009-08-04 00:28 102,439 a------- c:\windows\system32\sipr3260.dll

2009-08-04 00:28 65,602 a------- c:\windows\system32\cook3260.dll

2009-07-30 03:32 <DIR> --dsh--- c:\documents and settings\flake21\IETldCache

2009-07-30 00:45 11,067,392 -c------ c:\windows\system32\dllcache\ieframe.dll

2009-07-30 00:45 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll

2009-07-30 00:45 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll

2009-07-30 00:45 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll

2009-07-30 00:45 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll

2009-07-30 00:45 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll

2009-07-30 00:45 <DIR> --d----- c:\windows\ie8updates

2009-07-30 00:45 101,376 -c------ c:\windows\system32\dllcache\iecompat.dll

2009-07-30 00:44 <DIR> -cd-h--- c:\windows\ie8

2009-07-28 17:06 78,336 -c------ c:\windows\system32\dllcache\ieencode.dll

2009-07-28 17:06 63,488 -c------ c:\windows\system32\dllcache\icardie.dll

2009-07-28 17:06 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe

2009-07-28 17:06 78,336 -------- c:\windows\system32\ieencode.dll

2009-07-28 17:06 2,452,872 -c------ c:\windows\system32\dllcache\ieapfltr.dat

2009-07-28 17:06 991,232 -c------ c:\windows\system32\dllcache\ieframe.dll.mui

2009-07-28 17:06 380,928 -c------ c:\windows\system32\dllcache\ieapfltr.dll

2009-07-25 15:34 66,872 a------- c:\windows\system32\PnkBstrA.exe

2009-07-25 15:34 138,184 a------- c:\windows\system32\drivers\PnkBstrK.sys

2009-07-25 15:34 183,112 a------- c:\windows\system32\PnkBstrB.exe

2009-07-24 19:28 51,488 a------- c:\windows\system32\drivers\TfFsMon.sys

2009-07-24 19:28 39,200 a------- c:\windows\system32\drivers\TfSysMon.sys

2009-07-24 19:28 33,056 a------- c:\windows\system32\drivers\TfNetMon.sys

2009-07-24 19:28 12,576 a------- c:\windows\system32\drivers\TfKbMon.sys

2009-07-24 16:53 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys

2009-07-24 16:53 130,936 a------- c:\windows\system32\drivers\PCTCore.sys

2009-07-24 16:53 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys

2009-07-24 16:53 <DIR> --d----- c:\program files\common files\PC Tools

2009-07-24 16:53 64,392 a------- c:\windows\system32\drivers\pctplsg.sys

2009-07-24 16:52 <DIR> --d----- c:\program files\Spyware Doctor

2009-07-24 16:52 <DIR> --d----- c:\docume~1\flake21\applic~1\PC Tools

2009-07-24 16:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools

2009-07-23 23:21 119,808 -c------ c:\windows\system32\dllcache\t2embed.dll

2009-07-23 23:21 81,920 -c------ c:\windows\system32\dllcache\fontsub.dll

2009-07-23 21:24 4,096 a------- c:\windows\system32\crash

2009-07-23 20:31 <DIR> -cd----- c:\windows\system32\dllcache\cache

2009-07-23 20:29 <DIR> a-dshr-- C:\cmdcons

2009-07-23 20:25 219,648 a------- c:\windows\PEV.exe

2009-07-23 20:25 161,792 a------- c:\windows\SWREG.exe

2009-07-23 20:25 98,816 a------- c:\windows\sed.exe

2009-07-23 20:14 <DIR> --d-h--- c:\windows\system32\GroupPolicy

2009-07-22 23:57 <DIR> --d-h--- c:\windows\PIF

2009-07-22 17:28 <DIR> --d----- c:\program files\Spybot - Search & Destroy

2009-07-15 20:16 124,688 a------- c:\windows\system32\MSWINSCK.OCX

2009-07-15 19:57 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE

2009-07-14 00:24 21,504 ac------ c:\windows\system32\dllcache\hidserv.dll

2009-07-14 00:24 21,504 a------- c:\windows\system32\hidserv.dll

2009-07-14 00:24 14,592 ac------ c:\windows\system32\dllcache\kbdhid.sys

2009-07-14 00:24 14,592 a------- c:\windows\system32\drivers\kbdhid.sys

2009-07-14 00:24 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys

2009-07-14 00:24 32,128 a------- c:\windows\system32\drivers\usbccgp.sys

 

==================== Find3M ====================

 

2009-08-05 20:00 55,656 a------- c:\windows\system32\drivers\avgntflt.sys

2009-07-03 14:09 915,456 a------- c:\windows\system32\wininet.dll

2009-06-16 11:36 119,808 a------- c:\windows\system32\t2embed.dll

2009-06-16 11:36 81,920 a------- c:\windows\system32\fontsub.dll

2009-06-13 18:26 102,400 a------- c:\windows\DUMP43b0.tmp

2009-06-11 01:28 413,696 a------- c:\windows\system32\wrap_oal.dll

2009-06-11 01:28 110,592 a------- c:\windows\system32\OpenAL32.dll

2009-06-03 16:09 1,291,264 a------- c:\windows\system32\quartz.dll

2009-05-06 03:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009042020090427\index.dat

2009-05-06 03:07 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009050620090507\index.dat

 

============= FINISH: 0:38:43,46 ===============

 

 

_______________________________________

 

Segue o log Attach.txt

 

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

 

DDS (Ver_09-07-30.01)

 

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 21/4/2009 16:28:06

System Uptime: 8/10/2009 00:01:14 (-1416 hours ago)

 

Motherboard: DFI Inc. | | NF UltraII-M2 /NF SLiII-M2 /NFII -M2

Processor: AMD Athlon 64 X2 Dual Core Processor 4800+ | Socket M2 | 2511/201mhz

 

==== Disk Partitions =========================

 

A: is Removable

C: is FIXED (NTFS) - 47 GiB total, 7,954 GiB free.

D: is FIXED (FAT32) - 69 GiB total, 27,571 GiB free.

E: is FIXED (FAT32) - 47 GiB total, 20,684 GiB free.

F: is FIXED (NTFS) - 71 GiB total, 6,535 GiB free.

G: is CDROM ()

H: is CDROM ()

 

==== Disabled Device Manager Items =============

 

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Description: PC Camera

Device ID: USB\VID_0AC8&PID_301B\5&27A050D6&0&2

Manufacturer:

Name: PC Camera

PNP Device ID: USB\VID_0AC8&PID_301B\5&27A050D6&0&2

Service:

 

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

Description: NVIDIA nForce Networking Controller

Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&33E880BB&0&01

Manufacturer: Nvidia

Name: NVIDIA nForce Networking Controller

PNP Device ID: {1A3E09BE-1E45-494B-9174-D7385B45BBF5}\NVNET_DEV0057\4&33E880BB&0&01

Service: NVENETFD

 

==== System Restore Points ===================

 

RP1: 26/6/2009 17:42:24 - System Checkpoint

RP2: 29/6/2009 10:30:49 - System Checkpoint

RP3: 30/6/2009 16:20:19 - System Checkpoint

RP4: 3/7/2009 21:16:42 - System Checkpoint

RP5: 4/7/2009 22:45:15 - System Checkpoint

RP6: 8/7/2009 11:30:04 - System Checkpoint

RP7: 10/7/2009 22:12:25 - System Checkpoint

RP8: 11/7/2009 23:02:45 - System Checkpoint

RP9: 12/7/2009 23:51:42 - System Checkpoint

RP10: 14/7/2009 12:42:35 - System Checkpoint

RP11: 15/7/2009 13:43:16 - System Checkpoint

RP12: 15/7/2009 19:57:20 - Installed DirectX

RP13: 15/7/2009 19:57:43 - Installed DirectX

RP14: 15/7/2009 19:57:54 - Installed STREET FIGHTER IV.

RP15: 15/7/2009 23:52:41 - Installed DirectX

RP16: 17/7/2009 13:28:50 - System Checkpoint

RP17: 20/7/2009 15:34:26 - System Checkpoint

RP18: 21/7/2009 16:01:33 - System Checkpoint

RP19: 22/7/2009 21:01:10 - System Checkpoint

RP20: 23/7/2009 23:00:45 - System Checkpoint

RP21: 23/7/2009 23:16:56 - Software Distribution Service 3.0

RP22: 23/7/2009 23:23:57 - Software Distribution Service 3.0

RP23: 24/7/2009 03:00:14 - Software Distribution Service 3.0

RP24: 24/7/2009 20:16:38 - Software Distribution Service 3.0

RP25: 25/7/2009 03:00:13 - Software Distribution Service 3.0

RP26: 25/7/2009 14:48:20 - Installed DirectX

RP27: 25/7/2009 15:20:46 - Installed Need for Speed™ Undercover

RP28: 25/7/2009 21:54:59 - Software Distribution Service 3.0

RP29: 25/7/2009 23:50:04 - Software Distribution Service 3.0

RP30: 26/7/2009 02:44:00 - Software Distribution Service 3.0

RP31: 26/7/2009 04:19:39 - Software Distribution Service 3.0

RP32: 26/7/2009 18:17:27 - Software Distribution Service 3.0

RP33: 26/7/2009 18:43:21 - Software Distribution Service 3.0

RP34: 28/7/2009 00:38:11 - Software Distribution Service 3.0

RP35: 28/7/2009 02:56:14 - Software Distribution Service 3.0

RP36: 28/7/2009 23:57:47 - Removed Need for Speed™ Undercover

RP37: 29/7/2009 03:00:16 - Software Distribution Service 3.0

RP38: 30/7/2009 00:41:22 - Software Distribution Service 3.0

RP39: 31/7/2009 20:50:24 - System Checkpoint

RP40: 1/8/2009 22:15:12 - System Checkpoint

RP41: 2/8/2009 22:25:41 - System Checkpoint

RP42: 3/8/2009 22:37:24 - System Checkpoint

RP43: 4/8/2009 22:42:48 - System Checkpoint

RP44: 8/8/2009 04:21:36 - System Checkpoint

 

==== Installed Programs ======================

 

µTorrent

7-Zip 4.65

Adobe Flash Player 10 Plugin

Adobe Reader 6.0.2 ME

AMCap

Arquivo do WinRAR

Assistente de Conexão do Windows Live

ATI - Software Uninstall Utility

ATI Catalyst Control Center

ATI Display Driver

ATI HydraVision

ATI Parental Control & Encoder

Avira AntiVir Personal - Free Antivirus

AVIVO Codecs

biohazard 4

BS.Player FREE powered by AdVantage

Catalyst Control Center - Branding

Catalyst Control Center Core Implementation

Catalyst Control Center Graphics Full Existing

Catalyst Control Center Graphics Full New

Catalyst Control Center Graphics Light

Catalyst Control Center Graphics Previews Common

Catalyst Control Center HydraVision Full

ccc-core-preinstall

ccc-core-static

ccc-utility

CCC Help English

Choice Guard

Codec Pack - All In 1 6.0.3.0

ConvertXtoDVD 3.6.9.168

CoreAVC Pro 1.3.0.0

Critical Update for Windows Media Player 11 (KB959772)

DAEMON Tools Toolbar

Ferramenta de Carregamento do Windows Live

Free YouTube to Mp3 Converter version 2.5

Garena

Half-Life 2: Episode One

Half-Life 2: Episode Two

HijackThis 2.0.2

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Windows Media Player 11 (KB939683)

Hotfix for Windows XP (KB952287)

Hotfix for Windows XP (KB954550-v5)

Hotfix for Windows XP (KB961118)

K-Lite Codec Pack 3.2.5 Full

Left 4 Dead Standalone Patch

Magic ISO Maker v5.4 (build 0239)

MagicDisc 2.5.74

Malwarebytes' Anti-Malware

Messenger Plus! Live

Microsoft .NET Framework 2.0 Service Pack 2

Microsoft .NET Framework 3.0 Service Pack 2

Microsoft .NET Framework 3.5 SP1

Microsoft Application Error Reporting

Microsoft Games for Windows - LIVE

Microsoft Games for Windows - LIVE Redistributable

Microsoft Office Access MUI (English) 2007

Microsoft Office Access Setup Metadata MUI (English) 2007

Microsoft Office Enterprise 2007

Microsoft Office Excel MUI (English) 2007

Microsoft Office Groove MUI (English) 2007

Microsoft Office Groove Setup Metadata MUI (English) 2007

Microsoft Office InfoPath MUI (English) 2007

Microsoft Office OneNote MUI (English) 2007

Microsoft Office Outlook MUI (English) 2007

Microsoft Office PowerPoint MUI (English) 2007

Microsoft Office Proof (English) 2007

Microsoft Office Proof (French) 2007

Microsoft Office Proof (Spanish) 2007

Microsoft Office Proofing (English) 2007

Microsoft Office Publisher MUI (English) 2007

Microsoft Office Shared MUI (English) 2007

Microsoft Office Shared Setup Metadata MUI (English) 2007

Microsoft Office Word MUI (English) 2007

Microsoft Software Update for Web Folders (English) 12

Microsoft Visual C Runtime

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Mozilla Firefox (3.0.13)

MSVCRT

MSXML 4.0 SP2 (KB954430)

MSXML 6 Service Pack 2 (KB954459)

MUSICMATCH® Jukebox

Nero Suite

NVIDIA Drivers

NVIDIA PhysX

OpenAL

Portal

Power2Go 4.0

PowerBackup 1.0

PowerDirector Express

PowerDVD

PowerDVD Copy 1.0

PowerProducer

PowerStarter

PS TO PC CONVERTER

RealPlayer

Realtek AC'97 Audio

Security Update for 2007 Microsoft Office System (KB951550)

Security Update for 2007 Microsoft Office System (KB951944)

Security Update for 2007 Microsoft Office System (KB960003)

Security Update for Microsoft Office Excel 2007 (KB959997)

Security Update for Microsoft Office OneNote 2007 (KB950130)

Security Update for Microsoft Office PowerPoint 2007 (KB951338)

Security Update for Microsoft Office Publisher 2007 (KB950114)

Security Update for Microsoft Office system 2007 (KB954326)

Security Update for Microsoft Office system 2007 (KB956828)

Security Update for Microsoft Office Word 2007 (KB956358)

Security Update for Outlook 2007 (KB946983)

Security Update for Windows Internet Explorer 7 (KB938127-v2)

Security Update for Windows Internet Explorer 7 (KB972260)

Security Update for Windows Internet Explorer 8 (KB972260)

Security Update for Windows Media Player (KB952069)

Security Update for Windows Media Player 11 (KB936782)

Security Update for Windows Media Player 11 (KB954154)

Security Update for Windows XP (KB923561)

Security Update for Windows XP (KB938464-v2)

Security Update for Windows XP (KB941569)

Security Update for Windows XP (KB946648)

Security Update for Windows XP (KB950760)

Security Update for Windows XP (KB950762)

Security Update for Windows XP (KB950974)

Security Update for Windows XP (KB951066)

Security Update for Windows XP (KB951376-v2)

Security Update for Windows XP (KB951748)

Security Update for Windows XP (KB952004)

Security Update for Windows XP (KB952954)

Security Update for Windows XP (KB954459)

Security Update for Windows XP (KB954600)

Security Update for Windows XP (KB955069)

Security Update for Windows XP (KB956572)

Security Update for Windows XP (KB956802)

Security Update for Windows XP (KB956803)

Security Update for Windows XP (KB957097)

Security Update for Windows XP (KB958644)

Security Update for Windows XP (KB958687)

Security Update for Windows XP (KB958690)

Security Update for Windows XP (KB959426)

Security Update for Windows XP (KB960225)

Security Update for Windows XP (KB960715)

Security Update for Windows XP (KB960803)

Security Update for Windows XP (KB961371)

Security Update for Windows XP (KB961373)

Security Update for Windows XP (KB961501)

Security Update for Windows XP (KB968537)

Security Update for Windows XP (KB969898)

Security Update for Windows XP (KB970238)

Security Update for Windows XP (KB971633)

Security Update for Windows XP (KB973346)

Segoe UI

Skins

Skype™ 3.8

Smart Guardian

Software Update for Web Folders

Spybot - Search & Destroy

Spyware Doctor 6.0

Steam

STREET FIGHTER IV

Team Fortress 2

Terminator Salvation

Trials 2 Second Edition

Uninstall 1.0.0.0

Update for 2007 Microsoft Office System (KB967642)

Update for Office 2007 (KB934391)

Update for Outlook 2007 Junk Email Filter (kb971933)

Update for Windows Internet Explorer 8 (KB972636)

Update for Windows XP (KB951978)

Update for Windows XP (KB955839)

Update for Windows XP (KB961503)

Update for Windows XP (KB967715)

VideoLAN VLC media player 0.8.6c

Vista Codec Package

Windows Genuine Advantage Notifications (KB905474)

Windows Imaging Component

Windows Installer 3.1 (KB893803)

Windows Internet Explorer 8

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Messenger

Windows Presentation Foundation

Windows XP Service Pack 3

XML Paper Specification Shared Components Pack 1.0

XP Codec Pack

 

==== Event Viewer Messages From Past Week ========

 

5/8/2009 05:30:54, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.

5/8/2009 05:25:52, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.

 

==== End Of File ===========================

 

_______________________________________

 

Agradeço desde já mais uma vez!

um abraço!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! flake21

 

<@> Submeta este(s) ficheiro(s),à uma análise em: < Sunbelt Sandbox >

 

<!> c:\windows\system32\drivers\mrzvn.sys <--

 

<@> No campo,digite o seu E-Mail.

<@> Escolha o relatório,das verificações,no formato texto!

<@> Clique em: Submit sample for analysis,após indicar o caminho ao(s) ficheiros para upload.

<@> Poste o(s) relatório(s),dessa(s) análise(s),que lhe serão enviadas por E-Mail.

<@> Ps: Caso a pesquisa seja inconclusiva,verifique se o arquivo mrzvn.sys encontra-se oculto.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRram!

Obrigado mais uma vez pelo auxílio! Infelizmente, dessa vez, eu não consegui fazer o que foi solicitado!

A entrada para o arquivo "c:\windows\system32\drivers\mrzvn.sys" não estava na pasta c:\windows\system32\drivers...

Não consegui encontrar o arquivo, mesmo depois de selecionar a opção de visualização de pastas e arquivos ocultos!

não pude obter o log!

=/

Fico no aguardo!

abraços

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! flake21

 

<!> Com certeza,não existe mais no PC.

<><><><><><><><><>

<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.

<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )

<@> Clique em Executar --> Aguarde!

<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.

<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!

<><><><><><><><><>

<!> Os logs estão limpos!

<!> Bom trabalho! :thumbsup:

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado novamente DigRam!

Obrigado pela competência, rapidez e paciência que você teve ao guiar todo o processo!

é de pessoas asism que a rede precisa!

muito obrigado!

Problema mais que resolvido!! :yes:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.