Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Ariane Taisa

[Resolvido!] Virus do som @_@

Recommended Posts

Então, ontem baixei no www.4shared.com o DAEMON TOOLS -.-'... até ai ok...

instalei, funciono certinho...

mas notei algo no pc =P... tava tocando pedaços de musicas toda hora kkkk... fechei todos os programas abertos, esperei e a fia da mae nao parava @_@...

hoje mesma coisa, as vezes ouvia vozes, risadas, depois gritos...

ai baixei o AVAST, fiz o escaneamento...

deu nisso...

pegueimuahahaha.jpg

-.-'... f*** neh...

ai exclui o arquivo -.-'...

rrrrip.jpg

 

mas tem um problema ¬¬, agora to ouvindo som de propaganda italiana -.-', ainda nao paro =x

alguma solução ou dica? :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Ariane Taisa! Baixe > HijackThis

 

Abra uma pasta em C:\ e salve nela.

 

Quando abrir a ferramenta, clique em "Do a system scan and save a logfile". Selecione, copie todo o seu conteúdo e cole na sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Logfile of HijackThis v1.99.1

Scan saved at 21:43:14, on 21/10/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\csrcs.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Outlook Express\data\bin\Explorer.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\DOCUME~1\ARIANE~1\CONFIG~1\Temp\Rar$EX00.781\Skype.exe

C:\Documents and Settings\Ariane Taisa\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [sys] C:\Arquivos de programas\Outlook Express\data\bin\Explorer.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [DAEMON Tools] "C:\Arquivos de programas\DAEMON Tools\daemon.exe" -lang 1033

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

 

 

:o

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o Malwarebytes' Anti-Malware (MBAM) '>http://www.besttechie.net/tools/mbam-setup.exe"]neste link ou '>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html"]neste aqui.

 

Baixe: '>http://download.bleepingcomputer.com/sUBs/ComboFix.exe"]ComboFix > salve na área de trabalho

 

Salve ou imprima estas instruções:

 

A ordem de rodar as ferramentas deve ser como está nas instruções.

 

Dê um duplo-clique no mbam-setup.exe, escolha a linguagem e na instalação, aceite todas as opções padrão.

 

  • Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas e clique então, em Concluir.
  • Se houver atualizações a serem feitas, serão baixadas e instaladas.
  • Ao final da atualização, com o programa aberto, marque Verificação Rápida e clique no botão Verificar.
  • Começará então o exame. Aguarde, pois pode demorar.
  • Ao acabar o exame, clique em OK, depois no botão Mostrar Resultados para ver o relatório.
  • Se houver ítens encontrados, certifique-se de que, estão todos marcados e clique no botão Remover.
  • Ao final da desinfecção, abrirá o Bloco de notas com um log e poderá aparecer um aviso se quer reiniciar o PC. (Ver Nota abaixo)
  • O log é automaticamente salvo pelo MBAM e para vê-lo, clique na aba Logs na janela principal do programa.
    NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar o PC.
  • Desative seu antivirus, antispywares e firewall, para não causar conflitos. Mantenha-os desativados até terminar as instruções.
  • Dê um duplo-clique no combofix.exe e clique em Executar para prosseguir o Fix. Aguarde pois é um pouco demorado.
  • O ComboFix reiniciará o PC automaticamente para completar o processo de remoção. Caso isso não aconteça, reinicie manualmente.
  • Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.
  • IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Para parar ou sair do ComboFix, tecle "N".
  • Selecione, copie e cole o conteúdo do log do MBAM na sua póxima resposta + o conteúdo do ComboFix.txt.
     
    OBS: Não rode o ComboFix mais do que uma vez. Isso irá sobreescrever o log e dificultará a remoção do(s) malware(s)

O ComboFix é uma ferramenta que pode danificar o sistema se for usada incorretamente. Use-o apenas sob supervisão de um analista de malwares.

Compartilhar este post


Link para o post
Compartilhar em outros sites

malwarebytes::----------------------

------------------------------------------

Malwarebytes' Anti-Malware 1.41

Versão do banco de dados: 3012

Windows 5.1.2600 Service Pack 2

 

22/10/2009 14:16:52

mbam-log-2009-10-22 (14-16-52).txt

 

Tipo de Verificação: Rápida

Objetos verificados: 87027

Tempo decorrido: 4 minute(s), 2 second(s)

 

Processos da Memória infectados: 1

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 1

Ítens do Registro infectados: 1

Pastas infectadas: 0

Arquivos infectados: 1

 

Processos da Memória infectados:

C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\csrcs (Trojan.Agent) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Delete on reboot.

 

ComboFix 09-10-23.01 - Ariane Taisa 24/10/2009 15:09.1.1 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1503.949 [GMT -2:00]

Executando de: c:\documents and settings\Ariane Taisa\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1296 [VPS 091023-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-09-24 to 2009-10-24 ))))))))))))))))))))))))))))

.

 

2009-10-24 16:59 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-24 16:59 . 2009-10-24 16:59 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-10-24 16:59 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-24 13:41 . 2009-10-24 13:41 -------- d-----w- c:\windows\system32\CatRoot_bak

2009-10-24 13:13 . 2009-10-24 13:13 -------- d-----w- c:\windows\LastGood

2009-10-24 01:42 . 2009-10-24 01:42 -------- d--h--w- c:\windows\$hf_mig$

2009-10-24 01:34 . 2009-10-24 01:34 -------- d-----w- C:\FOUND.002

2009-10-23 19:59 . 2009-02-09 11:50 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-10-23 19:59 . 2009-02-09 11:50 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2009-10-23 19:59 . 2009-02-09 11:50 2184704 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2009-10-23 19:58 . 2009-02-09 11:50 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-10-23 19:38 . 2002-07-03 13:44 53248 ----a-w- c:\windows\amcap.exe

2009-10-23 19:38 . 2004-08-30 18:37 286720 ----a-w- c:\windows\vsnpstd2.exe

2009-10-23 19:38 . 2004-06-08 20:25 53248 ----a-w- c:\windows\system32\dsnpstd2.dll

2009-10-23 19:37 . 2004-12-16 20:14 347264 ----a-w- c:\windows\system32\drivers\snpstd2.sys

2009-10-23 19:37 . 2004-09-24 18:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll

2009-10-23 19:37 . 2004-09-24 15:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll

2009-10-23 19:37 . 2004-02-16 15:59 61440 ----a-w- c:\windows\system32\csnpstd2.dll

2009-10-23 19:37 . 2009-10-23 19:37 -------- d-----w- c:\arquivos de programas\Arquivos comuns\snpstd2

2009-10-23 19:37 . 2004-06-09 18:00 20480 ----a-w- c:\windows\usnpstd2.exe

2009-10-23 19:27 . 2009-10-23 19:27 -------- d-----w- C:\FOUND.001

2009-10-23 19:12 . 2009-10-23 19:12 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-10-23 19:12 . 2009-10-23 19:12 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\skypePM

2009-10-23 19:11 . 2009-10-23 19:12 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype

2009-10-23 19:11 . 2009-10-23 19:11 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Skype

2009-10-22 20:50 . 2009-10-22 20:50 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\DAEMON Tools

2009-10-22 20:49 . 2009-10-22 20:49 -------- d-----w- c:\arquivos de programas\DAEMON Tools Lite

2009-10-22 16:10 . 2009-10-22 16:10 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Malwarebytes

2009-10-22 16:10 . 2009-10-22 16:10 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-10-21 22:02 . 2008-11-26 17:16 50864 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2009-10-21 22:02 . 2008-11-26 17:16 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2009-10-21 22:02 . 2008-11-26 17:15 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2009-10-21 22:01 . 2008-11-26 17:15 97480 ----a-w- c:\windows\system32\AvastSS.scr

2009-10-21 22:01 . 2008-11-26 17:17 111184 ----a-w- c:\windows\system32\drivers\aswSP.sys

2009-10-21 22:01 . 2008-11-26 17:17 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2009-10-21 22:01 . 2008-11-26 17:18 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys

2009-10-21 22:01 . 2008-11-26 17:18 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2009-10-21 22:01 . 2008-11-26 17:21 1236208 ----a-w- c:\windows\system32\aswBoot.exe

2009-10-21 22:01 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll

2009-10-21 22:01 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll

2009-10-21 22:01 . 2009-10-21 22:01 -------- d-----w- c:\arquivos de programas\Alwil Software

2009-10-20 11:25 . 2009-10-20 11:25 -------- d-----w- c:\arquivos de programas\EA GAMES

2009-10-20 11:25 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll

2009-10-20 11:18 . 2009-10-22 20:47 716272 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-10-17 22:21 . 2009-10-17 22:21 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Media Player Classic

2009-10-17 18:33 . 2009-10-17 18:33 -------- d-----w- c:\windows\PAC207

2009-10-17 18:20 . 2009-10-17 18:20 -------- d-----w- c:\windows\Downloaded Installations

2009-10-16 16:05 . 2009-10-16 16:05 -------- d-----w- c:\arquivos de programas\Windows Media Connect 2

2009-10-16 16:03 . 2009-10-16 16:03 -------- d-----w- c:\windows\system32\drivers\UMDF

2009-10-16 16:03 . 2009-10-16 16:03 -------- d-----w- c:\windows\system32\LogFiles

2009-10-16 16:03 . 2008-07-09 07:34 26488 ----a-w- c:\windows\system32\spupdsvc.exe

2009-10-16 09:17 . 2009-10-16 09:17 -------- d-----w- C:\FOUND.000

2009-10-15 11:15 . 2004-08-04 01:08 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\Realtek Sound Manager

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\AvRack

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\Realtek AC97

2009-10-14 11:14 . 2005-08-19 08:31 3644800 ----a-r- c:\windows\system32\drivers\ALCXWDM.SYS

2009-10-14 11:14 . 2005-08-17 09:39 90112 ----a-r- c:\windows\SOUNDMAN.EXE

2009-10-14 11:14 . 2005-07-15 07:48 40960 ------r- c:\windows\system32\ChCfg.exe

2009-10-14 11:14 . 2004-09-07 05:23 156672 ----a-r- c:\windows\system32\RtlCPAPI.dll

2009-10-14 11:14 . 2005-08-17 09:21 10458112 ----a-r- c:\windows\system32\RTLCPL.EXE

2009-10-14 11:14 . 2005-08-12 09:40 307200 ------r- c:\windows\alcupd.exe

2009-10-14 11:14 . 2005-08-12 08:35 212992 ------r- c:\windows\alcrmv.exe

2009-10-14 11:14 . 2009-10-14 11:14 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2009-10-14 11:13 . 2009-10-14 11:13 -------- d-----w- c:\arquivos de programas\Arquivos comuns\InstallShield

2009-10-13 18:11 . 2009-10-13 18:11 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Skype

2009-10-10 20:59 . 2009-10-10 20:59 -------- d-----w- c:\documents and settings\Ariane Taisa\Configuraes locais

2009-10-10 20:54 . 2009-10-10 20:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2009-10-10 20:00 . 2009-10-10 20:00 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2009-10-10 19:19 . 2009-10-10 19:19 -------- d-----w- c:\documents and settings\Ariane Taisa\Tracing

2009-10-10 19:18 . 2009-10-10 19:18 -------- d-----w- c:\arquivos de programas\Microsoft

2009-10-10 19:18 . 2009-10-10 19:18 -------- d-----w- c:\arquivos de programas\Windows Live SkyDrive

2009-10-10 19:12 . 2009-10-10 19:12 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live

2009-10-10 19:08 . 2009-10-10 19:08 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Talkback

2009-10-10 19:08 . 2009-10-10 19:08 0 ----a-w- c:\windows\nsreg.dat

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-10-24 13:13 . 2001-10-28 16:07 48628 ----a-w- c:\windows\system32\perfc016.dat

2009-10-24 13:13 . 2001-10-28 16:07 344380 ----a-w- c:\windows\system32\perfh016.dat

2009-10-22 20:34 . 2009-10-10 18:04 98304 ----a-w- c:\windows\DUMP561e.tmp

2009-10-17 22:17 . 2009-10-17 22:17 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack

2009-10-10 18:59 . 2009-10-10 18:59 -------- d-----w- c:\arquivos de programas\Windows Live

2009-10-10 18:44 . 2009-10-10 18:44 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe

2009-10-10 18:29 . 2009-10-10 18:29 -------- d-----w- c:\arquivos de programas\microsoft frontpage

2009-10-10 18:26 . 2009-10-10 18:26 -------- d-----w- c:\arquivos de programas\Serviços on-line

2009-10-10 18:25 . 2009-10-10 18:25 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Serviços

2009-10-10 18:24 . 2009-10-10 18:24 21844 ----a-w- c:\windows\system32\emptyregdb.dat

2009-07-26 18:44 . 2009-07-26 18:44 48448 ----a-w- c:\windows\system32\sirenacm.dll

2009-10-12 14:50 . 2009-10-10 19:07 67688 ----a-w- c:\arquivos de programas\mozilla firefox\components\jar50.dll

2009-10-12 14:50 . 2009-10-10 19:07 54368 ----a-w- c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2009-10-12 14:50 . 2009-10-10 19:07 34944 ----a-w- c:\arquivos de programas\mozilla firefox\components\myspell.dll

2009-10-12 14:50 . 2009-10-10 19:07 46712 ----a-w- c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2009-10-12 14:50 . 2009-10-10 19:07 172136 ----a-w- c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sys"="c:\arquivos de programas\Outlook Express\data\bin\Explorer.exe" [2009-09-21 28672]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883840]

"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-01-17 486856]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"Malwarebytes Anti-Malware (reboot)"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-08-30 286720]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-08-17 90112]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\Ariane Taisa\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=

"c:\\Documents and Settings\\Ariane Taisa\\Meus documentos\\Aslj_Client\\aslj.bin"=

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/10/2009 20:01 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/10/2009 20:01 20560]

S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]

S3 st3bus28;st3bus28;c:\windows\system32\DRIVERS\st3bus28.sys --> c:\windows\system32\DRIVERS\st3bus28.sys [?]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.daemon-search.com/startpage

FF - ProfilePath - c:\documents and settings\Ariane Taisa\Dados de aplicativos\Mozilla\Firefox\Profiles\sunrovxv.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage

FF - component: c:\arquivos de programas\Mozilla Firefox\components\xpinstal.dll

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-24 15:12

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(3460)

c:\windows\system32\msi.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Tempo para conclusão: 2009-10-24 15:12

ComboFix-quarantined-files.txt 2009-10-24 17:12

 

Pré-execução: 5.563.809.792 bytes disponíveis

Pós execução: 6.039.060.480 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - D283AC2C30A6F36991E1BEFE30B4FAE9

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá, Acesse http://virusscan.jotti.org/

 

No site, na caixa Procurar, cole esta linha abaixo:

 

c:\arquivos de programas\Outlook Express\data\bin\Explorer.exe

 

Clique em Submit, aguarde o resultado da análise aparecer e salve.

 

Faça o mesmo com esse:

 

c:\Documents and Settings\Ariane Taisa\Meus documentos\Aslj_Client\aslj.bin

 

Poste o resultado das análises.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desative seu antivirus, antispywares e firewall, para não causar conflitos. Mantenha-os desativados até terminar as instruções.

 

Selecione e copie o texto dentro do QUOTE. Abra o Bloco de notas e cole o que copiou. Salve então, na área de trabalho, com o nome de CFScript.txt.

 

File::

c:\arquivos de programas\Outlook Express\data\bin\Explorer.exe

c:\Documents and Settings\Ariane Taisa\Meus documentos\Aslj_Client\aslj.bin

 

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Sys"=-

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Documents and Settings\\Ariane Taisa\\Meus documentos\\Aslj_Client\\aslj.bin"=-

Arraste agora o CFScript.txt para o ComboFix conforme a demonstração abaixo.

 

CFScript.gif

 

O ComboFix irá rodar e reiniciará o PC automaticamente para completar o processo de remoção. Caso isso não aconteça, então reinicie manualmente.

 

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando.

 

Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes.

 

Aos visitantes: Se estiverem com um problema semelhante, não utilizem esse script, pois o uso sem supervisão pode causar danos ao sistema.

 

Quando acabar, será gerado um log, que estará em C:\ComboFix.txt.

 

OBS: Não rode o ComboFix mais do que uma vez. Isso irá sobreescrever o log e dificultará a remoção do(s) malware(s)

 

Poste um novo log do HijackThis e o novo log do ComboFix.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-10-23.01 - Ariane Taisa 27/10/2009 15:36.2.1 - FAT32x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1503.1060 [GMT -2:00]

Executando de: c:\documents and settings\Ariane Taisa\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Ariane Taisa\Desktop\CFScript.txt

AV: avast! antivirus 4.8.1296 [VPS 091023-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

 

FILE ::

"c:\arquivos de programas\Outlook Express\data\bin\Explorer.exe"

"c:\documents and settings\Ariane Taisa\Meus documentos\Aslj_Client\aslj.bin"

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\arquivos de programas\Outlook Express\data\bin\Explorer.exe

c:\documents and settings\Ariane Taisa\Meus documentos\Aslj_Client\aslj.bin

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-09-27 to 2009-10-27 ))))))))))))))))))))))))))))

.

 

2009-10-25 18:12 . 2009-10-25 18:12 -------- d-----w- c:\windows\system32\KB905474

2009-10-25 18:12 . 2009-03-11 00:26 1434496 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe

2009-10-25 18:12 . 2009-03-11 00:18 454536 ----a-w- c:\windows\system32\KB905474\wgasetup.exe

2009-10-25 18:05 . 2009-10-25 18:05 -------- d-----w- c:\windows\ServicePackFiles

2009-10-25 17:52 . 2009-10-25 17:52 -------- d-----w- C:\FOUND.003

2009-10-24 21:03 . 2009-10-24 21:03 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\NCH Swift Sound

2009-10-24 21:02 . 2009-10-24 21:02 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\NCH Software

2009-10-24 21:02 . 2009-10-24 21:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\NCH Swift Sound

2009-10-24 21:02 . 2009-10-24 21:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\NCH Software

2009-10-24 21:01 . 2009-10-24 21:01 -------- d-----w- c:\arquivos de programas\NCH Software

2009-10-24 16:59 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-24 16:59 . 2009-10-24 16:59 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-10-24 16:59 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-24 13:41 . 2009-10-24 13:41 -------- d-----w- c:\windows\system32\CatRoot_bak

2009-10-24 13:36 . 2008-06-14 17:59 272384 ------w- c:\windows\system32\drivers\bthport.sys

2009-10-24 13:36 . 2008-06-14 17:59 272384 ------w- c:\windows\system32\dllcache\bthport.sys

2009-10-24 13:33 . 2008-10-24 11:10 453632 ------w- c:\windows\system32\dllcache\mrxsmb.sys

2009-10-24 01:42 . 2009-10-24 01:42 -------- d--h--w- c:\windows\$hf_mig$

2009-10-24 01:34 . 2009-10-24 01:34 -------- d-----w- C:\FOUND.002

2009-10-23 19:59 . 2009-08-04 17:05 2061952 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-10-23 19:59 . 2009-08-04 17:05 2019840 ------w- c:\windows\system32\dllcache\ntkrpamp.exe

2009-10-23 19:59 . 2009-08-04 17:05 2184576 ------w- c:\windows\system32\dllcache\ntoskrnl.exe

2009-10-23 19:58 . 2009-08-04 17:05 2140160 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-10-23 19:38 . 2002-07-03 13:44 53248 ----a-w- c:\windows\amcap.exe

2009-10-23 19:38 . 2004-08-30 18:37 286720 ----a-w- c:\windows\vsnpstd2.exe

2009-10-23 19:38 . 2004-06-08 20:25 53248 ----a-w- c:\windows\system32\dsnpstd2.dll

2009-10-23 19:37 . 2004-12-16 20:14 347264 ----a-w- c:\windows\system32\drivers\snpstd2.sys

2009-10-23 19:37 . 2004-09-24 18:24 57344 ----a-w- c:\windows\system32\rsnpstd2.dll

2009-10-23 19:37 . 2004-09-24 15:52 36864 ----a-w- c:\windows\system32\vsnpstd2.dll

2009-10-23 19:37 . 2004-02-16 15:59 61440 ----a-w- c:\windows\system32\csnpstd2.dll

2009-10-23 19:37 . 2009-10-23 19:37 -------- d-----w- c:\arquivos de programas\Arquivos comuns\snpstd2

2009-10-23 19:37 . 2004-06-09 18:00 20480 ----a-w- c:\windows\usnpstd2.exe

2009-10-23 19:27 . 2009-10-23 19:27 -------- d-----w- C:\FOUND.001

2009-10-23 19:12 . 2009-10-23 19:12 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-10-23 19:12 . 2009-10-23 19:12 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\skypePM

2009-10-23 19:11 . 2009-10-23 19:12 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype

2009-10-23 19:11 . 2009-10-23 19:11 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Skype

2009-10-22 20:50 . 2009-10-22 20:50 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\DAEMON Tools

2009-10-22 20:49 . 2009-10-22 20:49 -------- d-----w- c:\arquivos de programas\DAEMON Tools Lite

2009-10-22 16:10 . 2009-10-22 16:10 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Malwarebytes

2009-10-22 16:10 . 2009-10-22 16:10 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-10-21 22:02 . 2008-11-26 17:16 50864 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2009-10-21 22:02 . 2008-11-26 17:16 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2009-10-21 22:02 . 2008-11-26 17:15 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2009-10-21 22:01 . 2008-11-26 17:15 97480 ----a-w- c:\windows\system32\AvastSS.scr

2009-10-21 22:01 . 2008-11-26 17:17 111184 ----a-w- c:\windows\system32\drivers\aswSP.sys

2009-10-21 22:01 . 2008-11-26 17:17 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2009-10-21 22:01 . 2008-11-26 17:18 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys

2009-10-21 22:01 . 2008-11-26 17:18 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2009-10-21 22:01 . 2008-11-26 17:21 1236208 ----a-w- c:\windows\system32\aswBoot.exe

2009-10-21 22:01 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll

2009-10-21 22:01 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll

2009-10-21 22:01 . 2009-10-21 22:01 -------- d-----w- c:\arquivos de programas\Alwil Software

2009-10-20 11:25 . 2009-10-20 11:25 -------- d-----w- c:\arquivos de programas\EA GAMES

2009-10-20 11:25 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll

2009-10-20 11:18 . 2009-10-22 20:47 716272 ----a-w- c:\windows\system32\drivers\sptd.sys

2009-10-17 22:21 . 2009-10-17 22:21 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Media Player Classic

2009-10-17 18:33 . 2009-10-17 18:33 -------- d-----w- c:\windows\PAC207

2009-10-17 18:20 . 2009-10-17 18:20 -------- d-----w- c:\windows\Downloaded Installations

2009-10-16 16:05 . 2009-10-16 16:05 -------- d-----w- c:\arquivos de programas\Windows Media Connect 2

2009-10-16 16:03 . 2009-10-16 16:03 -------- d-----w- c:\windows\system32\drivers\UMDF

2009-10-16 16:03 . 2009-10-16 16:03 -------- d-----w- c:\windows\system32\LogFiles

2009-10-16 16:03 . 2007-07-27 12:41 26488 ----a-w- c:\windows\system32\spupdsvc.exe

2009-10-16 09:17 . 2009-10-16 09:17 -------- d-----w- C:\FOUND.000

2009-10-15 11:15 . 2004-08-04 01:08 26496 ----a-w- c:\windows\system32\dllcache\usbstor.sys

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\Realtek Sound Manager

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\AvRack

2009-10-14 11:14 . 2009-10-14 11:14 -------- d-----w- c:\arquivos de programas\Realtek AC97

2009-10-14 11:14 . 2005-08-19 08:31 3644800 ----a-r- c:\windows\system32\drivers\ALCXWDM.SYS

2009-10-14 11:14 . 2005-08-17 09:39 90112 ----a-r- c:\windows\SOUNDMAN.EXE

2009-10-14 11:14 . 2005-07-15 07:48 40960 ------r- c:\windows\system32\ChCfg.exe

2009-10-14 11:14 . 2004-09-07 05:23 156672 ----a-r- c:\windows\system32\RtlCPAPI.dll

2009-10-14 11:14 . 2005-08-17 09:21 10458112 ----a-r- c:\windows\system32\RTLCPL.EXE

2009-10-14 11:14 . 2005-08-12 09:40 307200 ------r- c:\windows\alcupd.exe

2009-10-14 11:14 . 2005-08-12 08:35 212992 ------r- c:\windows\alcrmv.exe

2009-10-14 11:14 . 2009-10-14 11:14 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2009-10-14 11:13 . 2009-10-14 11:13 -------- d-----w- c:\arquivos de programas\Arquivos comuns\InstallShield

2009-10-13 18:11 . 2009-10-13 18:11 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Skype

2009-10-10 20:59 . 2009-10-10 20:59 -------- d-----w- c:\documents and settings\Ariane Taisa\Configuraes locais

2009-10-10 20:54 . 2009-10-10 20:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2009-10-10 20:00 . 2009-10-10 20:00 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2009-10-10 19:19 . 2009-10-10 19:19 -------- d-----w- c:\documents and settings\Ariane Taisa\Tracing

2009-10-10 19:18 . 2009-10-10 19:18 -------- d-----w- c:\arquivos de programas\Microsoft

2009-10-10 19:18 . 2009-10-10 19:18 -------- d-----w- c:\arquivos de programas\Windows Live SkyDrive

2009-10-10 19:12 . 2009-10-10 19:12 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live

2009-10-10 19:08 . 2009-10-10 19:08 -------- d-----w- c:\documents and settings\Ariane Taisa\Dados de aplicativos\Talkback

2009-10-10 19:08 . 2009-10-10 19:08 0 ----a-w- c:\windows\nsreg.dat

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-10-24 13:13 . 2001-10-28 16:07 48628 ----a-w- c:\windows\system32\perfc016.dat

2009-10-24 13:13 . 2001-10-28 16:07 344380 ----a-w- c:\windows\system32\perfh016.dat

2009-10-22 20:34 . 2009-10-10 18:04 98304 ----a-w- c:\windows\DUMP561e.tmp

2009-10-17 22:17 . 2009-10-17 22:17 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack

2009-10-10 18:59 . 2009-10-10 18:59 -------- d-----w- c:\arquivos de programas\Windows Live

2009-10-10 18:44 . 2009-10-10 18:44 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe

2009-10-10 18:29 . 2009-10-10 18:29 -------- d-----w- c:\arquivos de programas\microsoft frontpage

2009-10-10 18:26 . 2009-10-10 18:26 -------- d-----w- c:\arquivos de programas\Serviços on-line

2009-10-10 18:25 . 2009-10-10 18:25 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Serviços

2009-10-10 18:24 . 2009-10-10 18:24 21844 ----a-w- c:\windows\system32\emptyregdb.dat

2009-09-25 05:56 . 2004-08-04 04:45 664064 ----a-w- c:\windows\system32\wininet.dll

2009-09-25 05:56 . 2004-08-04 04:45 81920 ----a-w- c:\windows\system32\ieencode.dll

2009-09-11 14:35 . 2004-08-04 04:45 133632 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-04 20:46 . 2004-08-04 04:45 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-08-26 08:15 . 2004-08-04 04:45 247326 ----a-w- c:\windows\system32\strmdll.dll

2009-08-05 09:06 . 2004-08-04 04:45 205312 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-04 17:05 . 2004-08-04 02:40 2061952 ------w- c:\windows\system32\ntkrnlpa.exe

2009-08-04 17:05 . 2004-08-04 04:40 2184576 ------w- c:\windows\system32\ntoskrnl.exe

2009-10-12 14:50 . 2009-10-10 19:07 67688 ----a-w- c:\arquivos de programas\mozilla firefox\components\jar50.dll

2009-10-12 14:50 . 2009-10-10 19:07 54368 ----a-w- c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2009-10-12 14:50 . 2009-10-10 19:07 34944 ----a-w- c:\arquivos de programas\mozilla firefox\components\myspell.dll

2009-10-12 14:50 . 2009-10-10 19:07 46712 ----a-w- c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2009-10-12 14:50 . 2009-10-10 19:07 172136 ----a-w- c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

.

 

((((((((((((((((((((((((((((( SnapShot@2009-10-24_17.12.03 )))))))))))))))))))))))))))))))))))))))))

.

+ 2004-08-04 04:45 . 2009-06-25 08:46 59392 c:\windows\system32\wdigest.dll

+ 2009-10-24 13:15 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe

+ 2004-08-04 04:45 . 2009-06-15 11:33 81408 c:\windows\system32\tlntsess.exe

+ 2004-08-04 04:45 . 2009-06-15 11:33 77824 c:\windows\system32\telnet.exe

- 2009-10-16 16:05 . 2008-07-09 07:34 18296 c:\windows\system32\spmsg.dll

+ 2009-10-16 16:05 . 2007-11-30 11:18 18296 c:\windows\system32\spmsg.dll

+ 2004-08-04 04:45 . 2009-06-25 08:46 56320 c:\windows\system32\secur32.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 39424 c:\windows\system32\pngfilt.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 39424 c:\windows\system32\pngfilt.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 91648 c:\windows\system32\mtxoci.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 66560 c:\windows\system32\mtxclu.dll

+ 2004-08-04 04:45 . 2008-06-12 14:18 66560 c:\windows\system32\mtxclu.dll

- 2009-10-10 18:22 . 2004-08-04 01:45 58880 c:\windows\system32\msdtclog.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 58880 c:\windows\system32\msdtclog.dll

+ 2004-08-04 04:45 . 2008-06-24 16:24 74240 c:\windows\system32\mscms.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 48640 c:\windows\system32\mqupgrd.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 48640 c:\windows\system32\mqupgrd.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 95744 c:\windows\system32\mqsec.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 95744 c:\windows\system32\mqsec.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 16896 c:\windows\system32\mqise.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 16896 c:\windows\system32\mqise.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 47104 c:\windows\system32\mqdscli.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 47104 c:\windows\system32\mqdscli.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 19968 c:\windows\system32\mqbkup.exe

+ 2004-08-04 04:45 . 2009-06-22 11:49 19968 c:\windows\system32\mqbkup.exe

+ 2004-08-04 04:45 . 2009-09-25 05:56 16384 c:\windows\system32\jsproxy.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 96768 c:\windows\system32\inseng.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 96768 c:\windows\system32\inseng.dll

+ 2001-10-28 16:06 . 2009-07-29 04:53 82432 c:\windows\system32\fontsub.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 55808 c:\windows\system32\extmgr.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 55808 c:\windows\system32\extmgr.dll

+ 2004-08-04 02:58 . 2009-06-22 11:48 91776 c:\windows\system32\drivers\mqac.sys

+ 2004-08-04 02:59 . 2009-06-22 11:34 92544 c:\windows\system32\drivers\ksecdd.sys

+ 2004-08-04 01:45 . 2009-06-25 08:46 59392 c:\windows\system32\dllcache\wdigest.dll

+ 2004-08-04 04:45 . 2009-06-15 11:33 81408 c:\windows\system32\dllcache\tlntsess.exe

+ 2004-08-04 04:45 . 2009-06-15 11:33 77824 c:\windows\system32\dllcache\telnet.exe

+ 2004-08-04 01:45 . 2009-06-25 08:46 56320 c:\windows\system32\dllcache\secur32.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 39424 c:\windows\system32\dllcache\pngfilt.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 39424 c:\windows\system32\dllcache\pngfilt.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 91648 c:\windows\system32\dllcache\mtxoci.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 66560 c:\windows\system32\dllcache\mtxclu.dll

+ 2004-08-04 04:45 . 2008-06-12 14:18 66560 c:\windows\system32\dllcache\mtxclu.dll

- 2009-10-10 18:22 . 2004-08-04 01:45 58880 c:\windows\system32\dllcache\msdtclog.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 58880 c:\windows\system32\dllcache\msdtclog.dll

+ 2004-08-04 01:45 . 2008-06-24 16:24 74240 c:\windows\system32\dllcache\mscms.dll

+ 2004-08-04 01:45 . 2009-09-04 20:46 58880 c:\windows\system32\dllcache\msasn1.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 48640 c:\windows\system32\dllcache\mqupgrd.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 48640 c:\windows\system32\dllcache\mqupgrd.dll

+ 2004-08-04 01:45 . 2009-06-25 18:36 95744 c:\windows\system32\dllcache\mqsec.dll

- 2004-08-04 01:45 . 2004-08-04 01:45 95744 c:\windows\system32\dllcache\mqsec.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 16896 c:\windows\system32\dllcache\mqise.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 16896 c:\windows\system32\dllcache\mqise.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 47104 c:\windows\system32\dllcache\mqdscli.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 47104 c:\windows\system32\dllcache\mqdscli.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 19968 c:\windows\system32\dllcache\mqbkup.exe

+ 2004-08-04 04:45 . 2009-06-22 11:49 19968 c:\windows\system32\dllcache\mqbkup.exe

+ 2004-08-04 02:58 . 2009-06-22 11:48 91776 c:\windows\system32\dllcache\mqac.sys

+ 2004-08-04 02:59 . 2009-06-22 11:34 92544 c:\windows\system32\dllcache\ksecdd.sys

+ 2004-08-04 04:45 . 2009-09-25 05:56 16384 c:\windows\system32\dllcache\jsproxy.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 96768 c:\windows\system32\dllcache\inseng.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 96768 c:\windows\system32\dllcache\inseng.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 81920 c:\windows\system32\dllcache\ieencode.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 81920 c:\windows\system32\dllcache\ieencode.dll

+ 2009-10-10 18:24 . 2009-09-18 09:56 18432 c:\windows\system32\dllcache\iedw.exe

- 2009-10-10 18:24 . 2004-08-04 01:45 18432 c:\windows\system32\dllcache\iedw.exe

+ 2001-10-28 16:06 . 2009-07-29 04:53 82432 c:\windows\system32\dllcache\fontsub.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 55808 c:\windows\system32\dllcache\extmgr.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 55808 c:\windows\system32\dllcache\extmgr.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 85504 c:\windows\system32\dllcache\avifil32.dll

+ 2004-08-04 04:45 . 2009-06-10 14:24 85504 c:\windows\system32\dllcache\avifil32.dll

- 2004-08-04 01:45 . 2004-08-04 01:45 58880 c:\windows\system32\dllcache\atl.dll

+ 2004-08-04 01:45 . 2009-07-17 18:57 58880 c:\windows\system32\dllcache\atl.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 85504 c:\windows\system32\avifil32.dll

+ 2004-08-04 04:45 . 2009-06-10 14:24 85504 c:\windows\system32\avifil32.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 58880 c:\windows\system32\atl.dll

+ 2004-08-04 04:45 . 2009-07-17 18:57 58880 c:\windows\system32\atl.dll

+ 2004-08-04 04:45 . 2009-06-22 11:49 4608 c:\windows\system32\mqsvc.exe

- 2004-08-04 04:45 . 2004-08-04 04:45 4608 c:\windows\system32\mqsvc.exe

- 2004-08-04 04:45 . 2004-08-04 04:45 4608 c:\windows\system32\dllcache\mqsvc.exe

+ 2004-08-04 04:45 . 2009-06-22 11:49 4608 c:\windows\system32\dllcache\mqsvc.exe

+ 2008-02-17 06:33 . 2009-09-18 10:04 361984 c:\windows\system32\xpsp3res.dll

+ 2004-08-04 04:45 . 2009-04-02 01:02 604160 c:\windows\system32\wmspdmod.dll

+ 2006-10-18 23:47 . 2008-06-24 20:12 295936 c:\windows\system32\wmpeffects.dll

- 2006-10-18 23:47 . 2006-10-18 23:47 295936 c:\windows\system32\wmpeffects.dll

+ 2004-08-04 04:45 . 2009-07-14 01:43 286208 c:\windows\system32\wmpdxm.dll

+ 2004-08-04 04:45 . 2008-06-18 07:03 938496 c:\windows\system32\WMNetmgr.dll

+ 2004-08-04 04:45 . 2007-10-25 11:28 222720 c:\windows\system32\wmasf.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 132096 c:\windows\system32\wkssvc.dll

+ 2004-08-04 04:45 . 2009-06-10 06:31 132096 c:\windows\system32\wkssvc.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 351232 c:\windows\system32\winhttp.dll

+ 2004-08-04 04:45 . 2008-12-16 12:50 351232 c:\windows\system32\winhttp.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 417792 c:\windows\system32\vbscript.dll

+ 2004-08-04 04:45 . 2007-12-18 14:42 417792 c:\windows\system32\vbscript.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 625664 c:\windows\system32\urlmon.dll

+ 2004-08-04 04:45 . 2009-07-29 04:53 119808 c:\windows\system32\t2embed.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 473600 c:\windows\system32\shlwapi.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 473600 c:\windows\system32\shlwapi.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 169472 c:\windows\system32\Setup\msmqocm.dll

+ 2004-08-04 04:45 . 2009-06-25 08:46 168448 c:\windows\system32\schannel.dll

+ 2004-08-04 04:45 . 2009-04-15 15:17 584192 c:\windows\system32\rpcrt4.dll

+ 2004-08-04 04:45 . 2008-10-15 16:59 332800 c:\windows\system32\netapi32.dll

+ 2004-08-04 04:45 . 2008-06-20 17:41 247808 c:\windows\system32\mswsock.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 247808 c:\windows\system32\mswsock.dll

+ 2009-10-10 18:22 . 2009-06-05 07:48 655872 c:\windows\system32\mstscax.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 532480 c:\windows\system32\mstime.dll

+ 2004-08-04 04:45 . 2006-12-04 18:21 414720 c:\windows\system32\msscp.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 146432 c:\windows\system32\msrating.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 146432 c:\windows\system32\msrating.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 449024 c:\windows\system32\mshtmled.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 161792 c:\windows\system32\msdtcuiu.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 956928 c:\windows\system32\msdtctm.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 428032 c:\windows\system32\msdtcprx.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 523776 c:\windows\system32\mqutil.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 523776 c:\windows\system32\mqutil.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 186880 c:\windows\system32\mqtrig.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 186880 c:\windows\system32\mqtrig.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 117248 c:\windows\system32\mqtgsvc.exe

+ 2004-08-04 04:45 . 2009-06-22 11:49 117248 c:\windows\system32\mqtgsvc.exe

+ 2004-08-04 04:45 . 2009-06-25 18:36 517120 c:\windows\system32\mqsnap.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 123392 c:\windows\system32\mqrtdep.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 123392 c:\windows\system32\mqrtdep.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 177152 c:\windows\system32\mqrt.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 177152 c:\windows\system32\mqrt.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 661504 c:\windows\system32\mqqm.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 225280 c:\windows\system32\mqoa.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 225280 c:\windows\system32\mqoa.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 138240 c:\windows\system32\mqad.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 138240 c:\windows\system32\mqad.dll

+ 2004-08-04 04:45 . 2009-06-25 08:46 727040 c:\windows\system32\lsasrv.dll

- 2004-08-04 04:45 . 2006-10-18 22:03 100864 c:\windows\system32\logagent.exe

+ 2004-08-04 04:45 . 2008-06-18 03:09 100864 c:\windows\system32\logagent.exe

+ 2004-08-04 04:45 . 2009-05-07 15:43 345600 c:\windows\system32\localspl.dll

+ 2004-08-04 04:45 . 2009-06-25 08:46 298496 c:\windows\system32\kerberos.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 450560 c:\windows\system32\jscript.dll

+ 2004-08-04 04:45 . 2009-08-21 06:51 450560 c:\windows\system32\jscript.dll

+ 2009-10-10 18:24 . 2008-04-11 18:51 683520 c:\windows\system32\inetcomm.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 251392 c:\windows\system32\iepeers.dll

+ 2004-08-04 04:45 . 2008-10-23 13:00 283648 c:\windows\system32\gdi32.dll

+ 2009-10-10 18:12 . 2009-10-25 23:25 103032 c:\windows\system32\FNTCACHE.DAT

- 2009-10-10 18:12 . 2009-10-18 06:23 103032 c:\windows\system32\FNTCACHE.DAT

+ 2004-08-04 04:45 . 2008-07-07 20:31 253952 c:\windows\system32\es.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 205312 c:\windows\system32\dxtrans.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 357888 c:\windows\system32\dxtmsft.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 357888 c:\windows\system32\dxtmsft.dll

+ 2004-08-04 03:07 . 2008-06-20 09:52 225920 c:\windows\system32\drivers\tcpip6.sys

+ 2004-08-04 03:14 . 2008-06-20 10:45 360320 c:\windows\system32\drivers\tcpip.sys

+ 2004-08-04 03:14 . 2008-12-11 11:57 333184 c:\windows\system32\drivers\srv.sys

+ 2001-10-28 16:07 . 2008-05-08 12:28 202752 c:\windows\system32\drivers\RMCast.sys

+ 2004-08-04 03:15 . 2008-10-24 11:10 453632 c:\windows\system32\drivers\mrxsmb.sys

+ 2004-08-04 03:14 . 2008-08-14 09:51 138368 c:\windows\system32\drivers\afd.sys

+ 2004-08-04 04:45 . 2008-06-20 17:41 148992 c:\windows\system32\dnsapi.dll

+ 2009-10-10 18:22 . 2008-04-21 21:27 216064 c:\windows\system32\dllcache\wordpad.exe

+ 2004-08-04 04:45 . 2009-04-02 01:02 604160 c:\windows\system32\dllcache\wmspdmod.dll

+ 2004-08-04 04:45 . 2009-07-14 01:43 286208 c:\windows\system32\dllcache\wmpdxm.dll

+ 2004-08-04 04:45 . 2008-06-18 07:03 938496 c:\windows\system32\dllcache\WMNetmgr.dll

+ 2004-08-04 04:45 . 2007-10-25 11:28 222720 c:\windows\system32\dllcache\wmasf.dll

+ 2004-08-04 04:45 . 2009-06-10 06:31 132096 c:\windows\system32\dllcache\wkssvc.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 132096 c:\windows\system32\dllcache\wkssvc.dll

+ 2004-08-04 01:45 . 2009-09-25 05:56 664064 c:\windows\system32\dllcache\wininet.dll

+ 2004-08-04 01:45 . 2008-12-16 12:50 351232 c:\windows\system32\dllcache\winhttp.dll

- 2004-08-04 01:45 . 2004-08-04 01:45 351232 c:\windows\system32\dllcache\winhttp.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 417792 c:\windows\system32\dllcache\vbscript.dll

+ 2004-08-04 04:45 . 2007-12-18 14:42 417792 c:\windows\system32\dllcache\vbscript.dll

+ 2004-08-04 01:45 . 2009-09-25 05:56 625664 c:\windows\system32\dllcache\urlmon.dll

+ 2004-08-04 04:45 . 2007-06-27 18:02 318464 c:\windows\system32\dllcache\unregmp2.exe

+ 2009-10-10 18:24 . 2009-06-21 22:06 153088 c:\windows\system32\dllcache\triedit.dll

- 2009-10-10 18:24 . 2004-08-04 01:45 153088 c:\windows\system32\dllcache\triedit.dll

+ 2004-08-04 03:07 . 2008-06-20 09:52 225920 c:\windows\system32\dllcache\tcpip6.sys

+ 2004-08-04 03:14 . 2008-06-20 10:45 360320 c:\windows\system32\dllcache\tcpip.sys

+ 2004-08-04 04:45 . 2009-07-29 04:53 119808 c:\windows\system32\dllcache\t2embed.dll

+ 2004-08-04 04:45 . 2009-08-26 08:15 247326 c:\windows\system32\dllcache\strmdll.dll

+ 2004-08-04 03:14 . 2008-12-11 11:57 333184 c:\windows\system32\dllcache\srv.sys

- 2004-08-04 01:45 . 2004-08-04 01:45 473600 c:\windows\system32\dllcache\shlwapi.dll

+ 2004-08-04 01:45 . 2009-09-25 05:56 473600 c:\windows\system32\dllcache\shlwapi.dll

+ 2004-08-04 01:45 . 2009-06-25 08:46 168448 c:\windows\system32\dllcache\schannel.dll

+ 2004-08-04 01:45 . 2009-04-15 15:17 584192 c:\windows\system32\dllcache\rpcrt4.dll

+ 2001-10-28 16:07 . 2008-05-08 12:28 202752 c:\windows\system32\dllcache\rmcast.sys

+ 2004-08-04 01:45 . 2008-10-15 16:59 332800 c:\windows\system32\dllcache\netapi32.dll

+ 2004-08-04 01:45 . 2008-06-20 17:41 247808 c:\windows\system32\dllcache\mswsock.dll

- 2004-08-04 01:45 . 2004-08-04 01:45 247808 c:\windows\system32\dllcache\mswsock.dll

+ 2004-08-04 04:45 . 2009-08-05 09:06 205312 c:\windows\system32\dllcache\mswebdvd.dll

+ 2004-08-04 01:45 . 2009-09-11 14:35 133632 c:\windows\system32\dllcache\msv1_0.dll

+ 2009-10-10 18:22 . 2009-06-05 07:48 655872 c:\windows\system32\dllcache\mstscax.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 532480 c:\windows\system32\dllcache\mstime.dll

+ 2004-08-04 04:45 . 2006-12-04 18:21 414720 c:\windows\system32\dllcache\msscp.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 146432 c:\windows\system32\dllcache\msrating.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 146432 c:\windows\system32\dllcache\msrating.dll

+ 2004-08-04 01:45 . 2009-06-25 18:36 169472 c:\windows\system32\dllcache\msmqocm.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 449024 c:\windows\system32\dllcache\mshtmled.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 161792 c:\windows\system32\dllcache\msdtcuiu.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 956928 c:\windows\system32\dllcache\msdtctm.dll

+ 2009-10-10 18:22 . 2008-06-12 14:18 428032 c:\windows\system32\dllcache\msdtcprx.dll

+ 2009-10-10 18:24 . 2008-05-01 14:32 331776 c:\windows\system32\dllcache\msadce.dll

- 2009-10-10 18:24 . 2004-08-04 01:45 331776 c:\windows\system32\dllcache\msadce.dll

+ 2004-08-04 01:45 . 2009-06-25 18:36 523776 c:\windows\system32\dllcache\mqutil.dll

- 2004-08-04 01:45 . 2004-08-04 01:45 523776 c:\windows\system32\dllcache\mqutil.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 186880 c:\windows\system32\dllcache\mqtrig.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 186880 c:\windows\system32\dllcache\mqtrig.dll

+ 2004-08-04 04:45 . 2009-06-22 11:49 117248 c:\windows\system32\dllcache\mqtgsvc.exe

- 2004-08-04 04:45 . 2004-08-04 04:45 117248 c:\windows\system32\dllcache\mqtgsvc.exe

+ 2004-08-04 04:45 . 2009-06-25 18:36 517120 c:\windows\system32\dllcache\mqsnap.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 123392 c:\windows\system32\dllcache\mqrtdep.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 123392 c:\windows\system32\dllcache\mqrtdep.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 177152 c:\windows\system32\dllcache\mqrt.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 177152 c:\windows\system32\dllcache\mqrt.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 661504 c:\windows\system32\dllcache\mqqm.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 225280 c:\windows\system32\dllcache\mqoa.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 225280 c:\windows\system32\dllcache\mqoa.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 138240 c:\windows\system32\dllcache\mqad.dll

+ 2004-08-04 04:45 . 2009-06-25 18:36 138240 c:\windows\system32\dllcache\mqad.dll

+ 2004-08-04 01:45 . 2009-06-25 08:46 727040 c:\windows\system32\dllcache\lsasrv.dll

+ 2004-08-04 04:45 . 2008-06-18 03:09 100864 c:\windows\system32\dllcache\logagent.exe

- 2004-08-04 04:45 . 2006-10-18 22:03 100864 c:\windows\system32\dllcache\logagent.exe

+ 2004-08-04 04:45 . 2009-05-07 15:43 345600 c:\windows\system32\dllcache\localspl.dll

+ 2004-08-04 01:45 . 2009-06-25 08:46 298496 c:\windows\system32\dllcache\kerberos.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 450560 c:\windows\system32\dllcache\jscript.dll

+ 2004-08-04 04:45 . 2009-08-21 06:51 450560 c:\windows\system32\dllcache\jscript.dll

+ 2009-10-10 18:24 . 2008-04-11 18:51 683520 c:\windows\system32\dllcache\inetcomm.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 251392 c:\windows\system32\dllcache\iepeers.dll

+ 2004-08-04 01:45 . 2008-10-23 13:00 283648 c:\windows\system32\dllcache\gdi32.dll

+ 2004-08-04 04:45 . 2008-07-07 20:31 253952 c:\windows\system32\dllcache\es.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 205312 c:\windows\system32\dllcache\dxtrans.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 357888 c:\windows\system32\dllcache\dxtmsft.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 357888 c:\windows\system32\dllcache\dxtmsft.dll

+ 2004-08-04 01:45 . 2008-06-20 17:41 148992 c:\windows\system32\dllcache\dnsapi.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 151552 c:\windows\system32\dllcache\cdfview.dll

+ 2004-08-04 03:14 . 2008-08-14 09:51 138368 c:\windows\system32\dllcache\afd.sys

- 2004-08-04 04:45 . 2004-08-04 04:45 100352 c:\windows\system32\dllcache\6to4svc.dll

+ 2004-08-04 04:45 . 2006-08-16 11:59 100352 c:\windows\system32\dllcache\6to4svc.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 151552 c:\windows\system32\cdfview.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 100352 c:\windows\system32\6to4svc.dll

+ 2004-08-04 04:45 . 2006-08-16 11:59 100352 c:\windows\system32\6to4svc.dll

- 2009-10-23 19:12 . 2009-10-23 19:12 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe

+ 2009-10-24 22:11 . 2009-10-24 22:12 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe

+ 2004-08-04 04:45 . 2007-06-27 18:02 318464 c:\windows\inf\unregmp2.exe

+ 2009-10-24 13:33 . 2008-10-24 11:10 453632 c:\windows\Driver Cache\i386\mrxsmb.sys

+ 2009-10-24 13:36 . 2008-06-14 17:59 272384 c:\windows\Driver Cache\i386\bthport.sys

+ 2009-10-24 13:36 . 2009-08-13 13:56 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll

+ 2004-08-04 04:45 . 2009-05-20 06:56 2458112 c:\windows\system32\WMVCore.dll

+ 2004-08-04 04:38 . 2009-04-19 20:10 1846784 c:\windows\system32\win32k.sys

+ 2004-08-04 04:45 . 2008-07-03 13:15 8484352 c:\windows\system32\shell32.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 1506304 c:\windows\system32\shdocvw.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 1439744 c:\windows\system32\query.dll

+ 2004-08-04 04:45 . 2009-07-17 16:27 1439744 c:\windows\system32\query.dll

+ 2004-08-04 04:45 . 2009-06-03 19:26 1295360 c:\windows\system32\quartz.dll

+ 2004-08-04 04:45 . 2008-09-04 16:45 1106944 c:\windows\system32\msxml3.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 3084288 c:\windows\system32\mshtml.dll

+ 2004-08-04 04:45 . 2009-03-21 14:20 1025024 c:\windows\system32\kernel32.dll

+ 2004-08-04 04:45 . 2009-05-20 06:56 2458112 c:\windows\system32\dllcache\WMVCore.dll

+ 2004-08-04 01:38 . 2009-04-19 20:10 1846784 c:\windows\system32\dllcache\win32k.sys

+ 2004-08-04 01:45 . 2008-07-03 13:15 8484352 c:\windows\system32\dllcache\shell32.dll

+ 2004-08-04 01:45 . 2009-09-25 05:56 1506304 c:\windows\system32\dllcache\shdocvw.dll

- 2004-08-04 04:45 . 2004-08-04 04:45 1439744 c:\windows\system32\dllcache\query.dll

+ 2004-08-04 04:45 . 2009-07-17 16:27 1439744 c:\windows\system32\dllcache\query.dll

+ 2004-08-04 04:45 . 2009-06-03 19:26 1295360 c:\windows\system32\dllcache\quartz.dll

+ 2004-08-04 04:45 . 2008-09-04 16:45 1106944 c:\windows\system32\dllcache\msxml3.dll

+ 2009-10-10 18:24 . 2009-07-10 13:41 1315328 c:\windows\system32\dllcache\msoe.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 3084288 c:\windows\system32\dllcache\mshtml.dll

+ 2004-08-04 01:45 . 2009-03-21 14:20 1025024 c:\windows\system32\dllcache\kernel32.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 1055744 c:\windows\system32\dllcache\danim.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 1024000 c:\windows\system32\dllcache\browseui.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 1055744 c:\windows\system32\danim.dll

+ 2004-08-04 04:45 . 2009-09-25 05:56 1024000 c:\windows\system32\browseui.dll

+ 2009-10-23 19:59 . 2009-08-04 17:05 2184576 c:\windows\Driver Cache\i386\ntoskrnl.exe

+ 2009-10-23 19:59 . 2009-08-04 17:05 2019840 c:\windows\Driver Cache\i386\ntkrpamp.exe

- 2009-10-23 19:59 . 2009-02-09 11:50 2019840 c:\windows\Driver Cache\i386\ntkrpamp.exe

+ 2009-10-23 19:59 . 2009-08-04 17:05 2061952 c:\windows\Driver Cache\i386\ntkrnlpa.exe

- 2009-10-23 19:59 . 2009-02-09 11:50 2061952 c:\windows\Driver Cache\i386\ntkrnlpa.exe

+ 2009-10-23 19:58 . 2009-08-04 17:05 2140160 c:\windows\Driver Cache\i386\ntkrnlmp.exe

- 2009-10-23 19:58 . 2009-02-09 11:50 2140160 c:\windows\Driver Cache\i386\ntkrnlmp.exe

+ 2004-08-04 04:45 . 2009-07-14 01:43 10841088 c:\windows\system32\wmp.dll

+ 2004-08-04 04:45 . 2009-07-14 01:43 10841088 c:\windows\system32\dllcache\wmp.dll

.

-- Snapshot resetado para data atual --

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883840]

"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-01-17 486856]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"Malwarebytes Anti-Malware (reboot)"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"SNPSTD2"="c:\windows\vsnpstd2.exe" [2004-08-30 286720]

"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-08-17 90112]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

 

c:\documents and settings\Ariane Taisa\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/10/2009 20:01 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/10/2009 20:01 20560]

S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]

S3 st3bus28;st3bus28;c:\windows\system32\DRIVERS\st3bus28.sys --> c:\windows\system32\DRIVERS\st3bus28.sys [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-10-27 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-10-25 00:18]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.daemon-search.com/startpage

FF - ProfilePath - c:\documents and settings\Ariane Taisa\Dados de aplicativos\Mozilla\Firefox\Profiles\sunrovxv.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage

FF - component: c:\arquivos de programas\Mozilla Firefox\components\xpinstal.dll

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-27 15:40

Windows 5.1.2600 Service Pack 2 FAT NTAPI

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2009-10-27 15:42

ComboFix-quarantined-files.txt 2009-10-27 17:42

ComboFix2.txt 2009-10-24 17:12

 

Pré-execução: 5.139.529.728 bytes disponíveis

Pós execução: 5.290.442.752 bytes disponíveis

 

- - End Of File - - 1F48356E513946A169F4F8B6800285A5

 

Logfile of HijackThis v1.99.1

Scan saved at 15:53:25, on 27/10/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\vsnpstd2.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Ariane Taisa\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [sNPSTD2] C:\WINDOWS\vsnpstd2.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, os logs estão limpos. Para finalizar, vá em Iniciar > Executar > digite (ou copie e cole): ComboFix /Uninstall

 

Dê o OK. Aguarde, pois isso irá desinstalar o ComboFix, deletar os arquivos e pastas relacionados e apagará pontos da Restauração do sistema que possam estar infectados, criando um ponto limpo.

 

Atualize o Internet Explorer. Baixe e instale o Internet Explorer 8.

 

Visite o Windows Update e atualize o seu sistema, baixando o Service Pack 3

 

Ou, se preferir, baixe e instale o pacote completo (+- 300 Mb):

http://www.microsoft.com/downloads/details.aspx?FamilyID=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&DisplayLang=pt-br

 

Leia estes artigos sobre segurança:

 

Proteja seu PC

Cuidados ao navegar na net.

 

Abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.