Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

jhocorocio

[Resolvido!] Trojan atapi.sys - Log do hijackthis

Recommended Posts

Galera, o avg tem acusado o tal do trojan horse no atapi.sys... meu pc está um lixo. Segue o log do hijack this. E obrigado pela ajuda!

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:54:35, on 11/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\agrsmsvc.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\System32\svchost.exe

C:\Hijack\HiJackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - (no file)

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKCU\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKCU\..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

O4 - HKCU\..\Run: [skyTel] SkyTel.EXE

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} (CAtmCap Object) - https://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235609580187

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258079346734

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: GbPluginBb - C:\WINDOWS\

O20 - Winlogon Notify: GbPluginCef - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbiehcef.dll

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Mensageiro MessengerRemoteAccess (MessengerRemoteAccess) - Unknown owner - C:\WINDOWS\system32\3DViewerw.exe (file missing)

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

 

--

End of file - 8338 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia jhocorocio

 

 

*Baixe o MalwareBytes Anti-malware e salve-o no desktop:

*Instale o programa

*Ao finalizar, se alguma atualização existir,o download será automático. Aguarde...

*Terminada a atualização, o programa será aberto automaticamente.

*Na aba [Verificação], selecione a opção [Verificação completa]

*Clique em [Verificar] e selecione as unidades a serem examinadas

*Remova o que for encontrado

*Ao término do scan poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] e finalmente clique em [OK]. Um relatório (mbam-log-ano-mês-data.txt) será apresentado.

*Reinicie o PC

*Abra novamente o programa Malwarebytes e na aba [Logs] clique no arquivo mbam-log-ano-mês-data.txt

*Clique em [Abrir], copie, cole-o na sua próxima resposta

Compartilhar este post


Link para o post
Compartilhar em outros sites

Cara, ontem passei a ferramente de remoção de software mal-intencionado da Microsoft, e pelo jeito o esquema se foi... Passei o antimalware e não acusou nada. Pelo gerenciador de tarefas, não aparece nada mto estranho, a não ser um svchost ocupando 21k da memória e o system ocupando 81k... Não sei se é problema isso. Enfim, segue o log do antimalware:

Malwarebytes' Anti-Malware 1.42

Versão do banco de dados: 3349

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

12/12/2009 11:17:58

mbam-log-2009-12-12 (11-17-58).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 215685

Tempo decorrido: 52 minute(s), 45 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 0

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

(Nenhum ítem malicioso foi detectado)

 

Obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde jhocorocio

 

 

*Baixe o DDS e salve-o no desktop

*Desative temporariamente seu antivírus

 

Iniciar > Programas > AVG

Abra a Interface do usuário do AVG

Clique duas vezes na Proteção Residente

Desmarque a opção "Proteção Residente ativa"

Salve as alterações

*Duplo clique em dds e aguarde

*Ao término surgirá um relatório (DDS.txt). Salve-o no desktop.

*Uma nova janela surgirá ("D.D.S - Optional_Scan"), clique em [NÃO]

*Ao término clique [OK]

*Cole o relatório DDS.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde, segue o relatório:

 

DDS (Ver_09-12-01.01) - NTFSx86

Run by user at 14:12:37,67 on s b 12/12/2009

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.454 [GMT -3:00]

 

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

 

============== Running Processes ===============

 

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

C:\WINDOWS\system32\svchost -k rpcss

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\agrsmsvc.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\System32\alg.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Documents and Settings\user\Desktop\dds.scr

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

============== Pseudo HJT Report ===============

 

uStart Page = about:blank

uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\arquivos de

 

programas\avg\avg8\toolbar\IEToolbar.dll

uURLSearchHooks: H - No File

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos

 

comuns\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\arquivos de programas\avg\avg8\avgssie.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre1.6.0_03\bin\ssv.dll

BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos

 

comuns\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\arquivos de

 

programas\avg\avg8\toolbar\IEToolbar.dll

BHO: {C41A1C0E-EA6C-11D4-B1B8-444553540000} - No File

BHO: GbIehObj Class: {c41a1c0e-ea6c-11d4-b1b8-444553540003} - c:\arquivos de programas\gbplugin\gbiehcef.dll

BHO: GbIehObj Class: {c41a1c0e-ea6c-11d4-b1b8-444553540008} - c:\arquiv~1\gbplugin\gbiehuni.dll

BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\arquivos de programas\windows

 

live\toolbar\wltcore.dll

TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\arquivos de programas\windows live\toolbar\wltcore.dll

TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\arquivos de programas\avg\avg8\toolbar\IEToolbar.dll

TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File

uRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [igfxtray] c:\windows\system32\igfxtray.exe

uRun: [Alcmtr] ALCMTR.EXE

uRun: [sunJavaUpdateSched] c:\arquivos de programas\java\jre1.6.0_03\bin\jusched.exe

uRun: [skyTel] SkyTel.EXE

mRun: [AVG8_TRAY] c:\arquiv~1\avg\avg8\avgtray.exe

mRun: [QuickTime Task] "c:\arquivos de programas\quicktime\qttask.exe" -atboottime

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~2\office11\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\arquivos de programas\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\arquivos de

 

programas\java\jre1.6.0_03\bin\ssv.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\arquivos de programas\windows

 

live\writer\WriterBrowserExtension.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -

 

c:\arquiv~1\micros~2\office11\REFIEBAR.DLL

DPF: {33564D57-0000-0010-8000-00AA00389B71} -

 

hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} - hxxps://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab

DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -

 

hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235609580187

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -

 

hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258079346734

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} - hxxps://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\arquivos de programas\avg\avg8\avgpp.dll

Notify: GbPluginCef - c:\arquivos de programas\gbplugin\gbiehcef.dll

Notify: GbPluginUni - c:\arquiv~1\gbplugin\gbiehuni.dll

Notify: avgrsstarter - avgrsstx.dll

Notify: igfxcui - igfxdev.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: GbPlugin ShlObj: {e37cb5f0-51f5-4395-a808-5fa49e399f83} - GbPluginObj Class

SEH: GbPluginObj Class: {e37cb5f0-51f5-4395-a808-5fa49e399008} - c:\arquiv~1\gbplugin\gbiehuni.dll

SEH: GbPluginObj Class: {e37cb5f0-51f5-4395-a808-5fa49e399003} - c:\arquivos de programas\gbplugin\gbiehcef.dll

SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digiwet.dll

 

================= FIREFOX ===================

 

FF - ProfilePath - c:\docume~1\user\dadosd~1\mozilla\firefox\profiles\zqpe721h.default\

FF - prefs.js: browser.startup.homepage - about:blank

FF - prefs.js: keyword.URL - hxxp://br.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_br&p=

FF - component: c:\arquivos de programas\avg\avg8\firefox\components\avgssff.dll

FF - component: c:\documents and settings\user\dados de

 

aplicativos\mozilla\firefox\profiles\zqpe721h.default\extensions\{87f8774f-b485-47e2-a755-a40a8a5e886c}\components\GbMzhBb.dl

 

l

FF - component: c:\documents and settings\user\dados de

 

aplicativos\mozilla\firefox\profiles\zqpe721h.default\extensions\{87f8774f-b485-47e2-a755-a40a8a5e8873}\components\GbMzhUni.d

 

ll

FF - plugin: c:\arquivos de programas\microsoft\office live\npOLW.dll

FF - plugin: c:\arquivos de programas\windows live\photo gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} -

 

c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

 

============= SERVICES / DRIVERS ===============

 

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-11-9 26624]

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\GbpKm.sys [2009-2-28 30504]

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-9 335240]

R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-9 27784]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-9 108552]

R1 SNSID;SNSID;c:\windows\system32\drivers\SNSID.SYS [2008-5-2 22272]

R1 SNSMS;SNSMS;c:\windows\system32\drivers\SNSMS.SYS [2008-5-2 34440]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\avg\avg8\avgwdsvc.exe [2009-11-9 297752]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-18 54752]

R2 GbpSv;Gbp Service;c:\arquiv~1\gbplugin\GbpSv.exe [2009-11-12 53800]

R2 Ps2KSecureKeyboard;SecureKbd;c:\windows\system32\drivers\psseckbd.sys [2008-5-2 15048]

S1 IPNETC;IP Network Control;c:\windows\system32\drivers\ipnetc.sys --> c:\windows\system32\drivers\ipnetc.sys [?]

S2 MessengerRemoteAccess;Mensageiro MessengerRemoteAccess;c:\windows\system32\3dviewerw.exe srv -->

 

c:\windows\system32\3DViewerw.exe srv [?]

S2 swyvsw;Helper Server;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]

S2 zbcgfpjj;Driver Network;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]

S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\documents and settings\user\configurações

 

locais\temp\{5f83c1a2-1af2-48fe-809e-46148f7c64c4}\fsgk.sys --> c:\documents and settings\user\configurações

 

locais\temp\{5f83c1a2-1af2-48fe-809e-46148f7c64c4}\fsgk.sys [?]

S3 fsssvc;Serviço Windows Live Proteção para a Família;c:\arquivos de programas\windows live\family safety\fsssvc.exe

 

[2009-8-5 704864]

S3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [2007-5-29 508160]

 

=============== Created Last 30 ================

 

2009-12-12 03:23:42 0 d-----w- C:\786f9b05e438736728

2009-12-12 02:52:45 0 d-----w- C:\Hijack

2009-12-11 12:49:25 0 d-----w- c:\docume~1\user\dadosd~1\Malwarebytes

2009-12-11 12:49:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-12-11 12:49:12 0 d-----w- c:\docume~1\alluse~1\dadosd~1\Malwarebytes

2009-12-11 12:49:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-11 12:49:11 0 d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-12-11 12:33:55 164 ----a-w- c:\windows\system32\fjhdyfhsn.bat

2009-12-11 02:20:04 4 ----a-w- c:\docume~1\user\dadosd~1\avdrn.dat

2009-12-09 01:38:13 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2009-12-07 03:18:33 0 d-----w- c:\arquivos de programas\Audio MP3 Editor

2009-12-01 22:55:09 360580 ----a-w- c:\windows\eSellerateEngine.dll

2009-12-01 22:55:09 127 ---ha-w- c:\docume~1\user\dadosd~1\lakerda1967.sys

2009-12-01 22:55:09 0 d-----w- c:\arquivos de programas\arquivos comuns\eSellerate

2009-12-01 22:54:06 0 d-----w- c:\arquivos de programas\docXConverter3

2009-11-30 18:56:18 0 d-----w- c:\arquivos de programas\HP - Tentativa idiota

2009-11-30 01:37:42 0 d-----w- c:\arquivos de programas\avijoin

2009-11-28 13:42:09 54156 ---ha-w- c:\windows\QTFont.qfn

2009-11-28 13:42:09 1409 ----a-w- c:\windows\QTFont.for

2009-11-27 17:49:13 19286 ----a-w- C:\cleanup.exe

2009-11-27 10:05:26 1089883 -c----w- c:\windows\system32\dllcache\ntprint.cat

2009-11-26 22:33:09 0 d-----w- c:\windows\system32\XPSViewer

2009-11-26 22:32:11 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-11-26 22:32:11 117760 ------w- c:\windows\system32\prntvpt.dll

2009-11-26 22:32:10 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-11-26 22:32:10 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2009-11-26 22:32:10 575488 ------w- c:\windows\system32\xpsshhdr.dll

2009-11-26 22:32:10 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2009-11-26 22:32:10 1676288 ------w- c:\windows\system32\xpssvcs.dll

2009-11-26 22:32:09 0 d-----w- C:\1117323d4e990be59c04

2009-11-25 13:12:29 480 --sha-r- c:\documents and settings\user\ntuser.pol

2009-11-25 13:11:44 0 d--h--w- c:\windows\system32\GroupPolicy

2009-11-24 20:01:40 0 d-----w- c:\arquivos de programas\Microsoft Office Outlook Connector

2009-11-20 14:42:00 3312 ----a-w- c:\windows\system32\wbem\Outlook_01ca69ef9e449378.mof

 

==================== Find3M ====================

 

2009-12-11 12:34:54 96512 ----a-w- c:\windows\system32\drivers\atapi.sys

2009-12-09 12:07:14 79402 ----a-w- c:\windows\system32\perfc016.dat

2009-12-09 12:07:14 469730 ----a-w- c:\windows\system32\perfh016.dat

2009-11-30 19:07:41 150595 ----a-w- c:\windows\hpoins15.dat

2009-11-27 17:49:09 731136 ----a-w- c:\windows\inf\plugIE8.exe

2009-11-13 01:40:52 230432 ----a-w- C:\PA207.DAT

2009-11-10 01:27:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

2009-11-10 01:27:20 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2009-11-10 01:27:19 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2009-11-09 20:17:30 26624 ----a-w- c:\windows\system32\drivers\fsbts.sys

2009-10-29 07:42:04 916480 ----a-w- c:\windows\system32\wininet.dll

2009-10-22 18:40:54 30504 ----a-w- c:\windows\system32\drivers\GbpKm.sys

2009-10-21 05:39:39 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:39:39 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 16:20:16 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-13 10:34:00 271360 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:39:20 150016 ----a-w- c:\windows\system32\rastls.dll

2009-10-12 13:39:19 79872 ----a-w- c:\windows\system32\raschap.dll

2009-10-01 21:49:54 6675776 ----a-w- c:\arquivos de programas\Thunderbird Setup 2.0.0.23.exe

2009-02-26 23:42:06 25811528 ----a-w- c:\arquivos de programas\wmp11-windowsxp-x86-pt-br.exe

2009-02-21 23:17:40 10752240 ----a-w- c:\arquivos de programas\bsplayer235.985_clip.exe

2009-02-21 14:18:45 7321032 ----a-w- c:\arquivos de programas\daemon4303-lite.exe

2008-10-26 22:17:04 7730856 ----a-w- c:\arquivos de programas\Google_Earth_CZXV.exe

2008-07-17 12:49:26 9032208 ----a-w- c:\arquivos de programas\winamp554_full_emusic-7plus_en-us.exe

2008-07-12 02:56:57 1221566 ----a-w- c:\arquivos de programas\mIRC-AgeMania-v1.1.rar

2008-07-02 23:57:55 7326008 ----a-w- c:\arquivos de programas\Firefox Setup 3.0.exe

2008-06-23 00:34:03 8990072 ----a-w- c:\arquivos de programas\winamp5531_full_emusic-7plus_en-us.exe

2008-05-31 16:13:51 6553344 ----a-w- c:\arquivos de programas\AWCSetup.exe

2008-05-31 16:02:03 22872200 ----a-w- c:\arquivos de programas\setuppor.exe

2008-05-08 18:54:36 7789280 ----a-w- c:\arquivos de programas\SpywareTerminator_Setup.exe

2008-04-22 21:19:58 5968817 ----a-w- c:\arquivos de programas\realalt175.exe

2009-02-26 03:11:00 32768 --sha-w- c:\windows\system32\config\systemprofile\configurações

 

locais\histórico\history.ie5\mshist012009022620090227\index.dat

 

============= FINISH: 14:13:00,57 ===============

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Delete o DDS e seus relatórios

 

2.

*Desative temporariamente seu antivírus

*Baixe o ComboFix e salve-o no desktop

*Duplo-clique no arquivo Combofix.exe

*Aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix irá continuar o processo automaticamente. Caso não esteja uma janela, conforme abaixo, será aberta. Clique em [sIM] para aceitar a instalação do mesmo.

 

recovery-console-prompt.jpg

 

*Após a instalação, clique em [sIM] para continuar.

 

recovery-console-installed.jpg

 

*Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER.

*O programa será fechado automaticamente

 

*Cole o relatório criado em C:\combofix.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-12-11.05 - user 12/12/2009 14:37:55.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.571 [GMT -3:00]

Executando de: c:\documents and settings\user\Desktop\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

ADS - drivers: deleted 362 bytes in 1 streams.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\arquivos de programas\GbPlugin\gbiehcef.dll

C:\cleanup.exe

C:\start.bat

c:\windows\system32\7866944.dat

c:\windows\system32\AutoRun.inf

c:\windows\system32\config\systemprofile\av_md.exe

c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd

c:\windows\system32\filetemp.tmp

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_MESSENGERREMOTEACCESS

-------\Service_MessengerRemoteAccess

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-11-12 to 2009-12-12 ))))))))))))))))))))))))))))

.

 

2009-12-12 17:10 . 2009-11-27 13:45 2063640 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgcorex.dll

2009-12-12 17:10 . 2009-11-27 13:45 3514648 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgui.exe

2009-12-12 17:10 . 2009-11-27 13:45 2029336 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgtray.exe

2009-12-12 03:23 . 2009-12-12 03:27 -------- d-----w- C:\786f9b05e438736728

2009-12-12 02:52 . 2009-12-12 02:54 -------- d-----w- C:\Hijack

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\Malwarebytes

2009-12-11 12:49 . 2009-12-03 19:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-12-11 12:49 . 2009-12-03 19:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-11 12:34 . 2009-12-11 12:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2009-12-11 12:33 . 2009-12-11 12:33 164 ----a-w- c:\windows\system32\fjhdyfhsn.bat

2009-12-09 01:38 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2009-12-07 03:18 . 2009-12-07 03:18 -------- d-----w- c:\arquivos de programas\Audio MP3 Editor

2009-12-01 22:55 . 2009-12-01 22:55 127 ---ha-w- c:\documents and settings\user\Dados de aplicativos\lakerda1967.sys

2009-12-01 22:55 . 2009-12-01 22:55 360580 ----a-w- c:\windows\eSellerateEngine.dll

2009-12-01 22:55 . 2009-12-01 22:55 -------- d-----w- c:\arquivos de programas\Arquivos comuns\eSellerate

2009-12-01 22:54 . 2009-12-01 22:56 -------- d-----w- c:\arquivos de programas\docXConverter3

2009-11-30 19:06 . 2009-11-30 19:06 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\HPSSUPPLY

2009-11-30 18:56 . 2009-11-30 18:59 -------- d-----w- c:\arquivos de programas\HP - Tentativa idiota

2009-11-30 01:37 . 2009-11-30 01:37 -------- d-----w- c:\arquivos de programas\avijoin

2009-11-27 23:10 . 2009-11-27 23:24 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center

2009-11-26 22:33 . 2009-11-26 22:33 -------- d-----w- c:\windows\system32\XPSViewer

2009-11-26 22:33 . 2009-11-26 22:33 -------- d-----w- c:\arquivos de programas\MSBuild

2009-11-26 22:32 . 2009-11-26 22:32 -------- d-----w- c:\arquivos de programas\Reference Assemblies

2009-11-26 22:32 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2009-11-26 22:32 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-11-26 22:32 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2009-11-26 22:32 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2009-11-26 22:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2009-11-26 22:32 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2009-11-26 22:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2009-11-26 22:32 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-11-26 22:32 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2009-11-26 22:32 . 2009-11-26 22:32 -------- d-----w- C:\1117323d4e990be59c04

2009-11-25 13:11 . 2009-11-25 13:11 -------- d--h--w- c:\windows\system32\GroupPolicy

2009-11-24 20:01 . 2009-11-24 20:01 -------- d-----w- c:\arquivos de programas\Microsoft Office Outlook Connector

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-12 17:42 . 2008-05-06 10:51 -------- d-----w- c:\arquivos de programas\GbPlugin

2009-12-12 03:11 . 2009-11-09 18:55 -------- d-----w- c:\arquivos de programas\Worm fight

2009-12-11 12:34 . 2004-08-04 01:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys

2009-12-11 02:20 . 2009-12-11 02:20 16 ----a-w- c:\documents and settings\NetworkService\Dados de aplicativos\fvgqad.dat

2009-12-11 02:20 . 2009-12-11 02:20 4 ----a-w- c:\documents and settings\user\Dados de aplicativos\avdrn.dat

2009-12-10 12:23 . 2008-05-06 10:51 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\GbPlugin

2009-12-09 12:07 . 2001-10-28 18:07 79402 ----a-w- c:\windows\system32\perfc016.dat

2009-12-09 12:07 . 2001-10-28 18:07 469730 ----a-w- c:\windows\system32\perfh016.dat

2009-11-30 19:07 . 2008-06-28 21:31 150595 ----a-w- c:\windows\hpoins15.dat

2009-11-30 19:06 . 2008-06-28 21:33 -------- d-----w- c:\arquivos de programas\HP

2009-11-27 22:51 . 2008-05-13 01:20 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spyware Terminator

2009-11-27 22:51 . 2008-05-13 01:20 -------- d-----w- c:\arquivos de programas\Spyware Terminator

2009-11-27 22:44 . 2008-05-13 01:20 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\Spyware Terminator

2009-11-27 17:49 . 2009-11-27 17:49 731136 ----a-w- c:\windows\inf\plugIE8.exe

2009-11-24 19:54 . 2008-05-04 21:13 -------- d-----w- c:\arquivos de programas\Windows Live

2009-11-21 15:58 . 2004-08-04 03:45 471552 ----a-w- c:\windows\AppPatch\aclayers.dll

2009-11-13 01:40 . 2009-04-18 03:10 230432 ----a-w- C:\PA207.DAT

2009-11-10 01:29 . 2009-11-10 01:27 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVG Security Toolbar

2009-11-10 01:27 . 2009-11-10 01:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

2009-11-10 01:27 . 2009-11-10 01:27 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2009-11-10 01:27 . 2009-11-10 01:27 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2009-11-10 01:27 . 2009-11-09 11:16 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2009-11-10 01:26 . 2009-11-10 01:26 -------- d-----w- c:\arquivos de programas\AVG

2009-11-10 01:26 . 2009-11-10 01:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\avg8

2009-11-10 00:54 . 2009-03-18 23:28 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight

2009-11-09 20:17 . 2009-11-09 20:17 26624 ----a-w- c:\windows\system32\drivers\fsbts.sys

2009-11-09 03:08 . 2009-11-09 03:08 -------- d-----w- c:\arquivos de programas\CCleaner

2009-11-07 19:51 . 2007-12-27 22:52 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe

2009-11-06 23:44 . 2009-11-06 23:44 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\McAfee

2009-11-06 23:42 . 2009-11-06 23:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\McAfee Security Scan

2009-11-06 23:42 . 2009-11-06 23:42 -------- d-----w- c:\arquivos de programas\McAfee Security Scan

2009-10-29 07:42 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll

2009-10-25 15:07 . 2009-10-01 21:56 -------- d-----w- c:\arquivos de programas\Mozilla Thunderbird

2009-10-22 18:40 . 2009-02-28 19:05 30504 ----a-w- c:\windows\system32\drivers\GbpKm.sys

2009-10-21 23:13 . 2009-02-21 23:20 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\BSplayer

2009-10-21 05:39 . 2004-08-04 03:45 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:39 . 2004-08-04 03:45 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 16:20 . 2004-08-04 02:00 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-13 10:34 . 2004-08-04 03:45 271360 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:39 . 2004-08-04 03:45 150016 ----a-w- c:\windows\system32\rastls.dll

2009-10-12 13:39 . 2004-08-04 03:45 79872 ----a-w- c:\windows\system32\raschap.dll

2009-10-01 21:49 . 2009-10-01 21:44 6675776 ----a-w- c:\arquivos de programas\Thunderbird Setup 2.0.0.23.exe

2009-02-26 23:42 . 2009-02-26 23:31 25811528 ----a-w- c:\arquivos de programas\wmp11-windowsxp-x86-pt-br.exe

2009-02-21 23:17 . 2009-02-21 23:09 10752240 ----a-w- c:\arquivos de programas\bsplayer235.985_clip.exe

2009-02-21 14:18 . 2009-02-21 14:15 7321032 ----a-w- c:\arquivos de programas\daemon4303-lite.exe

2008-10-26 22:17 . 2008-10-26 22:12 7730856 ----a-w- c:\arquivos de programas\Google_Earth_CZXV.exe

2008-07-17 12:49 . 2008-07-17 12:47 9032208 ----a-w- c:\arquivos de programas\winamp554_full_emusic-7plus_en-us.exe

2008-07-12 02:56 . 2008-07-12 02:56 1221566 ----a-w- c:\arquivos de programas\mIRC-AgeMania-v1.1.rar

2008-07-02 23:57 . 2008-07-02 23:57 7326008 ----a-w- c:\arquivos de programas\Firefox Setup 3.0.exe

2008-06-23 00:34 . 2008-06-23 00:33 8990072 ----a-w- c:\arquivos de programas\winamp5531_full_emusic-7plus_en-us.exe

2008-05-31 16:13 . 2008-05-31 16:13 6553344 ----a-w- c:\arquivos de programas\AWCSetup.exe

2008-05-31 16:02 . 2008-05-31 16:02 22872200 ----a-w- c:\arquivos de programas\setuppor.exe

2008-05-08 18:54 . 2008-05-13 01:20 7789280 ----a-w- c:\arquivos de programas\SpywareTerminator_Setup.exe

2008-04-22 21:19 . 2008-04-22 23:55 5968817 ----a-w- c:\arquivos de programas\realalt175.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-09-02 14:58 1107200 ----a-w- c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]

"Alcmtr"="ALCMTR.EXE" [2005-05-03 69632]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]

"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]

"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2006-09-01 282624]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-11-10 01:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

"c:\\Arquivos de programas\\Microsoft Games\\Rise of Nations\\thrones.exe"=

"c:\\Arquivos de programas\\Jogos\\Free-Unreal-Tournament-1999-GOTY\\System\\UCC.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Brazilian\\setup.exe"=

"c:\\Arquivos de programas\\Jogos\\Age of Empires 2\\empires2.exe"=

"c:\\Arquivos de programas\\Jogos\\Age of Empires 2\\Age of empires 2 gold\\Age of empires 2 gold\\age2_x1.exe"=

"c:\\Arquivos de programas\\Jogos\\THAW-by maikon.lucas-www.gamedownload.com.br\\THAW-by maikon.lucas-www.gamedownload.com.br\\Game\\THAW.exe"=

"c:\\Documents and Settings\\user\\Desktop\\utorrent.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Jogos\\Ea Sports\\F-1 Mania 2008\\F1 Challenge 2008.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"53:UDP"= 53:UDP:Promo

"4867:TCP"= 4867:TCP:psvwfhkq

 

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [9/11/2009 17:17 26624]

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/2/2009 12:05 717296]

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2009 22:27 335240]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2009 22:27 108552]

R1 SNSID;SNSID;c:\windows\system32\drivers\SNSID.SYS [2/5/2008 21:51 22272]

R1 SNSMS;SNSMS;c:\windows\system32\drivers\SNSMS.SYS [2/5/2008 21:51 34440]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [9/11/2009 22:26 297752]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [18/3/2009 22:37 54752]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [12/11/2009 18:19 53800]

R2 Ps2KSecureKeyboard;SecureKbd;c:\windows\system32\drivers\psseckbd.sys [2/5/2008 21:51 15048]

S0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\GbpKm.sys [28/2/2009 16:05 30504]

S1 IPNETC;IP Network Control;c:\windows\system32\drivers\ipnetc.sys --> c:\windows\system32\drivers\ipnetc.sys [?]

S2 swyvsw;Helper Server;c:\windows\system32\svchost.exe -k netsvcs [4/8/2004 00:45 14336]

S2 zbcgfpjj;Driver Network;c:\windows\system32\svchost.exe -k netsvcs [4/8/2004 00:45 14336]

S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\documents and settings\user\Configurações locais\Temp\{5F83C1A2-1AF2-48FE-809E-46148F7C64C4}\fsgk.sys --> c:\documents and settings\user\Configurações locais\Temp\{5F83C1A2-1AF2-48FE-809E-46148F7C64C4}\fsgk.sys [?]

S3 fsssvc;Serviço Windows Live Proteção para a Família;c:\arquivos de programas\Windows Live\Family Safety\fsssvc.exe [5/8/2009 22:48 704864]

S3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29/5/2007 13:30 508160]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

zbcgfpjj

.

------- Scan Suplementar -------

.

uStart Page = about:blank

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} - hxxps://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab

DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab

DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} - hxxps://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

FF - ProfilePath - c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\

FF - prefs.js: browser.startup.homepage - about:blank

FF - prefs.js: keyword.URL - hxxp://br.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_br&p=

FF - component: c:\arquivos de programas\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}\components\GbMzhBb.dll

FF - component: c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}\components\GbMzhUni.dll

FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

- - - - ORFÃOS REMOVIDOS - - - -

 

ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399008} - c:\arquiv~1\GbPlugin\gbiehuni.dll

ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399003} - c:\arquivos de programas\GbPlugin\gbiehcef.dll

Notify- GbPluginBb - (no file)

Notify- GbPluginCef - c:\arquivos de programas\GBPLUGIN\gbiehcef.dll

Notify- GbPluginUni - c:\arquiv~1\GbPlugin\gbiehuni.dll

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-12 14:55

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: error reading MBR

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spsa.sys >>UNKNOWN [0x86D8D938]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf754bf28

\Driver\ACPI -> ACPI.sys @ 0xf72c6cb8

\Driver\atapi -> atapi.sys @ 0xf725bb40

IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Realtek RTL8169/8110 Family Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7164bb0

PacketIndicateHandler -> NDIS.sys @ 0xf7171a21

SendHandler -> NDIS.sys @ 0xf714f87b

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\swyvsw]

"ServiceDll"="c:\windows\system32\htowzij.dll"

--

 

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\zbcgfpjj]

"ServiceDll"="c:\windows\system32\htowzij.dll"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(2980)

c:\windows\system32\WININET.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\agrsmsvc.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\arquiv~1\AVG\AVG8\avgrsx.exe

c:\arquiv~1\AVG\AVG8\avgnsx.exe

c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\arquivos de programas\Spyware Terminator\sp_rsser.exe

c:\windows\system32\wscntfy.exe

c:\windows\RTHDCPL.EXE

.

**************************************************************************

.

Tempo para conclusão: 2009-12-12 14:59:53 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-12-12 17:59

 

Pré-execução: 12 pasta(s) 17.659.957.248 bytes disponíveis

Pós execução: 16 pasta(s) 17.590.755.328 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

- - End Of File - - 68BD3F7C0DCFCB78B0457E962737DEA9

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo:

 

File::

c:\windows\system32\htowzij.dll

c:\windows\system32\fjhdyfhsn.bat

c:\documents and settings\NetworkService\Dados de aplicativos\fvgqad.dat

c:\documents and settings\user\Dados de aplicativos\avdrn.dat

Registry::

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4867:TCP"=-

NetSvcs::

zbcgfpjj

NetSvc::

swyvsw

zbcgfpjj

Driver::

zbcgfpjj

swyvsw

zbcgfpjj

 

*Salve o arquivo no desktop como CFScript.txt

*Arraste o arquivo para o Combofix conforme ilustração abaixo:

 

CFScript.gif

 

*Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!!..para interromper o processo tecle N ou 2.

 

 

*Cole o relatório criado em C:\combofix.txt e novo log do hijack

Compartilhar este post


Link para o post
Compartilhar em outros sites

O sistema não conseguiu iniciar sozinho... nas duas x q usei o combofix, depois dele reiniciar a máquina, só apareceu o papel de parede... entrei no gerenciador de tarefas e iniciei system, só assim o combofix concluiu o relatório...

 

Segue o log do combofix, enquanto passo o hijack.

 

ComboFix 09-12-11.05 - user 12/12/2009 16:13:07.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.593 [GMT -3:00]

Executando de: c:\documents and settings\user\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\user\Desktop\CFScript.txt

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

 

FILE ::

"c:\documents and settings\NetworkService\Dados de aplicativos\fvgqad.dat"

"c:\documents and settings\user\Dados de aplicativos\avdrn.dat"

"c:\windows\system32\fjhdyfhsn.bat"

"c:\windows\system32\htowzij.dll"

.

ADS - drivers: deleted 8 bytes in 1 streams.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\NetworkService\Dados de aplicativos\fvgqad.dat

c:\documents and settings\user\Dados de aplicativos\avdrn.dat

c:\windows\system32\fjhdyfhsn.bat

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_SWYVSW

-------\Legacy_ZBCGFPJJ

-------\Service_swyvsw

-------\Service_zbcgfpjj

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-11-12 to 2009-12-12 ))))))))))))))))))))))))))))

.

 

2009-12-12 17:10 . 2009-11-27 13:45 2063640 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgcorex.dll

2009-12-12 17:10 . 2009-11-27 13:45 3514648 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgui.exe

2009-12-12 17:10 . 2009-11-27 13:45 2029336 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\avg8\update\backup\avgtray.exe

2009-12-12 03:23 . 2009-12-12 03:27 -------- d-----w- C:\786f9b05e438736728

2009-12-12 02:52 . 2009-12-12 02:54 -------- d-----w- C:\Hijack

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\Malwarebytes

2009-12-11 12:49 . 2009-12-03 19:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2009-12-11 12:49 . 2009-12-11 12:49 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2009-12-11 12:49 . 2009-12-03 19:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-11 12:34 . 2009-12-11 12:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2009-12-09 01:38 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2009-12-07 03:18 . 2009-12-07 03:18 -------- d-----w- c:\arquivos de programas\Audio MP3 Editor

2009-12-01 22:55 . 2009-12-01 22:55 127 ---ha-w- c:\documents and settings\user\Dados de aplicativos\lakerda1967.sys

2009-12-01 22:55 . 2009-12-01 22:55 360580 ----a-w- c:\windows\eSellerateEngine.dll

2009-12-01 22:55 . 2009-12-01 22:55 -------- d-----w- c:\arquivos de programas\Arquivos comuns\eSellerate

2009-12-01 22:54 . 2009-12-01 22:56 -------- d-----w- c:\arquivos de programas\docXConverter3

2009-11-30 19:06 . 2009-11-30 19:06 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\HPSSUPPLY

2009-11-30 18:56 . 2009-11-30 18:59 -------- d-----w- c:\arquivos de programas\HP - Tentativa idiota

2009-11-30 01:37 . 2009-11-30 01:37 -------- d-----w- c:\arquivos de programas\avijoin

2009-11-27 23:10 . 2009-11-27 23:24 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center

2009-11-26 22:33 . 2009-11-26 22:33 -------- d-----w- c:\windows\system32\XPSViewer

2009-11-26 22:33 . 2009-11-26 22:33 -------- d-----w- c:\arquivos de programas\MSBuild

2009-11-26 22:32 . 2009-11-26 22:32 -------- d-----w- c:\arquivos de programas\Reference Assemblies

2009-11-26 22:32 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2009-11-26 22:32 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-11-26 22:32 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2009-11-26 22:32 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2009-11-26 22:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2009-11-26 22:32 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2009-11-26 22:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2009-11-26 22:32 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-11-26 22:32 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2009-11-26 22:32 . 2009-11-26 22:32 -------- d-----w- C:\1117323d4e990be59c04

2009-11-25 13:11 . 2009-11-25 13:11 -------- d--h--w- c:\windows\system32\GroupPolicy

2009-11-24 20:01 . 2009-11-24 20:01 -------- d-----w- c:\arquivos de programas\Microsoft Office Outlook Connector

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-12-12 17:42 . 2008-05-06 10:51 -------- d-----w- c:\arquivos de programas\GbPlugin

2009-12-12 03:11 . 2009-11-09 18:55 -------- d-----w- c:\arquivos de programas\Worm fight

2009-12-11 12:34 . 2004-08-04 01:59 96512 ------w- c:\windows\system32\drivers\atapi.sys

2009-12-10 12:23 . 2008-05-06 10:51 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\GbPlugin

2009-12-09 12:07 . 2001-10-28 18:07 79402 ----a-w- c:\windows\system32\perfc016.dat

2009-12-09 12:07 . 2001-10-28 18:07 469730 ----a-w- c:\windows\system32\perfh016.dat

2009-11-30 19:07 . 2008-06-28 21:31 150595 ----a-w- c:\windows\hpoins15.dat

2009-11-30 19:06 . 2008-06-28 21:33 -------- d-----w- c:\arquivos de programas\HP

2009-11-27 22:51 . 2008-05-13 01:20 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spyware Terminator

2009-11-27 22:51 . 2008-05-13 01:20 -------- d-----w- c:\arquivos de programas\Spyware Terminator

2009-11-27 22:44 . 2008-05-13 01:20 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\Spyware Terminator

2009-11-27 17:49 . 2009-11-27 17:49 731136 ----a-w- c:\windows\inf\plugIE8.exe

2009-11-24 19:54 . 2008-05-04 21:13 -------- d-----w- c:\arquivos de programas\Windows Live

2009-11-21 15:58 . 2004-08-04 03:45 471552 ----a-w- c:\windows\AppPatch\aclayers.dll

2009-11-13 01:40 . 2009-04-18 03:10 230432 ----a-w- C:\PA207.DAT

2009-11-10 01:29 . 2009-11-10 01:27 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVG Security Toolbar

2009-11-10 01:27 . 2009-11-10 01:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

2009-11-10 01:27 . 2009-11-10 01:27 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2009-11-10 01:27 . 2009-11-10 01:27 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2009-11-10 01:27 . 2009-11-09 11:16 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2009-11-10 01:26 . 2009-11-10 01:26 -------- d-----w- c:\arquivos de programas\AVG

2009-11-10 01:26 . 2009-11-10 01:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\avg8

2009-11-10 00:54 . 2009-03-18 23:28 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight

2009-11-09 20:17 . 2009-11-09 20:17 26624 ----a-w- c:\windows\system32\drivers\fsbts.sys

2009-11-09 03:08 . 2009-11-09 03:08 -------- d-----w- c:\arquivos de programas\CCleaner

2009-11-07 19:51 . 2007-12-27 22:52 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe

2009-11-06 23:44 . 2009-11-06 23:44 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\McAfee

2009-11-06 23:42 . 2009-11-06 23:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\McAfee Security Scan

2009-11-06 23:42 . 2009-11-06 23:42 -------- d-----w- c:\arquivos de programas\McAfee Security Scan

2009-10-29 07:42 . 2004-08-04 03:45 916480 ------w- c:\windows\system32\wininet.dll

2009-10-25 15:07 . 2009-10-01 21:56 -------- d-----w- c:\arquivos de programas\Mozilla Thunderbird

2009-10-22 18:40 . 2009-02-28 19:05 30504 ----a-w- c:\windows\system32\drivers\GbpKm.sys

2009-10-21 23:13 . 2009-02-21 23:20 -------- d-----w- c:\documents and settings\user\Dados de aplicativos\BSplayer

2009-10-21 05:39 . 2004-08-04 03:45 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:39 . 2004-08-04 03:45 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 16:20 . 2004-08-04 02:00 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-13 10:34 . 2004-08-04 03:45 271360 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:39 . 2004-08-04 03:45 150016 ----a-w- c:\windows\system32\rastls.dll

2009-10-12 13:39 . 2004-08-04 03:45 79872 ----a-w- c:\windows\system32\raschap.dll

2009-10-01 21:49 . 2009-10-01 21:44 6675776 ----a-w- c:\arquivos de programas\Thunderbird Setup 2.0.0.23.exe

2009-02-26 23:42 . 2009-02-26 23:31 25811528 ----a-w- c:\arquivos de programas\wmp11-windowsxp-x86-pt-br.exe

2009-02-21 23:17 . 2009-02-21 23:09 10752240 ----a-w- c:\arquivos de programas\bsplayer235.985_clip.exe

2009-02-21 14:18 . 2009-02-21 14:15 7321032 ----a-w- c:\arquivos de programas\daemon4303-lite.exe

2008-10-26 22:17 . 2008-10-26 22:12 7730856 ----a-w- c:\arquivos de programas\Google_Earth_CZXV.exe

2008-07-17 12:49 . 2008-07-17 12:47 9032208 ----a-w- c:\arquivos de programas\winamp554_full_emusic-7plus_en-us.exe

2008-07-12 02:56 . 2008-07-12 02:56 1221566 ----a-w- c:\arquivos de programas\mIRC-AgeMania-v1.1.rar

2008-07-02 23:57 . 2008-07-02 23:57 7326008 ----a-w- c:\arquivos de programas\Firefox Setup 3.0.exe

2008-06-23 00:34 . 2008-06-23 00:33 8990072 ----a-w- c:\arquivos de programas\winamp5531_full_emusic-7plus_en-us.exe

2008-05-31 16:13 . 2008-05-31 16:13 6553344 ----a-w- c:\arquivos de programas\AWCSetup.exe

2008-05-31 16:02 . 2008-05-31 16:02 22872200 ----a-w- c:\arquivos de programas\setuppor.exe

2008-05-08 18:54 . 2008-05-13 01:20 7789280 ----a-w- c:\arquivos de programas\SpywareTerminator_Setup.exe

2008-04-22 21:19 . 2008-04-22 23:55 5968817 ----a-w- c:\arquivos de programas\realalt175.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-09-02 14:58 1107200 ----a-w- c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]

"Alcmtr"="ALCMTR.EXE" [2005-05-03 69632]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]

"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]

"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]

"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2006-09-01 282624]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]

c:\arquivos de programas\GBPLUGIN\gbiehcef.dll [bU]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginUni]

c:\arquiv~1\GbPlugin\gbiehuni.dll [bU]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-11-10 01:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

"c:\\Arquivos de programas\\Microsoft Games\\Rise of Nations\\thrones.exe"=

"c:\\Arquivos de programas\\Jogos\\Free-Unreal-Tournament-1999-GOTY\\System\\UCC.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Brazilian\\setup.exe"=

"c:\\Arquivos de programas\\Jogos\\Age of Empires 2\\empires2.exe"=

"c:\\Arquivos de programas\\Jogos\\Age of Empires 2\\Age of empires 2 gold\\Age of empires 2 gold\\age2_x1.exe"=

"c:\\Arquivos de programas\\Jogos\\THAW-by maikon.lucas-www.gamedownload.com.br\\THAW-by maikon.lucas-www.gamedownload.com.br\\Game\\THAW.exe"=

"c:\\Documents and Settings\\user\\Desktop\\utorrent.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Jogos\\Ea Sports\\F-1 Mania 2008\\F1 Challenge 2008.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"53:UDP"= 53:UDP:Promo

 

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [9/11/2009 17:17 26624]

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\GbpKm.sys [28/2/2009 16:05 30504]

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/2/2009 12:05 717296]

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/11/2009 22:27 335240]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/11/2009 22:27 108552]

R1 SNSID;SNSID;c:\windows\system32\drivers\SNSID.SYS [2/5/2008 21:51 22272]

R1 SNSMS;SNSMS;c:\windows\system32\drivers\SNSMS.SYS [2/5/2008 21:51 34440]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [9/11/2009 22:26 297752]

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [18/3/2009 22:37 54752]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [12/11/2009 18:19 53800]

R2 Ps2KSecureKeyboard;SecureKbd;c:\windows\system32\drivers\psseckbd.sys [2/5/2008 21:51 15048]

S1 IPNETC;IP Network Control;c:\windows\system32\drivers\ipnetc.sys --> c:\windows\system32\drivers\ipnetc.sys [?]

S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\documents and settings\user\Configurações locais\Temp\{5F83C1A2-1AF2-48FE-809E-46148F7C64C4}\fsgk.sys --> c:\documents and settings\user\Configurações locais\Temp\{5F83C1A2-1AF2-48FE-809E-46148F7C64C4}\fsgk.sys [?]

S3 fsssvc;Serviço Windows Live Proteção para a Família;c:\arquivos de programas\Windows Live\Family Safety\fsssvc.exe [5/8/2009 22:48 704864]

S3 PAC207;PC Camera;c:\windows\system32\drivers\PFC027.SYS [29/5/2007 13:30 508160]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

------- Scan Suplementar -------

.

uStart Page = about:blank

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} - hxxps://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab

DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab

FF - ProfilePath - c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\

FF - prefs.js: browser.startup.homepage - about:blank

FF - prefs.js: keyword.URL - hxxp://br.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_br&p=

FF - component: c:\arquivos de programas\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}\components\GbMzhBb.dll

FF - component: c:\documents and settings\user\Dados de aplicativos\Mozilla\Firefox\Profiles\zqpe721h.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}\components\GbMzhUni.dll

FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-12 16:23

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

 

device: opened successfully

user: error reading MBR

called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spga.sys >>UNKNOWN [0x86D8C938]<<

kernel: MBR read successfully

detected MBR rootkit hooks:

\Driver\Disk -> CLASSPNP.SYS @ 0xf7568f28

\Driver\ACPI -> ACPI.sys @ 0xf72e3cb8

\Driver\atapi -> atapi.sys @ 0xf7278b40

IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Realtek RTL8169/8110 Family Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7181bb0

PacketIndicateHandler -> NDIS.sys @ 0xf718ea21

SendHandler -> NDIS.sys @ 0xf716c87b

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(3700)

c:\windows\system32\WININET.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\agrsmsvc.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\arquiv~1\AVG\AVG8\avgrsx.exe

c:\arquiv~1\AVG\AVG8\avgnsx.exe

c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\arquivos de programas\Spyware Terminator\sp_rsser.exe

c:\windows\system32\wscntfy.exe

c:\windows\RTHDCPL.EXE

.

**************************************************************************

.

Tempo para conclusão: 2009-12-12 16:27:02 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-12-12 19:26

ComboFix2.txt 2009-12-12 17:59

 

Pré-execução: 15 pasta(s) 17.620.320.256 bytes disponíveis

Pós execução: 16 pasta(s) 17.605.824.512 bytes disponíveis

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

- - End Of File - - C75BF6713D215293D16427916481C8F1

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:31:57, on 12/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\agrsmsvc.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\QuickTime\qttask.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\hkcmd.exe

C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\explorer.exe

C:\Hijack\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - (no file)

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (file missing)

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKCU\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKCU\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKCU\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKCU\..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe

O4 - HKCU\..\Run: [skyTel] SkyTel.EXE

O4 - HKCU\..\Run: [RTHDCPL] RTHDCPL.EXE

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} (CAtmCap Object) - https://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235609580187

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258079346734

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: GbPluginCef - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbiehcef.dll (file missing)

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

 

--

End of file - 7851 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Clique em [iniciar] > [Executar] > digite: combofix /uninstall

*Clique [OK]

 

92674490.jpg

 

*Clique em [Executar]

*Surgirá a mensagem: "ComboFix está desinstalado"

 

*Clique [OK]

*Delete o arquivo C:\combofix.txt

 

2.

*Baixe o MBR e salve-o em C:\

*Duplo clique em C:\mbr.exe

*Cole o relatório criado em C:\MBR.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...o PC está limpo.

 

*Delete os arquivos C:\MBR.exe e C:\mbr.txt

 

 

Um abraço e Feliz Natal.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.