mukarillo 0 Denunciar post Postado Dezembro 12, 2009 Olá galera, hoje a tarde, derrepente, meu msn começou a abrir inúmeras janelas de converça e chamar a atenção e mandar umas mensagens que nao tem nada a ve ( tipo: SQA$#), támbem abria o site do msn. ai procurei na internet e achei o site de você's não sei bem o que fazer, lendo umas instruções ai eu vi um tal de HijackThis e fiz. C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\dlllhost.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\3nvy\alg.exe C:\svrhost.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\dwwin.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/ F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\dlllhost.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe -- End of file - 5054 bytes Caso eu tenha de fazer outra coisa, porfavor me falem :/ to com medo de ser um keyloger ou algo parecido! Valeu, Muka. Ps: Meu computador, abre uma janela falando qeu deu um erro no Explorer.exe. Alguem sabe arrumar isso :s Obrigado denovo Edit: quando eu instalei o avast! ele diz qeu tem um vírus na memoria RAM e que precisa ser reiniciado para qeu possa fazer uma verificação ( algo assim). O que devo fazer? Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 13, 2009 Boa Noite! mukarillo <!> Seu relatório do HijackThis,veio sem o cabeçalho. <><><><><><><><><><><> <@> Baixe: < > <@> < Link - 2 > <@> < Link - 3 > <@> Atualize o programa! <@> Escolha o escaneamento Completo! <@> Desabilite programas de proteção,ao executar o malwarebytes. <@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme! <@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. <@> Para maiores detalhes: < Link > <><><><><><><><><><><> <@> Poste,os relatórios: mbam-log-2009-xx-xx (00-00-00).txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
mukarillo 0 Denunciar post Postado Dezembro 13, 2009 Malwarebytes' Anti-Malware 1.42 Versão do banco de dados: 3350 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 12/12/2009 22:41:54 mbam-log-2009-12-12 (22-41-54).txt Tipo de Verificação: Completa (C:\|D:\|E:\|) Objetos verificados: 227322 Tempo decorrido: 32 minute(s), 42 second(s) Processos da Memória infectados: 1 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 3 Valores do Registro infectados: 0 Ítens do Registro infectados: 3 Pastas infectadas: 2 Arquivos infectados: 8 Processos da Memória infectados: C:\WINDOWS\system32\dlllhost.exe (Worm.AutoRun) -> Unloaded process successfully. Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully. Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Worm.AutoRun) -> Data: c:\windows\system32\dlllhost.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Worm.AutoRun) -> Data: system32\dlllhost.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\dlllhost.exe) Good: (Userinit.exe) -> Quarantined and deleted successfully. Pastas infectadas: C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> Quarantined and deleted successfully. C:\WINDOWS\3nvy (Trojan.Banker) -> Quarantined and deleted successfully. Arquivos infectados: C:\WINDOWS\system32\dlllhost.exe (Worm.AutoRun) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\iexplorer.pif (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\s3tu7.dll (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\tum8v.exe (HackTool.PWSViewer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{584F9A72-8980-4029-9F43-668B28870040}\RP67\A0028370.exe (Backdoor.IRCbot) -> Quarantined and deleted successfully. C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> Quarantined and deleted successfully. C:\WINDOWS\3nvy\alg.ex (Trojan.Banker) -> Quarantined and deleted successfully. C:\Arquivos de programas\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully. E o do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:47:08, on 12/12/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe -- End of file - 5238 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 13, 2009 Boa Noite! mukarillo <@> Baixe: < > ( ...by sUBs ) <!> Link-2 --> < ForoSpyware > <!> Link-3 --> < GeeksToGo > <!> Link-4 --> < como usar o combofix > <@> Salve-o no desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Ps: A execução,por comando,também é possível:<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall <@> Clique em Ok. <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <@> Terminando,clique Sim ou Yes. --> Aguarde! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link! <!> Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação: <!> Ps: Anote essas detecções,e dê o OK. <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta! <!> Ps: Para evitar problemas,siga todas as recomendações propostas. <!> O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter! <><><><><><><><><><><><> <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
mukarillo 0 Denunciar post Postado Dezembro 13, 2009 aqui esta o log do Combo ComboFix 09-12-11.05 - Lopes 13/12/2009 3:08.1.4 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.2559.1961 [GMT -2:00] Executando de: c:\documents and settings\Lopes\desktop\Combofix.exe Comandos utilizados :: /killall AV: avast! antivirus 4.8.1368 [VPS 091212-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycler\S-1-5-21-1123561945-1960408961-682003330-1001 C:\restore . (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-13 to 2009-12-13 )))))))))))))))))))))))))))) . 2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Malwarebytes 2009-12-13 00:07 . 2009-12-03 18:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Malwarebytes 2009-12-13 00:07 . 2009-12-03 18:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-12-12 23:05 . 2009-12-13 04:53 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat 2009-12-12 22:33 . 2009-12-12 23:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Comodo 2009-12-12 22:33 . 2009-12-12 22:33 87104 ----a-w- c:\windows\system32\drivers\inspect.sys 2009-12-12 22:33 . 2009-12-12 22:33 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys 2009-12-12 22:33 . 2009-12-12 22:33 171552 ----a-w- c:\windows\system32\guard32.dll 2009-12-12 22:33 . 2009-12-12 22:33 133064 ----a-w- c:\windows\system32\drivers\cmdguard.sys 2009-12-12 22:33 . 2009-12-12 22:33 -------- d-----w- c:\arquivos de programas\COMODO 2009-12-12 22:14 . 2009-12-12 22:15 -------- d-----w- C:\LinhaDefensiva 2009-12-12 21:36 . 2009-12-12 22:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy 2009-12-12 21:36 . 2009-12-12 21:36 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy 2009-12-12 21:30 . 2009-12-12 21:30 -------- d-----w- c:\arquivos de programas\CCleaner 2009-12-12 21:17 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Symantec Shared 2009-12-12 21:05 . 2009-12-12 21:07 707329 ----a-w- C:\Wanasah.exe 2009-12-12 16:22 . 2009-12-12 21:25 2771 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys 2009-12-12 00:37 . 2009-12-12 00:37 53248 ----a-w- c:\windows\fullscreen.exe 2009-12-06 17:33 . 2009-12-06 17:33 -------- d-----w- c:\arquivos de programas\ElfBot NG852 2009-12-05 23:56 . 2009-12-05 23:56 -------- d-----w- c:\windows\system32\LogFiles 2009-12-04 11:31 . 2009-12-04 12:16 -------- d-----w- c:\arquivos de programas\tibiacast2 2009-12-04 11:26 . 2009-11-06 14:49 551936 ----a-w- c:\arquivos de programas\Tibiacast Installer.msi 2009-12-04 11:26 . 2009-12-04 11:23 507461 ----a-w- c:\arquivos de programas\tibiacast_2_6_1.zip 2009-12-03 03:08 . 2009-08-19 07:18 107864 ----a-w- c:\windows\system32\tsccvid.dll 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\windows\system32\QuickTime 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\QuickTime 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\Arquivos comuns\TechSmith Shared 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\TechSmith 2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Publish Providers 2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Sony 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Vstplugins 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Sony 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Sony 2009-12-03 02:53 . 2009-12-03 02:53 -------- d-----w- c:\arquivos de programas\Sony Setup 2009-12-02 20:54 . 2008-07-08 17:29 1654869 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\DynuEncrypt.dll 2009-12-02 19:30 . 2009-12-02 19:30 -------- d-----w- C:\Level Up! Games 2009-12-02 19:21 . 2009-12-02 19:21 -------- d-----w- C:\TopGames37 2009-12-02 19:18 . 2009-12-02 19:18 -------- d-----w- c:\arquivos de programas\Arquivos comuns\SWF Studio 2009-11-28 13:20 . 2009-11-28 13:21 -------- d-----w- c:\arquivos de programas\TibiaCam TV Lite 2009-11-27 16:07 . 2009-11-27 16:07 -------- d-----w- c:\arquivos de programas\Tibia850 2009-11-26 01:43 . 2009-11-26 01:43 -------- d-----w- c:\arquivos de programas\Gravity 2009-11-26 00:53 . 2009-02-09 05:10 67208 ----a-w- c:\windows\UnDeploy.exe 2009-11-26 00:49 . 2009-11-26 00:50 -------- d-----w- c:\windows\system32\NtmsData 2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Norton 2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Symantec 2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\NortonInstaller 2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\NortonInstaller 2009-11-24 19:51 . 2009-11-24 19:51 -------- d-----w- c:\windows\system32\Adobe 2009-11-23 22:34 . 2009-11-23 22:34 -------- d-----w- c:\arquivos de programas\Windows Journal Viewer 2009-11-18 00:43 . 2009-11-18 00:43 190464 ----a-w- c:\windows\system32\delzip179.dll 2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Eng.dll 2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Kor.dll 2009-11-15 22:57 . 2009-09-23 19:42 364912 ----a-w- c:\windows\system32\CMStarterCore.exe 2009-11-15 22:54 . 2009-11-15 22:57 -------- d-----w- c:\arquivos de programas\Webzen . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-13 05:07 . 2009-10-18 20:35 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\TEMP 2009-12-12 22:19 . 2009-09-06 22:27 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Tibia 2009-12-11 13:49 . 2009-09-06 22:26 -------- d-----w- c:\arquivos de programas\Tibia 2009-12-09 23:24 . 2009-10-18 20:34 -------- d-----w- c:\arquivos de programas\ElfBot NG 2009-12-08 22:56 . 2009-09-07 04:33 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center 2009-12-02 19:14 . 2009-09-05 22:28 -------- d-----w- c:\arquivos de programas\microsoft frontpage 2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Media Player Classic 2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack 2009-11-29 16:05 . 2009-09-11 23:43 -------- d-----w- c:\arquivos de programas\Teamspeak2_RC2 2009-11-24 23:54 . 2009-09-07 00:38 1280480 ----a-w- c:\windows\system32\aswBoot.exe 2009-11-24 23:51 . 2009-09-07 00:38 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys 2009-11-24 23:50 . 2009-09-07 00:38 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2009-11-24 23:50 . 2009-09-07 00:38 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-11-24 23:50 . 2009-09-07 00:38 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-11-24 23:49 . 2009-09-07 00:38 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-11-24 23:48 . 2009-09-07 00:38 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-11-24 23:47 . 2009-09-07 00:38 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2009-11-24 23:47 . 2009-09-07 00:38 97480 ----a-w- c:\windows\system32\AvastSS.scr 2009-11-16 20:58 . 2009-09-07 00:30 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-11-15 22:57 . 2009-09-05 22:36 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information 2009-11-09 19:29 . 2009-11-09 19:27 -------- d-----w- c:\arquivos de programas\Tibia852 2009-11-09 18:00 . 2009-11-29 20:50 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2009-11-08 22:21 . 2009-11-08 22:10 -------- d-----w- c:\arquivos de programas\No-IP 2009-11-02 13:49 . 2009-11-02 13:49 -------- d-----w- c:\arquivos de programas\Asprate 2009-10-31 22:20 . 2009-09-10 23:36 -------- d-----w- c:\arquivos de programas\TibiaTestserver 2009-10-18 13:34 . 2003-03-30 14:06 76196 ----a-w- c:\windows\system32\perfc016.dat 2009-10-18 13:34 . 2003-03-30 14:06 465632 ----a-w- c:\windows\system32\perfh016.dat 2009-10-06 23:56 . 2009-10-04 01:51 415526 ----a-w- c:\arquivos de programas\backgroung.bmp 2009-09-07 00:30 . 2009-09-07 00:30 8 --sh--r- c:\windows\system32\EBE27D3236.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840] "MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-21 13680640] "COMODO Internet Security"="c:\arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" [2009-12-12 1800464] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\guard32.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-10-15 04:04 39792 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2008-06-19 08:20 57344 ----a-r- c:\windows\ALCMTR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader] 2007-08-17 14:50 483144 ----a-w- c:\arquivos de programas\Corel\Corel MediaOne\Corel Photo Downloader.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2004-08-04 03:45 15360 ------w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2004-08-04 03:56 1667584 ------w- c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2009-01-21 16:08 13680640 ----a-w- c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2009-01-21 16:08 86016 ----a-w- c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] 2009-01-21 16:08 1657376 ----a-w- c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2008-11-17 08:08 17676288 ----a-r- c:\windows\RTHDCPL.EXE [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Tibia\\Tibia.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"= "c:\\Arquivos de programas\\Valve\\hl.exe"= "c:\\Arquivos de programas\\Tibia852\\Tibia.exe"= "c:\\Arquivos de programas\\Tibia850\\Tibia.exe"= "c:\\Arquivos de programas\\Tibia\\Tibia2.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/9/2009 22:38 114768] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [12/12/2009 20:33 133064] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/12/2009 20:33 25160] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/9/2009 22:38 20560] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?] S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?] . ------- Scan Suplementar ------- . uStart Page = hxxp://www.terra.com.br/portal/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=2&q= FF - component: c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\extensions\{41fe951c-2aaf-4f08-ab67-aebd1ed636f2}\components\FFExternalAlert.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . - - - - ORFÃOS REMOVIDOS - - - - AddRemove-ms32 - c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\iexplorer.pif ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-13 03:13 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'explorer.exe'(4040) c:\windows\system32\msi.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe c:\arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe c:\arquivos de programas\Alwil Software\Avast4\ashServ.exe c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\PSIService.exe c:\arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe c:\arquivos de programas\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Tempo para conclusão: 2009-12-13 03:16:08 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-12-13 05:16 Pré-execução: 10 pasta(s) 376.206.114.816 bytes disponíveis Pós execução: 12 pasta(s) 376.184.508.416 bytes disponíveis - - End Of File - - 64CDB4A10B1209AD4C3882833B1EE3B6 E aqui do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 03:18:43, on 13/12/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe -- End of file - 4927 bytes Obrigado desde já! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 13, 2009 Bom Dia! mukarillo <!> Você possui 2 antivírus: Comodo e Avast <!> Faça a opção por um deles e,se escolher o Comodo,desinstale o Spybot. <!> Ps: Caso desinstale o Comodo,faça-o em Modo de Segurança. <><><><><><><><><><><> <@> Desinstale o Malwarebytes. <@> Dê um duplo-clique no arquivo em destaque: <!> C:\Arquivos de programas\Malwarebytes' Anti-Malware\unins000.exe <-- <@> Reinicie o computador,após a conclusão! <><><><><><><><><><><> <@> Selecione e copie,todo o conteúdo que está na área do Quote,para o Bloco de Notas. <@> Salve-o,no desktop,com o nome: CFScript.txt File::c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys c:\windows\system32\EBE27D3236.sys Driver:: "npggsvc" "EBE27D3236" Folder:: c:\arquivos de programas\Arquivos comuns\Symantec Shared C:\LinhaDefensiva <@> Ps: Não utilizem este script em outra máquina! <@> Arraste,o CFScript.txt para o ícone/interior do ComboFix. <@> Veja a demonstração! <@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix. <@> Ps: Faça o arraste,até surgir essa solicitação! ( janela ) <@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
mukarillo 0 Denunciar post Postado Dezembro 13, 2009 Aqui vai do Combo ComboFix 09-12-11.05 - Lopes 13/12/2009 13:13:55.2.4 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.2559.2066 [GMT -2:00] Executando de: c:\documents and settings\Lopes\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Lopes\Desktop\CFScript.txt AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} FILE :: "c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys" "c:\windows\system32\EBE27D3236.sys" . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\arquivos de programas\Arquivos comuns\Symantec Shared c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Office\Recent\date\unlock\index\Browser\ms32.sys C:\LinhaDefensiva c:\linhadefensiva\banker.bat c:\linhadefensiva\BankerFix.vbs c:\linhadefensiva\credits\exec.txt c:\linhadefensiva\exec\download.exe c:\linhadefensiva\exec\md5.exe c:\linhadefensiva\exec\MoveEx.exe c:\linhadefensiva\exec\pv.exe c:\linhadefensiva\exec\unzip.exe c:\linhadefensiva\func\lang.vbs c:\linhadefensiva\func\reg.vbs c:\linhadefensiva\func\scan.vbs c:\linhadefensiva\func\strings.vbs c:\linhadefensiva\Iniciar-BankerFix.vbs c:\linhadefensiva\lang\bat\antivirusnote.txt c:\linhadefensiva\lang\bat\changepass.txt c:\linhadefensiva\lang\bat\error-removing.txt c:\linhadefensiva\lang\bat\filesremoved.txt c:\linhadefensiva\lang\bat\logend.txt c:\linhadefensiva\lang\bat\logremhelp.txt c:\linhadefensiva\lang\bat\logremtif.txt c:\linhadefensiva\lang\bat\noproblems.txt c:\linhadefensiva\lang\bat\opening.txt c:\linhadefensiva\lang\bat\rebootrequired.txt c:\linhadefensiva\lang\bat\seeforum.txt c:\linhadefensiva\lang\bat\wait.txt c:\linhadefensiva\lang\bat\win95.txt c:\linhadefensiva\lang\init\en.txt c:\linhadefensiva\lang\init\ptb.txt c:\linhadefensiva\lang\vb\bankerfix.txt c:\linhadefensiva\lang\vb\loader.txt c:\linhadefensiva\lang\vb\postreboot.txt c:\linhadefensiva\leiame.txt c:\linhadefensiva\QUA\backup.reg c:\linhadefensiva\readme.txt c:\linhadefensiva\reflist\fx.reg c:\linhadefensiva\reflist\ref-allu c:\linhadefensiva\reflist\ref-appdata c:\linhadefensiva\reflist\ref-commonfiles c:\linhadefensiva\reflist\ref-hosts c:\linhadefensiva\reflist\ref-md5 c:\linhadefensiva\reflist\ref-mydoc c:\linhadefensiva\reflist\ref-profile c:\linhadefensiva\reflist\ref-programfiles c:\linhadefensiva\reflist\ref-reg c:\linhadefensiva\reflist\ref-start c:\linhadefensiva\reflist\ref-startup c:\linhadefensiva\reflist\ref-sysdrive c:\linhadefensiva\reflist\ref-system c:\linhadefensiva\reflist\ref-system32 c:\linhadefensiva\reflist\ref-tasks c:\linhadefensiva\reflist\ref-temp c:\linhadefensiva\reflist\ref-wincommon c:\linhadefensiva\reflist\ref-windows c:\linhadefensiva\reflist\reft-startup c:\linhadefensiva\reflist\reg-proxy c:\linhadefensiva\relatorio.txt c:\linhadefensiva\relatorios\2009-12-12.txt c:\linhadefensiva\relatorios\errorlog.txt c:\linhadefensiva\rotinas\arquiva-relatorio.vbs c:\linhadefensiva\rotinas\postreboot.bat c:\linhadefensiva\rotinas\postreboot.vbs c:\linhadefensiva\rotinas\remocao\driver.vbs c:\linhadefensiva\rotinas\remocao\shell.vbs c:\linhadefensiva\rotinas\remocao\userinit.vbs c:\linhadefensiva\rotinas\remocao\winlogon.vbs c:\linhadefensiva\rotinas\update.vbs c:\linhadefensiva\VERSION c:\windows\system32\EBE27D3236.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_npggsvc (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-13 to 2009-12-13 )))))))))))))))))))))))))))) . 2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Malwarebytes 2009-12-13 00:07 . 2009-12-13 00:07 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Malwarebytes 2009-12-12 23:05 . 2009-12-13 04:53 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat 2009-12-12 22:33 . 2009-12-12 23:05 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Comodo 2009-12-12 22:33 . 2009-12-12 22:33 87104 ----a-w- c:\windows\system32\drivers\inspect.sys 2009-12-12 22:33 . 2009-12-12 22:33 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys 2009-12-12 22:33 . 2009-12-12 22:33 171552 ----a-w- c:\windows\system32\guard32.dll 2009-12-12 22:33 . 2009-12-12 22:33 133064 ----a-w- c:\windows\system32\drivers\cmdguard.sys 2009-12-12 22:33 . 2009-12-12 22:33 -------- d-----w- c:\arquivos de programas\COMODO 2009-12-12 21:36 . 2009-12-13 15:08 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy 2009-12-12 21:36 . 2009-12-13 15:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy 2009-12-12 21:30 . 2009-12-12 21:30 -------- d-----w- c:\arquivos de programas\CCleaner 2009-12-12 21:05 . 2009-12-12 21:07 707329 ----a-w- C:\Wanasah.exe 2009-12-12 00:37 . 2009-12-12 00:37 53248 ----a-w- c:\windows\fullscreen.exe 2009-12-06 17:33 . 2009-12-06 17:33 -------- d-----w- c:\arquivos de programas\ElfBot NG852 2009-12-05 23:56 . 2009-12-05 23:56 -------- d-----w- c:\windows\system32\LogFiles 2009-12-04 11:31 . 2009-12-04 12:16 -------- d-----w- c:\arquivos de programas\tibiacast2 2009-12-04 11:26 . 2009-11-06 14:49 551936 ----a-w- c:\arquivos de programas\Tibiacast Installer.msi 2009-12-04 11:26 . 2009-12-04 11:23 507461 ----a-w- c:\arquivos de programas\tibiacast_2_6_1.zip 2009-12-03 03:08 . 2009-08-19 07:18 107864 ----a-w- c:\windows\system32\tsccvid.dll 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\windows\system32\QuickTime 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\QuickTime 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\Arquivos comuns\TechSmith Shared 2009-12-03 03:08 . 2009-12-03 03:08 -------- d-----w- c:\arquivos de programas\TechSmith 2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Publish Providers 2009-12-03 03:00 . 2009-12-03 03:00 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Sony 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Vstplugins 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Sony 2009-12-03 02:54 . 2009-12-03 02:54 -------- d-----w- c:\arquivos de programas\Sony 2009-12-03 02:53 . 2009-12-03 02:53 -------- d-----w- c:\arquivos de programas\Sony Setup 2009-12-02 20:54 . 2008-07-08 17:29 1654869 ----a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\DynuEncrypt.dll 2009-12-02 19:30 . 2009-12-02 19:30 -------- d-----w- C:\Level Up! Games 2009-12-02 19:21 . 2009-12-02 19:21 -------- d-----w- C:\TopGames37 2009-12-02 19:18 . 2009-12-02 19:18 -------- d-----w- c:\arquivos de programas\Arquivos comuns\SWF Studio 2009-11-28 13:20 . 2009-11-28 13:21 -------- d-----w- c:\arquivos de programas\TibiaCam TV Lite 2009-11-27 16:07 . 2009-11-27 16:07 -------- d-----w- c:\arquivos de programas\Tibia850 2009-11-26 01:43 . 2009-11-26 01:43 -------- d-----w- c:\arquivos de programas\Gravity 2009-11-26 00:53 . 2009-02-09 05:10 67208 ----a-w- c:\windows\UnDeploy.exe 2009-11-26 00:49 . 2009-11-26 00:50 -------- d-----w- c:\windows\system32\NtmsData 2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Norton 2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Symantec 2009-11-24 22:53 . 2009-12-12 21:45 -------- d-----w- c:\arquivos de programas\NortonInstaller 2009-11-24 22:53 . 2009-11-24 22:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\NortonInstaller 2009-11-24 19:51 . 2009-11-24 19:51 -------- d-----w- c:\windows\system32\Adobe 2009-11-23 22:34 . 2009-11-23 22:34 -------- d-----w- c:\arquivos de programas\Windows Journal Viewer 2009-11-18 00:43 . 2009-11-18 00:43 190464 ----a-w- c:\windows\system32\delzip179.dll 2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Eng.dll 2009-11-15 22:57 . 2009-09-23 19:42 53616 ----a-w- c:\windows\system32\CMStarter_Kor.dll 2009-11-15 22:57 . 2009-09-23 19:42 364912 ----a-w- c:\windows\system32\CMStarterCore.exe 2009-11-15 22:54 . 2009-11-15 22:57 -------- d-----w- c:\arquivos de programas\Webzen . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-13 05:07 . 2009-10-18 20:35 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\TEMP 2009-12-12 22:19 . 2009-09-06 22:27 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Tibia 2009-12-11 13:49 . 2009-09-06 22:26 -------- d-----w- c:\arquivos de programas\Tibia 2009-12-09 23:24 . 2009-10-18 20:34 -------- d-----w- c:\arquivos de programas\ElfBot NG 2009-12-08 22:56 . 2009-09-07 04:33 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center 2009-12-02 19:14 . 2009-09-05 22:28 -------- d-----w- c:\arquivos de programas\microsoft frontpage 2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\documents and settings\Lopes\Dados de aplicativos\Media Player Classic 2009-11-29 20:50 . 2009-11-29 20:50 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack 2009-11-29 16:05 . 2009-09-11 23:43 -------- d-----w- c:\arquivos de programas\Teamspeak2_RC2 2009-11-16 20:58 . 2009-09-07 00:30 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-11-15 22:57 . 2009-09-05 22:36 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information 2009-11-09 19:29 . 2009-11-09 19:27 -------- d-----w- c:\arquivos de programas\Tibia852 2009-11-09 18:00 . 2009-11-29 20:50 85504 ----a-w- c:\windows\system32\ff_vfw.dll 2009-11-08 22:21 . 2009-11-08 22:10 -------- d-----w- c:\arquivos de programas\No-IP 2009-11-02 13:49 . 2009-11-02 13:49 -------- d-----w- c:\arquivos de programas\Asprate 2009-10-31 22:20 . 2009-09-10 23:36 -------- d-----w- c:\arquivos de programas\TibiaTestserver 2009-10-18 13:34 . 2003-03-30 14:06 76196 ----a-w- c:\windows\system32\perfc016.dat 2009-10-18 13:34 . 2003-03-30 14:06 465632 ----a-w- c:\windows\system32\perfh016.dat 2009-10-06 23:56 . 2009-10-04 01:51 415526 ----a-w- c:\arquivos de programas\backgroung.bmp . ((((((((((((((((((((((((((((( SnapShot@2009-12-13_05.13.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-12-13 15:06 . 2009-12-13 15:06 262144 c:\windows\system32\config\systemprofile\NtUser.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840] "MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-21 13680640] "COMODO Internet Security"="c:\arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" [2009-12-12 1800464] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\guard32.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-10-15 04:04 39792 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2008-06-19 08:20 57344 ----a-r- c:\windows\ALCMTR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader] 2007-08-17 14:50 483144 ----a-w- c:\arquivos de programas\Corel\Corel MediaOne\Corel Photo Downloader.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] 2004-08-04 03:45 15360 ------w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2004-08-04 03:56 1667584 ------w- c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2009-01-21 16:08 13680640 ----a-w- c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2009-01-21 16:08 86016 ----a-w- c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] 2009-01-21 16:08 1657376 ----a-w- c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2008-11-17 08:08 17676288 ----a-r- c:\windows\RTHDCPL.EXE [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Tibia\\Tibia.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"= "c:\\Arquivos de programas\\Valve\\hl.exe"= "c:\\Arquivos de programas\\Tibia852\\Tibia.exe"= "c:\\Arquivos de programas\\Tibia850\\Tibia.exe"= "c:\\Arquivos de programas\\Tibia\\Tibia2.exe"= R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [12/12/2009 20:33 133064] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/12/2009 20:33 25160] S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?] . ------- Scan Suplementar ------- . uStart Page = hxxp://www.terra.com.br/portal/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2381354&SearchSource=2&q= FF - component: c:\documents and settings\Lopes\Dados de aplicativos\Mozilla\Firefox\Profiles\3sjfn7b9.default\extensions\{41fe951c-2aaf-4f08-ab67-aebd1ed636f2}\components\FFExternalAlert.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\arquivos de programas\WEBZEN\WebzenGameStarter\NPGameWebStarter.dll ---- FIREFOX POLICIES ---- c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-13 13:17 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'explorer.exe'(3000) c:\windows\system32\msi.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\PSIService.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Tempo para conclusão: 2009-12-13 13:20:04 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-12-13 15:20 ComboFix2.txt 2009-12-13 05:16 Pré-execução: 11 pasta(s) 376.268.128.256 bytes disponíveis Pós execução: 11 pasta(s) 376.163.098.624 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer - - End Of File - - 2AB738EDD85BB60880F3C30BB8844A6B E aqui do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:20:29, on 13/12/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PSIService.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Documents and Settings\Lopes\Meus documentos\Downloads\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.terra.com.br/portal/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe -- End of file - 3605 bytes Obrigado! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 13, 2009 Boa Tarde! mukarillo <!> Seus logs não apresentam entradas ruins. :natal_smile: <><><><><><><><><><><> <@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /uninstall --> Clique OK. < > <@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança ) <@> Clique em Executar --> Aguarde! <@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. <@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! <@> Ou,vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\combofix" /uninstall <@> Clique OK. <><><><><><><><><><><> <@> Faça um escaneamento,online,em: < Eset Nod32 > <@> Utilize o navegador Internet Explorer. <@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar. <@> Marque a caixa: "YES, I accept the Terms of Use" --> Start. <@> Aceite a instalação do ActiveX e,ao terminar,salve e poste o relatório. ( C:\Arquivos de programas\EsetOnlineScanner\log ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
mukarillo 0 Denunciar post Postado Dezembro 14, 2009 Prontinho, o log do Eset ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=8a6647a594a37547b073c1f8cc2c43bd # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-12-14 03:33:12 # local_time=2009-12-14 01:33:12 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=768 16777215 100 0 8435761 8435761 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=3073 16777189 80 89 0 58868 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=97626 # found=3 # cleaned=3 # scan_time=2444 C:\Wanasah.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Spybot - Search & Destroy\Recovery\Virtumonde1.zip Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{584F9A72-8980-4029-9F43-668B28870040}\RP67\A0029078.exe probably a variant of Win32/Agent trojan (deleted - quarantined) 00000000000000000000000000000000 C Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Dezembro 14, 2009 Boa Tarde! mukarillo <@> Baixe: < TFC > ( by Old Timer ) <!> Link - 2 < http://www.geekstogo.com/forum/TFC-Temp-File-Cleaner-OldTimer-file187.html > <@> Salve-o no desktop! <@> Feche todos os programas! ( Internet,navegador,etc... ) <@> Execute TFC.exe,com um duplo-clique. <@> Ps: Para Windows Vista --> Clique direito --> Escolha: Executar como Administrador <@> Clique em Start --> Aguarde! <@> Terminando,reinicie o computador...caso a ferramenta não o solicite e dê início ao processo. ( reboot ) °°°°°°°°°°°°°°°°°°°°°°°°° °°°°°°°°°°°°°°°°°°°°°°°°° <@> Não havendo problemas,estabeleça um ponto limpo na Restauração do Sistema. <@> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema. <@> Marque: Desativar Restauração do Sistema --> Aplicar --> Aguarde! --> Ok. <@> Depois,desmarque novamente! --> Aplicar --> Aguarde! --> Ok. <@> Para maiores detalhes,leia o Tutorial: < Link > °°°°°°°°°°°°°°°°°°°°°°°°° °°°°°°°°°°°°°°°°°°°°°°°°° <!> Seus logs estão limpos! :natal_smile: <!> Tudo Ok? Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Janeiro 15, 2010 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites