Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Fábio Mesquita

[Resolvido!] [Resolvido!] Análise de Log

Recommended Posts

Bom dia pessoal,

 

Segue um log para análise. Trata-se do servidor aqui da empresa e gostaria de verificar se temos algum problema.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 09:11:12, on 12/03/2010

Platform: Windows 2003 SP2 (WinNT 5.02.3790)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal

 

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\system32\spoolsv.exe

D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

D:\WINDOWS\system32\Dfssvc.exe

D:\WINDOWS\System32\dns.exe

D:\WINDOWS\System32\svchost.exe

D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

D:\WINDOWS\system32\inetsrv\inetinfo.exe

D:\WINDOWS\System32\ismserv.exe

D:\Arquivos de programas\Java\jre6\bin\jqs.exe

D:\ARQUIV~1\EASYPH~1\MySql\bin\mysqld.exe

D:\Arquivos de programas\No-IP\DUC20.exe

D:\WINDOWS\system32\ntfrs.exe

D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

C:\Proxyplus\ProxyPlus.exe

d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe

D:\WINDOWS\system32\tcpsvcs.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

D:\WINDOWS\System32\svchost.exe

d:\windows\system32\inetsrv\w3wp.exe

d:\windows\system32\inetsrv\w3wp.exe

D:\WINDOWS\Explorer.EXE

D:\WINDOWS\AhnRpta.exe

D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe

D:\Arquivos de programas\EasyPHP1-7\easyphp.exe

D:\Arquivos de programas\Java\jre6\bin\jusched.exe

D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

D:\WINDOWS\system32\ctfmon.exe

C:\Digistar\MesaPC\MesaPC.exe

D:\WINDOWS\system32\wuauclt.exe

D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = res://shdoclc.dll/softAdmin.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.1.1:4480;https=192.168.1.1:4480;ftp=192.168.1.1:4480;gopher=192.168.1.1:4480;socks=192.168.1.1:1080

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [ibersoft IB Backup] D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe

O4 - HKLM\..\Run: [EasyPHP] "D:\Arquivos de programas\EasyPHP1-7\easyphp.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "D:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVP] "D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe"

O4 - HKLM\..\RunOnce: [NoIE4StubProcessing] D:\WINDOWS\system32\reg.exe DELETE "HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" /v "NoIE4StubProcessing" /f

O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [cdoosoft] D:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\5\herss.exe

O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] D:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p

O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVIÇO DE REDE')

O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O14 - IERESET.INF: START_PAGE_URL=http:\\athaserver\workforce

O15 - ESC Trusted Zone: http://digistar2.locaweb.com.br

O15 - ESC Trusted Zone: http://ufpr.dl.sourceforge.net

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266575582546

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O17 - HKLM\Software\..\Telephony: DomainName = intranet.athalaia.com.br

O17 - HKLM\System\CCS\Services\Tcpip\..\{2788FC13-9A42-49E1-889F-1DECAD2E2EA7}: NameServer = 192.168.1.1,10.1.1.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{50AB2C0F-106A-4A56-B1D0-567CC8F5E821}: NameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{F73743B8-D6D2-4182-A56F-80FFAD52100D}: NameServer = 201.10.120.2,201.10.128.2

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O23 - Service: Apache - Unknown owner - D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: MySQL - Unknown owner - D:\ARQUIV~1\EASYPH~1\MySql\bin\mysqld.exe

O23 - Service: NoIPDUCService - Vitalwerks LLC - D:\Arquivos de programas\No-IP\DUC20.exe

O23 - Service: Fortech Proxy+ (ProxyPlus) - FORTECH Ltd. - C:\Proxyplus\ProxyPlus.exe

 

--

End of file - 7164 bytes

 

Grato pela ajuda!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde....

 

 

*Baixe o MalwareBytes Anti-malware e salve-o no desktop:

*Instale o programa

*Se alguma atualização existir,o download será automático. Aguarde...

*O programa será aberto automaticamente.

*Na aba [Verificação], selecione a opção [Verificação completa]

*Clique em [Verificar] e selecione as unidades (C:\ e D:\) a serem examinadas

*Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados]

*Selecione todos os resultados e clique em [Remover Selecionados]

*Um relatório (mbam-log-ano-mês-data.txt) será apresentado.

*Cole-o na sua próxima resposta

Compartilhar este post


Link para o post
Compartilhar em outros sites

Wings, segue o log:

 

Malwarebytes' Anti-Malware 1.44

Versão do banco de dados: 3869

Windows 5.2.3790 Service Pack 2

Internet Explorer 8.0.6001.18702

 

15/03/2010 10:56:21

mbam-log-2010-03-15 (10-56-21).txt

 

Tipo de Verificação: Completa (C:\|D:\|F:\|)

Objetos verificados: 574655

Tempo decorrido: 1 hour(s), 29 minute(s), 0 second(s)

 

Processos da Memória infectados: 1

Módulos de Memória Infectados: 1

Chaves do Registro infectadas: 3

Valores do Registro infectados: 2

Ítens do Registro infectados: 5

Pastas infectadas: 0

Arquivos infectados: 53

 

Processos da Memória infectados:

D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

D:\WINDOWS\system32\ahndoor0.dll (Spyware.OnlineGames) -> Delete on reboot.

 

Chaves do Registro infectadas:

HKEY_CLASSES_ROOT\CLSID\{bd344af4-67ab-4e19-a630-7435587d320b} (Spyware.OnlineGames) -> Delete on reboot.

HKEY_CLASSES_ROOT\CLSID\NOD32KVBIT (Trojan.Frethog) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\MADOWN (Worm.Magania) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bd344af4-67ab-4e19-a630-7435587d320b} (Spyware.OnlineGames) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Spyware.OnlineGames) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\control panel\ConnectionsTab (Hijack.ConnectionControl) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn (Hijack.Desktop) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

D:\WINDOWS\system32\ahndoor0.dll (Spyware.OnlineGames) -> Delete on reboot.

C:\1di1w.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\2sm66r.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\62.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\6ruaqx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\9d6tpg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\9g86.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\a2g21.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\anoataly.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\l61yyp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\mbdm.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\mbvd.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\pcxis.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\s1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\vb0hsoay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\vlvtdflx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\wu1n.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

C:\cs6phv6d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\1di1w.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\2sm66r.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\62.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\6ruaqx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\9d6tpg.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\9g86.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\a2g21.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\anoataly.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\cs6phv6d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\l61yyp.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\mbdm.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\mbvd.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\pcxis.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\q3kku.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\s1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\vb0hsoay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\vlvtdflx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\wu1n.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\Documents and Settings\Administrador\Configurações locais\Temp\cvasds2.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\Documents and Settings\Administrador\Configurações locais\Temp\cvasds3.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.

F:\cs6phv6d.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

F:\62.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

F:\s1.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

F:\pcxis.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

F:\bkpathafiles\programas\Adobe Acrobat 8 Professional with keygen\Crack\keygen.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

F:\bkpathafiles\programas\ADOBE CS3 PC\Crack\XF-AdobeMasterCS3-KG.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.

F:\bkpathafiles\programas\ADOBE CS4 PC\Crack\adobe-master-cs4-keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

F:\BACK_UP_DELL_RAID\raid\PROGRAMAS\Adobe CS3_PC\Adobe CS3\keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.

F:\BACK_UP_DELL_RAID\raid\PROGRAMAS\Adobe CS3_PC\adobe cs3 novo\Crack\XF-AdobeMasterCS3-KG.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.

D:\0qw6vege.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\nds0q.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\mje12tni.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\Documents and Settings\Administrador\Configurações locais\Temp\cvasds1.dll (Spyware.OnlineGames) -> Delete on reboot.

D:\Documents and Settings\Administrador\Configurações locais\Temp\herss.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.

D:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.

 

 

uma dúvida, estes procedimentos podem ser realizados remotamente?

 

Obrigado!

 

Fábio Mesquita

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue o log:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:11:49, on 15/03/2010

Platform: Windows 2003 SP2 (WinNT 5.02.3790)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal

 

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\system32\spoolsv.exe

D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

D:\WINDOWS\system32\Dfssvc.exe

D:\WINDOWS\System32\dns.exe

D:\WINDOWS\System32\svchost.exe

D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

D:\WINDOWS\system32\inetsrv\inetinfo.exe

D:\WINDOWS\System32\ismserv.exe

D:\Arquivos de programas\Java\jre6\bin\jqs.exe

D:\ARQUIV~1\EASYPH~1\MySql\bin\mysqld.exe

D:\Arquivos de programas\No-IP\DUC20.exe

D:\WINDOWS\system32\ntfrs.exe

C:\Proxyplus\ProxyPlus.exe

d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe

D:\WINDOWS\system32\tcpsvcs.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

D:\WINDOWS\System32\svchost.exe

d:\windows\system32\inetsrv\w3wp.exe

d:\windows\system32\inetsrv\w3wp.exe

D:\WINDOWS\system32\userinit.exe

D:\WINDOWS\Explorer.EXE

D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe

D:\Arquivos de programas\EasyPHP1-7\easyphp.exe

D:\Arquivos de programas\Java\jre6\bin\jusched.exe

D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

D:\WINDOWS\system32\ctfmon.exe

D:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.1.1:4480;https=192.168.1.1:4480;ftp=192.168.1.1:4480;gopher=192.168.1.1:4480;socks=192.168.1.1:1080

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [ibersoft IB Backup] D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe

O4 - HKLM\..\Run: [EasyPHP] "D:\Arquivos de programas\EasyPHP1-7\easyphp.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "D:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVP] "D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe"

O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVIÇO DE REDE')

O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O14 - IERESET.INF: START_PAGE_URL=http:\\athaserver\workforce

O15 - ESC Trusted Zone: http://digistar2.locaweb.com.br

O15 - ESC Trusted Zone: http://ufpr.dl.sourceforge.net

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266575582546

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O17 - HKLM\Software\..\Telephony: DomainName = intranet.athalaia.com.br

O17 - HKLM\System\CCS\Services\Tcpip\..\{2788FC13-9A42-49E1-889F-1DECAD2E2EA7}: NameServer = 192.168.1.1,10.1.1.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{50AB2C0F-106A-4A56-B1D0-567CC8F5E821}: NameServer = 192.168.1.1

O17 - HKLM\System\CCS\Services\Tcpip\..\{F73743B8-D6D2-4182-A56F-80FFAD52100D}: NameServer = 201.10.120.2,201.10.128.2

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O23 - Service: Apache - Unknown owner - D:\ARQUIV~1\EASYPH~1\Apache\apache.exe

O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: MySQL - Unknown owner - D:\ARQUIV~1\EASYPH~1\MySql\bin\mysqld.exe

O23 - Service: NoIPDUCService - Vitalwerks LLC - D:\Arquivos de programas\No-IP\DUC20.exe

O23 - Service: Fortech Proxy+ (ProxyPlus) - FORTECH Ltd. - C:\Proxyplus\ProxyPlus.exe

 

--

End of file - 6631 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Remover tudo]

*Clique na aba [Logs], selecione o relatório e clique em [Remover]

 

2.

*Baixe o OTL e salve-o no desktop

http://oldtimer.geekstogo.com/OTL.exe

*Duplo clique em OTL.exe

*Selecione as opções abaixo:

 

[x] Scan All Users

[x[ Minimal Output

[x] Use Company Name WhiteList

[x] Skip Microsoft Files

[x] LOP Check

[x] Purity Check

*Clique em [Run Scan] e aguarde o término do processo

*Dois relatórios serão criados no desktop chamados: OTL.txt e Extras.txt

*Cole o relatório OTL.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

OTL logfile created on: 15/03/2010 15:31:34 - Run 1

OTL by OldTimer - Version 3.1.37.1 Folder = D:\Documents and Settings\Administrador\Desktop

Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTDomainController

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

1.022,00 Mb Total Physical Memory | 395,00 Mb Available Physical Memory | 39,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 76,00% Paging File free

Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]

 

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Arquivos de programas

Drive C: | 97,66 Gb Total Space | 1,75 Gb Free Space | 1,80% Space Free | Partition Type: NTFS

Drive D: | 16,82 Gb Total Space | 2,41 Gb Free Space | 14,31% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ATHASERVER

Current User Name: Administrador

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - D:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools)

PRC - D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

PRC - D:\Arquivos de programas\Update Services\service\bin\wsusservice.exe (Microsoft Corporation)

PRC - D:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

PRC - D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

PRC - d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)

PRC - d:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\dns.exe (Microsoft Corporation)

PRC - C:\Digistar\MesaPC\MesaPC.exe (Digistar Telecom)

PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\pop3server\pop3svc.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\inetsrv\w3wp.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\ismserv.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\dfssvc.exe (Microsoft Corporation)

PRC - C:\Proxyplus\ProxyPlus.exe (FORTECH Ltd.)

PRC - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)

PRC - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)

PRC - D:\Arquivos de programas\EasyPHP1-7\mysql\bin\mysqld.exe ()

PRC - D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe ()

PRC - D:\Arquivos de programas\EasyPHP1-7\easyphp.exe (EasyPHP)

PRC - D:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)

PRC - D:\Arquivos de programas\EasyPHP1-7\apache\apache.exe ()

 

 

========== Modules (SafeList) ==========

 

MOD - D:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools)

MOD - D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (AVP) -- D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

SRV - (WsusService) -- D:\Arquivos de programas\Update Services\Service\bin\WsusService.exe (Microsoft Corporation)

SRV - (WSusCertServer) -- D:\Arquivos de programas\Update Services\Service\bin\WsusCertServer.exe (Microsoft Corporation)

SRV - (NoIPDUCService) -- D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

SRV - (SQLWriter) -- d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)

SRV - (MSSQL$MICROSOFT##SSEE) Windows Internal Database (MICROSOFT##SSEE) -- d:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

SRV - (DNS) -- D:\WINDOWS\system32\dns.exe (Microsoft Corporation)

SRV - (LicenseService) -- D:\WINDOWS\system32\llssrv.exe (Microsoft Corporation)

SRV - (NtFrs) -- D:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)

SRV - (RSoPProv) -- D:\WINDOWS\system32\rsopprov.exe (Microsoft Corporation)

SRV - (Pop3Svc) -- D:\WINDOWS\system32\pop3server\pop3svc.exe (Microsoft Corporation)

SRV - (Tssdis) -- D:\WINDOWS\system32\tssdis.exe (Microsoft Corporation)

SRV - (W3SVC) -- D:\WINDOWS\system32\inetsrv\iisw3adm.dll (Microsoft Corporation)

SRV - (IsmServ) -- D:\WINDOWS\system32\ismserv.exe (Microsoft Corporation)

SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (MSFtpsvc) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (IISADMIN) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (Dfs) -- D:\WINDOWS\system32\dfssvc.exe (Microsoft Corporation)

SRV - (ProxyPlus) -- C:\Proxyplus\ProxyPlus.exe (FORTECH Ltd.)

SRV - (FirebirdServerDefaultInstance) -- D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)

SRV - (FirebirdGuardianDefaultInstance) -- D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)

SRV - (IDriverT) -- D:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (MySQL) -- D:\Arquivos de programas\EasyPHP1-7\mysql\bin\mysqld.exe ()

SRV - (TrkSvr) -- D:\WINDOWS\system32\trksvr.dll (Microsoft Corporation)

SRV - (DHCPServer) -- D:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)

SRV - (sacsvr) -- D:\WINDOWS\system32\sacsvr.dll (Microsoft Corporation)

SRV - (Apache) -- D:\Arquivos de programas\EasyPHP1-7\apache\apache.exe ()

 

 

========== Driver Services (SafeList) ==========

 

DRV - (klif) -- D:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)

DRV - (m4cxw2k3) -- D:\WINDOWS\system32\drivers\m4cxw2k3.sys (D-Link Corporation)

DRV - (WLBS) -- D:\WINDOWS\system32\drivers\wlbs.sys (Microsoft Corporation)

DRV - (AppleTalk) -- D:\WINDOWS\system32\drivers\sfmatalk.sys (Microsoft Corporation)

DRV - (DfsDriver) -- D:\WINDOWS\system32\drivers\Dfs.sys (Microsoft Corporation)

DRV - (ClusDisk) -- D:\WINDOWS\system32\drivers\clusdisk.sys (Microsoft Corporation)

DRV - (aarich) -- D:\WINDOWS\system32\drivers\aarich.sys (Adaptec, Inc.)

DRV - (ati2mpad) -- D:\WINDOWS\system32\drivers\ati2mpad.sys (ATI Technologies Inc.)

DRV - (RTL8169) -- D:\WINDOWS\system32\drivers\RT8169xp.sys (Realtek Semiconductor Corporation )

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.1:4480

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=192.168.1.1:4480;https=192.168.1.1:4480;ftp=192.168.1.1:4480;gopher=192.168.1.1:4480;socks=192.168.1.1:1080

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

 

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Components: D:\Arquivos de programas\Mozilla Firefox\components [2009/07/28 13:09:43 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Plugins: D:\Arquivos de programas\Mozilla Firefox\plugins [2009/07/28 13:09:42 | 000,000,000 | ---D | M]

 

[2008/12/05 09:25:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Extensions

[2010/03/15 09:20:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\cp6twxur.default\extensions

[2010/03/15 09:20:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\cp6twxur.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2010/03/15 09:30:37 | 000,000,000 | ---D | M] -- D:\Arquivos de programas\Mozilla Firefox\extensions

 

O1 HOSTS File: ([2003/04/01 09:00:00 | 000,000,776 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AVP] D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

O4 - HKLM..\Run: [EasyPHP] D:\Arquivos de programas\EasyPHP1-7\easyphp.exe (EasyPHP)

O4 - HKLM..\Run: [ibersoft IB Backup] D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe ()

O4 - HKU\.DEFAULT..\RunOnce: [TSClientMSIUninstaller] D:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\RunOnce: [TSClientMSIUninstaller] D:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - Startup: D:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk = D:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)

O4 - Startup: D:\Documents and Settings\FD\Menu Iniciar\Programas\Inicializar\No-IP DUC.lnk = D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 1

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: Wallpaper = C:\Documentos\desktop.jpg ()

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266575582546 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\klogon: DllName - D:\WINDOWS\system32\klogon.dll - D:\WINDOWS\system32\klogon.dll (Kaspersky Lab)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O24 - Desktop WallPaper: D:\WINDOWS\Web\Wallpaper\Windows Server 2003.bmp

O24 - Desktop BackupWallPaper: D:\WINDOWS\Web\Wallpaper\Windows Server 2003.bmp

O29 - HKLM SecurityProviders - (pwdssp.dll) - D:\WINDOWS\System32\pwdssp.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/01/29 17:45:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2010/03/15 10:56:15 | 000,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010/03/15 10:56:15 | 000,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]

O33 - MountPoints2\{38c8ef35-4af6-11dc-b7da-0008543466fe}\Shell\AutoRun\command - "" = F:\setupSNK.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010/03/15 15:30:25 | 000,555,008 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Administrador\Desktop\OTL.exe

[2010/03/15 09:22:47 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Malwarebytes

[2010/03/15 09:22:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010/03/15 09:22:37 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes

[2010/03/15 09:22:36 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys

[2010/03/15 09:22:36 | 000,000,000 | ---D | C] -- D:\Arquivos de programas\Malwarebytes' Anti-Malware

[2010/03/15 09:21:59 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\Administrador\Desktop\mbam-setup.exe

[2010/03/12 08:33:37 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

[2010/02/19 09:17:59 | 000,000,000 | -H-D | C] -- D:\WINDOWS\ie8

[2010/02/19 07:58:21 | 000,000,000 | ---D | C] -- D:\WINDOWS\SxsCaPendDel

[2010/02/19 07:51:26 | 000,000,000 | -HSD | C] -- D:\Config.Msi

[2008/01/29 12:27:33 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\IMPLODE.DLL

[2007/10/15 10:52:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\ApplicationHistory

[2007/01/31 08:58:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft

[2007/01/31 08:58:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft

[2007/01/31 08:51:24 | 000,000,000 | --SD | M] -- D:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft

[2007/01/31 08:51:24 | 000,000,000 | --SD | M] -- D:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft

[94 D:\WINDOWS\System32\dllcache\*.tmp files -> D:\WINDOWS\System32\dllcache\*.tmp -> ]

[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

[197 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2010/03/15 15:30:40 | 041,083,424 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox.dat

[2010/03/15 15:30:28 | 000,555,008 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Administrador\Desktop\OTL.exe

[2010/03/15 15:30:21 | 000,170,528 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox2.dat

[2010/03/15 12:15:33 | 000,065,536 | ---- | M] () -- D:\WINDOWS\NETLOGON.CHG

[2010/03/15 12:14:28 | 001,094,254 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI

[2010/03/15 12:14:28 | 000,703,550 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat

[2010/03/15 12:14:28 | 000,165,038 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat

[2010/03/15 12:14:28 | 000,106,184 | ---- | M] () -- D:\WINDOWS\System32\perfc016.dat

[2010/03/15 12:14:28 | 000,095,164 | ---- | M] () -- D:\WINDOWS\System32\perfh016.dat

[2010/03/15 12:10:54 | 000,005,958 | RHS- | M] () -- D:\Documents and Settings\Administrador\ntuser.pol

[2010/03/15 12:10:25 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl

[2010/03/15 12:09:42 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT

[2010/03/15 12:09:38 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat

[2010/03/15 12:05:45 | 000,569,252 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox.idx

[2010/03/15 12:05:45 | 000,017,960 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox2.idx

[2010/03/15 12:05:03 | 004,194,304 | -H-- | M] () -- D:\Documents and Settings\Administrador\NTUSER.DAT

[2010/03/15 12:05:03 | 000,000,210 | -HS- | M] () -- D:\Documents and Settings\Administrador\ntuser.ini

[2010/03/15 12:05:02 | 003,366,802 | -H-- | M] () -- D:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\IconCache.db

[2010/03/15 10:56:15 | 000,000,053 | RHS- | M] () -- D:\autorun.inf

[2010/03/15 09:22:41 | 000,000,743 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/03/15 09:22:14 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\Administrador\Desktop\mbam-setup.exe

[2010/03/15 02:02:18 | 000,000,262 | ---- | M] () -- D:\WINDOWS\tasks\BKP Ecalc.job

[2010/03/15 01:32:56 | 000,000,278 | ---- | M] () -- D:\WINDOWS\tasks\Defrag D.job

[2010/03/15 01:00:09 | 000,000,278 | ---- | M] () -- D:\WINDOWS\tasks\Defrag C.job

[2010/03/14 11:38:36 | 000,116,736 | RHS- | M] () -- D:\nhx.exe

[2010/03/12 09:05:49 | 000,004,142 | ---- | M] () -- D:\WINDOWS\imsins.BAK

[2010/03/12 08:33:38 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

[2010/03/08 05:40:05 | 000,127,488 | RHS- | M] () -- D:\2u923g01.exe

[2010/03/04 11:02:07 | 000,114,688 | RHS- | M] () -- D:\fk.exe

[2010/02/19 10:01:38 | 000,012,328 | ---- | M] () -- D:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT

[2010/02/19 08:23:54 | 000,094,272 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT

[94 D:\WINDOWS\System32\dllcache\*.tmp files -> D:\WINDOWS\System32\dllcache\*.tmp -> ]

[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]

[197 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2010/03/15 09:22:41 | 000,000,743 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/03/14 11:38:02 | 000,116,736 | RHS- | C] () -- D:\nhx.exe

[2010/03/06 16:41:20 | 000,127,488 | RHS- | C] () -- D:\2u923g01.exe

[2010/03/04 11:02:43 | 000,114,688 | RHS- | C] () -- D:\fk.exe

[2009/07/28 12:13:30 | 031,526,351 | ---- | C] () -- D:\Arquivos de programas\EasyPHP1-8.zip

[2009/03/03 16:16:10 | 000,010,752 | ---- | C] () -- D:\WINDOWS\System32\KOAZJA_L.DLL

[2008/09/09 11:38:10 | 000,000,028 | ---- | C] () -- D:\Arquivos de programas\log.php

[2008/05/13 14:05:56 | 000,176,128 | ---- | C] () -- D:\WINDOWS\GeoCodecLib.dll

[2008/01/29 12:27:34 | 000,748,160 | ---- | C] () -- D:\WINDOWS\System32\CO2C40EN.DLL

[2008/01/29 12:27:34 | 000,131,072 | ---- | C] () -- D:\WINDOWS\System32\P2SODBC.DLL

[2008/01/29 12:27:34 | 000,054,272 | ---- | C] () -- D:\WINDOWS\System32\P2IRDAO.DLL

[2008/01/29 12:27:34 | 000,050,176 | ---- | C] () -- D:\WINDOWS\System32\P2CTDAO.DLL

[2008/01/29 12:27:34 | 000,036,352 | ---- | C] () -- D:\WINDOWS\System32\P2BBND.DLL

[2008/01/02 13:50:11 | 000,040,656 | ---- | C] () -- D:\WINDOWS\php.ini

[2007/09/17 17:35:28 | 000,049,957 | ---- | C] () -- D:\WINDOWS\php.ini_atual

[2007/09/17 17:35:28 | 000,040,056 | ---- | C] () -- D:\WINDOWS\php.ini___

[2007/09/04 00:56:27 | 000,000,048 | ---- | C] () -- D:\WINDOWS\WinInit.ini

[2007/09/03 23:12:36 | 000,000,386 | ---- | C] () -- D:\WINDOWS\ecalc.ini

[2007/07/05 16:00:46 | 000,039,837 | ---- | C] () -- D:\WINDOWS\php.ini.ZendOptimizer-3.0.2_bak

[2007/07/04 18:43:38 | 000,044,432 | ---- | C] () -- D:\WINDOWS\System32\smtpctrs.ini

[2007/07/04 18:43:38 | 000,002,157 | ---- | C] () -- D:\WINDOWS\System32\ntfsdrct.ini

[2007/05/09 16:58:08 | 000,000,147 | ---- | C] () -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\fusioncache.dat

[2007/04/05 14:06:47 | 000,012,042 | ---- | C] () -- D:\WINDOWS\System32\ftpctrs.ini

[2007/04/03 18:26:59 | 000,000,140 | ---- | C] () -- D:\WINDOWS\ODBC.INI

[2007/02/05 07:58:17 | 000,079,698 | ---- | C] () -- D:\WINDOWS\System32\w3ctrs.ini

[2007/02/05 07:58:17 | 000,016,150 | ---- | C] () -- D:\WINDOWS\System32\axperf.ini

[2007/02/05 07:58:13 | 000,017,849 | ---- | C] () -- D:\WINDOWS\System32\infoctrs.ini

[2007/01/31 09:48:28 | 000,004,664 | ---- | C] () -- D:\WINDOWS\System32\dhcpctrs.ini

[2007/01/31 09:47:56 | 000,023,681 | ---- | C] () -- D:\WINDOWS\System32\dnsperf.ini

[2005/03/24 18:16:10 | 000,179,577 | ---- | C] () -- D:\WINDOWS\System32\schema.ini

[2003/08/29 12:26:36 | 000,002,080 | ---- | C] () -- D:\WINDOWS\my.ini

[2003/04/01 09:00:00 | 000,051,066 | ---- | C] () -- D:\WINDOWS\System32\ntdsctrs.ini

[2003/04/01 09:00:00 | 000,041,489 | ---- | C] () -- D:\WINDOWS\System32\ntfrsrep.ini

[2003/04/01 09:00:00 | 000,023,411 | ---- | C] () -- D:\WINDOWS\System32\iasperf.ini

[2003/04/01 09:00:00 | 000,023,252 | ---- | C] () -- D:\WINDOWS\System32\ipsecprf.ini

[2003/04/01 09:00:00 | 000,010,527 | ---- | C] () -- D:\WINDOWS\System32\ntfrscon.ini

 

========== LOP Check ==========

 

[2007/03/14 08:50:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Genie-soft

[2008/05/09 16:20:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\HK-Software

[2009/09/15 09:09:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Notepad++

[2009/09/15 09:19:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\uTorrent

[2007/03/12 10:25:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\Genie-soft

[2007/10/22 16:18:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\Grisoft

[2008/10/13 16:56:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\LogMeIn

[2007/03/12 10:38:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Backup\Dados de aplicativos\Genie-soft

[2008/04/10 09:10:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\fabiano\Dados de aplicativos\Genie-soft

[2007/12/22 11:14:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\fabiano\Dados de aplicativos\Grisoft

[2007/09/10 18:58:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Easy Thumbnails

[2007/11/12 17:31:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Grisoft

[2008/05/13 15:28:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Notepad++

[2007/12/27 06:50:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\João\Dados de aplicativos\Grisoft

[2008/05/16 17:28:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\João\Dados de aplicativos\Notepad++

[2007/12/27 07:04:13 | 000,000,000 | ---D | M] -- D:\Documents and Settings\roberto\Dados de aplicativos\Grisoft

[2008/09/07 17:53:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\vendas\Dados de aplicativos\Notepad++

[2010/03/15 02:02:18 | 000,000,262 | ---- | M] () -- D:\WINDOWS\Tasks\BKP Ecalc.job

[2010/03/15 01:00:09 | 000,000,278 | ---- | M] () -- D:\WINDOWS\Tasks\Defrag C.job

[2010/03/15 01:32:56 | 000,000,278 | ---- | M] () -- D:\WINDOWS\Tasks\Defrag D.job

[2009/03/24 08:51:41 | 000,000,556 | ---- | M] () -- D:\WINDOWS\Tasks\GBMPro6 Task - BKP_Diario_Athalaia.job

[2010/02/20 00:00:10 | 000,032,514 | ---- | M] () -- D:\WINDOWS\Tasks\SchedLgU.Txt

 

========== Purity Check ==========

 

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Selecione e copie o código abaixo:

 

:Processes

explorer.exe

 

:Files

D:\nhx.exe

D:\2u923g01.exe

D:\fk.exe

 

:Commands

[purity]

[emptytemp]

[start explorer]

[Reboot]

*Duplo clique em OTL

*No espaço abaixo de "Custom Scans/Fixes" cole-o (Ctrl+v)

*Clique em [Run Fix]

*O PC será reiniciado

*Cole o relatório criado em C:\_OTListIt\MovedFiles\MDA_HMS.log.txt, onde MDA é mês/dia/ano e HMS é hora/minuto/segundos

Compartilhar este post


Link para o post
Compartilhar em outros sites

All processes killed

========== PROCESSES ==========

No active process named explorer.exe was found!

========== FILES ==========

D:\nhx.exe moved successfully.

D:\2u923g01.exe moved successfully.

D:\fk.exe moved successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrador

->Temp folder emptied: 120355410 bytes

->Temporary Internet Files folder emptied: 90126123 bytes

->Java cache emptied: 101082300 bytes

->FireFox cache emptied: 102070642 bytes

->Flash cache emptied: 930 bytes

 

User: All Users

 

User: Backup

->Temp folder emptied: 144478 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 10483271 bytes

 

User: fabiano

->Temp folder emptied: 12840 bytes

->Temporary Internet Files folder emptied: 144862 bytes

 

User: FD

->Temp folder emptied: 199 bytes

->Temporary Internet Files folder emptied: 279598 bytes

 

User: fábio

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 121422 bytes

 

User: João

->Temp folder emptied: 6974553 bytes

->Temporary Internet Files folder emptied: 170458 bytes

 

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: luis

->Temp folder emptied: 25214 bytes

->Temporary Internet Files folder emptied: 10594963 bytes

 

User: NetworkService

->Temp folder emptied: 8728 bytes

->Temporary Internet Files folder emptied: 402 bytes

 

User: roberto

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 121422 bytes

 

User: vendas

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 7645068 bytes

->FireFox cache emptied: 5010972 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 1229962 bytes

%systemroot%\System32 .tmp files removed: 136941609 bytes

%systemroot%\System32\dllcache .tmp files removed: 76687056 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 27565388 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 666,00 mb

 

 

OTL by OldTimer - Version 3.1.37.1 log created on 03152010_161144

 

Files\Folders moved on Reboot...

D:\Documents and Settings\Administrador\Configurações locais\Temp\cvasds0.dll moved successfully.

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

OTL logfile created on: 15/03/2010 16:31:09 - Run 2

OTL by OldTimer - Version 3.1.37.1 Folder = D:\Documents and Settings\Administrador\Desktop

Windows Server 2003 Standard Edition Service Pack 2 (Version = 5.2.3790) - Type = NTDomainController

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

1.022,00 Mb Total Physical Memory | 256,00 Mb Available Physical Memory | 25,00% Memory free

2,00 Gb Paging File | 2,00 Gb Available in Paging File | 75,00% Paging File free

Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]

 

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Arquivos de programas

Drive C: | 97,66 Gb Total Space | 1,71 Gb Free Space | 1,75% Space Free | Partition Type: NTFS

Drive D: | 16,82 Gb Total Space | 2,95 Gb Free Space | 17,52% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

Drive F: | 465,65 Gb Total Space | 344,92 Gb Free Space | 74,07% Space Free | Partition Type: FAT32

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: ATHASERVER

Current User Name: Administrador

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - D:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

PRC - D:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools)

PRC - D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

PRC - D:\Arquivos de programas\Update Services\service\bin\wsusservice.exe (Microsoft Corporation)

PRC - D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

PRC - d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)

PRC - d:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\dns.exe (Microsoft Corporation)

PRC - C:\Digistar\MesaPC\MesaPC.exe (Digistar Telecom)

PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\pop3server\pop3svc.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\inetsrv\w3wp.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\ismserv.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

PRC - D:\WINDOWS\system32\dfssvc.exe (Microsoft Corporation)

PRC - C:\Proxyplus\ProxyPlus.exe (FORTECH Ltd.)

PRC - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)

PRC - D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)

PRC - D:\Arquivos de programas\EasyPHP1-7\mysql\bin\mysqld.exe ()

PRC - D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe ()

PRC - D:\Arquivos de programas\EasyPHP1-7\easyphp.exe (EasyPHP)

PRC - D:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)

PRC - D:\Arquivos de programas\EasyPHP1-7\apache\apache.exe ()

 

 

========== Modules (SafeList) ==========

 

MOD - D:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools)

MOD - D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.3790.3959_x-ww_D8713E55\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (AVP) -- D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

SRV - (WsusService) -- D:\Arquivos de programas\Update Services\Service\bin\WsusService.exe (Microsoft Corporation)

SRV - (WSusCertServer) -- D:\Arquivos de programas\Update Services\Service\bin\WsusCertServer.exe (Microsoft Corporation)

SRV - (NoIPDUCService) -- D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

SRV - (SQLWriter) -- d:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)

SRV - (MSSQL$MICROSOFT##SSEE) Windows Internal Database (MICROSOFT##SSEE) -- d:\WINDOWS\SYSMSI\SSEE\MSSQL.2005\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)

SRV - (DNS) -- D:\WINDOWS\system32\dns.exe (Microsoft Corporation)

SRV - (LicenseService) -- D:\WINDOWS\system32\llssrv.exe (Microsoft Corporation)

SRV - (NtFrs) -- D:\WINDOWS\system32\ntfrs.exe (Microsoft Corporation)

SRV - (RSoPProv) -- D:\WINDOWS\system32\rsopprov.exe (Microsoft Corporation)

SRV - (Pop3Svc) -- D:\WINDOWS\system32\pop3server\pop3svc.exe (Microsoft Corporation)

SRV - (Tssdis) -- D:\WINDOWS\system32\tssdis.exe (Microsoft Corporation)

SRV - (W3SVC) -- D:\WINDOWS\system32\inetsrv\iisw3adm.dll (Microsoft Corporation)

SRV - (IsmServ) -- D:\WINDOWS\system32\ismserv.exe (Microsoft Corporation)

SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (MSFtpsvc) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (IISADMIN) -- D:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)

SRV - (Dfs) -- D:\WINDOWS\system32\dfssvc.exe (Microsoft Corporation)

SRV - (ProxyPlus) -- C:\Proxyplus\ProxyPlus.exe (FORTECH Ltd.)

SRV - (FirebirdServerDefaultInstance) -- D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe (The Firebird Project)

SRV - (FirebirdGuardianDefaultInstance) -- D:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe (The Firebird Project)

SRV - (IDriverT) -- D:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)

SRV - (MySQL) -- D:\Arquivos de programas\EasyPHP1-7\mysql\bin\mysqld.exe ()

SRV - (TrkSvr) -- D:\WINDOWS\system32\trksvr.dll (Microsoft Corporation)

SRV - (DHCPServer) -- D:\WINDOWS\system32\tcpsvcs.exe (Microsoft Corporation)

SRV - (sacsvr) -- D:\WINDOWS\system32\sacsvr.dll (Microsoft Corporation)

SRV - (Apache) -- D:\Arquivos de programas\EasyPHP1-7\apache\apache.exe ()

 

 

========== Driver Services (SafeList) ==========

 

DRV - (klif) -- D:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)

DRV - (m4cxw2k3) -- D:\WINDOWS\system32\drivers\m4cxw2k3.sys (D-Link Corporation)

DRV - (WLBS) -- D:\WINDOWS\system32\drivers\wlbs.sys (Microsoft Corporation)

DRV - (AppleTalk) -- D:\WINDOWS\system32\drivers\sfmatalk.sys (Microsoft Corporation)

DRV - (DfsDriver) -- D:\WINDOWS\system32\drivers\Dfs.sys (Microsoft Corporation)

DRV - (ClusDisk) -- D:\WINDOWS\system32\drivers\clusdisk.sys (Microsoft Corporation)

DRV - (aarich) -- D:\WINDOWS\system32\drivers\aarich.sys (Adaptec, Inc.)

DRV - (ati2mpad) -- D:\WINDOWS\system32\drivers\ati2mpad.sys (ATI Technologies Inc.)

DRV - (RTL8169) -- D:\WINDOWS\system32\drivers\RT8169xp.sys (Realtek Semiconductor Corporation )

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.1.1:4480

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=192.168.1.1:4480;https=192.168.1.1:4480;ftp=192.168.1.1:4480;gopher=192.168.1.1:4480;socks=192.168.1.1:1080

 

========== FireFox ==========

 

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

 

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: D:\Arquivos de programas\Mozilla Firefox\components [2010/03/15 15:54:49 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: D:\Arquivos de programas\Mozilla Firefox\plugins [2010/03/15 15:54:49 | 000,000,000 | ---D | M]

 

[2008/12/05 09:25:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Extensions

[2010/03/15 09:20:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\cp6twxur.default\extensions

[2010/03/15 09:20:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\cp6twxur.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2010/03/15 09:30:37 | 000,000,000 | ---D | M] -- D:\Arquivos de programas\Mozilla Firefox\extensions

 

O1 HOSTS File: ([2003/04/01 09:00:00 | 000,000,776 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AVP] D:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Servers\avp.exe (Kaspersky Lab)

O4 - HKLM..\Run: [EasyPHP] D:\Arquivos de programas\EasyPHP1-7\easyphp.exe (EasyPHP)

O4 - HKLM..\Run: [ibersoft IB Backup] D:\Arquivos de programas\Ibersoft\IBBackup\ibbackup.exe ()

O4 - HKU\S-1-5-21-3275425016-1838925424-743828447-500..\Run: [cdoosoft] D:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\herss.exe File not found

O4 - HKU\.DEFAULT..\RunOnce: [TSClientMSIUninstaller] D:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\RunOnce: [TSClientMSIUninstaller] D:\WINDOWS\System32\cmd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-19..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\RunOnce: [tscuninstall] D:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)

O4 - Startup: D:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk = D:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)

O4 - Startup: D:\Documents and Settings\FD\Menu Iniciar\Programas\Inicializar\No-IP DUC.lnk = D:\Arquivos de programas\No-IP\DUC20.exe (Vitalwerks LLC)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ShowSuperHidden = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 1

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: Wallpaper = C:\Documentos\desktop.jpg ()

O7 - HKU\S-1-5-21-3275425016-1838925424-743828447-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1266575582546 (WUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.athalaia.com.br

O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\klogon: DllName - D:\WINDOWS\system32\klogon.dll - D:\WINDOWS\system32\klogon.dll (Kaspersky Lab)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O24 - Desktop WallPaper: D:\WINDOWS\Web\Wallpaper\Windows Server 2003.bmp

O24 - Desktop BackupWallPaper: D:\WINDOWS\Web\Wallpaper\Windows Server 2003.bmp

O29 - HKLM SecurityProviders - (pwdssp.dll) - D:\WINDOWS\System32\pwdssp.dll (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/01/29 17:45:09 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O32 - AutoRun File - [2010/03/15 16:11:22 | 000,000,053 | RHS- | M] () - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010/03/15 16:11:22 | 000,000,053 | RHS- | M] () - D:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2008/02/18 11:50:50 | 000,000,000 | ---D | M] - F:\autorun -- [ FAT32 ]

O32 - AutoRun File - [2010/03/15 16:11:24 | 000,000,053 | RHS- | M] () - F:\autorun.inf -- [ FAT32 ]

O33 - MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\Shell\AutoRun\command - "" = F:\nhx.exe -- [2010/03/14 11:38:38 | 000,116,736 | RHS- | M] ()

O33 - MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\Shell\open\Command - "" = F:\nhx.exe -- [2010/03/14 11:38:38 | 000,116,736 | RHS- | M] ()

O33 - MountPoints2\{38c8ef35-4af6-11dc-b7da-0008543466fe}\Shell\AutoRun\command - "" = F:\setupSNK.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010/03/15 16:11:44 | 000,000,000 | ---D | C] -- D:\_OTL

[2010/03/15 15:30:25 | 000,555,008 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Administrador\Desktop\OTL.exe

[2010/03/15 09:22:47 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Malwarebytes

[2010/03/15 09:22:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010/03/15 09:22:37 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes

[2010/03/15 09:22:36 | 000,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys

[2010/03/15 09:22:36 | 000,000,000 | ---D | C] -- D:\Arquivos de programas\Malwarebytes' Anti-Malware

[2010/03/15 09:21:59 | 005,115,824 | ---- | C] (Malwarebytes Corporation ) -- D:\Documents and Settings\Administrador\Desktop\mbam-setup.exe

[2010/03/12 08:33:37 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

[2010/02/19 09:17:59 | 000,000,000 | -H-D | C] -- D:\WINDOWS\ie8

[2010/02/19 07:58:21 | 000,000,000 | ---D | C] -- D:\WINDOWS\SxsCaPendDel

[2010/02/19 07:51:26 | 000,000,000 | -HSD | C] -- D:\Config.Msi

[2008/01/29 12:27:33 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\IMPLODE.DLL

[2007/10/15 10:52:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\ApplicationHistory

[2007/01/31 08:58:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft

[2007/01/31 08:58:36 | 000,000,000 | ---D | M] -- D:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft

[2007/01/31 08:51:24 | 000,000,000 | --SD | M] -- D:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft

[2007/01/31 08:51:24 | 000,000,000 | --SD | M] -- D:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft

 

========== Files - Modified Within 30 Days ==========

 

[2010/03/15 16:29:32 | 041,140,768 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox.dat

[2010/03/15 16:25:33 | 000,173,088 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox2.dat

[2010/03/15 16:21:52 | 000,065,536 | ---- | M] () -- D:\WINDOWS\NETLOGON.CHG

[2010/03/15 16:14:48 | 000,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT

[2010/03/15 16:14:45 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat

[2010/03/15 16:13:39 | 000,570,476 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox.idx

[2010/03/15 16:13:39 | 000,018,248 | -HS- | M] () -- D:\WINDOWS\System32\drivers\fidbox2.idx

[2010/03/15 16:12:55 | 000,000,210 | -HS- | M] () -- D:\Documents and Settings\Administrador\ntuser.ini

[2010/03/15 16:12:54 | 004,194,304 | -H-- | M] () -- D:\Documents and Settings\Administrador\NTUSER.DAT

[2010/03/15 16:11:22 | 000,000,053 | RHS- | M] () -- D:\autorun.inf

[2010/03/15 15:30:28 | 000,555,008 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Administrador\Desktop\OTL.exe

[2010/03/15 12:14:28 | 001,094,254 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI

[2010/03/15 12:14:28 | 000,703,550 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat

[2010/03/15 12:14:28 | 000,165,038 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat

[2010/03/15 12:14:28 | 000,106,184 | ---- | M] () -- D:\WINDOWS\System32\perfc016.dat

[2010/03/15 12:14:28 | 000,095,164 | ---- | M] () -- D:\WINDOWS\System32\perfh016.dat

[2010/03/15 12:10:54 | 000,005,958 | RHS- | M] () -- D:\Documents and Settings\Administrador\ntuser.pol

[2010/03/15 12:10:25 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl

[2010/03/15 12:05:02 | 003,366,802 | -H-- | M] () -- D:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\IconCache.db

[2010/03/15 09:22:41 | 000,000,743 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/03/15 09:22:14 | 005,115,824 | ---- | M] (Malwarebytes Corporation ) -- D:\Documents and Settings\Administrador\Desktop\mbam-setup.exe

[2010/03/15 02:02:18 | 000,000,262 | ---- | M] () -- D:\WINDOWS\tasks\BKP Ecalc.job

[2010/03/15 01:32:56 | 000,000,278 | ---- | M] () -- D:\WINDOWS\tasks\Defrag D.job

[2010/03/15 01:00:09 | 000,000,278 | ---- | M] () -- D:\WINDOWS\tasks\Defrag C.job

[2010/03/12 09:05:49 | 000,004,142 | ---- | M] () -- D:\WINDOWS\imsins.BAK

[2010/03/12 08:33:38 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- D:\Documents and Settings\Administrador\Desktop\HiJackThis.exe

[2010/02/19 10:01:38 | 000,012,328 | ---- | M] () -- D:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT

[2010/02/19 08:23:54 | 000,094,272 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT

 

========== Files Created - No Company Name ==========

 

[2010/03/15 09:22:41 | 000,000,743 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2009/07/28 12:13:30 | 031,526,351 | ---- | C] () -- D:\Arquivos de programas\EasyPHP1-8.zip

[2009/03/03 16:16:10 | 000,010,752 | ---- | C] () -- D:\WINDOWS\System32\KOAZJA_L.DLL

[2008/09/09 11:38:10 | 000,000,028 | ---- | C] () -- D:\Arquivos de programas\log.php

[2008/05/13 14:05:56 | 000,176,128 | ---- | C] () -- D:\WINDOWS\GeoCodecLib.dll

[2008/01/29 12:27:34 | 000,748,160 | ---- | C] () -- D:\WINDOWS\System32\CO2C40EN.DLL

[2008/01/29 12:27:34 | 000,131,072 | ---- | C] () -- D:\WINDOWS\System32\P2SODBC.DLL

[2008/01/29 12:27:34 | 000,054,272 | ---- | C] () -- D:\WINDOWS\System32\P2IRDAO.DLL

[2008/01/29 12:27:34 | 000,050,176 | ---- | C] () -- D:\WINDOWS\System32\P2CTDAO.DLL

[2008/01/29 12:27:34 | 000,036,352 | ---- | C] () -- D:\WINDOWS\System32\P2BBND.DLL

[2008/01/02 13:50:11 | 000,040,656 | ---- | C] () -- D:\WINDOWS\php.ini

[2007/09/17 17:35:28 | 000,049,957 | ---- | C] () -- D:\WINDOWS\php.ini_atual

[2007/09/17 17:35:28 | 000,040,056 | ---- | C] () -- D:\WINDOWS\php.ini___

[2007/09/04 00:56:27 | 000,000,048 | ---- | C] () -- D:\WINDOWS\WinInit.ini

[2007/09/03 23:12:36 | 000,000,386 | ---- | C] () -- D:\WINDOWS\ecalc.ini

[2007/07/05 16:00:46 | 000,039,837 | ---- | C] () -- D:\WINDOWS\php.ini.ZendOptimizer-3.0.2_bak

[2007/07/04 18:43:38 | 000,044,432 | ---- | C] () -- D:\WINDOWS\System32\smtpctrs.ini

[2007/07/04 18:43:38 | 000,002,157 | ---- | C] () -- D:\WINDOWS\System32\ntfsdrct.ini

[2007/05/09 16:58:08 | 000,000,147 | ---- | C] () -- D:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\fusioncache.dat

[2007/04/05 14:06:47 | 000,012,042 | ---- | C] () -- D:\WINDOWS\System32\ftpctrs.ini

[2007/04/03 18:26:59 | 000,000,140 | ---- | C] () -- D:\WINDOWS\ODBC.INI

[2007/02/05 07:58:17 | 000,079,698 | ---- | C] () -- D:\WINDOWS\System32\w3ctrs.ini

[2007/02/05 07:58:17 | 000,016,150 | ---- | C] () -- D:\WINDOWS\System32\axperf.ini

[2007/02/05 07:58:13 | 000,017,849 | ---- | C] () -- D:\WINDOWS\System32\infoctrs.ini

[2007/01/31 09:48:28 | 000,004,664 | ---- | C] () -- D:\WINDOWS\System32\dhcpctrs.ini

[2007/01/31 09:47:56 | 000,023,681 | ---- | C] () -- D:\WINDOWS\System32\dnsperf.ini

[2005/03/24 18:16:10 | 000,179,577 | ---- | C] () -- D:\WINDOWS\System32\schema.ini

[2003/08/29 12:26:36 | 000,002,080 | ---- | C] () -- D:\WINDOWS\my.ini

[2003/04/01 09:00:00 | 000,051,066 | ---- | C] () -- D:\WINDOWS\System32\ntdsctrs.ini

[2003/04/01 09:00:00 | 000,041,489 | ---- | C] () -- D:\WINDOWS\System32\ntfrsrep.ini

[2003/04/01 09:00:00 | 000,023,411 | ---- | C] () -- D:\WINDOWS\System32\iasperf.ini

[2003/04/01 09:00:00 | 000,023,252 | ---- | C] () -- D:\WINDOWS\System32\ipsecprf.ini

[2003/04/01 09:00:00 | 000,010,527 | ---- | C] () -- D:\WINDOWS\System32\ntfrscon.ini

 

========== LOP Check ==========

 

[2007/03/14 08:50:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Genie-soft

[2008/05/09 16:20:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\HK-Software

[2009/09/15 09:09:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\Notepad++

[2009/09/15 09:19:05 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Administrador\Dados de aplicativos\uTorrent

[2007/03/12 10:25:07 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\Genie-soft

[2007/10/22 16:18:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\Grisoft

[2008/10/13 16:56:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Dados de aplicativos\LogMeIn

[2007/03/12 10:38:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Backup\Dados de aplicativos\Genie-soft

[2008/04/10 09:10:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\fabiano\Dados de aplicativos\Genie-soft

[2007/12/22 11:14:08 | 000,000,000 | ---D | M] -- D:\Documents and Settings\fabiano\Dados de aplicativos\Grisoft

[2007/09/10 18:58:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Easy Thumbnails

[2007/11/12 17:31:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Grisoft

[2008/05/13 15:28:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\FD\Dados de aplicativos\Notepad++

[2007/12/27 06:50:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\João\Dados de aplicativos\Grisoft

[2008/05/16 17:28:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\João\Dados de aplicativos\Notepad++

[2007/12/27 07:04:13 | 000,000,000 | ---D | M] -- D:\Documents and Settings\roberto\Dados de aplicativos\Grisoft

[2008/09/07 17:53:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\vendas\Dados de aplicativos\Notepad++

[2010/03/15 02:02:18 | 000,000,262 | ---- | M] () -- D:\WINDOWS\Tasks\BKP Ecalc.job

[2010/03/15 01:00:09 | 000,000,278 | ---- | M] () -- D:\WINDOWS\Tasks\Defrag C.job

[2010/03/15 01:32:56 | 000,000,278 | ---- | M] () -- D:\WINDOWS\Tasks\Defrag D.job

[2009/03/24 08:51:41 | 000,000,556 | ---- | M] () -- D:\WINDOWS\Tasks\GBMPro6 Task - BKP_Diario_Athalaia.job

[2010/02/20 00:00:10 | 000,032,514 | ---- | M] () -- D:\WINDOWS\Tasks\SchedLgU.Txt

 

========== Purity Check ==========

 

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Selecione e copie o código abaixo:

:Processes

explorer.exe

 

:OTL

O33 - MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\Shell\AutoRun\command - "" = F:\nhx.exe -- [2010/03/14 11:38:38 | 000,116,736 | RHS- | M] ()

O33 - MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\Shell\open\Command - "" = F:\nhx.exe -- [2010/03/14 11:38:38 | 000,116,736 | RHS- | M] ()

O33 - MountPoints2\{38c8ef35-4af6-11dc-b7da-0008543466fe}\Shell\AutoRun\command - "" = F:\setupSNK.exe -- File not found

 

:Commands

[start explorer]

[Reboot]

*Duplo clique em OTL

*No espaço abaixo de "Custom Scans/Fixes" cole-o (Ctrl+v)

*Clique em [Run Fix]

*O PC será reiniciado

*Cole o relatório criado em C:\_OTListIt\MovedFiles\MDA_HMS.log.txt, onde MDA é mês/dia/ano e HMS é hora/minuto/segundos

Compartilhar este post


Link para o post
Compartilhar em outros sites

========== PROCESSES ==========

Process explorer.exe killed successfully!

========== OTL ==========

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1a70df0d-98f3-11dd-97f8-0008543466fe}\ not found.

F:\nhx.exe moved successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1a70df0d-98f3-11dd-97f8-0008543466fe}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1a70df0d-98f3-11dd-97f8-0008543466fe}\ not found.

File F:\nhx.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{38c8ef35-4af6-11dc-b7da-0008543466fe}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{38c8ef35-4af6-11dc-b7da-0008543466fe}\ not found.

File F:\setupSNK.exe not found.

========== COMMANDS ==========

 

OTL by OldTimer - Version 3.1.37.1 log created on 03162010_074805

 

Files\Folders moved on Reboot...

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.