Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Leandrueo

[Resolvido!] Virus de E-mail

Recommended Posts

Cai naquelas armadilhas tipicas de e-mails " Foto da festinha" po tinha ido numa festa ontem dessa mesma pessoa que me mando o e-mail, dai acreditei e cliquei =\ anti-virus pegou, mas será que já to limpo? Segue Hijack

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:38:30, on 11/7/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\WINDOWS\PixArt\PAC7302\Monitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jucheck.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftvsa.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftlist.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Arquivos de programas\AVG\AVG8\avgui.exe

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.ask.com?o=15425&l=dis

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\DOCUME~1\windows\CONFIG~1\Temp\449.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] C:\Arquivos de programas\NVIDIA Corporation\nView\nwiz.exe /install

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe

O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 8354 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite....

 

1.

*Baixe o MalwareBytes Anti-malware e salve-o no desktop

*Instale o programa

*Se alguma atualização existir,o download será automático. Aguarde...

*O programa será aberto automaticamente.

*Na aba [Verificação], selecione a opção [Verificação completa]

*Clique em [Verificar] e selecione as partições a serem examinadas (geralmente C:\ e D:\)

*Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados]

*Clique em [Remover Selecionados]

*Um relatório (mbam-log-ano-mês-data.txt) será apresentado.

*Cole-o na sua próxima resposta

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue MBAM

 

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Versão da Base de Dados: 4306

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 6.0.2900.5512

 

13/7/2010 06:40:59

mbam-log-2010-07-13 (06-40-59).txt

 

Tipo de Verificação: Verificação Completa (C:\|Q:\|)

Objetos escaneados: 169065

Tempo decorrido: 1 hora(s), 0 minuto(s), 47 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 2

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 1

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\advanced dhtml enable (Trojan.Agent) -> Quarantined and deleted successfully.

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

C:\Documents and Settings\windows\Configurações locais\Temp\utt28.tmp.exe (Trojan.Pakes) -> Quarantined and deleted successfully.

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o Kaspersky Virus Removal Tool e salve-o no desktop

*Desative temporariamente seu antivírus

 

Iniciar > Programas > AVG

Abra a Interface do usuário do AVG

Clique duas vezes na Proteção Residente

Desmarque a opção "Proteção Residente ativa"

Salve as alterações

*Instale o programa

*A tela principal do programa será aberta automaticamente

*Selecione a opção:

 

[] Meu Computador

*Clique em [start scan]....aguarde. Pode demorar.

*Caso encontre algo, clique em [skip]

*Ao término do scan, clique em [Report]

*Uma janela chamada "Detailed report" será aberta

*Clique no sinal [+] ao lado de Autoscan para expandir os eventos encontrados

*Clique com o botão direito do mouse e selecione "Select all"

*Clique novamente com o botão direito do mouse e selecione "Copy"

*Abra o bloco de notas e cole (Ctrl+v) e salve o arquivo no desktop como log.txt

*Feche a janela "Detailed report" do Kasperky

*Na tela principal do Kaspersky clique em [Exit] > [No]

*Cole o relatório salvo no desktop na sua próxima resposta

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue Log do KasperSky e Hijack atualizado

 

 

Autoscan: completed 16 hours ago (events: 2, objects: 161020, time: 01:43:38)

14/7/2010 18:54:05 Task started

14/7/2010 20:37:44 Task completed

 

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:31:25, on 15/7/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\WINDOWS\RTHDCPL.EXE

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\PixArt\PAC7302\Monitor.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftvsa.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftlist.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jucheck.exe

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.ask.com?o=15425&l=dis

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Flash Video Decoder for FLV - {66376D90-C89B-4D3B-B507-670A8E5515D3} - C:\ProgramData\WLSetup\aVWJatSQINFHTBbyp.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] C:\Arquivos de programas\NVIDIA Corporation\nView\nwiz.exe /install

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe

O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: setup_9.0.0.722_13.07.2010_19-53.lnk = C:\Documents and Settings\windows\Desktop\Virus Removal Tool\setup_9.0.0.722_13.07.2010_19-53\startup.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 8662 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Apagar tudo]

*Clique na aba [Logs], selecione o relatório e clique em [Apagar]

 

2.

*Abra a pasta Virus Removal Tool, localizada no desktop, duplo clique no atalho Start

*A tela principal do Kaspersky será aberta novamente

*Clique em [Exit] > [Yes] > [sim] > [sim]

*O PC será reiniciado

*Delete o arquivo setup do Kaspersky e o log salvo no desktop

 

3.

*Desative temporariamente seu antivírus

 

Iniciar > Programas > AVG

Abra a Interface do usuário do AVG

Clique duas vezes na Proteção Residente

Desmarque a opção "Proteção Residente ativa"

Salve as alterações

*Baixe o ComboFix e salve-o no desktop

 

*Execute o Combofix e aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso contrário, clique em [sIM] para a sua instalação.

 

recovery-console-prompt.jpg

 

*Clique em [sIM] para continuar.

 

recovery-console-installed.jpg

 

*Aguarde a conclusão de todas as etapas

 

etapas.jpg

 

*Enquanto o ComboFix estiver em execução, evite usar o mouse e o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER.

 

*O programa será fechado automaticamente e um relatório (C:\combofix.txt) será apresentado. Cole-o na próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 10-07-15.05 - windows 16/07/2010 13:48:59.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.894.523 [GMT -3:00]

Executando de: c:\documents and settings\windows\Desktop\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\vbzlib1.dll

 

c:\windows\system32\userinit.exe . . . está infectado!!

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2010-06-16 to 2010-07-16 ))))))))))))))))))))))))))))

.

 

2010-07-15 15:40 . 2008-04-14 12:00 11776 ----a-w- c:\windows\system32\eSmYWEoaJFQyqzUl.exe

2010-07-15 15:40 . 2010-07-15 15:40 -------- d-----w- C:\ProgramData

2010-07-13 01:18 . 2010-07-13 01:26 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Youtube Downloader HD

2010-07-13 01:18 . 2010-07-13 01:18 -------- d-----w- c:\arquivos de programas\Youtube Downloader HD

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Malwarebytes

2010-07-13 00:56 . 2010-04-29 18:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-07-13 00:56 . 2010-04-29 18:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-12 02:33 . 2010-07-12 02:33 401720 ----a-w- C:\HiJackThis.exe

2010-07-12 01:16 . 2010-07-14 19:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\VirtualizedApplications

2010-07-11 23:04 . 2010-07-14 03:03 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\SoftGrid Client

2010-07-11 23:04 . 2010-07-11 23:04 -------- d-----w- c:\windows\system32\config\systemprofile\Dados de aplicativos\{90140011-0062-0409-0000-0000000FF1CE}

2010-07-11 23:03 . 2010-07-16 16:54 -------- d-----w- c:\windows\system32\config\systemprofile\Dados de aplicativos\SoftGrid Client

2010-07-11 23:01 . 2010-07-15 02:15 -------- d-----w- c:\arquivos de programas\Microsoft Application Virtualization Client

2010-07-11 23:01 . 2010-07-11 23:01 -------- d-----w- c:\documents and settings\All Users\Microsoft

2010-07-11 23:00 . 2010-07-11 23:05 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\TP

2010-07-07 04:01 . 2010-07-07 04:01 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Ashampoo

2010-07-07 04:00 . 2010-07-07 04:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ashampoo

2010-07-07 04:00 . 2010-07-07 04:00 -------- d-----w- c:\arquivos de programas\Ashampoo

2010-07-07 00:29 . 2010-07-07 00:29 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Publish Providers

2010-07-07 00:29 . 2010-07-07 00:29 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Sony

2010-07-06 21:32 . 2010-07-06 21:32 -------- d-----w- c:\arquivos de programas\Vstplugins

2010-07-06 21:31 . 2010-07-06 21:31 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Sony

2010-07-06 21:31 . 2010-07-06 21:31 -------- d-----w- c:\arquivos de programas\Sony

2010-07-06 21:29 . 2010-07-06 21:29 -------- d-----w- c:\arquivos de programas\Sony Setup

2010-06-29 00:37 . 2010-06-29 00:37 -------- d-----w- c:\arquivos de programas\DsNET Corp

2010-06-29 00:26 . 2010-06-29 00:26 -------- d-----w- c:\documents and settings\windows\dwhelper

2010-06-21 20:13 . 2010-06-21 20:13 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\AnvSoft

2010-06-21 20:12 . 2010-06-21 20:12 -------- d-----w- c:\arquivos de programas\AnvSoft

2010-06-20 14:55 . 2008-04-13 22:20 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll

2010-06-20 14:55 . 2008-04-13 22:20 21504 ----a-w- c:\windows\system32\hidserv.dll

2010-06-20 14:55 . 2008-04-13 21:58 14720 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys

2010-06-20 14:55 . 2008-04-13 21:58 14720 ----a-w- c:\windows\system32\drivers\kbdhid.sys

2010-06-19 00:48 . 2006-06-29 16:07 14048 ------w- c:\windows\system32\spmsg2.dll

2010-06-19 00:45 . 2010-06-19 00:48 -------- d-----w- c:\windows\system32\XPSViewer

2010-06-19 00:45 . 2010-06-19 00:45 -------- d-----w- c:\arquivos de programas\MSBuild

2010-06-19 00:45 . 2010-06-19 00:45 -------- d-----w- c:\arquivos de programas\Reference Assemblies

2010-06-19 00:44 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll

2010-06-19 00:44 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2010-06-19 00:44 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2010-06-19 00:44 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2010-06-19 00:44 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2010-06-19 00:44 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2010-06-19 00:44 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe

2010-06-19 00:44 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2010-06-19 00:44 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2010-06-19 00:44 . 2010-06-19 00:44 -------- d-----w- C:\8194a7fb617d1a1856ac

2010-06-19 00:34 . 2010-06-29 01:02 -------- d-----w- c:\arquivos de programas\VDownloader

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-07-15 02:16 . 2008-04-14 12:00 80432 ----a-w- c:\windows\system32\perfc016.dat

2010-07-15 02:16 . 2008-04-14 12:00 473762 ----a-w- c:\windows\system32\perfh016.dat

2010-07-14 22:16 . 2010-04-06 22:51 -------- d-----w- c:\arquivos de programas\Google

2010-07-11 22:54 . 2010-01-21 14:09 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\uTorrent

2010-07-02 22:16 . 2010-06-13 01:52 -------- d-----w- c:\arquivos de programas\Persona

2010-07-02 22:13 . 2010-04-03 17:00 98304 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\npNxGameUS.dll

2010-07-02 22:13 . 2010-04-03 17:00 258352 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\unicows.dll

2010-07-02 22:13 . 2010-04-03 17:00 126976 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\nxgameus.dll

2010-07-02 22:13 . 2010-04-03 17:00 765952 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\NGMDll.dll

2010-07-02 22:13 . 2010-04-03 17:00 401408 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\NGMResource.dll

2010-06-14 14:31 . 2010-01-13 13:02 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-13 02:32 . 2010-06-13 02:01 -------- d-----w- c:\arquivos de programas\Pangya

2010-06-13 02:02 . 2010-04-03 16:10 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\PMB Files

2010-06-09 08:06 . 2010-06-09 08:06 976832 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Adobe\Reader\9.3\ARM\32105\AdobeARM.exe

2010-06-09 08:06 . 2010-06-09 08:06 70584 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Adobe\Reader\9.3\ARM\32105\AdobeExtractFiles.dll

2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Adobe\Reader\9.3\ARM\32105\ReaderUpdater.exe

2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Adobe\Reader\9.3\ARM\32105\AcrobatUpdater.exe

2010-06-06 22:59 . 2010-03-19 21:38 -------- d-----w- c:\arquivos de programas\MSECache

2010-06-03 03:03 . 2010-01-13 13:47 -------- d-----w- c:\arquivos de programas\Messenger Plus! Live

2010-05-30 19:41 . 2010-01-21 14:10 -------- d-----w- c:\arquivos de programas\uTorrent

2010-05-28 18:38 . 2010-05-28 18:38 503808 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\msvcp71.dll

2010-05-28 18:38 . 2010-05-28 18:38 499712 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\jmc.dll

2010-05-28 18:38 . 2010-05-28 18:38 348160 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\msvcr71.dll

2010-05-28 18:38 . 2010-05-28 18:38 61440 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-37c78fe7-n\decora-sse.dll

2010-05-28 18:38 . 2010-05-28 18:38 12800 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-37c78fe7-n\decora-d3d.dll

2010-05-02 08:08 . 2008-04-14 12:00 1851392 ----a-w- c:\windows\system32\win32k.sys

2010-04-28 18:45 . 2010-04-28 18:45 73000 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

2010-04-24 04:10 . 2009-12-03 01:23 18280 ----a-w- c:\windows\system32\drivers\Sftvolxp.sys

2010-04-24 04:10 . 2009-12-03 01:23 20584 ----a-w- c:\windows\system32\drivers\Sftredirxp.sys

2010-04-24 04:10 . 2009-12-03 01:23 211432 ----a-w- c:\windows\system32\drivers\Sftplayxp.sys

2010-04-24 04:10 . 2010-04-24 04:10 1015144 ----a-w- c:\windows\system32\sftldr.dll

2010-04-24 04:10 . 2009-12-03 01:23 554344 ----a-w- c:\windows\system32\drivers\Sftfsxp.sys

2010-04-21 02:13 . 2010-04-21 02:13 691696 ----a-w- c:\windows\system32\drivers\sptd.sys

2010-04-20 05:31 . 2008-04-14 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll

.

 

------- Sigcheck -------

 

[-] 2008-05-19 . 1D01C384F3BA123EB6F09769DEA005AC . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66376D90-C89B-4D3B-B507-670A8E5515D3}]

2010-07-15 15:40 1020928 ----a-w- c:\programdata\WLSetup\aVWJatSQINFHTBbyp.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-11-25 15:01 1230080 ----a-w- c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"ares"="c:\arquivos de programas\Ares\Ares.exe" [2010-01-09 955392]

"Pando Media Booster"="c:\arquivos de programas\Pando Networks\Media Booster\PMB.exe" [2010-04-03 2938552]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-11 16126464]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2010-07-08 2048352]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-01-11 246504]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]

"LogMeIn Hamachi Ui"="c:\arquivos de programas\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2010-03-18 421888]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2010-01-13 13:45 11952 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"=

"c:\\Arquivos de programas\\Ares\\Ares.exe"=

"c:\\Documents and Settings\\windows\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=

"c:\\Arquivos de programas\\Pando Networks\\Media Booster\\PMB.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"=

"c:\\NGM\\NGM.exe"=

"c:\\Arquivos de programas\\Sports Interactive\\Football Manager 2010\\fm.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\DsNET Corp\\aTube Catcher 2.0\\yct.exe"=

"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57938:TCP"= 57938:TCP:Pando Media Booster

"57938:UDP"= 57938:UDP:Pando Media Booster

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/1/2010 10:45 335240]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/1/2010 10:45 108552]

R2 avg8emc;AVG Free8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [13/1/2010 10:45 908056]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [13/1/2010 10:45 297752]

R2 cvhsvc;Client Virtualization Handler;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/2/2010 02:33 821664]

R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\arquivos de programas\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 1107336]

R2 sftlist;Application Virtualization Client;c:\arquivos de programas\Microsoft Application Virtualization Client\sftlist.exe [24/4/2010 01:10 483688]

R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [2/12/2009 22:23 554344]

R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [2/12/2009 22:23 211432]

R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2/12/2009 22:23 20584]

R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [2/12/2009 22:23 18280]

R3 sftvsa;Application Virtualization Service Agent;c:\arquivos de programas\Microsoft Application Virtualization Client\sftvsa.exe [24/4/2010 01:10 209768]

S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [14/7/2010 19:12 136176]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/4/2010 23:13 691696]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2010-07-13 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2009-10-22 14:50]

 

2010-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-07-14 22:11]

 

2010-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-07-14 22:11]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://br.ask.com?o=15425&l=dis

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = *.local

FF - ProfilePath - c:\documents and settings\windows\Dados de aplicativos\Mozilla\Firefox\Profiles\g9cswzeo.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.globo.com/

FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=

FF - plugin: c:\arquiv~1\MICROS~3\Office14\NPSPWRAP.DLL

FF - plugin: c:\arquivos de programas\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\arquivos de programas\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\Pando Networks\Media Booster\npPandoWebPlugin.dll

FF - plugin: c:\docume~1\windows\DADOSD~1\POWERC~1\nppowerloader.dll

FF - plugin: c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\npNxGameUS.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORFÃOS REMOVIDOS - - - -

 

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKLM-Run-nwiz - c:\arquivos de programas\NVIDIA Corporation\nView\nwiz.exe

AddRemove-HijackThis - c:\documents and settings\windows\Desktop\HijackThis.exe

AddRemove-NVIDIA nView Desktop Manager - c:\arquivos de programas\NVIDIA Corporation\nView\nViewSetup.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-07-16 13:57

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-1060284298-1960408961-842925246-1003\Software\G*e*n*i*e*"!\FM Genie Scout 10]

"GameDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\games"

"ShortlistDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\shortlists"

"ScreenshotsDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010"

"SaveDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\"

"HistoryDir"="c:\\Documents and Settings\\windows\\Desktop\\FM Genie Scout 10\\History Points"

"LangDB"="c:\\Arquivos de programas\\Sports Interactive\\Football Manager 2010\\data\\updates\\update-1030\\db\\1030\\lang_db.dat"

"LastSaveGame"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\games\\Alessandro.fm"

"Language"="English"

"LoadLangDB"=dword:00000001

"CompressHistoryPoints"=dword:00000000

"HighlightedAttributes"=dword:00000000

"MinCondition"=dword:00000050

"GraphStep"=dword:00000000

"SkinName"="Steklo Black"

"LastUpdateCheck"=dword:00009da9

"HighQualityGUI"=dword:00000001

"AutomaticallyUpdateCheck"=dword:00000001

"AdvancedGeneration"=dword:00000000

"TranslateStaffSkills"=dword:00000001

"TranslatePlayerSkills"=dword:00000001

"TranslatePositions"=dword:00000001

"ShowHistory"=dword:00000001

"Version"=dword:00000074

"UniqueID"="44-0050-626F"

"Currency"=dword:00000056

"UseProxy"=dword:00000000

"ProxyHost"=""

"ProxyPort"=""

"UseAuthentication"=dword:00000000

"UserName"=""

"UserPassword"=""

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(256)

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\nvsvc32.exe

c:\windows\RTHDCPL.EXE

c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\windows\system32\RUNDLL32.EXE

c:\arquivos de programas\Bonjour\mDNSResponder.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquiv~1\AVG\AVG8\avgrsx.exe

c:\arquiv~1\AVG\AVG8\avgnsx.exe

c:\arquivos de programas\AVG\AVG8\avgcsrvx.exe

c:\arquivos de programas\iPod\bin\iPodService.exe

c:\windows\system32\wscntfy.exe

c:\arquivos de programas\Arquivos comuns\Java\Java Update\jucheck.exe

.

**************************************************************************

.

Tempo para conclusão: 2010-07-16 14:01:43 - Máquina reiniciou

ComboFix-quarantined-files.txt 2010-07-16 17:01

 

Pré-execução: 14 pasta(s) 44.492.857.344 bytes disponíveis

Pós execução: 17 pasta(s) 46.095.773.696 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - A495B5B87562DD9291435855E27C53BD

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o SystemLook e salve-o no desktop

*Duplo clique em SystemLook.exe

*Cole o código abaixo no espaço em branco:

 

:file

c:\windows\system32\eSmYWEoaJFQyqzUl.exe

c:\programdata\WLSetup\aVWJatSQINFHTBbyp.dll

*Clique em [Look]

*Cole o relatório criado em SystemLook.txt localizado no desktop

Compartilhar este post


Link para o post
Compartilhar em outros sites

SystemLook v1.0 by jpshortstuff (11.01.10)

Log created at 11:17 on 24/07/2010 by windows (Administrator - Elevation successful)

 

========== file ==========

 

c:\windows\system32\eSmYWEoaJFQyqzUl.exe - File found and opened.

MD5: D2CB204038210C55E0071947891A5642

Created at 15:40 on 15/07/2010

Modified at 12:00 on 14/04/2008

Size: 11776 bytes

Attributes: --a---

FileDescription: Servidor de registro Microsoft©

FileVersion: 5.1.2600.5512 (xpsp.080413-2105)

ProductVersion: 5.1.2600.5512

OriginalFilename: REGSVR32.EXE

InternalName: REGSVR32

ProductName: Sistema operacional Microsoft® Windows®

CompanyName: Microsoft Corporation

LegalCopyright: © Microsoft Corporation. Todos os direitos reservados.

 

c:\programdata\WLSetup\aVWJatSQINFHTBbyp.dll - Unable to find/read file.

 

-=End Of File=-

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Delete o SystemLook e seu relatório.

 

2.

*Execute o hijack, clique em [Do a system scan only, selecione a entrada abaixo e clique em [Fix checked]

 

O2 - BHO: Flash Video Decoder for FLV - {66376D90-C89B-4D3B-B507-670A8E5515D3} - C:\ProgramData\WLSetup\aVWJatSQINFHTBbyp.dll

*Feche o hijack

 

3.

*Clique em [iniciar] > [Executar] > digite: Combofix /uninstall

*Clique [OK]

 

92674490.jpg

 

*Clique em [Executar]

*Aguarde até surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

4.

*Clique em [iniciar] > [Executar] > digite: sfc /scannow

 

sfc.jpg

*Clique OK

*Será solicitado o cd do Windows

*Coloque-o no CD-Rom e aguarde o término....

*Retire o CD e reinicie o PC

 

Informe como está o PC....

Compartilhar este post


Link para o post
Compartilhar em outros sites

Não achei essa dll, vou mandar um log do hijack atualizado pra você ver.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:01:42, on 24/7/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\PixArt\PAC7302\Monitor.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftvsa.exe

C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Microsoft Application Virtualization Client\sftlist.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Virtualization Handler\CVHSVC.EXE

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jucheck.exe

C:\Arquivos de programas\uTorrent\uTorrent.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.ask.com?o=15425&l=dis

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Flash Video Decoder for FLV - {96D54723-E733-4440-A383-8A621BCF17F2} - C:\WINDOWS\system32\flash101flv.dll (file missing)

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe

O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [Pando Media Booster] C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\DTLite.exe" -autorun

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Arquivos de programas\LogMeIn Hamachi\hamachi-2.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 8362 bytes

 

 

 

E o cd do windows eu nem tenho cara, esse pc tem uns 2 anos e eu perdi o cd =\ tem outro jeito?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe novamente o SystemLook e salve-o no desktop

*Duplo clique em SystemLook.exe

*Cole o código abaixo no espaço em branco:

 

:filefind

*userinit*

*Clique em [Look]

*Cole o relatório apresentado em SystemLook.txt localizado no desktop

Compartilhar este post


Link para o post
Compartilhar em outros sites

SystemLook v1.0 by jpshortstuff (11.01.10)

Log created at 11:18 on 25/07/2010 by windows (Administrator - Elevation successful)

 

========== filefind ==========

 

Searching for "*userinit*"

C:\Qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir --a--- 26112 bytes [12:00 14/04/2008] [12:00 14/04/2008] A7EA40F680163808D96F89B4FF991876

C:\WINDOWS\ERDNT\cache\userinit.exe --a--- 26112 bytes [17:00 16/07/2010] [12:00 14/04/2008] A7EA40F680163808D96F89B4FF991876

C:\WINDOWS\system32\userinit.exe --a--- 26112 bytes [12:00 14/04/2008] [12:00 14/04/2008] A7EA40F680163808D96F89B4FF991876

 

-=End Of File=-

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Desative temporariamente seu antivírus

 

 

*Baixe novamente o ComboFix e salve-o no desktop

 

*Abra o bloco de notas e cole nele todo o conteúdo do código abaixo:

 

Fcopy::

C:\WINDOWS\ERDNT\cache\userinit.exe | C\WINDOWS\system32\userinit.exe

*Salve o arquivo no desktop como CFScript.txt

*Arraste o arquivo para o Combofix conforme ilustração abaixo:

 

CFScript.gif

 

*Importante: enquanto o combofix estiver em execução, evite usar o mouse e o teclado!!..para interromper o processo tecle N ou 2.

 

*Cole o relatório criado em C:\combofix.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 10-08-02.01 - windows 02/08/2010 22:15:09.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.894.341 [GMT -3:00]

Executando de: c:\documents and settings\windows\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\windows\Desktop\CFScript.txt

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_OSPPSVC

-------\Service_osppsvc

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2010-07-03 to 2010-08-03 ))))))))))))))))))))))))))))

.

 

2010-08-02 23:38 . 2010-08-02 23:38 503808 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-704272a8-n\msvcp71.dll

2010-08-02 23:38 . 2010-08-02 23:38 348160 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-704272a8-n\msvcr71.dll

2010-08-02 23:38 . 2010-08-02 23:38 499712 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-704272a8-n\jmc.dll

2010-08-02 23:38 . 2010-08-02 23:38 61440 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-17059fb5-n\decora-sse.dll

2010-08-02 23:38 . 2010-08-02 23:38 12800 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-17059fb5-n\decora-d3d.dll

2010-07-28 18:19 . 2010-07-28 18:19 -------- d-----w- c:\arquivos de programas\RealVNC

2010-07-25 22:56 . 2010-07-25 22:56 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\LolClient

2010-07-25 22:30 . 2010-07-25 22:30 -------- d-----w- C:\Riot Games

2010-07-25 21:55 . 2010-07-25 21:56 -------- d-----w- C:\League Of legends

2010-07-22 14:30 . 2010-07-22 14:30 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\WinAVI

2010-07-22 14:30 . 2010-07-22 14:30 -------- d-----w- c:\arquivos de programas\WinAVI Video Converter

2010-07-15 15:40 . 2008-04-14 12:00 11776 ----a-w- c:\windows\system32\eSmYWEoaJFQyqzUl.exe

2010-07-15 15:40 . 2010-07-16 17:08 -------- d-----w- C:\ProgramData

2010-07-13 01:18 . 2010-07-13 01:26 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Youtube Downloader HD

2010-07-13 01:18 . 2010-07-13 01:18 -------- d-----w- c:\arquivos de programas\Youtube Downloader HD

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Malwarebytes

2010-07-13 00:56 . 2010-04-29 18:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2010-07-13 00:56 . 2010-07-13 00:56 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-07-13 00:56 . 2010-04-29 18:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-12 02:33 . 2010-07-12 02:33 401720 ----a-w- C:\HiJackThis.exe

2010-07-12 01:16 . 2010-07-14 19:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\VirtualizedApplications

2010-07-11 23:04 . 2010-07-14 03:03 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\SoftGrid Client

2010-07-11 23:04 . 2010-07-11 23:04 -------- d-----w- c:\windows\system32\config\systemprofile\Dados de aplicativos\{90140011-0062-0409-0000-0000000FF1CE}

2010-07-11 23:03 . 2010-08-03 01:21 -------- d-----w- c:\windows\system32\config\systemprofile\Dados de aplicativos\SoftGrid Client

2010-07-11 23:01 . 2010-07-15 02:15 -------- d-----w- c:\arquivos de programas\Microsoft Application Virtualization Client

2010-07-11 23:01 . 2010-07-11 23:01 -------- d-----w- c:\documents and settings\All Users\Microsoft

2010-07-11 23:00 . 2010-07-11 23:05 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\TP

2010-07-07 04:01 . 2010-07-07 04:01 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Ashampoo

2010-07-07 04:00 . 2010-07-07 04:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ashampoo

2010-07-07 04:00 . 2010-07-07 04:00 -------- d-----w- c:\arquivos de programas\Ashampoo

2010-07-07 00:29 . 2010-07-07 00:29 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Publish Providers

2010-07-07 00:29 . 2010-07-07 00:29 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\Sony

2010-07-06 21:32 . 2010-07-06 21:32 -------- d-----w- c:\arquivos de programas\Vstplugins

2010-07-06 21:31 . 2010-07-06 21:31 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Sony

2010-07-06 21:31 . 2010-07-06 21:31 -------- d-----w- c:\arquivos de programas\Sony

2010-07-06 21:29 . 2010-07-06 21:29 -------- d-----w- c:\arquivos de programas\Sony Setup

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-07-25 22:30 . 2010-01-13 13:38 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2010-07-25 21:56 . 2010-04-03 16:10 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\PMB Files

2010-07-25 13:05 . 2010-01-21 14:09 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\uTorrent

2010-07-15 02:16 . 2008-04-14 12:00 80432 ----a-w- c:\windows\system32\perfc016.dat

2010-07-15 02:16 . 2008-04-14 12:00 473762 ----a-w- c:\windows\system32\perfh016.dat

2010-07-14 22:16 . 2010-04-06 22:51 -------- d-----w- c:\arquivos de programas\Google

2010-07-02 22:16 . 2010-06-13 01:52 -------- d-----w- c:\arquivos de programas\Persona

2010-07-02 22:13 . 2010-04-03 17:00 98304 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\npNxGameUS.dll

2010-07-02 22:13 . 2010-04-03 17:00 258352 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\unicows.dll

2010-07-02 22:13 . 2010-04-03 17:00 126976 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\nxgameus.dll

2010-07-02 22:13 . 2010-04-03 17:00 765952 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\NGMDll.dll

2010-07-02 22:13 . 2010-04-03 17:00 401408 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\NGMResource.dll

2010-06-29 01:02 . 2010-06-19 00:34 -------- d-----w- c:\arquivos de programas\VDownloader

2010-06-29 00:37 . 2010-06-29 00:37 -------- d-----w- c:\arquivos de programas\DsNET Corp

2010-06-21 20:13 . 2010-06-21 20:13 -------- d-----w- c:\documents and settings\windows\Dados de aplicativos\AnvSoft

2010-06-21 20:12 . 2010-06-21 20:12 -------- d-----w- c:\arquivos de programas\AnvSoft

2010-06-19 00:45 . 2010-06-19 00:45 -------- d-----w- c:\arquivos de programas\MSBuild

2010-06-19 00:45 . 2010-06-19 00:45 -------- d-----w- c:\arquivos de programas\Reference Assemblies

2010-06-14 14:31 . 2010-01-13 13:02 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe

2010-06-13 02:32 . 2010-06-13 02:01 -------- d-----w- c:\arquivos de programas\Pangya

2010-06-06 22:59 . 2010-03-19 21:38 -------- d-----w- c:\arquivos de programas\MSECache

2010-05-28 18:38 . 2010-05-28 18:38 503808 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\msvcp71.dll

2010-05-28 18:38 . 2010-05-28 18:38 499712 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\jmc.dll

2010-05-28 18:38 . 2010-05-28 18:38 348160 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-11afc729-n\msvcr71.dll

2010-05-28 18:38 . 2010-05-28 18:38 61440 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-37c78fe7-n\decora-sse.dll

2010-05-28 18:38 . 2010-05-28 18:38 12800 ----a-w- c:\documents and settings\windows\Dados de aplicativos\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-37c78fe7-n\decora-d3d.dll

.

 

------- Sigcheck -------

 

[-] 2008-05-19 . 1D01C384F3BA123EB6F09769DEA005AC . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

.

((((((((((((((((((((((((((((( SnapShot@2010-07-16_16.56.13 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-07-12 03:02 . 2009-07-12 03:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll

+ 2010-08-03 01:22 . 2010-08-03 01:22 16384 c:\windows\Temp\Perflib_Perfdata_e8.dat

- 2010-07-16 16:54 . 2010-07-16 16:54 29218 c:\windows\system32\config\systemprofile\Dados de aplicativos\SoftGrid Client\Icon Cache\icon_ex.dat

+ 2010-08-03 01:21 . 2010-08-03 01:21 29218 c:\windows\system32\config\systemprofile\Dados de aplicativos\SoftGrid Client\Icon Cache\icon_ex.dat

+ 2010-07-22 14:30 . 2010-07-22 14:30 51712 c:\windows\Installer\5907875.msi

+ 2010-07-22 14:30 . 2010-07-22 14:30 53248 c:\windows\Installer\590786f.msi

+ 2010-07-22 14:30 . 2010-07-22 14:30 51712 c:\windows\Installer\5907869.msi

+ 2010-07-22 14:30 . 2010-07-22 14:30 53248 c:\windows\Installer\5907863.msi

+ 2010-04-06 00:22 . 2008-07-12 11:18 467984 c:\windows\system32\d3dx10_39.dll

- 2010-04-06 00:22 . 2008-07-10 14:01 467984 c:\windows\system32\d3dx10_39.dll

+ 2010-07-25 22:35 . 2010-07-25 22:35 216576 c:\windows\Installer\6e86241.msi

+ 2010-04-06 00:22 . 2008-07-12 11:18 3851784 c:\windows\system32\D3DX9_39.dll

- 2010-04-06 00:22 . 2008-07-10 14:00 3851784 c:\windows\system32\D3DX9_39.dll

+ 2010-04-06 00:22 . 2008-07-12 11:18 1493528 c:\windows\system32\D3DCompiler_39.dll

- 2010-04-06 00:22 . 2008-07-10 14:00 1493528 c:\windows\system32\D3DCompiler_39.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

2009-11-25 15:01 1230080 ----a-w- c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\arquivos de programas\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

 

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"ares"="c:\arquivos de programas\Ares\Ares.exe" [2010-01-09 955392]

"Pando Media Booster"="c:\arquivos de programas\Pando Networks\Media Booster\PMB.exe" [2010-04-03 2938552]

"DAEMON Tools Lite"="c:\arquivos de programas\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2007-04-11 16126464]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2010-07-08 2048352]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-01-11 246504]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]

"LogMeIn Hamachi Ui"="c:\arquivos de programas\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2010-03-18 421888]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2010-04-28 142120]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2010-01-13 13:45 11952 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"=

"c:\\Arquivos de programas\\Ares\\Ares.exe"=

"c:\\Documents and Settings\\windows\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=

"c:\\Arquivos de programas\\Pando Networks\\Media Booster\\PMB.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"=

"c:\\NGM\\NGM.exe"=

"c:\\Arquivos de programas\\Sports Interactive\\Football Manager 2010\\fm.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\DsNET Corp\\aTube Catcher 2.0\\yct.exe"=

"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=

"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=

"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=

"c:\\Riot Games\\League of Legends\\lol.launcher.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57938:TCP"= 57938:TCP:Pando Media Booster

"57938:UDP"= 57938:UDP:Pando Media Booster

"8378:TCP"= 8378:TCP:League of Legends Launcher

"8378:UDP"= 8378:UDP:League of Legends Launcher

"8379:TCP"= 8379:TCP:League of Legends Launcher

"8379:UDP"= 8379:UDP:League of Legends Launcher

"8393:TCP"= 8393:TCP:League of Legends Lobby

"8393:UDP"= 8393:UDP:League of Legends Lobby

"8390:TCP"= 8390:TCP:League of Legends Game Client

"8390:UDP"= 8390:UDP:League of Legends Game Client

"6989:TCP"= 6989:TCP:League of Legends Launcher

"6989:UDP"= 6989:UDP:League of Legends Launcher

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/1/2010 10:45 335240]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/1/2010 10:45 108552]

R2 avg8emc;AVG Free8 E-mail Scanner;c:\arquiv~1\AVG\AVG8\avgemc.exe [13/1/2010 10:45 908056]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [13/1/2010 10:45 297752]

R2 cvhsvc;Client Virtualization Handler;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/2/2010 02:33 821664]

R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\arquivos de programas\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 1107336]

R2 sftlist;Application Virtualization Client;c:\arquivos de programas\Microsoft Application Virtualization Client\sftlist.exe [24/4/2010 01:10 483688]

R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [2/12/2009 22:23 554344]

R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [2/12/2009 22:23 211432]

R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [2/12/2009 22:23 20584]

R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [2/12/2009 22:23 18280]

R3 sftvsa;Application Virtualization Service Agent;c:\arquivos de programas\Microsoft Application Virtualization Client\sftvsa.exe [24/4/2010 01:10 209768]

S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [14/7/2010 19:12 136176]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\windows\CONFIG~1\Temp\RSM4E8.tmp --> c:\docume~1\windows\CONFIG~1\Temp\RSM4E8.tmp [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/4/2010 23:13 691696]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2010-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2009-10-22 14:50]

 

2010-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-07-14 22:11]

 

2010-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-07-14 22:11]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://br.ask.com?o=15425&l=dis

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = *.local

FF - ProfilePath - c:\documents and settings\windows\Dados de aplicativos\Mozilla\Firefox\Profiles\g9cswzeo.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.globo.com/

FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=

FF - plugin: c:\arquiv~1\MICROS~3\Office14\NPSPWRAP.DLL

FF - plugin: c:\arquivos de programas\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\arquivos de programas\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\Pando Networks\Media Booster\npPandoWebPlugin.dll

FF - plugin: c:\docume~1\windows\DADOSD~1\POWERC~1\nppowerloader.dll

FF - plugin: c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\npNxGameUS.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

.

- - - - ORFÃOS REMOVIDOS - - - -

 

BHO-{96D54723-E733-4440-A383-8A621BCF17F2} - c:\windows\system32\flash101flv.dll

 

 

 

**************************************************************************

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos:

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\windows\CONFIG~1\Temp\RSM4E8.tmp"

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-1060284298-1960408961-842925246-1003\Software\G*e*n*i*e*"!\FM Genie Scout 10]

"GameDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\games"

"ShortlistDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\shortlists"

"ScreenshotsDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010"

"SaveDir"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\"

"HistoryDir"="c:\\Documents and Settings\\windows\\Desktop\\FM Genie Scout 10\\History Points"

"LangDB"="c:\\Arquivos de programas\\Sports Interactive\\Football Manager 2010\\data\\updates\\update-1030\\db\\1030\\lang_db.dat"

"LastSaveGame"="c:\\Documents and Settings\\windows\\Meus documentos\\Sports Interactive\\Football Manager 2010\\games\\Alessandro.fm"

"Language"="English"

"LoadLangDB"=dword:00000001

"CompressHistoryPoints"=dword:00000000

"HighlightedAttributes"=dword:00000000

"MinCondition"=dword:00000050

"GraphStep"=dword:00000000

"SkinName"="Steklo Black"

"LastUpdateCheck"=dword:00009da9

"HighQualityGUI"=dword:00000001

"AutomaticallyUpdateCheck"=dword:00000001

"AdvancedGeneration"=dword:00000000

"TranslateStaffSkills"=dword:00000001

"TranslatePlayerSkills"=dword:00000001

"TranslatePositions"=dword:00000001

"ShowHistory"=dword:00000001

"Version"=dword:00000074

"UniqueID"="44-0050-626F"

"Currency"=dword:00000056

"UseProxy"=dword:00000000

"ProxyHost"=""

"ProxyPort"=""

"UseAuthentication"=dword:00000000

"UserName"=""

"UserPassword"=""

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'explorer.exe'(2392)

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\nvsvc32.exe

c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\arquivos de programas\Bonjour\mDNSResponder.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\windows\RTHDCPL.EXE

c:\windows\system32\RUNDLL32.EXE

c:\arquiv~1\AVG\AVG8\avgrsx.exe

c:\arquiv~1\AVG\AVG8\avgnsx.exe

c:\arquivos de programas\AVG\AVG8\avgcsrvx.exe

c:\windows\system32\wscntfy.exe

c:\arquivos de programas\iPod\bin\iPodService.exe

c:\arquivos de programas\Windows Live\Contacts\wlcomm.exe

.

**************************************************************************

.

Tempo para conclusão: 2010-08-02 22:26:50 - Máquina reiniciou

ComboFix-quarantined-files.txt 2010-08-03 01:26

ComboFix2.txt 2010-07-16 17:01

 

Pré-execução: 17 pasta(s) 43.087.319.040 bytes disponíveis

Pós execução: 18 pasta(s) 43.092.529.152 bytes disponíveis

 

- - End Of File - - EC981786FCFF490E82E8373288B2ED47

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...log limpo.

 

1.

*Clique em [iniciar] > [Executar] > digite: Combofix /uninstall

*Clique [OK]

 

92674490.jpg

 

*Clique em [Executar]

*Aguarde surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

2.

*Delete o SystemLook e seu relatório.

 

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.