lucasbsp 0 Denunciar post Postado Novembro 26, 2010 olá gostaria que vcs me ajudassem a tirar um virus que nao consigo retirar e ja formatei os hds aguardo ancioso obrigado Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:53:31, on 11/25/aaaa Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.20627) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\VM305_STI.EXE C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Windows Media Player\wmplayer.exe C:\Documents and Settings\Lucas\Meus documentos\Downloads\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://so92.com/? O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [uSB Antivirus] C:\Arquivos de programas\USB Disk Security\USBGuard.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [unlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ccleaner] "C:\Arquivos de programas\CCleaner\CCleaner.exe" /AUTO O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0E73B4-96AE-4D5B-9CD1-48F0473B9492}: NameServer = 10.0.1.254 O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 5671 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 Olá lucasbsp *Faça um scan online com o NOD32 *Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 26, 2010 Olá Wings fiz o scaneamento lembrando que ele travou em 70% aguardei 1hora e nd depois conclui. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=623a8f04a5d4d84a803ca57c12af8f9c # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-26 04:07:53 # local_time=2010-11-26 02:07:53 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=52858 # found=6 # cleaned=6 # scan_time=2361 D:\backup\pc cruel\profiles\Downloads\Desflasheando w300i\Programas\Far Manager\Plugins\SEFP\sefp0.10.0.51patch.exe probably a variant of Win32/Agent.NMZPOJA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\programas\sound forge 8.0\keygen - Sound Forge 8.0.exe a variant of Win32/Keygen.AQ application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\Utilitários básicos\nero 7 full\Nero-7.7.5.1_ptb_trial.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\programas\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\programas\unlocker1.8.7.exe a variant of Win32/Adware.ADON application (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\programas\nero 7 full\Nero-7.7.5.1_ptb_trial.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=623a8f04a5d4d84a803ca57c12af8f9c # end=stopped # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-11-26 05:58:28 # local_time=2010-11-26 03:58:28 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=49884 # found=10 # cleaned=10 # scan_time=6369 D:\backup\DEKSTOP\Downloads\crack + keygen NFS.www.therebels.biz.rar probably a variant of Win32/Agent.BXDOMKW trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\backup\pc cruel\profiles\Downloads\Desflash_w300i.zip probably a variant of Win32/Agent.NMZPOJA trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\backup\pc cruel\profiles\Downloads\SETOOL v0.915034.rar a variant of Win32/Packed.Themida application (deleted - quarantined) 00000000000000000000000000000000 C D:\backup\pc cruel\profiles\Downloads\ultrasurf.zip Win32/UltraReach application (deleted - quarantined) 00000000000000000000000000000000 C D:\backup\pc cruel\profiles\Downloads\Desflasheando w300i\Programas\Far Manager.zip probably a variant of Win32/Agent.NMZPOJA trojan (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\systempassrec4134.rar Win32/PassRecovery application (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\mailpv\mailpv.exe Win32/MailPassView.132 application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\System Password Recovery 4.1.3.4.455 + Serial\setup.exe Win32/PassRecovery application (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\programas\WinXP keyChanger.exe Win32/PSWTool.RAS.A application (deleted - quarantined) 00000000000000000000000000000000 C D:\Meus documentos\Pen driver\Utilitários básicos\nero 7 full\Nero.Premium.Edition.v7.0.5.4.Incl.KeyMaker.REPACK-DVT.ZIP probably a variant of Win32/Agent.HZREFUA trojan (deleted - quarantined) 00000000000000000000000000000000 C Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 1. *Desative seu antivírus temporariamente *Baixe o RSIT e salve-o no desktop *Execute o RSIT e clique [Continue] *Cole o relatório C:\rsit\log.txt 2. *Baixe o GMER e salve-o no desktop *Crie uma pasta chamada GMER em C:\ e extraia para lá *Feche todos os programas ativos (MSN, IE, Firefox, etc...) *Desative temporariamente o antivírus *Execute o gmer *Se receber um aviso sobre atividade de rootkit clique [Não] *Desmarque [] IAT/EAT *Clique [scan] e aguarde. Pode demorar.... *Ao finalizar, clique [save...] *Salve no desktop como gmer *Cole o relatório gmer.txt Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 26, 2010 Segue os logs Logfile of random's system information tool 1.08 (written by random/random) Run by Lucas at 2010-11-26 13:57:06 Microsoft Windows XP Professional Service Pack 2 System drive C: has 67 GB (87%) free of 76 GB Total RAM: 1023 MB (74% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 13:57:28, on 11/26/aaaa Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.20627) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\VM305_STI.EXE C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Documents and Settings\Lucas\Desktop\RSIT.exe C:\Arquivos de programas\trend micro\Lucas.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://so92.com/? O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [uSB Antivirus] C:\Arquivos de programas\USB Disk Security\USBGuard.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [unlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ccleaner] "C:\Arquivos de programas\CCleaner\CCleaner.exe" /AUTO O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0E73B4-96AE-4D5B-9CD1-48F0473B9492}: NameServer = 10.0.1.254 O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 5398 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll [2010-11-22 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-22 79648] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "USB Antivirus"=C:\Arquivos de programas\USB Disk Security\USBGuard.exe [2008-08-16 798720] "NeroFilterCheck"=C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [2006-01-12 155648] "UnlockerAssistant"=C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe [2008-05-02 15872] "SunJavaUpdateSched"=C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe [2010-02-18 248040] "BigDog305"=C:\WINDOWS\VM305_STI.EXE [2005-08-05 61440] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-10 7286784] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-10 86016] "Adobe Reader Speed Launcher"=C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760] "Adobe ARM"=C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"=C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [2007-01-15 147456] "ccleaner"=C:\Arquivos de programas\CCleaner\CCleaner.exe [2010-04-23 1668920] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2007-07-21 15360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [] Ad-Aware Update (Weekly).job SA.DAT [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2007-09-02 133632] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=323 "NoDriveAutoRun"=67108863 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"=67108863 "NoDriveTypeAutoRun"=323 "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" ======File associations====== .inf - open - Notepad.exe "%1" .ini - open - Notepad.exe "%1" .js - open - WScript.exe "%1" %* .txt - open - Notepad.exe "%1" .vbs - open - WScript.exe "%1" %* ======List of files/folders created in the last 1 months====== 2010-11-26 13:57:06 ----D---- C:\rsit 2010-11-26 13:57:06 ----D---- C:\Arquivos de programas\trend micro 2010-11-26 00:29:44 ----D---- C:\Arquivos de programas\ESET 2010-11-26 00:02:06 ----D---- C:\Nova pasta 2010-11-25 23:31:12 ----A---- C:\mbr.exe 2010-11-25 23:03:01 ----ASH---- C:\hiberfil.sys 2010-11-25 22:18:26 ----SHD---- C:\Config.Msi 2010-11-25 22:18:14 ----D---- C:\WINDOWS\SxsCaPendDel 2010-11-25 21:13:02 ----A---- C:\InfoSat.txt 2010-11-25 04:32:38 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com 2010-11-25 04:32:32 ----D---- C:\Arquivos de programas\SUPERAntiSpyware 2010-11-25 03:57:36 ----SHD---- C:\RECYCLER 2010-11-25 01:46:29 ----A---- C:\ComboFix.txt 2010-11-25 01:22:44 ----D---- C:\WINDOWS\Minidump 2010-11-24 21:01:25 ----D---- C:\Arquivos de programas\ToniArts 2010-11-24 19:40:49 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe 2010-11-24 19:40:02 ----D---- C:\Arquivos de programas\Arquivos comuns\Adobe 2010-11-24 19:40:02 ----D---- C:\Arquivos de programas\Adobe 2010-11-24 15:45:55 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\TeamViewer 2010-11-24 15:45:50 ----D---- C:\Arquivos de programas\TeamViewer 2010-11-24 15:18:03 ----D---- C:\WINDOWS\Sun 2010-11-24 00:58:26 ----D---- C:\Arquivos de programas\GameVicio 2010-11-24 00:48:18 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll 2010-11-24 00:41:04 ----D---- C:\Arquivos de programas\Sierra 2010-11-24 00:16:36 ----A---- C:\WINDOWS\ODBC.INI 2010-11-24 00:16:32 ----A---- C:\WINDOWS\system32\mdimon.dll 2010-11-24 00:15:34 ----D---- C:\Arquivos de programas\Microsoft.NET 2010-11-24 00:15:01 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER 2010-11-24 00:14:49 ----D---- C:\WINDOWS\SHELLNEW 2010-11-24 00:14:46 ----D---- C:\Arquivos de programas\Microsoft Office 2010-11-24 00:13:42 ----RD---- C:\MSOCache 2010-11-23 19:25:01 ----D---- C:\Arquivos de programas\Marcos Velasco Security 2010-11-23 15:16:09 ----A---- C:\WINDOWS\NeroDigital.ini 2010-11-23 15:16:06 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Media Player Classic 2010-11-23 15:07:05 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Malwarebytes 2010-11-23 15:06:56 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes 2010-11-23 13:46:50 ----A---- C:\WINDOWS\system32\CF26396.exe 2010-11-23 13:16:05 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer 2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\rmoc3260.dll 2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pndx5032.dll 2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pndx5016.dll 2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pncrt.dll 2010-11-23 13:15:53 ----A---- C:\WINDOWS\system32\x264vfw.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\xvidvfw.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\xvidcore.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\WMV9VCM.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\ssldivx.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\qt-dx331.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\libdivx.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\dtu100.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\dpl100.dll 2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\divx.dll 2010-11-23 13:15:51 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest 2010-11-23 13:15:51 ----A---- C:\WINDOWS\system32\ff_vfw.dll 2010-11-23 13:15:50 ----A---- C:\WINDOWS\system32\msvcr71.dll 2010-11-23 13:15:49 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Real 2010-11-23 13:15:49 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Real 2010-11-23 13:15:49 ----D---- C:\Arquivos de programas\K-Lite Codec Pack 2010-11-23 13:15:49 ----A---- C:\WINDOWS\system32\msvcp71.dll 2010-11-23 12:33:54 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2010-11-23 00:44:03 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\TS3Client 2010-11-23 00:42:45 ----D---- C:\Arquivos de programas\TeamSpeak 3 Client 2010-11-22 21:57:40 ----D---- C:\WINDOWS\nview 2010-11-22 21:57:39 ----A---- C:\WINDOWS\system32\nvudisp.exe 2010-11-22 21:57:05 ----D---- C:\WINDOWS\system32\ReinstallBackups 2010-11-22 21:56:24 ----A---- C:\WINDOWS\system32\NVUNINST.EXE 2010-11-22 21:39:49 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys 2010-11-22 21:39:48 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys 2010-11-22 21:39:47 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys 2010-11-22 21:39:46 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys 2010-11-22 21:39:44 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2010-11-22 21:39:43 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys 2010-11-22 21:39:41 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys 2010-11-22 21:39:32 ----A---- C:\WINDOWS\system32\vfwwdm32.dll 2010-11-22 21:39:30 ----RA---- C:\WINDOWS\VM305_STI.EXE 2010-11-22 21:39:30 ----RA---- C:\WINDOWS\system32\VM305STI.dll 2010-11-22 21:39:30 ----RA---- C:\WINDOWS\system32\drivers\usbVM305.sys 2010-11-22 21:39:30 ----R---- C:\WINDOWS\Zoom.exe 2010-11-22 21:39:30 ----R---- C:\WINDOWS\VMPipe.dll 2010-11-22 21:39:29 ----RA---- C:\WINDOWS\amcap.exe 2010-11-22 21:39:29 ----D---- C:\WINDOWS\EffectResources 2010-11-22 21:39:29 ----A---- C:\WINDOWS\VM303UninstNT.exe 2010-11-22 21:33:50 ----HD---- C:\WINDOWS\PIF 2010-11-22 19:30:12 ----D---- C:\Arquivos de programas\FlashGet 2010-11-22 17:24:17 ----D---- C:\Arquivos de programas\FlashGet Network 2010-11-22 16:05:55 ----D---- C:\Arquivos de programas\xerox 2010-11-22 16:05:54 ----D---- C:\WINDOWS\system32\xircom 2010-11-22 16:05:54 ----D---- C:\Arquivos de programas\microsoft frontpage 2010-11-22 16:01:06 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Sun 2010-11-22 16:01:06 ----D---- C:\Arquivos de programas\Arquivos comuns\Java 2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\javaws.exe 2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\javaw.exe 2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\java.exe 2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\deploytk.dll 2010-11-22 16:00:28 ----D---- C:\Arquivos de programas\Java 2010-11-22 16:00:06 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Sun 2010-11-22 15:10:04 ----D---- C:\WINDOWS\temp 2010-11-22 15:04:04 ----A---- C:\WINDOWS\libem.INI 2010-11-22 15:04:00 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\FlashGet 2010-11-22 15:03:55 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\FlashGetBHO 2010-11-22 15:02:22 ----D---- C:\Arquivos de programas\CCleaner 2010-11-22 14:50:06 ----A---- C:\WINDOWS\system32\spupdsvc.exe 2010-11-22 14:49:01 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage 2010-11-22 14:44:31 ----D---- C:\Arquivos de programas\Unlocker 2010-11-22 14:40:37 ----D---- C:\Arquivos de programas\VS Revo Group 2010-11-22 14:38:58 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\BITS 2010-11-22 14:38:47 ----D---- C:\profiles 2010-11-22 14:32:37 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Ahead 2010-11-22 14:31:35 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Nero 2010-11-22 14:31:35 ----D---- C:\Arquivos de programas\Nero 2010-11-22 14:31:35 ----D---- C:\Arquivos de programas\Arquivos comuns\Ahead 2010-11-22 14:30:22 ----A---- C:\WINDOWS\system32\d3dx9_30.dll 2010-11-22 14:30:21 ----A---- C:\WINDOWS\system32\d3dx9_28.dll 2010-11-21 11:56:05 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Macromedia 2010-11-21 11:56:04 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Adobe 2010-11-21 11:55:28 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Mozilla 2010-11-21 11:42:43 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Identities 2010-11-21 11:42:19 ----SD---- C:\Documents and Settings\Lucas\Dados de aplicativos\Microsoft 2010-11-21 11:42:19 ----ASH---- C:\Documents and Settings\Lucas\Dados de aplicativos\desktop.ini 2010-11-21 11:41:27 ----D---- C:\WINDOWS\Prefetch 2010-11-21 11:39:25 ----D---- C:\WINDOWS\system32\dllcache 2010-11-21 11:38:53 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest 2010-11-21 11:33:01 ----A---- C:\WINDOWS\system32\drivers\fetnd5.sys 2010-11-21 09:43:11 ----A---- C:\WINDOWS\system32\drivers\SBREDrv.sys 2010-11-21 09:24:02 ----ASH---- C:\pagefile.sys 2010-11-21 08:42:59 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Lavasoft 2010-11-21 05:23:00 ----D---- C:\WINDOWS\ERDNT 2010-11-21 04:04:56 ----D---- C:\Arquivos de programas\Mozilla Firefox 2010-11-21 04:01:30 ----D---- C:\Arquivos de programas\Microsoft 2010-11-21 04:01:17 ----D---- C:\Arquivos de programas\Windows Live SkyDrive 2010-11-21 04:00:57 ----D---- C:\Arquivos de programas\Windows Live 2010-11-21 03:59:41 ----D---- C:\Arquivos de programas\Arquivos comuns\Windows Live 2010-11-21 03:58:33 ----D---- C:\WINDOWS\pss 2010-11-21 03:52:06 ----D---- C:\Arquivos de programas\USB Disk Security 2010-11-21 03:51:50 ----A---- C:\WINDOWS\system32\drivers\AegisP.sys 2010-11-21 03:51:46 ----DC---- C:\WINDOWS\system32\DRVSTORE 2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\Install6x.dll 2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\drivers\rt61.sys 2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\AegisI5.exe 2010-11-21 03:51:32 ----D---- C:\Arquivos de programas\RALINK 2010-11-21 03:49:56 ----D---- C:\Arquivos de programas\WinRAR 2010-11-21 03:49:11 ----A---- C:\WINDOWS\system32\drivers\splitter.sys 2010-11-21 03:49:10 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys 2010-11-21 03:47:36 ----N---- C:\WINDOWS\system32\ksuser.dll 2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\wdmioctl.dll 2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\drivers\smsens.sys 2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\drivers\aeaudio.sys 2010-11-21 03:47:33 ----A---- C:\WINDOWS\system32\SMMedia.dll 2010-11-21 03:47:32 ----A---- C:\WINDOWS\SynthCoreA.Dll 2010-11-21 03:47:32 ----A---- C:\WINDOWS\SynCor.exe 2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\SynthCore11Resources.dll 2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\Syncor11.dll 2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\S11thk32.dll 2010-11-21 03:47:28 ----D---- C:\WINDOWS\VirtualEar 2010-11-21 03:47:28 ----A---- C:\WINDOWS\system32\Audio3d.dll 2010-11-21 03:47:27 ----A---- C:\WINDOWS\system32\virtear.dll 2010-11-21 03:47:26 ----D---- C:\Arquivos de programas\Analog Devices 2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\drivers\smwdm.sys 2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\CleanUp.exe 2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\a3d.dll 2010-11-21 03:47:25 ----HD---- C:\Arquivos de programas\InstallShield Installation Information 2010-11-21 03:47:25 ----A---- C:\WINDOWS\system32\DSndUp.exe 2010-11-21 03:47:17 ----D---- C:\Arquivos de programas\Arquivos comuns\InstallShield 2010-11-21 03:47:02 ----A---- C:\WINDOWS\Ascd_tmp.ini 2010-11-21 03:46:59 ----A---- C:\WINDOWS\system32\drivers\ASUSHWIO.SYS 2010-11-21 03:45:46 ----HD---- C:\Arquivos de programas\Uninstall Information 2010-11-21 03:40:21 ----D---- C:\WINDOWS\SoftwareDistribution 2010-11-21 03:40:20 ----SD---- C:\WINDOWS\system32\Microsoft 2010-11-21 03:40:20 ----N---- C:\WINDOWS\SchedLgU.Txt 2010-11-21 03:39:01 ----A---- C:\WINDOWS\system32\tzchange.exe 2010-11-21 03:38:58 ----HD---- C:\WINDOWS\$hf_mig$ 2010-11-21 03:38:51 ----N---- C:\WINDOWS\system32\spmsg.dll 2010-11-21 03:38:45 ----D---- C:\Arquivos de programas\MSXML 6.0 2010-11-21 03:38:42 ----D---- C:\Arquivos de programas\MSXML 4.0 2010-11-21 03:38:34 ----RASH---- C:\MSDOS.SYS 2010-11-21 03:38:34 ----RASH---- C:\IO.SYS 2010-11-21 03:38:34 ----A---- C:\WINDOWS\control.ini 2010-11-21 03:38:34 ----A---- C:\CONFIG.SYS 2010-11-21 03:38:34 ----A---- C:\AUTOEXEC.BAT 2010-11-21 03:38:22 ----A---- C:\WINDOWS\system32\mapi32.dll 2010-11-21 03:37:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest 2010-11-21 03:37:33 ----HD---- C:\Arquivos de programas\WindowsUpdate 2010-11-21 03:37:32 ----D---- C:\Arquivos de programas\Serviços on-line 2010-11-21 03:37:14 ----D---- C:\WINDOWS\system32\DirectX 2010-11-21 03:36:42 ----A---- C:\WINDOWS\system32\atrace.dll 2010-11-21 03:36:38 ----A---- C:\WINDOWS\system32\desktop.ini 2010-11-21 03:36:38 ----A---- C:\WINDOWS\desktop.ini 2010-11-21 03:36:28 ----A---- C:\WINDOWS\system32\nmevtmsg.dll 2010-11-21 03:36:26 ----A---- C:\WINDOWS\system32\acctres.dll 2010-11-21 03:36:25 ----D---- C:\Arquivos de programas\Arquivos comuns\Serviços 2010-11-21 03:36:21 ----SD---- C:\WINDOWS\Tasks 2010-11-21 03:36:21 ----A---- C:\WINDOWS\system32\icfgnt5.dll 2010-11-21 03:36:19 ----D---- C:\Arquivos de programas\Arquivos comuns\MSSoap 2010-11-21 03:36:13 ----D---- C:\WINDOWS\srchasst 2010-11-21 03:36:11 ----D---- C:\WINDOWS\system32\Macromed 2010-11-21 03:36:09 ----A---- C:\WINDOWS\system32\wuweb.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wups.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wucltui.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauserv.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuaueng1.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuaueng.dll 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauclt1.exe 2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauclt.exe 2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\wuapi.dll 2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\qmgrprxy.dll 2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\qmgr.dll 2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\bitsprx3.dll 2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\bitsprx2.dll 2010-11-21 03:36:02 ----D---- C:\Arquivos de programas\Movie Maker 2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrslv.dll 2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrdm.dll 2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrcdlg.dll 2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\racpldlg.dll 2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\fltMc.exe 2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\fltlib.dll 2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys 2010-11-21 03:35:48 ----D---- C:\WINDOWS\system32\Restore 2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srsvc.dll 2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srrstr.dll 2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srclient.dll 2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\drivers\sr.sys 2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\mnmdd.dll 2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\isrdbg32.dll 2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\ils.dll 2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\nmmkcert.dll 2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\msconf.dll 2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\mnmsrvc.exe 2010-11-21 03:35:42 ----D---- C:\Arquivos de programas\NetMeeting 2010-11-21 03:35:41 ----A---- C:\WINDOWS\system32\msoert2.dll 2010-11-21 03:35:41 ----A---- C:\WINDOWS\system32\msoeacct.dll 2010-11-21 03:35:40 ----A---- C:\WINDOWS\system32\inetres.dll 2010-11-21 03:35:39 ----A---- C:\WINDOWS\system32\inetcomm.dll 2010-11-21 03:35:37 ----D---- C:\Arquivos de programas\Outlook Express 2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\schedsvc.dll 2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\mstinit.exe 2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\mstask.dll 2010-11-21 03:35:36 ----A---- C:\WINDOWS\system32\icwphbk.dll 2010-11-21 03:35:36 ----A---- C:\WINDOWS\system32\icwdial.dll 2010-11-21 03:35:35 ----A---- C:\WINDOWS\system32\isign32.dll 2010-11-21 03:35:35 ----A---- C:\WINDOWS\system32\inetcfg.dll 2010-11-21 03:35:27 ----D---- C:\Arquivos de programas\Arquivos comuns\System 2010-11-21 03:35:25 ----D---- C:\Arquivos de programas\Internet Explorer 2010-11-21 03:34:59 ----D---- C:\Arquivos de programas\ComPlus Applications 2010-11-21 03:34:59 ----A---- C:\WINDOWS\vbaddin.ini 2010-11-21 03:34:59 ----A---- C:\WINDOWS\vb.ini 2010-11-21 03:34:58 ----D---- C:\WINDOWS\Registration 2010-11-21 03:34:53 ----D---- C:\Arquivos de programas\Windows Media Connect 2 2010-11-21 03:34:51 ----D---- C:\Arquivos de programas\Windows Media Player 2010-11-21 03:34:49 ----D---- C:\Arquivos de programas\Messenger 2010-11-21 03:34:43 ----D---- C:\Arquivos de programas\MSN Gaming Zone 2010-11-21 03:34:43 ----A---- C:\WINDOWS\system32\write.exe 2010-11-21 03:34:30 ----A---- C:\WINDOWS\system32\sndvol32.exe 2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\hticons.dll 2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avwav.dll 2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avtapi.dll 2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avmeter.dll 2010-11-21 03:34:28 ----A---- C:\WINDOWS\system32\winchat.exe 2010-11-21 03:34:18 ----A---- C:\WINDOWS\system32\getuname.dll 2010-11-21 03:34:18 ----A---- C:\WINDOWS\system32\charmap.exe 2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\winmine.exe 2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\sol.exe 2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\calc.exe 2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\reset.exe 2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\mshearts.exe 2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\freecell.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\usrlogon.cmd 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tsshutdn.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tslabels.ini 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tskill.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tsdiscon.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tscon.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\shadow.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\rwinsta.exe 2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\regini.exe 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\rdpcfgex.dll 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\qwinsta.exe 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\qappsrv.exe 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\msg.exe 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\msdtcprf.ini 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\logoff.exe 2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\cdmodem.dll 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxlegih.dll 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxex.dll 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxdm.dll 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\dcomcnfg.exe 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\comrepl.dll 2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\comaddin.dll 2010-11-21 03:34:11 ----A---- C:\WINDOWS\system32\stclient.dll 2010-11-21 03:34:11 ----A---- C:\WINDOWS\system32\comsnap.dll 2010-11-21 03:34:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc 2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\sndrec32.exe 2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\mplay32.exe 2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\accwiz.exe 2010-11-21 03:34:01 ----D---- C:\Arquivos de programas\Windows NT 2010-11-21 03:34:01 ----A---- C:\WINDOWS\system32\hypertrm.dll 2010-11-21 03:34:00 ----A---- C:\WINDOWS\system32\mspaint.exe 2010-11-21 03:34:00 ----A---- C:\WINDOWS\system32\clipbrd.exe 2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\tscfgwmi.dll 2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\spider.exe 2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys 2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys 2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\sessmgr.exe 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\remotepg.dll 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdshost.exe 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdsaddin.exe 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdchost.dll 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\mstscax.dll 2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\mstsc.exe 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\tscupgrd.exe 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\termsrv.dll 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpwsx.dll 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpsnd.dll 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpclip.exe 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\qprocess.exe 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\icaapi.dll 2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\cfgbkend.dll 2010-11-21 03:33:56 ----D---- C:\WINDOWS\system32\MsDtc 2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\mtxoci.dll 2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\msdtcuiu.dll 2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\msdtcprx.dll 2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\xolehlp.dll 2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtctm.dll 2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtclog.dll 2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtc.exe 2010-11-21 03:33:53 ----D---- C:\WINDOWS\system32\Com 2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\colbact.dll 2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\clbcatex.dll 2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\catsrvps.dll 2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\comsvcs.dll 2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\catsrvut.dll 2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\catsrv.dll 2010-11-21 03:33:51 ----A---- C:\WINDOWS\system32\comuid.dll 2010-11-21 03:33:51 ----A---- C:\WINDOWS\system32\clbcatq.dll 2010-11-21 03:33:44 ----A---- C:\WINDOWS\system32\servdeps.dll 2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\mmfutil.dll 2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\licwmi.dll 2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\cmprops.dll 2010-11-21 03:33:39 ----A---- C:\WINDOWS\system32\drivers\termdd.sys 2010-11-21 03:33:39 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys 2010-11-21 01:33:28 ----A---- C:\WINDOWS\system32\h323log.txt 2010-11-21 01:33:07 ----A---- C:\WINDOWS\system32\drivers\audstub.sys 2010-11-21 01:32:36 ----A---- C:\WINDOWS\system32\drivers\redbook.sys 2010-11-21 01:32:22 ----A---- C:\WINDOWS\system32\storprop.dll 2010-11-21 01:32:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll 2010-11-21 01:32:20 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys 2010-11-21 01:32:04 ----A---- C:\WINDOWS\system32\drivers\GAGP30KX.SYS 2010-11-21 01:31:21 ----SHD---- C:\WINDOWS\Installer 2010-11-21 01:31:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2010-11-21 01:31:20 ----D---- C:\Arquivos de programas\Arquivos comuns\ODBC 2010-11-21 01:31:20 ----A---- C:\WINDOWS\ODBCINST.INI 2010-11-21 01:31:17 ----D---- C:\Arquivos de programas\Arquivos comuns\SpeechEngines 2010-11-21 01:31:16 ----RD---- C:\Arquivos de programas 2010-11-21 01:31:16 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared 2010-11-21 01:31:16 ----D---- C:\Arquivos de programas\Arquivos comuns 2010-11-21 01:30:40 ----ASH---- C:\Documents and Settings\All Users\Dados de aplicativos\desktop.ini 2010-11-21 01:30:20 ----D---- C:\WINDOWS\system32\CatRoot2 2010-11-21 01:30:20 ----D---- C:\WINDOWS\system32\CatRoot 2010-11-21 01:30:15 ----SD---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft 2010-11-21 01:29:46 ----D---- C:\Documents and Settings 2010-11-21 01:29:45 ----SHD---- C:\System Volume Information 2010-11-21 01:23:46 ----SH---- C:\boot.ini 2010-11-21 01:20:12 ----D---- C:\WINDOWS\OemDir 2010-11-21 01:20:06 ----SD---- C:\WINDOWS\Downloaded Program Files 2010-11-21 01:20:06 ----RSD---- C:\WINDOWS\Fonts 2010-11-21 01:20:06 ----RD---- C:\WINDOWS\Web 2010-11-21 01:20:06 ----HD---- C:\WINDOWS\inf 2010-11-21 01:20:06 ----D---- C:\WINDOWS\WinSxS 2010-11-21 01:20:06 ----D---- C:\WINDOWS\WBEM 2010-11-21 01:20:06 ----D---- C:\WINDOWS\twain_32 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\wins 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\wbem 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\usmt 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\spool 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ShellExt 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\Setup 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ras 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\pt-br 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\oobe 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\npp 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\mui 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\inetsrv 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\IME 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\icsxml 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ias 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\export 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\UMDF 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\etc 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\disdn 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\dhcp 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\config 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\3com_dmi 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\3076 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\2052 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1054 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1046 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1042 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1041 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1037 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1033 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1031 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1028 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1025 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32 2010-11-21 01:20:06 ----D---- C:\WINDOWS\system 2010-11-21 01:20:06 ----D---- C:\WINDOWS\security 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Resources 2010-11-21 01:20:06 ----D---- C:\WINDOWS\repair 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Provisioning 2010-11-21 01:20:06 ----D---- C:\WINDOWS\PeerNet 2010-11-21 01:20:06 ----D---- C:\WINDOWS\pchealth 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Offline Web Pages 2010-11-21 01:20:06 ----D---- C:\WINDOWS\mui 2010-11-21 01:20:06 ----D---- C:\WINDOWS\msapps 2010-11-21 01:20:06 ----D---- C:\WINDOWS\msagent 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Media 2010-11-21 01:20:06 ----D---- C:\WINDOWS\java 2010-11-21 01:20:06 ----D---- C:\WINDOWS\ime 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Help 2010-11-21 01:20:06 ----D---- C:\WINDOWS\ehome 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Driver Cache 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Debug 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Cursors 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Connection Wizard 2010-11-21 01:20:06 ----D---- C:\WINDOWS\Config 2010-11-21 01:20:06 ----D---- C:\WINDOWS\AppPatch 2010-11-21 01:20:06 ----D---- C:\WINDOWS\addins 2010-11-21 01:20:06 ----D---- C:\WINDOWS ======List of files/folders modified in the last 1 months====== 2010-11-25 21:19:12 ----A---- C:\WINDOWS\win.ini 2010-11-25 21:19:12 ----A---- C:\WINDOWS\system.ini 2010-11-21 11:39:15 ----ASH---- C:\WINDOWS\fonts\desktop.ini ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2004-08-03 46464] R0 viamraid;viamraid; C:\WINDOWS\system32\drivers\viamraid.sys [2005-04-26 60928] R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2007-07-21 14848] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-11-21 21419] R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816] R3 hidusb;Driver de classe HID da Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2007-07-21 9600] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-10 3530432] R3 RT61;Ralink RT61 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2006-08-02 384384] R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368] R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2007-07-21 31616] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2007-07-21 20480] R3 ZSMC0305;A4 TECH PC Camera V; C:\WINDOWS\System32\Drivers\usbVM305.sys [2006-05-08 391688] S3 catchme;catchme; \??\C:\DOCUME~1\Lucas\CONFIG~1\Temp\catchme.sys [] S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165] S3 MSTEE;Conversor em T entre locais de fluxo contínuo Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Conexão de TV e vídeo da Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136] S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360] S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2007-07-21 26496] S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2007-09-02 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2007-09-02 82944] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 JavaQuickStarterService;Java Quick Starter; C:\Arquivos de programas\Java\jre6\bin\jqs.exe [2010-11-22 153376] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-10 131139] R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056] R3 NMIndexingService;NMIndexingService; C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [2007-01-15 266240] S3 NBService;NBService; C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144] S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 WMPNetworkSvc;Serviço de Compartilhamento de Rede do Windows Media Player; C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe [2006-11-02 914944] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2007-07-21 14336] -----------------EOF----------------- GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2010-11-26 14:17:45 Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Scsi\viamraid1Port2Path0Target0Lun0 SAMSUNG_ rev.SU10 Running: gmer.exe; Driver: C:\DOCUME~1\Lucas\CONFIG~1\Temp\kwliqkoc.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6F63360, 0x20469D, 0xE8000020] ---- EOF - GMER 1.0.15 ---- Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 *Baixe o OTC e salve-o no desktop *Execute o OTC e clique em [CleanUp!] Seus logs estão limpos. Ainda com problema? Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 26, 2010 Então wings fiz todos os procedimentos que você me falou mas quando atualizo o combofix e ele escanear mostra o seguinte foi detectado rootkit no seu sistema e deve ser reiniciado agora nao sei se pelos logs da pra você saber mas tenho 2 hds um de 80gb que eh para o sistema e um de 160gb que eh para backup tem como esse virus ter infiltrado nos meus arquivos? abrass aguardo resposta Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 Combofix não é uma ferramenta para ser usada como antivírus! Seu uso é complexo e pode acarretar alterações no sistema. De onde você baixou o combofix? Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 26, 2010 Eu sei mas não uso ele como anti virus e sim quando eu acho que tem algum malware que o antivirus nao pega baixei ele no baixaki wings! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 1. *Execute o arquivo c:\Arquivos de programas\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe 2. *Desative temporariamente seu antivírus *Baixe o ComboFix e salve-o no desktop *Execute o Combofix e aceite o contrato *Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso contrário, clique [sIM] para instalar e depois [sIM] para continuar. *Aguarde a conclusão de todas as etapas *Não use o mouse e o teclado durante a execução do Combofix!!..... Para interromper o procedimento tecle [N] ou [2] e depois [ENTER] *Cole o relatório C:\combofix.txt *Se for reiniciar o PC haverá uma opção, na inicialização, chamada Console de Recuperação. Não entre no Windows através da mesma desde que devidamente orientado(a)! Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 26, 2010 Então wings fiz o procedimento igual você mostra no tópico quando om combofix começa a verificar arquivos e ficheiros segue a seguinte mensagem apos alguns minutos "O COMBOFIX DETECTOU A PRESENÇA DE ATIVIDADE DE ROOTKIT E PRECISA REINICIAR A MÁQUINA.Renicio a maquina normalmente ele faz os procedimentos padrão e abaixo segue o log ComboFix 10-11-25.06 - Lucas 11/26/aaaa 18:04:27.11.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1023.807 [GMT -2:00] Executando de: c:\documents and settings\Lucas\Desktop\ComboFix.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2010-10-26 to 2010-11-26 )))))))))))))))))))))))))))) . 2010-11-24 02:13 . 2010-11-24 02:13 -------- d-----r- C:\MSOCache 2010-11-22 16:38 . 2010-11-22 16:38 -------- d-----w- C:\profiles . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . . ------- Sigcheck ------- [-] 2007-09-03 . BD8686216E34E22C4ED45A2320B2BEA1 . 360576 . . [5.1.2600.2892] . . c:\windows\system32\drivers\tcpip.sys [-] 2007-09-02 . DB3AA410ED1228B9DF98C06549AE0763 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll [-] 2007-09-02 17:20 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456] "ccleaner"="c:\arquivos de programas\CCleaner\CCleaner.exe" [2010-04-23 1668920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "USB Antivirus"="c:\arquivos de programas\USB Disk Security\USBGuard.exe" [2008-08-16 798720] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "UnlockerAssistant"="c:\arquivos de programas\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872] "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-02-18 248040] "BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-07-21 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2007-07-21 44544] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] 2005-10-10 13:49 1519616 ----a-w- c:\windows\system32\nwiz.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [11/22/aaaa 21:39 391688] . Conteúdo da pasta 'Tarefas Agendadas' . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ TCP: {8D0E73B4-96AE-4D5B-9CD1-48F0473B9492} = 10.0.1.254 FF - ProfilePath - c:\documents and settings\Lucas\Dados de aplicativos\Mozilla\Firefox\Profiles\zawixtqt.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll . . ------- Associação de arquivos/ficheiros ------- . inifile=Notepad.exe "%1" txtfile=Notepad.exe "%1" . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-11-26 18:07 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@?????????????? Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 5.1.2600 Disk: SAMSUNG_ rev.SU10 -> Harddisk0\DR0 -> \Device\Scsi\viamraid1Port2Path0Target2Lun0 device: opened successfully user: MBR read successfully Disk trace: called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys SCSIPORT.SYS hal.dll viamraid.sys c:\docume~1\Lucas\CONFIG~1\Temp\catchme.sys c:\windows\system32\drivers\viamraid.sys VIA Technologies inc,.ltd VIA RAID driver 1 ntkrnlpa!IofCallDriver[0x804EE0F6] -> \Device\Harddisk0\DR0[0x86592AB8] 3 CLASSPNP[0xF762D05B] -> ntkrnlpa!IofCallDriver[0x804EE0F6] -> \Device\Scsi\viamraid1Port2Path0Target0Lun0[0x86586A38] kernel: MBR read successfully _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; } user != kernel MBR !!! sectors 156368014 (+255): user != kernel ************************************************************************** . Tempo para conclusão: 2010-11-26 18:08:52 ComboFix-quarantined-files.txt 2010-11-26 20:08 Pré-execução: 6 pasta(s) 70.128.513.024 bytes disponíveis Pós execução: 8 pasta(s) 70.130.139.136 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - DBE569F4041376428D0BB040D8368DBB esqueci de ressaltar quando entro em minha unidade D: aparece o RECYLCLER Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 26, 2010 1. *Baixe o TDSSKiller e salve-o no desktop *Extraia para o desktop e execute o TDSSKiller *Clique [start Scan] *Caso encontre algo, clique na seta ao lado da palavra "Cure" e selecione "Skip" *Clique [Continue] *Ao término, clique [Close] *Cole o relatório C:\TDSSKiller.versão_data.mês.ano_hora.minutos.segundos_log.txt 2. *Baixe o MalwareBytes Anti-malware e salve-o no desktop *Instale o programa e aguarde a atualização *O programa será aberto automaticamente *Na aba [Verificação], selecione [Verificação completa] *Clique [Verificar] e selecione todas as partições *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] *Clique [Remover Selecionados] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 27, 2010 segue os log o tdsskiller nao encontrou nd 2010/11/26 23:05:13.0218 TDSS rootkit removing tool 2.4.9.0 Nov 26 2010 15:38:31 2010/11/26 23:05:13.0218 ================================================================================ 2010/11/26 23:05:13.0218 SystemInfo: 2010/11/26 23:05:13.0218 2010/11/26 23:05:13.0218 OS Version: 5.1.2600 ServicePack: 2.0 2010/11/26 23:05:13.0218 Product type: Workstation 2010/11/26 23:05:13.0218 ComputerName: LUCAS-1B5A603ED 2010/11/26 23:05:13.0218 UserName: Lucas 2010/11/26 23:05:13.0218 Windows directory: C:\WINDOWS 2010/11/26 23:05:13.0218 System windows directory: C:\WINDOWS 2010/11/26 23:05:13.0218 Processor architecture: Intel x86 2010/11/26 23:05:13.0218 Number of processors: 1 2010/11/26 23:05:13.0218 Page size: 0x1000 2010/11/26 23:05:13.0218 Boot type: Normal boot 2010/11/26 23:05:13.0218 ================================================================================ 2010/11/26 23:05:13.0578 Initialize success 2010/11/26 23:05:22.0640 ================================================================================ 2010/11/26 23:05:22.0640 Scan started 2010/11/26 23:05:22.0640 Mode: Manual; 2010/11/26 23:05:22.0640 ================================================================================ 2010/11/26 23:05:23.0218 ACPI (c0162963d82fcfb3f1795263ece1088a) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/11/26 23:05:23.0328 ACPIEC (ebd5cf43ad9526eab9b2a15a54760ea9) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/11/26 23:05:23.0484 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys 2010/11/26 23:05:23.0546 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2010/11/26 23:05:23.0640 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys 2010/11/26 23:05:23.0718 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys 2010/11/26 23:05:24.0265 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/11/26 23:05:24.0328 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/11/26 23:05:24.0437 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/11/26 23:05:24.0515 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/11/26 23:05:24.0578 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/11/26 23:05:24.0828 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/11/26 23:05:24.0906 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2010/11/26 23:05:24.0984 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/11/26 23:05:25.0031 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/11/26 23:05:25.0125 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/11/26 23:05:25.0812 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/11/26 23:05:25.0906 dmboot (ee1e26656d60b8ade14a058a56ebd5f7) C:\WINDOWS\system32\drivers\dmboot.sys 2010/11/26 23:05:25.0984 dmio (29a6d15f8d2f1d9a5c7e0ef594a0dcc4) C:\WINDOWS\system32\DRIVERS\dmio.sys 2010/11/26 23:05:26.0046 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/11/26 23:05:26.0109 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2010/11/26 23:05:26.0187 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/11/26 23:05:26.0281 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/11/26 23:05:26.0343 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2010/11/26 23:05:26.0390 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys 2010/11/26 23:05:26.0421 Fips (8ec0d923cd6128de73dda0df082bb985) C:\WINDOWS\system32\drivers\Fips.sys 2010/11/26 23:05:26.0453 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 2010/11/26 23:05:26.0500 FltMgr (5a85cd3d07273e3f6fe72ee9c6431632) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2010/11/26 23:05:26.0515 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/11/26 23:05:26.0593 Ftdisk (d24d7839d594b255e1c298245b7ba6a2) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/11/26 23:05:26.0640 gagp30kx (4216cd545e5c30807b560c5dcaa812e6) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys 2010/11/26 23:05:26.0703 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/11/26 23:05:26.0734 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/11/26 23:05:26.0828 HTTP (909d110c9634b0f1487eaaea837317d9) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/11/26 23:05:26.0921 i8042prt (fcad1d4a4724b6fa6f05a5db7f89443c) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/11/26 23:05:26.0953 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/11/26 23:05:27.0062 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2010/11/26 23:05:27.0109 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/11/26 23:05:27.0140 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/11/26 23:05:27.0171 IpNat (5191673215c91ff13ceaa83ef8e9653f) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/11/26 23:05:27.0234 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/11/26 23:05:27.0281 isapnp (a41645b9470d99701e90715d443374bd) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/11/26 23:05:27.0343 Kbdclass (7fc1e330386610d5eb3e7c4c7893ca93) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/11/26 23:05:27.0375 kbdhid (45c3722b3bd4c7aa411eae97f2f050db) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/11/26 23:05:27.0406 kmixer (8531438246ce9474e41ee1599904c0c7) C:\WINDOWS\system32\drivers\kmixer.sys 2010/11/26 23:05:27.0437 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/11/26 23:05:27.0531 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/11/26 23:05:27.0593 Modem (ceaf7d279d51d10b9cee49f56422b213) C:\WINDOWS\system32\drivers\Modem.sys 2010/11/26 23:05:27.0625 Mouclass (b4766ab1c226e04a9d7ca4f99d2aa795) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/11/26 23:05:27.0671 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/11/26 23:05:27.0734 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/11/26 23:05:27.0796 MRxSmb (7412ce77c6fd823f8889b4df420c680b) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/11/26 23:05:27.0859 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2010/11/26 23:05:27.0906 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/11/26 23:05:27.0921 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/11/26 23:05:27.0984 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/11/26 23:05:28.0015 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/11/26 23:05:28.0062 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 2010/11/26 23:05:28.0421 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2010/11/26 23:05:28.0453 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2010/11/26 23:05:28.0531 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2010/11/26 23:05:28.0593 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2010/11/26 23:05:28.0687 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/11/26 23:05:28.0734 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/11/26 23:05:28.0781 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/11/26 23:05:28.0843 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/11/26 23:05:28.0890 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/11/26 23:05:28.0968 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/11/26 23:05:29.0140 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2010/11/26 23:05:29.0218 Ntfs (05ab81909514bfd69cbb1f2c147cf6b9) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/11/26 23:05:29.0312 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/11/26 23:05:29.0531 nv (9e1f2f09e34c92a96b9900b6a45d5026) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2010/11/26 23:05:29.0703 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/11/26 23:05:29.0765 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/11/26 23:05:29.0859 Parport (8b225d87cbe08a5cb090bbf9f7de1d30) C:\WINDOWS\system32\DRIVERS\parport.sys 2010/11/26 23:05:29.0906 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/11/26 23:05:30.0015 ParVdm (598a4e8249dcee03c4426b1cf3917abd) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/11/26 23:05:30.0078 PCI (ef5c8b50da721eb49c5466f1317b8fc9) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/11/26 23:05:30.0265 Pcmcia (20ccda6d41140456f4bd91c1b188812d) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/11/26 23:05:30.0750 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/11/26 23:05:30.0859 Processor (5eb97be44a1bf76d1b077f3dbe4a55ba) C:\WINDOWS\system32\DRIVERS\processr.sys 2010/11/26 23:05:30.0953 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/11/26 23:05:31.0015 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/11/26 23:05:31.0359 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/11/26 23:05:31.0421 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/11/26 23:05:31.0500 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/11/26 23:05:31.0562 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/11/26 23:05:31.0656 Rdbss (ed375ce745c42a14f10753f7022ecd6a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/11/26 23:05:31.0703 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/11/26 23:05:31.0796 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2010/11/26 23:05:31.0906 RDPWD (047bea21274c8a4a233674a76c958c2c) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/11/26 23:05:32.0015 redbook (ddd1a19cd2eda2d6ae5ab61baaeb4278) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/11/26 23:05:32.0218 RT61 (4bb5f4cdd6c6b9874eb2bb40f657e9f3) C:\WINDOWS\system32\DRIVERS\RT61.sys 2010/11/26 23:05:32.0359 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/11/26 23:05:32.0437 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2010/11/26 23:05:32.0484 Serial (d8b7e132cb532ee6f3fb5bb3a96df946) C:\WINDOWS\system32\DRIVERS\serial.sys 2010/11/26 23:05:32.0546 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/11/26 23:05:32.0718 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2010/11/26 23:05:32.0828 smwdm (1d381a07361e4d6a8be95026b3eba47a) C:\WINDOWS\system32\drivers\smwdm.sys 2010/11/26 23:05:33.0000 splitter (9bb1dd670cb7505a90fc4e61d4aa8227) C:\WINDOWS\system32\drivers\splitter.sys 2010/11/26 23:05:33.0093 sr (cfa635cf7e75e4eb98fbc164e3583111) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/11/26 23:05:33.0187 Srv (5230953c21c811b5fc1ff31ae2b48097) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/11/26 23:05:33.0265 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2010/11/26 23:05:33.0328 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/11/26 23:05:33.0406 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2010/11/26 23:05:33.0687 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/11/26 23:05:33.0781 Tcpip (bd8686216e34e22c4ed45a2320b2bea1) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/11/26 23:05:33.0875 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/11/26 23:05:33.0937 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/11/26 23:05:34.0015 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/11/26 23:05:34.0234 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2010/11/26 23:05:34.0359 Update (7b2170ee3d858ce8fbe503904cc9b663) C:\WINDOWS\system32\DRIVERS\update.sys 2010/11/26 23:05:34.0453 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2010/11/26 23:05:34.0500 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/11/26 23:05:34.0562 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/11/26 23:05:34.0625 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/11/26 23:05:34.0687 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/11/26 23:05:34.0734 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2010/11/26 23:05:34.0796 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys 2010/11/26 23:05:34.0859 viamraid (0363e216e4eb5052969c96608934dbde) C:\WINDOWS\system32\drivers\viamraid.sys 2010/11/26 23:05:34.0937 VolSnap (eb2f82aaeadcc9baac66cba4d714e338) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/11/26 23:05:35.0031 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/11/26 23:05:35.0203 wdmaud (0bfa8203b8148fb4e54bc212c41ce497) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/11/26 23:05:35.0515 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2010/11/26 23:05:35.0625 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2010/11/26 23:05:35.0687 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2010/11/26 23:05:35.0796 ZSMC0305 (c53cb6b30e8d7fe6d950707508aacfb9) C:\WINDOWS\system32\Drivers\usbVM305.sys 2010/11/26 23:05:36.0093 ================================================================================ 2010/11/26 23:05:36.0093 Scan finished 2010/11/26 23:05:36.0093 ================================================================================ 2010/11/26 23:05:51.0546 Deinitialize success Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Versão da Base de Dados: 5195 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.11 11/26/aaaa 23:41:04 mbam-log-2010-11-26 (23-41-04).txt Tipo de Verificação: Verificação Completa (A:\|C:\|D:\|) Objetos escaneados: 193322 Tempo decorrido: 23 minuto(s), 29 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 3 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001359.exe (Trojan.Downloader) -> No action taken. D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001364.exe (PUP.MailPassView) -> No action taken. D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001366.exe (RiskWare.Tool.CK) -> No action taken. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 27, 2010 1. *Delete o TDSSKiller e o relatório C:\TDSSKiller.versão_data.mês.ano_hora.minutos.segundos_log.txt 2. *Clique [iniciar] > [Executar] > copie e cole: Combofix /uninstall *Clique [OK] > [Executar] *Aguarde surgir a mensagem: "ComboFix está desinstalado" *Clique [OK] 3. *Baixe o Kaspersky Virus Removal Tool e salve-o no desktop *Instale o programa *Selecione a opção: [X] Meu Computador *Clique em [start scan]....aguarde. Pode demorar, seja paciente! *Caso encontre algo, clique [skip] ou [ignorar] *Ao finalizar, clique [Report] *Uma janela chamada "Detailed report" será aberta *Clique no sinal [+] ao lado de Autoscan para expandir os eventos encontrados *Clique com o botão direito do mouse em Autoscan e selecione "Select all" *Clique novamente com o botão direito do mouse e selecione "Copy" *Abra o bloco de notas, cole (Ctrl+v) e salve o arquivo no desktop como log.txt *Feche a janela "Detailed report" do Kasperky *Na tela principal do Kaspersky clique em [Exit] > [No] *Cole o relatório log.txt salvo no desktop Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 27, 2010 Autoscan: completed 32 minutes ago (events: 2, objects: 323395, time: 01:36:59) 11/27/aaaa 12:31:44 Task started 11/27/aaaa 14:08:43 Task completed Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 27, 2010 OK... 1. *Abra a pasta Virus Removal Tool, localizada no desktop, execute o atalho Start *Clique em [Exit] > [Yes] > [sim] > [sim] *O PC será reiniciado *Delete os arquivos setup do Kaspersky e log.txt salvos no desktop 2. *Baixe o antiboot e salve-o no desktop *Extraia para C:\ *Clique [iniciar] > [Executar] > copie e cole: C:\antiboot.exe -l sinowal.txt *Clique [OK] *Caso receba a mensagem: "No infected Disks found", tecle [ENTER] e o programa será fechado. *Caso receba a mensagem: "Bootkit has been detected! Would you like to cure? y/n", tecle [Y] *Ao término, tecle [Y] > [ENTER] e o PC será reiniciado *Cole o relatório C:\sinowal.txt Informe. Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 27, 2010 Log started.... Unpacking driver Starting up driver No Infected Disks found Log started.... Unpacking driver Starting up driver No Infected Disks found Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 28, 2010 OK...o PC está limpo. :) Delete o antiboot e o arquivo C:\sinowal.txt Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
lucasbsp 0 Denunciar post Postado Novembro 28, 2010 sim ok muito obrigado wings mas ak será msm que saiu tudo rsrsrs??? sera que nao conveem passar o combofix novamente pra ver se dar a mensagem de rootkit ? eh so uma duvida ok grande abrass e muito obrigado pela atenção e disposição pra ajudar" :) Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Novembro 28, 2010 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites