Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

lucasbsp

[Resolvido] &nbspMalware rootkit

Recommended Posts

olá gostaria que vcs me ajudassem a tirar um virus que nao consigo retirar e ja formatei os hds aguardo ancioso obrigado

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 23:53:31, on 11/25/aaaa

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.20627)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\VM305_STI.EXE

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\Documents and Settings\Lucas\Meus documentos\Downloads\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://so92.com/?

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [uSB Antivirus] C:\Arquivos de programas\USB Disk Security\USBGuard.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [unlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [ccleaner] "C:\Arquivos de programas\CCleaner\CCleaner.exe" /AUTO

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0E73B4-96AE-4D5B-9CD1-48F0473B9492}: NameServer = 10.0.1.254

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 5671 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá lucasbsp

 

 

*Faça um scan online com o NOD32

 

4682a6d30e.gif

 

*Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Wings fiz o scaneamento lembrando que ele travou em 70% aguardei 1hora e nd depois conclui.

 

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=623a8f04a5d4d84a803ca57c12af8f9c

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2010-11-26 04:07:53

# local_time=2010-11-26 02:07:53 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=52858

# found=6

# cleaned=6

# scan_time=2361

D:\backup\pc cruel\profiles\Downloads\Desflasheando w300i\Programas\Far Manager\Plugins\SEFP\sefp0.10.0.51patch.exe probably a variant of Win32/Agent.NMZPOJA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\programas\sound forge 8.0\keygen - Sound Forge 8.0.exe a variant of Win32/Keygen.AQ application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\Utilitários básicos\nero 7 full\Nero-7.7.5.1_ptb_trial.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\programas\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\programas\unlocker1.8.7.exe a variant of Win32/Adware.ADON application (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\programas\nero 7 full\Nero-7.7.5.1_ptb_trial.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C

esets_scanner_update returned -1 esets_gle=53251

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6211

# api_version=3.0.2

# EOSSerial=623a8f04a5d4d84a803ca57c12af8f9c

# end=stopped

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2010-11-26 05:58:28

# local_time=2010-11-26 03:58:28 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=49884

# found=10

# cleaned=10

# scan_time=6369

D:\backup\DEKSTOP\Downloads\crack + keygen NFS.www.therebels.biz.rar probably a variant of Win32/Agent.BXDOMKW trojan (deleted - quarantined) 00000000000000000000000000000000 C

D:\backup\pc cruel\profiles\Downloads\Desflash_w300i.zip probably a variant of Win32/Agent.NMZPOJA trojan (deleted - quarantined) 00000000000000000000000000000000 C

D:\backup\pc cruel\profiles\Downloads\SETOOL v0.915034.rar a variant of Win32/Packed.Themida application (deleted - quarantined) 00000000000000000000000000000000 C

D:\backup\pc cruel\profiles\Downloads\ultrasurf.zip Win32/UltraReach application (deleted - quarantined) 00000000000000000000000000000000 C

D:\backup\pc cruel\profiles\Downloads\Desflasheando w300i\Programas\Far Manager.zip probably a variant of Win32/Agent.NMZPOJA trojan (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\systempassrec4134.rar Win32/PassRecovery application (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\mailpv\mailpv.exe Win32/MailPassView.132 application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\Anti-virus\programas para recuperar senhas do msn\System Password Recovery 4.1.3.4.455 + Serial\setup.exe Win32/PassRecovery application (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\programas\WinXP keyChanger.exe Win32/PSWTool.RAS.A application (deleted - quarantined) 00000000000000000000000000000000 C

D:\Meus documentos\Pen driver\Utilitários básicos\nero 7 full\Nero.Premium.Edition.v7.0.5.4.Incl.KeyMaker.REPACK-DVT.ZIP probably a variant of Win32/Agent.HZREFUA trojan (deleted - quarantined) 00000000000000000000000000000000 C

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Desative seu antivírus temporariamente

 

*Baixe o RSIT e salve-o no desktop

*Execute o RSIT e clique [Continue]

*Cole o relatório C:\rsit\log.txt

 

2.

*Baixe o GMER e salve-o no desktop

*Crie uma pasta chamada GMER em C:\ e extraia para lá

*Feche todos os programas ativos (MSN, IE, Firefox, etc...)

*Desative temporariamente o antivírus

*Execute o gmer

*Se receber um aviso sobre atividade de rootkit clique [Não]

*Desmarque

[] IAT/EAT

*Clique [scan] e aguarde. Pode demorar....

*Ao finalizar, clique [save...]

*Salve no desktop como gmer

*Cole o relatório gmer.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue os logs

 

Logfile of random's system information tool 1.08 (written by random/random)

Run by Lucas at 2010-11-26 13:57:06

Microsoft Windows XP Professional Service Pack 2

System drive C: has 67 GB (87%) free of 76 GB

Total RAM: 1023 MB (74% free)

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 13:57:28, on 11/26/aaaa

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.20627)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\VM305_STI.EXE

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Documents and Settings\Lucas\Desktop\RSIT.exe

C:\Arquivos de programas\trend micro\Lucas.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://so92.com/?

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [uSB Antivirus] C:\Arquivos de programas\USB Disk Security\USBGuard.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [unlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [ccleaner] "C:\Arquivos de programas\CCleaner\CCleaner.exe" /AUTO

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0E73B4-96AE-4D5B-9CD1-48F0473B9492}: NameServer = 10.0.1.254

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 5398 bytes

 

======Scheduled tasks folder======

 

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

 

======Registry dump======

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll [2010-11-22 41760]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

JQSIEStartDetectorImpl Class - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-11-22 79648]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"USB Antivirus"=C:\Arquivos de programas\USB Disk Security\USBGuard.exe [2008-08-16 798720]

"NeroFilterCheck"=C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

"UnlockerAssistant"=C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe [2008-05-02 15872]

"SunJavaUpdateSched"=C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe [2010-02-18 248040]

"BigDog305"=C:\WINDOWS\VM305_STI.EXE [2005-08-05 61440]

"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-10-10 7286784]

"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-10-10 86016]

"Adobe Reader Speed Launcher"=C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]

"Adobe ARM"=C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"=C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883840]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [2007-01-15 147456]

"ccleaner"=C:\Arquivos de programas\CCleaner\CCleaner.exe [2010-04-23 1668920]

"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2007-07-21 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

nwiz.exe /install []

 

 

Ad-Aware Update (Weekly).job

SA.DAT

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2007-09-02 133632]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=323

"NoDriveAutoRun"=67108863

"NoDrives"=0

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveAutoRun"=67108863

"NoDriveTypeAutoRun"=323

"NoDrives"=0

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"

"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"

"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

 

======File associations======

 

.inf - open - Notepad.exe "%1"

.ini - open - Notepad.exe "%1"

.js - open - WScript.exe "%1" %*

.txt - open - Notepad.exe "%1"

.vbs - open - WScript.exe "%1" %*

 

======List of files/folders created in the last 1 months======

 

2010-11-26 13:57:06 ----D---- C:\rsit

2010-11-26 13:57:06 ----D---- C:\Arquivos de programas\trend micro

2010-11-26 00:29:44 ----D---- C:\Arquivos de programas\ESET

2010-11-26 00:02:06 ----D---- C:\Nova pasta

2010-11-25 23:31:12 ----A---- C:\mbr.exe

2010-11-25 23:03:01 ----ASH---- C:\hiberfil.sys

2010-11-25 22:18:26 ----SHD---- C:\Config.Msi

2010-11-25 22:18:14 ----D---- C:\WINDOWS\SxsCaPendDel

2010-11-25 21:13:02 ----A---- C:\InfoSat.txt

2010-11-25 04:32:38 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com

2010-11-25 04:32:32 ----D---- C:\Arquivos de programas\SUPERAntiSpyware

2010-11-25 03:57:36 ----SHD---- C:\RECYCLER

2010-11-25 01:46:29 ----A---- C:\ComboFix.txt

2010-11-25 01:22:44 ----D---- C:\WINDOWS\Minidump

2010-11-24 21:01:25 ----D---- C:\Arquivos de programas\ToniArts

2010-11-24 19:40:49 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe

2010-11-24 19:40:02 ----D---- C:\Arquivos de programas\Arquivos comuns\Adobe

2010-11-24 19:40:02 ----D---- C:\Arquivos de programas\Adobe

2010-11-24 15:45:55 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\TeamViewer

2010-11-24 15:45:50 ----D---- C:\Arquivos de programas\TeamViewer

2010-11-24 15:18:03 ----D---- C:\WINDOWS\Sun

2010-11-24 00:58:26 ----D---- C:\Arquivos de programas\GameVicio

2010-11-24 00:48:18 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll

2010-11-24 00:41:04 ----D---- C:\Arquivos de programas\Sierra

2010-11-24 00:16:36 ----A---- C:\WINDOWS\ODBC.INI

2010-11-24 00:16:32 ----A---- C:\WINDOWS\system32\mdimon.dll

2010-11-24 00:15:34 ----D---- C:\Arquivos de programas\Microsoft.NET

2010-11-24 00:15:01 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER

2010-11-24 00:14:49 ----D---- C:\WINDOWS\SHELLNEW

2010-11-24 00:14:46 ----D---- C:\Arquivos de programas\Microsoft Office

2010-11-24 00:13:42 ----RD---- C:\MSOCache

2010-11-23 19:25:01 ----D---- C:\Arquivos de programas\Marcos Velasco Security

2010-11-23 15:16:09 ----A---- C:\WINDOWS\NeroDigital.ini

2010-11-23 15:16:06 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Media Player Classic

2010-11-23 15:07:05 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Malwarebytes

2010-11-23 15:06:56 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes

2010-11-23 13:46:50 ----A---- C:\WINDOWS\system32\CF26396.exe

2010-11-23 13:16:05 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer

2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\rmoc3260.dll

2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pndx5032.dll

2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pndx5016.dll

2010-11-23 13:15:56 ----A---- C:\WINDOWS\system32\pncrt.dll

2010-11-23 13:15:53 ----A---- C:\WINDOWS\system32\x264vfw.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\xvidvfw.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\xvidcore.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\WMV9VCM.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\ssldivx.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\qt-dx331.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\libdivx.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\dtu100.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\dpl100.dll

2010-11-23 13:15:52 ----A---- C:\WINDOWS\system32\divx.dll

2010-11-23 13:15:51 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest

2010-11-23 13:15:51 ----A---- C:\WINDOWS\system32\ff_vfw.dll

2010-11-23 13:15:50 ----A---- C:\WINDOWS\system32\msvcr71.dll

2010-11-23 13:15:49 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Real

2010-11-23 13:15:49 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Real

2010-11-23 13:15:49 ----D---- C:\Arquivos de programas\K-Lite Codec Pack

2010-11-23 13:15:49 ----A---- C:\WINDOWS\system32\msvcp71.dll

2010-11-23 12:33:54 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2010-11-23 00:44:03 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\TS3Client

2010-11-23 00:42:45 ----D---- C:\Arquivos de programas\TeamSpeak 3 Client

2010-11-22 21:57:40 ----D---- C:\WINDOWS\nview

2010-11-22 21:57:39 ----A---- C:\WINDOWS\system32\nvudisp.exe

2010-11-22 21:57:05 ----D---- C:\WINDOWS\system32\ReinstallBackups

2010-11-22 21:56:24 ----A---- C:\WINDOWS\system32\NVUNINST.EXE

2010-11-22 21:39:49 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys

2010-11-22 21:39:48 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys

2010-11-22 21:39:47 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys

2010-11-22 21:39:46 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys

2010-11-22 21:39:44 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS

2010-11-22 21:39:43 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys

2010-11-22 21:39:41 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys

2010-11-22 21:39:32 ----A---- C:\WINDOWS\system32\vfwwdm32.dll

2010-11-22 21:39:30 ----RA---- C:\WINDOWS\VM305_STI.EXE

2010-11-22 21:39:30 ----RA---- C:\WINDOWS\system32\VM305STI.dll

2010-11-22 21:39:30 ----RA---- C:\WINDOWS\system32\drivers\usbVM305.sys

2010-11-22 21:39:30 ----R---- C:\WINDOWS\Zoom.exe

2010-11-22 21:39:30 ----R---- C:\WINDOWS\VMPipe.dll

2010-11-22 21:39:29 ----RA---- C:\WINDOWS\amcap.exe

2010-11-22 21:39:29 ----D---- C:\WINDOWS\EffectResources

2010-11-22 21:39:29 ----A---- C:\WINDOWS\VM303UninstNT.exe

2010-11-22 21:33:50 ----HD---- C:\WINDOWS\PIF

2010-11-22 19:30:12 ----D---- C:\Arquivos de programas\FlashGet

2010-11-22 17:24:17 ----D---- C:\Arquivos de programas\FlashGet Network

2010-11-22 16:05:55 ----D---- C:\Arquivos de programas\xerox

2010-11-22 16:05:54 ----D---- C:\WINDOWS\system32\xircom

2010-11-22 16:05:54 ----D---- C:\Arquivos de programas\microsoft frontpage

2010-11-22 16:01:06 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Sun

2010-11-22 16:01:06 ----D---- C:\Arquivos de programas\Arquivos comuns\Java

2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\javaws.exe

2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\javaw.exe

2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\java.exe

2010-11-22 16:00:41 ----A---- C:\WINDOWS\system32\deploytk.dll

2010-11-22 16:00:28 ----D---- C:\Arquivos de programas\Java

2010-11-22 16:00:06 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Sun

2010-11-22 15:10:04 ----D---- C:\WINDOWS\temp

2010-11-22 15:04:04 ----A---- C:\WINDOWS\libem.INI

2010-11-22 15:04:00 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\FlashGet

2010-11-22 15:03:55 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\FlashGetBHO

2010-11-22 15:02:22 ----D---- C:\Arquivos de programas\CCleaner

2010-11-22 14:50:06 ----A---- C:\WINDOWS\system32\spupdsvc.exe

2010-11-22 14:49:01 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage

2010-11-22 14:44:31 ----D---- C:\Arquivos de programas\Unlocker

2010-11-22 14:40:37 ----D---- C:\Arquivos de programas\VS Revo Group

2010-11-22 14:38:58 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\BITS

2010-11-22 14:38:47 ----D---- C:\profiles

2010-11-22 14:32:37 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Ahead

2010-11-22 14:31:35 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Nero

2010-11-22 14:31:35 ----D---- C:\Arquivos de programas\Nero

2010-11-22 14:31:35 ----D---- C:\Arquivos de programas\Arquivos comuns\Ahead

2010-11-22 14:30:22 ----A---- C:\WINDOWS\system32\d3dx9_30.dll

2010-11-22 14:30:21 ----A---- C:\WINDOWS\system32\d3dx9_28.dll

2010-11-21 11:56:05 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Macromedia

2010-11-21 11:56:04 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Adobe

2010-11-21 11:55:28 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Mozilla

2010-11-21 11:42:43 ----D---- C:\Documents and Settings\Lucas\Dados de aplicativos\Identities

2010-11-21 11:42:19 ----SD---- C:\Documents and Settings\Lucas\Dados de aplicativos\Microsoft

2010-11-21 11:42:19 ----ASH---- C:\Documents and Settings\Lucas\Dados de aplicativos\desktop.ini

2010-11-21 11:41:27 ----D---- C:\WINDOWS\Prefetch

2010-11-21 11:39:25 ----D---- C:\WINDOWS\system32\dllcache

2010-11-21 11:38:53 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest

2010-11-21 11:33:01 ----A---- C:\WINDOWS\system32\drivers\fetnd5.sys

2010-11-21 09:43:11 ----A---- C:\WINDOWS\system32\drivers\SBREDrv.sys

2010-11-21 09:24:02 ----ASH---- C:\pagefile.sys

2010-11-21 08:42:59 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Lavasoft

2010-11-21 05:23:00 ----D---- C:\WINDOWS\ERDNT

2010-11-21 04:04:56 ----D---- C:\Arquivos de programas\Mozilla Firefox

2010-11-21 04:01:30 ----D---- C:\Arquivos de programas\Microsoft

2010-11-21 04:01:17 ----D---- C:\Arquivos de programas\Windows Live SkyDrive

2010-11-21 04:00:57 ----D---- C:\Arquivos de programas\Windows Live

2010-11-21 03:59:41 ----D---- C:\Arquivos de programas\Arquivos comuns\Windows Live

2010-11-21 03:58:33 ----D---- C:\WINDOWS\pss

2010-11-21 03:52:06 ----D---- C:\Arquivos de programas\USB Disk Security

2010-11-21 03:51:50 ----A---- C:\WINDOWS\system32\drivers\AegisP.sys

2010-11-21 03:51:46 ----DC---- C:\WINDOWS\system32\DRVSTORE

2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\Install6x.dll

2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\drivers\rt61.sys

2010-11-21 03:51:39 ----A---- C:\WINDOWS\system32\AegisI5.exe

2010-11-21 03:51:32 ----D---- C:\Arquivos de programas\RALINK

2010-11-21 03:49:56 ----D---- C:\Arquivos de programas\WinRAR

2010-11-21 03:49:11 ----A---- C:\WINDOWS\system32\drivers\splitter.sys

2010-11-21 03:49:10 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys

2010-11-21 03:47:36 ----N---- C:\WINDOWS\system32\ksuser.dll

2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\wdmioctl.dll

2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\drivers\smsens.sys

2010-11-21 03:47:34 ----A---- C:\WINDOWS\system32\drivers\aeaudio.sys

2010-11-21 03:47:33 ----A---- C:\WINDOWS\system32\SMMedia.dll

2010-11-21 03:47:32 ----A---- C:\WINDOWS\SynthCoreA.Dll

2010-11-21 03:47:32 ----A---- C:\WINDOWS\SynCor.exe

2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\SynthCore11Resources.dll

2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\Syncor11.dll

2010-11-21 03:47:31 ----A---- C:\WINDOWS\system32\S11thk32.dll

2010-11-21 03:47:28 ----D---- C:\WINDOWS\VirtualEar

2010-11-21 03:47:28 ----A---- C:\WINDOWS\system32\Audio3d.dll

2010-11-21 03:47:27 ----A---- C:\WINDOWS\system32\virtear.dll

2010-11-21 03:47:26 ----D---- C:\Arquivos de programas\Analog Devices

2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\drivers\smwdm.sys

2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\CleanUp.exe

2010-11-21 03:47:26 ----A---- C:\WINDOWS\system32\a3d.dll

2010-11-21 03:47:25 ----HD---- C:\Arquivos de programas\InstallShield Installation Information

2010-11-21 03:47:25 ----A---- C:\WINDOWS\system32\DSndUp.exe

2010-11-21 03:47:17 ----D---- C:\Arquivos de programas\Arquivos comuns\InstallShield

2010-11-21 03:47:02 ----A---- C:\WINDOWS\Ascd_tmp.ini

2010-11-21 03:46:59 ----A---- C:\WINDOWS\system32\drivers\ASUSHWIO.SYS

2010-11-21 03:45:46 ----HD---- C:\Arquivos de programas\Uninstall Information

2010-11-21 03:40:21 ----D---- C:\WINDOWS\SoftwareDistribution

2010-11-21 03:40:20 ----SD---- C:\WINDOWS\system32\Microsoft

2010-11-21 03:40:20 ----N---- C:\WINDOWS\SchedLgU.Txt

2010-11-21 03:39:01 ----A---- C:\WINDOWS\system32\tzchange.exe

2010-11-21 03:38:58 ----HD---- C:\WINDOWS\$hf_mig$

2010-11-21 03:38:51 ----N---- C:\WINDOWS\system32\spmsg.dll

2010-11-21 03:38:45 ----D---- C:\Arquivos de programas\MSXML 6.0

2010-11-21 03:38:42 ----D---- C:\Arquivos de programas\MSXML 4.0

2010-11-21 03:38:34 ----RASH---- C:\MSDOS.SYS

2010-11-21 03:38:34 ----RASH---- C:\IO.SYS

2010-11-21 03:38:34 ----A---- C:\WINDOWS\control.ini

2010-11-21 03:38:34 ----A---- C:\CONFIG.SYS

2010-11-21 03:38:34 ----A---- C:\AUTOEXEC.BAT

2010-11-21 03:38:22 ----A---- C:\WINDOWS\system32\mapi32.dll

2010-11-21 03:37:37 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest

2010-11-21 03:37:33 ----HD---- C:\Arquivos de programas\WindowsUpdate

2010-11-21 03:37:32 ----D---- C:\Arquivos de programas\Serviços on-line

2010-11-21 03:37:14 ----D---- C:\WINDOWS\system32\DirectX

2010-11-21 03:36:42 ----A---- C:\WINDOWS\system32\atrace.dll

2010-11-21 03:36:38 ----A---- C:\WINDOWS\system32\desktop.ini

2010-11-21 03:36:38 ----A---- C:\WINDOWS\desktop.ini

2010-11-21 03:36:28 ----A---- C:\WINDOWS\system32\nmevtmsg.dll

2010-11-21 03:36:26 ----A---- C:\WINDOWS\system32\acctres.dll

2010-11-21 03:36:25 ----D---- C:\Arquivos de programas\Arquivos comuns\Serviços

2010-11-21 03:36:21 ----SD---- C:\WINDOWS\Tasks

2010-11-21 03:36:21 ----A---- C:\WINDOWS\system32\icfgnt5.dll

2010-11-21 03:36:19 ----D---- C:\Arquivos de programas\Arquivos comuns\MSSoap

2010-11-21 03:36:13 ----D---- C:\WINDOWS\srchasst

2010-11-21 03:36:11 ----D---- C:\WINDOWS\system32\Macromed

2010-11-21 03:36:09 ----A---- C:\WINDOWS\system32\wuweb.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wups.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wucltui.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauserv.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuaueng1.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuaueng.dll

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauclt1.exe

2010-11-21 03:36:08 ----A---- C:\WINDOWS\system32\wuauclt.exe

2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\wuapi.dll

2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\qmgrprxy.dll

2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\qmgr.dll

2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\bitsprx3.dll

2010-11-21 03:36:07 ----A---- C:\WINDOWS\system32\bitsprx2.dll

2010-11-21 03:36:02 ----D---- C:\Arquivos de programas\Movie Maker

2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrslv.dll

2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrdm.dll

2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\safrcdlg.dll

2010-11-21 03:35:54 ----A---- C:\WINDOWS\system32\racpldlg.dll

2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\fltMc.exe

2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\fltlib.dll

2010-11-21 03:35:49 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys

2010-11-21 03:35:48 ----D---- C:\WINDOWS\system32\Restore

2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srsvc.dll

2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srrstr.dll

2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\srclient.dll

2010-11-21 03:35:48 ----A---- C:\WINDOWS\system32\drivers\sr.sys

2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\mnmdd.dll

2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\isrdbg32.dll

2010-11-21 03:35:47 ----A---- C:\WINDOWS\system32\ils.dll

2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\nmmkcert.dll

2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\msconf.dll

2010-11-21 03:35:46 ----A---- C:\WINDOWS\system32\mnmsrvc.exe

2010-11-21 03:35:42 ----D---- C:\Arquivos de programas\NetMeeting

2010-11-21 03:35:41 ----A---- C:\WINDOWS\system32\msoert2.dll

2010-11-21 03:35:41 ----A---- C:\WINDOWS\system32\msoeacct.dll

2010-11-21 03:35:40 ----A---- C:\WINDOWS\system32\inetres.dll

2010-11-21 03:35:39 ----A---- C:\WINDOWS\system32\inetcomm.dll

2010-11-21 03:35:37 ----D---- C:\Arquivos de programas\Outlook Express

2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\schedsvc.dll

2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\mstinit.exe

2010-11-21 03:35:37 ----A---- C:\WINDOWS\system32\mstask.dll

2010-11-21 03:35:36 ----A---- C:\WINDOWS\system32\icwphbk.dll

2010-11-21 03:35:36 ----A---- C:\WINDOWS\system32\icwdial.dll

2010-11-21 03:35:35 ----A---- C:\WINDOWS\system32\isign32.dll

2010-11-21 03:35:35 ----A---- C:\WINDOWS\system32\inetcfg.dll

2010-11-21 03:35:27 ----D---- C:\Arquivos de programas\Arquivos comuns\System

2010-11-21 03:35:25 ----D---- C:\Arquivos de programas\Internet Explorer

2010-11-21 03:34:59 ----D---- C:\Arquivos de programas\ComPlus Applications

2010-11-21 03:34:59 ----A---- C:\WINDOWS\vbaddin.ini

2010-11-21 03:34:59 ----A---- C:\WINDOWS\vb.ini

2010-11-21 03:34:58 ----D---- C:\WINDOWS\Registration

2010-11-21 03:34:53 ----D---- C:\Arquivos de programas\Windows Media Connect 2

2010-11-21 03:34:51 ----D---- C:\Arquivos de programas\Windows Media Player

2010-11-21 03:34:49 ----D---- C:\Arquivos de programas\Messenger

2010-11-21 03:34:43 ----D---- C:\Arquivos de programas\MSN Gaming Zone

2010-11-21 03:34:43 ----A---- C:\WINDOWS\system32\write.exe

2010-11-21 03:34:30 ----A---- C:\WINDOWS\system32\sndvol32.exe

2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\hticons.dll

2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avwav.dll

2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avtapi.dll

2010-11-21 03:34:29 ----A---- C:\WINDOWS\system32\avmeter.dll

2010-11-21 03:34:28 ----A---- C:\WINDOWS\system32\winchat.exe

2010-11-21 03:34:18 ----A---- C:\WINDOWS\system32\getuname.dll

2010-11-21 03:34:18 ----A---- C:\WINDOWS\system32\charmap.exe

2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\winmine.exe

2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\sol.exe

2010-11-21 03:34:17 ----A---- C:\WINDOWS\system32\calc.exe

2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\reset.exe

2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\mshearts.exe

2010-11-21 03:34:16 ----A---- C:\WINDOWS\system32\freecell.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\usrlogon.cmd

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tsshutdn.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tslabels.ini

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tskill.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tsdiscon.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\tscon.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\shadow.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\rwinsta.exe

2010-11-21 03:34:15 ----A---- C:\WINDOWS\system32\regini.exe

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\rdpcfgex.dll

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\qwinsta.exe

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\qappsrv.exe

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\msg.exe

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\msdtcprf.ini

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\logoff.exe

2010-11-21 03:34:14 ----A---- C:\WINDOWS\system32\cdmodem.dll

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxlegih.dll

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxex.dll

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\mtxdm.dll

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\dcomcnfg.exe

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\comrepl.dll

2010-11-21 03:34:12 ----A---- C:\WINDOWS\system32\comaddin.dll

2010-11-21 03:34:11 ----A---- C:\WINDOWS\system32\stclient.dll

2010-11-21 03:34:11 ----A---- C:\WINDOWS\system32\comsnap.dll

2010-11-21 03:34:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc

2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\sndrec32.exe

2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\mplay32.exe

2010-11-21 03:34:02 ----A---- C:\WINDOWS\system32\accwiz.exe

2010-11-21 03:34:01 ----D---- C:\Arquivos de programas\Windows NT

2010-11-21 03:34:01 ----A---- C:\WINDOWS\system32\hypertrm.dll

2010-11-21 03:34:00 ----A---- C:\WINDOWS\system32\mspaint.exe

2010-11-21 03:34:00 ----A---- C:\WINDOWS\system32\clipbrd.exe

2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\tscfgwmi.dll

2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\spider.exe

2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys

2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys

2010-11-21 03:33:59 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\sessmgr.exe

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\remotepg.dll

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdshost.exe

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdsaddin.exe

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\rdchost.dll

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\mstscax.dll

2010-11-21 03:33:58 ----A---- C:\WINDOWS\system32\mstsc.exe

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\tscupgrd.exe

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\termsrv.dll

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpwsx.dll

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpsnd.dll

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\rdpclip.exe

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\qprocess.exe

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\icaapi.dll

2010-11-21 03:33:57 ----A---- C:\WINDOWS\system32\cfgbkend.dll

2010-11-21 03:33:56 ----D---- C:\WINDOWS\system32\MsDtc

2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\mtxoci.dll

2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\msdtcuiu.dll

2010-11-21 03:33:56 ----A---- C:\WINDOWS\system32\msdtcprx.dll

2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\xolehlp.dll

2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtctm.dll

2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtclog.dll

2010-11-21 03:33:55 ----A---- C:\WINDOWS\system32\msdtc.exe

2010-11-21 03:33:53 ----D---- C:\WINDOWS\system32\Com

2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\colbact.dll

2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\clbcatex.dll

2010-11-21 03:33:53 ----A---- C:\WINDOWS\system32\catsrvps.dll

2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\comsvcs.dll

2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\catsrvut.dll

2010-11-21 03:33:52 ----A---- C:\WINDOWS\system32\catsrv.dll

2010-11-21 03:33:51 ----A---- C:\WINDOWS\system32\comuid.dll

2010-11-21 03:33:51 ----A---- C:\WINDOWS\system32\clbcatq.dll

2010-11-21 03:33:44 ----A---- C:\WINDOWS\system32\servdeps.dll

2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\mmfutil.dll

2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\licwmi.dll

2010-11-21 03:33:43 ----A---- C:\WINDOWS\system32\cmprops.dll

2010-11-21 03:33:39 ----A---- C:\WINDOWS\system32\drivers\termdd.sys

2010-11-21 03:33:39 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

2010-11-21 01:33:28 ----A---- C:\WINDOWS\system32\h323log.txt

2010-11-21 01:33:07 ----A---- C:\WINDOWS\system32\drivers\audstub.sys

2010-11-21 01:32:36 ----A---- C:\WINDOWS\system32\drivers\redbook.sys

2010-11-21 01:32:22 ----A---- C:\WINDOWS\system32\storprop.dll

2010-11-21 01:32:20 ----A---- C:\WINDOWS\system32\nv4_disp.dll

2010-11-21 01:32:20 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys

2010-11-21 01:32:04 ----A---- C:\WINDOWS\system32\drivers\GAGP30KX.SYS

2010-11-21 01:31:21 ----SHD---- C:\WINDOWS\Installer

2010-11-21 01:31:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

2010-11-21 01:31:20 ----D---- C:\Arquivos de programas\Arquivos comuns\ODBC

2010-11-21 01:31:20 ----A---- C:\WINDOWS\ODBCINST.INI

2010-11-21 01:31:17 ----D---- C:\Arquivos de programas\Arquivos comuns\SpeechEngines

2010-11-21 01:31:16 ----RD---- C:\Arquivos de programas

2010-11-21 01:31:16 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared

2010-11-21 01:31:16 ----D---- C:\Arquivos de programas\Arquivos comuns

2010-11-21 01:30:40 ----ASH---- C:\Documents and Settings\All Users\Dados de aplicativos\desktop.ini

2010-11-21 01:30:20 ----D---- C:\WINDOWS\system32\CatRoot2

2010-11-21 01:30:20 ----D---- C:\WINDOWS\system32\CatRoot

2010-11-21 01:30:15 ----SD---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft

2010-11-21 01:29:46 ----D---- C:\Documents and Settings

2010-11-21 01:29:45 ----SHD---- C:\System Volume Information

2010-11-21 01:23:46 ----SH---- C:\boot.ini

2010-11-21 01:20:12 ----D---- C:\WINDOWS\OemDir

2010-11-21 01:20:06 ----SD---- C:\WINDOWS\Downloaded Program Files

2010-11-21 01:20:06 ----RSD---- C:\WINDOWS\Fonts

2010-11-21 01:20:06 ----RD---- C:\WINDOWS\Web

2010-11-21 01:20:06 ----HD---- C:\WINDOWS\inf

2010-11-21 01:20:06 ----D---- C:\WINDOWS\WinSxS

2010-11-21 01:20:06 ----D---- C:\WINDOWS\WBEM

2010-11-21 01:20:06 ----D---- C:\WINDOWS\twain_32

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\wins

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\wbem

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\usmt

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\spool

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ShellExt

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\Setup

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ras

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\pt-br

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\oobe

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\npp

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\mui

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\inetsrv

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\IME

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\icsxml

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\ias

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\export

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\UMDF

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\etc

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers\disdn

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\drivers

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\dhcp

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\config

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\3com_dmi

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\3076

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\2052

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1054

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1046

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1042

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1041

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1037

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1033

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1031

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1028

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32\1025

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system32

2010-11-21 01:20:06 ----D---- C:\WINDOWS\system

2010-11-21 01:20:06 ----D---- C:\WINDOWS\security

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Resources

2010-11-21 01:20:06 ----D---- C:\WINDOWS\repair

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Provisioning

2010-11-21 01:20:06 ----D---- C:\WINDOWS\PeerNet

2010-11-21 01:20:06 ----D---- C:\WINDOWS\pchealth

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Offline Web Pages

2010-11-21 01:20:06 ----D---- C:\WINDOWS\mui

2010-11-21 01:20:06 ----D---- C:\WINDOWS\msapps

2010-11-21 01:20:06 ----D---- C:\WINDOWS\msagent

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Media

2010-11-21 01:20:06 ----D---- C:\WINDOWS\java

2010-11-21 01:20:06 ----D---- C:\WINDOWS\ime

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Help

2010-11-21 01:20:06 ----D---- C:\WINDOWS\ehome

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Driver Cache

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Debug

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Cursors

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Connection Wizard

2010-11-21 01:20:06 ----D---- C:\WINDOWS\Config

2010-11-21 01:20:06 ----D---- C:\WINDOWS\AppPatch

2010-11-21 01:20:06 ----D---- C:\WINDOWS\addins

2010-11-21 01:20:06 ----D---- C:\WINDOWS

 

======List of files/folders modified in the last 1 months======

 

2010-11-25 21:19:12 ----A---- C:\WINDOWS\win.ini

2010-11-25 21:19:12 ----A---- C:\WINDOWS\system.ini

2010-11-21 11:39:15 ----ASH---- C:\WINDOWS\fonts\desktop.ini

 

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R0 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2004-08-03 46464]

R0 viamraid;viamraid; C:\WINDOWS\system32\drivers\viamraid.sys [2005-04-26 60928]

R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2007-07-21 14848]

R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-11-21 21419]

R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]

R3 hidusb;Driver de classe HID da Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2007-07-21 9600]

R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-10-10 3530432]

R3 RT61;Ralink RT61 Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT61.sys [2006-08-02 384384]

R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]

R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2007-07-21 31616]

R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2007-07-21 20480]

R3 ZSMC0305;A4 TECH PC Camera V; C:\WINDOWS\System32\Drivers\usbVM305.sys [2006-05-08 391688]

S3 catchme;catchme; \??\C:\DOCUME~1\Lucas\CONFIG~1\Temp\catchme.sys []

S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]

S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]

S3 MSTEE;Conversor em T entre locais de fluxo contínuo Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]

S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]

S3 NdisIP;Conexão de TV e vídeo da Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]

S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]

S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]

S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2007-07-21 26496]

S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2007-09-02 77568]

S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2007-09-02 82944]

 

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R2 JavaQuickStarterService;Java Quick Starter; C:\Arquivos de programas\Java\jre6\bin\jqs.exe [2010-11-22 153376]

R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-10-10 131139]

R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]

R3 NMIndexingService;NMIndexingService; C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [2007-01-15 266240]

S3 NBService;NBService; C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-15 774144]

S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

S3 WMPNetworkSvc;Serviço de Compartilhamento de Rede do Windows Media Player; C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe [2006-11-02 914944]

S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2007-07-21 14336]

 

-----------------EOF-----------------

 

GMER 1.0.15.15530 - http://www.gmer.net

Rootkit scan 2010-11-26 14:17:45

Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Scsi\viamraid1Port2Path0Target0Lun0 SAMSUNG_ rev.SU10

Running: gmer.exe; Driver: C:\DOCUME~1\Lucas\CONFIG~1\Temp\kwliqkoc.sys

 

 

---- Kernel code sections - GMER 1.0.15 ----

 

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6F63360, 0x20469D, 0xE8000020]

 

---- EOF - GMER 1.0.15 ----

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o OTC e salve-o no desktop

*Execute o OTC e clique em [CleanUp!]

 

 

Seus logs estão limpos.

 

Ainda com problema?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Então wings fiz todos os procedimentos que você me falou mas quando atualizo o combofix e ele escanear

mostra o seguinte foi detectado rootkit no seu sistema e deve ser reiniciado agora

nao sei se pelos logs da pra você saber mas tenho 2 hds um de 80gb que eh para o sistema

e um de 160gb que eh para backup tem como esse virus ter infiltrado nos meus arquivos? abrass aguardo resposta

Compartilhar este post


Link para o post
Compartilhar em outros sites

Combofix não é uma ferramenta para ser usada como antivírus!

 

Seu uso é complexo e pode acarretar alterações no sistema.

 

De onde você baixou o combofix?

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Execute o arquivo c:\Arquivos de programas\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe

 

2.

*Desative temporariamente seu antivírus

 

*Baixe o ComboFix e salve-o no desktop

 

*Execute o Combofix e aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso contrário, clique [sIM] para instalar e depois [sIM] para continuar.

 

191d6c44ae.jpg

 

dd8ae98175.jpg

 

*Aguarde a conclusão de todas as etapas

 

etapas.jpg

 

*Não use o mouse e o teclado durante a execução do Combofix!!..... Para interromper o procedimento tecle [N] ou [2] e depois [ENTER]

 

*Cole o relatório C:\combofix.txt

 

*Se for reiniciar o PC haverá uma opção, na inicialização, chamada Console de Recuperação. Não entre no Windows através da mesma desde que devidamente orientado(a)!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Então wings fiz o procedimento igual você mostra no tópico quando om combofix começa a verificar arquivos e ficheiros segue a seguinte mensagem apos alguns minutos "O COMBOFIX DETECTOU A PRESENÇA DE ATIVIDADE DE ROOTKIT E PRECISA REINICIAR A MÁQUINA.Renicio a maquina normalmente ele faz os procedimentos padrão e abaixo segue o log

 

ComboFix 10-11-25.06 - Lucas 11/26/aaaa 18:04:27.11.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1023.807 [GMT -2:00]

Executando de: c:\documents and settings\Lucas\Desktop\ComboFix.exe

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2010-10-26 to 2010-11-26 ))))))))))))))))))))))))))))

.

 

2010-11-24 02:13 . 2010-11-24 02:13 -------- d-----r- C:\MSOCache

2010-11-22 16:38 . 2010-11-22 16:38 -------- d-----w- C:\profiles

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

 

------- Sigcheck -------

 

[-] 2007-09-03 . BD8686216E34E22C4ED45A2320B2BEA1 . 360576 . . [5.1.2600.2892] . . c:\windows\system32\drivers\tcpip.sys

 

[-] 2007-09-02 . DB3AA410ED1228B9DF98C06549AE0763 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

 

[-] 2007-09-02 17:20 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883840]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]

"ccleaner"="c:\arquivos de programas\CCleaner\CCleaner.exe" [2010-04-23 1668920]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"USB Antivirus"="c:\arquivos de programas\USB Disk Security\USBGuard.exe" [2008-08-16 798720]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

"UnlockerAssistant"="c:\arquivos de programas\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-02-18 248040]

"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-07-21 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nltide_2"="shell32" [X]

"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2007-07-21 44544]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

2005-10-10 13:49 1519616 ----a-w- c:\windows\system32\nwiz.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R3 ZSMC0305;A4 TECH PC Camera V;c:\windows\system32\drivers\usbVM305.sys [11/22/aaaa 21:39 391688]

.

Conteúdo da pasta 'Tarefas Agendadas'

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

TCP: {8D0E73B4-96AE-4D5B-9CD1-48F0473B9492} = 10.0.1.254

FF - ProfilePath - c:\documents and settings\Lucas\Dados de aplicativos\Mozilla\Firefox\Profiles\zawixtqt.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

.

.

------- Associação de arquivos/ficheiros -------

.

inifile=Notepad.exe "%1"

txtfile=Notepad.exe "%1"

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-11-26 18:07

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

 

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net

Windows 5.1.2600 Disk: SAMSUNG_ rev.SU10 -> Harddisk0\DR0 -> \Device\Scsi\viamraid1Port2Path0Target2Lun0

 

device: opened successfully

user: MBR read successfully

 

Disk trace:

called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys SCSIPORT.SYS hal.dll viamraid.sys

c:\docume~1\Lucas\CONFIG~1\Temp\catchme.sys

c:\windows\system32\drivers\viamraid.sys VIA Technologies inc,.ltd VIA RAID driver

1 ntkrnlpa!IofCallDriver[0x804EE0F6] -> \Device\Harddisk0\DR0[0x86592AB8]

3 CLASSPNP[0xF762D05B] -> ntkrnlpa!IofCallDriver[0x804EE0F6] -> \Device\Scsi\viamraid1Port2Path0Target0Lun0[0x86586A38]

kernel: MBR read successfully

_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [bP+0x0], CH; JL 0x2e; JNZ 0x3a; }

user != kernel MBR !!!

sectors 156368014 (+255): user != kernel

 

**************************************************************************

.

Tempo para conclusão: 2010-11-26 18:08:52

ComboFix-quarantined-files.txt 2010-11-26 20:08

 

Pré-execução: 6 pasta(s) 70.128.513.024 bytes disponíveis

Pós execução: 8 pasta(s) 70.130.139.136 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - DBE569F4041376428D0BB040D8368DBB

 

esqueci de ressaltar quando entro em minha unidade D: aparece o RECYLCLER

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Baixe o TDSSKiller e salve-o no desktop

*Extraia para o desktop e execute o TDSSKiller

*Clique [start Scan]

*Caso encontre algo, clique na seta ao lado da palavra "Cure" e selecione "Skip"

*Clique [Continue]

*Ao término, clique [Close]

*Cole o relatório C:\TDSSKiller.versão_data.mês.ano_hora.minutos.segundos_log.txt

 

2.

*Baixe o MalwareBytes Anti-malware e salve-o no desktop

 

*Instale o programa e aguarde a atualização

*O programa será aberto automaticamente

*Na aba [Verificação], selecione [Verificação completa]

*Clique [Verificar] e selecione todas as partições

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados]

*Clique [Remover Selecionados]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

segue os log o tdsskiller nao encontrou nd

 

2010/11/26 23:05:13.0218 TDSS rootkit removing tool 2.4.9.0 Nov 26 2010 15:38:31

2010/11/26 23:05:13.0218 ================================================================================

2010/11/26 23:05:13.0218 SystemInfo:

2010/11/26 23:05:13.0218

2010/11/26 23:05:13.0218 OS Version: 5.1.2600 ServicePack: 2.0

2010/11/26 23:05:13.0218 Product type: Workstation

2010/11/26 23:05:13.0218 ComputerName: LUCAS-1B5A603ED

2010/11/26 23:05:13.0218 UserName: Lucas

2010/11/26 23:05:13.0218 Windows directory: C:\WINDOWS

2010/11/26 23:05:13.0218 System windows directory: C:\WINDOWS

2010/11/26 23:05:13.0218 Processor architecture: Intel x86

2010/11/26 23:05:13.0218 Number of processors: 1

2010/11/26 23:05:13.0218 Page size: 0x1000

2010/11/26 23:05:13.0218 Boot type: Normal boot

2010/11/26 23:05:13.0218 ================================================================================

2010/11/26 23:05:13.0578 Initialize success

2010/11/26 23:05:22.0640 ================================================================================

2010/11/26 23:05:22.0640 Scan started

2010/11/26 23:05:22.0640 Mode: Manual;

2010/11/26 23:05:22.0640 ================================================================================

2010/11/26 23:05:23.0218 ACPI (c0162963d82fcfb3f1795263ece1088a) C:\WINDOWS\system32\DRIVERS\ACPI.sys

2010/11/26 23:05:23.0328 ACPIEC (ebd5cf43ad9526eab9b2a15a54760ea9) C:\WINDOWS\system32\drivers\ACPIEC.sys

2010/11/26 23:05:23.0484 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys

2010/11/26 23:05:23.0546 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys

2010/11/26 23:05:23.0640 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys

2010/11/26 23:05:23.0718 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys

2010/11/26 23:05:24.0265 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

2010/11/26 23:05:24.0328 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys

2010/11/26 23:05:24.0437 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

2010/11/26 23:05:24.0515 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

2010/11/26 23:05:24.0578 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

2010/11/26 23:05:24.0828 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

2010/11/26 23:05:24.0906 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys

2010/11/26 23:05:24.0984 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

2010/11/26 23:05:25.0031 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys

2010/11/26 23:05:25.0125 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys

2010/11/26 23:05:25.0812 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys

2010/11/26 23:05:25.0906 dmboot (ee1e26656d60b8ade14a058a56ebd5f7) C:\WINDOWS\system32\drivers\dmboot.sys

2010/11/26 23:05:25.0984 dmio (29a6d15f8d2f1d9a5c7e0ef594a0dcc4) C:\WINDOWS\system32\DRIVERS\dmio.sys

2010/11/26 23:05:26.0046 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

2010/11/26 23:05:26.0109 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys

2010/11/26 23:05:26.0187 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys

2010/11/26 23:05:26.0281 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys

2010/11/26 23:05:26.0343 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys

2010/11/26 23:05:26.0390 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys

2010/11/26 23:05:26.0421 Fips (8ec0d923cd6128de73dda0df082bb985) C:\WINDOWS\system32\drivers\Fips.sys

2010/11/26 23:05:26.0453 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys

2010/11/26 23:05:26.0500 FltMgr (5a85cd3d07273e3f6fe72ee9c6431632) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

2010/11/26 23:05:26.0515 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

2010/11/26 23:05:26.0593 Ftdisk (d24d7839d594b255e1c298245b7ba6a2) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

2010/11/26 23:05:26.0640 gagp30kx (4216cd545e5c30807b560c5dcaa812e6) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys

2010/11/26 23:05:26.0703 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys

2010/11/26 23:05:26.0734 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys

2010/11/26 23:05:26.0828 HTTP (909d110c9634b0f1487eaaea837317d9) C:\WINDOWS\system32\Drivers\HTTP.sys

2010/11/26 23:05:26.0921 i8042prt (fcad1d4a4724b6fa6f05a5db7f89443c) C:\WINDOWS\system32\DRIVERS\i8042prt.sys

2010/11/26 23:05:26.0953 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys

2010/11/26 23:05:27.0062 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

2010/11/26 23:05:27.0109 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

2010/11/26 23:05:27.0140 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys

2010/11/26 23:05:27.0171 IpNat (5191673215c91ff13ceaa83ef8e9653f) C:\WINDOWS\system32\DRIVERS\ipnat.sys

2010/11/26 23:05:27.0234 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys

2010/11/26 23:05:27.0281 isapnp (a41645b9470d99701e90715d443374bd) C:\WINDOWS\system32\DRIVERS\isapnp.sys

2010/11/26 23:05:27.0343 Kbdclass (7fc1e330386610d5eb3e7c4c7893ca93) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

2010/11/26 23:05:27.0375 kbdhid (45c3722b3bd4c7aa411eae97f2f050db) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

2010/11/26 23:05:27.0406 kmixer (8531438246ce9474e41ee1599904c0c7) C:\WINDOWS\system32\drivers\kmixer.sys

2010/11/26 23:05:27.0437 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys

2010/11/26 23:05:27.0531 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

2010/11/26 23:05:27.0593 Modem (ceaf7d279d51d10b9cee49f56422b213) C:\WINDOWS\system32\drivers\Modem.sys

2010/11/26 23:05:27.0625 Mouclass (b4766ab1c226e04a9d7ca4f99d2aa795) C:\WINDOWS\system32\DRIVERS\mouclass.sys

2010/11/26 23:05:27.0671 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys

2010/11/26 23:05:27.0734 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

2010/11/26 23:05:27.0796 MRxSmb (7412ce77c6fd823f8889b4df420c680b) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

2010/11/26 23:05:27.0859 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys

2010/11/26 23:05:27.0906 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys

2010/11/26 23:05:27.0921 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

2010/11/26 23:05:27.0984 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys

2010/11/26 23:05:28.0015 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

2010/11/26 23:05:28.0062 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys

2010/11/26 23:05:28.0421 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys

2010/11/26 23:05:28.0453 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys

2010/11/26 23:05:28.0531 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys

2010/11/26 23:05:28.0593 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys

2010/11/26 23:05:28.0687 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

2010/11/26 23:05:28.0734 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

2010/11/26 23:05:28.0781 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

2010/11/26 23:05:28.0843 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys

2010/11/26 23:05:28.0890 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys

2010/11/26 23:05:28.0968 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys

2010/11/26 23:05:29.0140 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys

2010/11/26 23:05:29.0218 Ntfs (05ab81909514bfd69cbb1f2c147cf6b9) C:\WINDOWS\system32\drivers\Ntfs.sys

2010/11/26 23:05:29.0312 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

2010/11/26 23:05:29.0531 nv (9e1f2f09e34c92a96b9900b6a45d5026) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

2010/11/26 23:05:29.0703 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

2010/11/26 23:05:29.0765 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

2010/11/26 23:05:29.0859 Parport (8b225d87cbe08a5cb090bbf9f7de1d30) C:\WINDOWS\system32\DRIVERS\parport.sys

2010/11/26 23:05:29.0906 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys

2010/11/26 23:05:30.0015 ParVdm (598a4e8249dcee03c4426b1cf3917abd) C:\WINDOWS\system32\drivers\ParVdm.sys

2010/11/26 23:05:30.0078 PCI (ef5c8b50da721eb49c5466f1317b8fc9) C:\WINDOWS\system32\DRIVERS\pci.sys

2010/11/26 23:05:30.0265 Pcmcia (20ccda6d41140456f4bd91c1b188812d) C:\WINDOWS\system32\drivers\Pcmcia.sys

2010/11/26 23:05:30.0750 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys

2010/11/26 23:05:30.0859 Processor (5eb97be44a1bf76d1b077f3dbe4a55ba) C:\WINDOWS\system32\DRIVERS\processr.sys

2010/11/26 23:05:30.0953 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys

2010/11/26 23:05:31.0015 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

2010/11/26 23:05:31.0359 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

2010/11/26 23:05:31.0421 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

2010/11/26 23:05:31.0500 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

2010/11/26 23:05:31.0562 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

2010/11/26 23:05:31.0656 Rdbss (ed375ce745c42a14f10753f7022ecd6a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

2010/11/26 23:05:31.0703 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

2010/11/26 23:05:31.0796 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

2010/11/26 23:05:31.0906 RDPWD (047bea21274c8a4a233674a76c958c2c) C:\WINDOWS\system32\drivers\RDPWD.sys

2010/11/26 23:05:32.0015 redbook (ddd1a19cd2eda2d6ae5ab61baaeb4278) C:\WINDOWS\system32\DRIVERS\redbook.sys

2010/11/26 23:05:32.0218 RT61 (4bb5f4cdd6c6b9874eb2bb40f657e9f3) C:\WINDOWS\system32\DRIVERS\RT61.sys

2010/11/26 23:05:32.0359 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys

2010/11/26 23:05:32.0437 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys

2010/11/26 23:05:32.0484 Serial (d8b7e132cb532ee6f3fb5bb3a96df946) C:\WINDOWS\system32\DRIVERS\serial.sys

2010/11/26 23:05:32.0546 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys

2010/11/26 23:05:32.0718 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys

2010/11/26 23:05:32.0828 smwdm (1d381a07361e4d6a8be95026b3eba47a) C:\WINDOWS\system32\drivers\smwdm.sys

2010/11/26 23:05:33.0000 splitter (9bb1dd670cb7505a90fc4e61d4aa8227) C:\WINDOWS\system32\drivers\splitter.sys

2010/11/26 23:05:33.0093 sr (cfa635cf7e75e4eb98fbc164e3583111) C:\WINDOWS\system32\DRIVERS\sr.sys

2010/11/26 23:05:33.0187 Srv (5230953c21c811b5fc1ff31ae2b48097) C:\WINDOWS\system32\DRIVERS\srv.sys

2010/11/26 23:05:33.0265 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys

2010/11/26 23:05:33.0328 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys

2010/11/26 23:05:33.0406 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys

2010/11/26 23:05:33.0687 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys

2010/11/26 23:05:33.0781 Tcpip (bd8686216e34e22c4ed45a2320b2bea1) C:\WINDOWS\system32\DRIVERS\tcpip.sys

2010/11/26 23:05:33.0875 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys

2010/11/26 23:05:33.0937 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys

2010/11/26 23:05:34.0015 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys

2010/11/26 23:05:34.0234 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys

2010/11/26 23:05:34.0359 Update (7b2170ee3d858ce8fbe503904cc9b663) C:\WINDOWS\system32\DRIVERS\update.sys

2010/11/26 23:05:34.0453 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

2010/11/26 23:05:34.0500 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys

2010/11/26 23:05:34.0562 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys

2010/11/26 23:05:34.0625 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

2010/11/26 23:05:34.0687 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

2010/11/26 23:05:34.0734 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys

2010/11/26 23:05:34.0796 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\system32\DRIVERS\viaide.sys

2010/11/26 23:05:34.0859 viamraid (0363e216e4eb5052969c96608934dbde) C:\WINDOWS\system32\drivers\viamraid.sys

2010/11/26 23:05:34.0937 VolSnap (eb2f82aaeadcc9baac66cba4d714e338) C:\WINDOWS\system32\drivers\VolSnap.sys

2010/11/26 23:05:35.0031 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys

2010/11/26 23:05:35.0203 wdmaud (0bfa8203b8148fb4e54bc212c41ce497) C:\WINDOWS\system32\drivers\wdmaud.sys

2010/11/26 23:05:35.0515 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS

2010/11/26 23:05:35.0625 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

2010/11/26 23:05:35.0687 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

2010/11/26 23:05:35.0796 ZSMC0305 (c53cb6b30e8d7fe6d950707508aacfb9) C:\WINDOWS\system32\Drivers\usbVM305.sys

2010/11/26 23:05:36.0093 ================================================================================

2010/11/26 23:05:36.0093 Scan finished

2010/11/26 23:05:36.0093 ================================================================================

2010/11/26 23:05:51.0546 Deinitialize success

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Versão da Base de Dados: 5195

 

Windows 5.1.2600 Service Pack 2

Internet Explorer 7.0.5730.11

 

11/26/aaaa 23:41:04

mbam-log-2010-11-26 (23-41-04).txt

 

Tipo de Verificação: Verificação Completa (A:\|C:\|D:\|)

Objetos escaneados: 193322

Tempo decorrido: 23 minuto(s), 29 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 3

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001359.exe (Trojan.Downloader) -> No action taken.

D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001364.exe (PUP.MailPassView) -> No action taken.

D:\System Volume Information\_restore{545B52EC-1B93-495B-9FE2-79FCC1B9ECFF}\RP5\A0001366.exe (RiskWare.Tool.CK) -> No action taken.

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Delete o TDSSKiller e o relatório C:\TDSSKiller.versão_data.mês.ano_hora.minutos.segundos_log.txt

 

2.

*Clique [iniciar] > [Executar] > copie e cole: Combofix /uninstall

 

9c7dcf5090.jpg

 

*Clique [OK] > [Executar]

*Aguarde surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

3.

*Baixe o Kaspersky Virus Removal Tool e salve-o no desktop

*Instale o programa

*Selecione a opção:

[X] Meu Computador

*Clique em [start scan]....aguarde. Pode demorar, seja paciente!

*Caso encontre algo, clique [skip] ou [ignorar]

*Ao finalizar, clique [Report]

*Uma janela chamada "Detailed report" será aberta

*Clique no sinal [+] ao lado de Autoscan para expandir os eventos encontrados

*Clique com o botão direito do mouse em Autoscan e selecione "Select all"

*Clique novamente com o botão direito do mouse e selecione "Copy"

*Abra o bloco de notas, cole (Ctrl+v) e salve o arquivo no desktop como log.txt

*Feche a janela "Detailed report" do Kasperky

*Na tela principal do Kaspersky clique em [Exit] > [No]

*Cole o relatório log.txt salvo no desktop

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...

 

1.

*Abra a pasta Virus Removal Tool, localizada no desktop, execute o atalho Start

*Clique em [Exit] > [Yes] > [sim] > [sim]

*O PC será reiniciado

*Delete os arquivos setup do Kaspersky e log.txt salvos no desktop

 

2.

*Baixe o antiboot e salve-o no desktop

*Extraia para C:\

*Clique [iniciar] > [Executar] > copie e cole: C:\antiboot.exe -l sinowal.txt

*Clique [OK]

*Caso receba a mensagem: "No infected Disks found", tecle [ENTER] e o programa será fechado.

*Caso receba a mensagem: "Bootkit has been detected! Would you like to cure? y/n", tecle [Y]

*Ao término, tecle [Y] > [ENTER] e o PC será reiniciado

*Cole o relatório C:\sinowal.txt

 

Informe.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Log started....

Unpacking driver

 

Starting up driver

No Infected Disks found

 

Log started....

Unpacking driver

 

Starting up driver

No Infected Disks found

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...o PC está limpo. :)

 

Delete o antiboot e o arquivo C:\sinowal.txt

 

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

sim ok muito obrigado wings mas ak será msm que saiu tudo rsrsrs???

sera que nao conveem passar o combofix novamente pra ver se dar a mensagem de rootkit ?

eh so uma duvida ok grande abrass e muito obrigado pela atenção e disposição pra ajudar" :)

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.