Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Hugstom

[Arquivado] &nbspvirus

Recommended Posts

OLA

 

MEU PCA ENCONTRA-SE COM ALGUM TIPO DE VISRUS

QUE FAS COM QUE MEU PC TRAVE E FIQUE COM

A TELA TODA BRANCA PISCANDO

E ENVIANDO MENSANGENS NO MSN NA CAIXA DE EMAIL

 

ISSO OCORREU LOGO DEPOIS QUE INSTALEI

O OFFICE 2010 E DAI PRA FRENTE

TRAVA TODA HORA O ANTI VIRUS ACUSANDO VIRUS DE

15 EM 15 MINUTOS

O PC FICOU LENTO E NAO CONSIGO REMOVER ESSE VIRUS

 

SE FOR MESMO VIRUS ...

DESDE JA OBRIGADO

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 16:14:31, on 5/4/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe

C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program-Files\Java\msnmsg.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Program-Files\Java\iexplorer.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com

R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {C0B6368A-A218-4855-AE42-6AD2DAF9DDF6} - C:\WINDOWS\system32\javawhelper.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: (no name) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - (no file)

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - (no file)

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [avast5] "C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe" /nogui

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsg] C:\Program-Files\Java\msnmsg.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [iexplorer] C:\Program-Files\Java\iexplorer.exe

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')

O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.sbradesco.kit.net

O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O20 - AppInit_DLLs: C:\WINDOWS\System32\dmdlgs32.dll

O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O20 - Winlogon Notify: 487cc309517 - Invalid registry found

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Mail Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: avast! Web Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: ProtexisLicensing - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe

O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

 

--

End of file - 9442 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Hugstom

 

 

1.

*Baixe o Bankerfix e salve-o no desktop

*Execute-o, clique [OK] > [sIM] (se pedir alguma atualização) > [OK] > [ENTER]

*Ao finalizar, tecle [ENTER]

*Cole o relatório C:\LinhaDefensiva\relatorio.txt

 

2.

*Baixe o MalwareBytes e salve-o no desktop

*Instale o programa e aguarde a atualização

*O programa será aberto automaticamente

*Na aba [Verificação], selecione [Verificação completa]

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado (C:\Documents and settings\Nome_do_Usuário\Dados de aplicativos\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam.txt)

 

Caso já tenhas o Malwarebytes instalado....

 

*Abra o Malwarebytes, clique [Atualização] > [baixar Atualizações]

*Na aba [Verificação], selecione [x] Verificação completa

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Gostaria de acrescentar que na tentativa desesperada de conseguir

conserta meu pc movi os arquivos do Disco C: para o Disco D:

E ISSO fez com que eu perdesse algums arquivos,

mais um deles nao consegui recupera

Meu msn e ja tentei de tudo

exclui mais quando instalo outro

tem um aviso que me diz que ja tenho ele instalado

 

e meu avast ainda fica dizendo que

um arquivo infectado foi encontrado mais nao retira

isso ocorre de 7 em 7 minutos marcado no relogio

obrigado ...

 

 

 

 

 

 

BankerFix 3.1 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2011-04-26 - 15:05

-------------------------------------------------------

Lista de Definição: 2011-03-01-1 | CORE: 2010-12-28-6

=======================================================

 

Arquivo infectado detectado: C:\WINDOWS\Media\ev.dll

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\Media\logo.dll

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\Media\mp3configuration.ini

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\Media\NewIcon.ico

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\Media\Ok.dll

Arquivo infectado removido com sucesso!

 

 

 

----- Fim -------------------------

 

 

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Versão da Base de Dados: 6443

 

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

 

26/4/2011 15:56:43

mbam-log-2011-04-26 (15-56-43).txt

 

Tipo de Verificação: Verificação Completa (C:\|)

Objetos escaneados: 193519

Tempo decorrido: 41 minuto(s), 50 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 0

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

(Não foram detectados ítens maliciosos)

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Delete o Bankerfix e a pasta C:\LinhaDefensiva

 

2.

*Baixe o ERUNT e salve-o no desktop

*Crie uma pasta em C:\ chamada ERUNT e extraia para ela

*Execute o arquivo C:\ERUNT\ERUNT.exe

*Clique [OK] > [OK] > [sim] > [OK]

 

3.

*Desative temporariamente seu antivírus

Clique com o botão direito do mouse no ícone do Avast ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme.

*Baixe o ComboFix e salve-o no desktop

*Execute-o e aceite o contrato

*Se o Console de Recuperação do Microsoft Windows não estiver instalado, aceite a sua instalação

*Após a instalação do Console, clique [sim] e aguarde a conclusão das etapas

*Não use o mouse nem o teclado durante as etapas, pois implicará na desconfiguração do seu desktop!

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Boa Tarde

segue aqui o relatório

 

ComboFix 11-04-27.04 - Usuario 28/04/2011 13:37:23.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.594 [GMT -3:00]

Executando de: c:\documents and settings\Usuario\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

* Criado um novo ponto de restauração

.

ADS - system32: deleted 2 bytes in 1 streams.

ADS - drivers: deleted 324 bytes in 1 streams.

.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\arquivos de programas\arquivos comuns\picasa check\loga.dll

c:\arquivos de programas\arquivos comuns\picasa check\logaa.dll

c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp

c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\CleanUp.lnk

c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\License Agreement.lnk

c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\Readme.lnk

c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\Uninstall.lnk

c:\documents and settings\Usuario\AppTime

c:\documents and settings\Usuario\WINDOWS

c:\windows\Media\mp3\mod01.mp3

c:\windows\Media\mp3\mod03.mp3

c:\windows\Media\mp3\mod04.mp3

c:\windows\sys

c:\windows\sys\System.ini

c:\windows\system32\_000005_.tmp.dll

c:\windows\system32\bios_setup1399.txt

c:\windows\system32\drivers\npf.sys

c:\windows\system32\Packet.dll

c:\windows\system32\pthreadVC.dll

c:\windows\system32\sysdm.exe

c:\windows\system32\wpcap.dll

c:\windows\winhelp26.ini

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_NPF

-------\Service_npf

.

.

(((((((((((((((( Arquivos/Ficheiros criados de 2011-03-28 to 2011-04-28 ))))))))))))))))))))))))))))

.

.

2011-04-28 16:09 . 2011-04-28 16:10 -------- d-----w- C:\ERUNT

2011-04-12 17:37 . 2011-04-12 17:37 -------- d-----w- c:\arquivos de programas\MegaJogos

2011-04-11 16:15 . 2011-04-11 16:15 -------- d-----w- c:\arquivos de programas\MSBuild

2011-04-11 16:14 . 2011-04-11 16:14 -------- d-----w- c:\arquivos de programas\Microsoft Synchronization Services

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\documents and settings\All Users\Microsoft

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft.NET

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft SQL Server Compact Edition

2011-04-11 16:05 . 2011-04-11 16:05 -------- d-----w- c:\arquivos de programas\Microsoft Visual Studio 8

2011-04-11 16:02 . 2011-04-11 16:16 -------- d-----w- c:\windows\SHELLNEW

2011-04-11 16:01 . 2011-04-11 16:01 -------- d-----r- C:\MSOCache

2011-04-11 15:29 . 2011-04-11 15:29 -------- d-----w- c:\arquivos de programas\Microsoft Analysis Services

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes

2011-04-06 17:00 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2011-04-06 17:00 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-04-05 18:02 . 2011-04-06 02:40 -------- d-----w- c:\windows\SxsCaPendDel

2011-04-04 19:11 . 2011-04-04 19:11 -------- d-----w- c:\arquivos de programas\VS Revo Group

2011-04-04 19:03 . 2011-04-04 19:03 -------- d-----w- c:\arquivos de programas\Purple Parrot

2011-04-04 19:03 . 1999-05-07 05:00 209408 ----a-w- c:\windows\system32\tabctl32.ocx

2011-04-04 19:03 . 1998-06-24 05:00 137000 ----a-w- c:\windows\system32\msmapi32.ocx

2011-04-04 16:41 . 2011-04-06 14:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2011-04-04 14:18 . 2010-04-28 10:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys

2011-04-04 00:26 . 2011-04-04 20:32 -------- d-----w- c:\arquivos de programas\Google

2011-04-03 19:44 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-04-03 19:44 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-04-03 19:44 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-04-03 19:44 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-04-03 19:44 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2011-04-03 19:44 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys

2011-04-03 19:44 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2011-04-03 19:44 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr

2011-04-03 19:44 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe

2011-04-03 03:03 . 2011-04-03 03:03 -------- d-----w- C:\Program-Files

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\com.livebrush

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Livebrush

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe AIR

.

.

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-04-25 23:29 . 2004-08-04 03:45 1172480 ----a-w- c:\windows\system32\msxml3.dll

2011-03-07 05:33 . 2008-09-23 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-03-04 06:36 . 2004-08-04 03:45 420864 ----a-w- c:\windows\system32\vbscript.dll

2011-03-03 13:53 . 2004-08-04 03:38 1858048 ----a-w- c:\windows\system32\win32k.sys

2011-02-22 23:08 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll

2011-02-22 23:08 . 2004-08-04 03:45 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-02-22 23:08 . 2004-08-04 03:45 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-02-22 11:43 . 2004-08-04 03:37 385024 ----a-w- c:\windows\system32\html.iec

2011-02-17 13:18 . 2004-08-04 02:15 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-02-17 13:18 . 2004-08-04 02:14 357888 ----a-w- c:\windows\system32\drivers\srv.sys

2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-02-15 12:56 . 2004-08-04 03:44 290432 ----a-w- c:\windows\system32\atmfd.dll

2011-02-12 16:03 . 2011-02-12 16:03 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-02-12 16:03 . 2011-02-07 00:29 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-02-09 13:53 . 2004-08-04 03:45 270848 ----a-w- c:\windows\system32\sbe.dll

2011-02-09 13:53 . 2004-08-04 03:45 186880 ----a-w- c:\windows\system32\encdec.dll

2011-02-08 13:33 . 2004-08-04 03:45 978944 ----a-w- c:\windows\system32\mfc42.dll

2011-02-08 13:33 . 2004-08-04 03:45 974848 ----a-w- c:\windows\system32\mfc42u.dll

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FF.tmp

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FE.tmp

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FD.tmp

2011-02-02 21:11 . 2009-12-25 16:18 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-02-02 07:58 . 2008-09-23 19:23 2067456 ----a-w- c:\windows\system32\mstscax.dll

2009-10-10 16:16 . 2009-10-10 16:16 22074000 ----a-w- c:\arquivos de programas\MSNOIE8_PTBR_XP.EXE

.

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552]

"avast5"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

"BCSSync"="c:\arquivos de programas\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"ISUSPM Startup"="c:\arquiv~1\ARQUIV~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399003}"= "c:\arquivos de programas\GbPlugin\gbiehcef.dll" [2011-02-18 346568]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]

2011-02-18 18:50 346568 ----a-w- c:\arquivos de programas\GbPlugin\gbiehcef.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk /*

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\LEXPPS.EXE"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"c:\\WINDOWS\\system32\\rtcshare.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\OUTLOOK.EXE"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

.

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [19/3/2010 10:16 46664]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/4/2011 16:44 165584]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/4/2011 16:44 17744]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [19/3/2010 10:16 54728]

R2 SentinelKeysServer;Sentinel Keys Server;c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [11/7/2008 00:02 328992]

S2 azverrk;Universal Network;c:\windows\system32\svchost.exe -k netsvcs [4/8/2004 00:45 14336]

S2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 18:19 13592]

S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\arquivos de programas\Microsoft Office\Office14\GROOVE.EXE [25/3/2010 10:25 30969208]

S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000]

S3 SASENUM;SASENUM;\??\c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS --> c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [?]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/8/2004 00:45 14336]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WINRM REG_MULTI_SZ WINRM

.

Conteúdo da pasta 'Tarefas Agendadas'

.

2011-04-28 c:\windows\Tasks\AF4B6C5291851CFA.job

- c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe [2009-10-22 19:40]

.

2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{C54E4DC2-560C-48FC-90C1-7D9407A82835}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://start.facemoods.com/?a=gppc

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com

IE: &Enviar para o OneNote - c:\arquiv~1\MICROS~2\Office14\ONBttnIE.dll/105

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office14\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

Trusted Zone: gov.com.br\caixa

DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab

DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab

.

- - - - ORFÃOS REMOVIDOS - - - -

.

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

HKCU-Run-msnmsgr - c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe

Notify-487cc309517 - (no file)

Notify-dimsntfy - (no file)

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-04-28 13:44

Windows 5.1.2600 Service Pack 3 NTFS

.

Procurando processos ocultos ...

.

Procurando entradas auto inicializáveis ocultas ...

.

Procurando ficheiros/arquivos ocultos ...

.

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\azverrk]

"ServiceDll"="c:\windows\system32\pxeqog.dll"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

.

[HKEY_USERS\S-1-5-21-1202660629-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Òw*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

.

- - - - - - - > 'winlogon.exe'(656)

c:\arquivos de programas\GbPlugin\gbiehCef.dll

.

- - - - - - - > 'explorer.exe'(2948)

c:\windows\system32\WININET.dll

c:\arquiv~1\ARQUIV~1\MICROS~1\OFFICE14\Cultures\office.odf

c:\arquiv~1\MICROS~2\Office14\1046\GrooveIntlResource.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

c:\windows\system32\LEXBCES.EXE

c:\windows\system32\LEXPPS.EXE

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe

c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

c:\windows\system32\SearchIndexer.exe

c:\arquivos de programas\Alwil Software\Avast5\setup\avast.setup

c:\windows\system32\wbem\wmiapsrv.exe

c:\windows\system32\msiexec.exe

c:\windows\system32\SearchProtocolHost.exe

c:\windows\system32\SearchFilterHost.exe

.

**************************************************************************

.

Tempo para conclusão: 2011-04-28 13:48:59 - Máquina reiniciou

ComboFix-quarantined-files.txt 2011-04-28 16:48

.

Pré-execução: 7.857.205.248 bytes disponíveis

Pós execução: 7.897.956.352 bytes disponíveis

.

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5

- - End Of File - - 9EA5858FADD609BFF8F57D699742D1E1

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Abra o bloco de notas e cole nele o código abaixo:

File::

c:\windows\system32\pxeqog.dll

FileLook::

c:\windows\system32\REN1FF.tmp

c:\windows\system32\REN1FD.tmp

c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe

Registry::

[-HKEY_LOCAL_MACHINE\System\ControlSet004\Services\azverrk]

NetSvc::

azverrk

Driver::

azverrk

*Salve o arquivo no desktop como CFScript.txt

*Arraste-o para o Combofix conforme ilustração abaixo:

 

b2ea2c6367.gif

 

*Enquanto o combofix estiver em execução, não use o mouse nem o teclado!!

 

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue o relatório em andamento ...

 

 

ComboFix 11-04-27.04 - Usuario 28/04/2011 18:25:13.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.621 [GMT -3:00]

Executando de: c:\documents and settings\Usuario\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Usuario\Desktop\CFScript..txt

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

FILE ::

"c:\windows\system32\pxeqog.dll"

.

ADS - drivers: deleted 208 bytes in 1 streams.

.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

-------\Legacy_AZVERRK

-------\Service_azverrk

.

.

(((((((((((((((( Arquivos/Ficheiros criados de 2011-03-28 to 2011-04-28 ))))))))))))))))))))))))))))

.

.

2011-04-28 16:09 . 2011-04-28 16:10 -------- d-----w- C:\ERUNT

2011-04-12 17:37 . 2011-04-12 17:37 -------- d-----w- c:\arquivos de programas\MegaJogos

2011-04-11 16:15 . 2011-04-11 16:15 -------- d-----w- c:\arquivos de programas\MSBuild

2011-04-11 16:14 . 2011-04-11 16:14 -------- d-----w- c:\arquivos de programas\Microsoft Synchronization Services

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\documents and settings\All Users\Microsoft

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft.NET

2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft SQL Server Compact Edition

2011-04-11 16:05 . 2011-04-11 16:05 -------- d-----w- c:\arquivos de programas\Microsoft Visual Studio 8

2011-04-11 16:02 . 2011-04-11 16:16 -------- d-----w- c:\windows\SHELLNEW

2011-04-11 16:01 . 2011-04-11 16:01 -------- d-----r- C:\MSOCache

2011-04-11 15:29 . 2011-04-11 15:29 -------- d-----w- c:\arquivos de programas\Microsoft Analysis Services

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes

2011-04-06 17:00 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2011-04-06 17:00 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-04-05 18:02 . 2011-04-06 02:40 -------- d-----w- c:\windows\SxsCaPendDel

2011-04-04 19:11 . 2011-04-04 19:11 -------- d-----w- c:\arquivos de programas\VS Revo Group

2011-04-04 19:03 . 2011-04-04 19:03 -------- d-----w- c:\arquivos de programas\Purple Parrot

2011-04-04 19:03 . 1999-05-07 05:00 209408 ----a-w- c:\windows\system32\tabctl32.ocx

2011-04-04 19:03 . 1998-06-24 05:00 137000 ----a-w- c:\windows\system32\msmapi32.ocx

2011-04-04 16:41 . 2011-04-06 14:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2011-04-04 14:18 . 2010-04-28 10:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys

2011-04-04 00:26 . 2011-04-04 20:32 -------- d-----w- c:\arquivos de programas\Google

2011-04-03 19:44 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-04-03 19:44 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-04-03 19:44 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-04-03 19:44 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-04-03 19:44 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2011-04-03 19:44 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys

2011-04-03 19:44 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2011-04-03 19:44 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr

2011-04-03 19:44 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe

2011-04-03 03:03 . 2011-04-03 03:03 -------- d-----w- C:\Program-Files

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\com.livebrush

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Livebrush

2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe AIR

.

.

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-04-25 23:29 . 2004-08-04 03:45 1172480 ----a-w- c:\windows\system32\msxml3.dll

2011-03-07 05:33 . 2008-09-23 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-03-04 06:36 . 2004-08-04 03:45 420864 ----a-w- c:\windows\system32\vbscript.dll

2011-03-03 13:53 . 2004-08-04 03:38 1858048 ----a-w- c:\windows\system32\win32k.sys

2011-02-22 23:08 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll

2011-02-22 23:08 . 2004-08-04 03:45 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-02-22 23:08 . 2004-08-04 03:45 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-02-22 11:43 . 2004-08-04 03:37 385024 ----a-w- c:\windows\system32\html.iec

2011-02-17 13:18 . 2004-08-04 02:15 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-02-17 13:18 . 2004-08-04 02:14 357888 ----a-w- c:\windows\system32\drivers\srv.sys

2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-02-15 12:56 . 2004-08-04 03:44 290432 ----a-w- c:\windows\system32\atmfd.dll

2011-02-12 16:03 . 2011-02-12 16:03 73728 ----a-w- c:\windows\system32\javacpl.cpl

2011-02-12 16:03 . 2011-02-07 00:29 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-02-09 13:53 . 2004-08-04 03:45 270848 ----a-w- c:\windows\system32\sbe.dll

2011-02-09 13:53 . 2004-08-04 03:45 186880 ----a-w- c:\windows\system32\encdec.dll

2011-02-08 13:33 . 2004-08-04 03:45 978944 ----a-w- c:\windows\system32\mfc42.dll

2011-02-08 13:33 . 2004-08-04 03:45 974848 ----a-w- c:\windows\system32\mfc42u.dll

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FF.tmp

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FE.tmp

2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FD.tmp

2011-02-02 21:11 . 2009-12-25 16:18 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-02-02 07:58 . 2008-09-23 19:23 2067456 ----a-w- c:\windows\system32\mstscax.dll

2009-10-10 16:16 . 2009-10-10 16:16 22074000 ----a-w- c:\arquivos de programas\MSNOIE8_PTBR_XP.EXE

.

.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

--- c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe ---

Company: Nowhere Serone

File Description: Nos no theshian append sperow hideksi

File Version: 2, 2, 0, 4

Product Name: Edited default appears

Copyright: Copyright Lan Proceed Doulai 2004. All rights reserved.

Original Filename: Tool.exe

File size: 286720

Created time: 2009-10-22 21:33

Modified time: 2009-12-16 19:40

MD5: A9B34B97937675BDE34650D89C77FA5D

SHA1: 68036C05B3D76E08D1969DB8D2AC8004CC11087E

.

.

--- c:\windows\system32\REN1FD.tmp ---

Company: ------

File Description: ------

File Version: ------

Product Name: ------

Copyright: ------

Original Filename: ------

File size: 0

Created time: 2011-02-07 00:29

Modified time: 2011-02-07 00:29

MD5: D41D8CD98F00B204E9800998ECF8427E

SHA1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709

.

.

--- c:\windows\system32\REN1FF.tmp ---

Company: ------

File Description: ------

File Version: ------

Product Name: ------

Copyright: ------

Original Filename: ------

File size: 0

Created time: 2011-02-07 00:29

Modified time: 2011-02-07 00:29

MD5: D41D8CD98F00B204E9800998ECF8427E

SHA1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709

.

.

((((((((((((((((((((((((((((( SnapShot@2011-04-28_16.44.29 )))))))))))))))))))))))))))))))))))))))))

.

+ 2011-04-28 21:33 . 2011-04-28 21:33 16384 c:\windows\Temp\Perflib_Perfdata_110.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552]

"avast5"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

"BCSSync"="c:\arquivos de programas\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"ISUSPM Startup"="c:\arquiv~1\ARQUIV~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]

.

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399003}"= "c:\arquivos de programas\GbPlugin\gbiehcef.dll" [2011-02-18 346568]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]

2011-02-18 18:50 346568 ----a-w- c:\arquivos de programas\GbPlugin\gbiehcef.dll

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk /*

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\LEXPPS.EXE"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"c:\\WINDOWS\\system32\\rtcshare.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office14\\OUTLOOK.EXE"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

.

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [19/3/2010 10:16 46664]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/4/2011 16:44 165584]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/4/2011 16:44 17744]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [19/3/2010 10:16 54728]

R2 SentinelKeysServer;Sentinel Keys Server;c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [11/7/2008 00:02 328992]

S2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 18:19 13592]

S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?]

S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\arquivos de programas\Microsoft Office\Office14\GROOVE.EXE [25/3/2010 10:25 30969208]

S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000]

S3 SASENUM;SASENUM;\??\c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS --> c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [?]

S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/8/2004 00:45 14336]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

WINRM REG_MULTI_SZ WINRM

.

Conteúdo da pasta 'Tarefas Agendadas'

.

2011-04-28 c:\windows\Tasks\AF4B6C5291851CFA.job

- c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe [2009-10-22 19:40]

.

2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{C54E4DC2-560C-48FC-90C1-7D9407A82835}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://start.facemoods.com/?a=gppc

uInternet Connection Wizard,ShellNext = iexplore

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com

IE: &Enviar para o OneNote - c:\arquiv~1\MICROS~2\Office14\ONBttnIE.dll/105

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office14\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

Trusted Zone: gov.com.br\caixa

DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab

DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-04-28 18:33

Windows 5.1.2600 Service Pack 3 NTFS

.

Procurando processos ocultos ...

.

Procurando entradas auto inicializáveis ocultas ...

.

Procurando ficheiros/arquivos ocultos ...

.

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

.

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

.

[HKEY_USERS\S-1-5-21-1202660629-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Òw*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

.

- - - - - - - > 'winlogon.exe'(656)

c:\arquivos de programas\GbPlugin\gbiehCef.dll

.

- - - - - - - > 'explorer.exe'(2328)

c:\windows\system32\WININET.dll

c:\arquiv~1\ARQUIV~1\MICROS~1\OFFICE14\Cultures\office.odf

c:\arquiv~1\MICROS~2\Office14\1046\GrooveIntlResource.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\arquivos de programas\GbPlugin\gbiehCef.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

c:\windows\system32\LEXBCES.EXE

c:\windows\system32\LEXPPS.EXE

c:\arquivos de programas\Alwil Software\Avast5\setup\avast.setup

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe

c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

c:\windows\system32\SearchIndexer.exe

c:\windows\system32\wscntfy.exe

c:\windows\system32\msiexec.exe

c:\windows\system32\wbem\wmiapsrv.exe

c:\windows\system32\SearchProtocolHost.exe

c:\windows\system32\SearchFilterHost.exe

.

**************************************************************************

.

Tempo para conclusão: 2011-04-28 18:37:34 - Máquina reiniciou

ComboFix-quarantined-files.txt 2011-04-28 21:37

ComboFix2.txt 2011-04-28 16:49

.

Pré-execução: 7.795.261.440 bytes disponíveis

Pós execução: 7.771.688.960 bytes disponíveis

.

Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5

- - End Of File - - AB5537DC71476D0DA1486D5AB1E1A244

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.