Hugstom 0 Denunciar post Postado Abril 5, 2011 OLA MEU PCA ENCONTRA-SE COM ALGUM TIPO DE VISRUS QUE FAS COM QUE MEU PC TRAVE E FIQUE COM A TELA TODA BRANCA PISCANDO E ENVIANDO MENSANGENS NO MSN NA CAIXA DE EMAIL ISSO OCORREU LOGO DEPOIS QUE INSTALEI O OFFICE 2010 E DAI PRA FRENTE TRAVA TODA HORA O ANTI VIRUS ACUSANDO VIRUS DE 15 EM 15 MINUTOS O PC FICOU LENTO E NAO CONSIGO REMOVER ESSE VIRUS SE FOR MESMO VIRUS ... DESDE JA OBRIGADO Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 16:14:31, on 5/4/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program-Files\Java\msnmsg.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Program-Files\Java\iexplorer.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Usuario\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://br.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C0B6368A-A218-4855-AE42-6AD2DAF9DDF6} - C:\WINDOWS\system32\javawhelper.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: (no name) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - (no file) O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - (no file) O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [avast5] "C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe" /nogui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsg] C:\Program-Files\Java\msnmsg.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [iexplorer] C:\Program-Files\Java\iexplorer.exe O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\ARQUIV~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user') O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: http://www.sbradesco.kit.net O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O20 - AppInit_DLLs: C:\WINDOWS\System32\dmdlgs32.dll O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O20 - Winlogon Notify: 487cc309517 - Invalid registry found O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Mail Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe O23 - Service: avast! Web Scanner - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: ProtexisLicensing - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe -- End of file - 9442 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Abril 5, 2011 Olá Hugstom 1. *Baixe o Bankerfix e salve-o no desktop *Execute-o, clique [OK] > [sIM] (se pedir alguma atualização) > [OK] > [ENTER] *Ao finalizar, tecle [ENTER] *Cole o relatório C:\LinhaDefensiva\relatorio.txt 2. *Baixe o MalwareBytes e salve-o no desktop *Instale o programa e aguarde a atualização *O programa será aberto automaticamente *Na aba [Verificação], selecione [Verificação completa] *Clique [Verificar] e selecione a partição onde o Windows está instalado *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados] *Cole o relatório apresentado (C:\Documents and settings\Nome_do_Usuário\Dados de aplicativos\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam.txt) Caso já tenhas o Malwarebytes instalado.... *Abra o Malwarebytes, clique [Atualização] > [baixar Atualizações] *Na aba [Verificação], selecione [x] Verificação completa *Clique [Verificar] e selecione a partição onde o Windows está instalado *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
Hugstom 0 Denunciar post Postado Abril 26, 2011 Gostaria de acrescentar que na tentativa desesperada de conseguir conserta meu pc movi os arquivos do Disco C: para o Disco D: E ISSO fez com que eu perdesse algums arquivos, mais um deles nao consegui recupera Meu msn e ja tentei de tudo exclui mais quando instalo outro tem um aviso que me diz que ja tenho ele instalado e meu avast ainda fica dizendo que um arquivo infectado foi encontrado mais nao retira isso ocorre de 7 em 7 minutos marcado no relogio obrigado ... BankerFix 3.1 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2011-04-26 - 15:05 ------------------------------------------------------- Lista de Definição: 2011-03-01-1 | CORE: 2010-12-28-6 ======================================================= Arquivo infectado detectado: C:\WINDOWS\Media\ev.dll Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\Media\logo.dll Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\Media\mp3configuration.ini Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\Media\NewIcon.ico Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\Media\Ok.dll Arquivo infectado removido com sucesso! ----- Fim ------------------------- Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Versão da Base de Dados: 6443 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 26/4/2011 15:56:43 mbam-log-2011-04-26 (15-56-43).txt Tipo de Verificação: Verificação Completa (C:\|) Objetos escaneados: 193519 Tempo decorrido: 41 minuto(s), 50 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 0 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: (Não foram detectados ítens maliciosos) Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Abril 26, 2011 1. *Delete o Bankerfix e a pasta C:\LinhaDefensiva 2. *Baixe o ERUNT e salve-o no desktop *Crie uma pasta em C:\ chamada ERUNT e extraia para ela *Execute o arquivo C:\ERUNT\ERUNT.exe *Clique [OK] > [OK] > [sim] > [OK] 3. *Desative temporariamente seu antivírus Clique com o botão direito do mouse no ícone do Avast ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme. *Baixe o ComboFix e salve-o no desktop *Execute-o e aceite o contrato *Se o Console de Recuperação do Microsoft Windows não estiver instalado, aceite a sua instalação *Após a instalação do Console, clique [sim] e aguarde a conclusão das etapas *Não use o mouse nem o teclado durante as etapas, pois implicará na desconfiguração do seu desktop! *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
Hugstom 0 Denunciar post Postado Abril 28, 2011 Olá Boa Tarde segue aqui o relatório ComboFix 11-04-27.04 - Usuario 28/04/2011 13:37:23.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.594 [GMT -3:00] Executando de: c:\documents and settings\Usuario\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} * Criado um novo ponto de restauração . ADS - system32: deleted 2 bytes in 1 streams. ADS - drivers: deleted 324 bytes in 1 streams. . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\arquivos de programas\arquivos comuns\picasa check\loga.dll c:\arquivos de programas\arquivos comuns\picasa check\logaa.dll c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\CleanUp.lnk c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\License Agreement.lnk c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\Readme.lnk c:\documents and settings\All Users\Menu Iniciar\Programas\CleanUp\Uninstall.lnk c:\documents and settings\Usuario\AppTime c:\documents and settings\Usuario\WINDOWS c:\windows\Media\mp3\mod01.mp3 c:\windows\Media\mp3\mod03.mp3 c:\windows\Media\mp3\mod04.mp3 c:\windows\sys c:\windows\sys\System.ini c:\windows\system32\_000005_.tmp.dll c:\windows\system32\bios_setup1399.txt c:\windows\system32\drivers\npf.sys c:\windows\system32\Packet.dll c:\windows\system32\pthreadVC.dll c:\windows\system32\sysdm.exe c:\windows\system32\wpcap.dll c:\windows\winhelp26.ini . . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NPF -------\Service_npf . . (((((((((((((((( Arquivos/Ficheiros criados de 2011-03-28 to 2011-04-28 )))))))))))))))))))))))))))) . . 2011-04-28 16:09 . 2011-04-28 16:10 -------- d-----w- C:\ERUNT 2011-04-12 17:37 . 2011-04-12 17:37 -------- d-----w- c:\arquivos de programas\MegaJogos 2011-04-11 16:15 . 2011-04-11 16:15 -------- d-----w- c:\arquivos de programas\MSBuild 2011-04-11 16:14 . 2011-04-11 16:14 -------- d-----w- c:\arquivos de programas\Microsoft Synchronization Services 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\documents and settings\All Users\Microsoft 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft.NET 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft SQL Server Compact Edition 2011-04-11 16:05 . 2011-04-11 16:05 -------- d-----w- c:\arquivos de programas\Microsoft Visual Studio 8 2011-04-11 16:02 . 2011-04-11 16:16 -------- d-----w- c:\windows\SHELLNEW 2011-04-11 16:01 . 2011-04-11 16:01 -------- d-----r- C:\MSOCache 2011-04-11 15:29 . 2011-04-11 15:29 -------- d-----w- c:\arquivos de programas\Microsoft Analysis Services 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes 2011-04-06 17:00 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2011-04-06 17:00 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-05 18:02 . 2011-04-06 02:40 -------- d-----w- c:\windows\SxsCaPendDel 2011-04-04 19:11 . 2011-04-04 19:11 -------- d-----w- c:\arquivos de programas\VS Revo Group 2011-04-04 19:03 . 2011-04-04 19:03 -------- d-----w- c:\arquivos de programas\Purple Parrot 2011-04-04 19:03 . 1999-05-07 05:00 209408 ----a-w- c:\windows\system32\tabctl32.ocx 2011-04-04 19:03 . 1998-06-24 05:00 137000 ----a-w- c:\windows\system32\msmapi32.ocx 2011-04-04 16:41 . 2011-04-06 14:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2011-04-04 14:18 . 2010-04-28 10:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys 2011-04-04 00:26 . 2011-04-04 20:32 -------- d-----w- c:\arquivos de programas\Google 2011-04-03 19:44 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-04-03 19:44 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-04-03 19:44 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-04-03 19:44 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-04-03 19:44 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-04-03 19:44 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-04-03 19:44 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-04-03 19:44 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr 2011-04-03 19:44 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe 2011-04-03 03:03 . 2011-04-03 03:03 -------- d-----w- C:\Program-Files 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\com.livebrush 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Livebrush 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe AIR . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-25 23:29 . 2004-08-04 03:45 1172480 ----a-w- c:\windows\system32\msxml3.dll 2011-03-07 05:33 . 2008-09-23 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:36 . 2004-08-04 03:45 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:53 . 2004-08-04 03:38 1858048 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:08 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:08 . 2004-08-04 03:45 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 23:08 . 2004-08-04 03:45 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-02-22 11:43 . 2004-08-04 03:37 385024 ----a-w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2004-08-04 02:15 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 02:14 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2004-08-04 03:44 290432 ----a-w- c:\windows\system32\atmfd.dll 2011-02-12 16:03 . 2011-02-12 16:03 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-02-12 16:03 . 2011-02-07 00:29 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-02-09 13:53 . 2004-08-04 03:45 270848 ----a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53 . 2004-08-04 03:45 186880 ----a-w- c:\windows\system32\encdec.dll 2011-02-08 13:33 . 2004-08-04 03:45 978944 ----a-w- c:\windows\system32\mfc42.dll 2011-02-08 13:33 . 2004-08-04 03:45 974848 ----a-w- c:\windows\system32\mfc42u.dll 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FF.tmp 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FE.tmp 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FD.tmp 2011-02-02 21:11 . 2009-12-25 16:18 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-02-02 07:58 . 2008-09-23 19:23 2067456 ----a-w- c:\windows\system32\mstscax.dll 2009-10-10 16:16 . 2009-10-10 16:16 22074000 ----a-w- c:\arquivos de programas\MSNOIE8_PTBR_XP.EXE . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552] "avast5"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912] "BCSSync"="c:\arquivos de programas\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "ISUSPM Startup"="c:\arquiv~1\ARQUIV~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399003}"= "c:\arquivos de programas\GbPlugin\gbiehcef.dll" [2011-02-18 346568] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef] 2011-02-18 18:50 346568 ----a-w- c:\arquivos de programas\GbPlugin\gbiehcef.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /* . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\LEXPPS.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\WINDOWS\\system32\\rtcshare.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\OUTLOOK.EXE"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management . R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [19/3/2010 10:16 46664] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/4/2011 16:44 165584] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/4/2011 16:44 17744] R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [19/3/2010 10:16 54728] R2 SentinelKeysServer;Sentinel Keys Server;c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [11/7/2008 00:02 328992] S2 azverrk;Universal Network;c:\windows\system32\svchost.exe -k netsvcs [4/8/2004 00:45 14336] S2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 18:19 13592] S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\arquivos de programas\Microsoft Office\Office14\GROOVE.EXE [25/3/2010 10:25 30969208] S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000] S3 SASENUM;SASENUM;\??\c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS --> c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [?] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/8/2004 00:45 14336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . Conteúdo da pasta 'Tarefas Agendadas' . 2011-04-28 c:\windows\Tasks\AF4B6C5291851CFA.job - c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe [2009-10-22 19:40] . 2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{C54E4DC2-560C-48FC-90C1-7D9407A82835}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . . ------- Scan Suplementar ------- . uStart Page = hxxp://start.facemoods.com/?a=gppc uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com IE: &Enviar para o OneNote - c:\arquiv~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html Trusted Zone: gov.com.br\caixa DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab . - - - - ORFÃOS REMOVIDOS - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKCU-Run-msnmsgr - c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe Notify-487cc309517 - (no file) Notify-dimsntfy - (no file) . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-28 13:44 Windows 5.1.2600 Service Pack 3 NTFS . Procurando processos ocultos ... . Procurando entradas auto inicializáveis ocultas ... . Procurando ficheiros/arquivos ocultos ... . Varredura completada com sucesso arquivos/ficheiros ocultos: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet004\Services\azverrk] "ServiceDll"="c:\windows\system32\pxeqog.dll" . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_USERS\S-1-5-21-1202660629-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Òw*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- . - - - - - - - > 'winlogon.exe'(656) c:\arquivos de programas\GbPlugin\gbiehCef.dll . - - - - - - - > 'explorer.exe'(2948) c:\windows\system32\WININET.dll c:\arquiv~1\ARQUIV~1\MICROS~1\OFFICE14\Cultures\office.odf c:\arquiv~1\MICROS~2\Office14\1046\GrooveIntlResource.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\Alwil Software\Avast5\AvastSvc.exe c:\windows\system32\LEXBCES.EXE c:\windows\system32\LEXPPS.EXE c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE c:\arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe c:\windows\system32\SearchIndexer.exe c:\arquivos de programas\Alwil Software\Avast5\setup\avast.setup c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\msiexec.exe c:\windows\system32\SearchProtocolHost.exe c:\windows\system32\SearchFilterHost.exe . ************************************************************************** . Tempo para conclusão: 2011-04-28 13:48:59 - Máquina reiniciou ComboFix-quarantined-files.txt 2011-04-28 16:48 . Pré-execução: 7.857.205.248 bytes disponíveis Pós execução: 7.897.956.352 bytes disponíveis . WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5 - - End Of File - - 9EA5858FADD609BFF8F57D699742D1E1 Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Abril 28, 2011 *Abra o bloco de notas e cole nele o código abaixo: File:: c:\windows\system32\pxeqog.dll FileLook:: c:\windows\system32\REN1FF.tmp c:\windows\system32\REN1FD.tmp c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe Registry:: [-HKEY_LOCAL_MACHINE\System\ControlSet004\Services\azverrk] NetSvc:: azverrk Driver:: azverrk *Salve o arquivo no desktop como CFScript.txt *Arraste-o para o Combofix conforme ilustração abaixo: *Enquanto o combofix estiver em execução, não use o mouse nem o teclado!! *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
Hugstom 0 Denunciar post Postado Abril 28, 2011 Segue o relatório em andamento ... ComboFix 11-04-27.04 - Usuario 28/04/2011 18:25:13.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1015.621 [GMT -3:00] Executando de: c:\documents and settings\Usuario\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Usuario\Desktop\CFScript..txt AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . FILE :: "c:\windows\system32\pxeqog.dll" . ADS - drivers: deleted 208 bytes in 1 streams. . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((((( Drivers/Serviços ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_AZVERRK -------\Service_azverrk . . (((((((((((((((( Arquivos/Ficheiros criados de 2011-03-28 to 2011-04-28 )))))))))))))))))))))))))))) . . 2011-04-28 16:09 . 2011-04-28 16:10 -------- d-----w- C:\ERUNT 2011-04-12 17:37 . 2011-04-12 17:37 -------- d-----w- c:\arquivos de programas\MegaJogos 2011-04-11 16:15 . 2011-04-11 16:15 -------- d-----w- c:\arquivos de programas\MSBuild 2011-04-11 16:14 . 2011-04-11 16:14 -------- d-----w- c:\arquivos de programas\Microsoft Synchronization Services 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\documents and settings\All Users\Microsoft 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft.NET 2011-04-11 16:12 . 2011-04-11 16:12 -------- d-----w- c:\arquivos de programas\Microsoft SQL Server Compact Edition 2011-04-11 16:05 . 2011-04-11 16:05 -------- d-----w- c:\arquivos de programas\Microsoft Visual Studio 8 2011-04-11 16:02 . 2011-04-11 16:16 -------- d-----w- c:\windows\SHELLNEW 2011-04-11 16:01 . 2011-04-11 16:01 -------- d-----r- C:\MSOCache 2011-04-11 15:29 . 2011-04-11 15:29 -------- d-----w- c:\arquivos de programas\Microsoft Analysis Services 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes 2011-04-06 17:00 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2011-04-06 17:00 . 2011-04-06 17:00 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2011-04-06 17:00 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-04-05 18:02 . 2011-04-06 02:40 -------- d-----w- c:\windows\SxsCaPendDel 2011-04-04 19:11 . 2011-04-04 19:11 -------- d-----w- c:\arquivos de programas\VS Revo Group 2011-04-04 19:03 . 2011-04-04 19:03 -------- d-----w- c:\arquivos de programas\Purple Parrot 2011-04-04 19:03 . 1999-05-07 05:00 209408 ----a-w- c:\windows\system32\tabctl32.ocx 2011-04-04 19:03 . 1998-06-24 05:00 137000 ----a-w- c:\windows\system32\msmapi32.ocx 2011-04-04 16:41 . 2011-04-06 14:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2011-04-04 14:18 . 2010-04-28 10:44 54760 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys 2011-04-04 00:26 . 2011-04-04 20:32 -------- d-----w- c:\arquivos de programas\Google 2011-04-03 19:44 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-04-03 19:44 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-04-03 19:44 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-04-03 19:44 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-04-03 19:44 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2011-04-03 19:44 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys 2011-04-03 19:44 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2011-04-03 19:44 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr 2011-04-03 19:44 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe 2011-04-03 03:03 . 2011-04-03 03:03 -------- d-----w- C:\Program-Files 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\com.livebrush 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Livebrush 2011-04-01 13:31 . 2011-04-01 13:31 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe AIR . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-04-25 23:29 . 2004-08-04 03:45 1172480 ----a-w- c:\windows\system32\msxml3.dll 2011-03-07 05:33 . 2008-09-23 19:25 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:36 . 2004-08-04 03:45 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:53 . 2004-08-04 03:38 1858048 ----a-w- c:\windows\system32\win32k.sys 2011-02-22 23:08 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll 2011-02-22 23:08 . 2004-08-04 03:45 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-02-22 23:08 . 2004-08-04 03:45 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-02-22 11:43 . 2004-08-04 03:37 385024 ----a-w- c:\windows\system32\html.iec 2011-02-17 13:18 . 2004-08-04 02:15 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-02-17 13:18 . 2004-08-04 02:14 357888 ----a-w- c:\windows\system32\drivers\srv.sys 2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56 . 2004-08-04 03:44 290432 ----a-w- c:\windows\system32\atmfd.dll 2011-02-12 16:03 . 2011-02-12 16:03 73728 ----a-w- c:\windows\system32\javacpl.cpl 2011-02-12 16:03 . 2011-02-07 00:29 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-02-09 13:53 . 2004-08-04 03:45 270848 ----a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53 . 2004-08-04 03:45 186880 ----a-w- c:\windows\system32\encdec.dll 2011-02-08 13:33 . 2004-08-04 03:45 978944 ----a-w- c:\windows\system32\mfc42.dll 2011-02-08 13:33 . 2004-08-04 03:45 974848 ----a-w- c:\windows\system32\mfc42u.dll 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FF.tmp 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FE.tmp 2011-02-07 00:29 . 2011-02-07 00:29 0 ----a-w- c:\windows\system32\REN1FD.tmp 2011-02-02 21:11 . 2009-12-25 16:18 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-02-02 07:58 . 2008-09-23 19:23 2067456 ----a-w- c:\windows\system32\mstscax.dll 2009-10-10 16:16 . 2009-10-10 16:16 22074000 ----a-w- c:\arquivos de programas\MSNOIE8_PTBR_XP.EXE . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . . --- c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe --- Company: Nowhere Serone File Description: Nos no theshian append sperow hideksi File Version: 2, 2, 0, 4 Product Name: Edited default appears Copyright: Copyright Lan Proceed Doulai 2004. All rights reserved. Original Filename: Tool.exe File size: 286720 Created time: 2009-10-22 21:33 Modified time: 2009-12-16 19:40 MD5: A9B34B97937675BDE34650D89C77FA5D SHA1: 68036C05B3D76E08D1969DB8D2AC8004CC11087E . . --- c:\windows\system32\REN1FD.tmp --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File size: 0 Created time: 2011-02-07 00:29 Modified time: 2011-02-07 00:29 MD5: D41D8CD98F00B204E9800998ECF8427E SHA1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709 . . --- c:\windows\system32\REN1FF.tmp --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File size: 0 Created time: 2011-02-07 00:29 Modified time: 2011-02-07 00:29 MD5: D41D8CD98F00B204E9800998ECF8427E SHA1: DA39A3EE5E6B4B0D3255BFEF95601890AFD80709 . . ((((((((((((((((((((((((((((( SnapShot@2011-04-28_16.44.29 ))))))))))))))))))))))))))))))))))))))))) . + 2011-04-28 21:33 . 2011-04-28 21:33 16384 c:\windows\Temp\Perflib_Perfdata_110.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552] "avast5"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912] "BCSSync"="c:\arquivos de programas\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "ISUSPM Startup"="c:\arquiv~1\ARQUIV~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{E37CB5F0-51F5-4395-A808-5FA49E399003}"= "c:\arquivos de programas\GbPlugin\gbiehcef.dll" [2011-02-18 346568] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef] 2011-02-18 18:50 346568 ----a-w- c:\arquivos de programas\GbPlugin\gbiehcef.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /* . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\LEXPPS.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\WINDOWS\\system32\\rtcshare.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office14\\OUTLOOK.EXE"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management . R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [19/3/2010 10:16 46664] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/4/2011 16:44 165584] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/4/2011 16:44 17744] R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [19/3/2010 10:16 54728] R2 SentinelKeysServer;Sentinel Keys Server;c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [11/7/2008 00:02 328992] S2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 18:19 13592] S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\arquivos de programas\Microsoft Office\Office14\GROOVE.EXE [25/3/2010 10:25 30969208] S3 osppsvc;Office Software Protection Platform;c:\arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/1/2010 21:37 4640000] S3 SASENUM;SASENUM;\??\c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS --> c:\arquivos de programas\SUPERAntiSpyware\SASENUM.SYS [?] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/8/2004 00:45 14336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] WINRM REG_MULTI_SZ WINRM . Conteúdo da pasta 'Tarefas Agendadas' . 2011-04-28 c:\windows\Tasks\AF4B6C5291851CFA.job - c:\docume~1\usuario\dadosd~1\shimpu~1\city ping proxy.exe [2009-10-22 19:40] . 2011-04-28 c:\windows\Tasks\User_Feed_Synchronization-{C54E4DC2-560C-48FC-90C1-7D9407A82835}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . . ------- Scan Suplementar ------- . uStart Page = hxxp://start.facemoods.com/?a=gppc uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://br.rd.yahoo.com/customize/ycomp/defaults/su/*http://br.yahoo.com IE: &Enviar para o OneNote - c:\arquiv~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html Trusted Zone: gov.com.br\caixa DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://imagem.caixa.gov.br/cab/gbpdist.cab . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-04-28 18:33 Windows 5.1.2600 Service Pack 3 NTFS . Procurando processos ocultos ... . Procurando entradas auto inicializáveis ocultas ... . Procurando ficheiros/arquivos ocultos ... . Varredura completada com sucesso arquivos/ficheiros ocultos: 0 . ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_USERS\S-1-5-21-1202660629-492894223-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Òw*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- . - - - - - - - > 'winlogon.exe'(656) c:\arquivos de programas\GbPlugin\gbiehCef.dll . - - - - - - - > 'explorer.exe'(2328) c:\windows\system32\WININET.dll c:\arquiv~1\ARQUIV~1\MICROS~1\OFFICE14\Cultures\office.odf c:\arquiv~1\MICROS~2\Office14\1046\GrooveIntlResource.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\arquivos de programas\GbPlugin\gbiehCef.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\Alwil Software\Avast5\AvastSvc.exe c:\windows\system32\LEXBCES.EXE c:\windows\system32\LEXPPS.EXE c:\arquivos de programas\Alwil Software\Avast5\setup\avast.setup c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE c:\arquivos de programas\Arquivos comuns\Protexis\License Service\PSIService.exe c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\arquivos de programas\Arquivos comuns\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe c:\windows\system32\SearchIndexer.exe c:\windows\system32\wscntfy.exe c:\windows\system32\msiexec.exe c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\SearchProtocolHost.exe c:\windows\system32\SearchFilterHost.exe . ************************************************************************** . Tempo para conclusão: 2011-04-28 18:37:34 - Máquina reiniciou ComboFix-quarantined-files.txt 2011-04-28 21:37 ComboFix2.txt 2011-04-28 16:49 . Pré-execução: 7.795.261.440 bytes disponíveis Pós execução: 7.771.688.960 bytes disponíveis . Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5 - - End Of File - - AB5537DC71476D0DA1486D5AB1E1A244 Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Abril 28, 2011 Envie os arquivos para análise em http://virusscan.jotti.org c:\windows\system32\REN1FF.tmpc:\windows\system32\REN1FD.tmp Cole os links dos resultados. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Maio 28, 2011 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites