Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Edvan

[Resolvido] &nbspNovo Log para analise

Recommended Posts

Pessoal esse log é de outra maquina, sei que já tenho outro tópico aberto, mais como nao posso postar outros logs no mesmo tópico, então estou criando mais um aqui.

 

BankerFix 3.1 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2012-06-04 - 11:05

-------------------------------------------------------

Lista de Definição: 2012-03-19-1 | CORE: 2012-01-27-1

=======================================================

 

Arquivo infectado detectado: C:\WINDOWS\inf\asynceql.inf

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\Media\mssmtp.wav

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system\mkp.dll

Arquivo infectado removido com sucesso!

 

Arquivo infectado detectado: C:\WINDOWS\system32\drwtsn32.dll

Arquivo infectado removido com sucesso!

 

 

 

----- Fim -------------------------

 

Malwarebytes Anti-Malware 1.61.0.1400

www.malwarebytes.org

 

Versão da Base de Dados: v2012.06.04.04

 

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

f003204 :: FUN0044 [limitado]

 

04/06/2012 14:28:26

mbam-log-2012-06-04 (14-28-26).txt

 

Tipo de Verificação: Verificação Completa

Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opções de verificação desativadas: P2P

Objetos escaneados: 351640

Tempo decorrido: 3 hora(s), 15 minuto(s), 46 segundo(s)

 

Processos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Detectadas: 17

HKLM\SOFTWARE\Microsoft\DRM\amty (Worm.Autorun) -> Enviado para a Quarentena e deletado com sucesso.

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__GbPluginBb (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\CLSID\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\TypeLib\{C41A1C01-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\Interface\{5C350402-AD9A-41E7-A303-C49F6C520000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\Gbieh.GbIehObj.1 (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\Gbieh.GbIehObj (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginBb (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\Gbieh.GbPluginObj.1 (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCR\Gbieh.GbPluginObj (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso.

 

Valores de Registro Detectadas: 2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Data: GbPlugin ShlObj -> Enviado para a Quarentena e deletado com sucesso.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Data: GbPlugin ShlObj -> Enviado para a Quarentena e deletado com sucesso.

 

Itens de Dados no Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Pastas Detectadas: 1

C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> Enviado para a Quarentena e deletado com sucesso.

 

Arquivos Detectados: 2

C:\Arquivos de programas\GbPlugin\gbieh.dll (Trojan.Vundo) -> Será deletado na próxima inicialização.

C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> Enviado para a Quarentena e deletado com sucesso.

 

(fim)

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 08:54:21, on 05/06/2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe

c:\windows\system32\SpyPrinter.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O4 - HKLM\..\Run: [avast5] C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe /nogui

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CS2\Services\Tcpip\..\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: NameServer = 10.4.65.16

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = funpec.br

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SpyPrinterD - Unknown owner - c:\windows\system32\SpyPrinter.exe

 

--

End of file - 5981 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Edvan

 

|- Baixe: < desktopicon.png > ( ... by sUBs )

|- Salve-o no desktop! ( Área de trabalho! )

|- Ps: Desabilite seu antivírus,antispywares e/ou firewall. ( Menos o do Windows! )

|- Feche algum programa/arquivo que esteja aberto.

|- Feche,também,seu navegador! ( IE,Firefox,Opera ou Google Chrome )

|- Ps: Esteja conectado(a) à Internet. <- Importante!

|- Execute ComboFix.exe,com um duplo clique.

|- Para Windows Vista e/ou 7,dê clique direito em ComboFix.exe e execute-o como administrador.

|- Ps: Instale o "Console de Recuperação",caso seja solicitado!

|- Ps: Ficará,portanto,à seu critério optar por sua instalação.

|- Surgindo alguma mensagem de erro,execute ComboFix.exe em Modo de Segurança com rede.

|- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador.

|- Abrir-se-á a janela Auto Scan.

 

etapas.jpg

 

|- Aguarde a finalização de todas as Etapas.

|- Durante o scan,evite utilizar o mouse ou teclado!

|- Concluindo,poste: C:\ComboFix.txt

|- "ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão de analistas de segurança."

|- Poste,também,HijackThis atualizado!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 12-06-05.03 - f003204 05/06/2012 14:28:15.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.991.515 [GMT -3:00]

Executando de: c:\documents and settings\f003204\Desktop\60329_combofix_123123.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

AV: Avira AntiVir PersonalEdition Classic *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}

AV: Avira AntiVir PersonalEdition Classic *Enabled/Updated* {804E5358-FFA4-00C8-0D24-347CA8A3377C}

.

ADS - system32: deleted 2 bytes in 1 streams.

ADS - drivers: deleted 216 bytes in 2 streams.

.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Administrador.PROMOCAO\WINDOWS

c:\documents and settings\f003204\WINDOWS

c:\documents and settings\Niomar.PROMOCAO\WINDOWS

C:\restore

c:\windows\IsUn0416.exe

c:\windows\Media\_tmp

c:\windows\system\chron32.dll

c:\windows\system32\SET3F8.tmp

c:\windows\system32\SET3F9.tmp

c:\windows\system32\SET3FA.tmp

c:\windows\system32\SET3FB.tmp

c:\windows\system32\SET400.tmp

c:\windows\system32\SETB1.tmp

c:\windows\system32\SETBD.tmp

.

.

(((((((((((((((( Arquivos/Ficheiros criados de 2012-05-05 to 2012-06-05 ))))))))))))))))))))))))))))

.

.

2012-06-05 11:53 . 2012-06-05 11:53 388608 ----a-w- C:\HiJackThis.exe

2012-06-04 20:44 . 2012-06-04 20:44 54016 ----a-w- c:\windows\system32\drivers\fmhuptxw.sys

2012-05-24 16:55 . 2012-05-24 16:55 -------- d-----w- c:\arquivos de programas\Mozilla Maintenance Service

2012-05-24 16:55 . 2012-05-24 16:55 157352 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice_installer.exe

2012-05-24 16:55 . 2012-05-24 16:55 129976 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice.exe

.

.

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-04 17:07 . 2012-04-18 19:57 28880 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys

2012-04-18 20:25 . 2012-04-18 20:26 73728 ----a-w- c:\windows\system32\javacpl.cpl

2012-04-18 20:25 . 2010-10-22 17:00 472808 -c--a-w- c:\windows\system32\deployJava1.dll

2012-04-05 12:34 . 2009-10-27 20:08 46408 ----a-w- c:\windows\system32\drivers\gbpkm.sys

2012-05-24 16:55 . 2011-10-21 17:39 97208 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por padrão não são apresentadas.

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-03-07 00:15 123536 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4waxx.sys]

@="Driver"

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk]

backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^hp psc 2000 Series.lnk]

backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk]

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Post-it® Software Notes Lite.lnk]

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Post-it® Software Notes Lite.lnk

backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^Niomar.PROMOCAO^Menu Iniciar^Programas^Inicializar^Reboot.exe]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-13 22:21 1695232 ------w- c:\arquivos de programas\Messenger\msmsgs.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]

2003-12-05 06:36 249856 -c--a-w- c:\windows\system32\Keyhook.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]

2002-07-12 10:15 106496 -c--a-w- c:\windows\SiSUSBrg.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

2003-12-19 09:53 65024 -c--a-w- c:\windows\SOUNDMAN.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2012-01-18 17:02 254696 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"GbpSv"=2 (0x2)

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Fortes Informática\\RemProtDeamon.exe"=

"c:\\WINDOWS\\system32\\DWRCS.EXE"=

"c:\\Arquivos de programas\\Canon\\DIAS\\CnxDIAS.exe"=

"c:\\Arquivos de programas\\NetMeeting\\conf.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"14674:TCP"= 14674:TCP:NortonAV

"18245:TCP"= 18245:TCP:NortonAV

"17860:TCP"= 17860:TCP:NortonAV

"15603:TCP"= 15603:TCP:NortonAV

"18163:TCP"= 18163:TCP:NortonAV

"15280:TCP"= 15280:TCP:NortonAV

"15693:TCP"= 15693:TCP:NortonAV

"14644:TCP"= 14644:TCP:NortonAV

"17233:TCP"= 17233:TCP:NortonAV

"16774:TCP"= 16774:TCP:NortonAV

"14545:TCP"= 14545:TCP:NortonAV

"18857:TCP"= 18857:TCP:NortonAV

"18019:TCP"= 18019:TCP:NortonAV

"16171:TCP"= 16171:TCP:NortonAV

"16282:TCP"= 16282:TCP:NortonAV

"12432:TCP"= 12432:TCP:NortonAV

"14298:TCP"= 14298:TCP:NortonAV

.

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [27/10/2009 17:08 46408]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20/06/2011 08:09 612184]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [26/01/2009 15:05 337880]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [26/01/2009 15:05 20696]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [27/10/2009 17:10 214088]

R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880]

S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys [?]

S2 gupdate;Serviço do Google Update (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176]

S2 SpyPrinterD;SpyPrinterD;c:\windows\system32\SpyPrinter.exe [21/05/2008 16:53 1406464]

S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176]

S3 MozillaMaintenance;Mozilla Maintenance Service;c:\arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe [24/05/2012 13:55 129976]

S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880]

S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s [?]

S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

.

2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49]

.

2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49]

.

2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.funpec.br/ponto_online/

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

Trusted Zone: bancobrasil.com.br\www

Trusted Zone: bancobrasil.com.br\www14

Trusted Zone: bancobrasil.com.br\www2

Trusted Zone: bb.com.br\www

Trusted Zone: com.br\www.bancobrasil

Trusted Zone: com.br\www.bb

Trusted Zone: com.br\www14.bancobrasil

Trusted Zone: com.br\www2.bancobrasil

TCP: DhcpNameServer = 10.4.65.16

FF - ProfilePath - c:\documents and settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\

FF - prefs.js: browser.startup.homepage - hxxp://funpec.br/

.

- - - - ORFÃOS REMOVIDOS - - - -

.

MSConfigStartUp-Cmaudio - cmicnfg.cpl

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-06-05 14:36

Windows 5.1.2600 Service Pack 3 NTFS

.

Procurando processos ocultos ...

.

Procurando entradas auto inicializáveis ocultas ...

.

Procurando ficheiros/arquivos ocultos ...

.

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

.

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

.

[HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithList]

@Class="Shell"

"a"="shimgvw.dll"

"MRUList"="ab"

"b"="mspaint.exe"

.

[HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithProgids]

"$¨+_auto_file"=hex(0):

.

[HKEY_LOCAL_MACHINE\software\Adobe\CommonFiles\{AC76BA86-1033-0000-7760-000000000001}\ColorProfiles]

@DACL=(02 0000)

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AdobeRGB1998.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AppleRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Color Management Off.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\ColorMatchRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Acrobat 4.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Photoshop 4.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Europe Prepress Defaults.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Japan Color Prepress.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Coated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Uncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanWebCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\BlackWhite.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\CIERGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\JapanStandard.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\NTSC1953.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\PAL_SECAM.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop4DefaultCMYK.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop5DefaultCMYK.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\SMPTE-C.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\WideGamutRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Photoshop 5 Default Spaces.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\sRGB Color Space Profile.icm"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\US Prepress Defaults.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebCoatedSWOP.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Web Graphics Defaults.csf"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\000021599B0090400000000000F01FEC\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="Microsoft Application Error Reporting"

"1"="OFFICE12;1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"="READER8;[1]"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\C1B24092317057547BACC5E8B780994D\SourceList\Media]

@DACL=(02 0000)

"MediaPackage"="\\"

"1"="WILTON - VB;"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D6461317C3DC4F04799BDCE9E42626FE\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";Microsoft .NET Framework 2.0 [Disk 1]"

"2"=";Microsoft .NET Framework 2.0 [Disk 1]"

"3"=";Microsoft .NET Framework 2.0 [Disk 1]"

"4"=";Microsoft .NET Framework 2.0 [Disk 1]"

"5"=";Microsoft .NET Framework 2.0 [Disk 1]"

"6"=";Microsoft .NET Framework 2.0 [Disk 1]"

"7"=";Microsoft .NET Framework 2.0 [Disk 1]"

"8"=";Microsoft .NET Framework 2.0 [Disk 1]"

"9"=";Microsoft .NET Framework 2.0 [Disk 1]"

"10"=";Microsoft .NET Framework 2.0 [Disk 1]"

"11"=";Microsoft .NET Framework 2.0 [Disk 1]"

"12"=";Microsoft .NET Framework 2.0 [Disk 1]"

"13"=";Microsoft .NET Framework 2.0 [Disk 1]"

.

Tempo para conclusão: 2012-06-05 14:38:30

ComboFix-quarantined-files.txt 2012-06-05 17:38

.

Pré-execução: 5.872.652.288 bytes disponíveis

Pós execução: 6.229.417.984 bytes disponíveis

.

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - 109FCDB303BB445B4E9458B3D0CE68C8

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:42:53, on 05/06/2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\HiJackThis.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CS2\Services\Tcpip\..\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: NameServer = 10.4.65.16

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = funpec.br

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = funpec.br

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SpyPrinterD - Unknown owner - c:\windows\system32\SpyPrinter.exe

 

--

End of file - 5525 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Edvan

 

|- O Avast é seu antivírus usual?

|- Ps: Conheces o ficheiro em destaque? c:\windows\system32\drivers\fmhuptxw.sys

 

#######

S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys[?]

#######

|- E o driver ( ati4waxx.sys ),é de seu conhecimento?

 

-/-

 

|- Selecione e copie,o conteúdo que está em "vermelho",para o Bloco de Notas.

|- Salve-o,no desktop,com o nome: CFScript <-- Texto!

 

File::

Documents and Settings\Niomar.PROMOCAO\Menu Iniciar\Programas\Inicializar\Reboot.exe

 

SecCenter::

AV: Avira AntiVir PersonalEdition Classic *Enabled/Outdated* {00000000-0000-0000-0000-000000000000}

AV: Avira AntiVir PersonalEdition Classic *Enabled/Updated* {804E5358-FFA4-00C8-0D24-347CA8A3377C}

 

Registry::

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"14674:TCP"=-

"18245:TCP"=-

"17860:TCP"=-

"15603:TCP"=-

"18163:TCP"=-

"15280:TCP"=-

"15693:TCP"=-

"14644:TCP"=-

"17233:TCP"=-

"16774:TCP"=-

"14545:TCP"=-

"18857:TCP"=-

"18019:TCP"=-

"16171:TCP"=-

"16282:TCP"=-

"12432:TCP"=-

"14298:TCP"=-

 

|- Ps: Desabilite,temporariamente,seu antivírus.

|- Ps: Não utilizem este script em outra máquina!

|- Arraste,o CFScript.txt para o ícone/interior do ComboFix.

|- Veja a demonstração!

 

2872959479_997d4500c4_o.gif

 

|- Atenda à solicitação,que deverá surgir,para rodar o ComboFix.

|- Ps: Faça o arraste,até surgir essa solicitação! ( janela )

|- Concluindo,poste: C:\ComboFix.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Tarde! Edvan

 

|- O Avast é seu antivírus usual?

|- Ps: Conheces o ficheiro em destaque? c:\windows\system32\drivers\fmhuptxw.sys

 

#######

S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys[?]

#######

|- E o driver ( ati4waxx.sys ),é de seu conhecimento?

 

Sim amigo DigRam, o antivírus usual que essa maquina usa é o Avast.

 

Desconheço todos esses ficheiros!

 

 

 

 

 

 

ComboFix 12-06-05.03 - f003204 05/06/2012 17:30:36.2.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.991.608 [GMT -3:00]

Executando de: c:\documents and settings\f003204\Desktop\60329_combofix_123123.exe

Comandos utilizados :: c:\documents and settings\f003204\Desktop\CFScript.txt

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

(((((((((((((((( Arquivos/Ficheiros criados de 2012-05-05 to 2012-06-05 ))))))))))))))))))))))))))))

.

.

2012-06-05 11:53 . 2012-06-05 11:53 388608 ----a-w- C:\HiJackThis.exe

2012-06-04 20:44 . 2012-06-04 20:44 54016 ----a-w- c:\windows\system32\drivers\fmhuptxw.sys

2012-05-24 16:55 . 2012-05-24 16:55 -------- d-----w- c:\arquivos de programas\Mozilla Maintenance Service

2012-05-24 16:55 . 2012-05-24 16:55 157352 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice_installer.exe

2012-05-24 16:55 . 2012-05-24 16:55 129976 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice.exe

.

.

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-04 17:07 . 2012-04-18 19:57 28880 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys

2012-04-18 20:25 . 2012-04-18 20:26 73728 ----a-w- c:\windows\system32\javacpl.cpl

2012-04-18 20:25 . 2010-10-22 17:00 472808 -c--a-w- c:\windows\system32\deployJava1.dll

2012-04-05 12:34 . 2009-10-27 20:08 46408 ----a-w- c:\windows\system32\drivers\gbpkm.sys

2012-05-24 16:55 . 2011-10-21 17:39 97208 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por padrão não são apresentadas.

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2012-03-07 00:15 123536 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4waxx.sys]

@="Driver"

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk]

backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^hp psc 2000 Series.lnk]

backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk]

backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Post-it® Software Notes Lite.lnk]

path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Post-it® Software Notes Lite.lnk

backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup

.

[HKLM\~\startupfolder\C:^Documents and Settings^Niomar.PROMOCAO^Menu Iniciar^Programas^Inicializar^Reboot.exe]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-13 22:21 1695232 ------w- c:\arquivos de programas\Messenger\msmsgs.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]

2003-12-05 06:36 249856 -c--a-w- c:\windows\system32\Keyhook.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]

2002-07-12 10:15 106496 -c--a-w- c:\windows\SiSUSBrg.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]

2003-12-19 09:53 65024 -c--a-w- c:\windows\SOUNDMAN.EXE

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2012-01-18 17:02 254696 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"GbpSv"=2 (0x2)

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Fortes Informática\\RemProtDeamon.exe"=

"c:\\WINDOWS\\system32\\DWRCS.EXE"=

"c:\\Arquivos de programas\\Canon\\DIAS\\CnxDIAS.exe"=

"c:\\Arquivos de programas\\NetMeeting\\conf.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

.

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [27/10/2009 17:08 46408]

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20/06/2011 08:09 612184]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [26/01/2009 15:05 337880]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [26/01/2009 15:05 20696]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [27/10/2009 17:10 214088]

R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880]

S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys [?]

S2 gupdate;Serviço do Google Update (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176]

S2 SpyPrinterD;SpyPrinterD;c:\windows\system32\SpyPrinter.exe [21/05/2008 16:53 1406464]

S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176]

S3 MozillaMaintenance;Mozilla Maintenance Service;c:\arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe [24/05/2012 13:55 129976]

S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880]

S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s [?]

S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

.

2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49]

.

2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49]

.

2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.funpec.br/ponto_online/

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

Trusted Zone: bancobrasil.com.br\www

Trusted Zone: bancobrasil.com.br\www14

Trusted Zone: bancobrasil.com.br\www2

Trusted Zone: bb.com.br\www

Trusted Zone: com.br\www.bancobrasil

Trusted Zone: com.br\www.bb

Trusted Zone: com.br\www14.bancobrasil

Trusted Zone: com.br\www2.bancobrasil

TCP: DhcpNameServer = 10.4.65.16

FF - ProfilePath - c:\documents and settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\

FF - prefs.js: browser.startup.homepage - hxxp://funpec.br/

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2012-06-05 17:38

Windows 5.1.2600 Service Pack 3 NTFS

.

Procurando processos ocultos ...

.

Procurando entradas auto inicializáveis ocultas ...

.

Procurando ficheiros/arquivos ocultos ...

.

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

.

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

.

[HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithList]

@Class="Shell"

"a"="shimgvw.dll"

"MRUList"="ab"

"b"="mspaint.exe"

.

[HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithProgids]

"$¨+_auto_file"=hex(0):

.

[HKEY_LOCAL_MACHINE\software\Adobe\CommonFiles\{AC76BA86-1033-0000-7760-000000000001}\ColorProfiles]

@DACL=(02 0000)

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AdobeRGB1998.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AppleRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Color Management Off.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\ColorMatchRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Acrobat 4.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Photoshop 4.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Europe Prepress Defaults.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Japan Color Prepress.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Coated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Uncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanWebCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\BlackWhite.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\CIERGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\JapanStandard.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\NTSC1953.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\PAL_SECAM.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop4DefaultCMYK.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop5DefaultCMYK.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\SMPTE-C.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\WideGamutRGB.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Photoshop 5 Default Spaces.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\sRGB Color Space Profile.icm"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\US Prepress Defaults.csf"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedCoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebCoatedSWOP.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebUncoated.icc"=dword:00000001

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Web Graphics Defaults.csf"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\000021599B0090400000000000F01FEC\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="Microsoft Application Error Reporting"

"1"="OFFICE12;1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"="READER8;[1]"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

"11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\C1B24092317057547BACC5E8B780994D\SourceList\Media]

@DACL=(02 0000)

"MediaPackage"="\\"

"1"="WILTON - VB;"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D6461317C3DC4F04799BDCE9E42626FE\SourceList\Media]

@DACL=(02 0000)

"DiskPrompt"="[1]"

"1"=";Microsoft .NET Framework 2.0 [Disk 1]"

"2"=";Microsoft .NET Framework 2.0 [Disk 1]"

"3"=";Microsoft .NET Framework 2.0 [Disk 1]"

"4"=";Microsoft .NET Framework 2.0 [Disk 1]"

"5"=";Microsoft .NET Framework 2.0 [Disk 1]"

"6"=";Microsoft .NET Framework 2.0 [Disk 1]"

"7"=";Microsoft .NET Framework 2.0 [Disk 1]"

"8"=";Microsoft .NET Framework 2.0 [Disk 1]"

"9"=";Microsoft .NET Framework 2.0 [Disk 1]"

"10"=";Microsoft .NET Framework 2.0 [Disk 1]"

"11"=";Microsoft .NET Framework 2.0 [Disk 1]"

"12"=";Microsoft .NET Framework 2.0 [Disk 1]"

"13"=";Microsoft .NET Framework 2.0 [Disk 1]"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

.

- - - - - - - > 'explorer.exe'(3664)

c:\windows\system32\WININET.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Tempo para conclusão: 2012-06-05 17:40:04

ComboFix-quarantined-files.txt 2012-06-05 20:40

ComboFix2.txt 2012-06-05 17:38

.

Pré-execução: 6.046.384.128 bytes disponíveis

Pós execução: 6.031.691.776 bytes disponíveis

.

- - End Of File - - A5D5780C71A40CDC2231FBD446DF3B55

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edvan

 

|- Configure o Windows,para mostrar os arquivos/pastas ocultas.

 

|- Acesse: 5ddd15a0a515ee4d2c0ec8b4dcd87f0892b31334364ee054c605f091c3a9d7ad6g.jpg

 

83e4aac23f4afef13a3ebabeac5a83a9c3d09bc26d01ffd8e9659b806fce2f476g.jpg

 

|- Em "Arquivo para verificar",coloque:

 

|- <1> c:\windows\system32\drivers\fmhuptxw.sys

 

|- Ao concluir,coloque este outro:

 

|- <2> c:\windows\system32\Drivers\ati4waxx.sys

 

|- Clique em "Enviar".

|- Ps: Copie e poste,o resultado destes exames.

 

|- Baixe: | ZHPDiag2 | *ºº* < NicolasCoolman.jpg > ( ... de Nicolas Coolman )

 

|- Salve-o no desktop!

 

ZHPDiag2.jpg

 

|- Desabilite seu antivírus e execute "ZHPDiag2.exe",para instalar a ferramenta.

 

ZHPDiag_Installation.jpg

 

|- Confirme todos os passos,ao instalar ZHPDiag.

|- Conclua a instalação,clicando em "Termine".

 

ZHPDiag_MBRCheck.jpg

 

|- Ps: Após a instalação,além de ZHPScript,estarão disponíveis no desktop:

 

|- <1> MBRCheck

|- <2> ZHPDiag2

|- <3> ZHPFix

 

ZHPDiag_cones.jpg

 

|- Clique no ícone do pergaminho. ( ZHPScript )

 

ZHPDiag_Update.jpg

 

|- Clique na seta verde para atualizá-la e/ou baixar sua definição mais recente. ( Your version is update. )

|- Habilite todas as opções de diagnóstico,clicando em "Options".

 

ZHPDiag_All.jpg

 

|- Clique em All.

 

|- ZHPDiag_30days.jpg

 

|- Clique em "Calendar" e escolha 30 dias!

 

ZHPDiag_Lupa.jpg

 

|- Dê início ao scan,clicando no ícone da lupa. ( Start Diagnosis )

|- Ao concluir,clique em "Save Report".

|- Salve-o em um local conveniente! ( ZHPDiag.txt )

|- Ps: Não poste,diretamente,esse arquivo texto.

 

|- Ou envie-o à Pjjoint.malekal,clicando na seta azul! < ZHPDiag_Pjjoint-1.jpg >

 

|- Ou acesse: < wikisend.jpg >

 

|- Para enviar,siga o caminho: Selecionar arquivo... -> Abrir -> Upload file

|- Poste o endereço que estará em "Download link" ou "Forum link".

 

|- Ou acesse: < Cjoint_Logo.jpg >

 

|- Maiores informações: < |Link| >

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Em "Arquivo para verificar",coloque:

 

|- <1> c:\windows\system32\drivers\fmhuptxw.sys

 

|- Ao concluir,coloque este outro:

 

|- <2> c:\windows\system32\Drivers\ati4waxx.sys

 

|- Clique em "Enviar".

|- Ps: Copie e poste,o resultado destes exames.

 

DigRam, configurei o Windows, para mostrar os arquivos/pastas ocultas conforme solicitados, porem só achei o: (c:\windows\system32\drivers\fmhuptxw.sys)

 

O resultado está na imagem logo abaixo:

virus01l.jpg

 

 

Log do ZHPDiag.txt.

http://wikisend.com/download/399112/ZHPDiag.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edvan

 

|- Os ficheiros são legítimos!

 

-/-

 

|- Desabilite seu antivírus!

|- Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /uninstall --> Clique OK.

 

|- < 92674490.jpg >

 

|- Clique em Executar --> Aguarde!

|- Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.

|- Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!

|- Ou,vá em Iniciar --> Executar --> Digite ou cole ( Paste ):

 

|- CFuninstall.gif

 

"%userprofile%\desktop\combofix" /uninstall

 

|- Clique OK.

|- Aguarde a desinstalação,e clique OK na mensagem.

|- Ps: Outra opção,seria renomear o Combofix.exe para uninstall.exe e executá-lo.

 

-/-

 

|- Feche programas/pastas que estejam abertas.

|- Feche,também,o navegador!

|- Para Windows Vista,desabilite a UAC.

 

ZHPFix_Logo.jpg

 

|- Dê um duplo clique em ZHPFix.

|- Selecione e copie estas informações,que estão em vermelho,para o "Bloco de Notas".

 

O42 - Logiciel: J2SE Runtime Environment 5.0 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150060}

O43 - CFD: 05/12/2005 - 14:12:43 - [0] ----D C:\Documents and Settings\All Users.WINDOWS\Favoritos

O43 - CFD: 09/11/2007 - 10:18:12 - [4,738] ----D C:\Arquivos de programas\Crawler

O43 - CFD: 27/01/2009 - 10:09:01 - [3,493] ----D C:\Arquivos de programas\Spybot - Search & Destroy => Spybot - Search & Destroy

O44 - LFC:[MD5.55E96B1122D37C7CD9B371E9DA1E7C3B] - 05/06/2012 - 14:42:53 ---A- . (...) -- C:\hijackthis.log [5526]

O45 - LFCP:[MD5.B6F171E7A7C9348B205BC85B5695EE17] - 04/06/2012 - 08:15:26 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-18ACD379.pf

O45 - LFCP:[MD5.1336D3A134B0941124DA4B14060E9584] - 04/06/2012 - 08:15:27 ---A- - C:\WINDOWS\Prefetch\JUSCHED.EXE-153A82FA.pf

O45 - LFCP:[MD5.AB7EB3E750631E20F94802D217BD5133] - 04/06/2012 - 08:15:27 ---A- - C:\WINDOWS\Prefetch\READER_SL.EXE-074FC50A.pf

O45 - LFCP:[MD5.A9C93D24F033BCA67F9F8AB1F7E04547] - 04/06/2012 - 09:30:15 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-12E27DD0.pf

O45 - LFCP:[MD5.E5F0EAEFE28B347771ED8FDCE4F885C5] - 04/06/2012 - 12:09:47 ---A- - C:\WINDOWS\Prefetch\WMIAPSRV.EXE-1E2270A5.pf

O45 - LFCP:[MD5.2A411C49D9A8A7B4517D9C0829CA5938] - 04/06/2012 - 12:09:47 ---A- - C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf

O45 - LFCP:[MD5.D5923CF0CDC468C4348F4DFACE9FC3BF] - 04/06/2012 - 12:23:44 ---A- - C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf

O45 - LFCP:[MD5.B7D7E779C99552BF8D90DE7B51540732] - 04/06/2012 - 14:23:00 ---A- - C:\WINDOWS\Prefetch\MBAM-SETUP-1.61.0.1400[1].TMP-1585CB5A.pf

O45 - LFCP:[MD5.F8D424638599FE934F977C7F49C56652] - 04/06/2012 - 14:23:02 ---A- - C:\WINDOWS\Prefetch\MBAM-SETUP-1.61.0.1400[1].EXE-01804FF1.pf

O45 - LFCP:[MD5.F20A608B20B6F64EF5CDFE32D5354008] - 04/06/2012 - 17:45:06 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf

O45 - LFCP:[MD5.853A8A7C3C54C48956EA70DB40FDB25F] - 04/06/2012 - 17:50:22 ---A- - C:\WINDOWS\Prefetch\MBAMGUI.EXE-22501228.pf

O45 - LFCP:[MD5.AD59D31CA39542B2E4AC862EF2DA8A2E] - 04/06/2012 - 17:50:23 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-4CC34A26.pf

O45 - LFCP:[MD5.571CEDEC2D6894E5DE741C985F8E84D3] - 05/06/2012 - 08:39:10 ---A- - C:\WINDOWS\Prefetch\NET.EXE-01A53C2F.pf

O45 - LFCP:[MD5.2D47D6073483FD3C1230012825EC07C4] - 05/06/2012 - 08:43:58 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf

O45 - LFCP:[MD5.698218FE05AE1F29C21A73CCAEA86A9D] - 05/06/2012 - 08:44:12 ---A- - C:\WINDOWS\Prefetch\MSCONFIG.EXE-35E4DAE9.pf

O45 - LFCP:[MD5.DCA46490A4C8AA0B117BC0F89119CBFE] - 05/06/2012 - 08:44:37 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-22143848.pf

O45 - LFCP:[MD5.45C9E2B0AFBEC39278D349319988BB12] - 05/06/2012 - 08:45:16 ---A- - C:\WINDOWS\Prefetch\MBAM.EXE-1FC68C0D.pf

O45 - LFCP:[MD5.0ADFB6A1C4F52FE723652099978A7742] - 05/06/2012 - 08:56:06 ---A- - C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf

O45 - LFCP:[MD5.8F11690784992B7C0AA829D93964A21C] - 05/06/2012 - 08:56:06 ---A- - C:\WINDOWS\Prefetch\UNINS000.EXE-1490805C.pf

O45 - LFCP:[MD5.05F9DF9D77553EDCC8D404EAF2597FF1] - 05/06/2012 - 08:56:08 ---A- - C:\WINDOWS\Prefetch\_IU14D2N.TMP-1EF21ECF.pf

O45 - LFCP:[MD5.25E96BAF34920DAD4019C3DB47A640FF] - 05/06/2012 - 14:16:36 ---A- - C:\WINDOWS\Prefetch\COMBOFIX.EXE-1C681C0F.pf

O45 - LFCP:[MD5.6190B5F04AC05684740DE27ED0081FC5] - 05/06/2012 - 14:18:03 ---A- - C:\WINDOWS\Prefetch\NS2B.TMP-18463A2E.pf

O45 - LFCP:[MD5.4276FB740F3D01CCBF841A20D8C61B47] - 05/06/2012 - 14:18:06 ---A- - C:\WINDOWS\Prefetch\NS2C.TMP-21855412.pf

O45 - LFCP:[MD5.7C0FA77E60F295B3BF58BEE65A0B6ED6] - 05/06/2012 - 14:18:39 ---A- - C:\WINDOWS\Prefetch\NIRCMDB.EXE-0F3DC8F2.pf

O45 - LFCP:[MD5.7389155004B4EC071AF003F5EE0D7166] - 05/06/2012 - 14:21:23 ---A- - C:\WINDOWS\Prefetch\NS30.TMP-29FF67D5.pf

O45 - LFCP:[MD5.19DA35F91670F0CEA102526E37BBD4C8] - 05/06/2012 - 14:21:26 ---A- - C:\WINDOWS\Prefetch\CF6009.3XE-0F68A68E.pf

O45 - LFCP:[MD5.9D99AACFAEB1816B6087E6CEBFAE4AA1] - 05/06/2012 - 14:21:26 ---A- - C:\WINDOWS\Prefetch\NS31.TMP-0FCC266B.pf

O45 - LFCP:[MD5.BA521346287CF75A85217C3ECEDD207F] - 05/06/2012 - 14:38:31 ---A- - C:\WINDOWS\Prefetch\CF6662.3XE-0A302C9E.pf

O45 - LFCP:[MD5.C2E6A41488BA3944CCBB8DF80A6F35C4] - 05/06/2012 - 14:38:53 ---A- - C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf

O45 - LFCP:[MD5.F26743DD2E5191FAD422545FA7C5723D] - 05/06/2012 - 14:42:57 ---A- - C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-3863877A.pf

O45 - LFCP:[MD5.D817C9097A3221801011D0B4B8C75F67] - 05/06/2012 - 14:50:33 ---A- - C:\WINDOWS\Prefetch\SWAP.EXE-3B3C2F3B.pf

O45 - LFCP:[MD5.2BEDBD2061E8D0CA36755A9DD3F606E5] - 05/06/2012 - 15:05:52 ---A- - C:\WINDOWS\Prefetch\ACRORD32INFO.EXE-27B701E7.pf

O45 - LFCP:[MD5.1E5CA6B4EECF14D04C71BC7FD1326D76] - 05/06/2012 - 16:13:29 ---A- - C:\WINDOWS\Prefetch\FUNPEC.EXE-0C5E44B0.pf

O45 - LFCP:[MD5.969B277174D66C79EFE236447496FE05] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf

O45 - LFCP:[MD5.0CBCDA5ED9BA4213BCF3BAF3AE15D3EA] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\NS53.TMP-02D7F8F6.pf

O45 - LFCP:[MD5.B0E20734C5554F0D73CE2E33F6930128] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\PEV.3XE-358EBDB6.pf

O45 - LFCP:[MD5.682A1E3F0669C83FCF57FD9B01E0C5FA] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\GSAR.3XE-1971B17C.pf

O45 - LFCP:[MD5.7993F47E310A224CE35BA12FA1911461] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf

O45 - LFCP:[MD5.FE6423724610F2873A86E827F4D7FF19] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\NS54.TMP-108C1AB5.pf

O45 - LFCP:[MD5.A05C6F8327222BB7D0A0C4E022FDC4D6] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\NS55.TMP-293F738B.pf

O45 - LFCP:[MD5.59F98C7E760453F6A3D183BAD0352C9E] - 05/06/2012 - 17:28:02 ---A- - C:\WINDOWS\Prefetch\NS56.TMP-25BF6A27.pf

O45 - LFCP:[MD5.145660E16F9A82B1F2D8470F096B9DB9] - 05/06/2012 - 17:28:02 ---A- - C:\WINDOWS\Prefetch\SWREG.3XE-20CC4D60.pf

O45 - LFCP:[MD5.2AC4C35545678208CE140DADF56F4C6A] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS57.TMP-140C2419.pf

O45 - LFCP:[MD5.1397A96C864ED534BCB95EFDFACB795D] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS58.TMP-3AF2B999.pf

O45 - LFCP:[MD5.67C33ADD6DC1C123C00901E181B2E7F1] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS59.TMP-3A739EAE.pf

O45 - LFCP:[MD5.4D8DD298DA69962CC0C17A21EBBF0AEE] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS5A.TMP-1A599F1A.pf

O45 - LFCP:[MD5.95AE7178FCD4394C66A2DBD80C0B1822] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS5B.TMP-1F71EF26.pf

O45 - LFCP:[MD5.326B3B74D5A47436415D03DB12A71B8D] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\60329_COMBOFIX_123123.EXE-2BAE328A.pf

O45 - LFCP:[MD5.CAB3B98571335887E9E1167ADFE1B337] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\GREP.3XE-0FD7DFD4.pf

O45 - LFCP:[MD5.D94F54F64D43392FB2D2DD17DEBFEC90] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf

O45 - LFCP:[MD5.4FD52F5105EBE3C99B77671AC85169E9] - 05/06/2012 - 17:28:05 ---A- - C:\WINDOWS\Prefetch\NIRCMD.3XE-117BB35D.pf

O45 - LFCP:[MD5.33018D398E97A3C19B1DE1B2A59EF28E] - 05/06/2012 - 17:28:07 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.EXE-1C26180C.pf

O45 - LFCP:[MD5.CF9D77FFC0CED14837B419096FB5B6D2] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\RMBR.3XE-3AAE61A2.pf

O45 - LFCP:[MD5.0AC47C976C61F026D1DE1CA4261B5AEF] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\SED.3XE-370DAEC3.pf

O45 - LFCP:[MD5.C6CBB2D3CA13585948025CB0E3866FFF] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\SWSC.3XE-3AE13307.pf

O45 - LFCP:[MD5.50A96B94C7550ACF10BD587A36E2A206] - 05/06/2012 - 17:28:09 ---A- - C:\WINDOWS\Prefetch\HANDLE.3XE-10DA2EFC.pf

O45 - LFCP:[MD5.3D63A6FE23A2E4C2154A8F4AF46193A1] - 05/06/2012 - 17:28:09 ---A- - C:\WINDOWS\Prefetch\SWXCACLS.3XE-392ED218.pf

O45 - LFCP:[MD5.F9D00EB50264B5369FB704E14A48C44A] - 05/06/2012 - 17:28:11 ---A- - C:\WINDOWS\Prefetch\ATTRIB.3XE-09E9D153.pf

O45 - LFCP:[MD5.7422026E4FCC057998CE819CF27C3B5E] - 05/06/2012 - 17:28:14 ---A- - C:\WINDOWS\Prefetch\CMD.3XE-32EEC145.pf

O45 - LFCP:[MD5.C16927A12C4F54B2085F1F301B4C3FB1] - 05/06/2012 - 17:28:15 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.3XE-1AD11928.pf

O45 - LFCP:[MD5.C52FB72AEEBF1C76DDB3A36F0D40D4A7] - 05/06/2012 - 17:28:17 ---A- - C:\WINDOWS\Prefetch\HIDEC.3XE-111262DC.pf

O45 - LFCP:[MD5.49F301EEFEDAE54DA9DB853D524DAA2A] - 05/06/2012 - 17:28:18 ---A- - C:\WINDOWS\Prefetch\ATTRIB.EXE-39EAFB02.pf

O45 - LFCP:[MD5.471B8B382CF08B0A01124EE10D1EDB5C] - 05/06/2012 - 17:28:18 ---A- - C:\WINDOWS\Prefetch\HIDEC.3XE-3AF2FBA6.pf

O45 - LFCP:[MD5.0E68B49B98F8EA1A2B9FB1DA103339CE] - 05/06/2012 - 17:28:21 ---A- - C:\WINDOWS\Prefetch\PING.EXE-31216D26.pf

O45 - LFCP:[MD5.733CBC15FE4D0210C81F5816C1E9CEDC] - 05/06/2012 - 17:28:21 ---A- - C:\WINDOWS\Prefetch\PV.3XE-287F2865.pf

O45 - LFCP:[MD5.66B1DF36E6553F0270A1C08A47DAC475] - 05/06/2012 - 17:28:22 ---A- - C:\WINDOWS\Prefetch\PING.3XE-0C1ADF15.pf

O45 - LFCP:[MD5.BEAFCCCD8453F019C3DCF6BAB1562D83] - 05/06/2012 - 17:28:27 ---A- - C:\WINDOWS\Prefetch\COMBOFIX-DOWNLOAD.3XE-1CD0C4A7.pf

O45 - LFCP:[MD5.2422B104067C7FFA53703FB46E167575] - 05/06/2012 - 17:28:29 ---A- - C:\WINDOWS\Prefetch\SWSC.3XE-0165B0CE.pf

O45 - LFCP:[MD5.33704A99B501B9FFA60D7E9E3D3BE493] - 05/06/2012 - 17:28:32 ---A- - C:\WINDOWS\Prefetch\FINDSTR.EXE-0CA6274B.pf

O45 - LFCP:[MD5.B741F0E934A26F126FE9F5E4E38BF473] - 05/06/2012 - 17:28:33 ---A- - C:\WINDOWS\Prefetch\ATTRIB.3XE-09A7F4FD.pf

O45 - LFCP:[MD5.B24D6138E7755B27122FF8F573FFCFEA] - 05/06/2012 - 17:28:33 ---A- - C:\WINDOWS\Prefetch\GSAR.3XE-2009D0BD.pf

O45 - LFCP:[MD5.9888348F215FF9FD2FA024ECF567162C] - 05/06/2012 - 17:28:35 ---A- - C:\WINDOWS\Prefetch\PEV.EXE-31673B84.pf

O45 - LFCP:[MD5.0159BAD54D02CA1890B8A8C8360E3CED] - 05/06/2012 - 17:28:37 ---A- - C:\WINDOWS\Prefetch\SWSC.EXE-17AFBFBF.pf

O45 - LFCP:[MD5.492E2CB145884EB95250449DA9126F9D] - 05/06/2012 - 17:28:38 ---A- - C:\WINDOWS\Prefetch\SWREG.EXE-0F8682E2.pf

O45 - LFCP:[MD5.2CCB7AC41BDDBF1BDE976875FB7288DA] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.3XE-08A9718B.pf

O45 - LFCP:[MD5.6B8B8E0AF70C66FEB33207F22BE2FBEC] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\NIRKMD.3XE-1008F703.pf

O45 - LFCP:[MD5.66E8AD2DC6B268288DE15C37E6AC5A5D] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\SED.EXE-0F4B402F.pf

O45 - LFCP:[MD5.E3C25F0F857743FF91FEFE76F53A83F5] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\CF10459.3XE-01033214.pf

O45 - LFCP:[MD5.58D4C3B41976C14A8DE45C444E81B116] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\ERUNT.3XE-1F6EF454.pf

O45 - LFCP:[MD5.EA4B09EE2B96DEB81FABB9957E6F41D8] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\GREP.EXE-3309531C.pf

O45 - LFCP:[MD5.D6AD7C1C89751E5FB13FBF8EA0957B9B] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\NIRCMD.3XE-2822283E.pf

O45 - LFCP:[MD5.9D13AC43EE30016E4FA0B0AAE7E14EE8] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\NIRCMDC.3XE-1F054C5B.pf

O45 - LFCP:[MD5.9196E4C01FB3810FD179AA03B8C3D412] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\PEV.3XE-2D5F2597.pf

O45 - LFCP:[MD5.166A0B3DB366195F5B462B884291A49B] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\PEV.EXE-0CE2BF4A.pf

O45 - LFCP:[MD5.9EDCCF4424F25827C3ED3070E50C27A9] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\SORT.EXE-194AE83C.pf

O45 - LFCP:[MD5.96E9F40F6956FC302EFC94A2FFA5F739] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf

O45 - LFCP:[MD5.D63FB2D330D8BD4E922E696194988EDA] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\GREP.3XE-03DC3FDE.pf

O45 - LFCP:[MD5.39DC55CD3C9588BDF60699AE9DB1215A] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf

O45 - LFCP:[MD5.2E1EB2117C0F6E8E30FC4B11B423A216] - 05/06/2012 - 17:40:07 ---A- - C:\WINDOWS\Prefetch\SWREG.3XE-09144B6A.pf

O45 - LFCP:[MD5.F3452435CAA09F00A5EE9BC696FEA671] - 05/06/2012 - 17:40:07 ---A- - C:\WINDOWS\Prefetch\SWXCACLS.3XE-015A5BFF.pf

O45 - LFCP:[MD5.AB3A51D266EBF2EE9B2B8E610B3FB7BF] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\HANDLE.3XE-28C3AC9F.pf

O45 - LFCP:[MD5.BBB51B5037BF5EDB2841F2A1275966AC] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\NIRCMD.EXE-2C39EF53.pf

O45 - LFCP:[MD5.0DF31B9E28A7DB9F143D2A2B73122BFD] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\SED.3XE-03A27CDB.pf

O45 - LFCP:[MD5.D6518CEB8FD386A2E8DA9028604CE0E9] - 05/06/2012 - 17:46:34 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-21D9F19C.pf

O45 - LFCP:[MD5.EFAAC3A063201B150DA2A05A5F77EE61] - 05/06/2012 - 17:46:44 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf

O45 - LFCP:[MD5.E394F3D493F4EBE30B52892711FEC13C] - 06/06/2012 - 07:50:21 ---A- - C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf

O45 - LFCP:[MD5.B4CC37C40A8C5B2C6B28F85FC8CBDF89] - 06/06/2012 - 07:51:37 ---A- - C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf

O45 - LFCP:[MD5.47CB93376DE5DB1CD59478B0964E8B3C] - 06/06/2012 - 08:12:51 ---A- - C:\WINDOWS\Prefetch\THUNDERBIRD.EXE-2C374BBE.pf

O45 - LFCP:[MD5.A5364A9B47D4461899CD531DF95F9254] - 06/06/2012 - 08:12:55 ---A- - C:\WINDOWS\Prefetch\THUNDERBIRDPORTABLE.EXE-01EC7AB1.pf

O45 - LFCP:[MD5.5BFD93C094C36E0468235DAC048A8014] - 06/06/2012 - 08:17:47 ---A- - C:\WINDOWS\Prefetch\HELPER.EXE-3A31BCA1.pf

O45 - LFCP:[MD5.FF91E49A2A8D9EA4AE3C6FF39D494E1E] - 06/06/2012 - 08:25:06 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-38C1AF32.pf

O45 - LFCP:[MD5.840E8E42CA53F6F9DEEE0A2D2FAC00E9] - 06/06/2012 - 08:25:07 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf

O45 - LFCP:[MD5.5AABEA62D8A724557A364B00EC989FB2] - 06/06/2012 - 08:35:47 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-43D2B9C5.pf

O45 - LFCP:[MD5.43349A0954EF555F7C89BDE380D6E29B] - 06/06/2012 - 10:13:45 ---A- - C:\WINDOWS\Prefetch\EXCEL.EXE-3283F464.pf

O45 - LFCP:[MD5.5069F0C8955ED6EF74B5C5589333A2A8] - 06/06/2012 - 10:15:19 ---A- - C:\WINDOWS\Prefetch\ACRORD32.EXE-3AE6FA75.pf

O45 - LFCP:[MD5.FE4945D4727BC61591BF573F4791AE80] - 06/06/2012 - 10:16:44 ---A- - C:\WINDOWS\Prefetch\ADOBEUPDATER.EXE-19E95BBA.pf

O45 - LFCP:[MD5.C4A8B323A50A5333AB2813DCCE9A9C6B] - 06/06/2012 - 11:18:05 ---A- - C:\WINDOWS\Prefetch\DOAP.EXE-3A87DF2F.pf

O45 - LFCP:[MD5.BFC1BB094AF7B1C87E7A04B9CEF4330B] - 06/06/2012 - 11:37:56 ---A- - C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf

O45 - LFCP:[MD5.3C606F1FBD1FE9309D7EE8431FD3C44F] - 06/06/2012 - 12:12:09 ---A- - C:\WINDOWS\Prefetch\AVAST.SETUP-13B2B59D.pf

O45 - LFCP:[MD5.8BBEADC7DE3957787345B19D5A83D89A] - 06/06/2012 - 14:05:01 ---A- - C:\WINDOWS\Prefetch\GOOGLECRASHHANDLER.EXE-062CDC47.pf

O45 - LFCP:[MD5.28E9000D0DAEC07DA1A3658642DF0213] - 06/06/2012 - 14:05:01 ---A- - C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-19D08292.pf

O45 - LFCP:[MD5.9A97C9FCBF491481A24EADF5D5A6E04B] - 06/06/2012 - 14:28:19 ---A- - C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf

O45 - LFCP:[MD5.6BDD538485EEF0916E655EAC6065B243] - 06/06/2012 - 14:28:19 ---A- - C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf

O45 - LFCP:[MD5.A949ED7403404E59C476A9663BA29C3C] - 06/06/2012 - 14:31:43 ---A- - C:\WINDOWS\Prefetch\PLUGIN-CONTAINER.EXE-012592DA.pf

O45 - LFCP:[MD5.AFC7FE221A2D4DB0DF391C14FB3ECDD4] - 06/06/2012 - 14:37:01 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-2B53DE18.pf

O45 - LFCP:[MD5.E45AFB8FE6088A3462343DEE188CA2F7] - 06/06/2012 - 14:41:47 ---A- - C:\WINDOWS\Prefetch\MSPAINT.EXE-11CBB631.pf

O45 - LFCP:[MD5.E2F3AE73A1FC014AA8199CA292E5854C] - 06/06/2012 - 14:47:45 ---A- - C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf

O45 - LFCP:[MD5.BE850CBD7179072FDB61CFE1728476B8] - 06/06/2012 - 14:48:56 ---A- - C:\WINDOWS\Prefetch\AVASTUI.EXE-373CBE37.pf

O45 - LFCP:[MD5.C58A179B71AB23675AB175645507C9C3] - 06/06/2012 - 14:49:21 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.TMP-079FABD8.pf

O45 - LFCP:[MD5.2EC9A5BB76CD88F189CE373D5D5A80EA] - 06/06/2012 - 14:49:22 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.EXE-2DC55403.pf

O45 - LFCP:[MD5.69C8B7AAF401526CBE5311040A6C4584] - 06/06/2012 - 14:51:05 ---A- - C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.)

O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

 

[HKLM\Software\CToolbar]

[HKCU\Software\CToolbar]

 

proxyfix

emptytemp

emptyflash

firewallraz

sysrestore

|- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C"

|- Minimize o Bloco de Notas.

 

ZHPDiag_PasteClipboard.jpg

 

|- Clique no menu,"Paste ClipBoard".

|- Clique em "GO" -> Oui.

 

ZHPFix_GO.jpg

 

|- Ps: Temos,àcima,sequência de imagens para maior exclarecimento.

|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Rapport de ZHPFix 1.2.06 par Nicolas Coolman, Update du 17/05/2012

Fichier d'export Registre :

Run by f003204 at 08/06/2012 08:36:27

Windows XP Professional Service Pack 3 (Build 2600)

Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

Web site : http://nicolascoolman.skyrock.com/

 

========== Software ==========

DELETED J2SE Runtime Environment 5.0 Update 6

 

========== Registry Key ==========

DELETED [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}]

DELETED O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.)

DELETED O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.)

DELETED Key*: StartupReg: Adobe Reader Speed Launcher

DELETED Key: HKLM\Software\CToolbar

NOT FOUND Key: HKCU\Software\CToolbar

 

========== Registry Value ==========

ProxyFix : Proxy killed successfully

DELETED ProxyServer Value

DELETED ProxyEnable Value

DELETED EnableHttp1_1 Value

DELETED ProxyHttp1.1 Value

DELETED ProxyOverride Value

DELETED FirewallRaz (SP) : %windir%\system32\sessmgr.exe

DELETED FirewallRaz (SP) : %windir%\Network Diagnostic\xpnetdiag.exe

DELETED FirewallRaz (DP) : %windir%\system32\sessmgr.exe

DELETED FirewallRaz (DP) : C:\Arquivos de programas\MSN Messenger\livecall.exe

DELETED FirewallRaz (DP) : %windir%\Network Diagnostic\xpnetdiag.exe

No Value in Firewall Exception Register Key (FirewallRaz)

 

========== Repertory ==========

DELETED Folder: C:\Documents and Settings\All Users.WINDOWS\Favoritos

DELETED Folder: C:\Arquivos de programas\Crawler

DELETED Folder: C:\Arquivos de programas\Spybot - Search & Destroy

DELETED Window Temporary:

DELETED Flash Cookies:

 

========== File ==========

NOT FOUND File: c:\hijackthis.log

DELETED File: c:\windows\prefetch\rundll32.exe-18acd379.pf

DELETED File: c:\windows\prefetch\jusched.exe-153a82fa.pf

DELETED File: c:\windows\prefetch\reader_sl.exe-074fc50a.pf

DELETED File: c:\windows\prefetch\rundll32.exe-12e27dd0.pf

DELETED File: c:\windows\prefetch\wmiapsrv.exe-1e2270a5.pf

DELETED File: c:\windows\prefetch\wuauclt.exe-399a8e72.pf

DELETED File: c:\windows\prefetch\dfrgntfs.exe-269967df.pf

DELETED File: c:\windows\prefetch\mbam-setup-1.61.0.1400[1].tmp-1585cb5a.pf

DELETED File: c:\windows\prefetch\mbam-setup-1.61.0.1400[1].exe-01804ff1.pf

DELETED File: c:\windows\prefetch\notepad.exe-189578da.pf

DELETED File: c:\windows\prefetch\mbamgui.exe-22501228.pf

DELETED File: c:\windows\prefetch\rundll32.exe-4cc34a26.pf

DELETED File: c:\windows\prefetch\net.exe-01a53c2f.pf

DELETED File: c:\windows\prefetch\rundll32.exe-268bff96.pf

DELETED File: c:\windows\prefetch\msconfig.exe-35e4dae9.pf

DELETED File: c:\windows\prefetch\rundll32.exe-22143848.pf

DELETED File: c:\windows\prefetch\mbam.exe-1fc68c0d.pf

DELETED File: c:\windows\prefetch\regsvr32.exe-25eefe2f.pf

DELETED File: c:\windows\prefetch\unins000.exe-1490805c.pf

DELETED File: c:\windows\prefetch\_iu14d2n.tmp-1ef21ecf.pf

DELETED File: c:\windows\prefetch\combofix.exe-1c681c0f.pf

DELETED File: c:\windows\prefetch\ns2b.tmp-18463a2e.pf

DELETED File: c:\windows\prefetch\ns2c.tmp-21855412.pf

DELETED File: c:\windows\prefetch\nircmdb.exe-0f3dc8f2.pf

DELETED File: c:\windows\prefetch\ns30.tmp-29ff67d5.pf

DELETED File: c:\windows\prefetch\cf6009.3xe-0f68a68e.pf

DELETED File: c:\windows\prefetch\ns31.tmp-0fcc266b.pf

DELETED File: c:\windows\prefetch\cf6662.3xe-0a302c9e.pf

DELETED File: c:\windows\prefetch\imapi.exe-0bf740a4.pf

DELETED File: c:\windows\prefetch\hijackthis.exe-3863877a.pf

DELETED File: c:\windows\prefetch\swap.exe-3b3c2f3b.pf

DELETED File: c:\windows\prefetch\acrord32info.exe-27b701e7.pf

DELETED File: c:\windows\prefetch\funpec.exe-0c5e44b0.pf

DELETED File: c:\windows\prefetch\iexplore.exe-12915967.pf

DELETED File: c:\windows\prefetch\ns53.tmp-02d7f8f6.pf

DELETED File: c:\windows\prefetch\pev.3xe-358ebdb6.pf

DELETED File: c:\windows\prefetch\gsar.3xe-1971b17c.pf

DELETED File: c:\windows\prefetch\iexplore.exe-0a31fe70.pf

DELETED File: c:\windows\prefetch\ns54.tmp-108c1ab5.pf

DELETED File: c:\windows\prefetch\ns55.tmp-293f738b.pf

DELETED File: c:\windows\prefetch\ns56.tmp-25bf6a27.pf

DELETED File: c:\windows\prefetch\swreg.3xe-20cc4d60.pf

DELETED File: c:\windows\prefetch\ns57.tmp-140c2419.pf

DELETED File: c:\windows\prefetch\ns58.tmp-3af2b999.pf

DELETED File: c:\windows\prefetch\ns59.tmp-3a739eae.pf

DELETED File: c:\windows\prefetch\ns5a.tmp-1a599f1a.pf

DELETED File: c:\windows\prefetch\ns5b.tmp-1f71ef26.pf

DELETED File: c:\windows\prefetch\60329_combofix_123123.exe-2bae328a.pf

DELETED File: c:\windows\prefetch\grep.3xe-0fd7dfd4.pf

DELETED File: c:\windows\prefetch\iexplore.exe-12bbae74.pf

DELETED File: c:\windows\prefetch\nircmd.3xe-117bb35d.pf

DELETED File: c:\windows\prefetch\cscript.exe-1c26180c.pf

DELETED File: c:\windows\prefetch\rmbr.3xe-3aae61a2.pf

DELETED File: c:\windows\prefetch\sed.3xe-370daec3.pf

DELETED File: c:\windows\prefetch\swsc.3xe-3ae13307.pf

DELETED File: c:\windows\prefetch\handle.3xe-10da2efc.pf

DELETED File: c:\windows\prefetch\swxcacls.3xe-392ed218.pf

DELETED File: c:\windows\prefetch\attrib.3xe-09e9d153.pf

DELETED File: c:\windows\prefetch\cmd.3xe-32eec145.pf

DELETED File: c:\windows\prefetch\cscript.3xe-1ad11928.pf

DELETED File: c:\windows\prefetch\hidec.3xe-111262dc.pf

DELETED File: c:\windows\prefetch\attrib.exe-39eafb02.pf

DELETED File: c:\windows\prefetch\hidec.3xe-3af2fba6.pf

DELETED File: c:\windows\prefetch\ping.exe-31216d26.pf

DELETED File: c:\windows\prefetch\pv.3xe-287f2865.pf

DELETED File: c:\windows\prefetch\ping.3xe-0c1adf15.pf

DELETED File: c:\windows\prefetch\combofix-download.3xe-1cd0c4a7.pf

DELETED File: c:\windows\prefetch\swsc.3xe-0165b0ce.pf

DELETED File: c:\windows\prefetch\findstr.exe-0ca6274b.pf

DELETED File: c:\windows\prefetch\attrib.3xe-09a7f4fd.pf

DELETED File: c:\windows\prefetch\gsar.3xe-2009d0bd.pf

DELETED File: c:\windows\prefetch\pev.exe-31673b84.pf

DELETED File: c:\windows\prefetch\swsc.exe-17afbfbf.pf

DELETED File: c:\windows\prefetch\swreg.exe-0f8682e2.pf

DELETED File: c:\windows\prefetch\cscript.3xe-08a9718b.pf

DELETED File: c:\windows\prefetch\nirkmd.3xe-1008f703.pf

DELETED File: c:\windows\prefetch\sed.exe-0f4b402f.pf

DELETED File: c:\windows\prefetch\cf10459.3xe-01033214.pf

DELETED File: c:\windows\prefetch\erunt.3xe-1f6ef454.pf

DELETED File: c:\windows\prefetch\grep.exe-3309531c.pf

DELETED File: c:\windows\prefetch\nircmd.3xe-2822283e.pf

DELETED File: c:\windows\prefetch\nircmdc.3xe-1f054c5b.pf

DELETED File: c:\windows\prefetch\pev.3xe-2d5f2597.pf

DELETED File: c:\windows\prefetch\pev.exe-0ce2bf4a.pf

DELETED File: c:\windows\prefetch\sort.exe-194ae83c.pf

DELETED File: c:\windows\prefetch\chcp.com-18156052.pf

DELETED File: c:\windows\prefetch\grep.3xe-03dc3fde.pf

DELETED File: c:\windows\prefetch\regedit.exe-1b606482.pf

DELETED File: c:\windows\prefetch\swreg.3xe-09144b6a.pf

DELETED File: c:\windows\prefetch\swxcacls.3xe-015a5bff.pf

DELETED File: c:\windows\prefetch\handle.3xe-28c3ac9f.pf

DELETED File: c:\windows\prefetch\nircmd.exe-2c39ef53.pf

DELETED File: c:\windows\prefetch\sed.3xe-03a27cdb.pf

DELETED File: c:\windows\prefetch\rundll32.exe-21d9f19c.pf

DELETED File: c:\windows\prefetch\notepad.exe-336351a9.pf

DELETED File: c:\windows\prefetch\alg.exe-0f138680.pf

DELETED File: c:\windows\prefetch\ctfmon.exe-0e17969b.pf

DELETED File: c:\windows\prefetch\thunderbird.exe-2c374bbe.pf

DELETED File: c:\windows\prefetch\thunderbirdportable.exe-01ec7ab1.pf

DELETED File: c:\windows\prefetch\helper.exe-3a31bca1.pf

DELETED File: c:\windows\prefetch\rundll32.exe-38c1af32.pf

DELETED File: c:\windows\prefetch\rundll32.exe-451fc2c0.pf

DELETED File: c:\windows\prefetch\rundll32.exe-43d2b9c5.pf

DELETED File: c:\windows\prefetch\excel.exe-3283f464.pf

DELETED File: c:\windows\prefetch\acrord32.exe-3ae6fa75.pf

DELETED File: c:\windows\prefetch\adobeupdater.exe-19e95bba.pf

DELETED File: c:\windows\prefetch\doap.exe-3a87df2f.pf

DELETED File: c:\windows\prefetch\helpsvc.exe-2878dda2.pf

DELETED File: c:\windows\prefetch\avast.setup-13b2b59d.pf

DELETED File: c:\windows\prefetch\googlecrashhandler.exe-062cdc47.pf

DELETED File: c:\windows\prefetch\googleupdate.exe-19d08292.pf

DELETED File: c:\windows\prefetch\ntosboot-b00dfaad.pf

DELETED File: c:\windows\prefetch\userinit.exe-30b18140.pf

DELETED File: c:\windows\prefetch\plugin-container.exe-012592da.pf

DELETED File: c:\windows\prefetch\iexplore.exe-2b53de18.pf

DELETED File: c:\windows\prefetch\mspaint.exe-11cbb631.pf

DELETED File: c:\windows\prefetch\verclsid.exe-3667bd89.pf

DELETED File: c:\windows\prefetch\avastui.exe-373cbe37.pf

DELETED File: c:\windows\prefetch\zhpdiag2.tmp-079fabd8.pf

DELETED File: c:\windows\prefetch\zhpdiag2.exe-2dc55403.pf

DELETED File: c:\windows\prefetch\cmd.exe-087b4001.pf

NOT FOUND File: c:\windows\system32\drivers\ati4waxx.sys

DELETED File: c:\arquivos de programas\adobe\reader 8.0\reader\reader_sl.exe

DELETED Window Temporary:

DELETED Flash Cookies:

 

========== Restoration ==========

Restore System Point not created

 

 

========== Summary ==========

6 : Registry Key

12 : Registry Value

5 : Repertory

126 : File

1 : Software

1 : Restoration

 

 

End of clean in 00mn 40s

 

========== Report File ==========

C:\ZHP\ZHPFix[R1].txt - 08/06/2012 08:36:27 [9460]

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Tarde! Edvan

 

|- Atualize o Malwarebytes e execute novo escaneamento.

|- Ps: Pode ser o rápido! -> Poste o relatório!

 

-/-

 

|- Baixe: < otlDesktopIcon.png > ( ... by OldTimer Tools )

 

|- Clique em Salvar! < 0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg >

 

|- Salve-o no desktop! < 98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg >

 

|- Duplo clique em OTL.exe -> Executar: c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg

 

|- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida )

|- Ps: Para Windows 7,clique direito e execute-o como "Administrador".

|- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log )

|- Dispense o relatório "Extras".

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desculpe a demora amigo.

 

Malwarebytes Anti-Malware 1.61.0.1400

www.malwarebytes.org

 

Versão da Base de Dados: v2012.06.12.03

 

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 8.0.6001.18702

f003204 :: FUN0044 [administrador]

 

12/06/2012 10:17:19

mbam-log-2012-06-12 (10-17-19).txt

 

Tipo de Verificação: Verificação Rápida

Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opções de verificação desativadas: P2P

Objetos escaneados: 305018

Tempo decorrido: 43 minuto(s), 13 segundo(s)

 

Processos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Valores de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Pastas Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Arquivos Detectados: 0

(Não foram detectados ítens maliciosos)

 

(fim)

 

 

 

OTL logfile created on: 12/06/2012 11:09:04 - Run 1

OTL by OldTimer - Version 3.2.48.0 Folder = C:\Documents and Settings\f003204\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

991,48 Mb Total Physical Memory | 573,13 Mb Available Physical Memory | 57,80% Memory free

2,33 Gb Paging File | 2,05 Gb Available in Paging File | 87,95% Paging File free

Paging file location(s): C:\pagefile.sys 0 0 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 18,65 Gb Total Space | 5,77 Gb Free Space | 30,95% Space Free | Partition Type: NTFS

Drive D: | 18,65 Gb Total Space | 18,53 Gb Free Space | 99,40% Space Free | Partition Type: NTFS

Drive F: | 3,73 Gb Total Space | 3,31 Gb Free Space | 88,69% Space Free | Partition Type: FAT32

Drive P: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS

Drive S: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS

Drive X: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS

 

Computer Name: FUN0044 | User Name: f003204 | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012/06/12 11:07:53 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe

PRC - [2012/05/09 09:02:12 | 000,214,088 | ---- | M] ( ) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe

PRC - [2012/03/06 21:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe

PRC - [2012/03/06 21:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

PRC - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () -- C:\WINDOWS\system32\SpyPrinter.exe

PRC - [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2006/10/26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe

PRC - [2005/07/14 01:35:00 | 001,175,628 | ---- | M] (CANON INC.) -- C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012/06/12 03:07:52 | 001,767,424 | ---- | M] () -- C:\Arquivos de programas\Alwil Software\Avast5\defs\12061200\algo.dll

MOD - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () -- C:\WINDOWS\system32\SpyPrinter.exe

MOD - [2001/10/28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll

MOD - [2001/07/31 07:17:12 | 000,094,274 | ---- | M] () -- C:\WINDOWS\system32\HPBHEALR.DLL

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)

SRV - [2012/05/24 13:55:30 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012/05/09 09:02:12 | 000,214,088 | ---- | M] ( ) [Auto | Running] -- C:\Arquivos de programas\GbPlugin\gbpsv.exe -- (GbpSv)

SRV - [2012/03/06 21:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\SpyPrinter.exe -- (SpyPrinterD)

SRV - [2006/11/06 10:21:34 | 001,527,893 | ---- | M] (The Firebird Project) [Disabled | Stopped] -- C:\Arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance)

SRV - [2006/11/06 10:21:33 | 000,065,536 | ---- | M] (The Firebird Project) [Disabled | Stopped] -- C:\Arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance)

SRV - [2006/10/26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)

SRV - [2006/10/26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM)

SRV - [2006/10/26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

SRV - [2005/07/14 01:35:00 | 001,175,628 | ---- | M] (CANON INC.) [Auto | Running] -- C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe -- (Canon Driver Information Assist Service)

SRV - [2003/10/22 10:19:22 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Mrv8000c.sys -- (W8335XP)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)

DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)

DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)

DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)

DRV - File not found [Kernel | System | Stopped] -- -- (Changer)

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\f003204\CONFIG~1\Temp\catchme.sys -- (catchme)

DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\ati4waxx.sys -- (ati4waxx)

DRV - [2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GbpNdisrd.sys -- (NdisrdMP)

DRV - [2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GbpNdisrd.sys -- (Ndisrd)

DRV - [2012/04/05 09:34:04 | 000,046,408 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\gbpkm.sys -- (GbpKm)

DRV - [2012/03/06 21:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2012/03/06 21:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2012/03/06 21:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2012/03/06 21:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2012/03/06 21:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2012/03/06 21:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2012/03/06 20:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2004/08/03 21:31:36 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)

DRV - [2003/12/19 09:07:50 | 000,541,548 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

DRV - [2003/12/11 12:54:14 | 000,391,424 | ---- | M] (Sensaura Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)

DRV - [2003/12/05 08:13:42 | 000,429,440 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)

DRV - [2003/12/04 22:25:54 | 000,011,392 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)

DRV - [2003/07/17 22:58:20 | 000,036,992 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SISAGPX.SYS -- (SISAGP)

DRV - [2003/03/25 06:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\siside.sys -- (SiSide)

DRV - [2002/10/17 04:14:46 | 000,049,024 | R--- | M] (Windows ® 2000 DDK provider) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex)

DRV - [2002/08/20 06:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/

IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.startup.homepage: "http://funpec.br/"

FF - user.js - File not found

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Arquivos de programas\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Arquivos de programas\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Arquivos de programas\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Arquivos de programas\Alwil Software\Avast5\WebRep\FF [2012/03/26 08:27:38 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2012/05/24 13:55:31 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2011/10/20 16:56:09 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Documents and Settings\f003204\Thunderbird\App\thunderbird\components [2012/06/01 07:44:40 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Documents and Settings\f003204\Thunderbird\App\thunderbird\plugins

 

[2011/10/21 14:33:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Extensions

[2010/10/22 09:00:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}

[2012/05/24 13:56:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\extensions

[2012/05/24 13:56:38 | 000,000,000 | ---D | M] (Modulo de Seguranca - Banco do Brasil) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

[2012/05/24 13:55:42 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2007/08/15 14:07:51 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Arquivos de programas\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2012/03/26 08:27:38 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\ARQUIVOS DE PROGRAMAS\ALWIL SOFTWARE\AVAST5\WEBREP\FF

[2012/04/18 17:25:44 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\ARQUIVOS DE PROGRAMAS\JAVA\JRE6\LIB\DEPLOY\JQS\FF

[2012/05/24 13:55:30 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Arquivos de programas\mozilla firefox\components\browsercomps.dll

[2012/04/18 17:25:42 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Arquivos de programas\mozilla firefox\plugins\npdeployJava1.dll

[2012/04/10 14:10:25 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\buscape.xml

[2012/04/10 14:10:25 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\mercadolivre.xml

[2012/04/10 14:10:25 | 000,002,040 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\twitter.xml

[2012/04/10 14:10:25 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\wikipedia-br.xml

[2012/04/10 14:10:25 | 000,000,952 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml

 

O1 HOSTS File: ([2012/06/05 14:36:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Facilitador de Leitor de Link Adobe PDF) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.

O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bb.com.br ([www] * in Trusted sites)

O15 - HKCU\..Trusted Domains: com.br ([www.bancobrasil] * in Trusted sites)

O15 - HKCU\..Trusted Domains: com.br ([www.bb] * in Trusted sites)

O15 - HKCU\..Trusted Domains: com.br ([www14.bancobrasil] * in Trusted sites)

O15 - HKCU\..Trusted Domains: com.br ([www2.bancobrasil] * in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)

O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.4.65.16

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: DhcpNameServer = 10.4.65.16

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Alegria.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Alegria.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2005/10/03 14:28:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2012/06/12 11:07:46 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe

[2012/06/12 10:12:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Iniciar\Programas\Malwarebytes' Anti-Malware

[2012/06/12 10:12:37 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2012/06/12 10:12:36 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware

[2012/06/06 15:46:51 | 000,000,000 | -HSD | C] -- C:\RECYCLER

[2012/06/06 14:49:51 | 000,000,000 | ---D | C] -- C:\ZHP

[2012/06/06 14:49:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Iniciar\Programas\ZHP

[2012/06/06 14:49:19 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\ZHPDiag

[2012/06/05 14:44:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\f003204\Desktop\Ferramenta de remoção de virus

[2012/06/05 14:26:08 | 000,000,000 | RHSD | C] -- C:\cmdcons

[2012/06/05 14:18:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2012/06/05 08:53:31 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\HiJackThis.exe

[2012/06/04 08:33:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\f003204\Recent

[2012/05/24 13:55:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Mozilla

[2012/05/24 13:55:45 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Mozilla Maintenance Service

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2012/06/12 11:16:00 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job

[2012/06/12 11:07:53 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe

[2012/06/12 11:05:00 | 000,001,074 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2012/06/12 10:12:47 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk

[2012/06/12 09:51:51 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job

[2012/06/12 08:55:37 | 000,002,485 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Microsoft Office Excel 2007.lnk

[2012/06/12 07:35:30 | 000,001,070 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2012/06/12 07:34:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012/06/11 12:08:23 | 000,055,534 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Booking.com_ Confirmação.pdf

[2012/06/11 08:12:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012/06/08 08:58:53 | 000,110,485 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Câmeras Digitais e Filmadoras - Americanas.pdf

[2012/06/05 14:36:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2012/06/05 14:26:13 | 000,000,327 | RHS- | M] () -- C:\boot.ini

[2012/06/05 08:53:32 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\HiJackThis.exe

[2012/06/04 17:44:56 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\fmhuptxw.sys

[2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) -- C:\WINDOWS\System32\drivers\GbpNdisrd.sys

[2012/05/30 14:27:39 | 000,002,553 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Microsoft Office Word 2007.lnk

[2012/05/18 11:48:26 | 004,515,069 | ---- | M] () -- C:\Documents and Settings\f003204\Meus documentos\CONVÊNIOS.pdf

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012/06/12 10:12:47 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk

[2012/06/11 12:08:20 | 000,055,534 | ---- | C] () -- C:\Documents and Settings\f003204\Desktop\Booking.com_ Confirmação.pdf

[2012/06/08 08:58:49 | 000,110,485 | ---- | C] () -- C:\Documents and Settings\f003204\Desktop\Câmeras Digitais e Filmadoras - Americanas.pdf

[2012/06/05 14:26:09 | 000,261,856 | RHS- | C] () -- C:\cmldr

[2012/06/04 17:44:55 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\fmhuptxw.sys

[2012/05/18 11:48:25 | 004,515,069 | ---- | C] () -- C:\Documents and Settings\f003204\Meus documentos\CONVÊNIOS.pdf

[2011/10/20 16:58:51 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll

[2011/02/02 16:26:10 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2010/10/14 16:53:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CPC10Q.INI

 

========== LOP Check ==========

 

[2010/10/22 11:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Alwil Software

[2007/01/25 09:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Avg7

[2011/07/28 10:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\gas

[2012/05/21 07:49:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\GbPlugin

[2009/12/15 09:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\3M

[2011/08/02 15:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\Auslogics

[2011/04/07 17:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\BizAgi Ltd

[2011/04/07 17:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\IsolatedStorage

[2011/08/29 08:06:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\Thunderbird

[2012/06/12 11:16:00 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job

[2012/06/12 09:51:51 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 8 bytes -> C:\WINDOWS\System32\drivers:IncompleteBoot.cnt

 

< End of report >

 

 

OBS: O Avast disparou quando passei o Malwarebytes no PENDRIVER dela.

virusxw.jpg

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Edvan

 

|- Execute o OTL.exe.

|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )

 

:OTL

FF - user.js - File not found

O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

 

:Commands

[CLEARALLRESTOREPOINTS]

[purity]

[emptytemp]

[Reboot]

|- Clique no botão Consertar -> Aguarde a conclusão!

|- O computador vai reiniciar! -> Clique em "Executar".

 

OTL_RunFix.jpg

 

|- Para versões em Inglês,clique em Run Fix que é o mesmo que Consertar.

|- Poste o relatório: C:\_OTL\MovedFiles\*.log

 

-/-

 

|- Baixe: < UsbFix > ( ...de C_XX & El Desaparecido )

 

UsbFix_Download.jpg

 

|- Salve-o no desktop!

|- Siga com sua instalação.

|- Conecte seu pendrive ao computador!

|- Execute o arquivo UsbFix.exe,com um duplo clique.

 

UsbFix_Supprssion.jpg

 

|- Escolha a opção "Suppression" ou "Delete".

|- Aguarde a conclusão e poste o relatório. ( C:\UsbFix.txt )

 

-/-

 

|- Baixe: < rendu2.png > ( ... par tigzy )

 

|- Salve-o no desktop! RogueKiller_Logo.jpg

|- Feche aplicativos que estejam abertos!

 

RogueKiller_v733.jpg

 

|- Ps: Para Windows Vista ou 7,execute RogueKiller.exe como administrador.

|- Aguarde a finalização de seu Pre-scan.

 

RogueKiller_Scan2.jpg

 

|- Dê início ao diagnóstico,clicando no botão "Verificar".

|- Exemplo: Mode: Verificar -- Date: mm/dd/2012 00:52:24

|- Poste o relatório: RKreport[1].txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam!

 

Ao passar o < UsbFix > quando estava em 70% do scan apareceu essa tela aqui abaixo:

imagemey2.jpg

 

Reiniciou o sistema só que agora nao carrega mais minha area de trabalho, nao abre de jeito nenhum, nem em modo de segurança, estou em outra maquina escrevendo, estou tentando a restauração do sistema pelo ponto de restauração que o combofix criou.

 

Entrei com live-cd do Linux, copiei esses arquivos de partida para a maquina mesmo assim não carregou o sistema, NTDETECT.COM, AUTOEXEC.BAT e ntldr, fica na tela azul e nao carrega os ícones da área de trabalho, já tentei o CHKDSK /R /P e nada.

 

Entrei na partição que esta o sistema e copiei o log do UsbFix.

mais nao tem jeito de voltar as configurações para que ele abra normalmente.

 

############################## | UsbFix V 7.089 | [supressão]

 

Usuário: f003204 (Administrador) # FUN0044

Atualizado em 09/06/2012 por El Desaparecido

Começou em 14:15:26 | 12/06/2012

 

Site: http://eldesaparecido.com

Foro: http://forum.eldesaparecido.com

Arquivo suspeito ? : http://eldesaparecido.com/upload.php

Contato: contact@eldesaparecido.com

 

PC: AWARD_ (AWRDACPI) (X86-based PC) # Desktop Computer

CPU: AMD Sempron 2400+ (1662)

RAM -> [Total : 991 | Free : 592]

BIOS: Phoenix - AwardBIOS v6.00PG

BOOT: Normal boot

 

OS: Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3

WB: Windows Internet Explorer 8.0.6001.18702

 

SC: Security Center Service [Enabled]

WU: Windows Update Service [Enabled]

FW: Windows FireWall Service [Enabled]

 

C:\ (%systemdrive%) -> Disco fixo # 19 Gb (6 Mb livre - 32%) [] # NTFS

D:\ -> Disco fixo # 19 Gb (19 Mb livre - 99%) [] # NTFS

E:\ -> CD-ROM

F:\ -> Disco removível # 4 Gb (3 Mb livre - 89%) [] # FAT32

 

################## | Processos Ativos |

 

C:\WINDOWS\System32\smss.exe (712)

C:\WINDOWS\system32\winlogon.exe (784)

C:\WINDOWS\system32\services.exe (828)

C:\WINDOWS\system32\lsass.exe (840)

C:\ARQUIV~1\GbPlugin\GbpSv.exe (1004)

C:\WINDOWS\system32\svchost.exe (1040)

C:\WINDOWS\System32\svchost.exe (1184)

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1520)

C:\WINDOWS\system32\spoolsv.exe (1564)

C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe (280)

C:\Arquivos de programas\Java\jre6\bin\jqs.exe (480)

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe (616)

C:\WINDOWS\Explorer.EXE (1348)

c:\windows\system32\SpyPrinter.exe (576)

C:\WINDOWS\system32\svchost.exe (744)

C:\WINDOWS\system32\ctfmon.exe (2860)

C:\Arquivos de programas\Internet Explorer\iexplore.exe (2088)

C:\Arquivos de programas\Internet Explorer\iexplore.exe (2384)

C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe (1516)

C:\UsbFix\Go.exe (2704)

 

################## | Processos parados |

 

Parado! C:\ARQUIV~1\GbPlugin\GbpSv.exe (1004)

Parado! C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1520)

Parado! C:\WINDOWS\system32\spoolsv.exe (1564)

Parado! C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe (280)

Parado! C:\Arquivos de programas\Java\jre6\bin\jqs.exe (480)

Parado! C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe (616)

Parado! C:\WINDOWS\Explorer.EXE (1348)

Parado! c:\windows\system32\SpyPrinter.exe (576)

Parado! C:\WINDOWS\system32\ctfmon.exe (2860)

Parado! C:\Arquivos de programas\Internet Explorer\iexplore.exe (2088)

Parado! C:\Arquivos de programas\Internet Explorer\iexplore.exe (2384)

Parado! C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe (1516)

 

################## | Ficheiros # pastas infeciosos |

 

Supprimido ! C:\WINDOWS\system32\services.exe

Supprimido ! C:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21318

Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21098

Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21262

Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21318

Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1003

Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1004

Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1007

Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-1004

Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-1008

Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-500

Supprimido ! C:\khs

 

(!) Ficheiros temporários suprimido.

 

################## | Registro |

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Edvan

 

|- Muito extranho o ocorrido,pois ao passar o UsbFix na máquina do meu sobrinho,em modo diagnóstico,estava incluído o services.exe para remoção. Abortei o modo Suppression,pois desconfiei dessa indicação da ferramenta. Devido a esse fato,está suspenso,até segunda ordem,a execução dessa ferramenta em seu modo Delete ou Fix,caso seja encontrado o arquivo services.exe no relatório.

 

-/-

 

|- Amigo Edvan,utilize o CD do Windows XP e faça o devido reparo.

|- Entre na Bios e configure como 1° Boot a unidade de CD-ROM. Procure salvar essa escolha e reinicie o computador com o CD do Windows na unidade. Siga as indicações na tela e escolha R de Reparar. Ao concluir,volte a configurar,como 1° boot o HD...salve essa escolha e reinicie o computador,para sair do Setup.

Tendo êxito siga com a ferramenta RogueKiller e poste o relatório pedido.

 

-/-

 

################## | Ficheiros # pastas infeciosos |

 

Presente ! D:\WINDOWS\system32\services.exe

 

################## | Registro |

 

Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsHistory

Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsHistory

Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsMenu

Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsMenu

Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRun

Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRun

Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoSMHelp

Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoSMHelp

|- Fiz ainda a pouco,uma varredura com o UsbFix em meu computador e consta como infectado o services.exe.

|- Ps: Pelo visto,terei que enviar MP aos desenvolvedores,relatando o ocorrido ou bug.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia amigo DigRam!

 

Amigo Edvan,utilize o CD do Windows XP e faça o devido reparo.

|- Entre na Bios e configure como 1° Boot a unidade de CD-ROM. Procure salvar essa escolha e reinicie o computador com o CD do Windows na unidade. Siga as indicações na tela e escolha R de Reparar. Ao concluir,volte a configurar,como 1° boot o HD...salve essa escolha e reinicie o computador,para sair do Setup.

 

Já tentei essa dica amigo, nao obtive êxito, mais nao tem problema, essa maquina está precisando formatar mesmo, vou aproveitar e trocar o HD por um maior, pois o HD atual dela é de 40GB, como o usuário dessa maquina está precisando urgentemente dessa maquina para trabalhar então acho mais rápido formatar e fazer os backups dos dados dela..

 

Pode fechar o tópico! :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia amigo DigRam!

 

 

 

Já tentei essa dica amigo, nao obtive êxito, mais nao tem problema, essa maquina está precisando formatar mesmo, vou aproveitar e trocar o HD por um maior, pois o HD atual dela é de 40GB, como o usuário dessa maquina está precisando urgentemente dessa maquina para trabalhar então acho mais rápido formatar e fazer os backups dos dados dela..

 

Pode fechar o tópico! :thumbsup:

Ok! Edvan

 

|- De certa forma seu computador acabou sendo 'boi de piranha',ao detectar o bug na ferramenta UsbFix. São ossos do ofício...que me fez lembrar a crítica de um Analista,ao não procurar ganhar tempo na execução de algumas ferramentas,quando pedia sua execução em Modo diagnóstico. ( Rechercher )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Relaxa essas coisas acontece, a maquina já está 100% agora, no mais fico muito grato pela ajuda que você vem prestando aqui com suas analises e tutoriais.! :thumbsup:

 

Tem muita maquina infectada por aqui, vcs vão me ver muito por aqui ainda..hehe.

 

P.S: Novos Logs ainda vem por aí..rsrsrs :grin:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.