Edvan 30 Denunciar post Postado Junho 5, 2012 Pessoal esse log é de outra maquina, sei que já tenho outro tópico aberto, mais como nao posso postar outros logs no mesmo tópico, então estou criando mais um aqui. BankerFix 3.1 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2012-06-04 - 11:05 ------------------------------------------------------- Lista de Definição: 2012-03-19-1 | CORE: 2012-01-27-1 ======================================================= Arquivo infectado detectado: C:\WINDOWS\inf\asynceql.inf Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\Media\mssmtp.wav Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system\mkp.dll Arquivo infectado removido com sucesso! Arquivo infectado detectado: C:\WINDOWS\system32\drwtsn32.dll Arquivo infectado removido com sucesso! ----- Fim ------------------------- Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Versão da Base de Dados: v2012.06.04.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 f003204 :: FUN0044 [limitado] 04/06/2012 14:28:26 mbam-log-2012-06-04 (14-28-26).txt Tipo de Verificação: Verificação Completa Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM Opções de verificação desativadas: P2P Objetos escaneados: 351640 Tempo decorrido: 3 hora(s), 15 minuto(s), 46 segundo(s) Processos de Memória Detectados: 0 (Não foram detectados ítens maliciosos) Módulos de Memória Detectados: 0 (Não foram detectados ítens maliciosos) Chaves de Registro Detectadas: 17 HKLM\SOFTWARE\Microsoft\DRM\amty (Worm.Autorun) -> Enviado para a Quarentena e deletado com sucesso. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__GbPluginBb (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\CLSID\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\TypeLib\{C41A1C01-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\Interface\{5C350402-AD9A-41E7-A303-C49F6C520000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\Gbieh.GbIehObj.1 (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\Gbieh.GbIehObj (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C41A1C0E-EA6C-11D4-B1B8-444553540000} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginBb (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\Gbieh.GbPluginObj.1 (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCR\Gbieh.GbPluginObj (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Enviado para a Quarentena e deletado com sucesso. Valores de Registro Detectadas: 2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Data: GbPlugin ShlObj -> Enviado para a Quarentena e deletado com sucesso. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{E37CB5F0-51F5-4395-A808-5FA49E399F83} (Trojan.Vundo) -> Data: GbPlugin ShlObj -> Enviado para a Quarentena e deletado com sucesso. Itens de Dados no Registro Detectadas: 0 (Não foram detectados ítens maliciosos) Pastas Detectadas: 1 C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> Enviado para a Quarentena e deletado com sucesso. Arquivos Detectados: 2 C:\Arquivos de programas\GbPlugin\gbieh.dll (Trojan.Vundo) -> Será deletado na próxima inicialização. C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> Enviado para a Quarentena e deletado com sucesso. (fim) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 08:54:21, on 05/06/2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe c:\windows\system32\SpyPrinter.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll O4 - HKLM\..\Run: [avast5] C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe /nogui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CS2\Services\Tcpip\..\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: NameServer = 10.4.65.16 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = funpec.br O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SpyPrinterD - Unknown owner - c:\windows\system32\SpyPrinter.exe -- End of file - 5981 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 5, 2012 Bom Dia! Edvan |- Baixe: < > ( ... by sUBs ) |- Salve-o no desktop! ( Área de trabalho! ) |- Ps: Desabilite seu antivírus,antispywares e/ou firewall. ( Menos o do Windows! ) |- Feche algum programa/arquivo que esteja aberto. |- Feche,também,seu navegador! ( IE,Firefox,Opera ou Google Chrome ) |- Ps: Esteja conectado(a) à Internet. <- Importante! |- Execute ComboFix.exe,com um duplo clique. |- Para Windows Vista e/ou 7,dê clique direito em ComboFix.exe e execute-o como administrador. |- Ps: Instale o "Console de Recuperação",caso seja solicitado! |- Ps: Ficará,portanto,à seu critério optar por sua instalação. |- Surgindo alguma mensagem de erro,execute ComboFix.exe em Modo de Segurança com rede. |- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. |- Abrir-se-á a janela Auto Scan. |- Aguarde a finalização de todas as Etapas. |- Durante o scan,evite utilizar o mouse ou teclado! |- Concluindo,poste: C:\ComboFix.txt |- "ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão de analistas de segurança." |- Poste,também,HijackThis atualizado! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 5, 2012 ComboFix 12-06-05.03 - f003204 05/06/2012 14:28:15.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.991.515 [GMT -3:00] Executando de: c:\documents and settings\f003204\Desktop\60329_combofix_123123.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: Avira AntiVir PersonalEdition Classic *Enabled/Outdated* {00000000-0000-0000-0000-000000000000} AV: Avira AntiVir PersonalEdition Classic *Enabled/Updated* {804E5358-FFA4-00C8-0D24-347CA8A3377C} . ADS - system32: deleted 2 bytes in 1 streams. ADS - drivers: deleted 216 bytes in 2 streams. . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Administrador.PROMOCAO\WINDOWS c:\documents and settings\f003204\WINDOWS c:\documents and settings\Niomar.PROMOCAO\WINDOWS C:\restore c:\windows\IsUn0416.exe c:\windows\Media\_tmp c:\windows\system\chron32.dll c:\windows\system32\SET3F8.tmp c:\windows\system32\SET3F9.tmp c:\windows\system32\SET3FA.tmp c:\windows\system32\SET3FB.tmp c:\windows\system32\SET400.tmp c:\windows\system32\SETB1.tmp c:\windows\system32\SETBD.tmp . . (((((((((((((((( Arquivos/Ficheiros criados de 2012-05-05 to 2012-06-05 )))))))))))))))))))))))))))) . . 2012-06-05 11:53 . 2012-06-05 11:53 388608 ----a-w- C:\HiJackThis.exe 2012-06-04 20:44 . 2012-06-04 20:44 54016 ----a-w- c:\windows\system32\drivers\fmhuptxw.sys 2012-05-24 16:55 . 2012-05-24 16:55 -------- d-----w- c:\arquivos de programas\Mozilla Maintenance Service 2012-05-24 16:55 . 2012-05-24 16:55 157352 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice_installer.exe 2012-05-24 16:55 . 2012-05-24 16:55 129976 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice.exe . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-04 17:07 . 2012-04-18 19:57 28880 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys 2012-04-18 20:25 . 2012-04-18 20:26 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-04-18 20:25 . 2010-10-22 17:00 472808 -c--a-w- c:\windows\system32\deployJava1.dll 2012-04-05 12:34 . 2009-10-27 20:08 46408 ----a-w- c:\windows\system32\drivers\gbpkm.sys 2012-05-24 16:55 . 2011-10-21 17:39 97208 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por padrão não são apresentadas. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-03-07 00:15 123536 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4waxx.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk] backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^hp psc 2000 Series.lnk] backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] backup=c:\windows\pss\Microsoft Office.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Post-it® Software Notes Lite.lnk] path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Post-it® Software Notes Lite.lnk backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Niomar.PROMOCAO^Menu Iniciar^Programas^Inicializar^Reboot.exe] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-13 22:21 1695232 ------w- c:\arquivos de programas\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook] 2003-12-05 06:36 249856 -c--a-w- c:\windows\system32\Keyhook.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG] 2002-07-12 10:15 106496 -c--a-w- c:\windows\SiSUSBrg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] 2003-12-19 09:53 65024 -c--a-w- c:\windows\SOUNDMAN.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-18 17:02 254696 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "GbpSv"=2 (0x2) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Fortes Informática\\RemProtDeamon.exe"= "c:\\WINDOWS\\system32\\DWRCS.EXE"= "c:\\Arquivos de programas\\Canon\\DIAS\\CnxDIAS.exe"= "c:\\Arquivos de programas\\NetMeeting\\conf.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "14674:TCP"= 14674:TCP:NortonAV "18245:TCP"= 18245:TCP:NortonAV "17860:TCP"= 17860:TCP:NortonAV "15603:TCP"= 15603:TCP:NortonAV "18163:TCP"= 18163:TCP:NortonAV "15280:TCP"= 15280:TCP:NortonAV "15693:TCP"= 15693:TCP:NortonAV "14644:TCP"= 14644:TCP:NortonAV "17233:TCP"= 17233:TCP:NortonAV "16774:TCP"= 16774:TCP:NortonAV "14545:TCP"= 14545:TCP:NortonAV "18857:TCP"= 18857:TCP:NortonAV "18019:TCP"= 18019:TCP:NortonAV "16171:TCP"= 16171:TCP:NortonAV "16282:TCP"= 16282:TCP:NortonAV "12432:TCP"= 12432:TCP:NortonAV "14298:TCP"= 14298:TCP:NortonAV . R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [27/10/2009 17:08 46408] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20/06/2011 08:09 612184] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [26/01/2009 15:05 337880] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [26/01/2009 15:05 20696] R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [27/10/2009 17:10 214088] R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880] S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys [?] S2 gupdate;Serviço do Google Update (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176] S2 SpyPrinterD;SpyPrinterD;c:\windows\system32\SpyPrinter.exe [21/05/2008 16:53 1406464] S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe [24/05/2012 13:55 129976] S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880] S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s [?] S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s [?] . Conteúdo da pasta 'Tarefas Agendadas' . 2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49] . 2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49] . 2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . 2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.funpec.br/ponto_online/ IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: bancobrasil.com.br\www Trusted Zone: bancobrasil.com.br\www14 Trusted Zone: bancobrasil.com.br\www2 Trusted Zone: bb.com.br\www Trusted Zone: com.br\www.bancobrasil Trusted Zone: com.br\www.bb Trusted Zone: com.br\www14.bancobrasil Trusted Zone: com.br\www2.bancobrasil TCP: DhcpNameServer = 10.4.65.16 FF - ProfilePath - c:\documents and settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\ FF - prefs.js: browser.startup.homepage - hxxp://funpec.br/ . - - - - ORFÃOS REMOVIDOS - - - - . MSConfigStartUp-Cmaudio - cmicnfg.cpl . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-06-05 14:36 Windows 5.1.2600 Service Pack 3 NTFS . Procurando processos ocultos ... . Procurando entradas auto inicializáveis ocultas ... . Procurando ficheiros/arquivos ocultos ... . Varredura completada com sucesso arquivos/ficheiros ocultos: 0 . ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithList] @Class="Shell" "a"="shimgvw.dll" "MRUList"="ab" "b"="mspaint.exe" . [HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithProgids] "$¨+_auto_file"=hex(0): . [HKEY_LOCAL_MACHINE\software\Adobe\CommonFiles\{AC76BA86-1033-0000-7760-000000000001}\ColorProfiles] @DACL=(02 0000) "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AdobeRGB1998.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AppleRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Color Management Off.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\ColorMatchRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Acrobat 4.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Photoshop 4.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Europe Prepress Defaults.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Japan Color Prepress.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Coated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Uncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanWebCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\BlackWhite.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\CIERGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\JapanStandard.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\NTSC1953.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\PAL_SECAM.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop4DefaultCMYK.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop5DefaultCMYK.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\SMPTE-C.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\WideGamutRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Photoshop 5 Default Spaces.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\sRGB Color Space Profile.icm"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\US Prepress Defaults.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebCoatedSWOP.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Web Graphics Defaults.csf"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\000021599B0090400000000000F01FEC\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="Microsoft Application Error Reporting" "1"="OFFICE12;1" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"="READER8;[1]" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\C1B24092317057547BACC5E8B780994D\SourceList\Media] @DACL=(02 0000) "MediaPackage"="\\" "1"="WILTON - VB;" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";1" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D6461317C3DC4F04799BDCE9E42626FE\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";Microsoft .NET Framework 2.0 [Disk 1]" "2"=";Microsoft .NET Framework 2.0 [Disk 1]" "3"=";Microsoft .NET Framework 2.0 [Disk 1]" "4"=";Microsoft .NET Framework 2.0 [Disk 1]" "5"=";Microsoft .NET Framework 2.0 [Disk 1]" "6"=";Microsoft .NET Framework 2.0 [Disk 1]" "7"=";Microsoft .NET Framework 2.0 [Disk 1]" "8"=";Microsoft .NET Framework 2.0 [Disk 1]" "9"=";Microsoft .NET Framework 2.0 [Disk 1]" "10"=";Microsoft .NET Framework 2.0 [Disk 1]" "11"=";Microsoft .NET Framework 2.0 [Disk 1]" "12"=";Microsoft .NET Framework 2.0 [Disk 1]" "13"=";Microsoft .NET Framework 2.0 [Disk 1]" . Tempo para conclusão: 2012-06-05 14:38:30 ComboFix-quarantined-files.txt 2012-06-05 17:38 . Pré-execução: 5.872.652.288 bytes disponíveis Pós execução: 6.229.417.984 bytes disponíveis . WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - 109FCDB303BB445B4E9458B3D0CE68C8 Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:42:53, on 05/06/2012 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\svchost.exe C:\ARQUIV~1\ALWILS~1\Avast5\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\HiJackThis.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CS2\Services\Tcpip\..\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: NameServer = 10.4.65.16 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = funpec.br O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = funpec.br O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SpyPrinterD - Unknown owner - c:\windows\system32\SpyPrinter.exe -- End of file - 5525 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 5, 2012 Boa Tarde! Edvan |- O Avast é seu antivírus usual? |- Ps: Conheces o ficheiro em destaque? c:\windows\system32\drivers\fmhuptxw.sys ####### S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys[?] ####### |- E o driver ( ati4waxx.sys ),é de seu conhecimento? -/- |- Selecione e copie,o conteúdo que está em "vermelho",para o Bloco de Notas. |- Salve-o,no desktop,com o nome: CFScript <-- Texto! File:: Documents and Settings\Niomar.PROMOCAO\Menu Iniciar\Programas\Inicializar\Reboot.exe SecCenter:: AV: Avira AntiVir PersonalEdition Classic *Enabled/Outdated* {00000000-0000-0000-0000-000000000000} AV: Avira AntiVir PersonalEdition Classic *Enabled/Updated* {804E5358-FFA4-00C8-0D24-347CA8A3377C} Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "14674:TCP"=- "18245:TCP"=- "17860:TCP"=- "15603:TCP"=- "18163:TCP"=- "15280:TCP"=- "15693:TCP"=- "14644:TCP"=- "17233:TCP"=- "16774:TCP"=- "14545:TCP"=- "18857:TCP"=- "18019:TCP"=- "16171:TCP"=- "16282:TCP"=- "12432:TCP"=- "14298:TCP"=- |- Ps: Desabilite,temporariamente,seu antivírus. |- Ps: Não utilizem este script em outra máquina! |- Arraste,o CFScript.txt para o ícone/interior do ComboFix. |- Veja a demonstração! |- Atenda à solicitação,que deverá surgir,para rodar o ComboFix. |- Ps: Faça o arraste,até surgir essa solicitação! ( janela ) |- Concluindo,poste: C:\ComboFix.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 5, 2012 Boa Tarde! Edvan |- O Avast é seu antivírus usual? |- Ps: Conheces o ficheiro em destaque? c:\windows\system32\drivers\fmhuptxw.sys ####### S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys[?] ####### |- E o driver ( ati4waxx.sys ),é de seu conhecimento? Sim amigo DigRam, o antivírus usual que essa maquina usa é o Avast. Desconheço todos esses ficheiros! ComboFix 12-06-05.03 - f003204 05/06/2012 17:30:36.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.991.608 [GMT -3:00] Executando de: c:\documents and settings\f003204\Desktop\60329_combofix_123123.exe Comandos utilizados :: c:\documents and settings\f003204\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . . (((((((((((((((( Arquivos/Ficheiros criados de 2012-05-05 to 2012-06-05 )))))))))))))))))))))))))))) . . 2012-06-05 11:53 . 2012-06-05 11:53 388608 ----a-w- C:\HiJackThis.exe 2012-06-04 20:44 . 2012-06-04 20:44 54016 ----a-w- c:\windows\system32\drivers\fmhuptxw.sys 2012-05-24 16:55 . 2012-05-24 16:55 -------- d-----w- c:\arquivos de programas\Mozilla Maintenance Service 2012-05-24 16:55 . 2012-05-24 16:55 157352 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice_installer.exe 2012-05-24 16:55 . 2012-05-24 16:55 129976 ----a-w- c:\arquivos de programas\Mozilla Firefox\maintenanceservice.exe . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-04 17:07 . 2012-04-18 19:57 28880 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys 2012-04-18 20:25 . 2012-04-18 20:26 73728 ----a-w- c:\windows\system32\javacpl.cpl 2012-04-18 20:25 . 2010-10-22 17:00 472808 -c--a-w- c:\windows\system32\deployJava1.dll 2012-04-05 12:34 . 2009-10-27 20:08 46408 ----a-w- c:\windows\system32\drivers\gbpkm.sys 2012-05-24 16:55 . 2011-10-21 17:39 97208 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por padrão não são apresentadas. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-03-07 00:15 123536 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360] . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4waxx.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Acrobat Assistant.lnk] backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Acrobat Assistant.lnk . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^hp psc 2000 Series.lnk] backup=c:\windows\pss\hp psc 2000 Series.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Microsoft Office.lnk] backup=c:\windows\pss\Microsoft Office.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Iniciar^Programas^Inicializar^Post-it® Software Notes Lite.lnk] path=c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\Post-it® Software Notes Lite.lnk backup=c:\windows\pss\Post-it® Software Notes Lite.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Niomar.PROMOCAO^Menu Iniciar^Programas^Inicializar^Reboot.exe] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-05-11 06:06 40048 ----a-w- c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-13 22:20 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-13 22:21 1695232 ------w- c:\arquivos de programas\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook] 2003-12-05 06:36 249856 -c--a-w- c:\windows\system32\Keyhook.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG] 2002-07-12 10:15 106496 -c--a-w- c:\windows\SiSUSBrg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] 2003-12-19 09:53 65024 -c--a-w- c:\windows\SOUNDMAN.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-18 17:02 254696 ----a-w- c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "GbpSv"=2 (0x2) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Fortes Informática\\RemProtDeamon.exe"= "c:\\WINDOWS\\system32\\DWRCS.EXE"= "c:\\Arquivos de programas\\Canon\\DIAS\\CnxDIAS.exe"= "c:\\Arquivos de programas\\NetMeeting\\conf.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= . R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [27/10/2009 17:08 46408] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [20/06/2011 08:09 612184] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [26/01/2009 15:05 337880] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [26/01/2009 15:05 20696] R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [27/10/2009 17:10 214088] R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880] S0 ati4waxx;ati4waxx;c:\windows\system32\Drivers\ati4waxx.sys --> c:\windows\system32\Drivers\ati4waxx.sys [?] S2 gupdate;Serviço do Google Update (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176] S2 SpyPrinterD;SpyPrinterD;c:\windows\system32\SpyPrinter.exe [21/05/2008 16:53 1406464] S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [26/03/2012 10:49 136176] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe [24/05/2012 13:55 129976] S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [18/04/2012 16:57 28880] S4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -s [?] S4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s --> c:\arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -s [?] . Conteúdo da pasta 'Tarefas Agendadas' . 2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49] . 2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-03-26 13:49] . 2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . 2012-06-05 c:\windows\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.funpec.br/ponto_online/ IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: bancobrasil.com.br\www Trusted Zone: bancobrasil.com.br\www14 Trusted Zone: bancobrasil.com.br\www2 Trusted Zone: bb.com.br\www Trusted Zone: com.br\www.bancobrasil Trusted Zone: com.br\www.bb Trusted Zone: com.br\www14.bancobrasil Trusted Zone: com.br\www2.bancobrasil TCP: DhcpNameServer = 10.4.65.16 FF - ProfilePath - c:\documents and settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\ FF - prefs.js: browser.startup.homepage - hxxp://funpec.br/ . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-06-05 17:38 Windows 5.1.2600 Service Pack 3 NTFS . Procurando processos ocultos ... . Procurando entradas auto inicializáveis ocultas ... . Procurando ficheiros/arquivos ocultos ... . Varredura completada com sucesso arquivos/ficheiros ocultos: 0 . ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithList] @Class="Shell" "a"="shimgvw.dll" "MRUList"="ab" "b"="mspaint.exe" . [HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21318\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*$*¨*%\OpenWithProgids] "$¨+_auto_file"=hex(0): . [HKEY_LOCAL_MACHINE\software\Adobe\CommonFiles\{AC76BA86-1033-0000-7760-000000000001}\ColorProfiles] @DACL=(02 0000) "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AdobeRGB1998.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\AppleRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Color Management Off.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\ColorMatchRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Acrobat 4.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Emulate Photoshop 4.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Europe Prepress Defaults.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\EuroscaleUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Japan Color Prepress.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Coated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanColor2001Uncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\JapanWebCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\BlackWhite.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\CIERGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\JapanStandard.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\NTSC1953.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\PAL_SECAM.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop4DefaultCMYK.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Photoshop5DefaultCMYK.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\SMPTE-C.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\WideGamutRGB.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Photoshop 5 Default Spaces.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\sRGB Color Space Profile.icm"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\US Prepress Defaults.csf"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedCoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USSheetfedUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebCoatedSWOP.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Profiles\\Recommended\\USWebUncoated.icc"=dword:00000001 "c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Color\\Settings\\Web Graphics Defaults.csf"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\000021599B0090400000000000F01FEC\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="Microsoft Application Error Reporting" "1"="OFFICE12;1" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\68AB67CA7DA76401B7448A0100000030\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"="READER8;[1]" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" "11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\C1B24092317057547BACC5E8B780994D\SourceList\Media] @DACL=(02 0000) "MediaPackage"="\\" "1"="WILTON - VB;" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\CFD2C1F142D260E3CB8B271543DA9F98\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";1" . [HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D6461317C3DC4F04799BDCE9E42626FE\SourceList\Media] @DACL=(02 0000) "DiskPrompt"="[1]" "1"=";Microsoft .NET Framework 2.0 [Disk 1]" "2"=";Microsoft .NET Framework 2.0 [Disk 1]" "3"=";Microsoft .NET Framework 2.0 [Disk 1]" "4"=";Microsoft .NET Framework 2.0 [Disk 1]" "5"=";Microsoft .NET Framework 2.0 [Disk 1]" "6"=";Microsoft .NET Framework 2.0 [Disk 1]" "7"=";Microsoft .NET Framework 2.0 [Disk 1]" "8"=";Microsoft .NET Framework 2.0 [Disk 1]" "9"=";Microsoft .NET Framework 2.0 [Disk 1]" "10"=";Microsoft .NET Framework 2.0 [Disk 1]" "11"=";Microsoft .NET Framework 2.0 [Disk 1]" "12"=";Microsoft .NET Framework 2.0 [Disk 1]" "13"=";Microsoft .NET Framework 2.0 [Disk 1]" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- . - - - - - - - > 'explorer.exe'(3664) c:\windows\system32\WININET.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Tempo para conclusão: 2012-06-05 17:40:04 ComboFix-quarantined-files.txt 2012-06-05 20:40 ComboFix2.txt 2012-06-05 17:38 . Pré-execução: 6.046.384.128 bytes disponíveis Pós execução: 6.031.691.776 bytes disponíveis . - - End Of File - - A5D5780C71A40CDC2231FBD446DF3B55 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 5, 2012 Boa Noite! Edvan |- Configure o Windows,para mostrar os arquivos/pastas ocultas. |- Acesse: |- Em "Arquivo para verificar",coloque: |- <1> c:\windows\system32\drivers\fmhuptxw.sys |- Ao concluir,coloque este outro: |- <2> c:\windows\system32\Drivers\ati4waxx.sys |- Clique em "Enviar". |- Ps: Copie e poste,o resultado destes exames. |- Baixe: | ZHPDiag2 | *ºº* < > ( ... de Nicolas Coolman ) |- Salve-o no desktop! |- Desabilite seu antivírus e execute "ZHPDiag2.exe",para instalar a ferramenta. |- Confirme todos os passos,ao instalar ZHPDiag. |- Conclua a instalação,clicando em "Termine". |- Ps: Após a instalação,além de ZHPScript,estarão disponíveis no desktop: |- <1> MBRCheck |- <2> ZHPDiag2 |- <3> ZHPFix |- Clique no ícone do pergaminho. ( ZHPScript ) |- Clique na seta verde para atualizá-la e/ou baixar sua definição mais recente. ( Your version is update. ) |- Habilite todas as opções de diagnóstico,clicando em "Options". |- Clique em All. |- |- Clique em "Calendar" e escolha 30 dias! |- Dê início ao scan,clicando no ícone da lupa. ( Start Diagnosis ) |- Ao concluir,clique em "Save Report". |- Salve-o em um local conveniente! ( ZHPDiag.txt ) |- Ps: Não poste,diretamente,esse arquivo texto. |- Ou envie-o à Pjjoint.malekal,clicando na seta azul! < > |- Ou acesse: < > |- Para enviar,siga o caminho: Selecionar arquivo... -> Abrir -> Upload file |- Poste o endereço que estará em "Download link" ou "Forum link". |- Ou acesse: < > |- Maiores informações: < |Link| > Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 6, 2012 Em "Arquivo para verificar",coloque: |- <1> c:\windows\system32\drivers\fmhuptxw.sys |- Ao concluir,coloque este outro: |- <2> c:\windows\system32\Drivers\ati4waxx.sys |- Clique em "Enviar". |- Ps: Copie e poste,o resultado destes exames. DigRam, configurei o Windows, para mostrar os arquivos/pastas ocultas conforme solicitados, porem só achei o: (c:\windows\system32\drivers\fmhuptxw.sys) O resultado está na imagem logo abaixo: Log do ZHPDiag.txt. http://wikisend.com/download/399112/ZHPDiag.txt Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 6, 2012 Boa Noite! Edvan |- Os ficheiros são legítimos! -/- |- Desabilite seu antivírus! |- Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /uninstall --> Clique OK. |- < > |- Clique em Executar --> Aguarde! |- Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK. |- Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório! |- Ou,vá em Iniciar --> Executar --> Digite ou cole ( Paste ): |- "%userprofile%\desktop\combofix" /uninstall |- Clique OK. |- Aguarde a desinstalação,e clique OK na mensagem. |- Ps: Outra opção,seria renomear o Combofix.exe para uninstall.exe e executá-lo. -/- |- Feche programas/pastas que estejam abertas. |- Feche,também,o navegador! |- Para Windows Vista,desabilite a UAC. |- Dê um duplo clique em ZHPFix. |- Selecione e copie estas informações,que estão em vermelho,para o "Bloco de Notas". O42 - Logiciel: J2SE Runtime Environment 5.0 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150060} O43 - CFD: 05/12/2005 - 14:12:43 - [0] ----D C:\Documents and Settings\All Users.WINDOWS\Favoritos O43 - CFD: 09/11/2007 - 10:18:12 - [4,738] ----D C:\Arquivos de programas\Crawler O43 - CFD: 27/01/2009 - 10:09:01 - [3,493] ----D C:\Arquivos de programas\Spybot - Search & Destroy => Spybot - Search & Destroy O44 - LFC:[MD5.55E96B1122D37C7CD9B371E9DA1E7C3B] - 05/06/2012 - 14:42:53 ---A- . (...) -- C:\hijackthis.log [5526] O45 - LFCP:[MD5.B6F171E7A7C9348B205BC85B5695EE17] - 04/06/2012 - 08:15:26 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-18ACD379.pf O45 - LFCP:[MD5.1336D3A134B0941124DA4B14060E9584] - 04/06/2012 - 08:15:27 ---A- - C:\WINDOWS\Prefetch\JUSCHED.EXE-153A82FA.pf O45 - LFCP:[MD5.AB7EB3E750631E20F94802D217BD5133] - 04/06/2012 - 08:15:27 ---A- - C:\WINDOWS\Prefetch\READER_SL.EXE-074FC50A.pf O45 - LFCP:[MD5.A9C93D24F033BCA67F9F8AB1F7E04547] - 04/06/2012 - 09:30:15 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-12E27DD0.pf O45 - LFCP:[MD5.E5F0EAEFE28B347771ED8FDCE4F885C5] - 04/06/2012 - 12:09:47 ---A- - C:\WINDOWS\Prefetch\WMIAPSRV.EXE-1E2270A5.pf O45 - LFCP:[MD5.2A411C49D9A8A7B4517D9C0829CA5938] - 04/06/2012 - 12:09:47 ---A- - C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf O45 - LFCP:[MD5.D5923CF0CDC468C4348F4DFACE9FC3BF] - 04/06/2012 - 12:23:44 ---A- - C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf O45 - LFCP:[MD5.B7D7E779C99552BF8D90DE7B51540732] - 04/06/2012 - 14:23:00 ---A- - C:\WINDOWS\Prefetch\MBAM-SETUP-1.61.0.1400[1].TMP-1585CB5A.pf O45 - LFCP:[MD5.F8D424638599FE934F977C7F49C56652] - 04/06/2012 - 14:23:02 ---A- - C:\WINDOWS\Prefetch\MBAM-SETUP-1.61.0.1400[1].EXE-01804FF1.pf O45 - LFCP:[MD5.F20A608B20B6F64EF5CDFE32D5354008] - 04/06/2012 - 17:45:06 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf O45 - LFCP:[MD5.853A8A7C3C54C48956EA70DB40FDB25F] - 04/06/2012 - 17:50:22 ---A- - C:\WINDOWS\Prefetch\MBAMGUI.EXE-22501228.pf O45 - LFCP:[MD5.AD59D31CA39542B2E4AC862EF2DA8A2E] - 04/06/2012 - 17:50:23 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-4CC34A26.pf O45 - LFCP:[MD5.571CEDEC2D6894E5DE741C985F8E84D3] - 05/06/2012 - 08:39:10 ---A- - C:\WINDOWS\Prefetch\NET.EXE-01A53C2F.pf O45 - LFCP:[MD5.2D47D6073483FD3C1230012825EC07C4] - 05/06/2012 - 08:43:58 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf O45 - LFCP:[MD5.698218FE05AE1F29C21A73CCAEA86A9D] - 05/06/2012 - 08:44:12 ---A- - C:\WINDOWS\Prefetch\MSCONFIG.EXE-35E4DAE9.pf O45 - LFCP:[MD5.DCA46490A4C8AA0B117BC0F89119CBFE] - 05/06/2012 - 08:44:37 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-22143848.pf O45 - LFCP:[MD5.45C9E2B0AFBEC39278D349319988BB12] - 05/06/2012 - 08:45:16 ---A- - C:\WINDOWS\Prefetch\MBAM.EXE-1FC68C0D.pf O45 - LFCP:[MD5.0ADFB6A1C4F52FE723652099978A7742] - 05/06/2012 - 08:56:06 ---A- - C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf O45 - LFCP:[MD5.8F11690784992B7C0AA829D93964A21C] - 05/06/2012 - 08:56:06 ---A- - C:\WINDOWS\Prefetch\UNINS000.EXE-1490805C.pf O45 - LFCP:[MD5.05F9DF9D77553EDCC8D404EAF2597FF1] - 05/06/2012 - 08:56:08 ---A- - C:\WINDOWS\Prefetch\_IU14D2N.TMP-1EF21ECF.pf O45 - LFCP:[MD5.25E96BAF34920DAD4019C3DB47A640FF] - 05/06/2012 - 14:16:36 ---A- - C:\WINDOWS\Prefetch\COMBOFIX.EXE-1C681C0F.pf O45 - LFCP:[MD5.6190B5F04AC05684740DE27ED0081FC5] - 05/06/2012 - 14:18:03 ---A- - C:\WINDOWS\Prefetch\NS2B.TMP-18463A2E.pf O45 - LFCP:[MD5.4276FB740F3D01CCBF841A20D8C61B47] - 05/06/2012 - 14:18:06 ---A- - C:\WINDOWS\Prefetch\NS2C.TMP-21855412.pf O45 - LFCP:[MD5.7C0FA77E60F295B3BF58BEE65A0B6ED6] - 05/06/2012 - 14:18:39 ---A- - C:\WINDOWS\Prefetch\NIRCMDB.EXE-0F3DC8F2.pf O45 - LFCP:[MD5.7389155004B4EC071AF003F5EE0D7166] - 05/06/2012 - 14:21:23 ---A- - C:\WINDOWS\Prefetch\NS30.TMP-29FF67D5.pf O45 - LFCP:[MD5.19DA35F91670F0CEA102526E37BBD4C8] - 05/06/2012 - 14:21:26 ---A- - C:\WINDOWS\Prefetch\CF6009.3XE-0F68A68E.pf O45 - LFCP:[MD5.9D99AACFAEB1816B6087E6CEBFAE4AA1] - 05/06/2012 - 14:21:26 ---A- - C:\WINDOWS\Prefetch\NS31.TMP-0FCC266B.pf O45 - LFCP:[MD5.BA521346287CF75A85217C3ECEDD207F] - 05/06/2012 - 14:38:31 ---A- - C:\WINDOWS\Prefetch\CF6662.3XE-0A302C9E.pf O45 - LFCP:[MD5.C2E6A41488BA3944CCBB8DF80A6F35C4] - 05/06/2012 - 14:38:53 ---A- - C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf O45 - LFCP:[MD5.F26743DD2E5191FAD422545FA7C5723D] - 05/06/2012 - 14:42:57 ---A- - C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-3863877A.pf O45 - LFCP:[MD5.D817C9097A3221801011D0B4B8C75F67] - 05/06/2012 - 14:50:33 ---A- - C:\WINDOWS\Prefetch\SWAP.EXE-3B3C2F3B.pf O45 - LFCP:[MD5.2BEDBD2061E8D0CA36755A9DD3F606E5] - 05/06/2012 - 15:05:52 ---A- - C:\WINDOWS\Prefetch\ACRORD32INFO.EXE-27B701E7.pf O45 - LFCP:[MD5.1E5CA6B4EECF14D04C71BC7FD1326D76] - 05/06/2012 - 16:13:29 ---A- - C:\WINDOWS\Prefetch\FUNPEC.EXE-0C5E44B0.pf O45 - LFCP:[MD5.969B277174D66C79EFE236447496FE05] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-12915967.pf O45 - LFCP:[MD5.0CBCDA5ED9BA4213BCF3BAF3AE15D3EA] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\NS53.TMP-02D7F8F6.pf O45 - LFCP:[MD5.B0E20734C5554F0D73CE2E33F6930128] - 05/06/2012 - 17:28:00 ---A- - C:\WINDOWS\Prefetch\PEV.3XE-358EBDB6.pf O45 - LFCP:[MD5.682A1E3F0669C83FCF57FD9B01E0C5FA] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\GSAR.3XE-1971B17C.pf O45 - LFCP:[MD5.7993F47E310A224CE35BA12FA1911461] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-0A31FE70.pf O45 - LFCP:[MD5.FE6423724610F2873A86E827F4D7FF19] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\NS54.TMP-108C1AB5.pf O45 - LFCP:[MD5.A05C6F8327222BB7D0A0C4E022FDC4D6] - 05/06/2012 - 17:28:01 ---A- - C:\WINDOWS\Prefetch\NS55.TMP-293F738B.pf O45 - LFCP:[MD5.59F98C7E760453F6A3D183BAD0352C9E] - 05/06/2012 - 17:28:02 ---A- - C:\WINDOWS\Prefetch\NS56.TMP-25BF6A27.pf O45 - LFCP:[MD5.145660E16F9A82B1F2D8470F096B9DB9] - 05/06/2012 - 17:28:02 ---A- - C:\WINDOWS\Prefetch\SWREG.3XE-20CC4D60.pf O45 - LFCP:[MD5.2AC4C35545678208CE140DADF56F4C6A] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS57.TMP-140C2419.pf O45 - LFCP:[MD5.1397A96C864ED534BCB95EFDFACB795D] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS58.TMP-3AF2B999.pf O45 - LFCP:[MD5.67C33ADD6DC1C123C00901E181B2E7F1] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS59.TMP-3A739EAE.pf O45 - LFCP:[MD5.4D8DD298DA69962CC0C17A21EBBF0AEE] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS5A.TMP-1A599F1A.pf O45 - LFCP:[MD5.95AE7178FCD4394C66A2DBD80C0B1822] - 05/06/2012 - 17:28:03 ---A- - C:\WINDOWS\Prefetch\NS5B.TMP-1F71EF26.pf O45 - LFCP:[MD5.326B3B74D5A47436415D03DB12A71B8D] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\60329_COMBOFIX_123123.EXE-2BAE328A.pf O45 - LFCP:[MD5.CAB3B98571335887E9E1167ADFE1B337] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\GREP.3XE-0FD7DFD4.pf O45 - LFCP:[MD5.D94F54F64D43392FB2D2DD17DEBFEC90] - 05/06/2012 - 17:28:04 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-12BBAE74.pf O45 - LFCP:[MD5.4FD52F5105EBE3C99B77671AC85169E9] - 05/06/2012 - 17:28:05 ---A- - C:\WINDOWS\Prefetch\NIRCMD.3XE-117BB35D.pf O45 - LFCP:[MD5.33018D398E97A3C19B1DE1B2A59EF28E] - 05/06/2012 - 17:28:07 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.EXE-1C26180C.pf O45 - LFCP:[MD5.CF9D77FFC0CED14837B419096FB5B6D2] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\RMBR.3XE-3AAE61A2.pf O45 - LFCP:[MD5.0AC47C976C61F026D1DE1CA4261B5AEF] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\SED.3XE-370DAEC3.pf O45 - LFCP:[MD5.C6CBB2D3CA13585948025CB0E3866FFF] - 05/06/2012 - 17:28:08 ---A- - C:\WINDOWS\Prefetch\SWSC.3XE-3AE13307.pf O45 - LFCP:[MD5.50A96B94C7550ACF10BD587A36E2A206] - 05/06/2012 - 17:28:09 ---A- - C:\WINDOWS\Prefetch\HANDLE.3XE-10DA2EFC.pf O45 - LFCP:[MD5.3D63A6FE23A2E4C2154A8F4AF46193A1] - 05/06/2012 - 17:28:09 ---A- - C:\WINDOWS\Prefetch\SWXCACLS.3XE-392ED218.pf O45 - LFCP:[MD5.F9D00EB50264B5369FB704E14A48C44A] - 05/06/2012 - 17:28:11 ---A- - C:\WINDOWS\Prefetch\ATTRIB.3XE-09E9D153.pf O45 - LFCP:[MD5.7422026E4FCC057998CE819CF27C3B5E] - 05/06/2012 - 17:28:14 ---A- - C:\WINDOWS\Prefetch\CMD.3XE-32EEC145.pf O45 - LFCP:[MD5.C16927A12C4F54B2085F1F301B4C3FB1] - 05/06/2012 - 17:28:15 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.3XE-1AD11928.pf O45 - LFCP:[MD5.C52FB72AEEBF1C76DDB3A36F0D40D4A7] - 05/06/2012 - 17:28:17 ---A- - C:\WINDOWS\Prefetch\HIDEC.3XE-111262DC.pf O45 - LFCP:[MD5.49F301EEFEDAE54DA9DB853D524DAA2A] - 05/06/2012 - 17:28:18 ---A- - C:\WINDOWS\Prefetch\ATTRIB.EXE-39EAFB02.pf O45 - LFCP:[MD5.471B8B382CF08B0A01124EE10D1EDB5C] - 05/06/2012 - 17:28:18 ---A- - C:\WINDOWS\Prefetch\HIDEC.3XE-3AF2FBA6.pf O45 - LFCP:[MD5.0E68B49B98F8EA1A2B9FB1DA103339CE] - 05/06/2012 - 17:28:21 ---A- - C:\WINDOWS\Prefetch\PING.EXE-31216D26.pf O45 - LFCP:[MD5.733CBC15FE4D0210C81F5816C1E9CEDC] - 05/06/2012 - 17:28:21 ---A- - C:\WINDOWS\Prefetch\PV.3XE-287F2865.pf O45 - LFCP:[MD5.66B1DF36E6553F0270A1C08A47DAC475] - 05/06/2012 - 17:28:22 ---A- - C:\WINDOWS\Prefetch\PING.3XE-0C1ADF15.pf O45 - LFCP:[MD5.BEAFCCCD8453F019C3DCF6BAB1562D83] - 05/06/2012 - 17:28:27 ---A- - C:\WINDOWS\Prefetch\COMBOFIX-DOWNLOAD.3XE-1CD0C4A7.pf O45 - LFCP:[MD5.2422B104067C7FFA53703FB46E167575] - 05/06/2012 - 17:28:29 ---A- - C:\WINDOWS\Prefetch\SWSC.3XE-0165B0CE.pf O45 - LFCP:[MD5.33704A99B501B9FFA60D7E9E3D3BE493] - 05/06/2012 - 17:28:32 ---A- - C:\WINDOWS\Prefetch\FINDSTR.EXE-0CA6274B.pf O45 - LFCP:[MD5.B741F0E934A26F126FE9F5E4E38BF473] - 05/06/2012 - 17:28:33 ---A- - C:\WINDOWS\Prefetch\ATTRIB.3XE-09A7F4FD.pf O45 - LFCP:[MD5.B24D6138E7755B27122FF8F573FFCFEA] - 05/06/2012 - 17:28:33 ---A- - C:\WINDOWS\Prefetch\GSAR.3XE-2009D0BD.pf O45 - LFCP:[MD5.9888348F215FF9FD2FA024ECF567162C] - 05/06/2012 - 17:28:35 ---A- - C:\WINDOWS\Prefetch\PEV.EXE-31673B84.pf O45 - LFCP:[MD5.0159BAD54D02CA1890B8A8C8360E3CED] - 05/06/2012 - 17:28:37 ---A- - C:\WINDOWS\Prefetch\SWSC.EXE-17AFBFBF.pf O45 - LFCP:[MD5.492E2CB145884EB95250449DA9126F9D] - 05/06/2012 - 17:28:38 ---A- - C:\WINDOWS\Prefetch\SWREG.EXE-0F8682E2.pf O45 - LFCP:[MD5.2CCB7AC41BDDBF1BDE976875FB7288DA] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\CSCRIPT.3XE-08A9718B.pf O45 - LFCP:[MD5.6B8B8E0AF70C66FEB33207F22BE2FBEC] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\NIRKMD.3XE-1008F703.pf O45 - LFCP:[MD5.66E8AD2DC6B268288DE15C37E6AC5A5D] - 05/06/2012 - 17:28:43 ---A- - C:\WINDOWS\Prefetch\SED.EXE-0F4B402F.pf O45 - LFCP:[MD5.E3C25F0F857743FF91FEFE76F53A83F5] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\CF10459.3XE-01033214.pf O45 - LFCP:[MD5.58D4C3B41976C14A8DE45C444E81B116] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\ERUNT.3XE-1F6EF454.pf O45 - LFCP:[MD5.EA4B09EE2B96DEB81FABB9957E6F41D8] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\GREP.EXE-3309531C.pf O45 - LFCP:[MD5.D6AD7C1C89751E5FB13FBF8EA0957B9B] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\NIRCMD.3XE-2822283E.pf O45 - LFCP:[MD5.9D13AC43EE30016E4FA0B0AAE7E14EE8] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\NIRCMDC.3XE-1F054C5B.pf O45 - LFCP:[MD5.9196E4C01FB3810FD179AA03B8C3D412] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\PEV.3XE-2D5F2597.pf O45 - LFCP:[MD5.166A0B3DB366195F5B462B884291A49B] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\PEV.EXE-0CE2BF4A.pf O45 - LFCP:[MD5.9EDCCF4424F25827C3ED3070E50C27A9] - 05/06/2012 - 17:40:05 ---A- - C:\WINDOWS\Prefetch\SORT.EXE-194AE83C.pf O45 - LFCP:[MD5.96E9F40F6956FC302EFC94A2FFA5F739] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\CHCP.COM-18156052.pf O45 - LFCP:[MD5.D63FB2D330D8BD4E922E696194988EDA] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\GREP.3XE-03DC3FDE.pf O45 - LFCP:[MD5.39DC55CD3C9588BDF60699AE9DB1215A] - 05/06/2012 - 17:40:06 ---A- - C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf O45 - LFCP:[MD5.2E1EB2117C0F6E8E30FC4B11B423A216] - 05/06/2012 - 17:40:07 ---A- - C:\WINDOWS\Prefetch\SWREG.3XE-09144B6A.pf O45 - LFCP:[MD5.F3452435CAA09F00A5EE9BC696FEA671] - 05/06/2012 - 17:40:07 ---A- - C:\WINDOWS\Prefetch\SWXCACLS.3XE-015A5BFF.pf O45 - LFCP:[MD5.AB3A51D266EBF2EE9B2B8E610B3FB7BF] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\HANDLE.3XE-28C3AC9F.pf O45 - LFCP:[MD5.BBB51B5037BF5EDB2841F2A1275966AC] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\NIRCMD.EXE-2C39EF53.pf O45 - LFCP:[MD5.0DF31B9E28A7DB9F143D2A2B73122BFD] - 05/06/2012 - 17:40:08 ---A- - C:\WINDOWS\Prefetch\SED.3XE-03A27CDB.pf O45 - LFCP:[MD5.D6518CEB8FD386A2E8DA9028604CE0E9] - 05/06/2012 - 17:46:34 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-21D9F19C.pf O45 - LFCP:[MD5.EFAAC3A063201B150DA2A05A5F77EE61] - 05/06/2012 - 17:46:44 ---A- - C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf O45 - LFCP:[MD5.E394F3D493F4EBE30B52892711FEC13C] - 06/06/2012 - 07:50:21 ---A- - C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf O45 - LFCP:[MD5.B4CC37C40A8C5B2C6B28F85FC8CBDF89] - 06/06/2012 - 07:51:37 ---A- - C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf O45 - LFCP:[MD5.47CB93376DE5DB1CD59478B0964E8B3C] - 06/06/2012 - 08:12:51 ---A- - C:\WINDOWS\Prefetch\THUNDERBIRD.EXE-2C374BBE.pf O45 - LFCP:[MD5.A5364A9B47D4461899CD531DF95F9254] - 06/06/2012 - 08:12:55 ---A- - C:\WINDOWS\Prefetch\THUNDERBIRDPORTABLE.EXE-01EC7AB1.pf O45 - LFCP:[MD5.5BFD93C094C36E0468235DAC048A8014] - 06/06/2012 - 08:17:47 ---A- - C:\WINDOWS\Prefetch\HELPER.EXE-3A31BCA1.pf O45 - LFCP:[MD5.FF91E49A2A8D9EA4AE3C6FF39D494E1E] - 06/06/2012 - 08:25:06 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-38C1AF32.pf O45 - LFCP:[MD5.840E8E42CA53F6F9DEEE0A2D2FAC00E9] - 06/06/2012 - 08:25:07 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf O45 - LFCP:[MD5.5AABEA62D8A724557A364B00EC989FB2] - 06/06/2012 - 08:35:47 ---A- - C:\WINDOWS\Prefetch\RUNDLL32.EXE-43D2B9C5.pf O45 - LFCP:[MD5.43349A0954EF555F7C89BDE380D6E29B] - 06/06/2012 - 10:13:45 ---A- - C:\WINDOWS\Prefetch\EXCEL.EXE-3283F464.pf O45 - LFCP:[MD5.5069F0C8955ED6EF74B5C5589333A2A8] - 06/06/2012 - 10:15:19 ---A- - C:\WINDOWS\Prefetch\ACRORD32.EXE-3AE6FA75.pf O45 - LFCP:[MD5.FE4945D4727BC61591BF573F4791AE80] - 06/06/2012 - 10:16:44 ---A- - C:\WINDOWS\Prefetch\ADOBEUPDATER.EXE-19E95BBA.pf O45 - LFCP:[MD5.C4A8B323A50A5333AB2813DCCE9A9C6B] - 06/06/2012 - 11:18:05 ---A- - C:\WINDOWS\Prefetch\DOAP.EXE-3A87DF2F.pf O45 - LFCP:[MD5.BFC1BB094AF7B1C87E7A04B9CEF4330B] - 06/06/2012 - 11:37:56 ---A- - C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf O45 - LFCP:[MD5.3C606F1FBD1FE9309D7EE8431FD3C44F] - 06/06/2012 - 12:12:09 ---A- - C:\WINDOWS\Prefetch\AVAST.SETUP-13B2B59D.pf O45 - LFCP:[MD5.8BBEADC7DE3957787345B19D5A83D89A] - 06/06/2012 - 14:05:01 ---A- - C:\WINDOWS\Prefetch\GOOGLECRASHHANDLER.EXE-062CDC47.pf O45 - LFCP:[MD5.28E9000D0DAEC07DA1A3658642DF0213] - 06/06/2012 - 14:05:01 ---A- - C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-19D08292.pf O45 - LFCP:[MD5.9A97C9FCBF491481A24EADF5D5A6E04B] - 06/06/2012 - 14:28:19 ---A- - C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf O45 - LFCP:[MD5.6BDD538485EEF0916E655EAC6065B243] - 06/06/2012 - 14:28:19 ---A- - C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf O45 - LFCP:[MD5.A949ED7403404E59C476A9663BA29C3C] - 06/06/2012 - 14:31:43 ---A- - C:\WINDOWS\Prefetch\PLUGIN-CONTAINER.EXE-012592DA.pf O45 - LFCP:[MD5.AFC7FE221A2D4DB0DF391C14FB3ECDD4] - 06/06/2012 - 14:37:01 ---A- - C:\WINDOWS\Prefetch\IEXPLORE.EXE-2B53DE18.pf O45 - LFCP:[MD5.E45AFB8FE6088A3462343DEE188CA2F7] - 06/06/2012 - 14:41:47 ---A- - C:\WINDOWS\Prefetch\MSPAINT.EXE-11CBB631.pf O45 - LFCP:[MD5.E2F3AE73A1FC014AA8199CA292E5854C] - 06/06/2012 - 14:47:45 ---A- - C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf O45 - LFCP:[MD5.BE850CBD7179072FDB61CFE1728476B8] - 06/06/2012 - 14:48:56 ---A- - C:\WINDOWS\Prefetch\AVASTUI.EXE-373CBE37.pf O45 - LFCP:[MD5.C58A179B71AB23675AB175645507C9C3] - 06/06/2012 - 14:49:21 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.TMP-079FABD8.pf O45 - LFCP:[MD5.2EC9A5BB76CD88F189CE373D5D5A80EA] - 06/06/2012 - 14:49:22 ---A- - C:\WINDOWS\Prefetch\ZHPDIAG2.EXE-2DC55403.pf O45 - LFCP:[MD5.69C8B7AAF401526CBE5311040A6C4584] - 06/06/2012 - 14:51:05 ---A- - C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.) O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.) O53 - SMSR:HKLM\...\startupreg\Adobe Reader Speed Launcher [Key] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe [HKLM\Software\CToolbar] [HKCU\Software\CToolbar] proxyfix emptytemp emptyflash firewallraz sysrestore |- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C" |- Minimize o Bloco de Notas. |- Clique no menu,"Paste ClipBoard". |- Clique em "GO" -> Oui. |- Ps: Temos,àcima,sequência de imagens para maior exclarecimento. |- Poste o relatório: C:\ZHP\ZHPFix[R1].txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 8, 2012 Rapport de ZHPFix 1.2.06 par Nicolas Coolman, Update du 17/05/2012 Fichier d'export Registre : Run by f003204 at 08/06/2012 08:36:27 Windows XP Professional Service Pack 3 (Build 2600) Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html Web site : http://nicolascoolman.skyrock.com/ ========== Software ========== DELETED J2SE Runtime Environment 5.0 Update 6 ========== Registry Key ========== DELETED [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}] DELETED O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.) DELETED O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ati4waxx.sys . (...) -- C:\WINDOWS\system32\Drivers\ati4waxx.sys (.not file.) DELETED Key*: StartupReg: Adobe Reader Speed Launcher DELETED Key: HKLM\Software\CToolbar NOT FOUND Key: HKCU\Software\CToolbar ========== Registry Value ========== ProxyFix : Proxy killed successfully DELETED ProxyServer Value DELETED ProxyEnable Value DELETED EnableHttp1_1 Value DELETED ProxyHttp1.1 Value DELETED ProxyOverride Value DELETED FirewallRaz (SP) : %windir%\system32\sessmgr.exe DELETED FirewallRaz (SP) : %windir%\Network Diagnostic\xpnetdiag.exe DELETED FirewallRaz (DP) : %windir%\system32\sessmgr.exe DELETED FirewallRaz (DP) : C:\Arquivos de programas\MSN Messenger\livecall.exe DELETED FirewallRaz (DP) : %windir%\Network Diagnostic\xpnetdiag.exe No Value in Firewall Exception Register Key (FirewallRaz) ========== Repertory ========== DELETED Folder: C:\Documents and Settings\All Users.WINDOWS\Favoritos DELETED Folder: C:\Arquivos de programas\Crawler DELETED Folder: C:\Arquivos de programas\Spybot - Search & Destroy DELETED Window Temporary: DELETED Flash Cookies: ========== File ========== NOT FOUND File: c:\hijackthis.log DELETED File: c:\windows\prefetch\rundll32.exe-18acd379.pf DELETED File: c:\windows\prefetch\jusched.exe-153a82fa.pf DELETED File: c:\windows\prefetch\reader_sl.exe-074fc50a.pf DELETED File: c:\windows\prefetch\rundll32.exe-12e27dd0.pf DELETED File: c:\windows\prefetch\wmiapsrv.exe-1e2270a5.pf DELETED File: c:\windows\prefetch\wuauclt.exe-399a8e72.pf DELETED File: c:\windows\prefetch\dfrgntfs.exe-269967df.pf DELETED File: c:\windows\prefetch\mbam-setup-1.61.0.1400[1].tmp-1585cb5a.pf DELETED File: c:\windows\prefetch\mbam-setup-1.61.0.1400[1].exe-01804ff1.pf DELETED File: c:\windows\prefetch\notepad.exe-189578da.pf DELETED File: c:\windows\prefetch\mbamgui.exe-22501228.pf DELETED File: c:\windows\prefetch\rundll32.exe-4cc34a26.pf DELETED File: c:\windows\prefetch\net.exe-01a53c2f.pf DELETED File: c:\windows\prefetch\rundll32.exe-268bff96.pf DELETED File: c:\windows\prefetch\msconfig.exe-35e4dae9.pf DELETED File: c:\windows\prefetch\rundll32.exe-22143848.pf DELETED File: c:\windows\prefetch\mbam.exe-1fc68c0d.pf DELETED File: c:\windows\prefetch\regsvr32.exe-25eefe2f.pf DELETED File: c:\windows\prefetch\unins000.exe-1490805c.pf DELETED File: c:\windows\prefetch\_iu14d2n.tmp-1ef21ecf.pf DELETED File: c:\windows\prefetch\combofix.exe-1c681c0f.pf DELETED File: c:\windows\prefetch\ns2b.tmp-18463a2e.pf DELETED File: c:\windows\prefetch\ns2c.tmp-21855412.pf DELETED File: c:\windows\prefetch\nircmdb.exe-0f3dc8f2.pf DELETED File: c:\windows\prefetch\ns30.tmp-29ff67d5.pf DELETED File: c:\windows\prefetch\cf6009.3xe-0f68a68e.pf DELETED File: c:\windows\prefetch\ns31.tmp-0fcc266b.pf DELETED File: c:\windows\prefetch\cf6662.3xe-0a302c9e.pf DELETED File: c:\windows\prefetch\imapi.exe-0bf740a4.pf DELETED File: c:\windows\prefetch\hijackthis.exe-3863877a.pf DELETED File: c:\windows\prefetch\swap.exe-3b3c2f3b.pf DELETED File: c:\windows\prefetch\acrord32info.exe-27b701e7.pf DELETED File: c:\windows\prefetch\funpec.exe-0c5e44b0.pf DELETED File: c:\windows\prefetch\iexplore.exe-12915967.pf DELETED File: c:\windows\prefetch\ns53.tmp-02d7f8f6.pf DELETED File: c:\windows\prefetch\pev.3xe-358ebdb6.pf DELETED File: c:\windows\prefetch\gsar.3xe-1971b17c.pf DELETED File: c:\windows\prefetch\iexplore.exe-0a31fe70.pf DELETED File: c:\windows\prefetch\ns54.tmp-108c1ab5.pf DELETED File: c:\windows\prefetch\ns55.tmp-293f738b.pf DELETED File: c:\windows\prefetch\ns56.tmp-25bf6a27.pf DELETED File: c:\windows\prefetch\swreg.3xe-20cc4d60.pf DELETED File: c:\windows\prefetch\ns57.tmp-140c2419.pf DELETED File: c:\windows\prefetch\ns58.tmp-3af2b999.pf DELETED File: c:\windows\prefetch\ns59.tmp-3a739eae.pf DELETED File: c:\windows\prefetch\ns5a.tmp-1a599f1a.pf DELETED File: c:\windows\prefetch\ns5b.tmp-1f71ef26.pf DELETED File: c:\windows\prefetch\60329_combofix_123123.exe-2bae328a.pf DELETED File: c:\windows\prefetch\grep.3xe-0fd7dfd4.pf DELETED File: c:\windows\prefetch\iexplore.exe-12bbae74.pf DELETED File: c:\windows\prefetch\nircmd.3xe-117bb35d.pf DELETED File: c:\windows\prefetch\cscript.exe-1c26180c.pf DELETED File: c:\windows\prefetch\rmbr.3xe-3aae61a2.pf DELETED File: c:\windows\prefetch\sed.3xe-370daec3.pf DELETED File: c:\windows\prefetch\swsc.3xe-3ae13307.pf DELETED File: c:\windows\prefetch\handle.3xe-10da2efc.pf DELETED File: c:\windows\prefetch\swxcacls.3xe-392ed218.pf DELETED File: c:\windows\prefetch\attrib.3xe-09e9d153.pf DELETED File: c:\windows\prefetch\cmd.3xe-32eec145.pf DELETED File: c:\windows\prefetch\cscript.3xe-1ad11928.pf DELETED File: c:\windows\prefetch\hidec.3xe-111262dc.pf DELETED File: c:\windows\prefetch\attrib.exe-39eafb02.pf DELETED File: c:\windows\prefetch\hidec.3xe-3af2fba6.pf DELETED File: c:\windows\prefetch\ping.exe-31216d26.pf DELETED File: c:\windows\prefetch\pv.3xe-287f2865.pf DELETED File: c:\windows\prefetch\ping.3xe-0c1adf15.pf DELETED File: c:\windows\prefetch\combofix-download.3xe-1cd0c4a7.pf DELETED File: c:\windows\prefetch\swsc.3xe-0165b0ce.pf DELETED File: c:\windows\prefetch\findstr.exe-0ca6274b.pf DELETED File: c:\windows\prefetch\attrib.3xe-09a7f4fd.pf DELETED File: c:\windows\prefetch\gsar.3xe-2009d0bd.pf DELETED File: c:\windows\prefetch\pev.exe-31673b84.pf DELETED File: c:\windows\prefetch\swsc.exe-17afbfbf.pf DELETED File: c:\windows\prefetch\swreg.exe-0f8682e2.pf DELETED File: c:\windows\prefetch\cscript.3xe-08a9718b.pf DELETED File: c:\windows\prefetch\nirkmd.3xe-1008f703.pf DELETED File: c:\windows\prefetch\sed.exe-0f4b402f.pf DELETED File: c:\windows\prefetch\cf10459.3xe-01033214.pf DELETED File: c:\windows\prefetch\erunt.3xe-1f6ef454.pf DELETED File: c:\windows\prefetch\grep.exe-3309531c.pf DELETED File: c:\windows\prefetch\nircmd.3xe-2822283e.pf DELETED File: c:\windows\prefetch\nircmdc.3xe-1f054c5b.pf DELETED File: c:\windows\prefetch\pev.3xe-2d5f2597.pf DELETED File: c:\windows\prefetch\pev.exe-0ce2bf4a.pf DELETED File: c:\windows\prefetch\sort.exe-194ae83c.pf DELETED File: c:\windows\prefetch\chcp.com-18156052.pf DELETED File: c:\windows\prefetch\grep.3xe-03dc3fde.pf DELETED File: c:\windows\prefetch\regedit.exe-1b606482.pf DELETED File: c:\windows\prefetch\swreg.3xe-09144b6a.pf DELETED File: c:\windows\prefetch\swxcacls.3xe-015a5bff.pf DELETED File: c:\windows\prefetch\handle.3xe-28c3ac9f.pf DELETED File: c:\windows\prefetch\nircmd.exe-2c39ef53.pf DELETED File: c:\windows\prefetch\sed.3xe-03a27cdb.pf DELETED File: c:\windows\prefetch\rundll32.exe-21d9f19c.pf DELETED File: c:\windows\prefetch\notepad.exe-336351a9.pf DELETED File: c:\windows\prefetch\alg.exe-0f138680.pf DELETED File: c:\windows\prefetch\ctfmon.exe-0e17969b.pf DELETED File: c:\windows\prefetch\thunderbird.exe-2c374bbe.pf DELETED File: c:\windows\prefetch\thunderbirdportable.exe-01ec7ab1.pf DELETED File: c:\windows\prefetch\helper.exe-3a31bca1.pf DELETED File: c:\windows\prefetch\rundll32.exe-38c1af32.pf DELETED File: c:\windows\prefetch\rundll32.exe-451fc2c0.pf DELETED File: c:\windows\prefetch\rundll32.exe-43d2b9c5.pf DELETED File: c:\windows\prefetch\excel.exe-3283f464.pf DELETED File: c:\windows\prefetch\acrord32.exe-3ae6fa75.pf DELETED File: c:\windows\prefetch\adobeupdater.exe-19e95bba.pf DELETED File: c:\windows\prefetch\doap.exe-3a87df2f.pf DELETED File: c:\windows\prefetch\helpsvc.exe-2878dda2.pf DELETED File: c:\windows\prefetch\avast.setup-13b2b59d.pf DELETED File: c:\windows\prefetch\googlecrashhandler.exe-062cdc47.pf DELETED File: c:\windows\prefetch\googleupdate.exe-19d08292.pf DELETED File: c:\windows\prefetch\ntosboot-b00dfaad.pf DELETED File: c:\windows\prefetch\userinit.exe-30b18140.pf DELETED File: c:\windows\prefetch\plugin-container.exe-012592da.pf DELETED File: c:\windows\prefetch\iexplore.exe-2b53de18.pf DELETED File: c:\windows\prefetch\mspaint.exe-11cbb631.pf DELETED File: c:\windows\prefetch\verclsid.exe-3667bd89.pf DELETED File: c:\windows\prefetch\avastui.exe-373cbe37.pf DELETED File: c:\windows\prefetch\zhpdiag2.tmp-079fabd8.pf DELETED File: c:\windows\prefetch\zhpdiag2.exe-2dc55403.pf DELETED File: c:\windows\prefetch\cmd.exe-087b4001.pf NOT FOUND File: c:\windows\system32\drivers\ati4waxx.sys DELETED File: c:\arquivos de programas\adobe\reader 8.0\reader\reader_sl.exe DELETED Window Temporary: DELETED Flash Cookies: ========== Restoration ========== Restore System Point not created ========== Summary ========== 6 : Registry Key 12 : Registry Value 5 : Repertory 126 : File 1 : Software 1 : Restoration End of clean in 00mn 40s ========== Report File ========== C:\ZHP\ZHPFix[R1].txt - 08/06/2012 08:36:27 [9460] Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 8, 2012 Bom Tarde! Edvan |- Atualize o Malwarebytes e execute novo escaneamento. |- Ps: Pode ser o rápido! -> Poste o relatório! -/- |- Baixe: < > ( ... by OldTimer Tools ) |- Clique em Salvar! < > |- Salve-o no desktop! < > |- Duplo clique em OTL.exe -> Executar: |- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida ) |- Ps: Para Windows 7,clique direito e execute-o como "Administrador". |- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log ) |- Dispense o relatório "Extras". Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 12, 2012 Desculpe a demora amigo. Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Versão da Base de Dados: v2012.06.12.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 f003204 :: FUN0044 [administrador] 12/06/2012 10:17:19 mbam-log-2012-06-12 (10-17-19).txt Tipo de Verificação: Verificação Rápida Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM Opções de verificação desativadas: P2P Objetos escaneados: 305018 Tempo decorrido: 43 minuto(s), 13 segundo(s) Processos de Memória Detectados: 0 (Não foram detectados ítens maliciosos) Módulos de Memória Detectados: 0 (Não foram detectados ítens maliciosos) Chaves de Registro Detectadas: 0 (Não foram detectados ítens maliciosos) Valores de Registro Detectadas: 0 (Não foram detectados ítens maliciosos) Itens de Dados no Registro Detectadas: 0 (Não foram detectados ítens maliciosos) Pastas Detectadas: 0 (Não foram detectados ítens maliciosos) Arquivos Detectados: 0 (Não foram detectados ítens maliciosos) (fim) OTL logfile created on: 12/06/2012 11:09:04 - Run 1 OTL by OldTimer - Version 3.2.48.0 Folder = C:\Documents and Settings\f003204\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy 991,48 Mb Total Physical Memory | 573,13 Mb Available Physical Memory | 57,80% Memory free 2,33 Gb Paging File | 2,05 Gb Available in Paging File | 87,95% Paging File free Paging file location(s): C:\pagefile.sys 0 0 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas Drive C: | 18,65 Gb Total Space | 5,77 Gb Free Space | 30,95% Space Free | Partition Type: NTFS Drive D: | 18,65 Gb Total Space | 18,53 Gb Free Space | 99,40% Space Free | Partition Type: NTFS Drive F: | 3,73 Gb Total Space | 3,31 Gb Free Space | 88,69% Space Free | Partition Type: FAT32 Drive P: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS Drive S: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS Drive X: | 204,24 Gb Total Space | 17,94 Gb Free Space | 8,78% Space Free | Partition Type: NTFS Computer Name: FUN0044 | User Name: f003204 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/06/12 11:07:53 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe PRC - [2012/05/09 09:02:12 | 000,214,088 | ---- | M] ( ) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe PRC - [2012/03/06 21:15:17 | 004,241,512 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe PRC - [2012/03/06 21:15:14 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe PRC - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () -- C:\WINDOWS\system32\SpyPrinter.exe PRC - [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2006/10/26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe PRC - [2005/07/14 01:35:00 | 001,175,628 | ---- | M] (CANON INC.) -- C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe ========== Modules (No Company Name) ========== MOD - [2012/06/12 03:07:52 | 001,767,424 | ---- | M] () -- C:\Arquivos de programas\Alwil Software\Avast5\defs\12061200\algo.dll MOD - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () -- C:\WINDOWS\system32\SpyPrinter.exe MOD - [2001/10/28 17:42:30 | 000,116,224 | ---- | M] () -- C:\WINDOWS\system32\pdfcmnnt.dll MOD - [2001/07/31 07:17:12 | 000,094,274 | ---- | M] () -- C:\WINDOWS\system32\HPBHEALR.DLL ========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ) SRV - [2012/05/24 13:55:30 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance) SRV - [2012/05/09 09:02:12 | 000,214,088 | ---- | M] ( ) [Auto | Running] -- C:\Arquivos de programas\GbPlugin\gbpsv.exe -- (GbpSv) SRV - [2012/03/06 21:15:14 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus) SRV - [2008/05/13 15:44:12 | 001,406,464 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\SpyPrinter.exe -- (SpyPrinterD) SRV - [2006/11/06 10:21:34 | 001,527,893 | ---- | M] (The Firebird Project) [Disabled | Stopped] -- C:\Arquivos de programas\FireBird\FireBird_1_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance) SRV - [2006/11/06 10:21:33 | 000,065,536 | ---- | M] (The Firebird Project) [Disabled | Stopped] -- C:\Arquivos de programas\FireBird\FireBird_1_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance) SRV - [2006/10/26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006/10/26 13:40:34 | 000,335,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe -- (MDM) SRV - [2006/10/26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2005/07/14 01:35:00 | 001,175,628 | ---- | M] (CANON INC.) [Auto | Running] -- C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe -- (Canon Driver Information Assist Service) SRV - [2003/10/22 10:19:22 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Mrv8000c.sys -- (W8335XP) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME) DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP) DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump) DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc) DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt) DRV - File not found [Kernel | System | Stopped] -- -- (Changer) DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\f003204\CONFIG~1\Temp\catchme.sys -- (catchme) DRV - File not found [Kernel | Boot | Stopped] -- System32\Drivers\ati4waxx.sys -- (ati4waxx) DRV - [2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\GbpNdisrd.sys -- (NdisrdMP) DRV - [2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GbpNdisrd.sys -- (Ndisrd) DRV - [2012/04/05 09:34:04 | 000,046,408 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\gbpkm.sys -- (GbpKm) DRV - [2012/03/06 21:03:51 | 000,612,184 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2012/03/06 21:03:38 | 000,337,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2012/03/06 21:02:00 | 000,035,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2012/03/06 21:01:53 | 000,053,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2012/03/06 21:01:39 | 000,095,704 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2012/03/06 21:01:30 | 000,020,696 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2012/03/06 20:58:29 | 000,024,920 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2004/08/03 21:31:36 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC) DRV - [2003/12/19 09:07:50 | 000,541,548 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM) DRV - [2003/12/11 12:54:14 | 000,391,424 | ---- | M] (Sensaura Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS) DRV - [2003/12/05 08:13:42 | 000,429,440 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315) DRV - [2003/12/04 22:25:54 | 000,011,392 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp) DRV - [2003/07/17 22:58:20 | 000,036,992 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SISAGPX.SYS -- (SISAGP) DRV - [2003/03/25 06:50:46 | 000,004,096 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\siside.sys -- (SiSide) DRV - [2002/10/17 04:14:46 | 000,049,024 | R--- | M] (Windows ® 2000 DDK provider) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\sisidex.sys -- (sisidex) DRV - [2002/08/20 06:19:08 | 000,009,472 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sisperf.sys -- (sisperf) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.funpec.br/ponto_online/ IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://funpec.br/" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Arquivos de programas\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Arquivos de programas\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Arquivos de programas\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Arquivos de programas\Alwil Software\Avast5\WebRep\FF [2012/03/26 08:27:38 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2012/05/24 13:55:31 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2011/10/20 16:56:09 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Documents and Settings\f003204\Thunderbird\App\thunderbird\components [2012/06/01 07:44:40 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Documents and Settings\f003204\Thunderbird\App\thunderbird\plugins [2011/10/21 14:33:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Extensions [2010/10/22 09:00:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2012/05/24 13:56:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\extensions [2012/05/24 13:56:38 | 000,000,000 | ---D | M] (Modulo de Seguranca - Banco do Brasil) -- C:\Documents and Settings\f003204\Dados de aplicativos\Mozilla\Firefox\Profiles\yxt23its.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C} [2012/05/24 13:55:42 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de programas\Mozilla Firefox\extensions [2007/08/15 14:07:51 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Arquivos de programas\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2012/03/26 08:27:38 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\ARQUIVOS DE PROGRAMAS\ALWIL SOFTWARE\AVAST5\WEBREP\FF [2012/04/18 17:25:44 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\ARQUIVOS DE PROGRAMAS\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2012/05/24 13:55:30 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Arquivos de programas\mozilla firefox\components\browsercomps.dll [2012/04/18 17:25:42 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Arquivos de programas\mozilla firefox\plugins\npdeployJava1.dll [2012/04/10 14:10:25 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\buscape.xml [2012/04/10 14:10:25 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\mercadolivre.xml [2012/04/10 14:10:25 | 000,002,040 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\twitter.xml [2012/04/10 14:10:25 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\wikipedia-br.xml [2012/04/10 14:10:25 | 000,000,952 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml O1 HOSTS File: ([2012/06/05 14:36:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (Facilitador de Leitor de Link Adobe PDF) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites) O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites) O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites) O15 - HKCU\..Trusted Domains: bb.com.br ([www] * in Trusted sites) O15 - HKCU\..Trusted Domains: com.br ([www.bancobrasil] * in Trusted sites) O15 - HKCU\..Trusted Domains: com.br ([www.bb] * in Trusted sites) O15 - HKCU\..Trusted Domains: com.br ([www14.bancobrasil] * in Trusted sites) O15 - HKCU\..Trusted Domains: com.br ([www2.bancobrasil] * in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.4.65.16 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{476E693C-7351-4FB7-A72B-D3F4BA50A9FF}: DhcpNameServer = 10.4.65.16 O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop Components:0 (Minha página inicial atual) - About:Home O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Alegria.bmp O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Alegria.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2005/10/03 14:28:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) ========== Files/Folders - Created Within 30 Days ========== [2012/06/12 11:07:46 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe [2012/06/12 10:12:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Iniciar\Programas\Malwarebytes' Anti-Malware [2012/06/12 10:12:37 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2012/06/12 10:12:36 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware [2012/06/06 15:46:51 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2012/06/06 14:49:51 | 000,000,000 | ---D | C] -- C:\ZHP [2012/06/06 14:49:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menu Iniciar\Programas\ZHP [2012/06/06 14:49:19 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\ZHPDiag [2012/06/05 14:44:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\f003204\Desktop\Ferramenta de remoção de virus [2012/06/05 14:26:08 | 000,000,000 | RHSD | C] -- C:\cmdcons [2012/06/05 14:18:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2012/06/05 08:53:31 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\HiJackThis.exe [2012/06/04 08:33:21 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\f003204\Recent [2012/05/24 13:55:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Mozilla [2012/05/24 13:55:45 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Mozilla Maintenance Service [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2012/06/12 11:16:00 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job [2012/06/12 11:07:53 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\f003204\Desktop\OTL.exe [2012/06/12 11:05:00 | 000,001,074 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2012/06/12 10:12:47 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk [2012/06/12 09:51:51 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job [2012/06/12 08:55:37 | 000,002,485 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Microsoft Office Excel 2007.lnk [2012/06/12 07:35:30 | 000,001,070 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012/06/12 07:34:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2012/06/11 12:08:23 | 000,055,534 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Booking.com_ Confirmação.pdf [2012/06/11 08:12:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2012/06/08 08:58:53 | 000,110,485 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Câmeras Digitais e Filmadoras - Americanas.pdf [2012/06/05 14:36:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2012/06/05 14:26:13 | 000,000,327 | RHS- | M] () -- C:\boot.ini [2012/06/05 08:53:32 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\HiJackThis.exe [2012/06/04 17:44:56 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\fmhuptxw.sys [2012/06/04 14:07:37 | 000,028,880 | ---- | M] (GAS Tecnologia) -- C:\WINDOWS\System32\drivers\GbpNdisrd.sys [2012/05/30 14:27:39 | 000,002,553 | ---- | M] () -- C:\Documents and Settings\f003204\Desktop\Microsoft Office Word 2007.lnk [2012/05/18 11:48:26 | 004,515,069 | ---- | M] () -- C:\Documents and Settings\f003204\Meus documentos\CONVÊNIOS.pdf [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] ========== Files Created - No Company Name ========== [2012/06/12 10:12:47 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes Anti-Malware.lnk [2012/06/11 12:08:20 | 000,055,534 | ---- | C] () -- C:\Documents and Settings\f003204\Desktop\Booking.com_ Confirmação.pdf [2012/06/08 08:58:49 | 000,110,485 | ---- | C] () -- C:\Documents and Settings\f003204\Desktop\Câmeras Digitais e Filmadoras - Americanas.pdf [2012/06/05 14:26:09 | 000,261,856 | RHS- | C] () -- C:\cmldr [2012/06/04 17:44:55 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\fmhuptxw.sys [2012/05/18 11:48:25 | 004,515,069 | ---- | C] () -- C:\Documents and Settings\f003204\Meus documentos\CONVÊNIOS.pdf [2011/10/20 16:58:51 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2011/02/02 16:26:10 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2010/10/14 16:53:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CPC10Q.INI ========== LOP Check ========== [2010/10/22 11:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Alwil Software [2007/01/25 09:08:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Avg7 [2011/07/28 10:55:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\gas [2012/05/21 07:49:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\GbPlugin [2009/12/15 09:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\3M [2011/08/02 15:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\Auslogics [2011/04/07 17:03:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\BizAgi Ltd [2011/04/07 17:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\IsolatedStorage [2011/08/29 08:06:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\f003204\Dados de aplicativos\Thunderbird [2012/06/12 11:16:00 | 000,000,470 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{668266AB-0776-4FD7-9148-F25E864810DC}.job [2012/06/12 09:51:51 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{D95DE79C-3FA9-4A9D-AA9C-D039CBFC4D35}.job ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 8 bytes -> C:\WINDOWS\System32\drivers:IncompleteBoot.cnt < End of report > OBS: O Avast disparou quando passei o Malwarebytes no PENDRIVER dela. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 12, 2012 Boa Tarde! Edvan |- Execute o OTL.exe. |- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" ) :OTLFF - user.js - File not found O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] :Commands [CLEARALLRESTOREPOINTS] [purity] [emptytemp] [Reboot] |- Clique no botão Consertar -> Aguarde a conclusão! |- O computador vai reiniciar! -> Clique em "Executar". |- Para versões em Inglês,clique em Run Fix que é o mesmo que Consertar. |- Poste o relatório: C:\_OTL\MovedFiles\*.log -/- |- Baixe: < UsbFix > ( ...de C_XX & El Desaparecido ) |- Salve-o no desktop! |- Siga com sua instalação. |- Conecte seu pendrive ao computador! |- Execute o arquivo UsbFix.exe,com um duplo clique. |- Escolha a opção "Suppression" ou "Delete". |- Aguarde a conclusão e poste o relatório. ( C:\UsbFix.txt ) -/- |- Baixe: < > ( ... par tigzy ) |- Salve-o no desktop! |- Feche aplicativos que estejam abertos! |- Ps: Para Windows Vista ou 7,execute RogueKiller.exe como administrador. |- Aguarde a finalização de seu Pre-scan. |- Dê início ao diagnóstico,clicando no botão "Verificar". |- Exemplo: Mode: Verificar -- Date: mm/dd/2012 00:52:24 |- Poste o relatório: RKreport[1].txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 12, 2012 Boa tarde DigRam! Ao passar o < UsbFix > quando estava em 70% do scan apareceu essa tela aqui abaixo: Reiniciou o sistema só que agora nao carrega mais minha area de trabalho, nao abre de jeito nenhum, nem em modo de segurança, estou em outra maquina escrevendo, estou tentando a restauração do sistema pelo ponto de restauração que o combofix criou. Entrei com live-cd do Linux, copiei esses arquivos de partida para a maquina mesmo assim não carregou o sistema, NTDETECT.COM, AUTOEXEC.BAT e ntldr, fica na tela azul e nao carrega os ícones da área de trabalho, já tentei o CHKDSK /R /P e nada. Entrei na partição que esta o sistema e copiei o log do UsbFix. mais nao tem jeito de voltar as configurações para que ele abra normalmente. ############################## | UsbFix V 7.089 | [supressão] Usuário: f003204 (Administrador) # FUN0044 Atualizado em 09/06/2012 por El Desaparecido Começou em 14:15:26 | 12/06/2012 Site: http://eldesaparecido.com Foro: http://forum.eldesaparecido.com Arquivo suspeito ? : http://eldesaparecido.com/upload.php Contato: contact@eldesaparecido.com PC: AWARD_ (AWRDACPI) (X86-based PC) # Desktop Computer CPU: AMD Sempron 2400+ (1662) RAM -> [Total : 991 | Free : 592] BIOS: Phoenix - AwardBIOS v6.00PG BOOT: Normal boot OS: Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3 WB: Windows Internet Explorer 8.0.6001.18702 SC: Security Center Service [Enabled] WU: Windows Update Service [Enabled] FW: Windows FireWall Service [Enabled] C:\ (%systemdrive%) -> Disco fixo # 19 Gb (6 Mb livre - 32%) [] # NTFS D:\ -> Disco fixo # 19 Gb (19 Mb livre - 99%) [] # NTFS E:\ -> CD-ROM F:\ -> Disco removível # 4 Gb (3 Mb livre - 89%) [] # FAT32 ################## | Processos Ativos | C:\WINDOWS\System32\smss.exe (712) C:\WINDOWS\system32\winlogon.exe (784) C:\WINDOWS\system32\services.exe (828) C:\WINDOWS\system32\lsass.exe (840) C:\ARQUIV~1\GbPlugin\GbpSv.exe (1004) C:\WINDOWS\system32\svchost.exe (1040) C:\WINDOWS\System32\svchost.exe (1184) C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1520) C:\WINDOWS\system32\spoolsv.exe (1564) C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe (280) C:\Arquivos de programas\Java\jre6\bin\jqs.exe (480) C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe (616) C:\WINDOWS\Explorer.EXE (1348) c:\windows\system32\SpyPrinter.exe (576) C:\WINDOWS\system32\svchost.exe (744) C:\WINDOWS\system32\ctfmon.exe (2860) C:\Arquivos de programas\Internet Explorer\iexplore.exe (2088) C:\Arquivos de programas\Internet Explorer\iexplore.exe (2384) C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe (1516) C:\UsbFix\Go.exe (2704) ################## | Processos parados | Parado! C:\ARQUIV~1\GbPlugin\GbpSv.exe (1004) Parado! C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1520) Parado! C:\WINDOWS\system32\spoolsv.exe (1564) Parado! C:\Arquivos de programas\Canon\DIAS\CnxDIAS.exe (280) Parado! C:\Arquivos de programas\Java\jre6\bin\jqs.exe (480) Parado! C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe (616) Parado! C:\WINDOWS\Explorer.EXE (1348) Parado! c:\windows\system32\SpyPrinter.exe (576) Parado! C:\WINDOWS\system32\ctfmon.exe (2860) Parado! C:\Arquivos de programas\Internet Explorer\iexplore.exe (2088) Parado! C:\Arquivos de programas\Internet Explorer\iexplore.exe (2384) Parado! C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe (1516) ################## | Ficheiros # pastas infeciosos | Supprimido ! C:\WINDOWS\system32\services.exe Supprimido ! C:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21318 Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21098 Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21262 Supprimido ! D:\Recycler\S-1-5-21-2586132527-314635491-3328972525-21318 Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1003 Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1004 Supprimido ! D:\Recycler\S-1-5-21-515967899-879983540-725345543-1007 Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-1004 Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-1008 Supprimido ! D:\Recycler\S-1-5-21-602162358-1326574676-725345543-500 Supprimido ! C:\khs (!) Ficheiros temporários suprimido. ################## | Registro | Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 12, 2012 Boa Noite! Edvan |- Muito extranho o ocorrido,pois ao passar o UsbFix na máquina do meu sobrinho,em modo diagnóstico,estava incluído o services.exe para remoção. Abortei o modo Suppression,pois desconfiei dessa indicação da ferramenta. Devido a esse fato,está suspenso,até segunda ordem,a execução dessa ferramenta em seu modo Delete ou Fix,caso seja encontrado o arquivo services.exe no relatório. -/- |- Amigo Edvan,utilize o CD do Windows XP e faça o devido reparo. |- Entre na Bios e configure como 1° Boot a unidade de CD-ROM. Procure salvar essa escolha e reinicie o computador com o CD do Windows na unidade. Siga as indicações na tela e escolha R de Reparar. Ao concluir,volte a configurar,como 1° boot o HD...salve essa escolha e reinicie o computador,para sair do Setup. Tendo êxito siga com a ferramenta RogueKiller e poste o relatório pedido. -/- ################## | Ficheiros # pastas infeciosos | Presente ! D:\WINDOWS\system32\services.exe ################## | Registro | Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsHistory Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsHistory Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsMenu Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRecentDocsMenu Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRun Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoRun Presente ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoSMHelp Presente ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoSMHelp |- Fiz ainda a pouco,uma varredura com o UsbFix em meu computador e consta como infectado o services.exe. |- Ps: Pelo visto,terei que enviar MP aos desenvolvedores,relatando o ocorrido ou bug. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 13, 2012 Bom dia amigo DigRam! Amigo Edvan,utilize o CD do Windows XP e faça o devido reparo.|- Entre na Bios e configure como 1° Boot a unidade de CD-ROM. Procure salvar essa escolha e reinicie o computador com o CD do Windows na unidade. Siga as indicações na tela e escolha R de Reparar. Ao concluir,volte a configurar,como 1° boot o HD...salve essa escolha e reinicie o computador,para sair do Setup. Já tentei essa dica amigo, nao obtive êxito, mais nao tem problema, essa maquina está precisando formatar mesmo, vou aproveitar e trocar o HD por um maior, pois o HD atual dela é de 40GB, como o usuário dessa maquina está precisando urgentemente dessa maquina para trabalhar então acho mais rápido formatar e fazer os backups dos dados dela.. Pode fechar o tópico! :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 13, 2012 Bom dia amigo DigRam! Já tentei essa dica amigo, nao obtive êxito, mais nao tem problema, essa maquina está precisando formatar mesmo, vou aproveitar e trocar o HD por um maior, pois o HD atual dela é de 40GB, como o usuário dessa maquina está precisando urgentemente dessa maquina para trabalhar então acho mais rápido formatar e fazer os backups dos dados dela.. Pode fechar o tópico! :thumbsup: Ok! Edvan |- De certa forma seu computador acabou sendo 'boi de piranha',ao detectar o bug na ferramenta UsbFix. São ossos do ofício...que me fez lembrar a crítica de um Analista,ao não procurar ganhar tempo na execução de algumas ferramentas,quando pedia sua execução em Modo diagnóstico. ( Rechercher ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Edvan 30 Denunciar post Postado Junho 13, 2012 Relaxa essas coisas acontece, a maquina já está 100% agora, no mais fico muito grato pela ajuda que você vem prestando aqui com suas analises e tutoriais.! :thumbsup: Tem muita maquina infectada por aqui, vcs vão me ver muito por aqui ainda..hehe. P.S: Novos Logs ainda vem por aí..rsrsrs :grin: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Junho 13, 2012 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites