|
![]() |
||
[Ajuda] Malware
|
||
. Nós temos 759.284 usuários, convidamos você fazer parte de nossa comunidade também! Se ainda não encontrou o que procura use nossa pesquisa. Esperamos que aprecie nosso trabalho.
![]() |
|
|
Opções do Tópico |
|
|
#1 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
Galera ta sendo detectado aqui pelo avast esse Win32:Rootkit-gen [Rtk] e gostaria de saber como posso removê-lo... sempre que vou passar o antivirus diz que a memória ram esta danificada e não tentei excluir pq os arquivos contaminados fazem parte da pasta do windows.. ai esta o log pelo HijackThis:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:15:29, on 08/12/2009 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe C:\Windows\cbbtfmon.exe C:\Program Files\Free Download Manager\fdm.exe C:\Windows\System32\ftpros.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Windows\system32\igfxsrvc.exe D:\eMule\emule.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\taskeng.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Users\Bruno\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [GbpGSvc] C:\Windows\System32\Eguis.exe O4 - HKLM\..\Run: [agpl] C:\Windows\system32\agpl.exe O4 - HKLM\..\Run: [GbpSbb] C:\Windows\cbbtfmon.exe O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun O4 - HKCU\..\Run: [ftpros.exe] C:\Windows\System32\ftpros.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [eMuleAutoStart] D:\eMule\emule.exe -AutoStart O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Bluetooth Manager.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro\o2flash.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 8786 bytes |
|
|
|
|
|
#2 (permalink) |
|
Zumbi
Registrado em: May 2009
Mensagens: 7.233
Reputação: 7685
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Faça o download do Malwarebytes:
http://www.baixaki.com.br/download/m...ti-malware.htm 1) Instale o aplicativo, atualiza-o e efetue uma verificação completa. 2) Quando terminar o scan., se algum "malware" foi detectado., clique em (Exibir resultado), e depois clique em (remover selecionados). Abrirá um Relatório automatico, Copia e cole aqui. 3) as infecções serão enviadas para quarentena., e alguns tipos poderão exigir a reinicialização do sistema. * após executar o procedimento acima., envie também um novo log do hijackthis
__________________
* Até Maio.... estarei menos presente no GDH...... -- Acessos esporádicos -- |
|
|
|
|
|
#3 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
bom ai estão os logs depois de "removidos" os malware...
Malwarebytes' Anti-Malware 1.42 Versão do banco de dados: 3322 Windows 6.0.6000 Internet Explorer 7.0.6000.16386 08/12/2009 14:58:24 mbam-log-2009-12-08 (14-58-24).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 158628 Tempo decorrido: 58 minute(s), 13 second(s) Processos da Memória infectados: 1 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 0 Valores do Registro infectados: 2 Ítens do Registro infectados: 0 Pastas infectadas: 0 Arquivos infectados: 3 Processos da Memória infectados: C:\Windows\System32\ftpros.exe (Trojan.Downloader) -> Unloaded process successfully. Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: (Nenhum ítem malicioso foi detectado) Valores do Registro infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\ftpros.exe (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\gbpgsvc (Spyware.Banker) -> Quarantined and deleted successfully. Ítens do Registro infectados: (Nenhum ítem malicioso foi detectado) Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: C:\Windows\System32\ftpros.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\LinhaDefensiva\QUA\Arquivos\System32\eguis.EXE. vir (Trojan.SpamBot) -> Quarantined and deleted successfully. C:\Program Files\WinRAR\Core Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully. e aqui o log do HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:00:05, on 08/12/2009 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\cbbtfmon.exe C:\Program Files\Free Download Manager\fdm.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Program Files\O2Micro\o2flash.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Program Files\Avast4\ashMaiSv.exe C:\Program Files\Avast4\ashWebSv.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Windows\system32\NOTEPAD.EXE C:\Users\Bruno\Desktop\HiJackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [agpl] C:\Windows\system32\agpl.exe O4 - HKLM\..\Run: [GbpSbb] C:\Windows\cbbtfmon.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Segurança\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Segurança\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [eMuleAutoStart] D:\eMule\emule.exe -AutoStart O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Bluetooth Manager.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O13 - Gopher Prefix: O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro\o2flash.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 10873 bytes e uma outra dúvida é que sempre usei o avast e agora me decepcionei dele não remover esses malwares... gostaria de saber se esse avira que a galera tanto fala é melhor que o avast... espero que agora esteja limpo aqui.. |
|
|
|
|
|
#4 (permalink) | |
|
GeeK
|
Boa tarde, brunocfb, seja bem vindo ao fórum GdH.
Na verdade, nenhum antivirus, nem mesmo pago, tira todas as infecções. Mas sem dúvidas o Avira é muito melhor do que o avast. Se quiser, desinstale o avast! e faça o download do avira: http://www.free-av.com/en/products/1...antivirus.html Vou dar um auxilio, pois o Wolf está offline. O caso é dele, e assim que ele voltar ele continuará. Abra novamente o seu hijackthis, clique em [do a system scan only], selecione a(s) entrada(s) abaixo, e clique em [fix checked]: Citação:
*Desative seu antivirus temporariamente *Acesse o link abaixo e faça um scan online http://www.eset.com/onlinescan/index.php *Clique em [Yes] > [Start] *Instale o controle ActiveX: OnlineScanner.cab e na tela seguinte clique em [Start] *Marque as duas opções de scan (Remove found threats e Scan unwanted applications) *Clique em [Scan] *Ao término cole o relatório criado em C:\Arquivos de programas\EsetOnlineScanner\log Gere também um novo log do hijackthis.
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
|
|
|
#5 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
ai esta o log do ESET
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.16386 (vista_rtm.061101-2205) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=65acc99e4cb7394bb544fa712c49ca96 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-12-08 07:41:12 # local_time=2009-12-08 05:41:12 (-0300, Horário brasileiro de verão) # country="Brazil" # lang=1033 # osver=6.0.6000 NT # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=769 16775141 100 98 0 195658157 0 0 # compatibility_mode=5892 16776638 100 95 96902051 96906131 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=91115 # found=2 # cleaned=2 # scan_time=6268 C:\Windows\System32\issaas.exe a variant of Win32/Spy.Bancos.NPA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C D:\Jogos\GTA San Andreas\gta_sa_dll.exe probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:44:21, on 08/12/2009 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Windows\cbbtfmon.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Program Files\O2Micro\o2flash.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\conime.exe D:\Segurança\HiJackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [agpl] C:\Windows\system32\agpl.exe O4 - HKLM\..\Run: [GbpSbb] C:\Windows\cbbtfmon.exe O4 - HKLM\..\RunOnce: [CleanSetup] cmd /C rmdir /S /Q "C:\Users\Bruno\AppData\Local\Temp\nro.tmp\" O4 - HKCU\..\Run: [eMuleAutoStart] D:\eMule\emule.exe -AutoStart O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO DE REDE') O4 - Global Startup: Bluetooth Manager.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (file missing) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro\o2flash.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 8442 bytes no log do ESET diz que foi visto 2 arquivos infectados.. algo assim mas não sei se são os que estão em quarentena de quando passei o Malware. |
|
|
|
|
|
#6 (permalink) |
|
GeeK
|
*Desative temporariamente seu antivírus
*Baixe o ComboFix e salve-o no desktop *Feche o Internet Explorer e o Windows Explorer *Duplo-clique no arquivo Combofix.exe *Aceite o contrato *Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N. *O programa será fechado automaticamente *Cole o relatório criado em C:\combofix.txt
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
|
|
#7 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
aqui esta o relatorio do combofix
ComboFix 09-12-08.03 - Bruno 08/12/2009 18:05:49.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.55.1046.18.2039.1335 [GMT -2:00] Executando de: C:\Users\Bruno\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 091208-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1368 [VPS 091208-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ADS - system32: deleted 2 bytes in 1 streams. ADS - drivers: deleted 258 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) ) . C:\$RECYCLE.BIN\S-1-5-21-2152478756-3922319563-605102323-500 C:\Windows\system32\ccrpTmr6.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))) . 2030-08-29 13:22:31 . 2030-08-29 13:22:31 56832 ------w- C:\Windows\system32\iyvu9_32.dll 2030-08-29 13:22:31 . 2030-08-29 13:22:31 143872 ------w- C:\Windows\system32\iacenc.dll 2009-12-08 20:15:03 . 2009-12-08 20:15:03 -------- d-----w- C:\Users\Default\AppData\Local\temp 2009-12-08 19:58:41 . 2009-12-08 19:58:57 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Winamp 2009-12-08 17:44:48 . 2009-12-08 17:44:48 -------- d-----w- C:\Program Files\ESET 2009-12-08 15:52:30 . 2009-12-08 15:52:30 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Malwarebytes 2009-12-08 15:52:25 . 2009-12-03 18:14:06 38224 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys 2009-12-08 15:52:22 . 2009-12-08 15:52:22 -------- d-----w- C:\ProgramData\Malwarebytes 2009-12-08 15:52:21 . 2009-12-03 18:13:56 19160 ----a-w- C:\Windows\system32\drivers\mbam.sys 2009-12-08 15:01:18 . 2009-12-08 15:04:26 -------- d-----w- C:\LinhaDefensiva 2009-12-08 14:52:22 . 2009-12-08 14:52:27 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy 2009-12-08 09:47:26 . 2009-12-08 09:48:59 -------- d-----w- C:\Program Files\DAEMON Tools Lite 2009-12-03 13:48:40 . 2009-12-03 13:49:07 183475 ---h--w- C:\Windows\cbbtfmon.exe 2009-11-23 20:25:15 . 2009-11-23 20:25:16 -------- d-----w- C:\ZillaPDFtoTXTConverter . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-12-08 19:58:57 . 2009-08-28 15:36:00 -------- d-----w- C:\Program Files\Winamp |
|
|
|
|
|
#8 (permalink) |
|
GeeK
|
Relatório Incompleto. Abra o log que está em C:\combofix.txt
E cole-o aqui.
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
|
|
#9 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
realmente foi imcompleto.. foi malz ai..
ComboFix 09-12-08.03 - Bruno 08/12/2009 18:05:49.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.55.1046.18.2039.1335 [GMT -2:00] Executando de: C:\Users\Bruno\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 091208-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1368 [VPS 091208-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ADS - system32: deleted 2 bytes in 1 streams. ADS - drivers: deleted 258 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) ) . C:\$RECYCLE.BIN\S-1-5-21-2152478756-3922319563-605102323-500 C:\Windows\system32\ccrpTmr6.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))) . 2030-08-29 13:22:31 . 2030-08-29 13:22:31 56832 ------w- C:\Windows\system32\iyvu9_32.dll 2030-08-29 13:22:31 . 2030-08-29 13:22:31 143872 ------w- C:\Windows\system32\iacenc.dll 2009-12-08 20:15:03 . 2009-12-08 20:15:03 -------- d-----w- C:\Users\Default\AppData\Local\temp 2009-12-08 19:58:41 . 2009-12-08 19:58:57 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Winamp 2009-12-08 17:44:48 . 2009-12-08 17:44:48 -------- d-----w- C:\Program Files\ESET 2009-12-08 15:52:30 . 2009-12-08 15:52:30 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Malwarebytes 2009-12-08 15:52:25 . 2009-12-03 18:14:06 38224 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys 2009-12-08 15:52:22 . 2009-12-08 15:52:22 -------- d-----w- C:\ProgramData\Malwarebytes 2009-12-08 15:52:21 . 2009-12-03 18:13:56 19160 ----a-w- C:\Windows\system32\drivers\mbam.sys 2009-12-08 15:01:18 . 2009-12-08 15:04:26 -------- d-----w- C:\LinhaDefensiva 2009-12-08 14:52:22 . 2009-12-08 14:52:27 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy 2009-12-08 09:47:26 . 2009-12-08 09:48:59 -------- d-----w- C:\Program Files\DAEMON Tools Lite 2009-12-03 13:48:40 . 2009-12-03 13:49:07 183475 ---h--w- C:\Windows\cbbtfmon.exe 2009-11-23 20:25:15 . 2009-11-23 20:25:16 -------- d-----w- C:\ZillaPDFtoTXTConverter . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-12-08 19:58:57 . 2009-08-28 15:36:00 -------- d-----w- C:\Program Files\Winamp 2009-12-08 17:18:10 . 2009-09-16 22:47:20 -------- d-----w- C:\Program Files\Google 2009-12-08 09:48:43 . 2009-09-12 19:43:58 691696 ----a-w- C:\Windows\system32\drivers\sptd.sys 2009-12-08 09:47:08 . 2009-10-03 18:15:39 -------- d-----w- C:\ProgramData\DAEMON Tools Lite 2009-12-06 18:03:15 . 2006-11-06 01:32:59 83822 ----a-w- C:\Windows\system32\prfc0416.dat 2009-12-06 18:03:15 . 2006-11-06 01:32:59 508502 ----a-w- C:\Windows\system32\prfh0416.dat 2009-12-03 22:56:10 . 2009-08-28 17:35:54 -------- d-----w- C:\Program Files\Avast4 2009-11-24 23:54:29 . 2009-08-28 17:35:59 1280480 ----a-w- C:\Windows\system32\aswBoot.exe 2009-11-24 23:50:12 . 2009-08-28 17:36:31 114768 ----a-w- C:\Windows\system32\drivers\aswSP.sys 2009-11-24 23:50:00 . 2009-08-28 17:36:31 20560 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys 2009-11-24 23:49:48 . 2009-08-28 17:35:59 53328 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys 2009-11-24 23:49:07 . 2009-08-28 17:36:33 48560 ----a-w- C:\Windows\system32\drivers\aswTdi.sys 2009-11-24 23:48:57 . 2009-08-28 17:36:34 23120 ----a-w- C:\Windows\system32\drivers\aswRdr.sys 2009-11-24 23:47:28 . 2009-08-28 17:36:32 97480 ----a-w- C:\Windows\system32\AvastSS.scr 2009-11-24 11:31:54 . 2009-08-28 17:14:32 -------- d-----w- C:\ProgramData\Microsoft Help 2009-11-16 13:21:57 . 2009-10-09 12:23:31 -------- d-----w- C:\Program Files\VidSplitter 2009-11-16 12:33:10 . 2009-11-05 10:42:51 -------- d-----w- C:\Program Files\Netscape 2009-11-05 10:43:40 . 2009-11-05 10:43:40 0 ----a-w- C:\Windows\nsreg.dat 2009-11-05 10:43:35 . 2009-11-05 10:43:35 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Netscape 2009-11-01 19:52:31 . 2009-11-01 19:52:31 10134 ----a-r- C:\Users\Bruno\AppData\Roaming\Microsoft\Installer \{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2009-11-01 19:52:26 . 2009-11-01 19:52:26 -------- d-----w- C:\Program Files\Microsoft WSE 2009-11-01 19:42:45 . 2009-08-28 11:32:34 -------- d--h--w- C:\Program Files\InstallShield Installation Information 2009-10-26 19:09:10 . 2009-09-17 11:09:46 -------- d-----w- C:\Program Files\CDBurnerXP 2009-10-26 19:05:47 . 2009-10-26 19:05:47 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Ashampoo 2009-10-26 18:59:22 . 2009-10-26 18:59:22 -------- d-----w- C:\ProgramData\ashampoo 2009-10-26 18:59:21 . 2009-10-26 18:59:04 -------- d-----w- C:\Program Files\Ashampoo 2009-10-23 10:30:08 . 2009-08-29 16:57:13 -------- d-----w- C:\ProgramData\GbPlugin 2009-10-23 10:30:02 . 2009-08-29 16:57:13 -------- d-----w- C:\Program Files\GbPlugin 2009-10-17 17:08:27 . 2009-10-17 17:08:27 -------- d-----w- C:\ProgramData\Canneverbe Limited 2009-10-15 17:48:32 . 2009-08-29 18:33:21 30752 ----a-w- C:\Windows\system32\drivers\gbpkm.sys 2009-09-27 18:27:23 . 2009-08-28 11:26:28 100248 ----a-w- C:\Users\Bruno\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-26 20:38:17 . 2009-09-26 20:38:17 1202 ----a-w- C:\Windows\system32\ealregsnapshot1.reg 2009-09-26 16:22:56 . 2009-09-26 16:05:31 167998 ----a-w- C:\Windows\hpoins28.dat 2009-09-16 22:46:59 . 2009-09-16 22:46:59 56 --sh--r- C:\Windows\system32\7187BB8154.sys 2009-09-16 22:46:59 . 2009-09-16 22:46:59 1890 --sha-w- C:\Windows\system32\KGyGaAvL.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "eMuleAutoStart"="D:\eMule\emule.exe" [2009-02-22 19:15:14 5668864] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 12:34:32 1004136] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-04-04 07:26:30 138008] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-04-04 07:26:14 154392] "Persistence"="C:\Windows\system32\igfxpers.ex e" [2007-04-04 07:26:24 133912] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 08:01:32 4431872] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 03:47:42 31016] "avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2009-11-24 23:51:40 81000] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-08-29 18:08:01 149280] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 00:17:32 49152] "GbpSbb"="C:\Windows\cbbtfmon.exe" [2009-12-03 13:49:07 183475] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-18 2752512] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2009-10-15 17:42:22 316192 ----a-w- C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend] @="Service" R0 GbpKm;Gbp KernelMode;C:\Windows\System32\drivers\gbpkm.sys [29/08/2009 16:33:21 30752] R0 O2MDRDR;O2MDRDR;C:\Windows\System32\drivers\o2medi a.sys [20/11/2006 16:14:08 38400] R0 O2SDRDR;O2SDRDR;C:\Windows\System32\drivers\o2sd.s ys [09/03/2007 15:01:00 35968] R1 aswSP;avast! Self Protection;C:\Windows\System32\drivers\aswSP.sys [28/08/2009 15:36:31 114768] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswF sBlk.sys [28/08/2009 15:36:31 20560] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\as wMonFlt.sys [28/08/2009 15:35:59 53328] R2 GbpSv;Gbp Service;C:\PROGRA~1\GbPlugin\GbpSv.exe [23/10/2009 06:07:13 54048] S0 sptd;sptd;C:\Windows\System32\drivers\sptd.sys [12/09/2009 17:43:58 691696] S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [04/12/2009 11:13:47 135664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . ------- Scan Suplementar ------- . uStart Page = hxxp://www.daemon-search.com/startpage IE: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab . - - - - ORFÃOS REMOVIDOS - - - - HKLM-Run-agpl - C:\Windows\system32\agpl.exe AddRemove-DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\uninst.exe AddRemove-Detonadores Patch E_is1 - D:\Jogos\AGE\unins000.exe AddRemove-HijackThis - C:\Users\Bruno\Desktop\HijackThis.exe AddRemove-Tradução 4 - D:\Jogos\AGE\age2_x1\Desinstalar.exe ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-08 18:15:16 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************** ************************ . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Tempo para conclusão: 2009-12-08 18:18:46 ComboFix-quarantined-files.txt 2009-12-08 20:18:42 Pré-execução: 13.963.513.856 bytes disponíveis Pós execução: 13.929.988.096 bytes disponíveis - - End Of File - - 071BE65A1643F1C32227C39CC3254F50 |
|
|
|
|
|
#10 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
alguem ai pra ajudar?
|
|
|
|
|
|
#11 (permalink) |
|
Zumbi
Registrado em: May 2009
Mensagens: 7.233
Reputação: 7685
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Envie um novo log do hijackthis.
__________________
* Até Maio.... estarei menos presente no GDH...... -- Acessos esporádicos -- Última edição por Wolf-7x : 08-12-2009 às 23:45. |
|
|
|
|
|
#12 (permalink) |
|
GeeK
|
*Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo:
Código:
*Arraste o arquivo para o Combofix conforme ilustração abaixo: ![]() *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!!..para interromper o processo tecle N. *Cole o relatório criado em C:\combofix.txt
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
|
|
#13 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
bom depois de feito o que foi pedido abaixo seguem os logs....
ComboFix 09-12-08.03 - Bruno 09/12/2009 11:32:32.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.55.1046.18.2039.1319 [GMT -2:00] Executando de: C:\Users\Bruno\Desktop\ComboFix.exe Comandos utilizados :: C:\Users\Bruno\Desktop\CFScript.txt AV: avast! antivirus 4.8.1368 [VPS 091208-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1368 [VPS 091208-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ADS - drivers: deleted 204 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) ) . C:\Windows\system32\ccrpTmr6.dll . ---- Execuções precedente ------- . C:\$RECYCLE.BIN\S-1-5-21-2152478756-3922319563-605102323-500 C:\Windows\system32\ccrpTmr6.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))) . 2030-08-29 13:22:31 . 2030-08-29 13:22:31 56832 ------w- C:\Windows\system32\iyvu9_32.dll 2030-08-29 13:22:31 . 2030-08-29 13:22:31 143872 ------w- C:\Windows\system32\iacenc.dll 2009-12-09 13:41:43 . 2009-12-09 13:41:43 -------- d-----w- C:\Users\Default\AppData\Local\temp 2009-12-09 00:36:07 . 2009-12-09 00:36:08 -------- d-----w- C:\Program Files\UltraPlayer 2009-12-09 00:29:05 . 2009-12-09 00:29:09 -------- d-----w- C:\Program Files\Common Files\PX Storage Engine 2009-12-08 21:09:04 . 2009-12-09 00:34:19 -------- d-----w- C:\Program Files\Winamp 2009-12-08 17:44:48 . 2009-12-08 17:44:48 -------- d-----w- C:\Program Files\ESET 2009-12-08 15:52:30 . 2009-12-08 15:52:30 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Malwarebytes 2009-12-08 15:52:25 . 2009-12-03 18:14:06 38224 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys 2009-12-08 15:52:22 . 2009-12-08 15:52:22 -------- d-----w- C:\ProgramData\Malwarebytes 2009-12-08 15:52:21 . 2009-12-03 18:13:56 19160 ----a-w- C:\Windows\system32\drivers\mbam.sys 2009-12-08 15:01:18 . 2009-12-08 15:04:26 -------- d-----w- C:\LinhaDefensiva 2009-12-08 14:52:22 . 2009-12-08 14:52:27 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy 2009-12-08 09:47:26 . 2009-12-08 09:48:59 -------- d-----w- C:\Program Files\DAEMON Tools Lite 2009-12-03 13:48:40 . 2009-12-03 13:49:07 183475 ---h--w- C:\Windows\cbbtfmon.exe 2009-11-23 20:25:15 . 2009-11-23 20:25:16 -------- d-----w- C:\ZillaPDFtoTXTConverter . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-12-09 00:36:07 . 2009-08-28 11:32:34 -------- d--h--w- C:\Program Files\InstallShield Installation Information 2009-12-09 00:35:41 . 2009-08-28 11:32:23 -------- d-----w- C:\Program Files\Common Files\InstallShield 2009-12-08 17:18:10 . 2009-09-16 22:47:20 -------- d-----w- C:\Program Files\Google 2009-12-08 09:48:43 . 2009-09-12 19:43:58 691696 ----a-w- C:\Windows\system32\drivers\sptd.sys 2009-12-08 09:47:08 . 2009-10-03 18:15:39 -------- d-----w- C:\ProgramData\DAEMON Tools Lite 2009-12-06 18:03:15 . 2006-11-06 01:32:59 83822 ----a-w- C:\Windows\system32\prfc0416.dat 2009-12-06 18:03:15 . 2006-11-06 01:32:59 508502 ----a-w- C:\Windows\system32\prfh0416.dat 2009-12-03 22:56:10 . 2009-08-28 17:35:54 -------- d-----w- C:\Program Files\Avast4 2009-11-24 23:54:29 . 2009-08-28 17:35:59 1280480 ----a-w- C:\Windows\system32\aswBoot.exe 2009-11-24 23:50:12 . 2009-08-28 17:36:31 114768 ----a-w- C:\Windows\system32\drivers\aswSP.sys 2009-11-24 23:50:00 . 2009-08-28 17:36:31 20560 ----a-w- C:\Windows\system32\drivers\aswFsBlk.sys 2009-11-24 23:49:48 . 2009-08-28 17:35:59 53328 ----a-w- C:\Windows\system32\drivers\aswMonFlt.sys 2009-11-24 23:49:07 . 2009-08-28 17:36:33 48560 ----a-w- C:\Windows\system32\drivers\aswTdi.sys 2009-11-24 23:48:57 . 2009-08-28 17:36:34 23120 ----a-w- C:\Windows\system32\drivers\aswRdr.sys 2009-11-24 23:47:28 . 2009-08-28 17:36:32 97480 ----a-w- C:\Windows\system32\AvastSS.scr 2009-11-24 11:31:54 . 2009-08-28 17:14:32 -------- d-----w- C:\ProgramData\Microsoft Help 2009-11-16 13:21:57 . 2009-10-09 12:23:31 -------- d-----w- C:\Program Files\VidSplitter 2009-11-16 12:33:10 . 2009-11-05 10:42:51 -------- d-----w- C:\Program Files\Netscape 2009-11-05 10:43:40 . 2009-11-05 10:43:40 0 ----a-w- C:\Windows\nsreg.dat 2009-11-05 10:43:35 . 2009-11-05 10:43:35 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Netscape 2009-11-01 19:52:31 . 2009-11-01 19:52:31 10134 ----a-r- C:\Users\Bruno\AppData\Roaming\Microsoft\Installer \{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2009-11-01 19:52:26 . 2009-11-01 19:52:26 -------- d-----w- C:\Program Files\Microsoft WSE 2009-10-26 19:09:10 . 2009-09-17 11:09:46 -------- d-----w- C:\Program Files\CDBurnerXP 2009-10-26 19:05:47 . 2009-10-26 19:05:47 -------- d-----w- C:\Users\Bruno\AppData\Roaming\Ashampoo 2009-10-26 18:59:22 . 2009-10-26 18:59:22 -------- d-----w- C:\ProgramData\ashampoo 2009-10-26 18:59:21 . 2009-10-26 18:59:04 -------- d-----w- C:\Program Files\Ashampoo 2009-10-23 10:30:08 . 2009-08-29 16:57:13 -------- d-----w- C:\ProgramData\GbPlugin 2009-10-23 10:30:02 . 2009-08-29 16:57:13 -------- d-----w- C:\Program Files\GbPlugin 2009-10-17 17:08:27 . 2009-10-17 17:08:27 -------- d-----w- C:\ProgramData\Canneverbe Limited 2009-10-15 17:48:32 . 2009-08-29 18:33:21 30752 ----a-w- C:\Windows\system32\drivers\gbpkm.sys 2009-09-27 18:27:23 . 2009-08-28 11:26:28 100248 ----a-w- C:\Users\Bruno\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-26 20:38:17 . 2009-09-26 20:38:17 1202 ----a-w- C:\Windows\system32\ealregsnapshot1.reg 2009-09-26 16:22:56 . 2009-09-26 16:05:31 167998 ----a-w- C:\Windows\hpoins28.dat 2009-09-16 22:46:59 . 2009-09-16 22:46:59 56 --sh--r- C:\Windows\system32\7187BB8154.sys 2009-09-16 22:46:59 . 2009-09-16 22:46:59 1890 --sha-w- C:\Windows\system32\KGyGaAvL.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "eMuleAutoStart"="D:\eMule\emule.exe" [2009-02-22 19:15:14 5668864] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 12:34:32 1004136] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-04-04 07:26:30 138008] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-04-04 07:26:14 154392] "Persistence"="C:\Windows\system32\igfxpers.ex e" [2007-04-04 07:26:24 133912] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 08:01:32 4431872] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 03:47:42 31016] "avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2009-11-24 23:51:40 81000] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-08-29 18:08:01 149280] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 00:17:32 49152] "agpl"="C:\Windows\system32\agpl.exe" [BU] "GbpSbb"="C:\Windows\cbbtfmon.exe" [2009-12-03 13:49:07 183475] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-18 2752512] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2009-10-15 17:42:22 316192 ----a-w- C:\Program Files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend] @="Service" R0 GbpKm;Gbp KernelMode;C:\Windows\System32\drivers\gbpkm.sys [29/08/2009 16:33:21 30752] R0 O2MDRDR;O2MDRDR;C:\Windows\System32\drivers\o2medi a.sys [20/11/2006 16:14:08 38400] R0 O2SDRDR;O2SDRDR;C:\Windows\System32\drivers\o2sd.s ys [09/03/2007 15:01:00 35968] R1 aswSP;avast! Self Protection;C:\Windows\System32\drivers\aswSP.sys [28/08/2009 15:36:31 114768] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswF sBlk.sys [28/08/2009 15:36:31 20560] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\as wMonFlt.sys [28/08/2009 15:35:59 53328] R2 GbpSv;Gbp Service;C:\PROGRA~1\GbPlugin\GbpSv.exe [23/10/2009 06:07:13 54048] S0 sptd;sptd;C:\Windows\System32\drivers\sptd.sys [12/09/2009 17:43:58 691696] S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [04/12/2009 11:13:47 135664] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . ------- Scan Suplementar ------- . uStart Page = hxxp://www.daemon-search.com/startpage IE: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab . - - - - ORFÃOS REMOVIDOS - - - - HKLM-Run-WinampAgent - C:\Program Files\Winamp\winampa.exe AddRemove-{7FF95D80-7FEA-11D3-BDE9-0050DA1AB3B9} - C:\Program Files\UltraPlayer\UPUnInst.exe RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ct or.dll ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-09 11:42:07 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************** ************************ . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Tempo para conclusão: 2009-12-09 11:45:52 ComboFix-quarantined-files.txt 2009-12-09 13:45:48 Pré-execução: 13.528.240.128 bytes disponíveis Pós execução: 13.310.185.472 bytes disponíveis - - End Of File - - 63DFA1AB7542DDEBD1FCCC5411F3E147 quanto ao hijackthis quando vou abrir da erro.. não sei o que ta acontecendo agora.. o erro é o seguinte.. quando vai abrir diz: Run-time error "481" Invalid Picture |
|
|
|
|
|
#14 (permalink) | ||
|
GeeK
|
Mande o seguinte arquivo para analise do http://www.virustotal.com
Citação:
Citação:
*Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo: Código:
*Arraste o arquivo para o Combofix conforme ilustração abaixo: ![]() *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!!..para interromper o processo tecle N. *Cole o relatório criado em C:\combofix.txt
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
||
|
|
|
|
|
#15 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
esse arquivo C:\Windows\system32\7187BB8154.sys não consegui achar mais... coloquei ate em pesquisar .. fui diretamente na pasta e nada..
o outro o relatorio foi esse Arquivo ARPPRODUCTICON.exe recebido em 2009.12.06 18:46:56 (UTC) Andamento: terminado Resultado: 0/40 (0.00%) Modo compacto Imprimir resultados Antivírus Versão Última Atualização Resultado a-squared 4.5.0.43 2009.12.06 - AhnLab-V3 5.0.0.2 2009.12.06 - AntiVir 7.9.1.92 2009.12.05 - Antiy-AVL 2.0.3.7 2009.12.04 - Authentium 5.2.0.5 2009.12.02 - Avast 4.8.1351.0 2009.12.06 - AVG 8.5.0.426 2009.12.06 - BitDefender 7.2 2009.12.06 - CAT-QuickHeal 10.00 2009.12.05 - ClamAV 0.94.1 2009.12.06 - Comodo 3103 2009.12.01 - DrWeb 5.0.0.12182 2009.12.06 - eSafe 7.0.17.0 2009.12.06 - eTrust-Vet 35.1.7159 2009.12.04 - F-Prot 4.5.1.85 2009.12.05 - F-Secure 9.0.15370.0 2009.12.03 - Fortinet 4.0.14.0 2009.12.06 - GData 19 2009.12.06 - Ikarus T3.1.1.74.0 2009.12.06 - Jiangmin 13.0.900 2009.12.02 - K7AntiVirus 7.10.912 2009.12.05 - Kaspersky 7.0.0.125 2009.12.06 - McAfee 5824 2009.12.06 - McAfee+Artemis 5824 2009.12.06 - McAfee-GW-Edition 6.8.5 2009.12.06 - Microsoft 1.5302 2009.12.06 - NOD32 4665 2009.12.06 - Norman 6.03.02 2009.12.05 - nProtect 2009.1.8.0 2009.12.06 - Panda 10.0.2.2 2009.12.06 - PCTools 7.0.3.5 2009.12.05 - Rising 22.24.06.04 2009.12.06 - Sophos 4.48.0 2009.12.06 - Sunbelt 3.2.1858.2 2009.12.06 - Symantec 1.4.4.12 2009.12.06 - TheHacker 6.5.0.2.086 2009.12.05 - TrendMicro 9.100.0.1001 2009.12.06 - VBA32 3.12.12.0 2009.12.03 - ViRobot 2009.12.4.2072 2009.12.04 - VirusBuster 5.0.21.0 2009.12.06 - Informações adicionais File size: 10134 bytes MD5 : 6e42cf0d47af25dea4cecdbe093d521c SHA1 : ec3e157d289629ab3c391800e7d8774e0f3a2ec0 SHA256: 7e1f9048d457369e50ee2ccc3659c897a740ecf722036858c8 8390115e5612a1 TrID : File type identification Windows Icon (57.2%) MPEG Video (42.7%) ssdeep: 96:SYONfeZEWVArvU3mONfeZEWV4+xF9p0ONfeZEWVblMb6Ujj DhPm2TBnDifnZPmS:KNeTL3TNeT4+vDFNeTb6bVPmSB2nZPmS PEiD : - CWSandbox: http://research.sunbelt-software.com...cecdbe093d521c RDS : NSRL Reference Data Set ( Borland Software Corp. ) Delphi Studio: SetupIcon.ibdDelphi Studio with .NET interoperability: SetupIcon.ibd ( Microsoft ) .NET Framework SDK: SETUP.ICOApplications, Developer Tools: SETUPICON.IBDApplications, Developer Tools, Servers: SETUP.ICOBeta 2 Kit 2003: Setup.icoDeveloper Tools: SETUPICON.IBDDeveloper Tools, Servers: SETUPICON.IBDDisc 2488: SETUPICON.IBD, SetupIcon.ibdExchange 2000 Enterprise Server: SETUPICON.IBDExchange Server 2000: SETUPICON.IBDInternet Explorer Versions: SETUP.ICOInternet Explorer Versions: SETUP.ICOMSDN Disc: SETUP.ICOMSDN Disc 2436.10: SETUP.ICOMSDN Disc 2436.12: SETUP.ICOMSDN Disc 2436.18: SETUP.ICOMSDN Disc 2436.19: SETUP.ICOMSDN Disc 2436.20: SETUP.ICOMSDN Disc 2436.22: SETUP.ICOMSDN Disc 2436.24: SETUP.ICOMSDN Disc 2436.25: SETUP.ICOMSDN Disc 2436.26: SETUP.ICOMSDN Disc 2436.27: SETUP.ICOMSDN Disc 2436.28: SETUP.ICOMSDN Disc 2436.5: SETUP.ICOMSDN Disc 2436.6: SETUP.ICOMSDN Disc 2436.7: SETUP.ICOMSDN Disc 2436.8: SETUP.ICOMSDN Disc 3089: SETUPICON.IBDMSDN Disc 3089.1: SETUPICON.IBDMSDN Disc2436.3: SETUP.ICOMSDN Disc2488.1: SETUPICON.IBD, SetupIcon.ibdMSDN Disk 2436.14: SETUP.ICOMSDN Disk 2436.22: SETUP.ICOMSDN MS .NET framework 1.1 SDK, App. Center 2000 dev. ed., Commerce server 2002 dev. ed., Data Analyzer 3.5, Host Integration server 2000: SETUP.ICOMSDN MS .NET Framework 1.1 SDK, IE 5.5 SP1, IE 6.0, IE 6.0 SP1, SharePoint Server 2001, SharePoint Server 2001 SP2A: SETUP.ICOMSDN MS Application Center 2000, BizTalk Server 2002, BizTalk server 2004 beta, Content Management Server 2002, Identity Integration Server 2003: SETUP.ICOMSDN Office Publisher 2003: SETUP.ICOMSDN SharePoint portal server 2001, SMS 2.0 w SP2, MS IE 5.5 SP1, IE 6.0, IE 6.0 SP1, Windows 98, Windows ME: SETUP.ICOServers: SETUPICON.IBDSharePoint Portal Server: SETUP.ICOSharePoint Portal Server 2001: SETUP.ICOSharePoint Portal Server 2001: SETUP.ICOSharePoint Portal Server 2001: SETUP.ICOTahoe Server: SETUP.ICOVisual SourceSafe: SETUPICON.IBD ( Future Publishing ) ATmission Live CD - MEPIS Linux: binary9 ATENÇÃO: VirusTotal é um serviço gratuito oferecido por Hispasec Sistemas. Não há garantias quanto à disponibilidade e continuidade desse serviço. Apesar da taxa de detecção proporcionada pelo uso de múltiplos mecanismos de antivírus ser muito superior àquela oferecida por um único produto, os resultados NÃO garantem a possibilidade de um arquivo ser inofensivo. Atualmente, não há qualquer solução que ofereça 100% de eficiência na detecção de vírus e arquivos maliciosos.. VirusTotal © Hispasec Sistemas - Blog - Contato: info@virustotal.com - Terms of Service & Privacy Policy e aqui esta o ultimo relatorio ComboFix ComboFix 09-12-08.03 - Bruno 09/12/2009 12:41:13.3.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.55.1046.18.2039.1325 [GMT -2:00] Executando de: c:\users\Bruno\Desktop\ComboFix.exe Comandos utilizados :: c:\users\Bruno\Desktop\CFScript.txt AV: avast! antivirus 4.8.1368 [VPS 091208-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1368 [VPS 091208-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "c:\windows\cbbtfmon.exe" . ADS - drivers: deleted 204 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) ) . c:\windows\cbbtfmon.exe c:\windows\system32\ccrpTmr6.dll . ---- Execuções precedente ------- . c:\windows\system32\ccrpTmr6.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))) . 2030-08-29 13:22 . 2030-08-29 13:22 56832 ------w- c:\windows\system32\iyvu9_32.dll 2030-08-29 13:22 . 2030-08-29 13:22 143872 ------w- c:\windows\system32\iacenc.dll 2009-12-09 14:50 . 2009-12-09 14:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-12-09 00:36 . 2009-12-09 00:36 -------- d-----w- c:\program files\UltraPlayer 2009-12-09 00:29 . 2009-12-09 00:29 -------- d-----w- c:\program files\Common Files\PX Storage Engine 2009-12-08 21:09 . 2009-12-09 00:34 -------- d-----w- c:\program files\Winamp 2009-12-08 17:44 . 2009-12-08 17:44 -------- d-----w- c:\program files\ESET 2009-12-08 15:52 . 2009-12-08 15:52 -------- d-----w- c:\users\Bruno\AppData\Roaming\Malwarebytes 2009-12-08 15:52 . 2009-12-03 18:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-08 15:52 . 2009-12-08 15:52 -------- d-----w- c:\programdata\Malwarebytes 2009-12-08 15:52 . 2009-12-03 18:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-12-08 15:01 . 2009-12-08 15:04 -------- d-----w- C:\LinhaDefensiva 2009-12-08 14:52 . 2009-12-09 14:26 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2009-12-08 09:47 . 2009-12-08 09:48 -------- d-----w- c:\program files\DAEMON Tools Lite 2009-11-23 20:25 . 2009-11-23 20:25 -------- d-----w- C:\ZillaPDFtoTXTConverter . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-12-09 14:34 . 2009-08-29 16:57 -------- d-----w- c:\programdata\GbPlugin 2009-12-09 14:04 . 2009-08-29 16:57 -------- d-----w- c:\program files\GbPlugin 2009-12-09 00:36 . 2009-08-28 11:32 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-12-09 00:35 . 2009-08-28 11:32 -------- d-----w- c:\program files\Common Files\InstallShield 2009-12-08 17:18 . 2009-09-16 22:47 -------- d-----w- c:\program files\Google 2009-12-08 09:48 . 2009-09-12 19:43 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2009-12-08 09:47 . 2009-10-03 18:15 -------- d-----w- c:\programdata\DAEMON Tools Lite 2009-12-06 18:03 . 2006-11-06 01:32 83822 ----a-w- c:\windows\system32\prfc0416.dat 2009-12-06 18:03 . 2006-11-06 01:32 508502 ----a-w- c:\windows\system32\prfh0416.dat 2009-12-03 22:56 . 2009-08-28 17:35 -------- d-----w- c:\program files\Avast4 2009-11-24 23:54 . 2009-08-28 17:35 1280480 ----a-w- c:\windows\system32\aswBoot.exe 2009-11-24 23:50 . 2009-08-28 17:36 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-11-24 23:50 . 2009-08-28 17:36 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-11-24 23:49 . 2009-08-28 17:35 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2009-11-24 23:49 . 2009-08-28 17:36 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-11-24 23:48 . 2009-08-28 17:36 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-11-24 23:47 . 2009-08-28 17:36 97480 ----a-w- c:\windows\system32\AvastSS.scr 2009-11-24 11:31 . 2009-08-28 17:14 -------- d-----w- c:\programdata\Microsoft Help 2009-11-16 13:21 . 2009-10-09 12:23 -------- d-----w- c:\program files\VidSplitter 2009-11-16 12:33 . 2009-11-05 10:42 -------- d-----w- c:\program files\Netscape 2009-11-05 10:43 . 2009-11-05 10:43 0 ----a-w- c:\windows\nsreg.dat 2009-11-05 10:43 . 2009-11-05 10:43 -------- d-----w- c:\users\Bruno\AppData\Roaming\Netscape 2009-11-01 19:52 . 2009-11-01 19:52 10134 ----a-r- c:\users\Bruno\AppData\Roaming\Microsoft\Installer \{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe 2009-11-01 19:52 . 2009-11-01 19:52 -------- d-----w- c:\program files\Microsoft WSE 2009-10-26 19:09 . 2009-09-17 11:09 -------- d-----w- c:\program files\CDBurnerXP 2009-10-26 19:05 . 2009-10-26 19:05 -------- d-----w- c:\users\Bruno\AppData\Roaming\Ashampoo 2009-10-26 18:59 . 2009-10-26 18:59 -------- d-----w- c:\programdata\ashampoo 2009-10-26 18:59 . 2009-10-26 18:59 -------- d-----w- c:\program files\Ashampoo 2009-10-17 17:08 . 2009-10-17 17:08 -------- d-----w- c:\programdata\Canneverbe Limited 2009-10-15 17:48 . 2009-08-29 18:33 30752 ----a-w- c:\windows\system32\drivers\gbpkm.sys 2009-09-27 18:27 . 2009-08-28 11:26 100248 ----a-w- c:\users\Bruno\AppData\Local\GDIPFONTCACHEV1.DAT 2009-09-26 20:38 . 2009-09-26 20:38 1202 ----a-w- c:\windows\system32\ealregsnapshot1.reg 2009-09-26 16:22 . 2009-09-26 16:05 167998 ----a-w- c:\windows\hpoins28.dat 2009-09-16 22:46 . 2009-09-16 22:46 56 --sh--r- c:\windows\system32\7187BB8154.sys 2009-09-16 22:46 . 2009-09-16 22:46 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "eMuleAutoStart"="d:\emule\emule.exe" [2009-02-22 5668864] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-02 1004136] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-04 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-04 154392] "Persistence"="c:\windows\system32\igfxpers.ex e" [2007-04-04 133912] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 4431872] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-29 149280] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152] "agpl"="c:\windows\system32\agpl.exe" [BU] "WinampAgent"="c:\program files\Winamp\winampa.exe" [BU] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-1-18 2752512] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb] 2009-10-15 17:42 316192 ----a-w- c:\program files\GbPlugin\gbieh.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend] @="Service" R0 GbpKm;Gbp KernelMode;c:\windows\System32\drivers\gbpkm.sys [29/08/2009 16:33 30752] R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2medi a.sys [20/11/2006 16:14 38400] R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.s ys [09/03/2007 15:01 35968] R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [28/08/2009 15:36 114768] R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswF sBlk.sys [28/08/2009 15:36 20560] R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\as wMonFlt.sys [28/08/2009 15:35 53328] R2 GbpSv;Gbp Service;c:\progra~1\GbPlugin\GbpSv.exe [23/10/2009 06:07 54048] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04/12/2009 11:13 135664] S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [12/09/2009 17:43 691696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . ------- Scan Suplementar ------- . uStart Page = hxxp://www.infonet.com.br/ IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab . - - - - ORFÃOS REMOVIDOS - - - - HKLM-Run-GbpSbb - c:\windows\cbbtfmon.exe ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-09 12:55 Windows 6.0.6000 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************** ************************ . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'Explorer.exe'(752) c:\windows\system32\TosBtExt.dll . ------------------------ Outros Processos em Execução ------------------------ . c:\program files\Avast4\aswUpdSv.exe c:\program files\Avast4\ashServ.exe c:\windows\system32\igfxsrvc.exe c:\windows\RtHDVCpl.exe c:\program files\Avast4\ashDisp.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe c:\program files\O2Micro\o2flash.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe c:\program files\Avast4\ashMaiSv.exe c:\program files\Avast4\ashWebSv.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\conime.exe c:\windows\system32\wbem\unsecapp.exe . ************************************************** ************************ . Tempo para conclusão: 2009-12-09 12:58:06 - Máquina reiniciou ComboFix-quarantined-files.txt 2009-12-09 14:58 Pré-execução: 13.326.381.056 bytes disponíveis Pós execução: 13.231.738.880 bytes disponíveis - - End Of File - - 1C6BCAC1BD7354F39426EEDF702DE8B2 |
|
|
|
|
|
#16 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
consegui aqui o log do hijackthis
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:32:45, on 09/12/2009 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\PROGRA~1\GbPlugin\GbpSv.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Program Files\O2Micro\o2flash.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Program Files\Avast4\ashMaiSv.exe C:\Program Files\Avast4\ashWebSv.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Windows\servicing\TrustedInstaller.exe C:\Users\Bruno\AppData\Local\Google\Chrome\Applica tion\chrome.exe C:\Users\Bruno\Desktop\HiJackThis\HijackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.infonet.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [agpl] C:\Windows\system32\agpl.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - Global Startup: Bluetooth Manager.lnk = ? O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (file missing) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~1\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro\o2flash.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- End of file - 7571 bytes |
|
|
|
|
|
#17 (permalink) |
|
Zumbi
Registrado em: May 2009
Mensagens: 7.233
Reputação: 7685
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Enquanto o Djoni está off!!
acesse o site: http://virusscan.jotti.org/pt-br envie o seguinte arquivo para análise: C:\Windows\system32\agpl.exe * copie e cole em sua resposta o link contendo o resultado da verificação.
__________________
* Até Maio.... estarei menos presente no GDH...... -- Acessos esporádicos -- |
|
|
|
|
|
#18 (permalink) |
|
GeeK
|
Ia pedir um procedimento, mas vou esperar o resultado da analise que o wolf09 pediu.
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
|
|
#19 (permalink) |
|
Newbie
Registrado em: Dec 2006
Mensagens: 17
Reputação: 0
![]() |
por incrivel que pareça mas não encontrei o arquivo agpl.exe ... estranho pq realmente tem no relatorio mas não esta na pasta.. nem como arquivo oculto.. o que recomendam? passei aqui no pc o avast o spybot eles não detectaram mais nada...
aguardo |
|
|
|
|
|
#20 (permalink) |
|
GeeK
|
Vá em iniciar > programas > acessórios > ferramentas do sistema > restauração do sistema > criar ponto de restauração. Crie um ponto de restauração, para um caso de emergências.
*Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo: Código:
*Arraste o arquivo para o Combofix conforme ilustração abaixo: ![]() *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!!..para interromper o processo tecle N. *Cole o relatório criado em C:\combofix.txt
__________________
Problema resolvido? Por gentileza, edite a primeira postagem do seu tópico em modo avançado, e adicione [resolvido] ao final do título do tópico. Quem ajuda agradece! ![]() |
|
|
|
![]() |
| Opções do Tópico | |
|
|