|
![]() |
||
[resolvido]Malware não deixa instalar mais nenhum software de proteção
|
||
. Nós temos 754.061 usuários, convidamos você fazer parte de nossa comunidade também! Se ainda não encontrou o que procura use nossa pesquisa. Esperamos que aprecie nosso trabalho.
![]() |
|
|
Opções do Tópico |
|
|
#1 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Alguém ai já pegou algum virus ou algo do tipo que não deixa instalar nenhum software de proteção?
Estou com uma maquina assim aqui... nunca vi isso.. Nem o hijackthis consegue rodar nem no modo de segurança... tentei instalar alguns AV e nenhum teve exito, todos deram erro... inclusive o spybot, spysweeper e outros... Para tirar a prova instalei vários outros softwares diversos que acabei de baixar e todos funcionam bem.. Só quando é algum software de segurança, ele bloqueia algum dos arquivos do programa e não deixa instalar... Eu ia formatar, mas como tem outros hds com muitos arquivos armazenados, resolvi descobrir o tal virus e fazer uma varredura nas outras partições... Rodei o Ubuntu nessa maquina e rodei o clamTk até o fim, ele encontrou alguns trojans e deletou... mas o problema persiste, o clamAV não conseguiu detectar essa praga na partição windows.... Já no windows, por exemplo tentei instalar o Antivir e o resultado foi que ele deleta o arquivo: avarlt.dll.... tentei descompactar a instalação e antes tive o trabalho de renomear o arquivo citado para ele não deletar, mas assim que renomeio colocando o nome correto com a extensão ele deleta.... ![]() Não desisti, fui para uma versão paga, tentei o Kaspersky trial e o erro foi também em um outro arquivo: avp_io32.dll ![]() Então tentei o nod, que tbém ocorreu um erro, mas não consegui descobrir qual arquivo faltou, ele simplesmente dá a mensagem que não consegue carregar o serviço "Eset Service" Ekrn ![]() ![]() E assim também com hijackthis e com spybot: ![]() ![]() Agora estou tentando os AV online comecei com dois o Panda e o Trend micro, mas pelo jeito vai longe, então vou deixar rodando e amanhã talvez dê algum resultado, mas creio que esses AV só detectam, mas não eliminam o virus, fazendo eu adquirir algo, enfim, se alguém tiver alguma dica agradeço... Sintomas: A maquina aparentemente esta normal, ela tinha o AVG instalado, que foi totalmente destruido por esse virus, deixando esse AV totalmente inoperante, o único sintoma notável além é claro da impossibilidade de instalar software de segurança é com o som do windows, assim que inicia o som fica todo mudo, o controle de volume esta sempre no mínimo, mesmo aumentando o volume não sai som... Só sai o som quando o windows inicia, depois fica assim.... Alguém tem alguma idéia do que posso estar fazendo para limpar essa maquina antes de formatar? Aguardarei sugestões... Muito obrigado []´s
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs Última edição por coringa33 : 31-07-2008 às 17:48. Motivo: Problema resolvido!!!! |
|
|
|
|
|
#2 (permalink) |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
*Baixe o programa do link e instale-o. Execute-o e clique em "Do a system scan and save a logfile".
*Uma janela contendo o resultado do scan será aberta. Copie e cole o resultado aqui no fórum http://www.trendsecure.com/portal/en...HiJackThis.zip
__________________
|
|
|
|
|
|
#3 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, Obrigado, eu tentei o hijackthis anteriormente e nem ele eu consigo instalar, tentei o seu link a mesma coisa, até instala mas dá o mesmo erro (que o hijackthis não é um aplicativo win32 válido)...
Ai tentei as verificações online: rodei o panda, ele eu tinha que criar um cadastro para desinfectar e a conexão da rede caiu..rs Rodei o trend micro e deu erro no meio da verificação e fechou a janela. Ai fui no bitdefender e rodei ele consegui algo, veja o resultado: C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe Infected with: Trojan.Agent.AJKB C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0032472.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0032472.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033462.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033462.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033463.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033463.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033622.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033622.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033625.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP73\A0033625.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP74\A0033742.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP74\A0033742.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP74\A0033743.sys Infected with: Rootkit.Bagle.Gen C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP74\A0033743.sys Disinfection failed C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP74\A0033743.sys Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033755.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033755.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033756.sys Infected with: Rootkit.Bagle.Gen C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033756.sys Disinfection failed C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033756.sys Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033776.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP75\A0033776.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0033787.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0033787.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0034063.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0034063.exe Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0034064.sys Infected with: Rootkit.Bagle.Gen C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0034064.sys Disinfection failed C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP76\A0034064.sys Deleted C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP77\A0034090.exe Infected with: Trojan.Agent.AJKB C:\System Volume Information\_restore{3E73C002-CCD0-4FC0-A634-33C38BCE749E}\RP77\A0034090.exe Deleted Pelo jeito ele pegou esse trojan.Agente.AJKB, vou tentar agora instalar algum AV para ver o que ocorre lá... Obrigado pela ajuda de qualquer forma, não sei se eliminou ainda a virose, vou tentar e depois posto se continua ou resolveu... Valeu!!! []ś
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#4 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Não eliminou, acabei de verificar a maquina e o problema persiste!!!
Estou sem idéias, tentem o clamtk no ubuntu live cd, tentei os AV online, a maquina reinicia quando tento entrar no modo de segurança...... Enfim, estou mais perdido que cego em tiroteio..rs Alguém teria alguma idéia do que eu poderia fazer? Existe algum programa estilo hijackthis que roda pelo linux e analisa partição windows??? Estou ficando sem opções..rs Valeu! []ś
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#5 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Poxa depois de muito quebrar a cabeça consegui rodar o hijackthis.exe rsss e de forma simples, renomeei ele para um nome qualquer e consegui um log da máquina, se alguém puder analisar, agradeço:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:44:11, on 31/7/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Mixer.exe C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Arquivos de programas\QuickTime\qttask.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\meapag\procexp.exe C:\meapag\scuzi.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Arquivos de programas\Maxtor\MaxBlast\MaxBlastMonitor.exe O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe" O4 - HKLM\..\Run: [ClamWin] "C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" --logon O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [TransBar] C:\Arquivos de programas\AKSoftware\TransBar\TransBar.exe /s O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1212683016568 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - http://javadl-esd.sun.com/update/1.5...ndows-i586.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS1\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe -- End of file - 9010 bytes
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#6 (permalink) |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
*Baixe o programa do link e salve-o no desktop
ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe *Duplo clique em fsbl.exe e aceite o contrato *Feche todos os programas e janelas *Na janela inicial "Step 1: Scan for hidden items" clique em "Scan" *Ao terminar o scan clique em "Close" *Será criado um log com o nome fsb-xxxxx.log na mesma pasta do programa *Cole o resultado na sua próxima resposta
__________________
|
|
|
|
|
|
#7 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, obrigado por sua ajuda, ai vai o log:
07/31/08 12:10:13 [Info]: BlackLight Engine 1.0.70 initialized 07/31/08 12:10:13 [Info]: OS: 5.1 build 2600 (Service Pack 3) 07/31/08 12:10:15 [Note]: 7019 4 07/31/08 12:10:15 [Note]: 7005 0 07/31/08 12:14:28 [Note]: 7006 0 07/31/08 12:14:29 [Note]: 7011 436 07/31/08 12:14:29 [Note]: 7035 0 07/31/08 12:14:41 [Note]: 7026 0 07/31/08 12:14:50 [Note]: 7026 0 07/31/08 12:14:50 [Note]: 7024 3 07/31/08 12:14:50 [Info]: Hidden process: C:\WINDOWS\system32\drivers\hldrrr.exe 07/31/08 12:15:12 [Note]: FSRAW library version 1.7.1024 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13sphs.dll 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\CrlWTC114.dll 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13br.ths 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13cbe.dll 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13cbeEN.CBD 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13cbepo.cbt 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13ce.icr 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13ce.sav 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13en.hwl 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13en.mor 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13LDEN.dll 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:28 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13LDPO.dll 07/31/08 12:15:28 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13LDXX.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13LI.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13oz.icr 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13oz.sav 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13po.icr 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13po.lex 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13po.sav 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13po.ths 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13spls.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13SPML.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13sptl.ico 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13sptlPO.exe 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13SPTP.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13SPWP.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WT13uipo.dll 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13uk.adv 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13uk.icr 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13uk.rul 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13uk.sav 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13uk.ths 07/31/08 12:15:29 [Note]: 10002 3 07/31/08 12:15:29 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13us.adv 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13us.icr 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13us.rul 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\Wt13us.sav 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\wt13us.ths 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WTGEUK.chm 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WTGEUS.chm 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WTPO.chm 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Corel\Shared\Writing Tools\13\WTSPUT.chm 07/31/08 12:15:30 [Note]: 10002 3 07/31/08 12:15:30 [Note]: 10002 2 07/31/08 12:15:30 [Note]: 10002 2 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:34 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:35 [Note]: 10002 3 07/31/08 12:15:36 [Note]: 10002 2 07/31/08 12:15:36 [Note]: 10002 2 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\AdvrCntr3.dll 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\btc-bar.gif 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\logo.gif 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\NeroAPIGlueLayerUnicode.dll 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\NEROINST.DB 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\NeroPatentActivation.exe 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\NeroUpgrade.exe 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\patentactivationfax.htm 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\rollback.db 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NL3\ShellManager3.dll 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Info]: Hidden file: c:\Arquivos de programas\Arquivos comuns\Nero\Shared\NSCLoader.dll 07/31/08 12:17:25 [Note]: 10002 3 07/31/08 12:17:25 [Note]: 10002 2 07/31/08 12:17:25 [Note]: 10002 2 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\Empty.txt 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\Filters.xml 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\news.png 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\paint.png 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\Profiles\Blank.txt 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\Sample1.jpg 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Info]: Hidden file: c:\Arquivos de programas\Movie Maker\Shared\Sample2.jpg 07/31/08 12:20:16 [Note]: 10002 3 07/31/08 12:20:16 [Note]: 10002 2 07/31/08 12:20:16 [Note]: 10002 2 07/31/08 12:33:09 [Note]: 10002 2 07/31/08 12:33:09 [Note]: 10002 2 07/31/08 12:38:36 [Info]: Hidden file: C:\WINDOWS\system32\drivers\hldrrr.exe 07/31/08 12:38:36 [Note]: 10002 2 07/31/08 12:38:36 [Info]: Hidden file: c:\WINDOWS\system32\drivers\srosa.sys 07/31/08 12:38:36 [Note]: 10002 2 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1378662.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1402967.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1478896.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1491013.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1498705.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1508809.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1573222.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1582775.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1623824.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1667878.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1689960.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\1700875.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\718312.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\downld\749077.exe 07/31/08 12:38:54 [Note]: 10002 3 07/31/08 12:38:54 [Note]: 10002 2 07/31/08 12:38:54 [Note]: 10002 2 07/31/08 12:38:54 [Info]: Hidden file: c:\WINDOWS\system32\drivers\mdelk.exe 07/31/08 12:38:54 [Note]: 10002 2 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:30 [Note]: 10002 3 07/31/08 12:39:31 [Note]: 10002 3 07/31/08 12:39:31 [Note]: 10002 3 07/31/08 12:39:31 [Note]: 10002 2 07/31/08 12:39:31 [Note]: 10002 2 07/31/08 12:47:58 [Note]: 7007 0
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#8 (permalink) |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Era o que eu esperava... um Bagle com rootkit.
*Baixe o programa localizado no final da página http://www.zonavirus.com/datos/desca...5/elibagla.asp *Duplo clique em elibagla.exe *Selecione a unidade C:\ e marque a opção Eliminar Ficheros Automaticamente *Clique em Explorar *Ao terminar clique em Salir *Cole o resultado criado em C:\infosat.txt
__________________
Última edição por Wings : 31-07-2008 às 12:19. |
|
|
|
|
|
#9 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, mais uma vez lhe agradeço, ai vai o log do infosat, ele disse que achou:
![]() Depois eu reiniciei e ele fez a varredura por duas vezes, e gerou o log e achou um arquivo infectado e deletou, ai vai o log: Thu Jul 31 13:51:12 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:51:52 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:52:31 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:53:17 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:57:05 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:57:34 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ Nº Total de Directorios: 3827 Nº Total de Ficheros: 41160 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 0 Nº de Ficheros Limpiados: 0 Thu Jul 31 14:14:42 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Reinicie para Completar la Limpieza. Thu Jul 31 14:14:51 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Arquivos de programas\Maxtor\MaxBlast\MAXBLASTMONITOR.EXE --> Eliminado Bagle.dldr Nº Total de Directorios: 3827 Nº Total de Ficheros: 41175 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 1 Nº de Ficheros Limpiados: 1
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#10 (permalink) | |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
1.
*Faça o scan novamente com o F-Secure BlackLight e ao acabar clique em "Next" *Na janela "Step 2: Clean hidden items" selecione o arquivo abaixo: Citação:
*Selecione "Restart now" 2. *Execute novamente o EliBaglA. *Cole o resultado criado em C:\infosat.txt
__________________
|
|
|
|
|
|
|
#11 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, pronto, a maquina andou reiniciando, e todas as vezes o elibagla executa antes de iniciar completamente o windows, e todas as vezes executei o elibagla, ele anda encontrando MAXBLASTMONITOR.EXE e deletando, possivelmente vc verá mais partes coladas além dessa ultima depois que passei o F-secure, ai vai o infosat:
Thu Jul 31 13:51:12 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:51:52 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:52:31 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:53:17 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:57:05 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Restaurada Clave: "SafeBoot\Minimal y Network" Reinicie para Completar la Limpieza. Thu Jul 31 13:57:34 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ Nº Total de Directorios: 3827 Nº Total de Ficheros: 41160 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 0 Nº de Ficheros Limpiados: 0 Thu Jul 31 14:14:42 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Reinicie para Completar la Limpieza. Thu Jul 31 14:14:51 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Arquivos de programas\Maxtor\MaxBlast\MAXBLASTMONITOR.EXE --> Eliminado Bagle.dldr Nº Total de Directorios: 3827 Nº Total de Ficheros: 41175 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 1 Nº de Ficheros Limpiados: 1 Thu Jul 31 14:44:14 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Reinicie para Completar la Limpieza. Thu Jul 31 14:44:23 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Arquivos de programas\Maxtor\MaxBlast\MAXBLASTMONITOR.EXE --> Eliminado Bagle.dldr Nº Total de Directorios: 3827 Nº Total de Ficheros: 41177 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 1 Nº de Ficheros Limpiados: 1 Thu Jul 31 15:07:34 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado. C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado. Reinicie para Completar la Limpieza. Thu Jul 31 15:07:45 2008 EliBagle v11.65 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 30 de Julio del 2008) ---------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Arquivos de programas\Maxtor\MaxBlast\MAXBLASTMONITOR.EXE --> Eliminado Bagle.dldr Nº Total de Directorios: 3827 Nº Total de Ficheros: 41175 Nº de Ficheros Analizados: 11754 Nº de Ficheros Infectados: 1 Nº de Ficheros Limpiados: 1 []´s
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#12 (permalink) |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
É...o EliBaglA não vai resolver isso não.
1. *Delete a ferramenta EliBaglA e o arquivo C:\infosat.txt 2. *Baixe o programa do link e salve-o no Desktop http://download.bleepingcomputer.com/sUBs/ComboFix.exe *Renomei Combofix para Kombo.exe *Feche o Internet Explorer e o Windows Explorer *Duplo-clique no arquivo Kombo.exe *Ao surgir a tela com o título "Disclaimer of Warranty on Software" tecle "1" > ENTER. Pode demorar... *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!! *O ComboFix poderá reiniciar o PC automaticamente *Para parar ou sair do ComboFix, tecle "N" > ENTER *Ao final do procedimento, o programa será fechado automaticamente e será mostrado um log *Cole o resultado criado em C:\ComboFix.txt e novo log do hijack
__________________
|
|
|
|
|
|
#13 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, Estava dando erro no combofix, mas consegui, tive que baixar pelo linux livecd, renomeei com um nome sem extensão e ai no windows renomeei para kombo.exe e funcionou...
ai vai: ComboFix 08-07-31.01 - Maquina3 2008-07-31 16:19:59.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.258 [GMT -3:00] Executando de: C:\downloads\kombo.exe * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))) ) . C:\Arquivos de programas\Maxtor\MaxBlast\MaxBlastMonitor.exe C:\Documents and Settings\Maquina3\Dados de aplicativos\inst.exe C:\WINDOWS\system32\drivers\downld C:\WINDOWS\system32\drivers\downld\1378662.exe C:\WINDOWS\system32\drivers\downld\1402967.exe C:\WINDOWS\system32\drivers\downld\1478896.exe C:\WINDOWS\system32\drivers\downld\1491013.exe C:\WINDOWS\system32\drivers\downld\1498705.exe C:\WINDOWS\system32\drivers\downld\1508809.exe C:\WINDOWS\system32\drivers\downld\1573222.exe C:\WINDOWS\system32\drivers\downld\1582775.exe C:\WINDOWS\system32\drivers\downld\1623824.exe C:\WINDOWS\system32\drivers\downld\1667878.exe C:\WINDOWS\system32\drivers\downld\1689960.exe C:\WINDOWS\system32\drivers\downld\1700875.exe C:\WINDOWS\system32\drivers\downld\718312.exe C:\WINDOWS\system32\drivers\downld\749077.exe C:\WINDOWS\system32\drivers\hldrrr.exe C:\WINDOWS\system32\drivers\mdelk.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_SROSA -------\Service_srosa ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))) . 2008-07-31 16:10 . 2008-07-31 16:07 2,669,820 --------- C:\kombo.exe 2008-07-31 01:53 . 2008-07-31 01:53 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Avira 2008-07-31 01:53 . 2008-07-31 01:53 <DIR> d-------- C:\Arquivos de programas\Avira 2008-07-31 01:20 . 2008-07-31 04:47 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-07-31 00:10 . 2008-07-31 00:11 <DIR> d-------- C:\Arquivos de programas\Java 2008-07-31 00:05 . 2008-07-31 00:05 <DIR> d-------- C:\Arquivos de programas\Panda Security 2008-07-31 00:05 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys 2008-07-30 22:53 . 2008-07-30 22:53 <DIR> d-------- C:\Arquivos de programas\ESET 2008-07-30 20:32 . 2008-07-30 20:32 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-07-30 20:05 . 2008-07-30 20:05 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-07-30 20:05 . 2008-07-30 20:05 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy 2008-07-30 20:04 . 2008-07-30 20:04 <DIR> d-------- C:\Documents and Settings\All Users\.clamwin 2008-07-30 20:04 . 2008-07-30 20:04 <DIR> d-------- C:\Arquivos de programas\ClamWin 2008-07-30 19:33 . 2008-07-30 19:33 <DIR> d-------- C:\Arquivos de programas\Marcos Velasco Security 2008-07-30 19:11 . 2008-07-30 19:12 1,415,658 --------- C:\mvregclean55-br.zip 2008-07-30 19:10 . 2008-07-30 19:10 450,114 --------- C:\RegSeeker.zip 2008-07-30 19:04 . 2008-07-31 15:51 218,112 --a------ C:\HijackThis.exe 2008-07-30 18:28 . 2008-07-30 18:28 268 --ah----- C:\sqmdata19.sqm 2008-07-30 18:28 . 2008-07-30 18:28 244 --ah----- C:\sqmnoopt19.sqm 2008-07-30 18:24 . 2008-07-30 19:48 81,465 --a------ C:\WINDOWS\system32\drivers\klif.cab 2008-07-30 18:23 . 2008-03-03 09:39 31,896,064 --a------ C:\kav.br.msi 2008-07-30 18:23 . 2007-09-05 13:56 2,684,884 --a------ C:\kav7.0pb.pdf 2008-07-30 18:23 . 2008-07-03 12:07 646 --a------ C:\setup.reg 2008-07-30 18:20 . 2008-07-30 18:20 268 --ah----- C:\sqmdata18.sqm 2008-07-30 18:20 . 2008-07-30 18:20 244 --ah----- C:\sqmnoopt18.sqm 2008-07-30 18:09 . 2008-07-31 11:34 120,084 --------- C:\WINDOWS\system32\drivers\SROSA.SYS 2008-07-29 21:28 . 2008-07-29 21:28 268 --ah----- C:\sqmdata17.sqm 2008-07-29 21:28 . 2008-07-29 21:28 244 --ah----- C:\sqmnoopt17.sqm 2008-07-29 20:42 . 2006-01-18 02:03 708,616 --------- C:\WINDOWS\system32\drivers\hldrrr.exe 2008-07-29 16:30 . 2008-07-29 16:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-29 16:30 . 2008-07-29 16:30 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-28 12:29 . 2008-07-28 12:29 268 --ah----- C:\sqmdata16.sqm 2008-07-28 12:29 . 2008-07-28 12:29 244 --ah----- C:\sqmnoopt16.sqm 2008-07-28 11:37 . 2008-07-28 11:59 <DIR> d-------- C:\AMC 2008-07-26 19:29 . 2008-07-26 19:29 268 --ah----- C:\sqmdata15.sqm 2008-07-26 19:29 . 2008-07-26 19:29 244 --ah----- C:\sqmnoopt15.sqm 2008-07-26 18:48 . 2008-07-26 18:48 268 --ah----- C:\sqmdata14.sqm 2008-07-26 18:48 . 2008-07-26 18:48 244 --ah----- C:\sqmnoopt14.sqm 2008-07-26 18:23 . 2008-07-26 18:23 268 --ah----- C:\sqmdata13.sqm 2008-07-26 18:23 . 2008-07-26 18:23 244 --ah----- C:\sqmnoopt13.sqm 2008-07-26 17:17 . 2008-07-26 17:17 <DIR> d-------- C:\Arquivos de programas\TVTool 2008-07-26 14:44 . 2008-07-26 19:47 8 --a------ C:\WINDOWS\system32\nvModes.dat 2008-07-26 13:53 . 2008-07-26 13:53 268 --ah----- C:\sqmdata12.sqm 2008-07-26 13:53 . 2008-07-26 13:53 244 --ah----- C:\sqmnoopt12.sqm 2008-07-26 13:38 . 2008-07-26 13:38 268 --ah----- C:\sqmdata11.sqm 2008-07-26 13:38 . 2008-07-26 13:38 244 --ah----- C:\sqmnoopt11.sqm 2008-07-24 23:16 . 2008-07-24 23:16 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-07-24 13:52 . 2008-07-24 13:52 268 --ah----- C:\sqmdata10.sqm 2008-07-24 13:52 . 2008-07-24 13:52 244 --ah----- C:\sqmnoopt10.sqm 2008-07-24 13:16 . 2008-07-24 13:16 268 --ah----- C:\sqmdata09.sqm 2008-07-24 13:16 . 2008-07-24 13:16 244 --ah----- C:\sqmnoopt09.sqm 2008-07-23 16:04 . 2008-07-23 16:04 21,635 --a------ C:\WINDOWS\FontData.fdb 2008-07-23 15:06 . 2008-07-23 15:06 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Leadertech 2008-07-22 19:37 . 2008-07-22 19:37 268 --ah----- C:\sqmdata08.sqm 2008-07-22 19:37 . 2008-07-22 19:37 244 --ah----- C:\sqmnoopt08.sqm 2008-07-22 14:38 . 2008-07-31 16:22 268 --ah----- C:\sqmdata07.sqm 2008-07-22 14:38 . 2008-07-31 16:22 244 --ah----- C:\sqmnoopt07.sqm 2008-07-22 14:37 . 2008-07-31 15:52 268 --ah----- C:\sqmdata06.sqm 2008-07-22 14:37 . 2008-07-31 15:52 244 --ah----- C:\sqmnoopt06.sqm 2008-07-21 09:28 . 2008-07-31 15:17 268 --ah----- C:\sqmdata05.sqm 2008-07-21 09:28 . 2008-07-31 15:17 244 --ah----- C:\sqmnoopt05.sqm 2008-07-21 09:22 . 2008-07-31 15:05 268 --ah----- C:\sqmdata04.sqm 2008-07-21 09:22 . 2008-07-31 15:05 244 --ah----- C:\sqmnoopt04.sqm 2008-07-16 00:18 . 2008-07-16 00:18 <DIR> d-------- C:\Arquivos de programas\WMP11 Slipstreamer 2008-07-15 20:46 . 2008-07-15 20:46 <DIR> d-------- C:\Arquivos de programas\VirtuallTek 2008-07-15 14:16 . 2008-07-15 14:16 <DIR> d-------- C:\Arquivos de programas\AutoStreamer 2008-07-15 11:53 . 2008-07-18 00:39 <DIR> d-------- C:\Arquivos de programas\nLite 2008-07-14 22:51 . 2008-07-15 10:31 <DIR> d-------- C:\mega 2008-07-14 15:03 . 2008-07-14 15:36 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\JustVoip 2008-07-14 14:44 . 2008-07-14 14:54 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Gizmo5 2008-07-14 09:54 . 2008-07-14 09:54 <DIR> d-------- C:\Arquivos de programas\Lavalys 2008-07-13 14:50 . 2008-07-13 14:50 101 --a------ C:\WINDOWS\CMMIXER.INI 2008-07-12 12:52 . 2008-07-12 12:52 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\MyPhoneExplorer 2008-07-12 12:51 . 2008-07-12 12:52 <DIR> d-------- C:\Arquivos de programas\MyPhoneExplorer 2008-07-12 11:42 . 2008-07-21 20:16 <DIR> d-------- C:\celular 2008-07-11 21:34 . 2008-07-11 21:40 <DIR> d-------- C:\setool2lt 2008-07-10 18:30 . 2008-07-22 11:26 22 --a------ C:\WINDOWS\Kruptos.INI 2008-07-10 18:22 . 2008-07-10 18:22 <DIR> d-------- C:\Arquivos de programas\Kruptos 2008-07-10 16:01 . 2008-07-10 16:01 5,248 --a------ C:\WINDOWS\system32\giveio.sys 2008-07-10 15:53 . 2008-04-13 15:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2008-07-10 15:53 . 2008-04-13 15:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys 2008-07-08 23:06 . 2008-05-09 07:55 180,224 -----c--- C:\WINDOWS\system32\dllcache\scrobj.dll 2008-07-08 23:06 . 2008-05-09 07:55 172,032 -----c--- C:\WINDOWS\system32\dllcache\scrrun.dll 2008-07-08 23:06 . 2008-05-08 08:24 155,648 -----c--- C:\WINDOWS\system32\dllcache\wscript.exe 2008-07-08 23:06 . 2008-05-09 05:45 135,168 -----c--- C:\WINDOWS\system32\dllcache\cscript.exe 2008-07-08 23:06 . 2008-05-09 07:55 90,112 -----c--- C:\WINDOWS\system32\dllcache\wshext.dll 2008-07-08 19:22 . 2008-07-08 19:22 <DIR> d-------- C:\Arquivos de programas\Custom Technology 2008-07-08 18:15 . 2008-07-08 18:17 <DIR> d-------- C:\Arquivos de programas\AviSynth 2.5 2008-07-08 18:11 . 2008-07-08 18:27 <DIR> d-------- C:\Arquivos de programas\AVIXDVD 2008-07-06 00:48 . 2008-07-06 00:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Maxtor 2008-07-06 00:18 . 2008-07-31 13:55 268 --ah----- C:\sqmdata03.sqm 2008-07-06 00:18 . 2008-07-31 13:55 244 --ah----- C:\sqmnoopt03.sqm 2008-07-06 00:14 . 2008-07-31 09:55 268 --ah----- C:\sqmdata02.sqm 2008-07-06 00:14 . 2008-07-31 09:55 244 --ah----- C:\sqmnoopt02.sqm 2008-07-05 21:04 . 2008-07-30 18:49 268 --ah----- C:\sqmdata01.sqm 2008-07-05 21:04 . 2008-07-30 18:49 244 --ah----- C:\sqmnoopt01.sqm 2008-07-05 19:11 . 2008-07-30 18:39 268 --ah----- C:\sqmdata00.sqm 2008-07-05 19:11 . 2008-07-30 18:39 244 --ah----- C:\sqmnoopt00.sqm 2008-07-05 18:54 . 2008-07-05 18:54 400,864 --a------ C:\WINDOWS\system32\drivers\timntr.sys 2008-07-05 18:54 . 2008-07-05 18:54 32,768 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys 2008-07-05 18:53 . 2008-07-05 18:53 120,992 --a------ C:\WINDOWS\system32\drivers\snapman.sys 2008-07-05 18:52 . 2008-07-05 18:52 <DIR> d-------- C:\Arquivos de programas\Maxtor 2008-07-05 18:52 . 2008-07-05 18:53 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Maxtor 2008-07-05 18:36 . 2008-07-05 18:36 <DIR> d--hs---- C:\WINDOWS\ftpcache 2008-06-30 17:33 . 2008-06-30 17:33 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Apple Computer 2008-06-28 19:10 . 2008-07-30 21:13 <DIR> d-------- C:\Musicas Sacras russas 2008-06-28 18:18 . 2006-11-07 09:42 88,560 -ra------ C:\WINDOWS\system32\drivers\w200mgmt.sys 2008-06-28 18:18 . 2006-11-07 09:42 86,368 -ra------ C:\WINDOWS\system32\drivers\w200obex.sys 2008-06-28 18:09 . 2008-06-28 18:09 <DIR> d-------- C:\Arquivos de programas\Disc2Phone 2008-06-28 18:03 . 2008-06-28 18:03 <DIR> d-------- C:\WINDOWS\system32\URTTEMP 2008-06-28 18:01 . 2008-06-28 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer 2008-06-28 18:01 . 2008-06-28 18:02 <DIR> d-------- C:\Arquivos de programas\QuickTime 2008-06-28 17:58 . 2008-07-21 20:03 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\AdobeUM 2008-06-28 17:58 . 2008-06-28 17:58 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\AdobeAUM 2008-06-28 17:53 . 2008-06-28 17:54 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Teleca 2008-06-28 17:53 . 2008-06-28 17:53 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Sony Ericsson 2008-06-28 17:45 . 2006-11-07 05:42 97,056 -ra------ C:\WINDOWS\system32\drivers\w200mdm.sys 2008-06-28 17:45 . 2006-11-07 05:42 9,328 -ra------ C:\WINDOWS\system32\drivers\w200mdfl.sys 2008-06-28 17:45 . 2006-11-07 05:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cmnt.sys 2008-06-28 17:45 . 2006-11-07 05:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cm.sys 2008-06-28 17:44 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Documents 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Teleca 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Sony Ericsson 2008-06-28 17:42 . 2008-07-12 13:02 <DIR> d-------- C:\Arquivos de programas\Sony Ericsson 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Teleca Shared . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2008-07-13 23:29 --------- d-----w C:\Arquivos de programas\Microsoft Works 2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-14 17:34 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-05 15:16 --------- d-----w C:\Arquivos de programas\microsoft frontpage 2008-06-05 15:13 --------- d-----w C:\Arquivos de programas\Serviços on-line 2008-06-05 15:10 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços 2008-04-14 02:21 769,024 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe 2008-04-14 02:21 744,448 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe 2008-04-14 02:21 70,144 ----a-w C:\WINDOWS\notepad.exe 2008-04-14 02:21 32,866 ------w C:\WINDOWS\slrundll.exe 2008-04-14 02:21 287,744 ----a-w C:\WINDOWS\winhlp32.exe 2008-04-14 02:21 18,432 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\hscupd.exe 2008-04-14 02:21 171,520 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe 2008-04-14 02:21 150,528 ----a-w C:\WINDOWS\regedit.exe 2008-04-14 02:21 10,752 ----a-w C:\WINDOWS\hh.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 23:20 15360] "DAEMON Tools Lite"="C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 06:39 486856] "TransBar"="C:\Arquivos de programas\AKSoftware\TransBar\TransBar.exe" [2005-06-01 16:41 65536] "RocketDock"="C:\Arquivos de programas\RocketDock\RocketDock.exe" [2007-09-02 13:58 495616] "MsnMsgr"="C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2008-04-13 23:21 1695232] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 18:07 1828136] "SpybotSD TeaTimer"="C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-31 03:58 2156368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "ISUSPM Startup"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2006-10-22 12:22 86016] "NBKeyScan"="C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 17:29 2221352] "Sony Ericsson PC Suite"="C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744] "Adobe Photo Downloader"="C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2008-06-28 18:02 155648] "AcronisTimounterMonitor"="C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 17:39 1945448] "Acronis Scheduler2 Service"="C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 17:31 148760] "ClamWin"="C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" [2008-07-31 15:42 77824] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-31 15:41 266497] "C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe] "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 23:20 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "VIDC.YV12"= yv12vfw.dll "VIDC.SP54"= SP5X_32.DLL "VIDC.SP55"= SP5X_32.DLL "VIDC.SP56"= SP5X_32.DLL "VIDC.SP57"= SP5X_32.DLL "VIDC.SP58"= SP5X_32.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa] Authentication Packages REG_MULTI_SZ msv1_0 relog_ap [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sacsvr] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sglfb.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\tga.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\wd.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\EMULE BACKUP 230508\\emule.exe"= "C:\\Arquivos de programas\\Miranda IM\\miranda32.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Arquivos de programas\\TVUPlayer\\TVUPlayer.exe"= "C:\\Arquivos de programas\\SopCast\\SopCast.exe"= "C:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"= "C:\\Arquivos de programas\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"= "C:\\Arquivos de programas\\Joost\\xulrunner\\tvprunner.exe"= R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboo t.sys [2008-06-19 17:24] R1 tvtool;tvtool;C:\Arquivos de programas\TVTool\tvtool.sys [1996-04-03 15:33] S2 Ca533av;V3345 Video Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2002-10-21 11:37] S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\WINDOWS\system32\regedt32.exe [2001-10-28 09:07] S3 USBCamera;V3345 Digital Camera;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-12-04 14:38] S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 05:42] S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 05:42] S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 05:42] S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42] S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42] . Conte£do da pasta 'Tarefas Agendadas' . - - - - ORFAOS REMOVIDOS - - - - HKLM-Run-MaxBlastMonitor.exe - C:\Arquivos de programas\Maxtor\MaxBlast\MaxBlastMonitor.exe . ------- Ccan Suplementar ------- . FireFox -: Profile - C:\Documents and Settings\Maquina3\Dados de aplicativos\Mozilla\Firefox\Profiles\qxb9ny7h.defa ult\ FF -: plugin - C:\Arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF -: plugin - C:\Arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF -: plugin - C:\Arquivos de programas\Mozilla Firefox\plugins\npJoostPlugin.dll FF -: plugin - G:\WinXpSP3\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF -: plugin - G:\WinXpSP3\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-31 16:25:33 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************** ************************ . --------------------- DLLs Carregadas Sob os Processos em Execu‡ao --------------------- PROCESSOS: C:\WINDOWS\explorer.exe -> C:\Arquivos de programas\RocketDock\RocketDock.dll . ------------------------ Outros Processos em Execu‡Æo ------------------------ . C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\CapabilityManager.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\Generic.exe . ************************************************** ************************ . Tempo para conclusÆo: 2008-07-31 16:31:25 - Maquina reiniciou ComboFix-quarantined-files.txt 2008-07-31 19:31:17 Pre-Run: 9,657,454,592 bytes disponíveis Post-Run: 9,535,950,848 bytes dispon¡veis 301 --- E O F --- 2008-07-14 12:42:38 __________________________________________________ _______________ E o hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:43:19, on 31/7/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Mixer.exe C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Arquivos de programas\QuickTime\qttask.exe C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\CapabilityManager.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\Generic.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\meapag\scuzi.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe" O4 - HKLM\..\Run: [ClamWin] "C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" --logon O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [TransBar] C:\Arquivos de programas\AKSoftware\TransBar\TransBar.exe /s O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1212683016568 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - http://javadl-esd.sun.com/update/1.5...ndows-i586.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{9D833125-2367-4979-B50E-BE66F66D44FB}: NameServer = 208.67.222.222 208.67.220.220 O17 - HKLM\System\CS1\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe -- End of file - 9268 bytes
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#14 (permalink) | |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Por favor...envie o arquivo abaixo para análise em http://www.virustotal.com
Citação:
__________________
|
|
|
|
|
|
|
#15 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, esse arquivo é o hijackthis que peguei no inicio deste tópico, eu que renomeei com esse nome..rs "licença" em italiano (acho)..rs
[]´s
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#16 (permalink) | |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Pô!!...criativo você hein?...rss
Essa foi boa!! Vamos lá!! *Abra o bloco de notas, selecione, copie e cole nele todo o conteúdo do código abaixo: Citação:
*Arraste o arquivo para o Combofix conforme ilustração abaixo: ![]() *Importante: enquanto o combofix estiver em execução, não use o mouse nem o teclado!! *O ComboFix poderá (não significa que vá!!) reiniciar o PC automaticamente *Para parar ou sair do ComboFix, tecle "N" > ENTER *Ao final do procedimento, o programa será fechado automaticamente e será mostrado um log *Cole o resultado criado em C:\ComboFix.txt junto com novo log do hijack
__________________
|
|
|
|
|
|
|
#17 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings Puxa antes de mais nada muito obrigado pelo trabalhão que vc tem em analisar e dar sugestões para nos... Parabéns pelo seu trabalho... Muito obrigado...
Ps: fiz um teste agora tentando instalar um AV e instalei o ClamWin e esta ativo... creio que se não excluimos ainda esse malware, estamos no caminho certo.. Agora os novos logs: ComboFix 08-07-31.01 - Maquina3 2008-07-31 17:34:51.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.165 [GMT -3:00] Executando de: C:\downloads\kombo.exe Command switches used :: C:\Documents and Settings\Maquina3\Desktop\CFScript.txt * Criado um novo ponto de restauro ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !! FILE :: C:\sqmdata01.sqm C:\sqmdata02.sqm C:\sqmdata03.sqm C:\sqmdata04.sqm C:\sqmdata05.sqm C:\sqmdata06.sqm C:\sqmdata07.sqm C:\sqmdata08.sqm C:\sqmdata09.sqm C:\sqmdata10.sqm C:\sqmdata11.sqm C:\sqmdata12.sqm C:\sqmdata13.sqm C:\sqmdata14.sqm C:\sqmdata15.sqm C:\sqmdata16.sqm C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmdata19.sqm C:\sqmnoopt01.sqm C:\sqmnoopt02.sqm C:\sqmnoopt03.sqm C:\sqmnoopt04.sqm C:\sqmnoopt05.sqm C:\sqmnoopt06.sqm C:\sqmnoopt07.sqm C:\sqmnoopt08.sqm C:\sqmnoopt09.sqm C:\sqmnoopt10.sqm C:\sqmnoopt11.sqm C:\sqmnoopt12.sqm C:\sqmnoopt13.sqm C:\sqmnoopt14.sqm C:\sqmnoopt15.sqm C:\sqmnoopt16.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm C:\sqmnoopt19.sqm C:\WINDOWS\system32\drivers\hldrrr.exe C:\WINDOWS\system32\drivers\SROSA.SYS . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))) ) . C:\sqmdata01.sqm C:\sqmdata02.sqm C:\sqmdata03.sqm C:\sqmdata04.sqm C:\sqmdata05.sqm C:\sqmdata06.sqm C:\sqmdata07.sqm C:\sqmdata08.sqm C:\sqmdata09.sqm C:\sqmdata10.sqm C:\sqmdata11.sqm C:\sqmdata12.sqm C:\sqmdata13.sqm C:\sqmdata14.sqm C:\sqmdata15.sqm C:\sqmdata16.sqm C:\sqmdata17.sqm C:\sqmdata18.sqm C:\sqmdata19.sqm C:\sqmnoopt01.sqm C:\sqmnoopt02.sqm C:\sqmnoopt03.sqm C:\sqmnoopt04.sqm C:\sqmnoopt05.sqm C:\sqmnoopt06.sqm C:\sqmnoopt07.sqm C:\sqmnoopt08.sqm C:\sqmnoopt09.sqm C:\sqmnoopt10.sqm C:\sqmnoopt11.sqm C:\sqmnoopt12.sqm C:\sqmnoopt13.sqm C:\sqmnoopt14.sqm C:\sqmnoopt15.sqm C:\sqmnoopt16.sqm C:\sqmnoopt17.sqm C:\sqmnoopt18.sqm C:\sqmnoopt19.sqm . ((((((((((((((((((((((( Ficheiros criados de 2008-06-28 to 2008-07-31 )))))))))))))))))))))))))))))))) . 2008-07-31 17:23 . 2008-07-31 17:24 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\.clamwin 2008-07-31 16:31 . 2008-07-31 16:31 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configura ções locais 2008-07-31 16:31 . 2008-07-31 16:31 <DIR> d-------- C:\Documents and Settings\Maquina3\Configurações locais 2008-07-31 16:31 . 2008-07-31 16:31 <DIR> d-------- C:\Documents and Settings\NetworkService\Configurações locais 2008-07-31 16:31 . 2008-07-31 16:31 <DIR> d-------- C:\Documents and Settings\LocalService\Configurações locais 2008-07-31 01:53 . 2008-07-31 01:53 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Avira 2008-07-31 01:53 . 2008-07-31 01:53 <DIR> d-------- C:\Arquivos de programas\Avira 2008-07-31 01:20 . 2008-07-31 04:47 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-07-31 00:10 . 2008-07-31 00:11 <DIR> d-------- C:\Arquivos de programas\Java 2008-07-31 00:05 . 2008-07-31 00:05 <DIR> d-------- C:\Arquivos de programas\Panda Security 2008-07-31 00:05 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys 2008-07-30 22:53 . 2008-07-30 22:53 <DIR> d-------- C:\Arquivos de programas\ESET 2008-07-30 20:32 . 2008-07-30 20:32 <DIR> d-------- C:\Arquivos de programas\Trend Micro 2008-07-30 20:05 . 2008-07-31 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-07-30 20:05 . 2008-07-31 17:25 <DIR> d-------- C:\Arquivos de programas\Spybot - Search & Destroy 2008-07-30 20:04 . 2008-07-30 20:04 <DIR> d-------- C:\Documents and Settings\All Users\.clamwin 2008-07-30 20:04 . 2008-07-31 17:23 <DIR> d-------- C:\Arquivos de programas\ClamWin 2008-07-30 19:33 . 2008-07-30 19:33 <DIR> d-------- C:\Arquivos de programas\Marcos Velasco Security 2008-07-30 19:11 . 2008-07-30 19:12 1,415,658 --------- C:\mvregclean55-br.zip 2008-07-30 19:10 . 2008-07-30 19:10 450,114 --------- C:\RegSeeker.zip 2008-07-30 19:04 . 2008-07-31 15:51 218,112 --a------ C:\HijackThis.exe 2008-07-30 18:24 . 2008-07-30 19:48 81,465 --a------ C:\WINDOWS\system32\drivers\klif.cab 2008-07-30 18:23 . 2008-03-03 09:39 31,896,064 --a------ C:\kav.br.msi 2008-07-30 18:23 . 2007-09-05 13:56 2,684,884 --a------ C:\kav7.0pb.pdf 2008-07-30 18:23 . 2008-07-03 12:07 646 --a------ C:\setup.reg 2008-07-29 16:30 . 2008-07-29 16:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-29 16:30 . 2008-07-29 16:30 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-28 11:37 . 2008-07-28 11:59 <DIR> d-------- C:\AMC 2008-07-26 17:17 . 2008-07-26 17:17 <DIR> d-------- C:\Arquivos de programas\TVTool 2008-07-26 14:44 . 2008-07-26 19:47 8 --a------ C:\WINDOWS\system32\nvModes.dat 2008-07-24 23:16 . 2008-07-24 23:16 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe 2008-07-23 16:04 . 2008-07-23 16:04 21,635 --a------ C:\WINDOWS\FontData.fdb 2008-07-23 15:06 . 2008-07-23 15:06 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Leadertech 2008-07-16 00:18 . 2008-07-16 00:18 <DIR> d-------- C:\Arquivos de programas\WMP11 Slipstreamer 2008-07-15 20:46 . 2008-07-15 20:46 <DIR> d-------- C:\Arquivos de programas\VirtuallTek 2008-07-15 14:16 . 2008-07-15 14:16 <DIR> d-------- C:\Arquivos de programas\AutoStreamer 2008-07-15 11:53 . 2008-07-18 00:39 <DIR> d-------- C:\Arquivos de programas\nLite 2008-07-14 22:51 . 2008-07-15 10:31 <DIR> d-------- C:\mega 2008-07-14 15:03 . 2008-07-14 15:36 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\JustVoip 2008-07-14 14:44 . 2008-07-14 14:54 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Gizmo5 2008-07-14 09:54 . 2008-07-14 09:54 <DIR> d-------- C:\Arquivos de programas\Lavalys 2008-07-13 14:50 . 2008-07-13 14:50 101 --a------ C:\WINDOWS\CMMIXER.INI 2008-07-12 12:52 . 2008-07-12 12:52 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\MyPhoneExplorer 2008-07-12 12:51 . 2008-07-12 12:52 <DIR> d-------- C:\Arquivos de programas\MyPhoneExplorer 2008-07-12 11:42 . 2008-07-21 20:16 <DIR> d-------- C:\celular 2008-07-11 21:34 . 2008-07-11 21:40 <DIR> d-------- C:\setool2lt 2008-07-10 18:30 . 2008-07-22 11:26 22 --a------ C:\WINDOWS\Kruptos.INI 2008-07-10 18:22 . 2008-07-10 18:22 <DIR> d-------- C:\Arquivos de programas\Kruptos 2008-07-10 16:01 . 2008-07-10 16:01 5,248 --a------ C:\WINDOWS\system32\giveio.sys 2008-07-10 15:53 . 2008-04-13 15:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2008-07-10 15:53 . 2008-04-13 15:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys 2008-07-08 23:06 . 2008-05-09 07:55 180,224 -----c--- C:\WINDOWS\system32\dllcache\scrobj.dll 2008-07-08 23:06 . 2008-05-09 07:55 172,032 -----c--- C:\WINDOWS\system32\dllcache\scrrun.dll 2008-07-08 23:06 . 2008-05-08 08:24 155,648 -----c--- C:\WINDOWS\system32\dllcache\wscript.exe 2008-07-08 23:06 . 2008-05-09 05:45 135,168 -----c--- C:\WINDOWS\system32\dllcache\cscript.exe 2008-07-08 23:06 . 2008-05-09 07:55 90,112 -----c--- C:\WINDOWS\system32\dllcache\wshext.dll 2008-07-08 19:22 . 2008-07-08 19:22 <DIR> d-------- C:\Arquivos de programas\Custom Technology 2008-07-08 18:15 . 2008-07-08 18:17 <DIR> d-------- C:\Arquivos de programas\AviSynth 2.5 2008-07-08 18:11 . 2008-07-08 18:27 <DIR> d-------- C:\Arquivos de programas\AVIXDVD 2008-07-06 00:48 . 2008-07-06 00:48 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Maxtor 2008-07-05 19:11 . 2008-07-30 18:39 268 --ah----- C:\sqmdata00.sqm 2008-07-05 19:11 . 2008-07-30 18:39 244 --ah----- C:\sqmnoopt00.sqm 2008-07-05 18:54 . 2008-07-05 18:54 400,864 --a------ C:\WINDOWS\system32\drivers\timntr.sys 2008-07-05 18:54 . 2008-07-05 18:54 32,768 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys 2008-07-05 18:53 . 2008-07-05 18:53 120,992 --a------ C:\WINDOWS\system32\drivers\snapman.sys 2008-07-05 18:52 . 2008-07-05 18:52 <DIR> d-------- C:\Arquivos de programas\Maxtor 2008-07-05 18:52 . 2008-07-05 18:53 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Maxtor 2008-07-05 18:36 . 2008-07-05 18:36 <DIR> d--hs---- C:\WINDOWS\ftpcache 2008-06-30 17:33 . 2008-06-30 17:33 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Apple Computer 2008-06-28 19:10 . 2008-07-30 21:13 <DIR> d-------- C:\Musicas Sacras russas 2008-06-28 18:18 . 2006-11-07 09:42 88,560 -ra------ C:\WINDOWS\system32\drivers\w200mgmt.sys 2008-06-28 18:18 . 2006-11-07 09:42 86,368 -ra------ C:\WINDOWS\system32\drivers\w200obex.sys 2008-06-28 18:09 . 2008-06-28 18:09 <DIR> d-------- C:\Arquivos de programas\Disc2Phone 2008-06-28 18:03 . 2008-06-28 18:03 <DIR> d-------- C:\WINDOWS\system32\URTTEMP 2008-06-28 18:01 . 2008-06-28 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Apple Computer 2008-06-28 18:01 . 2008-06-28 18:02 <DIR> d-------- C:\Arquivos de programas\QuickTime 2008-06-28 17:58 . 2008-07-21 20:03 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\AdobeUM 2008-06-28 17:58 . 2008-06-28 17:58 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\AdobeAUM 2008-06-28 17:53 . 2008-06-28 17:54 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Teleca 2008-06-28 17:53 . 2008-06-28 17:53 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Sony Ericsson 2008-06-28 17:45 . 2006-11-07 05:42 97,056 -ra------ C:\WINDOWS\system32\drivers\w200mdm.sys 2008-06-28 17:45 . 2006-11-07 05:42 9,328 -ra------ C:\WINDOWS\system32\drivers\w200mdfl.sys 2008-06-28 17:45 . 2006-11-07 05:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cmnt.sys 2008-06-28 17:45 . 2006-11-07 05:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cm.sys 2008-06-28 17:44 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Documents 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Teleca 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Sony Ericsson 2008-06-28 17:42 . 2008-07-12 13:02 <DIR> d-------- C:\Arquivos de programas\Sony Ericsson 2008-06-28 17:42 . 2008-06-28 17:44 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Teleca Shared 2008-06-28 17:41 . 2006-11-07 05:42 61,504 -ra------ C:\WINDOWS\system32\drivers\w200bus.sys 2008-06-28 17:41 . 2006-11-07 05:42 5,840 -ra------ C:\WINDOWS\system32\drivers\w200whnt.sys 2008-06-28 17:41 . 2006-11-07 05:42 5,840 -ra------ C:\WINDOWS\system32\drivers\w200wh.sys 2008-06-28 17:40 . 2008-07-05 18:36 <DIR> d-------- C:\WINDOWS\Downloaded Installations 2008-06-26 03:01 . 2008-06-26 03:01 <DIR> d-------- C:\Arquivos de programas\MSXML 4.0 2008-06-26 00:09 . 2008-07-28 04:55 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Joost 2008-06-26 00:08 . 2008-06-26 00:09 <DIR> d-------- C:\Arquivos de programas\Joost 2008-06-25 22:58 . 2008-06-25 22:59 <DIR> d-------- C:\Arquivos de programas\SopCast 2008-06-25 22:43 . 2008-06-25 22:43 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\TVU Networks 2008-06-25 22:43 . 2008-06-25 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\TVU Networks 2008-06-25 22:37 . 2008-06-25 22:37 <DIR> d-------- C:\Documents and Settings\Maquina3\LocalLow 2008-06-25 22:37 . 2008-06-25 22:37 <DIR> d-------- C:\Arquivos de programas\TVUPlayer 2008-06-25 22:29 . 2008-06-25 22:29 <DIR> d-------- C:\Arquivos de programas\URUSoft 2008-06-22 21:05 . 2008-04-13 15:39 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2008-06-22 21:05 . 2008-04-13 15:39 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys 2008-06-22 20:57 . 2008-06-22 20:57 <DIR> d-------- C:\Arquivos de programas\Vivitar 2008-06-22 20:57 . 2008-06-22 20:57 <DIR> d-------- C:\Arquivos de programas\directx 2008-06-22 20:57 . 2002-10-21 11:37 515,803 --a------ C:\WINDOWS\system32\drivers\Ca533av.sys 2008-06-22 20:57 . 2002-01-19 15:33 131,072 --a------ C:\WINDOWS\system32\SP5X_32.DLL 2008-06-22 20:57 . 2002-01-19 15:33 131,072 --a------ C:\WINDOWS\system\SP5X_32.DLL 2008-06-22 20:57 . 2002-07-30 19:40 16,384 --a------ C:\WINDOWS\system32\Dext533.ax 2008-06-22 20:57 . 2002-12-04 14:38 11,144 --a------ C:\WINDOWS\system32\drivers\Bulk533.sys 2008-06-22 20:57 . 2004-01-08 15:17 1,876 --a------ C:\WINDOWS\CA533A.INI 2008-06-22 20:52 . 2008-04-13 15:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2008-06-22 20:52 . 2008-04-13 15:45 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2008-06-20 18:31 . 2008-06-20 18:31 <DIR> d-------- C:\Documents and Settings\Maquina3\Dados de aplicativos\Alien Skin 2008-06-20 14:48 . 2008-06-20 14:48 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 14:48 . 2008-06-20 14:48 147,968 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 08:51 . 2008-06-20 08:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 08:40 . 2008-06-20 08:40 138,496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 08:08 . 2008-06-20 08:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-19 23:19 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-06-19 23:19 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2008-06-19 23:19 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-06-19 14:06 . 2008-06-20 13:55 <DIR> d-------- C:\Documents and Settings\Maquina3\Contacts . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2008-07-13 23:29 --------- d-----w C:\Arquivos de programas\Microsoft Works 2008-06-20 17:48 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-18 20:37 2,045,459 ----a-w C:\WINDOWS\system32\x264vfw.dll 2008-06-14 17:34 272,384 ------w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-06 18:19 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2008-06-05 15:16 --------- d-----w C:\Arquivos de programas\microsoft frontpage 2008-06-05 15:13 --------- d-----w C:\Arquivos de programas\Serviços on-line 2008-06-05 15:10 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços 2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll 2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll 2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll 2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll 2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll 2008-05-09 08:45 135,168 ----a-w C:\WINDOWS\system32\cscript.exe 2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe 2008-05-07 05:11 1,292,800 ----a-w C:\WINDOWS\system32\quartz.dll 2008-04-23 07:14 826,368 ----a-w C:\WINDOWS\system32\wininet.dll 2008-04-14 02:37 1,804 ----a-w C:\WINDOWS\system32\dcache.bin 2008-04-14 02:24 332,800 ----a-w C:\WINDOWS\system32\netsetup.exe 2008-04-14 02:20 99,840 ----a-w C:\WINDOWS\system32\winscard.dll 2008-04-14 02:19 763,392 ----a-w C:\WINDOWS\system32\winntbbu.dll 2008-04-14 02:19 57,375 ----a-w C:\WINDOWS\system32\odbcji32.dll 2008-04-14 02:19 5,632 ----a-w C:\WINDOWS\system32\wmi.dll 2008-04-14 02:19 102,912 ----a-w C:\WINDOWS\system32\dpcdll.dll 2008-04-14 02:01 2,193,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe 2008-04-14 02:00 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll 2008-04-14 02:00 2,070,144 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe 2008-04-14 01:58 86,016 ------w C:\WINDOWS\system32\msxml6r.dll 2008-04-14 01:57 80,896 ------w C:\WINDOWS\system32\msshavmsg.dll 2008-04-14 01:56 49,664 ----a-w C:\WINDOWS\system32\inetres.dll 2008-04-14 01:55 563,712 ----a-w C:\WINDOWS\system32\shdoclc.dll 2008-04-14 01:54 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll 2008-04-14 01:54 1,845,760 ----a-w C:\WINDOWS\system32\win32k.sys 2008-04-14 01:53 67,584 ----a-w C:\WINDOWS\system32\browselc.dll 2008-04-13 22:21 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe 2008-04-13 22:20 995,328 ----a-w C:\WINDOWS\system32\setupapi.dll 2008-04-13 22:20 424,448 ----a-w C:\WINDOWS\system32\licdll.dll 2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys 2008-04-13 18:43 9,728 ------w C:\WINDOWS\system32\comsdupd.exe 2008-04-13 18:43 12,800 ----a-w C:\WINDOWS\system32\spiisupd.exe 2008-04-13 18:40 444,928 ----a-w C:\WINDOWS\system32\xpob2res.dll 2008-04-13 18:35 2,945,536 ----a-w C:\WINDOWS\system32\xpsp2res.dll 2008-04-13 18:35 192,512 ----a-w C:\WINDOWS\system32\xpsp1res.dll 2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll 2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll 2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll 2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll 2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll 2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll 2008-04-13 16:48 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll 2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll 2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll 2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 23:20 15360] "DAEMON Tools Lite"="C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 06:39 486856] "TransBar"="C:\Arquivos de programas\AKSoftware\TransBar\TransBar.exe" [2005-06-01 16:41 65536] "RocketDock"="C:\Arquivos de programas\RocketDock\RocketDock.exe" [2007-09-02 13:58 495616] "MsnMsgr"="C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184] "MSMSGS"="C:\Arquivos de programas\Messenger\msmsgs.exe" [2008-04-13 23:21 1695232] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 18:07 1828136] "SpybotSD TeaTimer"="C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "ISUSPM Startup"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "ISUSScheduler"="C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray. dll" [2006-10-22 12:22 86016] "NBKeyScan"="C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 17:29 2221352] "Sony Ericsson PC Suite"="C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744] "Adobe Photo Downloader"="C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2008-06-28 18:02 155648] "AcronisTimounterMonitor"="C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 17:39 1945448] "Acronis Scheduler2 Service"="C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 17:31 148760] "ClamWin"="C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" [2008-06-14 14:13 77824] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-31 15:41 266497] "C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe] "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 23:20 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3fhg"= mp3fhg.acm "msacm.divxa32"= divxa32.acm "VIDC.X264"= x264vfw.dll "VIDC.HFYU"= huffyuv.dll "vidc.i263"= i263_32.drv "VIDC.YV12"= yv12vfw.dll "VIDC.SP54"= SP5X_32.DLL "VIDC.SP55"= SP5X_32.DLL "VIDC.SP56"= SP5X_32.DLL "VIDC.SP57"= SP5X_32.DLL "VIDC.SP58"= SP5X_32.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa] Authentication Packages REG_MULTI_SZ msv1_0 relog_ap [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sacsvr] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sglfb.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\tga.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\wd.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\EMULE BACKUP 230508\\emule.exe"= "C:\\Arquivos de programas\\Miranda IM\\miranda32.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Arquivos de programas\\TVUPlayer\\TVUPlayer.exe"= "C:\\Arquivos de programas\\SopCast\\SopCast.exe"= "C:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"= "C:\\Arquivos de programas\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"= "C:\\Arquivos de programas\\Joost\\xulrunner\\tvprunner.exe"= R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboo t.sys [2008-06-19 17:24] R1 tvtool;tvtool;C:\Arquivos de programas\TVTool\tvtool.sys [1996-04-03 15:33] S2 Ca533av;V3345 Video Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2002-10-21 11:37] S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\WINDOWS\system32\regedt32.exe [2001-10-28 09:07] S3 USBCamera;V3345 Digital Camera;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-12-04 14:38] S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 05:42] S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 05:42] S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 05:42] S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42] S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42] *Newly Created Service* - AVGIO . Conte£do da pasta 'Tarefas Agendadas' . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-31 17:39:30 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************** ************************ . --------------------- DLLs Carregadas Sob os Processos em Execu‡ao --------------------- PROCESSOS: C:\WINDOWS\explorer.exe -> C:\Arquivos de programas\RocketDock\RocketDock.dll . ------------------------ Outros Processos em Execu‡Æo ------------------------ . C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\CapabilityManager.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\Generic.exe . ************************************************** ************************ . Tempo para conclusÆo: 2008-07-31 17:44:51 - Maquina reiniciou ComboFix-quarantined-files.txt 2008-07-31 20:44:43 ComboFix2.txt 2008-07-31 19:31:26 Pre-Run: 9,441,103,872 bytes disponíveis Post-Run: 9,429,413,888 bytes dispon¡veis 394 --- E O F --- 2008-07-14 12:42:38 __________________________________________________ _______________ Do Hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:53:26, on 31/7/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Mixer.exe C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Arquivos de programas\QuickTime\qttask.exe C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe C:\Arquivos de programas\ClamWin\bin\ClamTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe C:\Arquivos de programas\RocketDock\RocketDock.exe C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\CapabilityManager.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\Arquivos comuns\Teleca Shared\Generic.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\meapag\scuzi.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Arquivos de programas\Maxtor\MaxBlast\TimounterMonitor.exe O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedhlp.exe" O4 - HKLM\..\Run: [ClamWin] "C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" --logon O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [TransBar] C:\Arquivos de programas\AKSoftware\TransBar\TransBar.exe /s O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1212683016568 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - http://javadl-esd.sun.com/update/1.5...ndows-i586.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{9D833125-2367-4979-B50E-BE66F66D44FB}: NameServer = 208.67.222.222 208.67.220.220 O17 - HKLM\System\CS1\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS3\Services\Tcpip\..\{05E090BC-5C5A-43B6-AF3B-BA9A052F3D12}: NameServer = 208.67.222.222,208.67.220.220 O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Arquivos de programas\Arquivos comuns\Maxtor\Schedule2\schedul2.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe -- End of file - 9417 bytes
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#18 (permalink) |
|
Highlander
Registrado em: Apr 2007
Mensagens: 15.642
Reputação: 2819
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
OK...logs limpos.
1. *Vá em Iniciar > Executar > digite: Combofix /u *Clique OK *Delete a pasta C:\Qoobox e o arquivo C:\combofix.txt, se ainda existirem. 2. *Delete a ferramenta F-Secure BlackLight e o log criado pela mesma. 3. *Baixe o programa do link e salve-o numa pasta específica http://www.atribune.org/ccount/click.php?id=1 *Duplo clique em ATF-Cleaner.exe *Em Main selecione "Select all" *Clique em Empty Selected =>Caso use Firefox, também, siga os procedimentos abaixo: *Em Firefox clique em "Select all" ( se você deseja manter suas passwords clique em No, caso contrário clique Yes). *Clique "Empty Selected" ( se você deseja manter suas passwords clique em No, caso contrário clique Yes). *Clique em Exit ou no X para sair do programa 4. *Faça o download e instale a última versão do CCleaner (na instalação desmarque a opção de instalar Yahoo toolbar): http://filehippo.com/download_ccleaner/ *Abra o programa e clique em Executar Limpeza; *Após isto, clique em Registro -> Procurar erros -> Corrigir Erros Selecionados -> Corrigir Todos os Erros Selecionados Use regularmente os programas ATF-Cleaner e CCleaner para manter o PC em ordem. Um abraço. PS. Renomei o hijack, caso contrário pensarão que é algum novo vírus no pedaço!!...rss
__________________
|
|
|
|
|
|
#19 (permalink) |
|
Membro Senior
Registrado em: Jan 2005
Mensagens: 436
Reputação: 40
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wings, Agradeço muitíssimo sua ajuda, sem a qual eu não teria conseguido... E parabéns pelo trabalho... muito obrigado!!
Eu já usava o Ccleaner, não conhecia o ATF, mas já esta aqui para ser usado sempre... Bom agora vou instalar um antivirus, vou de Antivir, a peça rara que usa esse computador gostava do AVG .. Mas parece que dos gratuitos o antivir esta melhorzinho atualmente.. vou testar aqui.. ah pode deixar que renomeio o hijack, agora ele aceitou ficar com seu nome original..rs Muito obrigado e parabéns pelo trabalhão que vc tem!! []´s
__________________
AT/286 16 MHZ 2 MB memória RAM MS-DOS HD 40 MB Video CGA Disquete 5/4 principal jogo prince of persia... ano 1987 bons tempos...rs ___________________ lembram do TK2000...rs |
|
|
|
|
|
#20 (permalink) |
|
Newbie
Registrado em: Oct 2008
Mensagens: 1
Reputação: 0
![]() |
Running processes:
C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cmpe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\WZCBDL Service\WZCBDLS.exe C:\WINDOWS\sm56hlpr.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Ahead\InCD\InCD.exe C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\D-Link\Air Utility\AirCFG.exe C:\WINDOWS\ZSSnp211.exe C:\WINDOWS\Domino.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Orbitdownloader\orbitdm.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Arquivos de programas\Orbitdownloader\orbitnet.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Documents and Settings\Júnior\Configurações locais\Temp\_AZTMP0_\Exec\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Arquivos de programas\Orbitdownloader\GrabPro.dll O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Arquivos de programas\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [D-Link Air Utility] C:\Arquivos de programas\D-Link\Air Utility\AirCFG.exe O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe O4 - HKLM\..\Run: [64 inter flaw hold] C:\Documents and Settings\All Users\Dados de aplicativos\Mode Rule 64 Inter\frag cdrom.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Trans poll] C:\DOCUME~1\JNIOR~1\DADOSD~1\SETTIN~1\License heck.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Orbit.lnk = C:\Arquivos de programas\Orbitdownloader\orbitdm.exe O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Analisar com LeechGet - file://C:\Arquivos de programas\LeechGet 2007\\Parser.html O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202 O8 - Extra context menu item: Download usando Assistente LeechGet - file://C:\Arquivos de programas\LeechGet 2007\\Wizard.html O8 - Extra context menu item: Download usando LeechGet - file://C:\Arquivos de programas\LeechGet 2007\\AddUrl.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01...s/MSNPUpld.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JS...ws-i586-jc.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Arquivos de programas\WZCBDL Service\WZCBDLS.exe -- End of file - 10584 bytes |
|
|
|
![]() |
| Opções do Tópico | |
|
|