aqui segue combofixQUOTE]ComboFix 10-05-20.07 - Hilton 21/05/2010 0:30.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.446.37 [GMT -3:00]
Executando de: c:\documents and settings\Hilton\Meus documentos\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
A cópia de c:\windows\system32\userinit.exe foi encontrada e desinfectada
Cópia restaurada de - c:\windows\ServicePackFiles\i386\userinit.exe
.
(((((((((((((((( Arquivos/Ficheiros criados de 2010-04-21 to 2010-05-21 ))))))))))))))))))))))))))))
.
2010-05-21 02:59 . 2008-05-09 10:55 90112 -c----w- c:\windows\system32\dllcache\wshext.dll
2010-05-21 02:59 . 2008-05-09 10:55 180224 -c----w- c:\windows\system32\dllcache\scrobj.dll
2010-05-21 02:59 . 2008-05-09 10:55 172032 -c----w- c:\windows\system32\dllcache\scrrun.dll
2010-05-21 02:59 . 2008-05-09 08:45 135168 -c----w- c:\windows\system32\dllcache\cscript.exe
2010-05-21 02:59 . 2008-05-08 11:24 155648 -c----w- c:\windows\system32\dllcache\wscript.exe
2010-05-20 23:46 . 2010-05-20 23:46 -------- d-sh--w- c:\documents and settings\Hilton\PrivacIE
2010-05-20 23:46 . 2008-06-14 17:34 272384 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-05-20 23:46 . 2010-05-20 23:46 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-20 23:46 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-05-20 23:45 . 2008-10-15 16:36 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-05-20 23:40 . 2010-05-20 23:40 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-05-20 23:35 . 2010-05-20 23:35 -------- d-----w- c:\windows\l2schemas
2010-05-20 23:35 . 2010-05-20 23:35 -------- d-----w- c:\windows\system32\bits
2010-05-20 22:54 . 2010-05-20 22:54 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-05-20 22:54 . 2010-05-20 22:54 -------- d-sh--w- c:\documents and settings\Hilton\IETldCache
2010-05-20 22:49 . 2010-02-25 06:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-05-20 22:49 . 2010-02-25 06:17 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-05-20 22:49 . 2010-02-25 06:17 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-05-20 22:49 . 2010-02-25 14:47 11070976 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-05-20 22:49 . 2010-02-25 06:17 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-20 22:49 . 2010-02-25 06:17 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-05-20 22:49 . 2010-05-21 03:04 -------- d-----w- c:\windows\ie8updates
2010-05-20 22:48 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-05-20 22:47 . 2010-05-20 22:48 -------- dc-h--w- c:\windows\ie8
2010-05-18 19:35 . 2010-05-20 23:31 -------- d-----w- c:\windows\ServicePackFiles
2010-05-18 18:07 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-05-18 18:06 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-18 18:06 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-05-18 18:04 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-05-18 18:04 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-05-18 18:04 . 2010-02-17 17:07 2194176 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-18 18:04 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-05-18 18:04 . 2009-03-06 14:20 286208 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-05-18 18:04 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-05-18 18:04 . 2009-02-09 10:53 683520 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-05-18 18:04 . 2009-02-09 10:53 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-05-18 18:04 . 2009-02-09 10:53 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-05-18 18:03 . 2009-06-25 08:27 732672 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-05-18 18:03 . 2009-02-09 10:53 730624 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-05-18 18:03 . 2009-02-09 10:53 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-05-18 18:03 . 2010-02-16 19:07 2150400 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-18 18:03 . 2010-02-16 19:07 2028544 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-18 17:53 . 2008-04-21 21:15 216064 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-05-18 15:47 . 2010-03-06 14:28 1030144 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.2.9.exe
2010-05-18 15:47 . 2010-02-17 13:48 432640 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.2.9.scr
2010-05-18 15:47 . 2010-05-20 22:14 -------- dc----w- c:\arquivos de programas\MyDefrag v4.2.9
2010-05-18 15:06 . 2010-05-18 17:17 -------- d-----w- c:\documents and settings\Hilton\Dados de aplicativos\GetRightToGo
2010-05-18 14:51 . 2010-05-18 14:54 305322 -c--a-w- C:\BdUninstallTool2010.05.18-11.51.27.reg
2010-05-18 01:42 . 2010-05-18 01:42 2486272 -c--a-w- C:\BitDefender_Uninstall_Tool.exe
2010-05-18 00:09 . 2010-05-18 01:17 -------- dc----w- C:\MyDefrag v4.2.9
2010-05-18 00:08 . 2010-05-18 00:08 2068304 -c--a-w- C:\MyDefrag-v4.2.9.exe
2010-05-17 18:54 . 2010-05-17 18:54 -------- dc----w- C:\CCleaner
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-21 11:00 . 2009-04-27 23:08 -------- dc----w- c:\arquivos de programas\DNA
2010-05-21 11:00 . 2009-04-27 23:08 -------- d-----w- c:\documents and settings\Hilton\Dados de aplicativos\DNA
2010-05-21 03:08 . 2001-10-28 12:07 79022 ----a-w- c:\windows\system32\perfc016.dat
2010-05-21 03:08 . 2001-10-28 12:07 468108 ----a-w- c:\windows\system32\perfh016.dat
2010-05-18 17:27 . 2007-11-30 05:00 -------- dc----w- c:\arquivos de programas\Windows Live Favorites
2010-05-18 17:27 . 2007-10-23 01:43 -------- dc----w- c:\arquivos de programas\Windows Live Toolbar
2010-05-18 17:27 . 2007-08-07 03:25 -------- d-----w- c:\arquivos de programas\The Weather Channel FW
2010-05-18 17:27 . 2007-08-01 19:37 -------- d-----w- c:\arquivos de programas\Serviços on-line
2010-05-18 17:27 . 2007-10-24 02:54 -------- dc----w- c:\arquivos de programas\MSXML 4.0
2010-05-18 17:27 . 2007-10-19 14:51 -------- dc----w- c:\arquivos de programas\QuickTime
2010-05-18 17:27 . 2007-08-02 03:55 -------- d-----w- c:\arquivos de programas\MSN Messenger
2010-05-18 15:21 . 2008-09-28 22:47 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy
2010-05-07 17:43 . 2007-08-02 02:29 -------- d-----w- c:\documents and settings\Hilton\Dados de aplicativos\uTorrent
2010-04-29 23:01 . 2010-01-19 20:19 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-08 21:22 . 2008-11-28 17:21 -------- dc----w- c:\arquivos de programas\Vuze
2010-04-08 21:22 . 2008-11-28 17:22 -------- d-----w- c:\documents and settings\Hilton\Dados de aplicativos\Azureus
2010-04-08 14:47 . 2008-10-29 21:44 -------- dc----w- c:\arquivos de programas\WinAVIVideoConverter
2010-04-01 00:43 . 2007-08-02 02:29 -------- d-----w- c:\documents and settings\Hilton\Dados de aplicativos\LimeWire
2010-03-10 06:16 . 2004-08-04 03:45 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:17 . 2004-08-04 03:45 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-04 02:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-10-13 01:04 . 2009-10-13 01:04 2012 -c--a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.InstallState
2008-12-01 16:32 . 2009-05-08 01:11 89872 -c--a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.Communication.dll
2008-12-01 16:32 . 2008-12-01 16:32 99088 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Common.dll
2008-12-01 16:32 . 2009-05-08 01:11 1272080 -c--a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.exe
2008-12-01 16:32 . 2008-12-01 16:32 80656 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.Updater.exe
2008-12-01 16:32 . 2009-05-08 01:11 25872 -c--a-w- c:\arquivos de programas\DriversHQ.DriverDetective.ExceptionLogging.dll
2008-12-01 16:32 . 2008-12-01 16:32 20240 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.ExceptionLogging.XmlSerializers.dll
2008-12-01 16:32 . 2008-12-01 16:32 36112 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.ExceptionLogging.dll
2008-12-01 16:32 . 2008-12-01 16:32 120080 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.Communication.XmlSerializers.dll
2008-12-01 16:01 . 2008-12-01 16:01 28672 ----a-w- c:\arquivos de programas\Microsoft.ApplicationBlocks.Updater.Downloaders.dll
2008-12-01 16:01 . 2008-12-01 16:01 61440 ----a-w- c:\arquivos de programas\Microsoft.ApplicationBlocks.Updater.ActivationProcessors.dll
2008-12-01 16:01 . 2008-12-01 16:01 118784 ----a-w- c:\arquivos de programas\Microsoft.ApplicationBlocks.Updater.dll
2008-12-01 16:01 . 2008-12-01 16:01 69632 ----a-w- c:\arquivos de programas\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.dll
2008-12-01 16:00 . 2008-12-01 16:00 90112 ----a-w- c:\arquivos de programas\Microsoft.Practices.EnterpriseLibrary.Common.dll
2008-11-18 14:25 . 2008-11-18 14:25 53568 -c--a-w- c:\arquivos de programas\DriverDetective.chm
2008-11-07 17:28 . 2008-11-07 17:28 3569 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.Updater.exe.config
2008-11-07 17:25 . 2008-11-07 17:25 5282 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.exe.config
2008-10-20 15:15 . 2008-10-20 15:15 46592 ----a-w- c:\arquivos de programas\Microsoft.Practices.ObjectBuilder.dll
2008-08-25 09:41 . 2008-08-25 09:41 33040 ----a-w- c:\arquivos de programas\DriversHQ.DriverDetective.Client.DirectX.dll
2008-08-18 10:01 . 2008-08-18 10:01 36864 ----a-w- c:\arquivos de programas\Interop.WindowsInstaller.dll
2008-08-14 14:23 . 2008-08-14 14:23 49152 ----a-w- c:\arquivos de programas\XPBurnComponent.dll
2007-12-21 17:08 . 2007-12-21 17:07 18500624 -c--a-w- c:\arquivos de programas\setupeng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 -c--a-w- c:\arquivos de programas\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 -c--a-w- c:\arquivos de programas\mozilla firefox\plugins\ssldivx.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\arquivos de programas\DNA\btdna.exe" [2009-11-13 323392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
Microsoft Office.lnk - c:\arquivos de programas\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Hilton\\Desktop\\utorrent.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\Vuze\\Azureus.exe"=
"c:\\Arquivos de programas\\DNA\\btdna.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Hilton\\desktop\\Ares.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [10/12/2009 11:26 108289]
R2 ASKService;ASKService;c:\arquivos de programas\AskBarDis\bar\bin\AskService.exe [28/11/2008 14:22 464264]
S0 263131f1703d78a6b114931ecc53b127;263131f1703d78a6b114931ecc53b127;c:\windows\system32\263131f1703d78a6b114931ecc53b127.sys --> c:\windows\system32\263131f1703d78a6b114931ecc53b127.sys [?]
S1 81823764;81823764;c:\windows\system32\drivers\81823764.sys [21/3/2009 01:48 0]
S1 91d6bdbd;91d6bdbd;c:\windows\system32\drivers\91d6bdbd.sys [20/3/2009 21:02 0]
S1 92228175;92228175;c:\windows\system32\drivers\92228175.sys [9/3/2009 20:01 0]
S2 ASKUpgrade;ASKUpgrade;c:\arquivos de programas\AskBarDis\bar\bin\ASKUpgrade.exe [28/11/2008 14:22 234888]
S2 gupdate1ca1176eff4e0a;Google Update Service (gupdate1ca1176eff4e0a);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [30/7/2009 21:30 133104]
S2 YOxie;YOxie;c:\windows\System32\svchost.exe -k netsvcs [4/8/2004 00:45 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
YOxie
.
Conteúdo da pasta 'Tarefas Agendadas'
2010-05-21 c:\windows\Tasks\GlaryInitialize.job
- c:\arquivos de programas\Glary Utilities\initialize.exe [2009-04-27 16:22]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-07-31 00:29]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-07-31 00:29]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://uol.com.br/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-21 08:00
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'explorer.exe'(2064)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe
c:\arquivos de programas\Bonjour\mDNSResponder.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\windows\system32\wdfmgr.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
.
**************************************************************************
.
Tempo para conclusão: 2010-05-21 08:08:45 - Máquina reiniciou
ComboFix-quarantined-files.txt 2010-05-21 11:08
ComboFix2.txt 2010-05-18 17:44
Pré-execução: 5.617.098.752 bytes disponíveis
Pós execução: 5.608.259.584 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=4 Default=4 Failed=3 LastKnownGood=6 Sets=1,2,3,4,6
- - End Of File - - 6DE81C46EBB5FAADAEB33C07EEFEE31D
[/QUOTE]

samy620
Membro Junior
Registrado
67 Mensagens
2 Curtidas