Here's Combofix...
ComboFix.txt 27.29KB
131 downloadsbut did you mean OTL or OTS??
ComboFix 09-08-31.04 - Administrador 01/09/2009 13:24.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.991.567 [GMT -3:00]
Executando de: c:\documents and settings\Administrador\Desktop\Combo-Fix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Criado um novo ponto de restauração
.
ADS - drivers: deleted 204 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\arquivos de programas\ActivationManager
c:\arquivos de programas\ActivationManager\SaveData.dat
c:\arquivos de programas\ActivationManager\Uninstall.exe
c:\windows\Installer\1f577.msi
c:\windows\Installer\1f8853.msp
c:\windows\Installer\218168.msp
c:\windows\Installer\27102.msi
c:\windows\Installer\30149.msp
c:\windows\Installer\5222c.msp
c:\windows\system32\drivers\UACtymyrobqji.sys
c:\windows\system32\Plugins
c:\windows\system32\Plugins\ml\ml_pmp_device_Icaro - BASE LIBA.ini
c:\windows\system32\sfcfiles.dll
c:\windows\system32\UACbqmivxtqbd.dat
c:\windows\system32\UACibfvkyajwu.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACrxhostjexm.dat
c:\windows\system32\UACtaswcllnmh.dll
c:\windows\system32\UACuwksiqqpxx.dll
c:\windows\system32\UACxnssiuwidr.dll
c:\windows\system32\UACymxjvwipxu.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
(((((((((((((((( Arquivos/Ficheiros criados de 2009-08-01 to 2009-09-01 ))))))))))))))))))))))))))))
.
2009-08-31 15:55 . 2009-08-31 15:55 -------- d-----w- C:\_OTS
2009-08-29 02:50 . 2009-08-29 04:16 -------- d-----w- C:\573a298383e56b01f2971f12dd8f8a44
2009-08-28 15:57 . 2009-08-28 15:57 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-28 15:57 . 2009-08-28 15:57 32 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-27 04:26 . 2009-08-29 02:31 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ParetoLogic
2009-08-27 04:26 . 2009-08-29 02:31 -------- d-----w- c:\arquivos de programas\Arquivos comuns\ParetoLogic
2009-08-21 04:47 . 2009-08-21 04:47 -------- d-----w- c:\arquivos de programas\GameVicio
2009-08-21 01:32 . 2009-08-21 01:32 617 ----a-w- c:\windows\eReg.dat
2009-08-21 01:32 . 2009-08-24 02:09 -------- d-----w- c:\arquivos de programas\EA Games
2009-08-12 16:23 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-06 15:58 . 2009-03-16 21:36 931672 ----a-w- c:\windows\system32\XAudioD2_4.dll
2009-08-06 15:58 . 2009-03-16 21:35 343368 ----a-w- c:\windows\system32\XactEngineD3_4.dll
2009-08-06 15:58 . 2009-03-16 21:35 125768 ----a-w- c:\windows\system32\XAPOFXD1_3.dll
2009-08-06 15:58 . 2009-03-16 21:35 428888 ----a-w- c:\windows\system32\XactEngineA3_4.dll
2009-08-06 15:58 . 2009-03-16 21:35 4280136 ----a-w- c:\windows\system32\D3dx9d_41.dll
2009-08-06 15:58 . 2009-03-16 21:35 358728 ----a-w- c:\windows\system32\dinput8d.dll
2009-08-06 15:58 . 2009-03-16 21:35 45384 ----a-w- c:\windows\system32\X3DAudioD1_6.dll
2009-08-06 15:58 . 2009-03-16 21:36 3795784 ----a-w- c:\windows\system32\d3dx9d_33.dll
2009-08-06 15:58 . 2009-03-16 21:36 3083592 ----a-w- c:\windows\system32\d3d9d.dll
2009-08-06 15:58 . 2009-03-16 21:35 348504 ----a-w- c:\windows\system32\d3dref9.dll
2009-08-06 15:58 . 2009-03-16 21:35 497480 ----a-w- c:\windows\system32\D3DX10d_41.dll
2009-08-06 15:53 . 2009-08-06 15:58 -------- d-----w- c:\arquivos de programas\Microsoft DirectX SDK (March 2009)
2009-08-06 15:53 . 2009-08-06 15:53 118104 ----a-w- c:\windows\dxsdkuninst.exe
2009-08-06 05:01 . 2009-08-28 16:37 1324 ----a-w- c:\windows\system32\d3d9caps.dat
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 16:05 . 2009-02-09 01:36 -------- d-----w- c:\arquivos de programas\Mozilla Firefox 3 Beta 3
2009-08-28 15:57 . 2009-08-28 15:57 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-28 15:57 . 2009-08-28 15:57 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-25 07:08 . 2009-07-18 19:24 -------- d-----w- c:\arquivos de programas\sXe Injected
2009-08-25 05:47 . 2009-07-18 19:16 -------- d-----w- c:\arquivos de programas\Valve
2009-08-17 16:04 . 2007-12-15 13:06 -------- d-----w- c:\arquivos de programas\CoolSMS
2009-08-14 16:35 . 2007-12-15 12:41 2568 ----a-w- c:\windows\system32\KGyGaAvL.sys
2009-08-14 15:48 . 2008-05-11 16:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help
2009-08-06 20:13 . 2007-12-15 00:07 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information
2009-08-06 16:19 . 2009-07-09 15:33 -------- d-----w- c:\arquivos de programas\LucasArts
2009-08-05 09:00 . 2004-08-04 03:45 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 19:53 . 2008-05-24 20:42 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight
2009-07-29 02:17 . 2009-07-29 02:17 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!
2009-07-27 02:04 . 2009-07-27 02:03 -------- d-----w- c:\arquivos de programas\Messenger Plus! Live
2009-07-26 10:36 . 2009-01-18 19:56 83456 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit\DAP\SDCondition.dll
2009-07-23 01:55 . 2009-07-22 01:58 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Hamachi
2009-07-22 01:58 . 2009-07-22 01:57 -------- d-----w- c:\arquivos de programas\Hamachi
2009-07-22 01:57 . 2009-07-22 01:57 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-07-19 06:56 . 2009-07-04 04:07 98304 ----a-w- c:\windows\system32CmdLineExt.dll
2009-07-17 19:03 . 2004-08-04 03:45 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 02:43 . 2004-08-04 03:45 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 23:04 . 2008-11-24 16:04 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\GbPlugin
2009-07-08 20:41 . 2009-07-08 20:41 -------- d-----w- c:\arquivos de programas\FormatFactory
2009-07-07 22:18 . 2009-07-07 22:04 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Lite
2009-07-07 22:16 . 2009-07-07 22:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite
2009-07-07 22:15 . 2009-07-07 22:15 -------- d-----w- c:\arquivos de programas\DAEMON Tools Toolbar
2009-07-07 22:15 . 2009-07-07 22:15 -------- d-----w- c:\arquivos de programas\DAEMON Tools Lite
2009-07-07 22:04 . 2007-12-17 19:15 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-07 21:27 . 2009-07-07 21:27 10134 ----a-r- c:\documents and settings\Administrador\Dados de aplicativos\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
2009-07-06 15:33 . 2009-07-06 15:33 -------- d-----w- c:\arquivos de programas\Openoko Entertainment
2009-07-03 16:59 . 2004-08-04 03:45 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:27 . 2004-08-04 03:45 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:27 . 2004-08-04 03:45 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:27 . 2004-08-04 03:45 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:27 . 2004-08-04 03:45 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:27 . 2004-08-04 03:45 732672 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:27 . 2004-08-04 03:45 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-04 01:59 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:39 . 2004-08-04 03:45 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:39 . 2001-10-28 15:06 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 10:44 . 2004-08-04 03:45 77824 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:44 . 2004-08-04 03:45 81408 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-10 14:14 . 2004-08-04 03:45 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 12:21 . 2007-12-14 16:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2004-08-04 03:45 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-10 03:39 . 2001-10-28 15:07 83946 ----a-w- c:\windows\system32\perfc016.dat
2009-06-10 03:39 . 2001-10-28 15:07 480144 ----a-w- c:\windows\system32\perfh016.dat
2009-06-03 19:10 . 2004-08-04 03:45 1295872 ----a-w- c:\windows\system32\quartz.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\arquivos de programas\IObit\Advanced SystemCare 3\AWC.exe" [2009-05-01 2329936]
"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-15 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-05 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-05 114688]
"UnlockerAssistant"="c:\arquivos de programas\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"ISUSScheduler"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\Soundman.exe [2005-04-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\
Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2009-03-25 14:32 271152 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"WinampAgent"="c:\arquivos de programas\Winamp\winampa.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Arquivos de programas\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Arquivos de programas\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Arquivos de programas\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Arquivos de programas\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Arquivos de programas\\FrostWire\\FrostWire.exe"=
"c:\\Arquivos de programas\\DAP\\DAP.exe"=
"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Arquivos de programas\\FlashGet\\flashget.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Arquivos de programas\\DNA\\btdna.exe"=
"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=
"c:\\Arquivos de programas\\River Past\\Animated GIF Converter and Booster Pack\\VideoCleaner.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Icaro\\Arquivos\\HQS\\gc\\JKDH\\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\\FlatOut2.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\Valve\\hlds.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"= c:\arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
"c:\\Arquivos de programas\\Winamp Remote\\bin\\Orb.exe"= c:\arquivos de programas\Winamp Remote\bin\Orb.exe:*:Enabled:Orb
"c:\\Arquivos de programas\\Winamp Remote\\bin\\OrbTray.exe"= c:\arquivos de programas\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray
"c:\\Arquivos de programas\\Winamp Remote\\bin\\OrbStreamerClient.exe"= c:\arquivos de programas\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client
"c:\\Arquivos de programas\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"= c:\arquivos de programas\Macromedia\Dreamweaver 8\Dreamweaver.exe:*:Enabled:Dreamweaver 8
"c:\\Arquivos de programas\\FrostWire\\FrostWire.exe"= c:\arquivos de programas\FrostWire\FrostWire.exe:*:Enabled:LimeWire
"c:\\Arquivos de programas\\DAP\\DAP.exe"= c:\arquivos de programas\DAP\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)
"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Nero Web\\SetupX.exe"= c:\arquivos de programas\Arquivos comuns\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup
"c:\\Arquivos de programas\\FlashGet\\flashget.exe"= c:\arquivos de programas\FlashGet\flashget.exe:*:Enabled:Flashget
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= c:\arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= c:\arquivos de programas\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= c:\arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"= c:\arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync
"c:\\Arquivos de programas\\DNA\\btdna.exe"= c:\arquivos de programas\DNA\btdna.exe:*:Enabled:DNA
"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"= c:\arquivos de programas\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"c:\\Arquivos de programas\\River Past\\Animated GIF Converter and Booster Pack\\VideoCleaner.exe"= c:\arquivos de programas\River Past\Animated GIF Converter and Booster Pack\VideoCleaner.exe:*:Enabled:River Past Animated GIF Converter
"c:\\WINDOWS\\system32\\rtcshare.exe"= c:\windows\system32\rtcshare.exe:*:Enabled:Compartilhamento de aplicativo RTC
"c:\\Icaro\\Arquivos\\HQS\\gc\\JKDH\\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\\FlatOut2.exe"= c:\icaro\Arquivos\HQS\gc\JKDH\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\Flatout 2 WWW.THEREBELS.BIZ BY OWEN09\FlatOut2.exe:*:Enabled:FlatOut2
"c:\\Arquivos de programas\\Valve\\hl.exe"= c:\arquivos de programas\Valve\hl.exe:*:Enabled:Half-Life Launcher
"c:\\Arquivos de programas\\Valve\\hlds.exe"= c:\arquivos de programas\Valve\hlds.exe:*:Enabled:HLDS Launcher
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP"= 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [31/1/2009 16:34 26320]
R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [24/11/2008 13:04 52560]
R3 ham50;Intel HaM Data Fax Voice Modem;c:\windows\system32\drivers\ham50.sys [14/12/2007 21:46 365853]
S3 CrystalSysInfo;CrystalSysInfo;c:\arquivos de programas\MediaCoder\SysInfo.sys [25/9/2007 11:59 15152]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Administrador\desktop\SysProt\SysProtDrv.sys [29/8/2009 16:20 44288]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
Alerter
LmHosts
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Conteúdo da pasta 'Tarefas Agendadas'
2009-09-01 c:\windows\Tasks\GlaryInitialize.job
- c:\arquivos de programas\Glary Utilities\initialize.exe [2008-05-11 14:08]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.uol.com.br/
IE: c:\arquivos de programas\Software WIDCOMM\Bluetooth\btsendto_ie_ctx.htm
IE: &Clean Traces - c:\arquivos de programas\DAP\Privacy Package\dapcleanerie.htm
IE: &Descarregar tudo com o FlashGet - c:\arquivos de programas\FlashGet\jc_all.htm
IE: &Descarregar utilizando o FlashGet - c:\arquivos de programas\FlashGet\jc_link.htm
IE: &Download with &DAP - c:\arquivos de programas\DAP\dapextie.htm
IE: &Winamp Toolbar Search - c:\documents and settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to AMV Converter... - c:\arquivos de programas\MP3 Player Utilities 4.05\AMVConverter\grab.html
IE: Download &all with DAP - c:\arquivos de programas\DAP\dapextie2.htm
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.05\MediaManager\grab.html
LSP: c:\windows\system32\INetHTTPFilter.dll
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll
DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-01 13:37
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
[HKEY_USERS\S-1-5-21-507921405-602609370-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d7,2b,12,66,f3,f6,da,4a,b2,8d,23,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d7,2b,12,66,f3,f6,da,4a,b2,8d,23,\
[HKEY_USERS\S-1-5-21-507921405-602609370-682003330-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:12,60,ff,f8,2a,02,dc,f1,d7,25,74,1f,16,db,2d,58,43,c9,46,5d,24,75,02,
88,ae,51,05,76,8d,3c,87,6b,15,68,19,5f,0e,0e,ab,3a,6c,96,58,c2,ec,ad,15,63,\
"??"=hex:bd,8a,97,7e,54,25,e6,79,ec,fd,b6,38,5f,da,c8,4c
[HKEY_USERS\S-1-5-21-507921405-602609370-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:9e,07,aa,cf,8b,70,a0,48,1a,74,fa,89,53,b3,2b,2e,c7,54,f8,a8,b7,
dc,b4,96,b6,2f,67,36,5f,89,54,97,d3,10,41,bc,31,fc,6f,b0,28,84,0e,10,f6,5c,\
"rkeysecu"=hex:b6,f8,e3,02,31,6c,14,fd,d2,18,a7,c6,34,f9,2d,f6
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10b.exe"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@="FlashProp Class"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash6.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\ProgID]
@Denied: (A) (Everyone)
@="{FA169448-8BE3-443A-9C71-E2D1F366A8C2}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{3DA165B6-CC41-11d2-BDC6-00C04F79EC6B}\Version]
@Denied: (A) (Everyone)
@="{FA169448-8BE3-443A-9C71-E2D1F366A8C2}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{8D8763AB-E93B-4812-964E-F04E0008FD50}\Version]
@Denied: (A) (Everyone)
@="{8D8763AB-E93B-4812-964E-F04E0008FD50}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\arquivos de programas\GBPLUGIN\gbieh.dll
- - - - - - - > 'explorer.exe'(3508)
c:\windows\system32\WININET.dll
c:\arquiv~1\WINDOW~2\wmpband.dll
c:\arquivos de programas\GBPLUGIN\gbieh.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\arquivos de programas\Software WIDCOMM\Bluetooth\bin\btwdins.exe
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe
c:\arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\arquivos de programas\Mozilla Firefox 3 Beta 3\firefox.exe
.
**************************************************************************
.
Tempo para conclusão: 2009-09-01 13:47 - Máquina reiniciou
ComboFix-quarantined-files.txt 2009-09-01 16:47
Pré-execução: 16 pasta(s) 11.707.437.056 bytes disponíveis
Pós execução: 16 pasta(s) 11.664.551.936 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
380 --- E O F --- 2009-08-26 16:25