Hello, thank you for your quick response. Here's the Combo-Fix.txt
ComboFix 09-10-07.05 - Administrador 08/10/2009 17:34.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1280.780 [GMT -3:00]
Executando de: c:\documents and settings\Administrador\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrador\autorun.inf
c:\documents and settings\Administrador\Dados de aplicativos\inst.exe
c:\windows\system32\ahtqvfv.dll
c:\windows\system32\cffddgu.dll
c:\windows\system32\drivers\gasfkyskylkmrm.sys
c:\windows\system32\drivers\lvjhtumd.sys
c:\windows\system32\drivers\pkbbdfuj.sys
c:\windows\system32\gasfkyfrxltewf.dll
c:\windows\system32\gasfkyiqhgfvpg.dll
c:\windows\system32\gasfkykopswrtl.dat
c:\windows\system32\gasfkylhrmqgvp.dat
c:\windows\system32\gasfkyoetqwrqh.dll
c:\windows\system32\gasfkypxyvxfuw.dll
c:\windows\system32\gasfkypxyvxfuw.dll.kav
c:\windows\system32\gasfkyrdkridvb.dll
c:\windows\system32\gasfkywhlsdewu.dll
c:\windows\system32\gasfkyxrobrfth.dll
c:\windows\system32\gasfkyxrobrfth.dll.kav
c:\windows\system32\ycexobyd.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gasfkyscpbneoa
-------\Legacy_gasfkyscpbneoa
-------\Legacy_PKBBDFUJ
-------\Legacy_TAWYYGDW
-------\Service_pkbbdfuj
-------\Service_tawyygdw
(((((((((((((((( Arquivos/Ficheiros criados de 2009-09-08 to 2009-10-08 ))))))))))))))))))))))))))))
.
2009-10-08 20:16 . 2009-10-08 20:16 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\jgcyllql
2009-10-07 18:49 . 2009-10-07 18:49 -------- d-----w- c:\documents and settings\NetworkService\Dados de aplicativos\jgcyllql
2009-10-07 01:35 . 2009-10-07 02:22 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-07 01:35 . 2009-10-07 02:22 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-07 01:33 . 2009-10-08 20:53 783136 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-07 01:33 . 2009-10-08 20:53 13600 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-07 01:33 . 2009-10-08 20:15 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab
2009-10-07 01:33 . 2009-10-07 01:33 -------- d-----w- c:\arquivos de programas\Kaspersky Lab
2009-10-07 01:29 . 2009-10-07 01:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab Setup Files
2009-10-06 01:56 . 2009-07-28 19:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-06 01:56 . 2009-03-30 13:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-06 01:56 . 2009-02-13 15:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-06 01:56 . 2009-02-13 15:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-06 01:56 . 2009-10-06 01:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira
2009-10-06 01:56 . 2009-10-06 01:56 -------- d-----w- c:\arquivos de programas\Avira
2009-10-06 01:13 . 2009-10-06 01:04 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-06 01:04 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-06 00:59 . 2009-10-06 00:59 -------- dc-h--w- c:\documents and settings\All Users\Dados de aplicativos\{EF63305C-BAD7-4144-9208-D65528260864}
2009-10-06 00:59 . 2009-10-06 00:59 -------- d-----w- c:\arquivos de programas\Lavasoft
2009-10-05 00:31 . 2009-10-05 00:31 -------- d-----w- c:\arquivos de programas\Microsoft
2009-09-17 17:56 . 2009-09-17 17:56 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Macrovision Shared
2009-09-15 20:26 . 2009-09-15 20:26 221 ----a-w- c:\documents and settings\Administrador\GuDbVz.bat
2009-09-13 13:46 . 2009-09-13 13:46 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Leadertech
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 20:54 . 2008-08-01 19:51 -------- d-----w- c:\arquivos de programas\lg_fwupdate
2009-10-08 20:52 . 2009-10-07 01:33 3368 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-08 20:52 . 2009-10-07 01:33 12512 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-07 02:22 . 2007-10-31 16:41 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-10-05 17:23 . 2009-08-18 18:04 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\U3
2009-10-05 01:09 . 2008-08-25 14:04 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-17 18:04 . 2008-08-01 19:49 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe
2009-09-16 18:45 . 2008-08-09 23:49 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\uTorrent
2009-09-16 18:39 . 2008-09-06 15:10 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Vso
2009-08-29 17:01 . 2001-10-28 18:07 79240 ----a-w- c:\windows\system32\perfc016.dat
2009-08-29 17:01 . 2001-10-28 18:07 468462 ----a-w- c:\windows\system32\perfh016.dat
2009-08-29 16:55 . 2009-08-29 16:55 -------- d-----w- c:\arquivos de programas\MSBuild
2009-08-29 16:55 . 2009-08-29 16:55 -------- d-----w- c:\arquivos de programas\Reference Assemblies
2009-08-29 16:48 . 2009-08-29 16:48 -------- d-----w- c:\arquivos de programas\MSXML 6.0
2009-08-29 14:22 . 2008-08-04 01:20 -------- d-----w- c:\arquivos de programas\Java
2009-08-21 02:46 . 2009-08-21 02:45 -------- d-----w- c:\arquivos de programas\PDFCreator
2009-08-06 22:24 . 2008-08-01 19:11 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 22:24 . 2008-08-01 19:11 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 22:24 . 2008-08-01 19:11 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 22:24 . 2007-07-30 22:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 22:24 . 2008-08-01 19:11 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 22:24 . 2004-08-04 03:45 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 22:23 . 2008-08-01 19:11 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 22:23 . 2008-08-02 17:27 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 22:23 . 2008-08-02 17:27 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 22:23 . 2008-08-01 19:11 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:06 . 2004-08-04 03:45 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:53 . 2004-08-04 03:45 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:53 . 2001-10-28 18:06 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 19:44 . 2009-07-26 19:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-25 08:23 . 2009-01-12 00:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 18:57 . 2004-08-04 03:45 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 05:18 . 2004-08-04 03:45 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2004-10-01 18:00 . 2008-08-01 19:45 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe
2004-08-04 03:45 . 2004-08-04 03:45 61952 --sh--r- c:\windows\system32\admparsed.exe
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\arquivos de programas\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-08-01 16384]
"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Google Update"="c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2009-10-05 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="c:\windows\NewMixer.exe" [2002-07-02 1540096]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2001-12-18 617984]
"RemoteControl"="c:\arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"InCD"="c:\arquivos de programas\Ahead\InCD\InCD.exe" [2006-07-12 1397760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"LGODDFU"="c:\arquivos de programas\lg_fwupdate\fwupdate.exe" [2006-02-20 245760]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"ISUSPM Startup"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"WEBSERVER"="c:\arquivos de programas\Real Internet Empresa\Offline\BIN\RealWebServer.exe" [2004-01-12 380416]
"SERVAPP"="c:\arquivos de programas\Real Internet Empresa\Offline\BIN\ServAppWin.exe" [2002-02-15 41984]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"AdobeCS4ServiceManager"="c:\arquivos de programas\Arquivos comuns\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AVP"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 227856]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-11 20992]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=
"c:\\Arquivos de programas\\SoulseekNS\\slsk.exe"=
"c:\\Arquivos de programas\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\ServAppWin.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\RealWebServer.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\AtualizadorVersao.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\CFGCLI.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\ExecServRemoto.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\Instalador.exe"=
"c:\\Arquivos de programas\\Real Internet Empresa\\Offline\\BIN\\owb_0_ft_filetransfer.exe"=
"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/10/2009 22:04 64160]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [5/10/2009 22:56 108289]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\arquivos de programas\Lavasoft\Ad-Aware\AAWService.exe [3/7/2009 11:49 1028432]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
S2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe --> c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [?]
--- =Outros Serviços/Drivers Na Memória ---
*NewlyCreated* - PKBBDFUJ
*Deregistered* - pkbbdfuj
.
Conteúdo da pasta 'Tarefas Agendadas'
2009-10-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\arquivos de programas\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 01:02]
.
.
------- Scan Suplementar -------
.
uInternet Settings,ProxyOverride = localhost
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {63D996D8-49DE-41A9-B6C8-23D61B812B34} = 200.175.5.135,200.175.89.139
.
- - - - ORFÃOS REMOVIDOS - - - -
BHO-{04A5F964-6A87-44B8-82B1-8C71A95B9743} - c:\windows\system32\ycexobyd.dll
HKCU-Run-yiuubo - c:\documents and settings\Administrador\yiuubo.exe
HKCU-Run-restorer32_a - c:\documents and settings\Administrador\restorer32_a.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-08 17:53
Windows 5.1.2600 Service Pack 2 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(544)
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(2264)
c:\arquivos de programas\Logitech\MouseWare\System\LgWndHk.dll
c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 7.0\scrchpg.dll
c:\arquivos de programas\Arquivos comuns\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\arquivos de programas\Ahead\InCD\InCDsrv.exe
c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe
c:\arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
c:\documents and settings\All Users\Dados de aplicativos\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\arquivos de programas\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\documents and settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\arquivos de programas\Canon\CAL\CALMAIN.exe
c:\windows\system32\imapi.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\arquivos de programas\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Tempo para conclusão: 2009-10-08 18:02 - Máquina reiniciou
ComboFix-quarantined-files.txt 2009-10-08 21:02
Pré-execução: 13 pasta(s) 43.097.399.296 bytes disponíveis
Pós execução: 14 pasta(s) 39.945.183.232 bytes disponíveis
225 --- E O F --- 2009-10-07 20:43