ComboFix 08-11-16.05 - Robério 2008-11-18 5:13:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.634 [GMT -2:00]
Executando de: c:\documents and settings\Robério\Desktop\ComboFix.exe
* Criado um novo ponto de restauro
ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\documents and settings\All Users\Dados de aplicativos\pdfppt2.dll
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
C:\yannh.cmd
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-18 to 2008-11-18 ))))))))))))))))))))))))))))
.
2008-11-18 05:01 . 2008-11-18 05:01 <DIR> d-------- c:\windows\LastGood
2008-11-18 04:54 . 2007-02-09 10:26 184,320 --a------ c:\windows\system32\delnext.exe
2008-11-18 04:54 . 2004-05-05 09:40 16,384 --a------ c:\windows\system32\restart.exe
2008-11-17 23:24 . 2008-11-17 23:25 <DIR> d-------- C:\hijackthis
2008-11-17 23:23 . 2008-11-17 23:23 212,849 --a------ C:\hijackthis.zip
2008-11-17 23:18 . 2008-11-17 23:18 106,174 -r-hs---- c:\windows\system32\kamsoft.exe
2008-11-17 23:18 . 2008-11-18 05:00 85,504 -r-hs---- c:\windows\system32\gasretyw0.dll
2008-11-17 23:11 . 2001-09-05 23:27 18,176 --a------ c:\windows\system32\drivers\sermouse.sys
2008-11-17 23:11 . 2001-09-05 23:27 18,176 --a--c--- c:\windows\system32\dllcache\sermouse.sys
2008-11-12 19:51 . 2008-11-12 19:51 85,504 --a------ c:\windows\system32\ckvo0.VIR002
2008-11-12 18:51 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 18:44 . 2008-11-12 18:44 85,504 --a------ c:\windows\system32\ckvo0.VIR000
2008-11-12 13:03 . 2008-11-12 13:03 85,504 --a------ c:\windows\system32\ckvo0.VIR001
2008-11-10 17:53 . 2008-11-10 17:53 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-10 11:44 . 2008-11-11 03:08 <DIR> d-------- c:\documents and settings\Robério\Dados de aplicativos\Babylon
2008-11-10 11:44 . 2008-11-13 15:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Babylon
2008-11-10 11:44 . 2008-11-10 11:44 <DIR> d-------- c:\arquivos de programas\myBabylon_English
2008-11-10 11:44 . 2008-11-10 11:44 <DIR> d-------- c:\arquivos de programas\Conduit
2008-11-10 11:44 . 2008-11-10 11:44 <DIR> d-------- c:\arquivos de programas\Babylon
2008-11-09 12:37 . 2008-11-09 12:37 85,504 --a------ c:\windows\system32\ckvo0.VIR
2008-11-08 17:18 . 2008-11-07 07:21 109,879 -r-hs---- C:\sq.com
2008-11-01 22:07 . 2008-11-01 22:07 244 --ah----- C:\sqmnoopt03.sqm
2008-11-01 22:07 . 2008-11-01 22:07 232 --ah----- C:\sqmdata03.sqm
2008-11-01 22:07 . 2008-11-01 22:07 172 --ah----- C:\sqmnoopt04.sqm
2008-11-01 22:07 . 2008-11-01 22:07 172 --ah----- C:\sqmdata04.sqm
2008-11-01 21:47 . 2008-11-01 21:47 244 --ah----- C:\sqmnoopt02.sqm
2008-11-01 21:47 . 2008-11-01 21:47 232 --ah----- C:\sqmdata02.sqm
2008-10-28 12:50 . 2008-10-28 12:50 <DIR> d-------- c:\documents and settings\Robério\Dados de aplicativos\ArcSoft
2008-10-28 11:57 . 2008-11-01 22:29 739 --a------ c:\windows\STImgBrowser.INI
2008-10-28 11:53 . 1995-07-31 13:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-10-28 11:53 . 2001-11-02 15:06 163,840 --a------ c:\windows\system32\PhotoImpression Screen Saver.scr
2008-10-28 11:52 . 2008-10-28 11:52 <DIR> d-------- c:\arquivos de programas\ArcSoft
2008-10-28 11:51 . 2008-10-28 11:51 <DIR> d-------- c:\arquivos de programas\directx
2008-10-24 13:49 . 2008-10-24 13:49 56,579 --a------ C:\Apresentação4.pdf
2008-10-24 13:47 . 2008-10-24 13:47 <DIR> d-------- c:\windows\system32\psconv
2008-10-24 13:47 . 2008-10-24 13:47 <DIR> d-------- c:\arquivos de programas\psconvert
2008-10-24 13:47 . 2001-10-29 01:42 116,224 --a------ c:\windows\system32\pdfmonnt.dll
2008-10-24 13:47 . 2008-10-24 13:47 164 --a------ c:\windows\system32\psconv.ini
2008-10-24 12:59 . 1998-06-24 00:00 609,584 --a------ c:\windows\system32\COMCTL32.OCX
2008-10-24 12:48 . 2008-10-24 12:50 34 --a------ C:\pdfinfo.ini
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-08 11:29 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe
2008-11-02 00:29 --------- d-----w c:\arquivos de programas\DivX
2008-10-28 13:52 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2008-10-28 13:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 20:25 --------- d-----w c:\documents and settings\Robério\Dados de aplicativos\Ahead
2008-10-17 21:54 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\NCH Swift Sound
2008-10-17 21:54 --------- d-----w c:\arquivos de programas\NCH Swift Sound
2008-10-17 21:46 --------- d-----w c:\documents and settings\Robério\Dados de aplicativos\NCH Swift Sound
2008-10-17 21:39 --------- d-----w c:\arquivos de programas\NCH Software
2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-12 18:46 --------- d-----w c:\arquivos de programas\Google
2008-10-06 18:10 --------- d-----w c:\documents and settings\Robério\Dados de aplicativos\DivX
2008-10-06 18:04 --------- d-----w c:\arquivos de programas\IZArc
2008-10-06 13:15 --------- d-----w c:\arquivos de programas\Real Alternative
2008-10-06 12:58 --------- d-----w c:\arquivos de programas\SMPlayer
2008-10-05 19:58 --------- d-----w c:\arquivos de programas\MSXML 4.0
2008-10-05 02:47 --------- d-----w c:\documents and settings\Robério\Dados de aplicativos\Media Player Classic
2008-10-04 19:28 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SlySoft
2008-10-04 19:28 --------- d-----w c:\arquivos de programas\SlySoft
2008-10-04 19:27 --------- d-----w c:\arquivos de programas\Elaborate Bytes
2008-10-04 19:24 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero
2008-10-04 19:24 --------- d-----w c:\arquivos de programas\Nero
2008-10-04 19:24 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead
2008-10-04 19:19 --------- d-----w c:\arquivos de programas\Windows Media Connect 2
2008-10-04 19:13 --------- d-----w c:\arquivos de programas\MSN Messenger
2008-10-04 19:10 --------- d-----w c:\documents and settings\Robério\Dados de aplicativos\InstallShield
2008-10-04 19:10 --------- d-----w c:\arquivos de programas\Realtek
2008-10-04 18:59 --------- d-----w c:\arquivos de programas\Mobile Partner
2008-10-04 18:57 --------- d-----w c:\arquivos de programas\Intel
2008-10-04 18:44 --------- d-----w c:\arquivos de programas\microsoft frontpage
2008-10-04 18:43 --------- d-----w c:\arquivos de programas\Serviços on-line
2008-10-04 18:42 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços
2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\arquivos de programas\myBabylon_English\tbmyBa.dll" [2008-08-20 1780248]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2008-08-20 23:03 1780248 --a------ c:\arquivos de programas\myBabylon_English\tbmyBa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\arquivos de programas\myBabylon_English\tbmyBa.dll" [2008-08-20 1780248]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\arquivos de programas\myBabylon_English\tbmyBa.dll" [2008-08-20 1780248]
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AnyDVD"="c:\arquivos de programas\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-05-13 2091968]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-06 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-04-05 565248]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Babylon Client"="c:\arquivos de programas\Babylon\Babylon-Pro\Babylon.exe" [2008-09-28 3565280]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-05-09 c:\windows\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=
"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\yannh.cmd
\Shell\explore\Command - C:\yannh.cmd
\Shell\open\Command - C:\yannh.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{432d60b8-a477-11dd-8a5e-001d7dfcbda6}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86ac2e70-9259-11dd-8a13-001d7dfcbda6}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87915025-9658-11dd-8a24-001d7dfcbda6}]
\Shell\AutoRun\command - F:\yew.bat
\Shell\explore\Command - F:\yew.bat
\Shell\open\Command - F:\yew.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8eced66-aa24-11dd-8a7a-001d7dfcbda6}]
\Shell\AutoRun\command - F:\sq.com
\Shell\explore\Command - F:\sq.com
\Shell\open\Command - F:\sq.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c74aa0b4-af7d-11dd-8a94-001d7dfcbda6}]
\Shell\AutoRun\command - F:\sq.com
\Shell\explore\Command - F:\sq.com
\Shell\open\Command - F:\sq.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7eb7e16-9b74-11dd-8a36-001d7dfcbda6}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da3b9e31-939f-11dd-8a18-001d7dfcbda6}]
\Shell\AutoRun\command - F:\sq.com
\Shell\explore\Command - F:\sq.com
\Shell\open\Command - F:\sq.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb9974c3-9229-11dd-8a0c-806d6172696f}]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa54211c-924d-11dd-8a12-001d7dfcbda6}]
\Shell\AutoRun\command - F:\yew.bat
\Shell\explore\Command - F:\yew.bat
\Shell\open\Command - F:\yew.bat
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 05:35:27
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
Tempo para conclusão: 2008-11-18 5:46:30
ComboFix-quarantined-files.txt 2008-11-18 07:45:36
Pré-execução: 11 pasta(s) 145.349.181.440 bytes disponíveis
Pós execução: 11 pasta(s) 146,034,466,816 bytes disponíveis
200 --- E O F --- 2008-11-13 01:08:02