Olá, amigo Mr.Wolf
Então, completei com sucesso a segunda e a terceira etapa q tu me instruiu a fazer...
Infelizmente, o Downadup Remover da Symantec (segunda etapa) não achou nenhuma variação do vírus Win32/Downadup no meu pc (?) :cry:
Mas por outro lado, o ComboFix deletou vários arquivos infectados e gerou um... *Ahem*... rico log.txt para análise.
--Segue o log do ComboFix--
ComboFix 09-02-11.02 - Maria 2009-02-12 8:49:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1046.18.2046.1568 [GMT -2:00]
Executando de: c:\documents and settings\Maria\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\arquivos de programas\Mozilla Firefox\components\iamfamous.dll
C:\autorun.inf
c:\docume~1\Maria\CONFIG~1\Temp\tmp1.tmp
c:\docume~1\Maria\CONFIG~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Maria\Menu Iniciar\Programas\coolplay
c:\documents and settings\Maria\Menu Iniciar\Programas\coolplay\Uninstall.lnk
c:\recycler\S-0-1-11-100023070-100011628-100030921-2223.com
c:\windows\system32\drivers\gaopdxekjbfrdc.sys
c:\windows\system32\drivers\gaopdxkjfghndq.sys
c:\windows\system32\drivers\gaopdxlmpktiqm.sys
c:\windows\system32\drivers\gaopdxloynmsow.sys
c:\windows\system32\drivers\gaopdxpptywvdp.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxsmvcnupl.dll
F:\Autorun.inf
f:\recycler\S-0-1-11-100023070-100011628-100030921-2223.com
f:\recycler\S-7-9-51-100014447-100014769-100013599-2638.com
----- BITS: Sites possivelmente infetados -----
hxxp://autovideo.110mb.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-12 to 2009-02-12 ))))))))))))))))))))))))))))
.
2009-02-12 08:17 . 2009-02-12 08:18 <DIR> d-------- C:\32788R22FWJFW
2009-02-11 18:06 . 2009-02-11 18:06 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes
2009-02-10 18:43 . 2009-02-10 18:43 <DIR> d-------- c:\documents and settings\Maria\Dados de aplicativos\Malwarebytes
2009-02-10 18:43 . 2009-02-10 18:43 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2009-02-10 18:43 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-10 18:43 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-10 17:58 . 2009-02-10 17:58 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\SUPERAntiSpyware.com
2009-02-10 14:38 . 2009-02-10 14:40 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-09 23:12 . 2009-02-09 23:12 <DIR> d-------- c:\documents and settings\Maria\Dados de aplicativos\SUPERAntiSpyware.com
2009-02-09 23:12 . 2009-02-09 23:12 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SUPERAntiSpyware.com
2009-02-09 21:56 . 2009-02-09 21:56 1,131,800 --a------ c:\arquivos de programas\avgapix.dll
2009-02-09 21:56 . 2009-02-09 21:56 687,896 --a------ c:\arquivos de programas\avgcsrvx.exe
2009-02-09 21:56 . 2009-02-09 21:56 592,128 --a------ c:\arquivos de programas\avgnsx.exe
2009-02-09 21:56 . 2009-02-09 21:56 423,192 --a------ c:\arquivos de programas\fixcfg.exe
2009-02-09 21:56 . 2009-02-09 21:56 416,536 --a------ c:\arquivos de programas\avgcclix.dll
2009-02-09 21:56 . 2009-02-09 21:56 379,672 --a------ c:\arquivos de programas\avgclitx.dll
2009-02-09 21:56 . 2009-02-09 21:56 350,488 --a------ c:\arquivos de programas\avgxch32.dll
2009-02-09 21:56 . 2009-02-09 21:55 317,644 --a------ c:\arquivos de programas\sb.dat
2009-02-09 21:56 . 2009-02-09 21:56 270,616 --a------ c:\arquivos de programas\avgamnot.dll
2009-02-09 21:56 . 2009-02-09 21:56 222,488 --a------ c:\arquivos de programas\avg7api.dll
2009-02-09 21:56 . 2009-02-09 21:55 115,900 --a------ c:\arquivos de programas\sc.dat
2009-02-09 21:56 . 2009-02-09 21:55 2,188 --a------ c:\arquivos de programas\sb2.dat
2009-02-09 21:56 . 2009-02-09 21:45 1,044 --a------ c:\arquivos de programas\cf.dat
2009-02-09 21:56 . 2009-02-09 21:45 120 --a------ c:\arquivos de programas\ph.dat
2009-02-09 21:45 . 2009-02-09 21:55 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-09 21:45 . 2009-02-09 21:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\avg8
2009-02-09 21:45 . 2009-02-09 21:56 <DIR> d-------- c:\arquivos de programas\Icons
2009-02-09 21:45 . 2009-02-09 21:56 <DIR> d-------- c:\arquivos de programas\Firefox
2009-02-09 21:45 . 2009-02-09 21:54 <DIR> d-------- c:\arquivos de programas\AVG
2009-02-09 21:45 . 2009-02-09 21:56 3,344,152 --a------ c:\arquivos de programas\avgui.exe
2009-02-09 21:45 . 2009-02-09 21:56 2,363,672 --a------ c:\arquivos de programas\avguires.dll
2009-02-09 21:45 . 2009-02-09 21:56 2,266,392 --a------ c:\arquivos de programas\avguiadv.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,691,416 --a------ c:\arquivos de programas\avgcorex.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,601,304 --a------ c:\arquivos de programas\avgtray.exe
2009-02-09 21:45 . 2009-02-09 21:56 1,419,544 --a------ c:\arquivos de programas\avgupd.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,216,536 --a------ c:\arquivos de programas\avgwd.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,193,240 --a------ c:\arquivos de programas\avgfrw.exe
2009-02-09 21:45 . 2009-02-09 21:56 1,149,720 --a------ c:\arquivos de programas\avgabout.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,078,552 --a------ c:\arquivos de programas\avgssie.dll
2009-02-09 21:45 . 2009-02-09 21:45 1,045,128 --a------ c:\arquivos de programas\dbghelp.dll
2009-02-09 21:45 . 2009-02-09 21:56 1,032,984 --a------ c:\arquivos de programas\avgupd.exe
2009-02-09 21:45 . 2009-02-09 21:45 966,400 --a------ c:\arquivos de programas\avgresf.dll
2009-02-09 21:45 . 2009-02-09 21:56 935,192 --a------ c:\arquivos de programas\avgxpl.dll
2009-02-09 21:45 . 2009-02-09 21:56 935,164 --a------ c:\arquivos de programas\setup.dat
2009-02-09 21:45 . 2009-02-09 21:56 824,600 --a------ c:\arquivos de programas\avgcmgr.exe
2009-02-09 21:45 . 2009-02-09 21:56 819,992 --a------ c:\arquivos de programas\avgcfgx.dll
2009-02-09 21:45 . 2009-02-09 21:56 756,504 --a------ c:\arquivos de programas\avgscanx.exe
2009-02-09 21:45 . 2009-02-09 21:56 744,728 --a------ c:\arquivos de programas\avginet.dll
2009-02-09 21:45 . 2009-02-09 21:56 729,880 --a------ c:\arquivos de programas\avgcfgex.exe
2009-02-09 21:45 . 2009-02-09 21:56 677,144 --a------ c:\arquivos de programas\avgsrmx.dll
2009-02-09 21:45 . 2009-02-09 21:56 578,840 --a------ c:\arquivos de programas\avgiproxy.exe
2009-02-09 21:45 . 2009-02-09 21:56 531,224 --a------ c:\arquivos de programas\avgsched.dll
2009-02-09 21:45 . 2009-02-09 21:56 509,208 --a------ c:\arquivos de programas\avgvvx.dll
2009-02-09 21:45 . 2009-02-09 21:56 484,120 --a------ c:\arquivos de programas\avgrsx.exe
2009-02-09 21:45 . 2009-02-09 21:56 422,400 --a------ c:\arquivos de programas\avgwdwsc.dll
2009-02-09 21:45 . 2009-02-09 21:56 341,272 --a------ c:\arquivos de programas\avgsrmax.exe
2009-02-09 21:45 . 2009-02-09 21:56 341,272 --a------ c:\arquivos de programas\avglogx.dll
2009-02-09 21:45 . 2009-02-09 21:56 333,592 --a------ c:\arquivos de programas\avgscanx.dll
2009-02-09 21:45 . 2009-02-09 21:56 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-09 21:45 . 2009-02-09 21:56 311,064 --a------ c:\arquivos de programas\avglngx.dll
2009-02-09 21:45 . 2009-02-09 21:56 303,384 --a------ c:\arquivos de programas\avgmvflx.dll
2009-02-09 21:45 . 2009-02-09 21:56 298,264 --a------ c:\arquivos de programas\avgwdsvc.exe
2009-02-09 21:45 . 2009-02-09 21:56 264,472 --a------ c:\arquivos de programas\avgoff2k.dll
2009-02-09 21:45 . 2009-02-09 21:56 176,408 --a------ c:\arquivos de programas\avgmail.dll
2009-02-09 21:45 . 2009-02-09 21:56 117,528 --a------ c:\arquivos de programas\avgse.dll
2009-02-09 21:45 . 2009-02-09 21:56 84,399 --a------ c:\arquivos de programas\dfncfg.dat
2009-02-09 21:45 . 2009-02-09 21:56 79,128 --a------ c:\arquivos de programas\avgpp.dll
2009-02-09 21:45 . 2009-02-09 21:56 75,544 --a------ c:\arquivos de programas\avgdumpx.exe
2009-02-09 21:45 . 2009-02-09 21:56 69,400 --a------ c:\arquivos de programas\avgcrlpx.dll
2009-02-09 21:45 . 2009-02-09 21:56 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-04 18:19 . 2009-02-04 18:19 <DIR> d-------- C:\_UFRGS
2009-01-28 11:03 . 2009-01-28 11:05 <DIR> d-------- c:\arquivos de programas\Microsoft Games for Windows - LIVE
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 10:09 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP
2009-02-10 01:11 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2009-02-09 23:57 904 ----a-w c:\arquivos de programas\updatecomps.cfg
2009-02-09 23:57 559 ----a-w c:\arquivos de programas\update.cfg
2009-02-09 23:56 93,296 ----a-w c:\arquivos de programas\setupus.lns
2009-02-09 23:56 4,889 ----a-w c:\arquivos de programas\avgmwdef_us.mht
2009-02-09 23:56 278,597 ----a-w c:\arquivos de programas\avg8us.lng
2009-02-09 23:56 236,824 ----a-w c:\arquivos de programas\avgbat.bav
2009-02-09 23:56 2,552 ----a-w c:\arquivos de programas\avgatend.stp
2009-02-09 23:56 1,184 ----a-w c:\arquivos de programas\avgatupd.stp
2009-02-09 23:55 24,520 ----a-w c:\arquivos de programas\sc.dat.xcd
2009-02-09 23:55 138,536 ----a-w c:\arquivos de programas\sb.dat.xcd
2009-02-09 23:45 190 ----a-w c:\arquivos de programas\avg.snu
2009-02-09 23:45 17,321 ----a-w c:\arquivos de programas\contacts_us.html
2009-02-09 23:45 168,298 ----a-w c:\arquivos de programas\avgf8us.chm
2009-02-09 23:45 10,310 ----a-w c:\arquivos de programas\license_us.txt
2009-02-09 15:35 --------- d-----w c:\arquivos de programas\eMule
2009-02-02 13:46 201,352 ----a-w c:\windows\system32\PnkBstrB.exe
2009-02-02 13:46 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-02 02:41 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-01-04 03:52 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2009-01-04 03:52 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Fallout3
2009-01-04 03:49 --------- d-----w c:\arquivos de programas\MSBuild
2009-01-04 03:46 --------- d-----w c:\arquivos de programas\Reference Assemblies
2009-01-02 23:54 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\ATI
2009-01-02 23:50 --------- d-----w c:\arquivos de programas\ATI Technologies
2009-01-02 23:48 --------- d-----w c:\arquivos de programas\Arquivos comuns\ATI Technologies
2008-12-15 21:53 --------- d-----w c:\arquivos de programas\MSN Messenger
2008-12-01 16:35 593,920 ------w c:\windows\system32\ati2sgag.exe
2008-12-01 14:52 425,984 ----a-w c:\windows\system32\ATIDEMGX.dll
2008-12-01 14:51 318,464 ----a-w c:\windows\system32\ati2dvag.dll
2008-12-01 14:46 11,304,960 ----a-w c:\windows\system32\atioglxx.dll
2008-12-01 14:41 188,416 ----a-w c:\windows\system32\atipdlxx.dll
2008-12-01 14:40 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2008-12-01 14:40 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2008-12-01 14:40 147,456 ----a-w c:\windows\system32\Oemdspif.dll
2008-12-01 14:40 143,360 ----a-w c:\windows\system32\ati2evxx.dll
2008-12-01 14:38 598,016 ----a-w c:\windows\system32\ati2evxx.exe
2008-12-01 14:37 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2008-12-01 14:27 4,120,384 ----a-w c:\windows\system32\ati3duag.dll
2008-12-01 14:19 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2008-12-01 14:11 2,495,360 ----a-w c:\windows\system32\ativvaxx.dll
2008-12-01 13:57 48,640 ----a-w c:\windows\system32\amdpcom32.dll
2008-12-01 13:53 45,056 ----a-w c:\windows\system32\amdcalrt.dll
2008-12-01 13:53 45,056 ----a-w c:\windows\system32\amdcalcl.dll
2008-12-01 13:53 401,408 ----a-w c:\windows\system32\atikvmag.dll
2008-12-01 13:52 86,016 ----a-w c:\windows\system32\atiadlxx.dll
2008-12-01 13:52 17,408 ----a-w c:\windows\system32\atitvo32.dll
2008-12-01 13:50 3,252,224 ----a-w c:\windows\system32\Amdcaldd.dll
2008-12-01 13:50 286,720 ----a-w c:\windows\system32\atiok3x2.dll
2008-12-01 13:45 577,536 ----a-w c:\windows\system32\ati2cqag.dll
2008-11-28 13:18 744,960 ----a-w c:\windows\system32\IR41_32.DLL
2008-11-28 13:18 199,168 ----a-w c:\windows\system32\ir32_32.dll
2008-11-28 13:18 13,312 ----a-w c:\windows\system32\svrapi.dll
2008-10-05 23:58 22,328 ----a-w c:\documents and settings\Maria\Dados de aplicativos\PnkBstrK.sys
2004-03-11 16:27 40,960 -c--a-w c:\arquivos de programas\Uninstall_CDS.exe
2006-10-09 00:07 61 --sha-w c:\windows\cnerolf.dat
2008-10-22 11:01 32,768 --sha-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\MSHist012008102220081023\index.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"StartCCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Atalho para a Página de Propriedades do High Definition Audio"="HDAudPropShortcut.exe" [2004-08-12 c:\windows\system32\Hdaudpropshortcut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-14 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-09 21:56 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.X264"= x264vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0smrgdf c:\documents and settings\Maria\Dados de aplicativos\iolo"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^AutoCAD Startup Accelerator.lnk]
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Maria^Menu Iniciar^Programas^Inicializar^Active SMART.lnk]
backup=c:\windows\pss\Active SMART.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RivaTunerStartupDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS10 Preload
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2009-02-09 21:56 1601304 c:\arquiv~1\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera]
--a------ 2005-12-06 14:08 20480 c:\windows\FixCamera.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]
--a------ 2006-12-19 11:02 2842624 c:\arquivos do ricardo\Utilitários\Fraps\Fraps\fraps.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-12 00:12 49152 c:\arquivos de programas\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 00:21 1695232 c:\arquivos de programas\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--a------ 2004-09-22 17:10 1871872 c:\arquivos de programas\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-12-08 18:35 32768 c:\arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2std]
--a------ 2006-01-06 14:57 344064 c:\windows\vsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-03-28 02:07 593920 c:\arquivos de programas\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-12-15 03:23 75520 c:\arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2009-01-15 16:17 1830128 c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnp2std]
--a------ 2006-01-16 15:06 114688 c:\windows\tsnp2std.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\w3dr.exe]
--a------ 2008-08-03 12:38 61440 c:\arquivos do ricardo\Warcraft III\W3DR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 19:20 866584 c:\arquivos de programas\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ActiveSMART Service"=2 (0x2)
"nTuneService"=2 (0x2)
"ioloSystemService"=2 (0x2)
"ioloFileInfoList"=2 (0x2)
"NVSvc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ImapiService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos do Ricardo\\Need for Speed Underground 2\\speed2.exe"=
"c:\\Arquivos do Ricardo\\Half-Life\\hl.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos do Ricardo\\Soldat\\Soldat.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Arquivos do Ricardo\\Warcraft III\\war3.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Arquivos do Ricardo\\Battlefield 1942\\BF1942.exe"=
"c:\\Arquivos do Ricardo\\Battlefield 1942\\BF1942_w32ded.exe"=
"c:\\Arquivos do Ricardo\\Colin McRae Rally 2005\\CMR5.EXE"=
"c:\\Arquivos do Ricardo\\Battlefield 2\\BF2.exe"=
"c:\\Arquivos do Ricardo\\Utilitários\\BitLord\\BitLord.exe"=
"c:\\Arquivos do Ricardo\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Arquivos do Ricardo\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"f:\\Meus Jogos\\TDU\\TestDriveUnlimited.exe"=
"f:\\Meus Jogos\\TrackMania Nations Forever\\TmForever.exe"=
"f:\\Meus Jogos\\Call of Duty 4 Modern Warfare\\iw3mp.exe"=
"f:\\Meus Jogos\\First Encounter Assault Recon\\fpupdate.exe"=
"f:\\Meus Jogos\\First Encounter Assault Recon\\FEAR.exe"=
"f:\\Meus Jogos\\First Encounter Assault Recon\\FEARMP.exe"=
"f:\\Meus Jogos\\SEGA Rally Revo\\SEGA Rally.exe"=
"f:\\Meus Jogos\\Colin McRae DiRT\\DiRT\\DiRT.exe"=
"f:\\Meus Jogos\\Joint Task Force\\jtf.exe"=
"f:\\Meus Jogos\\Half-Life 2\\SteamApps\\jmchawk\\counter-strike source\\hl2.exe"=
"f:\\Meus Jogos\\Comanche 4\\update.exe"=
"f:\\Meus Jogos\\Grid\\GRID.exe"=
"f:\\Meus Jogos\\Crysis\\Bin32\\Crysis.exe"=
"f:\\Meus Jogos\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=
"c:\\Arquivos de programas\\avgupd.exe"=
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
R1 atitray;atitray;f:\utilitarios\ATI Tray Tools\atitray.sys [2008-09-08 18336]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-09 325128]
R1 SASDIFSV;SASDIFSV;c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R1 SNSID;SNSID;c:\windows\system32\drivers\SNSID.SYS [2007-07-02 22784]
R1 SNSMS;SNSMS;c:\windows\system32\drivers\SNSMS.SYS [2006-04-01 35464]
R2 avg8wd;AVG8 WatchDog;c:\arquiv~1\avgwdsvc.exe [2009-02-09 298264]
R2 NwSapAgent;Agente SAP;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
R2 Ps2KSecureKeyboard;SecureKbd;c:\windows\system32\drivers\psseckbd.sys [2006-04-01 15048]
R2 SNMgrSvc;SNMgrSvc;c:\windows\system32\SnMgrSvc.exe [2006-04-01 280712]
R2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-05-20 93184]
R3 vhidmini;Secure Mouse;c:\windows\system32\drivers\vhsecmou.sys [2006-04-01 12464]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [2006-11-10 24064]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2006-09-28 16512]
S3 C21NDIS;COM21 DP1110 USB Cable Modem;c:\windows\system32\drivers\C21Ndis.sys [2001-03-20 10962]
S3 Fadpu16E;Fadpu16E; [x]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]
S3 SASENUM;SASENUM;c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S4 ActiveSMART Service;ActiveSMART Service;f:\utilitarios\Active SMART\ASmartService.exe [2008-07-21 538272]
S4 ioloFileInfoList;iolo FileInfoList Service; [x]
S4 ioloSystemService;iolo System Service; [x]
.
Conteúdo da pasta 'Tarefas Agendadas'
2009-02-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORFÃOS REMOVIDOS - - - -
MSConfigStartUp-nwiz - nwiz.exe
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br/
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} - hxxps://ww4.banrisul.com.br/bto/link/msie/SecureControl2k.cab
FF - ProfilePath - c:\documents and settings\Maria\Dados de aplicativos\Mozilla\Firefox\Profiles\wr8lrxb5.default\
FF - component: c:\arquivos de programas\Firefox\components\avgssff.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\arquivos de programas\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npAtmCap.dll
FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npSnInstall.dll
---- FIREFOX POLICIES ----
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.
.
------- Associação de arquivos/ficheiros -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-12 08:54:18
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-57989841-1078145449-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b1,8c,dc,2a,d4,0d,34,48,d5,ff,8b,8d,61,01,8b,f6,e0,83,52,0e,ec,73,c4,
be,fe,03,ba,a0,ee,3e,64,60,9a,2f,9f,c8,20,d6,e9,45,a2,15,68,b1,b5,c1,c8,3a,\
"??"=hex:93,d1,e7,ab,fb,24,8c,1d,c0,c0,35,ea,3b,ed,16,4c
[HKEY_USERS\S-1-5-21-57989841-1078145449-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:4c,0b,bf,89,62,c5,af,c8,34,e3,9e,39,eb,37,74,0c,47,1e,8e,eb,c5,
74,ec,31,b1,e0,3d,54,ff,31,8f,56,c8,1d,20,c0,a4,d8,df,56,bf,2b,2b,7b,a9,65,\
"rkeysecu"=hex:e5,81,d4,14,9a,63,6c,db,db,1f,fa,22,6d,73,1b,a9
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\arquivos do ricardo\Utilitários\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Tempo para conclusão: 2009-02-12 8:56:17
ComboFix-quarantined-files.txt 2009-02-12 10:56:14
Pré-execução: 18 pasta(s) 53,700,743,168 bytes disponíveis
Pós execução: 18 pasta(s) 55,349,870,592 bytes disponíveis
WindowsXP-KB310994-SP2-Home-BootDisk-PTB.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
402 --- E O F --- 2009-01-27 17:10:21
--
Mais uma vez, muito obrigado pela sua ajuda Mr.Wolf, ela tem sido muitíssimo valiosa! :thumbs_up