Professional Documents
Culture Documents
Combo Fix
Combo Fix
1 - NTFSx86 MINIMAL
Microsoft Windows 2000 Professional 5.0.2195.4.1252.55.1046.18.255.177 [GMT -3:
00]
Executando de: C:\ComboFix.exe
ATENAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAO INSTALADA !!
.
(((((((((((((((((((((((((((((((((((((
))))))))))))))))))))))))))))
.
Outras Excluses
)))))))))))))))))))))))
c:\arquivos de programas\INSTALL.LOG
c:\documents and settings\Administrador\Dados de aplicativos\inst.exe
c:\winnt\system32\csrcs.exe
c:\winnt\system32\sshnas21.dll
.
(((((((((((((((((((((((((((((((((((((((
))))))))))))))))))))))))))))
.
Drivers/Servios
)))))))))))))))))))))
-------\Legacy_SSHNAS
-------\Service_SSHNAS
(((((((((((((((( Arquivos/Ficheiros criados de 2009-06-15 to 2009-07-15 )))))
)))))))))))))))))))))))
.
2010-07-09 09:38 . 2007-05-01 23:09
52496 ----a-wc:\winnt\system3
2\vfwwdm32.dll
2010-07-09 09:38 . 2007-05-01 23:09
12560 ----a-wc:\winnt\system3
2\tsbyuv.dll
2010-07-09 09:38 . 2007-05-01 23:09
258320 ----a-wc:\winnt\system3
2\msh263.drv
2010-07-09 09:38 . 2007-05-01 23:09
45840 ----a-wc:\winnt\system3
2\iyuv_32.dll
2010-07-09 09:38 . 2006-09-14 13:27
131072 ----a-wc:\winnt\system3
2\mtkjpeg.dll
2010-07-09 09:38 . 2006-08-01 13:36
44032 ----a-wc:\winnt\system3
2\drivers\usbmtk.sys
2010-07-09 09:38 . 2010-07-09 09:38
-------d-----wC:\Webca
m_Driver_v1_2_0
2010-07-09 09:31 . 2007-05-01 23:09
22768 ----a-wc:\winnt\system3
2\drivers\usbser.sys
2010-07-09 09:29 . 2010-07-09 09:29
-------d-----wC:\MTKUS
B_Driver_6235
2010-07-09 08:11 . 2010-07-09 08:17
-------d-----wc:\arqui
vos de programas\mp3DirectCut
2010-06-19 07:56 . 2010-06-19 07:56
-------d-----wc:\docum
ents and settings\All Users\Dados de aplicativos\nView_Profiles
2010-06-19 07:48 . 2004-10-29 21:50
462848 ----a-wc:\winnt\system3
2\nvshell.dll
2010-06-19 07:48 . 2004-10-29 21:50
1441792 ----a-wc:\winnt\system3
2\nview.dll
2010-06-19 07:48 . 2010-06-19 07:54
-------d-----wc:\winnt
\nview
2010-06-19 07:48 . 2004-10-29 21:50
442368 ----a-wc:\winnt\system3
2\nvappbar.exe
ns
2009-10-20 12:13 . 2009-10-20 12:13
-------d-----wC:\commo
n
2009-10-20 12:13 . 2009-10-20 12:13
-------d-----wC:\tools
2009-10-20 12:13 . 2009-10-20 12:13
4753
----a-wC:\unins000.dat
2009-10-20 12:13 . 2009-10-20 12:13
-------d-----wc:\winnt
\WinAVI Video Converter 9.0
2009-10-20 12:13 . 2009-10-20 12:13
-------d-----wc:\arqui
vos de programas\WinAVI Video Converter 9.0
2009-10-12 20:13 . 2009-10-12 20:13
47360 ----a-wc:\winnt\system3
2\drivers\pcouffin.sys
2009-10-12 20:13 . 2009-10-12 20:13
47360 ----a-wc:\documents and
settings\Administrador\Dados de aplicativos\pcouffin.sys
2009-10-12 20:13 . 2010-05-16 12:33
-------d-----wc:\docum
ents and settings\Administrador\Dados de aplicativos\Vso
2009-10-12 20:11 . 2009-10-12 20:12
-------d-----wc:\arqui
vos de programas\DVDFab 6
2009-10-12 17:11 . 2009-10-12 17:11
-------d-----wc:\docum
ents and settings\Administrador\Dados de aplicativos\Malwarebytes
2009-10-12 13:34 . 2010-07-14 14:34
-------d-----wC:\Clone
DVDTemp
2009-10-12 12:15 . 2009-10-12 12:15
-------d-----wc:\docum
ents and settings\All Users\Dados de aplicativos\SlySoft
2009-10-12 12:14 . 2009-10-12 12:14
-------d-----wc:\arqui
vos de programas\Elaborate Bytes
2009-10-12 12:14 . 2009-11-16 03:48
-------d-----wc:\arqui
vos de programas\SlySoft
2009-10-12 09:04 . 2009-11-03 03:37
-------d-----wc:\docum
ents and settings\All Users\Dados de aplicativos\DVD Shrink
2009-10-12 09:03 . 2009-10-12 09:03
-------d-----wc:\arqui
vos de programas\DVD Shrink
2009-10-12 05:58 . 2009-10-12 05:58
-------d-----wc:\arqui
vos de programas\Cpia de save
2009-10-03 22:09 . 2009-10-03 22:09
-------d-----wc:\arqui
vos de programas\DemoForge
2009-10-03 22:09 . 2009-10-03 22:24
-------d-----wc:\arqui
vos de programas\UltraVNC
2009-10-03 22:04 . 2009-10-03 22:07
-------d-----wc:\arqui
vos de programas\NetListener
2009-10-03 21:53 . 2009-10-03 21:53
-------d-----wc:\arqui
vos de programas\Winco
2009-10-03 21:50 . 2009-10-03 21:50
-------d-----wc:\arqui
vos de programas\Toleron
2009-09-19 03:13 . 2009-09-19 03:14
-------d-----wc:\arqui
vos de programas\Arquivos comuns\Akamai
2009-07-12 10:59 . 2009-07-12 11:09
3054946 -c--a-rC:\ComboFix.exe
2009-07-11 07:56 . 2009-07-31 12:48
-------d-----wc:\arqui
vos de programas\FanaticMU
.
((((((((((((((((((((((((((((((((((((( Relatrio Find3M )))))))))))))))))))))))
)))))))))))))))))))))))))))))
.
2010-07-15 14:29 . 2000-04-11 13:04
-------d-----wc:\docum
ents and settings\Administrador\Dados de aplicativos\DMCache
2010-06-18 03:30 . 2008-11-09 01:13
-------d-----wc:\arqui
vos de programas\SystemRequirementsLab
2010-03-31 09:40 . 2007-11-16 15:20
-------d--h--wc:\arqui
vos de programas\InstallShield Installation Information
2010-02-19 08:39 . 2000-04-11 16:19
52224 ----a-wc:\documents and
settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\yt3bandv.d
efault\extensions\{aac4043a-8832-4abe-9963-35377f30b8e6}\components\FFExternalAl
ert.dll
2010-02-19 08:39 . 2000-04-11 16:19
101376 ----a-wc:\documents and
settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\yt3bandv.d
efault\extensions\{aac4043a-8832-4abe-9963-35377f30b8e6}\components\RadioWMPCore
.dll
2010-02-13 04:12 . 2010-02-13 04:12
0
----a-wc:\arquivos de p
rogramas\agpspZs~3`2=
2010-01-15 01:08 . 2007-12-15 18:42
721904 ----a-wc:\winnt\system3
2\drivers\sptd.sys
2009-12-24 13:34 . 2000-04-11 08:06
-------d-----wc:\docum
ents and settings\All Users\Dados de aplicativos\vsosdk
2009-10-27 00:49 . 2009-10-27 00:49
-------d-----wc:\arqui
vos de programas\K-Lite Codec Pack
2009-10-27 00:33 . 2000-04-11 13:11
-------d-----wc:\arqui
vos de programas\Essentials Codec Pack
2009-10-13 18:00 . 2009-10-27 00:49
85504 ----a-wc:\winnt\system3
2\ff_vfw.dll
2009-10-12 20:11 . 2001-05-07 13:00
69568 ----a-wc:\winnt\system3
2\perfc016.dat
2009-10-12 20:11 . 2001-05-07 13:00
419020 ----a-wc:\winnt\system3
2\perfh016.dat
2009-10-12 13:41 . 2000-04-11 02:11
-------d-----wc:\arqui
vos de programas\KAPITALSIN
2009-10-12 07:27 . 2009-04-11 10:24
-------d-----wc:\arqui
vos de programas\Diablo II
2009-10-12 05:58 . 2009-06-12 06:27
-------d-----wc:\arqui
vos de programas\Warcraft III
2009-09-02 20:41 . 2000-04-11 03:31
102439 ----a-wc:\winnt\system3
2\sipr3260.dll
2009-09-02 20:41 . 2000-04-11 03:31
65602 ----a-wc:\winnt\system3
2\cook3260.dll
2009-09-02 20:41 . 2000-04-11 03:31
217127 ----a-wc:\winnt\system3
2\drv43260.dll
2009-09-02 20:41 . 2000-04-11 03:31
208935 ----a-wc:\winnt\system3
2\drv33260.dll
2009-09-02 20:41 . 2000-04-11 03:31
176165 ----a-wc:\winnt\system3
2\drv23260.dll
2009-09-02 20:41 . 2000-04-11 03:31
1184984 ----a-wc:\winnt\system3
2\wvc1dmod.dll
2009-08-16 15:08 . 2009-10-27 00:49
178176 ----a-wc:\winnt\system3
2\unrar.dll
2009-08-08 07:51 . 2009-04-11 11:16
43520 ----a-wc:\winnt\system3
2\CmdLineExt03.dll
2009-08-06 21:24 . 2007-11-15 19:09
327896 ----a-wc:\winnt\system3
2\wucltui.dll
2009-08-06 21:24 . 2007-11-15 19:09
209632 ----a-wc:\winnt\system3
2\wuweb.dll
2009-08-06 21:24 . 2007-11-15 19:09
44768 -c--a-wc:\winnt\system3
2\wups2.dll
2009-08-06 21:24 . 2007-11-15 19:09
35552 -c--a-wc:\winnt\system3
2\wups.dll
2009-08-06 21:24 . 2007-11-15 16:34
53472 ----a-wc:\winnt\system3
2\wuauclt.exe
2009-08-06 21:24 . 2003-06-19 02:05
96480 ----a-wc:\winnt\system3
2\cdm.dll
2009-08-06 21:23 . 2007-11-15 19:09
575704 ----a-wc:\winnt\system3
2\wuapi.dll
2009-08-06 21:23 . 2007-11-16 19:38
274288 ----a-wc:\winnt\system3
2\mucltui.dll
2009-08-06 21:23 . 2007-11-15
2\wuaueng.dll
2009-08-06 21:23 . 2007-07-30
2\muweb.dll
2009-07-29 06:35 . 2009-10-27
2\x264vfw.dll
2009-07-14 00:15 . 2009-10-27
2\dpl100.dll
2009-07-14 00:15 . 2009-10-27
2\divx.dll
2009-06-12 07:53 . 2009-06-12
n.dat
2009-06-12 06:48 . 2009-06-12
n.pif
2009-06-12 06:48 . 2009-06-12
n.exe
2009-05-29 21:37 . 2009-10-27
2\xvidvfw.dll
2009-05-29 21:31 . 2009-10-27
2\xvidcore.dll
2009-04-28 20:20 . 2007-11-17
2\drivers\PxHelp20.sys
2009-04-28 20:20 . 2007-11-17
2\pxafs.dll
2009-04-17 14:03 . 2009-04-26
2\MSJCE.dll
2008-01-09 18:31 . 2007-11-15
rogramas\folder.htt
2000-04-11 02:24 . 2000-04-11
rogramas\khw
.
16:34
1929952 ----a-w-
c:\winnt\system3
21:18
215920 ----a-w-
c:\winnt\system3
00:49
2378752 ----a-w-
c:\winnt\system3
00:49
90112
----a-w-
c:\winnt\system3
00:49
685056 ----a-w-
c:\winnt\system3
03:38
85279
-c--a-w-
c:\winnt\War3Uni
06:39
2829
-c--a-w-
c:\winnt\War3Uni
03:38
139264 -c--a-w-
c:\winnt\War3Uni
00:49
205824 ----a-w-
c:\winnt\system3
00:49
881664 ----a-w-
c:\winnt\system3
00:55
44944
-c----w-
c:\winnt\system3
00:55
129520 -c----w-
c:\winnt\system3
05:08
69632
-c--a-w-
c:\winnt\system3
16:38
22040
-c-h--w-
c:\arquivos de p
02:24
--sha-r-
c:\arquivos de p
245520 2060752B92A633AACD60576217BA4207
c:\winnt
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
\nwprovau]
2007-05-01 16:06
141584 ----a-wc:\winnt\system32\nwprovau.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\winnt\system32\MsgPlusLoader.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ
msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^Administrador^Menu Iniciar^Progr
amas^Inicializar^PowerReg Scheduler V3.exe]
backup=c:\winnt\pss\PowerReg Scheduler V3.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrador^Menu Iniciar^Progr
amas^Inicializar^PowerReg Scheduler.exe]
backup=c:\winnt\pss\PowerReg Scheduler.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Acelerador Cresce.Net.lnk]
backup=c:\winnt\pss\Acelerador Cresce.Net.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Acelerador POP.lnk]
backup=c:\winnt\pss\Acelerador POP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Discador Oi Internet.lnk]
backup=c:\winnt\pss\Discador Oi Internet.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^DRIVER PNP Monitor.lnk]
backup=c:\winnt\pss\DRIVER PNP Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Lorencia & MUWorld.lnk]
backup=c:\winnt\pss\Lorencia & MUWorld.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Microsoft Office.lnk]
backup=c:\winnt\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas
^Inicializar^Run Google Web Accelerator.lnk]
backup=c:\winnt\pss\Run Google Web Accelerator.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAu
tomount
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft C
onnection Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwareby
tes' Anti-Malware
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SlipStrea
m
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTe
rminator
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAge
nt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Winconnec
tion4
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NVSvc"=2 (0x2)
"Spooler"=2 (0x2)
"Schedule"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"nHancer"=2 (0x2)
"StiSvc"=2 (0x2)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=2 (0x2)
"sp_rssrv"=2 (0x2)
"AVP"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"ose"=3 (0x3)
"wuauserv"=2 (0x2)
"StarWindServiceAE"=2 (0x2)
"SCardSvr"=3 (0x3)
"SCardDrv"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE c:\winnt\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /install
"Synchronization Manager"=mobsync.exe /logon
R0 amd751;AMD 751 AGP Filter;c:\winnt\system32\drivers\amd751.sys [15/11/2007 14
:22 31684]
R0 NVDual;NVDual;c:\winnt\system32\drivers\nvdual.sys [11/1/2008 11:15 1598]
R0 pmfilt;pmfilt;c:\winnt\system32\drivers\pmfilt.sys [11/7/2008 06:24 10112]
R0 pmhelp;pmhelp;c:\winnt\system32\drivers\pmhelp.sys [11/7/2008 06:24 50464]
S3 cpuz131;cpuz131; [x]
S3 DCamUSBMtk;Webcam phone;c:\winnt\system32\drivers\usbmtk.sys [9/7/2010 06:38
44032]
S3 dfmirage;dfmirage;c:\winnt\system32\drivers\dfmirage.sys [25/11/2005 17:43 31
896]
S3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\winnt\system32\drivers\
RMSPPPOE.SYS [12/4/2000 10:29 33792]
S3 XDva031;XDva031; [x]
S3 XDva068;XDva068; [x]
S3 XDva081;XDva081; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ
Akamai
.
Contedo da pasta 'Tarefas Agendadas'
2008-07-09 c:\winnt\Tasks\XoftSpySE 2.job
- c:\arquivos de programas\XoftSpySE\XoftSpy.exe [2007-07-13 11:43]
2008-07-07 c:\winnt\Tasks\XoftSpySE.job
- c:\arquivos de programas\XoftSpySE\XoftSpy.exe [2007-07-13 11:43]
2010-06-15 c:\winnt\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
- c:\winnt\Ypygya.exe [2010-06-15 18:04]
.
- - - - ORFOS REMOVIDOS - - - -
HKLM-Explorer_Run-csrcs - c:\winnt\system32\csrcs.exe
.
------- Scan Suplementar ------.
uStart Page =
mSearch Bar = hxxp://farejador.ig.com.br/ie/
IE: Download All Links with IDM - c:\arquivos de programas\Internet Download Man
ager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\arquivos de programas\Internet Down
load Manager\IEGetVL.htm
IE: Download with IDM - c:\arquivos de programas\Internet Download Manager\IEExt
.htm
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3
000
LSP: c:\arquivos de programas\TrafficCompressor\TCompLsp.dll
LSP: %SystemRoot%\system32\msafd.dll
TCP: {1AB7C2BB-32AB-42AE-BC4C-1A40A1E30303} = 192.168.0.1,10.1.1.1
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\
Mozilla\Firefox\Profiles\yt3bandv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.
aspx?ctid=CT2536667&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Castle Age Customized Web Search
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT25
36667&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Administrador\Dados de aplicativos\Moz
illa\Firefox\Profiles\yt3bandv.default\extensions\{aac4043a-8832-4abe-9963-35377
f30b8e6}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Administrador\Dados de aplicativos\Moz
illa\Firefox\Profiles\yt3bandv.default\extensions\{aac4043a-8832-4abe-9963-35377
f30b8e6}\components\RadioWMPCore.dll
FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de progr
amas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
---- FIREFOX POLICIES ---FF - user.js: network.http.max-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 750
FF - user.js: network.http.max-persistent-connections-per-server - 2
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("b
rowser.fixup.alternate.suffix", ".com.br");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http:/
/www.gmer.net
Rootkit scan 2009-07-15 15:58
Windows 5.0.2195 Service Pack 4 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializveis ocultas ...
.
--------------------- DLLs Carregadas Sob os Processos em Execuo -------------------- - - - - - - > 'winlogon.exe'(184)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
- - - - - - - > 'explorer.exe'(248)
c:\winnt\AppPatch\AcLayers.DLL
.
Tempo para concluso: 2009-07-15 16:06 - Mquina reiniciou
ComboFix-quarantined-files.txt 2009-07-15 19:06
ComboFix2.txt 2009-07-12 12:09
Pr-execuo: 2.444.615.680 bytes disponveis
Ps execuo: 2.559.385.600 bytes disponveis
352