Guest
Public paste!

Untitled

By: a guest | Mar 20th, 2010 | Syntax: None | Size: 9.44 KB | Hits: 116 | Expires: Never
Copy text to clipboard
  1. ComboFix 10-03-19.06 - Administrador 20/03/2010   9:09.1.1 - x86
  2. Microsoft Windows XP Professional  5.1.2600.2.1252.55.1046.18.255.102 [GMT -3:00]
  3. Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe
  4.  
  5. ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!
  6. .
  7.  
  8. (((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
  9. .
  10.  
  11. c:\recycler\NPROTECT
  12.  
  13. .
  14. ((((((((((((((((   Arquivos/Ficheiros criados de 2010-02-20 to 2010-03-20  ))))))))))))))))))))))))))))
  15. .
  16.  
  17. 2010-03-20 00:32 . 2010-03-20 00:32     --------        d-----w-        c:\arquivos de programas\Trend Micro
  18. 2010-03-18 00:50 . 2009-12-21 19:07     594432  -c----w-        c:\windows\system32\dllcache\msfeeds.dll
  19. 2010-03-18 00:50 . 2009-12-21 19:07     1985536 -c----w-        c:\windows\system32\dllcache\iertutil.dll
  20. 2010-03-18 00:50 . 2009-12-21 19:07     246272  -c----w-        c:\windows\system32\dllcache\ieproxy.dll
  21. 2010-03-18 00:50 . 2009-12-21 19:07     55296   -c----w-        c:\windows\system32\dllcache\msfeedsbs.dll
  22. 2010-03-18 00:50 . 2009-12-21 19:08     12800   -c----w-        c:\windows\system32\dllcache\xpshims.dll
  23. 2010-03-18 00:50 . 2009-12-21 19:07     11070464        -c----w-        c:\windows\system32\dllcache\ieframe.dll
  24. 2010-03-17 18:43 . 2010-03-18 19:57     --------        d-----w-        c:\windows\ie8updates
  25.  
  26. .
  27. (((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
  28. .
  29. 2010-03-20 00:28 . 2009-07-06 23:07     --------        d-----w-        c:\arquivos de programas\Puxa Rápido
  30. 2010-03-19 21:09 . 2006-06-05 16:03     --------        d-----w-        c:\arquivos de programas\Arquivos comuns\Symantec Shared
  31. 2010-03-19 21:09 . 2006-04-20 22:37     --------        d-----w-        c:\arquivos de programas\Spybot - Search & Destroy
  32. 2010-03-19 21:04 . 2006-06-07 16:38     --------        d-----w-        c:\arquivos de programas\Google
  33. 2010-03-19 20:16 . 2007-02-13 23:53     --------        d-----w-        c:\arquivos de programas\LimeWire
  34. 2010-03-19 20:14 . 2006-04-20 00:33     --------        d-----w-        c:\arquivos de programas\Arquivos comuns\Adobe
  35. 2010-03-19 20:13 . 2006-04-20 22:37     --------        d-----w-        c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy
  36. 2010-03-19 20:11 . 2006-04-20 00:31     --------        d-----w-        c:\arquivos de programas\ESET
  37. 2010-03-18 20:45 . 2009-09-16 15:46     --------        d-----w-        c:\arquivos de programas\Microsoft Silverlight
  38. 2010-03-18 01:57 . 2007-02-13 23:57     --------        d-----w-        c:\documents and settings\Administrador\Dados de aplicativos\LimeWire
  39. 2010-03-18 01:48 . 2006-05-12 00:26     --------        d-----w-        c:\documents and settings\Administrador\Dados de aplicativos\teamspeak2
  40. 2010-03-18 00:27 . 2001-10-28 17:07     80586   ----a-w-        c:\windows\system32\perfc016.dat
  41. 2010-03-18 00:27 . 2001-10-28 17:07     471090  ----a-w-        c:\windows\system32\perfh016.dat
  42. 2010-03-16 22:34 . 2007-02-15 00:18     --------        d-----w-        c:\arquivos de programas\Winamp
  43. 2010-03-16 22:00 . 2007-02-14 01:09     --------        d-----w-        c:\arquivos de programas\Windows Media Connect 2
  44. 2009-12-31 16:14 . 2004-08-04 02:14     352640  ----a-w-        c:\windows\system32\drivers\srv.sys
  45. 2009-12-21 19:08 . 2004-08-04 03:45     916480  ----a-w-        c:\windows\system32\wininet.dll
  46. 2007-08-29 20:07 . 2007-08-29 20:07     3099767 ----a-w-        c:\arquivos de programas\bf2007.exe
  47. .
  48.  
  49. ((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
  50. .
  51. .
  52. *Nota* entradas vazias e legítimas por defeito não são mostradas.
  53. REGEDIT4
  54.  
  55. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  56. "ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
  57.  
  58. [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
  59. "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
  60.  
  61. [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
  62. "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
  63.  
  64. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
  65. "ForceClassicControlPanel"= 1 (0x1)
  66. HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
  67.  
  68. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
  69. 2001-07-09 10:50        155648  ----a-r-        c:\windows\system32\NeroCheck.exe
  70.  
  71. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
  72. "ISUSPM Startup"=c:\arquiv~1\ARQUIV~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
  73. "SMSERIAL"=sm56hlpr.exe
  74. "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"
  75. "ISUSScheduler"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start
  76. "snpstd3"=c:\windows\vsnpstd3.exe
  77.  
  78. [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
  79. "%windir%\\system32\\sessmgr.exe"=
  80. "c:\\Arquivos de programas\\Navnt\\POProxy.exe"=
  81. "c:\\Arquivos de programas\\Puxa Rápido\\PuxaRapido.exe"=
  82. "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
  83. "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
  84. "c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=
  85.  
  86. R3 npggsvc;nProtect GameGuard Service; [x]
  87. R3 npkycryp;npkycryp; [x]
  88. S2 NAV Auto-Protect;NAV Auto-Protect;c:\arquiv~1\Navnt\navapsvc.exe [1999-05-07 90112]
  89.  
  90. .
  91. Conteúdo da pasta 'Tarefas Agendadas'
  92.  
  93. 2010-03-20 c:\windows\Tasks\GlaryInitialize.job
  94. - c:\arquivos de programas\Glary Utilities\initialize.exe [2009-12-19 12:21]
  95.  
  96. 2002-01-01 c:\windows\Tasks\SmartDefrag.job
  97. - c:\arquivos de programas\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2002-01-01 17:30]
  98. .
  99. .
  100. ------- Scan Suplementar -------
  101. .
  102. uStart Page = hxxp://www.google.com.br/
  103. uSearchAssistant = hxxp://www.google.com/ie
  104. uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
  105. IE: &Clean Traces
  106. IE: &Download with &DAP
  107. IE: Download &all with DAP
  108. IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
  109. IE: Google Sidewiki...
  110. FF - ProfilePath - c:\documents and settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\g7o72m6b.default\
  111. FF - prefs.js: browser.search.selectedEngine - Puxaki.com.br
  112. FF - prefs.js: browser.startup.homepage - www.google.com.br
  113. FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q=
  114. FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
  115. FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll
  116. FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll
  117. FF - plugin: c:\arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll
  118. FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
  119.  
  120. ---- FIREFOX POLICIES ----
  121. c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
  122. .
  123. - - - - ORFÃOS REMOVIDOS - - - -
  124.  
  125. URLSearchHooks-{F4F10C1D-87C7-404A-B4B3-000000000000} - (no file)
  126.  
  127.  
  128.  
  129. **************************************************************************
  130.  
  131. catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
  132. Rootkit scan 2010-03-20 09:19
  133. Windows 5.1.2600 Service Pack 2 NTFS
  134.  
  135. Procurando processos ocultos ...
  136.  
  137. Procurando entradas auto inicializáveis ocultas ...
  138.  
  139. Procurando ficheiros/arquivos ocultos ...
  140.  
  141. Varredura completada com sucesso
  142. arquivos/ficheiros ocultos: 0
  143.  
  144. **************************************************************************
  145. .
  146. --------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
  147.  
  148. [HKEY_USERS\S-1-5-21-1547161642-842925246-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
  149. @Denied: (2) (Administrator)
  150. "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  151.    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,29,a5,bc,bd,f8,a7,63,41,bd,77,6d,\
  152. "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
  153.    d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,29,a5,bc,bd,f8,a7,63,41,bd,77,6d,\
  154.  
  155. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5b36680f-614c-486f-9963-f186612f5c0e}]
  156. @Denied: (Full) (Everyone)
  157. "Model"=dword:00000096
  158. "Therad"=dword:0000001e
  159. "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
  160.    38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
  161.  
  162. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
  163. @Denied: (Full) (Everyone)
  164. "scansk"=hex(0):b7,8d,59,4d,bf,af,40,20,39,77,36,c7,76,33,43,9a,8c,96,65,76,a6,
  165.    eb,66,3f,4c,e3,0f,89,89,64,d4,63,e8,cd,0c,84,86,ee,1a,c1,00,00,00,00,00,00,\
  166.  
  167. [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Òw*]
  168. "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
  169. .
  170. --------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
  171.  
  172. - - - - - - - > 'winlogon.exe'(400)
  173. c:\windows\system32\Ati2evxx.dll
  174.  
  175. - - - - - - - > 'explorer.exe'(872)
  176. c:\windows\system32\WININET.dll
  177. c:\windows\system32\webcheck.dll
  178. c:\windows\system32\msi.dll
  179. c:\windows\system32\WPDShServiceObj.dll
  180. c:\windows\system32\PortableDeviceTypes.dll
  181. c:\windows\system32\PortableDeviceApi.dll
  182. .
  183. Tempo para conclusão: 2010-03-20  09:28:22
  184. ComboFix-quarantined-files.txt  2010-03-20 12:28
  185.  
  186. Pré-execução: 15 pasta(s) 12.410.040.320 bytes disponíveis
  187. Pós execução: 19 pasta(s) 12.498.325.504 bytes disponíveis
  188.  
  189. - - End Of File - - CA634C9D5CD69AD21CF864E4CBC37EE9