Advertisement
Guest User

virus 1

a guest
Mar 12th, 2011
197
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.55 KB | None | 0 0
  1. » MBAM «
  2.  
  3. Malwarebytes' Anti-Malware 1.37
  4. Versão do banco de dados: 2182
  5. Windows 5.1.2600 Service Pack 3
  6.  
  7. 9/6/2009 16:40:24
  8. mbam-log-2009-06-09 (16-40-24).txt
  9.  
  10. Tipo de Verificação: Completa (C:\|D:\|E:\|F:\|)
  11. Objetos verificados: 256874
  12. Tempo decorrido: 1 hour(s), 1 minute(s), 17 second(s)
  13.  
  14. Processos da Memória infectados: 0
  15. Módulos de Memória Infectados: 0
  16. Chaves do Registro infectadas: 0
  17. Valores do Registro infectados: 0
  18. Ítens do Registro infectados: 5
  19. Pastas infectadas: 0
  20. Arquivos infectados: 0
  21.  
  22. Processos da Memória infectados:
  23. (Nenhum ítem malicioso foi detectado)
  24.  
  25. Módulos de Memória Infectados:
  26. (Nenhum ítem malicioso foi detectado)
  27.  
  28. Chaves do Registro infectadas:
  29. (Nenhum ítem malicioso foi detectado)
  30.  
  31. Valores do Registro infectados:
  32. (Nenhum ítem malicioso foi detectado)
  33.  
  34. Ítens do Registro infectados:
  35. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
  36. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
  37. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
  38. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
  39. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
  40.  
  41. Pastas infectadas:
  42. (Nenhum ítem malicioso foi detectado)
  43.  
  44. Arquivos infectados:
  45. (Nenhum ítem malicioso foi detectado)
  46.  
  47.  
  48.  
  49.  
  50.  
  51. » HIJACK THIS «
  52.  
  53. Logfile of Trend Micro HijackThis v2.0.2
  54. Scan saved at 16:56:50, on 9/6/2009
  55. Platform: Windows XP SP3 (WinNT 5.01.2600)
  56. MSIE: Internet Explorer v7.00 (7.00.5730.0013)
  57. Boot mode: Normal
  58.  
  59. Running processes:
  60. C:\WINDOWS\System32\smss.exe
  61. C:\WINDOWS\system32\winlogon.exe
  62. C:\WINDOWS\system32\services.exe
  63. C:\WINDOWS\system32\lsass.exe
  64. C:\WINDOWS\system32\svchost.exe
  65. C:\WINDOWS\System32\svchost.exe
  66. C:\WINDOWS\system32\spoolsv.exe
  67. C:\WINDOWS\system32\nvsvc32.exe
  68. C:\Arquivos de programas\Ralink\Common\RalinkRegistryWriter.exe
  69. C:\WINDOWS\Explorer.EXE
  70. C:\WINDOWS\system32\ctfmon.exe
  71. C:\WINDOWS\RTHDCPL.EXE
  72. C:\Arquivos de programas\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe
  73. C:\WINDOWS\system32\RUNDLL32.EXE
  74. C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
  75. C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
  76. C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
  77. C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
  78. C:\Arquivos de programas\Ralink\Common\RaUI.exe
  79. C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe
  80. C:\DOCUME~1\jonathas\CONFIG~1\Temp\ikduc.exe
  81. C:\Arquivos de programas\Mozilla Firefox\firefox.exe
  82. C:\WINDOWS\system32\svchost.exe
  83. C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
  84.  
  85. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.Microsoft....k/?LinkId=54896
  86. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.Microsoft....k/?LinkId=69157
  87. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.Microsoft....k/?LinkId=69157
  88. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.Microsoft....k/?LinkId=54896
  89. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.Microsoft....k/?LinkId=54896
  90. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.Microsoft....k/?LinkId=69157
  91. R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.Microsoft....k/?LinkId=74005
  92. R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Arquivos de programas\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
  93. O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~1\Office12\GRA8E1~1.DLL
  94. O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  95. O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Arquivos de programas\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
  96. O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Arquivos de programas\AskTBar\bar\1.bin\ASKTBAR.DLL
  97. O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Arquivos de programas\AskTBar\bar\1.bin\ASKTBAR.DLL
  98. O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
  99. O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
  100. O4 - HKLM\..\Run: [nod32kui] "C:\Arquivos de programas\Eset\nod32kui.exe" /WAITSERVICE
  101. O4 - HKLM\..\Run: [EnvyHFCPL] C:\Arquivos de programas\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe 1
  102. O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
  103. O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
  104. O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
  105. O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
  106. O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
  107. O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
  108. O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
  109. O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
  110. O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
  111. O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
  112. O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
  113. O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
  114. O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
  115. O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\Ralink\Common\RaUI.exe
  116. O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
  117. O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000
  118. O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll
  119. O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll
  120. O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL
  121. O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
  122. O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
  123. O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.Microsoft.com/intl/br/access/allinone.asp
  124. O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~1\Office12\GR99D3~1.DLL
  125. O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
  126. O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
  127. O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Arquivos de programas\Ralink\Common\RalinkRegistryWriter.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement