PDA

View Full Version : Need help - Virtumond.dll



sopoku
2008-05-13, 13:56
Hi all,

Yesterday, my spybot found virtumond.dll in my computer, but it was unable to resolve the problem because he couldn't delete a certain file called 'something.dll_old'. After reading some of the old posts posted here, i ran ComboFix.exe and after rebooting i was able to delete the file and after that spybot says my computer is clean. I need help because i don't know if the computer is really clean so here is my HJT log, for someone who can analyze it.
Sorry for my poor english, and many thx.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35, on 2008-05-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe
C:\Programas\Java\jre1.6.0_06\bin\jusched.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\AveDesk\AveDesk.exe
C:\Programas\DAEMON Tools Lite\daemon.exe
C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programas\Microsoft Office\Office12\OUTLOOK.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clix.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0EAE3D0-8B40-4CDA-A2B9-2CFE6E41712D} - C:\WINDOWS\system32\qoMdCTJc.dll (file missing)
O2 - BHO: (no name) - {AE6F8D85-21E5-47EF-AA9B-C434E188DEB9} - C:\WINDOWS\system32\efcdEVpp.dll (file missing)
O2 - BHO: (no name) - {FC4A36C9-D7DC-4E7D-82AF-68A62BC04356} - C:\WINDOWS\system32\cbXQhGAT.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVEDESK] "C:\Programas\AveDesk\AveDesk.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Policies\Explorer\Run: [NTSecurity] NTSecurity.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196441605638
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0D986BA-1CA8-44ED-8C69-536635C23B47}: NameServer = 195.23.129.126,194.79.69.222
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programas\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 9475 bytes

Rorschach112
2008-05-13, 14:08
Hello

Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

sopoku
2008-05-13, 14:38
I've run Combofix and HJT. I've disabled both anti-virus and anti-spyware programs during the process. Thanks in advance. Here are the logs:

ComboFix 08-05-12.1 - Helder Dias 2008-05-13 13:19:37.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.1433 [GMT 1:00]
Executando de: C:\Documents and Settings\Helder Dias\Ambiente de trabalho\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
D:\Autorun.inf
H:\Autorun.inf
I:\Autorun.inf
J:\Autorun.inf
K:\Autorun.inf
L:\Autorun.inf
M:\Autorun.inf
N:\Autorun.inf
O:\Autorun.inf
Y:\Autorun.inf
.
---- Previous Run -------
.
C:\Autorun.inf
C:\Documents and Settings\Helder Dias\Application Data\macromedia\Flash Player\#SharedObjects\G5VKXL8A\www.broadcaster.com
C:\Documents and Settings\Helder Dias\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aljplsae.ini
C:\WINDOWS\system32\cJTCdMoq.ini
C:\WINDOWS\system32\cJTCdMoq.ini2
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\system32\efcBsrPH.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ppVEdcfe.ini
C:\WINDOWS\system32\ppVEdcfe.ini2
C:\WINDOWS\system32\qoMfgHWq.dll
C:\WINDOWS\system32\TAGhQXbc.ini
C:\WINDOWS\system32\TAGhQXbc.ini2
C:\WINDOWS\system32\xdknurwt.ini
C:\WINDOWS\system32\yayyWmMf.dll
D:\Autorun.inf
H:\Autorun.inf
I:\Autorun.inf
J:\Autorun.inf
K:\Autorun.inf
L:\Autorun.inf
M:\Autorun.inf
N:\Autorun.inf
O:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WINDOWS_LOG


((((((((((((((((((((((( Ficheiros criados de 2008-04-13 to 2008-05-13 ))))))))))))))))))))))))))))))))
.

2008-05-12 12:59 . 2008-05-12 12:59 2,112 --a------ C:\WINDOWS\system32\nxgjgwfv.exe
2008-05-12 12:26 . 2008-05-12 13:02 <DIR> d-------- C:\Programas\DVDFab 5
2008-05-12 12:16 . 2008-05-12 12:16 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\Thinstall
2008-05-12 12:16 . 2008-05-12 12:16 32 --a------ C:\WINDOWS\Start.INI
2008-05-11 11:49 . 2008-05-11 11:49 2,112 --a------ C:\WINDOWS\system32\urpqubay.exe
2008-05-11 11:43 . 2008-05-12 11:43 109,807 --a------ C:\WINDOWS\BM4f05a259.xml
2008-05-10 11:49 . 2008-05-10 11:49 <DIR> d-------- C:\Programas\eXtreme Movie Manager
2008-05-06 15:52 . 2008-03-28 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-05-06 12:42 . 2008-05-06 12:43 110,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-06 12:42 . 2008-05-06 12:43 48,768 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-06 12:42 . 2008-05-06 12:43 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-06 12:42 . 2008-05-06 12:43 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-03 16:35 . 2008-05-03 16:35 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\Acronis
2008-05-03 16:23 . 2008-05-03 16:23 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Acronis
2008-05-03 15:23 . 2008-05-10 03:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 <DIR> d-------- C:\Programas\Ficheiros comuns\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 <DIR> d-------- C:\Programas\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 441,760 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2008-05-03 15:22 . 2008-05-03 15:22 368,544 --a------ C:\WINDOWS\system32\drivers\tdrpman.sys
2008-05-03 15:22 . 2008-05-03 15:22 129,248 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2008-05-03 15:22 . 2008-05-03 15:22 44,384 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2008-05-02 22:16 . 2008-05-02 22:16 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-02 22:15 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-01 16:06 . 2008-05-01 16:06 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\vlc
2008-05-01 15:01 . 2008-05-01 15:01 <DIR> d-------- C:\Programas\DAEMON Tools Lite
2008-05-01 14:49 . 2008-05-01 14:49 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-23 11:40 . 2006-10-06 17:11 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-23 11:40 . 2006-10-06 17:11 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-23 11:40 . 2008-04-23 11:40 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf

.
((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 12:18 --------- d-----w C:\Programas\Symantec AntiVirus
2008-05-13 10:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-13 09:26 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\uTorrent
2008-05-13 00:10 --------- d-----w C:\Programas\emule0.48a-Xtreme6.1
2008-05-12 12:28 --------- d--h--w C:\Programas\InstallShield Installation Information
2008-05-12 12:02 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Vso
2008-05-12 11:26 87,608 ----a-w C:\Documents and Settings\Helder Dias\Application Data\inst.exe
2008-05-12 11:26 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-05-12 11:26 47,360 ----a-w C:\Documents and Settings\Helder Dias\Application Data\pcouffin.sys
2008-05-10 16:43 --------- d-----w C:\Programas\eMule
2008-05-09 11:42 --------- d-----w C:\Programas\Aicon121
2008-05-06 14:42 --------- d-----w C:\Programas\ATI Technologies
2008-05-06 14:38 --------- d-----w C:\Programas\DIFX
2008-05-06 14:33 --------- d-----w C:\Programas\Paint.NET
2008-05-06 14:07 --------- d-----w C:\Programas\Unlocker
2008-05-06 11:43 --------- d-----w C:\Programas\Symantec
2008-05-06 11:43 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared
2008-05-06 11:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-02 21:16 --------- d-----w C:\Programas\TuneUp Utilities 2008
2008-05-01 13:59 --------- d-----w C:\Programas\Winamp
2008-05-01 13:53 --------- d-----w C:\Programas\SpywareBlaster
2008-05-01 13:48 --------- d-----w C:\Programas\Java
2008-04-11 15:11 --------- d-----w C:\Programas\Declarações Electrónicas
2008-04-11 14:41 --------- d-----w C:\Programas\Ficheiros comuns\PCSuite
2008-04-11 14:41 --------- d-----w C:\Programas\Ficheiros comuns\Nokia
2008-04-11 14:39 --------- d-----w C:\Programas\PC Connectivity Solution
2008-04-11 14:39 --------- d-----w C:\Programas\Nokia
2008-04-11 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-09 02:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-31 14:00 --------- d-----w C:\Programas\Messenger Plus! Live
2008-03-29 06:21 2,873,856 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-03-29 03:18 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-03-21 12:54 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Nokia Multimedia Player
2008-03-20 15:50 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-20 15:26 --------- d-----w C:\Programas\Ficheiros comuns\Nero
2008-03-20 15:25 --------- d-----w C:\Programas\Nero
2008-03-20 15:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-03-18 13:07 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Nokia
2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2008-02-17 16:53 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
.

------- Sigcheck -------

2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-01-12 18:11 360064 8283a4d489b207991efdc8328733d0bc C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-01-12 18:11 360064 8283a4d489b207991efdc8328733d0bc C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-05-13_11.32.33.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-13 10:27:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 12:23:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0EAE3D0-8B40-4CDA-A2B9-2CFE6E41712D}]
C:\WINDOWS\system32\qoMdCTJc.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE6F8D85-21E5-47EF-AA9B-C434E188DEB9}]
C:\WINDOWS\system32\efcdEVpp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC4A36C9-D7DC-4E7D-82AF-68A62BC04356}]
C:\WINDOWS\system32\cbXQhGAT.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"AVEDESK"="C:\Programas\AveDesk\AveDesk.exe" [2005-10-26 00:44 1424896]
"DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 10:39 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" [2008-02-13 12:36 6731312]
"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Acronis Scheduler2 Service"="C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe" [2007-10-30 20:07 140568]
"ccApp"="C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe" [2007-05-29 16:33 52840]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 04:18 437160]
"Nokia.PCSync"="C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]

C:\Documents and Settings\Helder Dias\Menu Iniciar\Programas\Arranque\
ATI Tray Tools.lnk - C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe [2007-05-22 10:04:58 521128]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSecurity"= NTSecurity.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\programas\ficheiros comuns\logitech\bluetooth\LBTWlgn.dll 2008-01-09 13:30 72208 c:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background
"PC Suite Tray"="C:\Programas\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"SpybotSD TeaTimer"=C:\Programas\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"Sunkist2k"=C:\Programas\Multimedia Card Reader\shwicon2k.exe
"!AVG Anti-Spyware"="C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"NeroFilterCheck"=C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe
"Kernel and Hardware Abstraction Layer"=KHALMNPR.EXE
"AcronisTimounterMonitor"=C:\Programas\Acronis\TrueImageHome\TimounterMonitor.exe
"TrueImageMonitor.exe"=C:\Programas\Acronis\TrueImageHome\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programas\\emule0.48a-Xtreme6.1\\emule.exe"=
"C:\\Programas\\eMule\\emule.exe"=
"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Jogos\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\Jogos\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Programas\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Programas\\Ficheiros comuns\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Programas\\TVAnts\\Tvants.exe"=
"C:\\Programas\\uTorrent\\uTorrent.exe"=
"C:\\Programas\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Jogos\\EA Games\\Command & Conquer Generals Zero Hour\\patchget.dat"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Agrupamento Peer-to-Peer do Windows
"3540:UDP"= 3540:UDP:Protocolo de resolução de nome Peer (PNRP)
"50021:TCP"= 50021:TCP:Bittorrent
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 inic162x;inic162x;C:\WINDOWS\system32\DRIVERS\inic162x.sys [2007-09-10 17:27]
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-03 15:22]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 11:22]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 21:22]
R1 atitray;atitray;C:\Programas\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 10:04]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 12:32]
R2 U3sHlpDr;U3sHlpDr;C:\WINDOWS\System32\Drivers\U3sHlpDr.sys [2007-02-22 21:41]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:57]
S3 p2pgasvc;Autenticação de grupo de funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 p2pimsvc;Gestor de identidade de funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 p2psvc;Funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 PNRPSvc;Protocolo de resolução de nome Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 RushTopDevice;RushTopDevice;C:\Programas\MSI\Core Center\RushTop.sys [2006-07-13 11:48]
S3 TryAndDecideService;Acronis Try And Decide Service;"C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-10-30 20:51]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-02 22:16]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc70c87f-f4a7-11db-8bd8-000c7691af0b}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a

.
Conte£do da pasta 'Tarefas Agendadas'
"2008-05-13 12:24:07 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programas\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-13 08:10:00 C:\WINDOWS\Tasks\emulext.job"
- C:\Programas\emule0.48a-Xtreme6.1\emule.exe
"2008-05-13 12:27:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programas\Windows Defender\MpCmdRun.exe
"2008-05-12 23:26:08 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Programas\Spybot - Search & Destroy\SpybotSD.exe!/AUTOCHECK /AUTOFIX /AUTOCLOSE
"2008-04-19 12:31:04 C:\WINDOWS\Tasks\µTorrent.job"


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:29, on 2008-05-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe
C:\Programas\Java\jre1.6.0_06\bin\jusched.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\AveDesk\AveDesk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\DAEMON Tools Lite\daemon.exe
C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clix.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0EAE3D0-8B40-4CDA-A2B9-2CFE6E41712D} - C:\WINDOWS\system32\qoMdCTJc.dll (file missing)
O2 - BHO: (no name) - {AE6F8D85-21E5-47EF-AA9B-C434E188DEB9} - C:\WINDOWS\system32\efcdEVpp.dll (file missing)
O2 - BHO: (no name) - {FC4A36C9-D7DC-4E7D-82AF-68A62BC04356} - C:\WINDOWS\system32\cbXQhGAT.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVEDESK] "C:\Programas\AveDesk\AveDesk.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Policies\Explorer\Run: [NTSecurity] NTSecurity.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196441605638
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0D986BA-1CA8-44ED-8C69-536635C23B47}: NameServer = 195.23.129.126,194.79.69.222
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programas\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 9317 bytes

Rorschach112
2008-05-13, 15:32
Hello

You don't need to PM me, I get email notifications when you reply


1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {A0EAE3D0-8B40-4CDA-A2B9-2CFE6E41712D} - C:\WINDOWS\system32\qoMdCTJc.dll (file missing)
O2 - BHO: (no name) - {AE6F8D85-21E5-47EF-AA9B-C434E188DEB9} - C:\WINDOWS\system32\efcdEVpp.dll (file missing)
O2 - BHO: (no name) - {FC4A36C9-D7DC-4E7D-82AF-68A62BC04356} - C:\WINDOWS\system32\cbXQhGAT.dll (file missing)
O4 - HKCU\..\Policies\Explorer\Run: [NTSecurity] NTSecurity.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


File::
C:\WINDOWS\system32\nxgjgwfv.exe
C:\WINDOWS\system32\urpqubay.exe
C:\WINDOWS\BM4f05a259.xml
N:\LaunchU3.exe

Folder::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc70c87f-f4a7-11db-8bd8-000c7691af0b}]

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Also post a new HijackThis log

sopoku
2008-05-13, 16:01
Hi again,

Just did what you've told me to do, and here are the new logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:52, on 2008-05-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe
C:\Programas\Java\jre1.6.0_06\bin\jusched.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\AveDesk\AveDesk.exe
C:\Programas\DAEMON Tools Lite\daemon.exe
C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clix.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVEDESK] "C:\Programas\AveDesk\AveDesk.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196441605638
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0D986BA-1CA8-44ED-8C69-536635C23B47}: NameServer = 195.23.129.126,194.79.69.222
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programas\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8944 bytes


ComboFix 08-05-12.1 - Helder Dias 2008-05-13 14:42:04.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.2070.18.1350 [GMT 1:00]
Executando de: C:\Documents and Settings\Helder Dias\Ambiente de trabalho\ComboFix.exe
Command switches used :: C:\Documents and Settings\Helder Dias\Ambiente de trabalho\CFScript.txt
* Criado um novo ponto de restauro

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM4f05a259.xml
C:\WINDOWS\system32\nxgjgwfv.exe
C:\WINDOWS\system32\urpqubay.exe
N:\LaunchU3.exe
.

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Helder Dias\Application Data\inst.exe
C:\WINDOWS\BM4f05a259.xml
C:\WINDOWS\system32\nxgjgwfv.exe
C:\WINDOWS\system32\urpqubay.exe
.
---- Previous Run -------
.
C:\autorun.inf
C:\Documents and Settings\Helder Dias\Application Data\macromedia\Flash Player\#SharedObjects\G5VKXL8A\www.broadcaster.com
C:\Documents and Settings\Helder Dias\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aljplsae.ini
C:\WINDOWS\system32\cJTCdMoq.ini
C:\WINDOWS\system32\cJTCdMoq.ini2
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\system32\efcBsrPH.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ppVEdcfe.ini
C:\WINDOWS\system32\ppVEdcfe.ini2
C:\WINDOWS\system32\qoMfgHWq.dll
C:\WINDOWS\system32\TAGhQXbc.ini
C:\WINDOWS\system32\TAGhQXbc.ini2
C:\WINDOWS\system32\xdknurwt.ini
C:\WINDOWS\system32\yayyWmMf.dll
D:\Autorun.inf
H:\Autorun.inf
I:\Autorun.inf
J:\Autorun.inf
K:\Autorun.inf
L:\Autorun.inf
M:\Autorun.inf
N:\Autorun.inf
O:\Autorun.inf
Y:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WINDOWS_LOG


((((((((((((((((((((((( Ficheiros criados de 2008-04-13 to 2008-05-13 ))))))))))))))))))))))))))))))))
.

2008-05-12 12:26 . 2008-05-12 13:02 <DIR> d-------- C:\Programas\DVDFab 5
2008-05-12 12:16 . 2008-05-12 12:16 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\Thinstall
2008-05-12 12:16 . 2008-05-12 12:16 32 --a------ C:\WINDOWS\Start.INI
2008-05-10 11:49 . 2008-05-10 11:49 <DIR> d-------- C:\Programas\eXtreme Movie Manager
2008-05-06 15:52 . 2008-03-28 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-05-06 12:42 . 2008-05-06 12:43 110,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-06 12:42 . 2008-05-06 12:43 48,768 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-06 12:42 . 2008-05-06 12:43 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-06 12:42 . 2008-05-06 12:43 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-03 16:35 . 2008-05-03 16:35 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\Acronis
2008-05-03 16:23 . 2008-05-03 16:23 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Acronis
2008-05-03 15:23 . 2008-05-10 03:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 <DIR> d-------- C:\Programas\Ficheiros comuns\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 <DIR> d-------- C:\Programas\Acronis
2008-05-03 15:22 . 2008-05-03 15:22 441,760 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2008-05-03 15:22 . 2008-05-03 15:22 368,544 --a------ C:\WINDOWS\system32\drivers\tdrpman.sys
2008-05-03 15:22 . 2008-05-03 15:22 129,248 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2008-05-03 15:22 . 2008-05-03 15:22 44,384 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2008-05-02 22:16 . 2008-05-02 22:16 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-02 22:15 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-01 16:06 . 2008-05-01 16:06 <DIR> d-------- C:\Documents and Settings\Helder Dias\Application Data\vlc
2008-05-01 15:01 . 2008-05-01 15:01 <DIR> d-------- C:\Programas\DAEMON Tools Lite
2008-05-01 14:49 . 2008-05-01 14:49 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-23 11:40 . 2006-10-06 17:11 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-23 11:40 . 2006-10-06 17:11 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-23 11:40 . 2008-04-23 11:40 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf

.
((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 13:47 --------- d-----w C:\Programas\Symantec AntiVirus
2008-05-13 10:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-13 09:26 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\uTorrent
2008-05-13 00:10 --------- d-----w C:\Programas\emule0.48a-Xtreme6.1
2008-05-12 12:28 --------- d--h--w C:\Programas\InstallShield Installation Information
2008-05-12 12:02 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Vso
2008-05-12 11:26 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-05-12 11:26 47,360 ----a-w C:\Documents and Settings\Helder Dias\Application Data\pcouffin.sys
2008-05-10 16:43 --------- d-----w C:\Programas\eMule
2008-05-09 11:42 --------- d-----w C:\Programas\Aicon121
2008-05-06 14:42 --------- d-----w C:\Programas\ATI Technologies
2008-05-06 14:38 --------- d-----w C:\Programas\DIFX
2008-05-06 14:33 --------- d-----w C:\Programas\Paint.NET
2008-05-06 14:07 --------- d-----w C:\Programas\Unlocker
2008-05-06 11:43 --------- d-----w C:\Programas\Symantec
2008-05-06 11:43 --------- d-----w C:\Programas\Ficheiros comuns\Symantec Shared
2008-05-06 11:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-02 21:16 --------- d-----w C:\Programas\TuneUp Utilities 2008
2008-05-01 13:59 --------- d-----w C:\Programas\Winamp
2008-05-01 13:53 --------- d-----w C:\Programas\SpywareBlaster
2008-05-01 13:48 --------- d-----w C:\Programas\Java
2008-04-11 15:11 --------- d-----w C:\Programas\Declarações Electrónicas
2008-04-11 14:41 --------- d-----w C:\Programas\Ficheiros comuns\PCSuite
2008-04-11 14:41 --------- d-----w C:\Programas\Ficheiros comuns\Nokia
2008-04-11 14:39 --------- d-----w C:\Programas\PC Connectivity Solution
2008-04-11 14:39 --------- d-----w C:\Programas\Nokia
2008-04-11 14:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-09 02:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-31 14:00 --------- d-----w C:\Programas\Messenger Plus! Live
2008-03-29 06:21 2,873,856 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-03-29 03:18 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-03-21 12:54 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Nokia Multimedia Player
2008-03-20 15:50 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-20 15:26 --------- d-----w C:\Programas\Ficheiros comuns\Nero
2008-03-20 15:25 --------- d-----w C:\Programas\Nero
2008-03-20 15:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-03-18 13:07 --------- d-----w C:\Documents and Settings\Helder Dias\Application Data\Nokia
2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe
2008-02-17 16:53 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
.

------- Sigcheck -------

2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-01-12 18:11 360064 8283a4d489b207991efdc8328733d0bc C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-01-12 18:11 360064 8283a4d489b207991efdc8328733d0bc C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-05-13_11.32.33.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-13 10:27:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 13:45:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"AVEDESK"="C:\Programas\AveDesk\AveDesk.exe" [2005-10-26 00:44 1424896]
"DAEMON Tools Lite"="C:\Programas\DAEMON Tools Lite\daemon.exe" [2008-04-01 10:39 486856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Programas\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" [2008-02-13 12:36 6731312]
"SunJavaUpdateSched"="C:\Programas\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Acronis Scheduler2 Service"="C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe" [2007-10-30 20:07 140568]
"ccApp"="C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe" [2007-05-29 16:33 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\\vptray.exe" [2007-10-07 20:48 125368]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHEI~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 04:18 437160]
"Nokia.PCSync"="C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]

C:\Documents and Settings\Helder Dias\Menu Iniciar\Programas\Arranque\
ATI Tray Tools.lnk - C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe [2007-05-22 10:04:58 521128]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\programas\ficheiros comuns\logitech\bluetooth\LBTWlgn.dll 2008-01-09 13:30 72208 c:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="C:\Programas\Windows Live\Messenger\MsnMsgr.Exe" /background
"PC Suite Tray"="C:\Programas\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"SpybotSD TeaTimer"=C:\Programas\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NBKeyScan"="C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"Sunkist2k"=C:\Programas\Multimedia Card Reader\shwicon2k.exe
"!AVG Anti-Spyware"="C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"NeroFilterCheck"=C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe
"Kernel and Hardware Abstraction Layer"=KHALMNPR.EXE
"AcronisTimounterMonitor"=C:\Programas\Acronis\TrueImageHome\TimounterMonitor.exe
"TrueImageMonitor.exe"=C:\Programas\Acronis\TrueImageHome\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programas\\emule0.48a-Xtreme6.1\\emule.exe"=
"C:\\Programas\\eMule\\emule.exe"=
"C:\\Programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Programas\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Jogos\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\Jogos\\EA Games\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Programas\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Programas\\Ficheiros comuns\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Programas\\TVAnts\\Tvants.exe"=
"C:\\Programas\\uTorrent\\uTorrent.exe"=
"C:\\Programas\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Jogos\\EA Games\\Command & Conquer Generals Zero Hour\\patchget.dat"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Agrupamento Peer-to-Peer do Windows
"3540:UDP"= 3540:UDP:Protocolo de resolução de nome Peer (PNRP)
"50021:TCP"= 50021:TCP:Bittorrent
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 inic162x;inic162x;C:\WINDOWS\system32\DRIVERS\inic162x.sys [2007-09-10 17:27]
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-03 15:22]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 11:22]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 21:22]
R1 atitray;atitray;C:\Programas\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 10:04]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 12:32]
R2 U3sHlpDr;U3sHlpDr;C:\WINDOWS\System32\Drivers\U3sHlpDr.sys [2007-02-22 21:41]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:57]
S3 p2pgasvc;Autenticação de grupo de funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 p2pimsvc;Gestor de identidade de funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 p2psvc;Funcionamento em rede Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 PNRPSvc;Protocolo de resolução de nome Peer;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:57]
S3 RushTopDevice;RushTopDevice;C:\Programas\MSI\Core Center\RushTop.sys [2006-07-13 11:48]
S3 TryAndDecideService;Acronis Try And Decide Service;"C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-10-30 20:51]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-02 22:16]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Conte£do da pasta 'Tarefas Agendadas'
"2008-05-13 13:46:06 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Programas\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-13 08:10:00 C:\WINDOWS\Tasks\emulext.job"
- C:\Programas\emule0.48a-Xtreme6.1\emule.exe
"2008-05-13 13:49:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Programas\Windows Defender\MpCmdRun.exe
"2008-05-12 23:26:08 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Programas\Spybot - Search & Destroy\SpybotSD.exe!/AUTOCHECK /AUTOFIX /AUTOCLOSE
"2008-04-19 12:31:04 C:\WINDOWS\Tasks\µTorrent.job"


Just one doubt, the CFScript.txt that you told me to do is just this?

File::
C:\WINDOWS\system32\nxgjgwfv.exe
C:\WINDOWS\system32\urpqubay.exe
C:\WINDOWS\BM4f05a259.xml
N:\LaunchU3.exe

Folder::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc70c87f-f4a7-11db-8bd8-000c7691af0b}]

Driver::

I'm asking this because there's nothing bellow Driver::

One more time...thanks

Rorschach112
2008-05-13, 16:40
Don't worry about that

Please download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Also post a new HijackThis log

sopoku
2008-05-13, 17:18
Just did what you've told me and here are the logs:

Malwarebytes' Anti-Malware 1.12
Versão do banco de dados: 744

Tipo de Verificação: Rápida
Objetos verificados: 37131
Tempo decorrido: 5 minute(s), 31 second(s)

Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 2
Valores do Registro infectados: 0
Ítens do Registro infectados: 0
Pastas infectadas: 0
Arquivos infectados: 1

Processos da Memória infectados:
(Nenhum ítem malicioso foi detectado)

Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)

Chaves do Registro infectadas:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Valores do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Ítens do Registro infectados:
(Nenhum ítem malicioso foi detectado)

Pastas infectadas:
(Nenhum ítem malicioso foi detectado)

Arquivos infectados:
C:\WINDOWS\system32\drivers\etc\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:13, on 2008-05-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Windows Defender\MSASCui.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe
C:\Programas\Java\jre1.6.0_06\bin\jusched.exe
C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe
C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\AveDesk\AveDesk.exe
C:\Programas\DAEMON Tools Lite\daemon.exe
C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\spider.exe
C:\Programas\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clix.pt/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Programas\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\_avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programas\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programas\Ficheiros comuns\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVEDESK] "C:\Programas\AveDesk\AveDesk.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programas\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Definições locais\Temp" (User 'Serviço de rede')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ATI Tray Tools.lnk = C:\Programas\Ray Adams\ATI Tray Tools\atitray.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196441605638
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0D986BA-1CA8-44ED-8C69-536635C23B47}: NameServer = 195.23.129.126,194.79.69.222
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programas\Ficheiros comuns\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programas\Ficheiros comuns\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programas\Ficheiros comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programas\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Programas\Ficheiros comuns\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8943 bytes

Thanks

sopoku
2008-05-13, 17:23
Sorry, the Mbam program language is in Portuguese....
I don´t know if you understand but i will translate the principal:

registry Keys Infected: 2
Files infected: 1

All of them were deleted and quarantined successfully.

:eek: :bigthumb:

sopoku
2008-05-13, 18:09
Is there anything else that i should do?

Rorschach112
2008-05-13, 18:22
One final thing

Follow these steps to uninstall Combofix and tools used in the removal of malware

Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png



You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here (http://java.sun.com/javase/downloads/index.jsp)



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html) protects against bad ActiveX
IE-SPYAD (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe) puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)

* SpywareGuard (http://www.javacoolsoftware.com/sgdownload.html) offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure

Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.


* MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here (http://www.mozilla.org/products/firefox/)

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here (http://forums.spywareinfo.com/index.php?showtopic=60955)

Thank you for your patience, and performing all of the procedures requested.

sopoku
2008-05-13, 18:30
Thanks a lot...you're fantastic.:bigthumb:

Rorschach112
2008-05-13, 18:32
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.