Phooey! I crossed my fingers when prompted to download the Windows Recovery Console, afraid to happen the same like MalwareBytes. Lucky it didn't.
Here's the log:
ComboFix 09-10-30.01 - Pablo 01/11/2009 16:22.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.55.1046.18.511.342 [GMT -2:00]
Executando de: c:\arquivos de programas\ComboFix.exe
* Criado um novo ponto de restauração
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\AUTOLNCH.REG
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-10-01 to 2009-11-01 ))))))))))))))))))))))))))))
.
2009-11-01 17:47 . 2009-11-01 17:47 3430299 ----a-r- c:\arquivos de programas\ComboFix.exe
2009-10-28 22:12 . 2009-10-28 22:12 -------- d-----w- c:\documents and settings\Pablo\Dados de aplicativos\Malwarebytes
2009-10-28 22:12 . 2009-09-10 16:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-28 22:12 . 2009-10-28 22:58 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2009-10-28 22:12 . 2009-10-28 22:12 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2009-10-28 22:12 . 2009-09-10 16:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 21:07 . 2009-10-28 21:07 523776 ----a-w- c:\arquivos de programas\dds.scr
2009-10-26 22:41 . 2009-10-26 22:41 -------- d-----w- c:\arquivos de programas\Trend Micro
2009-10-26 22:36 . 2009-10-26 22:36 812344 ----a-w- c:\arquivos de programas\HJTInstall.exe
2009-10-20 22:29 . 2009-10-20 22:38 -------- d-----w- c:\windows\system32\Adobe
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-28 22:09 . 2009-10-28 22:09 3637 ----a-w- c:\arquivos de programas\Attach 28-10-09.txt
2009-10-28 22:08 . 2009-10-28 22:08 4792 ----a-w- c:\arquivos de programas\DDS 28-10-09.txt
2009-08-25 02:35 . 2009-08-25 02:35 17695920 ----a-w- c:\arquivos de programas\PDFCreator-0_9_8_setup.exe
2009-08-22 01:54 . 2009-08-22 01:54 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-22 00:11 . 2009-08-22 00:11 7658952 ----a-w- c:\arquivos de programas\daemon4304-lite.exe
2006-03-02 12:00 . 2006-03-02 12:00 2629632 --sha-r- c:\windows\system32\pmgkaj.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"SpeedTouch USB Diagnostics"="c:\arquivos de programas\Alcatel\SpeedTouch USB\Dragdiag.exe" [2002-11-12 860672]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-7-21 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Counter-Strike Source\\hl2.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7052:TCP"= 7052:TCP:bsghgv
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\drivers\RMSPPPOE.SYS [10/6/2002 01:09 31232]
S2 bajjcbom;skklpopo;c:\windows\system32\svchost.exe -k netsvcs [2/3/2006 10:00 14336]
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [11/6/2009 13:58 36048]
--- =Outros Serviços/Drivers Na Memória ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
bajjcbom
.
Conteúdo da pasta 'Tarefas Agendadas'
2009-11-01 c:\windows\Tasks\User_Feed_Synchronization-{D289D6EF-4B0A-4DFC-B9BF-F2CAC5492AA5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 06:31]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br/
.
- - - - ORFÃOS REMOVIDOS - - - -
Toolbar-Locked - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
AddRemove-DAEMON Tools Toolbar - c:\arquivos de programas\DAEMON Tools Toolbar\uninst.exe
AddRemove-Xvid_is1 - c:\arquivos de programas\Xvid\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-01 16:24
Windows 5.1.2600 Service Pack 2 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bajjcbom]
"ServiceDll"="c:\windows\system32\pmgkaj.dll"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(536)
c:\windows\system32\COMRes.dll
.
Tempo para conclusão: 2009-11-01 16:25
ComboFix-quarantined-files.txt 2009-11-01 18:25
Pré-execução: 6 pasta(s) 73.323.630.592 bytes disponíveis
Pós execução: 8 pasta(s) 73.427.718.144 bytes disponíveis
WindowsXP-KB310994-SP2-Home-BootDisk-PTB.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - F01964B5FC42ED5412FE6F9DB598A01A