Unsolved

This post is more than 5 years old

1 Message

9600

November 21st, 2013 11:00

Virus Task no Working Combofix and more pliz Help

Hi, my problem started on 20/11 when it appeared a message that the globe GPS stopped working continuously realized it was virus and was in the temp folder each time this message appeared, created a file 2.96 mb folder I exclude all and spent avira to scan and found only one virus after that day today 21/11 as soon as I turned on the computer your theme was changed from windows aero talking would not change to a progam stop running and task manager was not opening so I spent a combofix goes down there:

ComboFix 13-11-19.01 - Familia 21/11/2013 14:54:16.1.2 - x64 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1046.18.4058.2789 [GMT -2:00]
Executando de: c:\users\Familia\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Criado um novo ponto de restauração
.
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Funmoods
c:\program files (x86)\Funmoods\1.8.11.0\Sqlite3.dll
c:\program files (x86)\Funmoods\1.8.11.0\uninstall.exe
c:\program files (x86)\sXe Injected
c:\program files (x86)\sXe Injected\chrome-extension_icpgjfneehieebagbmdbhnlpiopdcmna_0.localstorage
c:\program files (x86)\sXe Injected\Chrome\chrome-extension_icpgjfneehieebagbmdbhnlpiopdcmna_0.localstorage
c:\program files (x86)\sXe Injected\chromechange.exe
c:\program files (x86)\sXe Injected\ddsxei.sys
c:\program files (x86)\sXe Injected\default.reg
c:\program files (x86)\sXe Injected\firechange.exe
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\background.html
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\background.js
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\example.html
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\icon128.png
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\icon19.png
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\icon200.png
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\manifest.json
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\options.css
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\options.html
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\options.js
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\README.md
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\redirect.html
c:\program files (x86)\sXe Injected\icpgjfneehieebagbmdbhnlpiopdcmna\1.0.4_0\redirect.js
c:\program files (x86)\sXe Injected\localstrike-search.xml
c:\program files (x86)\sXe Injected\newtaburl_local.xpi
c:\program files (x86)\sXe Injected\Preferences
c:\program files (x86)\sXe Injected\search.ini
c:\program files (x86)\sXe Injected\speeddial.ini
c:\program files (x86)\sXe Injected\sXe-I EULA.txt
c:\program files (x86)\sXe Injected\sXe Injected.exe
c:\program files (x86)\sXe Injected\sXe Injected.txt
c:\program files (x86)\sXe Injected\sXe.dll
c:\program files (x86)\sXe Injected\TopSites.plist
c:\program files (x86)\sXe Injected\uninstall.exe
c:\program files (x86)\sXe Injected\uninstall.ini
c:\program files (x86)\sXe Injected\Web Data
c:\programdata\SearchNewTab
C:\STF7314.tmp
C:\STFF51A.tmp
c:\users\Familia\AppData\Local\EmUrCy.exe
c:\users\Familia\AppData\Local\Win3004.exe
c:\users\Familia\AppData\Roaming\337
c:\users\Familia\AppData\Roaming\337\OPiece\gamelogin.exe
c:\users\Familia\AppData\Roaming\337\OPiece\gl.db
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_bk_wnd.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_close.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_hide.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_max.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_min.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_restore.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\game_system.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\menu_bg.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\menu_item_over.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\pic-error.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\pic-info.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\pic-question.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\pic-warning.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\popup_dialog_bk.bmp
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\cmn\prepare.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\gl_res.xml
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\cus_pt_br\anniu_1.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\cus_pt_br\anniu_2.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\cus_pt_br\anniu_3.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\cus_pt_br\anniu_4.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\login_pt_br.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\sys_close_pt_br.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\OPiece\sys_min_pt_br.png
c:\users\Familia\AppData\Roaming\337\OPiece\image\default\resource.xml
c:\users\Familia\AppData\Roaming\337\OPiece\language\en_us\game_login.ini
c:\users\Familia\AppData\Roaming\337\OPiece\language\es_es\game_login.ini
c:\users\Familia\AppData\Roaming\337\OPiece\language\protocol.txt
c:\users\Familia\AppData\Roaming\337\OPiece\language\pt_br\game_login.ini
c:\users\Familia\AppData\Roaming\337\OPiece\language\tr_tr\game_login.ini
c:\users\Familia\AppData\Roaming\337\OPiece\language\zh_tw\game_login.ini
c:\users\Familia\AppData\Roaming\337\OPiece\layout\default\game_login_OPiece_pt_br.xml
c:\users\Familia\AppData\Roaming\337\OPiece\layout\default\gl_game.xml
c:\users\Familia\AppData\Roaming\337\OPiece\layout\default\gl_newwindow.xml
c:\users\Familia\AppData\Roaming\337\OPiece\layout\default\msgbox.xml
c:\users\Familia\AppData\Roaming\337\OPiece\main
c:\users\Familia\AppData\Roaming\337\OPiece\style\gl_style.xml
c:\users\Familia\AppData\Roaming\337\OPiece\TrayDownloader.exe
c:\users\Familia\AppData\Roaming\csrss.exe
c:\users\Familia\AppData\Roaming\csrss.exe.tmp
c:\users\Familia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\97335ed968c8d21501810d2516770677.exe
c:\windows\SysWow64\Config.ini
c:\windows\SysWow64\FlashPlayerApp.exe
c:\windows\SysWow64\frapsvid.dll
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2013-10-21 to 2013-11-21 ))))))))))))))))))))))))))))
.
.
2013-11-21 17:01 . 2013-11-21 17:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-11-21 17:01 . 2013-11-21 17:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-21 16:12 . 2013-11-21 16:13 -------- d-----w- C:\cod
2013-11-21 15:50 . 2013-11-21 15:50 3309568 ----a-w- C:\Win3005.exe
2013-11-21 15:20 . 2013-11-21 15:20 -------- d-----w- C:\Tf2
2013-11-18 17:06 . 2013-11-18 17:06 -------- d-----w- c:\users\Familia\minecraft
2013-11-14 13:04 . 2013-11-14 13:04 -------- d-----w- c:\program files\VID_0E8F&PID_0003
2013-11-14 13:04 . 2013-11-14 13:04 -------- d-----w- c:\program files (x86)\VID_0E8F&PID_0003
2013-11-14 13:04 . 2013-11-14 13:04 331908 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2013-11-14 13:04 . 2013-11-14 13:04 200836 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2013-11-14 13:04 . 2005-04-04 01:02 753664 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2013-11-14 13:04 . 2005-04-04 01:02 69714 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2013-11-14 13:04 . 2005-04-04 01:01 274432 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2013-11-14 13:04 . 2005-04-04 01:00 184320 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2013-11-14 13:04 . 2005-04-04 01:00 63488 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ISBEW64.exe
2013-11-14 13:04 . 2005-04-04 00:59 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2013-11-14 05:20 . 2013-11-14 05:20 -------- d-----w- c:\users\Familia\AppData\Local\NBGI
2013-11-14 04:43 . 2013-11-14 04:43 -------- d-----w- c:\program files (x86)\NAMCO BANDAI Games
2013-11-13 12:14 . 2013-11-13 12:14 -------- d-----w- c:\users\Familia\AppData\Roaming\InstallShield
2013-11-10 14:28 . 2013-11-10 14:28 -------- d-----w- c:\users\Familia\AppData\Local\2K Games
2013-11-08 13:36 . 2013-11-17 22:47 -------- d-----w- c:\program files (x86)\Electronic Arts
2013-11-05 21:59 . 2013-11-05 21:59 -------- d-----w- c:\users\Familia\AppData\Local\EMU
2013-11-05 21:25 . 2013-11-06 00:44 -------- d-----w- c:\program files (x86)\NARUTO SHIPPUDEN Ultimate Ninja STORM 3 Full Burst
2013-11-04 20:21 . 2013-11-04 20:21 -------- d-----w- c:\users\Familia\AppData\Local\Microsoft Games
2013-11-03 23:20 . 2013-10-18 01:36 1063200 ----a-w- c:\windows\system32\nvspcap64.dll
2013-11-03 23:20 . 2013-10-18 01:36 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-11-03 23:16 . 2013-09-27 23:01 39200 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2013-11-03 23:16 . 2013-09-27 23:01 28960 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2013-11-01 17:45 . 2013-11-01 17:45 -------- d-----w- c:\windows\system32\Wat
2013-10-29 02:20 . 2013-10-29 02:20 -------- d-----w- c:\users\Familia\AppData\Roaming\RIFT
2013-10-29 02:16 . 2013-10-29 02:16 -------- d-----w- c:\users\Familia\AppData\Roaming\PlayFirst
2013-10-29 02:16 . 2013-10-29 02:16 -------- d-----w- c:\programdata\PlayFirst
2013-10-27 14:58 . 2013-10-28 14:53 -------- d-----w- c:\programdata\DOWnloadd keeperr
2013-10-27 14:58 . 2013-10-27 15:57 -------- d-----w- c:\programdata\7f50ca171198558a
2013-10-27 02:42 . 2013-10-27 02:42 -------- d-----w- c:\users\Familia\AppData\Local\My Games
2013-10-24 19:49 . 2013-10-24 19:49 -------- d-----w- c:\users\Familia\AppData\Local\Blizzard Entertainment
2013-10-23 15:11 . 2013-11-03 23:15 -------- d-----w- c:\program files (x86)\Metro Last Light
2013-10-23 05:02 . 2013-10-23 05:02 589600 ----a-w- c:\windows\SysWow64\nvStreaming.exe
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-20 18:58 . 2013-06-01 05:31 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2013-11-20 18:58 . 2013-06-01 05:25 290184 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-11-20 18:58 . 2013-06-01 05:25 280904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2013-11-01 17:45 . 2013-06-03 01:53 419840 ----a-w- c:\windows\system32\systemcpl.dll
2013-11-01 17:45 . 2013-06-03 01:53 14848 ----a-w- c:\windows\system32\slwga.dll
2013-11-01 17:45 . 2013-06-03 01:53 13824 ----a-w- c:\windows\SysWow64\slwga.dll
2013-11-01 17:45 . 2013-06-03 01:54 1008640 ----a-w- c:\windows\system32\user32.dll
2013-11-01 17:45 . 2013-06-03 01:54 833024 ----a-w- c:\windows\SysWow64\user32.dll
2013-10-23 10:30 . 2013-05-29 14:30 61216 ----a-w- c:\windows\system32\OpenCL.dll
2013-10-23 10:30 . 2013-05-29 14:30 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-10-23 10:30 . 2013-05-29 14:29 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2013-05-29 14:29 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2009-07-13 21:59 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-23 10:30 . 2009-06-10 20:37 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 08:20 . 2013-05-29 14:30 6669600 ----a-w- c:\windows\system32\nvcpl.dll
2013-10-23 08:20 . 2013-05-29 14:30 3489568 ----a-w- c:\windows\system32\nvsvc64.dll
2013-10-23 08:20 . 2013-08-31 20:07 2559776 ----a-w- c:\windows\system32\nvsvcr.dll
2013-10-23 08:20 . 2013-05-29 14:30 922912 ----a-w- c:\windows\system32\nvvsvc.exe
2013-10-23 08:20 . 2013-05-29 14:30 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-10-23 08:20 . 2013-05-29 14:30 219424 ----a-w- c:\windows\system32\nvmctray.dll
2013-10-09 16:32 . 2013-05-29 00:37 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-09-27 23:01 . 2013-10-14 17:04 29984 ----a-w- c:\windows\system32\nvaudcap64v.dll
2013-09-15 15:04 . 2013-06-01 05:25 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2013-09-12 08:58 . 2013-10-14 18:14 1884448 ----a-w- c:\windows\system32\nvdispco6432723.dll
2013-09-12 08:58 . 2013-10-14 18:14 1511712 ----a-w- c:\windows\system32\nvdispgenco6432723.dll
2013-09-11 18:59 . 2013-09-11 18:59 98304 ----a-w- c:\windows\SysWow64\CmdLineExt.dll
2013-09-10 16:48 . 2013-05-30 04:10 81112 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2013-09-10 16:48 . 2013-05-29 22:04 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-09-10 16:48 . 2013-05-29 22:04 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-04 09:16 . 2013-09-04 09:16 69632 ----a-w- c:\windows\system32\DriverInstallCA.dll
2013-09-04 09:16 . 2013-09-04 09:16 40696 ----a-w- c:\windows\system32\drivers\RzMaelstromVAD.sys
2013-09-04 09:16 . 2013-09-04 09:16 245760 ----a-w- c:\windows\system32\DriverInstallCACMD.exe
2013-09-04 09:16 . 2013-09-04 09:16 136704 ----a-w- c:\windows\SysWow64\RzVAD.dll
2013-05-28 20:58 2169856 --sha-w- c:\windows\System32\hale.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . 1151B1BAA6F350B1DB6598E0FEA7C457 . 390656 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[7] 2009-10-28 . A93D41A4D4B0D91C072D11DD8AF266DE . 389632 . . [6.1.7600.20560] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[7] 2009-10-28 . DA3E2A6FA9660CC75B471530CE88453A . 389632 . . [6.1.7600.16447] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[7] 2009-07-14 . 132328DF455B0028F13BF0ABEE51A63A . 389120 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[-] 2013-06-03 . 87A00ED70FEC36D0DD968E5058C29AA1 . 389632 . . [6.1.7601.17514] .. c:\windows\system32\winlogon.exe
.
[7] 2010-11-20 . FE70103391A64039A921DBFFF9C7AB1B . 1008128 . . [6.1.7601.17514] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[-] 2013-11-01 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7601.17514] .. c:\windows\system32\user32.dll
.
[-] 2013-11-01 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2013-10-30 1820584]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"BitTorrent"="c:\users\Familia\AppData\Roaming\BitTorrent\BitTorrent.exe" [2013-05-29 1125456]
"Win3005"="C:\Win3005.exe" [2013-11-21 3309568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-10 347192]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2013-08-15 606040]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
.
R1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys
R1 Bfilter;Baidu Antivirus Minifilter Driver;c:\windows\System32\drivers\Bfilter.sys;c:\windows\SYSNATIVE\drivers\Bfilter.sys
R1 Bfmon;Baidu FS Monitor Driver;c:\windows\System32\drivers\Bfmon.sys;c:\windows\SYSNATIVE\drivers\Bfmon.sys
R2 AntiVirSchedulerService;Avira Agendamento;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
R2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
R2 RzMaelstromVADStreamingService;Razer Surround Audio Service;c:\programdata\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe;c:\programdata\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
R2 WebCake Desktop Updater;WebCake Desktop Updater;c:\program files (x86)\Betcat\WBDesktop.Updater.exe;c:\program files (x86)\Betcat\WBDesktop.Updater.exe
R3 BprotectEx;Baidu ProtectEx;c:\windows\System32\drivers\BprotectEx.sys;c:\windows\SYSNATIVE\drivers\BprotectEx.sys
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe
R3 MSICDSetup;MSICDSetup;d:\cdriver64.sys;d:\CDriver64.sys
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des
R3 NTIOLib_1_0_C;NTIOLib_1_0_C;d:\ntiolib_x64.sys;d:\NTIOLib_X64.sys
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys
R3 PCFApiUtil;PCFApiUtil;c:\program files (x86)\Baidu Security\PC Faster\3.7.0.0\PCFApiUtil64.sys;c:\program files (x86)\Baidu Security\PC Faster\3.7.0.0\PCFApiUtil64.sys
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192cu.sys
R3 RZMAELSTROMVADService;Razer Surround Audio Enhancer Service;c:\windows\system32\drivers\RzMaelstromVAD.sys;c:\windows\SYSNATIVE\drivers\RzMaelstromVAD.sys
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys
R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012
R3 X6va014;X6va014;c:\windows\SysWOW64\Drivers\X6va014;c:\windows\SysWOW64\Drivers\X6va014
R3 X6va015;X6va015;c:\windows\SysWOW64\Drivers\X6va015;c:\windows\SysWOW64\Drivers\X6va015
S1 Bprotect;Baidu Protect;c:\windows\System32\drivers\Bprotect.sys;c:\windows\SYSNATIVE\drivers\Bprotect.sys
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-11-16 21:13 1210320 ----a-w- c:\program files (x86)\Google\Chrome\Application\31.0.1650.57\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-10-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-29 16:32]
.
2013-07-19 c:\windows\Tasks\DriverEasy Scheduled Scan.job
- c:\program files\Easeware\DriverEasy\DriverEasy.exe [2013-06-19 15:24]
.
2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cec7deae525359.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-28 21:01]
.
2013-09-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-28 21:01]
.
2013-10-20 c:\windows\Tasks\HP Deskjet 3050 J610 series.exe_{DA92F58F-ABCA-4AB0-BA03-D6FC4B8A3938}.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HP Deskjet 3050 J610 series.exe [2012-10-17 06:40]
.
2013-10-10 c:\windows\Tasks\HP Deskjet 3050 J610 series.exe_{DCD98C55-250B-432E-B2B9-7471CD7E1584}.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\HP Deskjet 3050 J610 series.exe [2012-10-17 06:40]
.
2013-09-15 c:\windows\Tasks\Toolbox.exe_{532EEB20-7A8C-4701-84ED-2919D396EFA0}.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\Toolbox.exe [2012-10-17 06:34]
.
2013-10-10 c:\windows\Tasks\Toolbox.exe_{A08F0B73-D14B-4819-AAF0-1F2E6E2B58AB}.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\Toolbox.exe [2012-10-17 06:34]
.
2013-10-20 c:\windows\Tasks\Toolbox.exe_{A5E15B7D-66C5-4F3D-935D-7BFAEE559607}.job
- c:\program files\HP\HP Deskjet 3050 J610 series\Bin\Toolbox.exe [2012-10-17 06:34]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-10-18 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-10-18 1063200]
.
------- Scan Suplementar -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://websearch.wisesearch.info/?pid=512&r=2013/10/27&hid=3024610570131990908&lg=EN&cc=BR&unqvl=39
mStart Page = hxxp://websearch.wisesearch.info/?pid=512&r=2013/10/27&hid=3024610570131990908&lg=EN&cc=BR&unqvl=39
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride =
IE: E&xportar para o Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.5.254
TCP: Interfaces\{519B6B5E-A19C-403C-84F0-253002A4AC30}: NameServer = 8.8.8.8,8.8.4.4
.
- - - - ORFÃOS REMOVIDOS - - - -
.
Wow6432Node-HKCU-Run-97335ed968c8d21501810d2516770677 - c:\users\Familia\AppData\Roaming\csrss.exe
Wow6432Node-HKLM-Run- - (no file)
Wow6432Node-HKLM-Run-97335ed968c8d21501810d2516770677 - c:\users\Familia\AppData\Roaming\csrss.exe
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
AddRemove-sXe Injected - c:\program files (x86)\sXe Injected\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va012]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va014]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va014"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va015]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va015"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_USERS\S-1-5-21-1026650105-1370983364-2195953852-1000\Software\SecuROM\License information*]
"datasecu"=hex:dd,76,3a,13,fe,6d,ac,cc,8c,32,c9,69,e0,ca,89,41,b2,38,ae,07,f7,
30,20,c1,f0,d9,ca,c8,f2,59,44,b1,8d,a1,27,7f,48,2c,2f,22,84,95,cf,f1,e8,52,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Tempo para conclusão: 2013-11-21 15:02:48
ComboFix-quarantined-files.txt 2013-11-21 17:02
.
Pré-execução: 97.328.340.992 bytes disponíveis
Pós execução: 97.122.570.240 bytes disponíveis
.
- - End Of File - - C028FF0B39C6841017DF8E2A85DCC1D4
A36C5E4F47E84449FF07ED3517B43A31

and still the same problem

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 21st, 2013 12:00

1)  Combofix is a very powerful tool, and should only be run when explicitly indicated by a specialist.   Running it without proper supervision can sometimes do more damage than good.

2)  Unfortunately, one-on-one Malware Analysis/Removal is no longer done at the Dell Forums.  

Please follow the directions at http://spywarehammer.com/simplemachinesforum/index.php?topic=12262.0 to register and post the requested DDS logs at spywarehammer.com ; there are expert helpers there who can "walk you through" procedures to analyze your system, and clean-up the infection.   All help provided there is FREE.   If you decide to go for help there, please wait for a response, and do NOT attempt to run any other scans/removers on your own --- do exactly what they instruct you to do, no more, no less.

You should let them know you've already run ComboFix --- but I wouldn't include the log unless they specifically ask you for it.  

Good luck!

No Events found!

Top