por Manuela » Segunda Nov 19, 2007 19:51
Olá...
Tenho aqui os logs dos avg rootkit e panda:
AVG:
C:\WINDOWS\system32\drivers\srosa.sys,Hidden driver file
c:\Programas\Movie Maker\Shared,Hidden Directory
c:\Programas\Movie Maker\Shared\Empty.txt,Hidden File
c:\Programas\Movie Maker\Shared\Filters.xml,Hidden File
c:\Programas\Movie Maker\Shared\news.png,Hidden File
c:\Programas\Movie Maker\Shared\paint.png,Hidden File
c:\Programas\Movie Maker\Shared\Sample1.jpg,Hidden File
c:\Programas\Movie Maker\Shared\Sample2.jpg,Hidden File
c:\Programas\Seagate Software\Shared,Hidden Directory
c:\Programas\Seagate Software\Shared\amzi4.dll,Hidden File
c:\Programas\Seagate Software\Shared\cabanner.bmp,Hidden File
c:\Programas\Seagate Software\Shared\cawmark.bmp,Hidden File
c:\Programas\Seagate Software\Shared\Cdo32.dll,Hidden File
c:\Programas\Seagate Software\Shared\cebanner.bmp,Hidden File
c:\Programas\Seagate Software\Shared\cewmark.bmp,Hidden File
c:\Programas\Seagate Software\Shared\crtslv.dll,Hidden File
c:\Programas\Seagate Software\Shared\EnterpriseAddReport.exe,Hidden File
c:\Programas\Seagate Software\Shared\EnterpriseAPSBridge.dll,Hidden File
c:\Programas\Seagate Software\Shared\ExportModeller.dll,Hidden File
c:\Programas\Seagate Software\Shared\favorites.dll,Hidden File
c:\Programas\Seagate Software\Shared\keycode.dll,Hidden File
c:\Programas\Seagate Software\Shared\ltkrn11n.dll,Hidden File
c:\Programas\Seagate Software\Shared\Olapdbmg.dll,Hidden File
c:\Programas\Seagate Software\Shared\Olapdbmg.tlb,Hidden File
c:\Programas\Seagate Software\Shared\pg32conv.dll,Hidden File
c:\Programas\Seagate Software\Shared\rdwiz.dll,Hidden File
c:\Programas\Seagate Software\Shared\rdwiz_en.ini,Hidden File
c:\Programas\Seagate Software\Shared\regwiz.exe,Hidden File
c:\Programas\Seagate Software\Shared\Rule1.dfa,Hidden File
c:\Programas\Seagate Software\Shared\Rule1.llr,Hidden File
c:\Programas\Seagate Software\Shared\Rule1jp.dfa,Hidden File
c:\Programas\Seagate Software\Shared\Rule1jp.llr,Hidden File
c:\Programas\Seagate Software\Shared\s2sqlprs.dll,Hidden File
c:\Programas\Seagate Software\Shared\SAStarter.dll,Hidden File
c:\Programas\Seagate Software\Shared\sscdlg.cnt,Hidden File
c:\Programas\Seagate Software\Shared\sscdlg.dll,Hidden File
c:\Programas\Seagate Software\Shared\sscdlg.gid,Hidden File
c:\Programas\Seagate Software\Shared\Sscdlg.hlp,Hidden File
c:\Programas\Seagate Software\Shared\sscrc.dll,Hidden File
c:\Programas\Seagate Software\Shared\sscsdk80.dll,Hidden File
c:\Programas\Seagate Software\Shared\Sstree32.dll,Hidden File
c:\WINDOWS\ime\shared,Hidden Directory
c:\WINDOWS\system32\drivers\hidr.exe,Hidden File
c:\WINDOWS\system32\drivers\srosa.sys,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared,Hidden Directory
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\Burp.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CDASvc.exe,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CdrwUpdt.exe,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTAudCD.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTBurnCD.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTHtml.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTIntrfc.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTLogDB.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTMStore.exe,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTMStore.ocx,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTMuVo.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTMyComp.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTNeeon.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTNJB3.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTPCML.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTRegSvr.exe,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTSUApp.exe,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTSUSDK.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTTranQ.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTUnzip.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\CTVidCD.dco,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\MFInfo.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\Muce.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\MuVoPHlp.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\MxLib.dll,Hidden File
g:\Coisas\Creative Zen Neeon\Programa\CTShared\Shared\PdtIdMgr.pid,Hidden File
PANDA:
PATH ROOTKIT_NAME HIDDEN
C:\WINDOWS\system32\hldrrr.exe FALSE
C:\WINDOWS\system32\drivers\hidr.exe TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
C:\WINDOWS\system32\drivers\srosa.sys TRUE
Cumps.
M