Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

freakmaster

[Arquivado] Win Antivirus

Recommended Posts

PESSOAL PEGUEI O TAL DO WINANTIVIRUS

JA TESTEI ALGUNS SPYWARES QUE NUM FAZEM NADA...

 

TO POSTANDO OS LOGS...

PLEASE HELP...

 

Logfile of HijackThis v1.99.1

Scan saved at 16:09:34, on 08/09/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16512)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

E:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\Notepad.exe

C:\help\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - HKLM\..\Run: [avast!] e:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [MSF_Monitor] RunDll32.exe E:\ARQUIV~1\MYSECR~1\MSF32.dll,Start

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background

O8 - Extra context menu item: &Download with &DAP - E:\ARQUIV~1\DAP\dapextie.htm

O8 - Extra context menu item: Advanced Email Extractor - res://C:\Arquivos%20de%20programas\Advanced%20Email%20Extractor%20PRO\AeePMsie.dll/page.html

O8 - Extra context menu item: Baixar link usando &BitComet - res://E:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: Baixar todos os links usando BitComet - res://E:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Baixar todos os vídeos usando BitComet - res://E:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: Download &all with DAP - E:\ARQUIV~1\DAP\dapextie2.htm

O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Scan link with AEE - res://C:\Arquivos%20de%20programas\Advanced%20Email%20Extractor%20PRO\AeePMsie.dll/link.html

O8 - Extra context menu item: Sothink SWF Catcher - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL

O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - E:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.8.30.dll

O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm

O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Email Extractor - {AFA7DB99-3E4D-4396-94F8-B0B135BCB472} - res://C:\Arquivos%20de%20programas\Advanced%20Email%20Extractor%20PRO\AeePMsie.dll/page.html (file missing) (HKCU)

O9 - Extra 'Tools' menuitem: Advanced Email Extractor - {AFA7DB99-3E4D-4396-94F8-B0B135BCB472} - res://C:\Arquivos%20de%20programas\Advanced%20Email%20Extractor%20PRO\AeePMsie.dll/page.html (file missing) (HKCU)

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARQUIV~1\MSNMES~1\msgrapp.dll" (file missing)

O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARQUIV~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - e:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: avast! Antivirus - ALWIL Software - e:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - e:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - e:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - E:\Arquivos de programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - e:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

 

 

 

________________________________________________________________________________

_______

 

[09/08/2007, 16:46:48] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\FRE@K\Meus documentos\VirtumundoBeGone.exe" )

[09/08/2007, 16:46:56] - Detected System Information:

[09/08/2007, 16:46:56] - Windows Version: 5.1.2600, Service Pack 2

[09/08/2007, 16:46:56] - Current Username: FRE@K (Admin)

[09/08/2007, 16:46:56] - Windows is in NORMAL mode.

[09/08/2007, 16:46:56] - Searching for Browser Helper Objects:

[09/08/2007, 16:46:56] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)

[09/08/2007, 16:46:56] - BHO 2: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)

[09/08/2007, 16:46:56] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()

[09/08/2007, 16:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.

[09/08/2007, 16:46:56] - Checking for HKLM\...\Winlogon\Notify\SDHelper

[09/08/2007, 16:46:56] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.

[09/08/2007, 16:46:56] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)

[09/08/2007, 16:46:56] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)

[09/08/2007, 16:46:56] - BHO 6: {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} (Trixie.Bho)

[09/08/2007, 16:46:56] - BHO 7: {CB633E82-AFC3-4E70-BDD3-72D4DC640963} ()

[09/08/2007, 16:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.

[09/08/2007, 16:46:56] - Checking for HKLM\...\Winlogon\Notify\ddccb

[09/08/2007, 16:46:56] - Key not found: HKLM\...\Winlogon\Notify\ddccb, continuing.

[09/08/2007, 16:46:56] - Finished Searching Browser Helper Objects

[09/08/2007, 16:46:56] - Finishing up...

[09/08/2007, 16:46:56] - Nothing found! Exiting...

 

[09/08/2007, 16:52:07] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\FRE@K\Meus documentos\VirtumundoBeGone.exe" )

[09/08/2007, 16:52:16] - Detected System Information:

[09/08/2007, 16:52:16] - Windows Version: 5.1.2600, Service Pack 2

[09/08/2007, 16:52:16] - Current Username: FRE@K (Admin)

[09/08/2007, 16:52:16] - Windows is in NORMAL mode.

[09/08/2007, 16:52:16] - Searching for Browser Helper Objects:

[09/08/2007, 16:52:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)

[09/08/2007, 16:52:16] - BHO 2: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (BitComet Helper)

[09/08/2007, 16:52:16] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()

[09/08/2007, 16:52:16] - WARNING: BHO has no default name. Checking for Winlogon reference.

[09/08/2007, 16:52:16] - Checking for HKLM\...\Winlogon\Notify\SDHelper

[09/08/2007, 16:52:16] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.

[09/08/2007, 16:52:16] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)

[09/08/2007, 16:52:16] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)

[09/08/2007, 16:52:16] - BHO 6: {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} (Trixie.Bho)

[09/08/2007, 16:52:16] - BHO 7: {CB633E82-AFC3-4E70-BDD3-72D4DC640963} ()

[09/08/2007, 16:52:16] - WARNING: BHO has no default name. Checking for Winlogon reference.

[09/08/2007, 16:52:16] - Checking for HKLM\...\Winlogon\Notify\ddccb

[09/08/2007, 16:52:16] - Key not found: HKLM\...\Winlogon\Notify\ddccb, continuing.

[09/08/2007, 16:52:16] - Finished Searching Browser Helper Objects

[09/08/2007, 16:52:16] - Finishing up...

[09/08/2007, 16:52:16] - Nothing found! Exiting...

________________________________________________________________________________

________

 

VundoFix V6.5.8

 

Checking Java version...

 

Sun Java not detected

Scan started at 15:55:45 08/09/2007

 

Listing files found while scanning....__________________________________

 

 

________________________________________________________

 

Sat Sep 08 15:39:08 2007

EliStartPage v14.60 ©2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Eliminada Class, "{984544AB-5FA6-46AF-BE1D-E21804DAD281}" -> C:\WINDOWS\system32\xxyaxxv.dll

Eliminado Servicio, "DomainService"

 

Sat Sep 08 15:48:59 2007

EliStartPage v14.60 ©2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Linea Eliminada del HOSTS --> 127.0.0.1 mpa.one.microsoft.com

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

 

Sat Sep 08 15:49:06 2007

EliStartPage v14.60 ©2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

C:\WINDOWS\assembly\GAC\System.Drawing.Design.resources\1.0.5000.0_pt-BR_b03f5f7f11d50a3a\SYSTEM.DRAWING.DESIGN.RESOURCES.DLL --> Eliminado, MalWare.Celular

C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\pt-BR\SYSTEM.DRAWING.DESIGN.RESOURCES.DLL --> Eliminado, MalWare.Celular

 

Sat Sep 08 15:57:54 2007

EliTriIP v3.85 ©2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Acción Directa):

Linea Eliminada del HOSTS --> 127.0.0.1 mpa.one.microsoft.com

 

Sat Sep 08 15:57:59 2007

EliTriIP v3.85 ©2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\

___________________________________________________________________________

Script executed in Safe Mode

Rapport clean par Malekal_morte - http://www.malekal.com

Script executed in Safe Mode 08/09/2007 a 16:00:20.84

 

Microsoft Windows XP [versÆo 5.1.2600]

 

*** Suppression C:

 

*** Suppression C:\WINDOWS\

 

*** Suppression C:\WINDOWS\system32

tentative de suppression de C:\WINDOWS\system32\DRIVERS\etc\conf.dll

 

*** Suppression C:\Arquivos de programas

 

*** Deletion of the registry keys successful..

*** End of the report !

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia freakmaster!

 

<!> Opa,amigo!Voçê utilizou,também,algumas ferramentas direcionadas ao Vundo.

 

>1< VirtumundoBeGone

>2< VundoFix

>3< EliStarA << Sem a utilidade,ELINOTIF.DLL,algumas variantes do Vundo não são removidos.

________________________

 

>@< Faça o download do ComboFix.

>@< Baixe-o para o Desktop!

>@< Feche todas as janelas e execute a ferramenta!

>@< Para quem possui o Avast,surgirá um alerta de malware ( Win32 D adobra-EY[Trj] ),que deverá ser ignorado.

>@< Abrirá a janela Auto Scan. Aguarde!

>@< Digite a opção para continuar < Enter >

>@< Aguarde a conclusão!

>@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu ao tópico por mais de 20 dias, o mesmo foi arquivado.

 

Caso você seja o autor do tópico e quer que o mesmo seja reaberto, envie uma mensagem privada para um moderador com um link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.