GustavohP 0 Denunciar post Postado Abril 11, 2010 Ola Pessoal do iMaster Esse eh meu primeiro topico aki pena que seja para pedir ajuda sobre virus :( Bom, esses tempos mandei formatar meu pc em um lugar meio ruim, e o cara instalou o antivirus Solo gostei q ele eh leve, mas eh mto ruim, ultimamente ele tem pegado esse virus: Backdoor.Mazben.Ax nao importa quantas vezes eu delete ele, toda vez ele volta e outra coisa chata tbm eh que nao consigo instalar otro antivirus, nao consigo entrar em modo seguro, varios programas de remoção de virus nao roda, nem programas de reparação no sistema e registro ta impossivel mexer no pc, cada dia que passa ele fica mais lento Alguem pode me ajudar ? Obrigado Fico no Aguardo! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 12, 2010 Ola Pessoal do iMaster Esse eh meu primeiro topico aki pena que seja para pedir ajuda sobre virus :( Bom, esses tempos mandei formatar meu pc em um lugar meio ruim, e o cara instalou o antivirus Solo gostei q ele eh leve, mas eh mto ruim, ultimamente ele tem pegado esse virus: Backdoor.Mazben.Ax nao importa quantas vezes eu delete ele, toda vez ele volta e outra coisa chata tbm eh que nao consigo instalar otro antivirus, nao consigo entrar em modo seguro, varios programas de remoção de virus nao roda, nem programas de reparação no sistema e registro ta impossivel mexer no pc, cada dia que passa ele fica mais lento Alguem pode me ajudar ? Obrigado Fico no Aguardo! //////////////\/\\\\\\\\\\\\\\ Boa Noite! GustavohP <!> Poste o log do HijackThis,segundo este Tutorial. < Regra Nº 02 - Utilizando O Hijackthis - LEIA ANTES DE POSTAR! > <!> Caso tenha dificuldades,leia o seguinte Tutorial: < Como abrir um Tópico,em Segurança & Malwares > Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GustavohP 0 Denunciar post Postado Abril 12, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:47:27, on 12/4/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\explorer.exe C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe C:\Arquivos de programas\Analog Devices\SoundMAX\smax4.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\SRNMIC~1\SOLOSENT.EXE C:\SRNMIC~1\SOLOCFG.EXE C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\DOCUME~1\GUSTAV~1\CONFIG~1\Temp\winbmsnpk.exe C:\DOCUME~1\GUSTAV~1\CONFIG~1\Temp\yhthpy.exe C:\HijackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file) O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\smax4.exe" /tray O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [amd_dc_opt] C:\Arquivos de programas\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKLM\..\Run: [soloSentry] C:\SRNMIC~1\SOLOSENT.EXE O4 - HKLM\..\Run: [soloSchedule] C:\SRNMIC~1\SOLOCFG.EXE O4 - HKLM\..\Run: [soloSysCheck] C:\SRNMIC~1\SYSCHECK.COM O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) (HKCU) O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/PopularScreenSaversInitialSetup1.0.1.1.cab O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} (CopyGuardCtrl Class) - http://www.psapoll.com/CopyGuardIE.cab O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://systemrequirementslab.com.s3.amazonaws.com/iduu/bin/srldetect_intel.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: VideoAcceleratorService - Unknown owner - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe (file missing) O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe -- End of file - 6911 bytes Ta ai! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 13, 2010 Boa Tarde! GustavohP <@> Baixe: < > Link! <@> < Link - 2 > <@> < Link - 3 > <@> Atualize o programa! <@> Escolha o escaneamento Completo! <@> Desabilite programas de proteção,ao executar o malwarebytes. <@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme! <@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens. <@> Para maiores detalhes: < Link > <><><><><><><><><><><> <@> Poste,os relatórios: mbam-log-2010-xx-xx (00-00-00).txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GustavohP 0 Denunciar post Postado Abril 13, 2010 Log do HiJackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:14:31, on 13/4/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe C:\DOCUME~1\GUSTAV~1\CONFIG~1\Temp\sxoehu.exe C:\DOCUME~1\GUSTAV~1\CONFIG~1\Temp\vbxb.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\HijackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file) O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\smax4.exe" /tray O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [amd_dc_opt] C:\Arquivos de programas\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKLM\..\Run: [soloSentry] C:\SRNMIC~1\SOLOSENT.EXE O4 - HKLM\..\Run: [soloSchedule] C:\SRNMIC~1\SOLOCFG.EXE O4 - HKLM\..\Run: [soloSysCheck] C:\SRNMIC~1\SYSCHECK.COM O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra button: (no name) - {09E90109-A9AA-4980-BCEF-76F8D924E902} - (no file) (HKCU) O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O10 - Unknown file in Winsock LSP: c:\arquiv~1\speedb~1\sblsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} (CopyGuardCtrl Class) - http://www.psapoll.com/CopyGuardIE.cab O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://systemrequirementslab.com.s3.amazonaws.com/iduu/bin/srldetect_intel.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: VideoAcceleratorService - Unknown owner - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe (file missing) O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe -- End of file - 6925 bytes Log do Mawarebytes: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Versão da Base de Dados: 3984 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 13/4/2010 14:14:06 mbam-log-2010-04-13 (14-14-06).txt Tipo de Verificação: Verificação Completa (C:\|D:\|) Objetos escaneados: 206589 Tempo decorrido: 37 minuto(s), 55 segundo(s) Processos de Memória Infectados: 1 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 23 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 1 Pastas Infectadas: 3 Arquivos Infectados: 21 Processos de Memória Infectados: C:\Documents and Settings\GustavohP\Configurações locais\Temp\winujynf.exe (Trojan.Agent) -> Unloaded process successfully. Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bebf} (Adware.SmartShopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3cc3d8fe-f0e0-4dd1-a69a-8c56bcc7bec0} (Adware.SmartShopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} (Adware.SmartShopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8bcb5337-ec01-4e38-840c-a964f174255b} (Adware.SmartShopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\svchosts (Trojan.Banker) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Pastas Infectadas: C:\Documents and Settings\GustavohP\Dados de aplicativos\Smart-Shopper (Adware.SmartShopper) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Dados de aplicativos\Smart-Shopper\cs (Adware.SmartShopper) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463 (Keylogger.Ardamax) -> Quarantined and deleted successfully. Arquivos Infectados: C:\Documents and Settings\GustavohP\Configurações locais\Temp\WINFTHVCY.EXX (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Configurações locais\Temp\WINVHSDQ.EXX (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Configurações locais\Temp\WINWQXVV.EXX (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Configurações locais\Temp\YMCH.EXX (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Configurações locais\Temp\winujynf.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Meus documentos\Downloads\Alcohol 120%+Keygen\Alcohol 120% 1.9.8.7421 + Patch [Lançamento 24-02-2009]\Patch\patch_ssc.exe (Trojan.Patcher) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Meus documentos\Downloads\DAEMON Tools+ Patch\Patch\Patch.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Meus documentos\Downloads\u98.exe (Adware.UltraReach) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\AKV.exe (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.001 (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.002 (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.005 (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.006 (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.009 (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\28463\IHFO.exe (Keylogger.Ardamax) -> Quarantined and deleted successfully. C:\WINDOWS\system32\svchosts.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\explorer.exe (Worm.AutoRun) -> Quarantined and deleted successfully. D:\Instaladores\Photoshop CS3\Photoshop_CS3__Portable-Portugues_\Adobe Photoshop CS3\Msvcrt.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully. D:\Instaladores\Photoshop CS3\Photoshop_CS3__Portable-Portugues_\Adobe Photoshop CS3\Shfolder.dll (Trojan.Agent) -> Quarantined and deleted successfully. D:\L2 Off\L2off_C6_DHX\L2 Restarter\L2Res.exe (Spyware.Passwords) -> Quarantined and deleted successfully. D:\Lineage II\System L2GodsBr\fire.dll (Malware.Packer.T) -> Quarantined and deleted successfully. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 15, 2010 Bom Dia! GustavohP <@> Repita o scan com o Malwarebytes,e poste seu relatório. 0000000000000000000 0000000000000000000 <@> Baixe: < KB958644 > <@> Descompacte-a para a pasta C:\Windows e instale-a aí mesmo! <@> Baixe: < KK > <@> Salve-o no desktop! <@> Extraia o seu conteúdo para C:\ <@> Desative,temporariamente,seu antivírus. <@> Vá em Iniciar --> Executar --> Digite ou cole: c:\kk.exe -x -y -l conficker.txt -v <@> Clique OK e aguarde o término do scan. <@> Ps: O programa será fechado automaticamente. <@> Poste o resumo,localizado no final do relatório,criado em C:\conficker.txt 0000000000000000000 0000000000000000000 <@> Baixe: < DrWebCureIt > <@> Salve DrWebCureIt.exe em Arquivos de programas. <@> Reinicie o computador em Modo de Segurança. <@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit. <@> Na janela que abrir,clique em Iniciar --> OK. <@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda! <@> Terminando,marque a caixa de "Verificação Completa". <@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis". <@> Ps: Neste modo são verificados os seguintes objetos: :seta: Sectores de Arranque de Todos os Discos :seta: Todas as Unidades Removíveis :seta: Todos os Discos Locais <@> Clique em "Iniciar verificação" --> Aguarde! <@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim. <@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios". <@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Converta em Texto! <@> Poste: DrWeb.csv + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
GustavohP 0 Denunciar post Postado Abril 16, 2010 Log do Malwarebytes Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Versão da Base de Dados: 3984 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 15/4/2010 20:32:14 mbam-log-2010-04-15 (20-32-14).txt Tipo de Verificação: Verificação Completa (C:\|D:\|) Objetos escaneados: 206786 Tempo decorrido: 46 minuto(s), 18 segundo(s) Processos de Memória Infectados: 1 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 1 Pastas Infectadas: 0 Arquivos Infectados: 3 Processos de Memória Infectados: C:\Documents and Settings\GustavohP\Configurações locais\Temp\winubyoh.exe (Trojan.Proxy) -> Failed to unload process. Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: C:\Documents and Settings\GustavohP\Configurações locais\Temp\winubyoh.exe (Trojan.Proxy) -> Delete on reboot. C:\Documents and Settings\GustavohP\Configurações locais\Temp\WINHRXL.EXX (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\GustavohP\Configurações locais\Temp\WJRL.EXX (Trojan.Agent) -> Quarantined and deleted successfully. Ae eu fiz como você me pediu, soh que eu n consigo posta o log do KK e nem consigo baixa o DrWebCurelt qd eu tento posta o log, o firefox ou o ie8 trava, e qd eu tento baixa o DrWebCurelt o Firefox ou o Ie8 Fexa do nd Valeu pela Atenção! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 17, 2010 Boa Tarde! GustavohP <@> Utilize outro computador e crie o Kaspersky Rescue Disk. <@> A Kaspersky está oferecendo um Rescue Disk,para remover malwares,sem a necessidade de iniciar o Windows. <@> Baixe o arquivo ISO,e grave a imagem em um CD ou DVD. <@> Temos,abaixo,Links opcionais ao arquivo iso. < KasperskyRescueDisk > < Softpedia Mirror (US) [OTHER] > Link - 1 < Softpedia Mirror (RO) [OTHER] > Link - 2 < External Mirror 1 [OTHER] > Link - 3 <@> Reinicie seu computador,na desinfecção,à partir desse disco. <@> Escolha,no antivírus,a(s) unidade(s) que queira a verificação. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Maio 18, 2010 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites