Senhores, dando continuídade ao meu post do dia 10/07/2006, informo que instalei o spybot e o Ad-aware, mas não consegui executar nenhum destes softwares...feito isso, usei o HijackThis ( Logs ) e o anti-virus on line BitDefender...Por favor, peço que alguêm com mais experência possa analisar o resultado abaixo e me dar alguma alternativa para eliminar essas malditas pragas. Obrigado !
Logfile of HijackThis v1.99.1
Scan saved at 21:26:30, on 11/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\ARQUIV~1\mcafee.com\agent\mcagent.exe
C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe
C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe
C:\ARQUIV~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\XPAudio\csrss.exe
C:\Arquivos de programas\Messenger\msmsgs.exe
c:\arquiv~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\mscompls.exe
C:\ARQUIV~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\arquiv~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\CTsvcCDA.exe
c:\arquivos de programas\mcafee.com\agent\mcdetect.exe
c:\ARQUIV~1\mcafee.com\vso\mcshield.exe
c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe
C:\ARQUIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Arquivos de programas\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
D:\Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Arquivos de programas\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\ARQUIV~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CommServices] C:\WINDOWS\system32\XPAudio\csrss.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xportar para o Microsoft Excel -
res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEAFBE5D-9663-4815-97E7-18DA98C8D204}: NameServer = 200.204.0.10 200.204.0.138
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARQUIV~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\ARQUIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
BitDefender Online Scanner
Scan report generated at: Tue, Jul 11, 2006 -
Scan path: A:\;C:\;D:\;E:\;F:\;
Statistics
Time
01:13:25
Files
329906
Folders
2185
Boot Sectors
3
Archives
1683
Packed Files
47003
Results
Identified Viruses
4
Infected Files
7
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
6
Engines Info
Virus Definitions
407232
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
39
Unpack plugins
5
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020548.exe
Infected with: Trojan.Spy.Winspy.P
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020548.exe
Disinfection failed
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020548.exe
Deleted
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020551.exe
Infected with: Trojan.Spy.Winspy.P
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020551.exe
Disinfection failed
C:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP50\A0020551.exe
Deleted
C:\WINDOWS\rdesk.exe
Infected with: Trojan.Spy.Winspy.P
C:\WINDOWS\rdesk.exe
Disinfection failed
C:\WINDOWS\rdesk.exe
Deleted
C:\WINDOWS\system32\XPAudio\csrss.exe
Infected with: Trojan.Spy.Agent.HO
C:\WINDOWS\system32\XPAudio\csrss.exe
Disinfection failed
C:\WINDOWS\system32\XPAudio\csrss.exe
Delete failed
D:\Downloads\Win Epy Setup.exe=>(ZIP Sfx s)=>1.txt
Infected with: Trojan.Spy.Agent.HO
D:\Downloads\Win Epy Setup.exe=>(ZIP Sfx s)=>1.txt
Desinfection failed
D:\Downloads\Win Epy Setup.exe=>(ZIP Sfx s) =>1.txt
Deleted
D:\Downloads\Win Epy Setup.exe=>(ZIP Sfx s)
Updated
D:\Downloads\Win Epy Setup.exe
Update failed
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>7.txt
Infected with: Trojan.Spy.Winspy.P
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>7.txt
Disinfection failed
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>7.txt
Deleted
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)
Updated
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>13.txt
Infected with: Trojan.Spy.Winspy.P
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>13.txt
Disinfection failed
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)=>13.txt
Deleted
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe=>(ZIP Sfx s)
Updated
D:\System Volume Information\_restore{E4368D24-130A-4CDF-BDCC-E01865399EEA}\RP67\A0021929.exe
Update failed