1. Este site usa cookies. Ao continuar a usar este site está a concordar com o nosso uso de cookies. Saber Mais.

Virus no MSN http://www.corporatins.smtp.ru/Album_Susy.html

Discussão em 'Dúvidas e Suporte Técnico PC' iniciada por varejo, 13 de Março de 2007. (Respostas: 6; Visualizações: 1039)

  1. varejo

    varejo Power Member

    Boas, no pc do meu vizinho sempre que liga o messenger envia para os contactos este link: http://www.corporatins.smtp.ru/Album_Susy.html que infecta quem o abrir, ja corri com o AVG 7.5, ad-ware SE, win defender, spywareterminator, spybot, e nao consigo tirar akilo, que me aconselham mais a fazer???
    :004::004::004:
     
  2. Froz3n

    Froz3n I fold therefore I AM

    Eu conheço esse virus... Faz um scan com o programa Hijackthis e posta aqui o log... Pode ser ke descubramos o problema... Mas ha muitas pessoas ai infectadas com esse virus
     
  3. varejo

    varejo Power Member

    Boas, e sem colocar o hijackthis, nao existe outro tipo de programa que remova isso??
    com o hijackthis nao é um pouco complicado??? é que nunca trabalhei com esse programa!!
    :blubomte:
     
  4. Froz3n

    Froz3n I fold therefore I AM

    Nada complicado... Akilo apenas da te um log file, de todos os processos ke tao a correr e as suas directorias. Postas aki o log, e depois alguem ou msm eu, veremos a bixeirada ke ta a correr, e apagas directamente dps...
     
  5. varejo

    varejo Power Member

    Boas, tá aki o log do Hijackthis:

    Logfile of HijackThis v1.99.1
    Scan saved at 22:58:02, on 13-03-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programas\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Programas\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\vsnct511.exe
    C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Programas\Ficheiros comuns\PCSuite\DataLayer\DataLayer.exe
    C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\JVM0.exe
    C:\Programas\Windows Defender\MSASCui.exe
    C:\Programas\Spyware Terminator\SpywareTerminatorShield.exe
    C:\Programas\MSN Messenger\MsnMsgr.Exe
    C:\PROGRA~1\FICHEI~1\PCSuite\Services\SERVIC~1.EXE
    C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Programas\Nokia\Nokia PC Suite 6\PcSync2.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\system2525.exe
    C:\PROGRA~1\FICHEI~1\Nokia\MPAPI\MPAPI3s.exe
    C:\Programas\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\KEYBOA~1\keyexp.exe
    C:\Programas\Ulead Systems\Ulead Photo Express 3.0 SE\calcheck.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    c:\Programas\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Proprietário-de-HP\Definições locais\Temp\wzde36\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Watch for Browser Events - {42A7CE31-CEE7-4CCE-A060-A44A7E52E062} - C:\PROGRA~1\KEYBOA~1\kie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar4.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programas\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SNCT511] C:\WINDOWS\vsnct511.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
     
  6. luikki

    luikki Power Member

    posta a file aqui e apaga o que te for indicado
     

Partilhar esta Página