1. Este site usa cookies. Ao continuar a usar este site está a concordar com o nosso uso de cookies. Saber Mais.
  2. A secção Microsoft/Windows encontra-se actualmente em processo de reestruturação.
    Remover anúncio

Virus o que fazer? Urgente

Discussão em 'Windows Desktop e Surface' iniciada por amq, 15 de Junho de 2007. (Respostas: 6; Visualizações: 1685)

  1. amq

    amq Power Member

    Boas. Há uma semana reparei que o meu computador estava muito lento e decidi fazer uma pesquisa a ver se havia algum virus.
    Usei o avast e encontrei vários, na sua maioria cavalos de tróia e adware.
    Isto começou a piorar e procurei uns antispyware. Usando o AVG Anti-Spyware e o Spyware Doctor encontrei e eliminei alguns. Mas ainda está está muito lento. Usei também o HijackThis, mas não sei o que fazer. Cá vai o log:

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 19:39:53, on 15-06-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Programas\Alwil Software\Avast4\ashServ.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\windows\system32\javascriptsystem.exe
    C:\Programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Programas\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\WcgopSvc.exe
    C:\Programas\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    C:\WINDOWS\System32\alg.exe
    C:\Programas\MSN Messenger\usnsvc.exe
    C:\Programas\Internet Explorer\iexplore.exe
    C:\Programas\Spyware Doctor\svcntaux.exe
    C:\Documents and Settings\Alexandre Queirós\Definições locais\Temporary Internet Files\Content.IE5\94CMVORU\HiJackThis_v2[1].exe
    C:\Programas\WinRAR\WinRAR.exe
    C:\Programas\Spyware Doctor\swdsvc.exe
    C:\DOCUME~1\ALEXAN~1\DEFINI~1\Temp\Rar$EX07.696\StartupList.exe
    C:\DOCUME~1\ALEXAN~1\DEFINI~1\Temp\Rar$EX04.133\StartupList.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sapo.pt/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
    O2 - BHO: (no name) - {05B682AD-8813-40D3-AE2D-C4AB839931D9} - C:\WINDOWS\system32\vtspn.dll (file missing)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\system32\lgcafoks.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\vtusrqn.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programas\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\undqqtff.dll",realset
    O4 - HKLM\..\Run: [JavaScript System] "C:\windows\system32\javascriptsystem.exe"
    O4 - HKCU\..\Run: [swg] C:\Programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Programas\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIÇO LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVIÇO LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Serviço de rede')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Programas\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E274E61B-34BB-4C93-AAB0-21DE15F18175}: NameServer = 195.23.129.126,194.79.69.222
    O20 - Winlogon Notify: vtspn - C:\WINDOWS\system32\vtspn.dll (file missing)
    O20 - Winlogon Notify: vtusrqn - vtusrqn.dll (file missing)
    O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Daemon da cache de categorias dos componentes - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programas\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programas\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Programas\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Programas\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Programas\Spyware Doctor\swdsvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    --
    End of file - 7414 bytes




    Alguém sabe o que fazer??
     
  2. Dj Pedro

    Dj Pedro Power Member

    Experimenta com o SpySweeper é um programa muito bom contra adwares,spywares,etc..

    Cumps.:)
     
  3. Frabex

    Frabex Power Member

    Tens aí alguma bicharada.
    Faz fix checked aos:

    C:\windows\system32\javascriptsystem.exe

    C:\WINDOWS\WcgopSvc.exe

    O2 - BHO: (no name) - {05B682AD-8813-40D3-AE2D-C4AB839931D9} - C:\WINDOWS\system32\vtspn.dll (file missing)

    O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\system32\lgcafoks.dll

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\vtusrqn.dll (file missing)

    O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\undqqtff.dll",realset

    O4 - HKLM\..\Run: [JavaScript System] "C:\windows\system32\javascriptsystem.exe"

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab

    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/W...gPublisher.exe

    O20 - Winlogon Notify: vtspn - C:\WINDOWS\system32\vtspn.dll (file missing)

    O20 - Winlogon Notify: vtusrqn - vtusrqn.dll (file missing)

    O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Daemon da cache de categorias dos componentes - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    Depois de fazeres fix checked a esses todos, instala e corre o CCleaner (www.ccleaner.com) que limpa registos e entradas, limpa, e verifica se tem erros.
    Reinicia o PC.
    Conta o sucedido.
     
  4. luikki

    luikki Power Member

    Frabex:
    aconselho-te alguma calma e muito cuidado com a informação que pretendes passar para quem precisa de ajuda!!!
    o maior problema do amq é ter dois anti-vírus instalados em simultâneo...
    enquanto um deles não for desinstalado não vale a pena usar o hjt!!!!!
     
  5. amq

    amq Power Member

    Não entendi... Então ter 2 anti-virus é pior para mim???

    Ah, fiz o que o Frabex disse e parece que está mais rápido.
     
  6. luikki

    luikki Power Member

    claro que sim!!!!!!!!!!!
    decide-te por um e desinstala o outro...
    limpa o registo com o ccleaner...
     
  7. BladeRunner

    BladeRunner Banido

    Ter dois anti virus a funcionar em simultaneo só pode ter um resultado: conflitos e como resultado desses conflitos: "bicharada" e asneirada!!
     

Partilhar esta Página