anti-virus bitdefender 8.0

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

anti-virus bitdefender 8.0

Mensagempor luis1 » Domingo Nov 14, 2004 22:05

boas:
fiz um scan ao computador e estou com problema de perceber isto C:\WINDOWS\Downloaded Program Files\CABDialer.dll Infected Trojan.Downloader.Small.QZ
C:\WINDOWS\Downloaded Program Files\CABDialer.dll Disinfection failed
C:\WINDOWS\Downloaded Program Files\CABDialer.dll Moved
C:\WINDOWS\Downloaded Program Files\WinadX.dll=>(Upx) Infected Trojan.Downloader.Winupdt.A
C:\WINDOWS\Downloaded Program Files\WinadX.dll=>(Upx) Disinfection failed
C:\WINDOWS\Downloaded Program Files\WinadX.dll Moved

será k ainda tenho alguma praga!? :( obrigado
luis1
Aprendiz
Aprendiz
 
Mensagens: 53
Registado: Terça Set 28, 2004 23:03

Mensagempor Tretabyte » Terça Nov 16, 2004 13:08

Boas,
uma pequena e rapida procura no google encontra-se logo isto
http://www.pandasoftware.com/virus_info ... irus=50447
Effects

WUpd has the following effects:

*
It stores information on the Internet usage habits of the affected user.
*
It displays popup advertisements founding on this data.
*
It updates itself to a higher version, if available.

Infection strategy

WUpd creates the following files:

*
Depending on the version of the adware, WUpd creates any of the following files:
BRIDGEX.DLL, CLIENTCOMMN.DLL,COMM.DLL, WINAD.EXE, WINADX.DLL, WINCLT.EXE, WINKA.EXE or WINUPDT.EXE.
These files download other files from the Internet.
* IDE21201.VXD in the Windows system directory. This is a legitimate file and it is used in Windows Me/98/95 computers in order to get data on the hard disk installed.

WUpd deletes the files AUTOEXEC.BAT and AUTOEXEC.NT.

WUpd creates the following entries in the Windows Registry:

*
HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
Winad Client

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Run
WindUpdates
By creating these two entries, WUpd ensures it is run whenever Windows is started.
* HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Uninstall\ Winad Client

HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Uninstall\ Wind Updates
These two entries allow users to uninstall WUpd from the Control Panel.
*
HKEY_CLASSES_ROOT\ Bridge.brdg
*
HKEY_CLASSES_ROOT\ Bridge.brdg.1
*
HKEY_CLASSES_ROOT\ WinadX.Installer
*
HKEY_CLASSES_ROOT\ CLSID\ {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}
*
HKEY_CLASSES_ROOT \CLSID\ {9C691A33-7DDA-4C2F-BE4C-C176083F35CF}
*
HKEY_CLASSES_ROOT\ TypeLib\ {DDAF2479-6F00-4599-998A-3ED75686C6D0}
*
HKEY_CLASSES_ROOT\ Interface\ {4FDBDBAD-FEFE-4C4C-9CC1-1181052AFB12}
*
HKEY_LOCAL_MACHINE\ SOFTWARE\ Winad Client

Means of transmission

Adware is a license form for using programs, which offers the application at the only cost of viewing a series of advertisements. However, these programs sometimes collect data on Internet usage habits, pages viewed, inventory of the applications installed in the computer, etc.
Further Details

WUpd is written in the programming language Visual C++ and it is compressed with UPX.


sem mais
Tretabyte
Avatar do Utilizador
Tretabyte
Gurus
Gurus
 
Mensagens: 5333
Registado: Sábado Jan 17, 2004 13:17
Localização: Lx

Mensagempor luis1 » Terça Nov 16, 2004 23:26

boas!
obrigado tretabyte
luis1
Aprendiz
Aprendiz
 
Mensagens: 53
Registado: Terça Set 28, 2004 23:03

Mensagempor luis1 » Quinta Nov 18, 2004 23:54

boas!
já fiz isso ai e não resultou tenho mais isto para ver se me podem ajudar
Logfile of HijackThis v1.98.2
Scan saved at 22:28:51, on 18-11-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\DVDRAMSV.EXE
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programas\Ficheiros comuns\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Programas\Java\jre1.5.0\bin\jusched.exe
C:\Programas\Softwin\BitDefender8\bdoesrv.exe
C:\Programas\Softwin\BitDefender8\bdswitch.exe
C:\Programas\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programas\Internet Explorer\IEXPLORE.EXE
C:\Programas\Ficheiros comuns\Softwin\BitDefender Scan Server\bdss.exe
C:\Programas\Softwin\BitDefender8\vsserv.exe
c:\progra~1\softwin\bitdef~1\bdmcon.exe
C:\Programas\WinRAR\WinRAR.exe
C:\DOCUME~1\Luis\DEFINI~1\Temp\Rar$EX00.735\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programas\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Programas\Creative\SBLive\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [MaxProtector] C:\Programas\MaxProtector\MaxProtector.exe ontray
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] C:\Programas\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
O4 - HKLM\..\Run: [BDSwitchAgent] C:\Programas\Softwin\BitDefender8\\bdswitch.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Programas\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fazer Download utilizando o Download &Express - C:\Programas\Download Express\Add_Url.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 4136756906
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

obrigado
luis1
Aprendiz
Aprendiz
 
Mensagens: 53
Registado: Terça Set 28, 2004 23:03

Mensagempor [PT]CableGuy » Sexta Nov 19, 2004 0:14

Olá luis1:

Tenta usar o CD que indico no seguinte post:

LIMPA COMPLETAMENTE O TEU PC (Trojans,Worms,Virus)

Está uma maravilha e também ensina a usar as ferramentas usuais de combate a estes problemas.
Vale a pena tentar...visita o link para veres. :wink:
Abraços.
[PT]CableGuy
Gurus
Gurus
 
Mensagens: 1845
Registado: Domingo Mai 30, 2004 16:26

Mensagempor luis1 » Sábado Nov 20, 2004 18:50

boas cableguy já usei esse teu cd mas ele fica travado quando esta a ler os ficheiros obrigado
luis1
Aprendiz
Aprendiz
 
Mensagens: 53
Registado: Terça Set 28, 2004 23:03


Voltar para Segurança Informática

Quem está ligado:

Utilizadores a ver este Fórum: Nenhum utilizador registado e 3 visitantes

cron