Security Basics mailing list archives
RE: Please help: spyware in my machine...
From: René Oliveira Jr. <reneoliveirajr () hotmail com>
Date: Fri, 10 Nov 2006 19:29:56 +0000
Hi Eric, 1)Did you try remove these in windows security mode? 2)Did your windows xp are up to date?3)When I can't solve these problems with spybot, I try with microsoft anti-spyware remove tool
Regards
From: Meghdad Azriel <ericplastic-nabble () yahoo com br> To: security-basics () securityfocus com Subject: Please help: spyware in my machine... Date: Fri, 10 Nov 2006 04:20:35 -0800 (PST) MIME-Version: 1.0Received: from outgoing.securityfocus.com ([205.206.231.26]) by bay0-mc6-f14.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444); Fri, 10 Nov 2006 11:10:31 -0800 Received: from outgoing.securityfocus.com by outgoing.securityfocus.com via smtpd (for mx2.hotmail.com [65.54.244.168]) with ESMTP; Fri, 10 Nov 2006 11:03:59 -0800 Received: from lists.securityfocus.com (lists.securityfocus.com [205.206.231.19])by outgoing2.securityfocus.com (Postfix) with QMQPid AEE57181D4A; Fri, 10 Nov 2006 10:16:15 -0700 (MST)Received: (qmail 1238 invoked from network); 10 Nov 2006 13:39:51 -0000 X-Message-Info: txF49lGdW43sNMg06bhnBZKQAb0XEd7cicVhaOvjPrg= Mailing-List: contact security-basics-help () securityfocus com; run by ezmlm Precedence: bulk List-Id: <security-basics.list-id.securityfocus.com> List-Post: <mailto:security-basics () securityfocus com> List-Help: <mailto:security-basics-help () securityfocus com> List-Unsubscribe: <mailto:security-basics-unsubscribe () securityfocus com> List-Subscribe: <mailto:security-basics-subscribe () securityfocus com> Resent-Sender: listbounce () securityfocus com Errors-To: listbounce () securityfocus com Delivered-To: mailing list security-basics () securityfocus com
Delivered-To: moderator for security-basics () securityfocus com X-Nabble-From: ericplastic-nabble () yahoo com br Resent-Message-Id: <20061110171615.AEE57181D4A () outgoing2 securityfocus com> Resent-Date: Fri, 10 Nov 2006 10:16:15 -0700 (MST) Resent-From: security-basics-return-41778 () securityfocus comReturn-Path: security-basics-return-41778-reneoliveirajr=hotmail.com () securityfocus com X-OriginalArrivalTime: 10 Nov 2006 19:10:31.0842 (UTC) FILETIME=[E4642820:01C704FB]Hello, may you help me with this? there´s a red round icon with a yellow exclamation, that I couldn´t remove... I used SpybotS&D to clean but it´s still there... take a look: Logfile of HijackThis v1.99.1 Scan saved at 10:15:51, on 10/11/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\Arquivos de programas\Arquivos comuns\{705E7322-0855-1046-0606-050220040037}\Update.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe C:\DOCUME~1\Netsar\CONFIG~1\Temp\~e5d141.tmp C:\DOCUME~1\Netsar\CONFIG~1\Temp\~e5d141.tmp C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://192.168.0.145/site1/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1EC5262B-4D4E-B228-EDC9-03E8BDEC7F2B} - C:\WINDOWS\system32\goilqzj.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file) O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvwez.dll,startup O4 - HKLM\..\Run: [qflxncd.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\qflxncd.dll,pxvtukd O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [IpWins] C:\Arquivos de programas\ipwins\ipwins.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: .protected O4 - Global Startup: .protected O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111fd.bay111.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1140707718250 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: winwly32 - winwly32.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Arquivos deprogramas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe please help... --View this message in context: http://www.nabble.com/Please-help%3A-spyware-in-my-machine...-tf2607332.html#a7275861Sent from the Security Basics mailing list archive at Nabble.com. --------------------------------------------------------------------------- This list is sponsored by: Norwich University EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life. http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
_________________________________________________________________Descubra como mandar Torpedos Messenger do computador para o celular http://www.msn.com.br/artigos/maguire/default.asp
--------------------------------------------------------------------------- This list is sponsored by: Norwich University EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINEThe NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus ---------------------------------------------------------------------------
Current thread:
- Please help: spyware in my machine... Meghdad Azriel (Nov 10)
- RE: Please help: spyware in my machine... René Oliveira Jr . (Nov 10)
- Re: Please help: spyware in my machine... Tsu (Nov 10)
- Re: Please help: spyware in my machine... dawn (Nov 14)
- <Possible follow-ups>
- RE: Please help: spyware in my machine... Bob Dienhart (Nov 14)
- Re: Please help: spyware in my machine... Justin Lintz (Nov 15)