| Re: Virus identificado por avast! win32:banker-COP Por cierto aca esta mi reporte de kaspersky
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER INFORME
sábado, 20 de octubre de 2007 17:26:17
Sistema operativo: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner versión: 5.0.84.1
Ultima actualización: 20/10/2007
Registros en la base antivirus: 414476
-------------------------------------------------------------------------------
Configuración del análisis:
Analizar usando las siguientes bases: standard
Analizar archivos: verdadero
Analizar bases de correo: verdadero
Objetivo a analizar - Mi PC:
C:\
D:\
E:\
Estadísticas:
Número de objeros analizados: 82980
Virus encontrados: 1
Objetos infectados: 2 / 0
Objetos sospechosos: 0
Duración del análisis: 01:55:37
Bombre del objeto infectado / Nombre del virus / Última acción
C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERAN TISPYWARE.LOG Object is locked saltado
C:\Documents and Settings\Administrator\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked saltado
C:\Documents and Settings\Administrator\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\ApplicationHistory\hpqimzone.exe.3204510e .ini.inuse Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Ares\My Shared Folder\___ARESTRA___divx [spanish] un plan brillante con demi moore, michael caine[topquality] avi.wmv Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Ares\My Shared Folder\___ARESTRA___kyle xy 2x04 (maxmeister and jordanna-kvadratmalevicha ru) (hdtv-rip) rus.avi Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Ares\My Shared Folder\___ARESTRA___kyle xy 2x2-sub espaÑol-adeliux.avi Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Ares\My Shared Folder\___ARESTRA___kyle xy s02e04.avi Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Ares\My Shared Folder\___ARESTRA___un funeral de muerte cvcd ts-screener [dtl].mpg Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.fpt Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.cdx Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.dbf Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Desktop Search\Logs\OTFSMonLog.txt Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\Logs\Dfsr00005.log Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\pending.dat Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\Working\database_480E_6B3F_441F _9C5B\dfsr.db Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\Working\database_480E_6B3F_441F _9C5B\fsr.log Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\Working\database_480E_6B3F_441F _9C5B\fsrtmp.log Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Messenger\paotolosa_3@hotmail.c om\SharingMetadata\Working\database_480E_6B3F_441F _9C5B\tmp.edb Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\paotolosa_3@hotmail.com\real\members.stg Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\paotolosa_3@hotmail.com\shadow\members.st g Object is locked saltado
C:\Documents and Settings\Administrator\Configuración local\Datos de programa\Microsoft\Windows Media\11.0\WMSDKNSD.XML Object is locked saltado
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked saltado
C:\Documents and Settings\Administrator\Historial\History.IE5\index .dat Object is locked saltado
C:\Documents and Settings\Administrator\Historial\History.IE5\MSHis t012007102020071021\index.dat Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_ee0.dat Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_f3c.dat Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF335D.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF3377.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF66E8.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF66F9.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF6BFB.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF722A.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF72A8.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF793B.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DF7EC7.tmp Object is locked saltado
C:\Documents and Settings\Administrator\Local Settings\Temp\~DFF47F.tmp Object is locked saltado
C:\Documents and Settings\Administrator\ntuser.dat Object is locked saltado
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Ga therLogs\SystemIndex\SystemIndex.27.Crwl Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Ga therLogs\SystemIndex\SystemIndex.27.gthr Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MS S.log Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MS Stmp.log Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000C.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000D.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000E.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\0001000F.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010018.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010021.ci Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010021.wid Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\00010021.wsb Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\PropMap\CiPT0000.000 Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\PropMap\Used0000.000 Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\SecStore\CiST0000.000 Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\SystemIndex.chk1.gthr Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\SystemIndex.chk2.gthr Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Pr ojects\SystemIndex\SystemIndex.Ntfy8.gthr Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tm p.edb Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Wi ndows.edb Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp Object is locked saltado
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_ Perfdata_178.dat Object is locked saltado
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked saltado
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Desktop Search\Logs\UNCFATPHLog.txt Object is locked saltado
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked saltado
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked saltado
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked saltado
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked saltado
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked saltado
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked saltado
C:\Program Files\Alwil Software\Avast4\DATA\report\Protección residente.txt Object is locked saltado
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked saltado
C:\System Volume Information\_restore{5CAAC034-3E9F-4A8E-A3FE-99D20678A761}\RP13\change.log Object is locked saltado
C:\System Volume Information\_restore{5CAAC034-3E9F-4A8E-A3FE-99D20678A761}\RP8\A0000778.scr Infectados: Trojan-Downloader.Win32.Banload.dre saltado
C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado
C:\WINDOWS\ModemLog_HDAUDIO Soft Data Fax Modem with SmartCP.txt Object is locked saltado
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{E5F6023D-528D-4AAA-AA24-FB2A3843112E}.crmlog Object is locked saltado
C:\WINDOWS\SchedLgU.Txt Object is locked saltado
C:\WINDOWS\SoftwareDistribution\EventCache\{E5686E E4-22FE-4391-90DD-F9AD5B6EA824}.bin Object is locked saltado
C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked saltado
C:\WINDOWS\Sti_Trace.log Object is locked saltado
C:\WINDOWS\system\screensavers.scr Infectados: Trojan-Downloader.Win32.Banload.dre saltado
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked saltado
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked saltado
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked saltado
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\default Object is locked saltado
C:\WINDOWS\system32\config\default.LOG Object is locked saltado
C:\WINDOWS\system32\config\Internet.evt Object is locked saltado
C:\WINDOWS\system32\config\Media Ce.evt Object is locked saltado
C:\WINDOWS\system32\config\SAM Object is locked saltado
C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\SECURITY Object is locked saltado
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado
C:\WINDOWS\system32\config\software Object is locked saltado
C:\WINDOWS\system32\config\software.LOG Object is locked saltado
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\system Object is locked saltado
C:\WINDOWS\system32\config\system.LOG Object is locked saltado
C:\WINDOWS\system32\h323log.txt Object is locked saltado
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked saltado
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked saltado
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked saltado
C:\WINDOWS\system32\msmq\storage\QMLog Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado
C:\WINDOWS\Temp\Perflib_Perfdata_724.dat Object is locked saltado
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked saltado
C:\WINDOWS\wiadebug.log Object is locked saltado
C:\WINDOWS\wiaservc.log Object is locked saltado
C:\WINDOWS\WindowsUpdate.log Object is locked saltado
D:\System Volume Information\_restore{5CAAC034-3E9F-4A8E-A3FE-99D20678A761}\RP13\change.log Object is locked saltado
Análisis completado. |