Ver Mensaje Individual
  post #3 (permalink)  
Antiguo 03/02/08, 22:09:35
Fly By Night Fly By Night está offline
Usuario
 
Registrado: ene 2008
Ubicación: México
Mensajes: 20
Re: Problemas con Troyano Win32/Rbot

Hola!

He pasado los antivirus en IE y estos son los resultados. Me preocupan sobre todo los "skipped" del Kaspersky. ¿Qué puedo hacer?

Muchas gracias de antemano.

Saludos!


Va primero el SDFix... en posts siguientes pondré los otros antivirus...


SDFix: Version 1.135

Run by Fly By Night on Sun 02/03/2008 at 01:20 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default HKCU HomePage

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\SYSTEM32\MSV.EXE - Deleted
C:\lo.exe - Deleted
C:\WINDOWS\rundll32.exe - Deleted
C:\WINDOWS\system32\a.exe - Deleted
C:\WINDOWS\system32\msmsgs.exe - Deleted





Removing Temp Files...

ADS Check:




Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 13:28:28
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\BITS]
"StateIndex"=dword:00000000

scanning hidden files ...

C:\WINDOWS\system32\wbem\Performance\WmiApRpl_new. ini 924 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1


Remaining Services:
------------------



Authorized Application Key Export:

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Mon 11 Aug 2003 49,237 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Mon 11 Aug 2003 36,953 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Mon 11 Aug 2003 40,960 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Mon 11 Aug 2003 233,553 A..H. --- "C:\Program Files\America Online 9.0\waol.exe"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0091ab29 9e899a5920ad91739ad99c67\BIT122.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\021bbe9f 2a0e31da1414f03ea6d62389\BITEA.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\080070f6 461c8001578e5e4cd4bb024b\BIT5A.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a7407b4 9e4a15c0b9a45c0426de5360\BITFE.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\109fef93 c24da62cf8f31668d6ba9060\BIT54.tmp"
Wed 30 Jan 2008 487,736 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\15c0ab26 0081ce840e2b252751d01b80\BIT51.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1e0d5826 a4592cc6d08a9c51de1deab1\BIT116.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2d780972 0343ee9223ce4d88d99bf3c2\BIT13C.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\32cc7772 51e695000c46eaf909a80b37\BIT10B.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\33dda7a9 fdd16ad3949443f62d248f25\BIT15D.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3becf780 26ee8bb0c18f61c3d3645cb6\BITED.tmp"
Sun 3 Feb 2008 490,736 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4cbc0c1d a652794a86c37dbd177bef9d\BIT1FB.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4cc8107f de988bba1481bb736cc96c29\BIT53.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\52b72a83 54f3c8a72b1aee0b2a11d368\BIT130.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\55b5c397 ff94db07e8c1c336efaf0a7b\BIT206.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5652d934 eec8bfa4dc68c4e256a23d5e\BITDC.tmp"
Wed 30 Jan 2008 2,367,240 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\587d85e7 82ae94381c309d8add64e1a0\BIT44.tmp"
Sun 3 Feb 2008 1,025,808 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\63be32ba cbd73459f1f4fbd657823ecc\BIT4E.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\65cd5bd5 4188e653414d6e2035b6edfb\BIT50.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6f0fd10f c234123bcdf54ebca4b84cbd\BIT214.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\791153f2 4e30cff9e2b19e146f3029a9\BIT127.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\962449ea ea2a809dd7a3a95c81a023bd\BITE4.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a099dfb7 d5d88247579330743c8014f3\BIT143.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\a4eec311 89780c76a955690dc00fbe64\BIT103.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\adc42e4e 6905251cac80b18a8dccd42a\BIT20E.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b3ba2a04 0ecf3ac2cd2da399851bda00\BIT10F.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b945911f 54e4095cfe742ac0d024d810\BIT52.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c23140ab 2b4cffaee396a230df8b1229\BIT21A.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ccaf1415 8dd167fe34055e2bcf5a04e7\BIT58.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d20fc176 5c1d2a8e6c26cf77036ce48f\BIT59.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e3c31219 82c8a4d0c1605cfbcb9bb7c8\BIT56.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f934b30a 3337b488590ef3c1f3bbfd68\BIT150.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f941c900 a413f153861a4032214a1aec\BIT11C.tmp"
Sun 3 Feb 2008 611,592 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa53e640 686f7f15b5ee3f532304b804\BIT4D.tmp"
Mon 11 Aug 2003 111,824 A..H. --- "C:\Program Files\Common Files\aolshare\shell\us\shellext.dll"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\12304924 12c0d92c55a03b0de671f167\download\BIT6B1.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1fb659e2 5c21839251d560da33cbcfad\download\BITDF6.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\208c1a8c 52f47d7b2df4baa21f58d3da\download\BIT7AB.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\32e99364 da67a7850c38a7a4e067a1ed\download\BIT6D9.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4596f4b9 d8a4b5253ee760a58a45bcfb\download\BIT4A.tmp"
Wed 30 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\512e19b3 77bd5d52a1e190ecbd7a83eb\download\BIT5AB.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\52d0bad9 6d671744fec5c77caa4cdf4d\download\BIT452.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\694301db fd149d8645046cbc0b1067e8\download\BIT6D8.tmp"
Sat 2 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\7b94d041 c29d0b8d724c97ae0005e71b\download\BIT724.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\837a8691 e43011f909e4b3e192fe1437\download\BITBAE.tmp"
Sat 2 Feb 2008 101,774 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\aebb83db 003f77a45671fd2c1557da38\download\BIT1E3.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c9cdbfcd 49200c55d94bb81819c80f2b\download\BIT8E2.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d037d9bb bbdf880e477c3840b38c3180\download\BIT1B9.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d424e8f6 55073b64c82b6f4f138d5f7e\download\BIT49.tmp"
Thu 31 Jan 2008 3,049,009 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\da70638e e8e6f6c7eff37e755cd6f449\download\BIT763.tmp"
Thu 31 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\edc9e523 d8678897d85b5ee0ef1bbf7a\download\BIT1FB.tmp"
Sun 3 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f040a43a 7788e207ef67f26bf9f0471f\download\BITD94.tmp"

Finished!
Responder Con Cita