Ver la Versión Completa : ayuda


huapeche
15/01/08, 01:55:34
hola que tal, aqui les expongo mi caso para pedir un poco de ayuda, cuando escaneo mi compu con el norton 360 y no me detecta ningun virus pero escanee mi compu con el kaspersky en lina y si encontro 5 virus, quiciera un poco de ayuda,aqui les pego el texto...

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, January 14, 2008 11:37:07 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/01/2008
Kaspersky Anti-Virus database records: 511638
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 61959
Number of viruses found: 5
Number of infected objects: 22
Number of suspicious objects: 0
Duration of the scan process: 01:25:42

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Archivos comunes\AOL\ACS\MX\forms.fdb Object is locked skipped
C:\Archivos de programa\Archivos comunes\AOL\ACS\MX\static Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDCON.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDFW.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\AVContext.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\AVManual.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\Backup.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\NCO.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Archivos de programa\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\muvee Technologies\030625\0102\0310\values Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\LiveUpdate\2008-01-14_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtETmp\1AA3119F.TMP Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtETmp\7FFE89D7.TMP Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\SDEN89AR\indexCAEQ47F8.htm Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\SDEN89AR\indexCAQ3RLX1.htm Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Archivos temporales de Internet\Content.IE5\5B3XVWFC\esp1[1].txt Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Archivos temporales de Internet\Content.IE5\5B3XVWFC\packed[1].exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Historial\History.IE5\MSHist0120080114200801 15\index.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Temp\73.exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\Documents and Settings\Rosales Ramírez\Configuración local\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\call256.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\index2.dat Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\profile256.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\user1024.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Skype\rrrtepic\user4096.dbb Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\6.0\53\16741df5-2bea8276/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\6.0\53\16741df5-2bea8276 ZIP: infected - 1 skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\6.0\54\6e4d3ab6-35ff866a/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\6.0\54\6e4d3ab6-35ff866a ZIP: infected - 1 skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \eRT.jar-7fa2058c-2bb51828.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \eRT.jar-7fa2058c-2bb51828.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \nRT.jar-6308d025-19c82087.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Rosales Ramírez\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \nRT.jar-6308d025-19c82087.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Rosales Ramírez\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Rosales Ramírez\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\tracking.log Object is locked skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP141\A0016295.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017026.exe Infected: Trojan.Win32.Qhost.aei skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017052.sys Infected: Rootkit.Win32.Agent.pr skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017083.sys Infected: Rootkit.Win32.Agent.pr skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017093.sys Infected: Rootkit.Win32.Agent.pr skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017109.sys Infected: Rootkit.Win32.Agent.pr skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017121.sys Infected: Rootkit.Win32.Agent.pr skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP145\A0017173.exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\System Volume Information\_restore{58DEBF9E-8D38-41FB-BF88-3C8E6BEAA4D3}\RP146\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7DF18E 8D-AD91-4C13-9C16-9C739F0B8274}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dllmonitor.exe Object is locked skipped
C:\WINDOWS\system32\drivers\etc\Hosts.bak Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hdxniety.exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\WINDOWS\system32\iibs.exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\odtc.exe Infected: Trojan-Downloader.Win32.Delf.czz skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\x03a Infected: Trojan.Win32.Qhost.aei skipped
C:\WINDOWS\Temp\cc10.tmp Object is locked skipped
C:\WINDOWS\Temp\cc11.tmp Object is locked skipped
C:\WINDOWS\Temp\cc12.tmp Object is locked skipped
C:\WINDOWS\Temp\cc13.tmp Object is locked skipped
C:\WINDOWS\Temp\JETEE7D.tmp Object is locked skipped
C:\WINDOWS\Temp\JETEF58.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

axl456
15/01/08, 02:02:39
Descarga el SUPERantispyware (http://www.infospyware.com/Anti-Spywares.htm) y realiza un escaneo profundo de tu equipo eliminando lo que encuentre.

luego realiza lo siguiente:

Descarga la herramienta ComboFix (http://www.forospyware.com/sUBs/ComboFix.exe).
Has doble click en el archivo combofix.exe y sigue los avisos, es IMPORTANTE que para que trabaje correctamente no utilices ninguna otra aplicacion mientras él analiza.
Cuando termine este generara un reporte el cual debes pegar aqui.
Nota* Puede que algunos Antivirus como Panda detecten un falso positivo en ComboFix pero no hay que preocuparse por esto.


nos dejas el reporte del CF.

© Copyright 2005 - 2008 InfoSpyware ® Todos los derechos reservados.
InfoSpyware Security Blog