![]() |
| |||||||
| Foro Oficial de HijackThis en español Analizamos tu log de HijackThis para eliminar Hijackers, Spyware, Adware, ToolBars, Virus, Troyanos y Malwares en gral. Antes lea las Políticas del Foro de HijackThis. |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Entran virus Como quieren Bueno , primero que nada quiero darles las gracias a todos los q hacen esto posible ya q ayuda a aprender y enseñar Tengo un gran problema, necesito q me ayuden a chequera mi server, ya q tengo varios problemas con los virus, entran y salen como quieren, ultimamente tuve varios Troyanos q me costo harto eliminar por favor ayudita : le mando el log: Logfile of HijackThis v1.99.1 Scan saved at 10:30:47, on 09-09-2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\msdtc.exe C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE d:\Apache Group\Tomcat 4.1\bin\tomcat.exe C:\WINNT\System32\ati2plxx.exe C:\Program Files\CA\BrightStor ARCserve Backup\DBENG.exe C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsv c.exe C:\Program Files\CA\BrightStor ARCserve Backup\jobeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\msgeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\caserved.exe C:\Program Files\CA\BrightStor ARCserve Backup\casmrtbk.exe C:\Program Files\CA\BrightStor ARCserve Backup\tapeeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\cadiscovd.exe C:\Program Files\CA\SharedComponents\BrightStor\UniAgent\Univ Agent.exe C:\Program Files\CA\BrightStor ARCserve Backup\Catirpc.exe C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe C:\Program Files\CA\SharedComponents\BrightStor\DBAcommon\DBA SVR.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\WINNT\SYSTEM32\DWRCS.EXE C:\Program Files\CA\BrightStor ARCserve Backup\caloggerd.exe C:\WINNT\System32\svchost.exe C:\WINNT\SYSTEM32\GxRpcSrv.exe C:\WINNT\System32\llssrv.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\WINNT\System32\NMSSvc.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\Program Files\CA\BrightStor ARCserve Backup\caauthd.exe C:\WINNT\system32\ntfrs.exe d:\Program files\ODI\OStore\BIN\OSCMGR6.EXE d:\Program files\ODI\OStore\BIN\OSSERVER.EXE C:\Program Files\CA\BrightStor Backup Agent for Open Files\Ofant.exe C:\Program Files\CA\BrightStor ARCserve Backup Agent for SQL\dbasqlr.exe C:\Program Files\CA\BrightStor ARCserve Backup\LQServer.exe C:\WINNT\system32\regsvc.exe c:\winnt\system32\mss.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\Dfssvc.exe C:\WINNT\System32\inetsrv\inetinfo.exe C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe C:\WINNT\System32\svchost.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe C:\Program Files\CA\BrightStor ARCserve Backup\Mediasvr.exe C:\WINNT\Explorer.EXE C:\WINNT\System32\locator.exe C:\Program Files\CA\BrightStor ARCserve Backup\asalert.exe C:\Program Files\CA\BrightStor ARCserve Backup\LDBServer.exe C:\WINNT\SYSTEM32\DWRCST.exe C:\WINNT\system32\PROMon.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\internat.exe C:\WINNT\System32\svchost.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cl/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 130.0.0.5:8002 F2 - REG:system.ini: Shell= O1 - Hosts: 128.250.24.62 onlineaccounts2.abbeynational.co.uk O1 - Hosts: 128.250.24.62 www3.aibgbonline.co.uk O1 - Hosts: 128.250.24.62 www.bank.alliance-leicester.co.uk O1 - Hosts: 128.250.24.62 login.iblogin.com O1 - Hosts: 128.250.24.62 ww2.bankofscotlandhalifax-online.co.uk O1 - Hosts: 128.250.24.62 inet.barclays.co.uk O1 - Hosts: 128.250.24.62 iibank.barclays.co.uk O1 - Hosts: 128.250.24.62 iibank.cahoot.com O1 - Hosts: 128.250.24.62 www3.coventrybuildingsociety.co.uk O1 - Hosts: 128.250.24.62 ww.hsbc.co.uk O1 - Hosts: 128.250.24.62 login.ebank.offshore.hsbc.co.je O1 - Hosts: 128.250.24.62 ww3.online-offshore.lloydstsb.com O1 - Hosts: 128.250.24.62 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 128.250.24.62 ww3.online.lloydstsb.co.uk O1 - Hosts: 128.250.24.62 ww3.online.lloydstsb.co.uk O1 - Hosts: 128.250.24.62 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 128.250.24.62 ob2.nationet.com O1 - Hosts: 128.250.24.62 ww3.onlinebanking.natwestoffshore.com O1 - Hosts: 128.250.24.62 ww1.nwolb.com O1 - Hosts: 128.250.24.62 ww1.onlinebanking.iombank.com O1 - Hosts: 128.250.24.62 ww1.www.rbsdigital.com O1 - Hosts: 128.250.24.62 welcome.smile.co.uk O1 - Hosts: 128.250.24.62 login.365online.com O1 - Hosts: 128.250.24.62 wvw.citizensbankonline.com O1 - Hosts: 128.250.24.62 esecure.regionsnet.com O1 - Hosts: 128.250.24.62 rollb.associatedbank.com O1 - Hosts: 128.250.24.62 upb.unionplanters.com O1 - Hosts: 128.250.24.62 www.onlinebanking.huntington.com O1 - Hosts: 128.250.24.62 inet.southtrustonlinebanking.com O1 - Hosts: 128.250.24.62 logon.personal.wamu.com O1 - Hosts: 128.250.24.62 login.compassweb.com O1 - Hosts: 128.250.24.62 logon.firstmeritib.com O1 - Hosts: 128.250.24.62 login.ccfcuonline.org O1 - Hosts: 128.250.24.62 ww3.etimebanker.bankofthewest.com O1 - Hosts: 128.250.24.62 ww2.onlinebanking.lasallebank.com O1 - Hosts: 128.250.24.62 wvw.totallyfreebanking.com O1 - Hosts: 128.250.24.62 www.online.wellsfargo.com O1 - Hosts: 128.250.24.62 www.onlinebanking.bankofoklahoma.com O1 - Hosts: 128.250.24.62 accounts4.keybank.com O1 - Hosts: 128.250.24.62 logon.bankone.com O1 - Hosts: 128.250.24.62 www.secure.tdbanknorth.com O1 - Hosts: 128.250.24.62 www.secure.mvnt4.com O1 - Hosts: 128.250.24.62 ww.mynfbonline.com O1 - Hosts: 128.250.24.62 login.forumcuonline.com O1 - Hosts: 128.250.24.62 www.eds.usersonlnet.com O1 - Hosts: 128.250.24.62 www.onlineid.bankofamerica.com O1 - Hosts: 128.250.24.62 wvw.e-gold.com O1 - Hosts: 128.250.24.62 pcbs.peoples.com O1 - Hosts: 128.250.24.62 www.global1.onlinebank.com O1 - Hosts: 128.250.24.62 ww2.mybranch.lafcu.com O1 - Hosts: 128.250.24.62 login.webbanking.comerica.com O1 - Hosts: 128.250.24.62 web.banking.firsttennessee.com O1 - Hosts: 128.250.24.62 logon.members1st.org O1 - Hosts: 128.250.24.62 www.cib.ibanking-services.com O1 - Hosts: 128.250.24.62 www.miwebbusbank.ebanking-services.com O1 - Hosts: 128.250.24.62 wvw.paypal.com O1 - Hosts: 128.250.24.62 www.signin.ebay.com O1 - Hosts: 128.250.24.62 wvw.etrade.com O1 - Hosts: 128.250.24.62 ww4.fleethomelink.fleet.com O1 - Hosts: 128.250.24.62 ww3.connect.skyfi.com O1 - Hosts: 128.250.24.62 www6.usbank.com O1 - Hosts: 128.250.24.62 www.bvi.bancodevalencia.es O1 - Hosts: 128.250.24.62 extrant.banesto.es O1 - Hosts: 128.250.24.62 banesnt.banesto.es O1 - Hosts: 128.250.24.62 activia.caixagalicia.es O1 - Hosts: 128.250.24.62 www.bancae.caixapenedes.com O1 - Hosts: 128.250.24.62 login.caixasabadell.net O1 - Hosts: 128.250.24.62 oii.cajamadrid.es O1 - Hosts: 128.250.24.62 login.cajamar.es O1 - Hosts: 128.250.24.62 login.ccm.es O1 - Hosts: 128.250.24.62 ww.unicaja.es O1 - Hosts: 128.250.24.62 www5.bancopopular.es O1 - Hosts: 128.250.24.62 ww3.bbvanet.com O1 - Hosts: 128.250.24.62 ww.bayernlb.de O1 - Hosts: 128.250.24.62 ww2.berliner-volksbank.de O1 - Hosts: 128.250.24.62 ww7.homebanking-berlin.de O1 - Hosts: 128.250.24.62 portal09.commerzbanking.de O1 - Hosts: 128.250.24.62 www.meine.deutsche-bank.de O1 - Hosts: 128.250.24.62 ww2.dresdner-privat.de O1 - Hosts: 128.250.24.62 ww.e-banking.helaba.de O1 - Hosts: 128.250.24.62 ww.hsh-nordbank.de O1 - Hosts: 128.250.24.62 www.my.hypovereinsbank.de O1 - Hosts: 128.250.24.62 ww3.homebanking-berlin.de O1 - Hosts: 128.250.24.62 ww3.homebanking-berlin.de O1 - Hosts: 128.250.24.62 www.banking.lbbw.de O1 - Hosts: 128.250.24.62 lrp.sparkasse-banking.de O1 - Hosts: 128.250.24.62 ww3.homebanking-niedersachsen.de O1 - Hosts: 128.250.24.62 www.onlinebanking.norisbank.de O1 - Hosts: 128.250.24.62 www.banking.postbank.de O1 - Hosts: 128.250.24.62 wvw.internetbanking.gad.de O1 - Hosts: 128.250.24.62 ww1.portal.izb.de O1 - Hosts: 128.250.24.62 wvw.kunden-service.lbs.de O1 - Hosts: 128.250.24.62 ibanking.seb.de O1 - Hosts: 128.250.24.62 bw7.sparkasse-banking.de O1 - Hosts: 128.250.24.62 ww2.homebanking-sparkasse.de O1 - Hosts: 128.250.24.62 ww2.vr-networld-ebanking.de O1 - Hosts: 128.250.24.62 ww.bics.fr O1 - Hosts: 128.250.24.62 www.co.caixabank.fr O1 - Hosts: 128.250.24.62 ww.creditmutuel.fr O1 - Hosts: 128.250.24.62 internetbank.intesabci.it O1 - Hosts: 128.250.24.62 ww.extensive.bancalombarda.it O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\system32\dllcache\java.dll (file missing) O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe O4 - HKLM\..\Run: [HotKeyInformat] C:\Program Files\Sistemas Informat\HotKeys.exe O4 - HKLM\..\Run: [svchost] C:\WINNT\svchost.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [TrojanScanner] D:\Program Files\Trojan Remover\Trjscan.exe O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - Global Startup: Administrador de servicios.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Descargar usando Download &Express - C:\Program Files\Download Express\Add_Url.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126195862234 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CCS\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CS1\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CS2\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll O23 - Service: Alert Notification Server - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - d:\Apache Group\Tomcat 4.1\bin\tomcat.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\ati2plxx.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: CA BrightStor Database Engine (CASDBEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\DBENG.exe O23 - Service: CA BrightStor Discovery Service (CASDiscoverySvc) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsv c.exe O23 - Service: CA BrightStor Job Engine (CASJobEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\jobeng.exe O23 - Service: CA BrightStor Message Engine (CASMsgEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\msgeng.exe O23 - Service: CA BrightStor Service Controller (CASSvcControlSvr) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\caserved.exe O23 - Service: CA BrightStor Tape Engine (CASTapeEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\tapeeng.exe O23 - Service: CA BrightStor Domain Server (CASUnivDomainSvr) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\cadiscovd.exe O23 - Service: CA BrightStor Universal Agent (CASUniversalAgent) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\UniAgent\Univ Agent.exe O23 - Service: CA Remote Procedure Call Server (CATIRPC) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\Catirpc.exe O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: CA BrightStor Backup Agent RPC Server (DbaRpcService) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\DBAcommon\DBA SVR.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE O23 - Service: GxRpcServer - Unknown owner - C:\WINNT\SYSTEM32\GxRpcSrv.exe O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: FireDaemon Service: MOUSETASK (MOUSETASK) - Unknown owner - c:\winnt\system32\com\\FireDaemon.EXE (file missing) O23 - Service: mr2kserv - Unknown owner - C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe O23 - Service: ObjectStore Cache Manager R6.0 - eXcelon Corp. - d:\Program files\ODI\OStore\BIN\OSCMGR6.EXE O23 - Service: ObjectStore Server R6.0 - eXcelon Corp. - d:\Program files\ODI\OStore\BIN\OSSERVER.EXE O23 - Service: CA Backup Agent for Open Files (OpenFileAgent) - Computer Associates - C:\Program Files\CA\BrightStor Backup Agent for Open Files\Ofant.exe O23 - Service: Print Spool Handler (Print Spooler) - Unknown owner - C:\WINNT\system32\spooler.exe (file missing) O23 - Service: CA BrightStor Backup Agent Remote Service (RemoteDbagent) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup Agent for SQL\dbasqlr.exe O23 - Service: Remote Administrator Service (r_server) - Unknown owner - c:\winnt\system32\mss.exe" /service (file missing) O23 - Service: Disk Management Service (VxSvc) - VERITAS Software Corp. - C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe |
![]() | ![]() |
| ||||
| Re: Entran virus Como quieren Hola , te doy la bienvenida al Foro de InfoSpyware. Seguí estos pasos para: Eliminar Spyware VX2 Después nos comentas los resultados en este mismo mensaje. Salu2 Hablándole al mundo en "Twitter"" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Ya, hice todo lo q me dijiste , pero me podrias decir exactamente que tenia , y que solucion fue la q me diste en realidad, seeliminaron los host que me decias, pero cual fue la causa de todo eso....... Saludos. |
![]() | ![]() |
| ||||
| Re: Entran virus Como quieren Bueno antes que nada déjanos otro log de HijackThis en este mismo mensaje para verificar que ya tu sistema este limpio. Lo que tenias era una variante de Spyware VX2 el cual modifica el registro y el archivo Host de Win haciendo que tu navegador se redireccione al visitar ciertos sitios que este establece, aparte de otros problemas como enlentecer el sistema y mas. La solución que te di, es que ya tenemos como ese y otros malwares comunes los pasos para su eliminación y herramientas especificas para poder eliminarlo. Salu2 Hablándole al mundo en "Twitter"" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Entran virus Como quieren Bueno, muchas gracias por tu gran ayuda, aqui te mando el log : espero que asi este bien.. Saludos. Logfile of HijackThis v1.99.1 Scan saved at 8:21:42, on 12-09-2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\msdtc.exe C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE d:\Apache Group\Tomcat 4.1\bin\tomcat.exe C:\WINNT\System32\ati2plxx.exe C:\Program Files\CA\BrightStor ARCserve Backup\DBENG.exe C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsv c.exe C:\Program Files\CA\BrightStor ARCserve Backup\jobeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\msgeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\casmrtbk.exe C:\Program Files\CA\BrightStor ARCserve Backup\caserved.exe C:\Program Files\CA\BrightStor ARCserve Backup\tapeeng.exe C:\Program Files\CA\BrightStor ARCserve Backup\cadiscovd.exe C:\Program Files\CA\SharedComponents\BrightStor\UniAgent\Univ Agent.exe C:\Program Files\CA\BrightStor ARCserve Backup\Catirpc.exe C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe C:\Program Files\CA\SharedComponents\BrightStor\DBAcommon\DBA SVR.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\WINNT\SYSTEM32\DWRCS.EXE C:\WINNT\System32\svchost.exe C:\WINNT\SYSTEM32\GxRpcSrv.exe C:\WINNT\System32\llssrv.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe C:\WINNT\System32\NMSSvc.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINNT\system32\ntfrs.exe d:\Program files\ODI\OStore\BIN\OSCMGR6.EXE d:\Program files\ODI\OStore\BIN\OSSERVER.EXE C:\Program Files\CA\BrightStor Backup Agent for Open Files\Ofant.exe C:\Program Files\CA\BrightStor ARCserve Backup Agent for SQL\dbasqlr.exe C:\WINNT\system32\regsvc.exe c:\winnt\system32\mss.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\Dfssvc.exe C:\WINNT\System32\inetsrv\inetinfo.exe C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlagent.exe C:\Program Files\CA\BrightStor ARCserve Backup\caloggerd.exe C:\WINNT\System32\locator.exe C:\Program Files\CA\BrightStor ARCserve Backup\asalert.exe C:\Program Files\CA\BrightStor ARCserve Backup\LDBServer.exe C:\Program Files\CA\BrightStor ARCserve Backup\caauthd.exe C:\Program Files\CA\BrightStor ARCserve Backup\LQServer.exe C:\Program Files\CA\BrightStor ARCserve Backup\Mediasvr.exe C:\WINNT\Explorer.EXE C:\WINNT\SYSTEM32\DWRCST.exe C:\WINNT\system32\PROMon.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINNT\system32\internat.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\WINNT\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\CA\BrightStor ARCserve Backup\BrightStorMgr.exe C:\Program Files\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 130.0.0.5:8002 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\system32\dllcache\java.dll (file missing) O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe O4 - HKLM\..\Run: [HotKeyInformat] C:\Program Files\Sistemas Informat\HotKeys.exe O4 - HKLM\..\Run: [svchost] C:\WINNT\svchost.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [TrojanScanner] D:\Program Files\Trojan Remover\Trjscan.exe O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - Global Startup: Administrador de servicios.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Descargar usando Download &Express - C:\Program Files\Download Express\Add_Url.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126195862234 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CCS\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CS1\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = AtacamaKozan.local O17 - HKLM\System\CS2\Services\Tcpip\..\{348E2A78-5C25-4EC0-AB66-B11AA1D813E5}: NameServer = 130.0.0.100 O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll O23 - Service: Alert Notification Server - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\Alert\ALERT.EXE O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - d:\Apache Group\Tomcat 4.1\bin\tomcat.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\ati2plxx.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: CA BrightStor Database Engine (CASDBEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\DBENG.exe O23 - Service: CA BrightStor Discovery Service (CASDiscoverySvc) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\CADS\casdscsv c.exe O23 - Service: CA BrightStor Job Engine (CASJobEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\jobeng.exe O23 - Service: CA BrightStor Message Engine (CASMsgEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\msgeng.exe O23 - Service: CA BrightStor Service Controller (CASSvcControlSvr) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\caserved.exe O23 - Service: CA BrightStor Tape Engine (CASTapeEngine) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\tapeeng.exe O23 - Service: CA BrightStor Domain Server (CASUnivDomainSvr) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\cadiscovd.exe O23 - Service: CA BrightStor Universal Agent (CASUniversalAgent) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\UniAgent\Univ Agent.exe O23 - Service: CA Remote Procedure Call Server (CATIRPC) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup\Catirpc.exe O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: CA BrightStor Backup Agent RPC Server (DbaRpcService) - Computer Associates - C:\Program Files\CA\SharedComponents\BrightStor\DBAcommon\DBA SVR.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE O23 - Service: GxRpcServer - Unknown owner - C:\WINNT\SYSTEM32\GxRpcSrv.exe O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: FireDaemon Service: MOUSETASK (MOUSETASK) - Unknown owner - c:\winnt\system32\com\\FireDaemon.EXE (file missing) O23 - Service: mr2kserv - Unknown owner - C:\Program Files\Dell\OpenManage\Array Manager\mr2kserv.exe O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe O23 - Service: ObjectStore Cache Manager R6.0 - eXcelon Corp. - d:\Program files\ODI\OStore\BIN\OSCMGR6.EXE O23 - Service: ObjectStore Server R6.0 - eXcelon Corp. - d:\Program files\ODI\OStore\BIN\OSSERVER.EXE O23 - Service: CA Backup Agent for Open Files (OpenFileAgent) - Computer Associates - C:\Program Files\CA\BrightStor Backup Agent for Open Files\Ofant.exe O23 - Service: Print Spool Handler (Print Spooler) - Unknown owner - C:\WINNT\system32\spooler.exe (file missing) O23 - Service: CA BrightStor Backup Agent Remote Service (RemoteDbagent) - Computer Associates - C:\Program Files\CA\BrightStor ARCserve Backup Agent for SQL\dbasqlr.exe O23 - Service: Remote Administrator Service (r_server) - Unknown owner - c:\winnt\system32\mss.exe" /service (file missing) O23 - Service: Disk Management Service (VxSvc) - VERITAS Software Corp. - C:\Program Files\Dell\OpenManage\Array Manager\VxSvc.exe |
![]() | ![]() |
| ||||
| Re: Entran virus Como quieren Hola, hay dos archivos sospechosos en tu sistema pero antes de eliminarlos para estar seguros hacelos anlizar online con la herramienta de "Antivirus Online" Los archivos son: c:\winnt\system32\mss.exe C:\WINNT\svchost.exe Y nos contas los resultados. Salu2 Hablándole al mundo en "Twitter"" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Entran virus Como quieren hola de nuevo hice lo q dijiste el primero esta limpio, pero el segundo sale en el registro de windows solamente, como archivo dentro de la carpeta Winnt no esta, , lo elimino???, como puedo saber de q se trata , o como poder analizarlo si no lo puedo ver? Saludos |
![]() | ![]() |
| ||||
| Re: Entran virus Como quieren Hablándole al mundo en "Twitter"" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| about:blank (solucionado) | rubentome | Temas Solucionados | 13 | 06/06/05 04:08:53 |
| Ya No Puedo Mas... About Blank, Pop Ups En Mi Explorer | kermitr05 | Foro Oficial de HijackThis en español | 11 | 16/05/05 19:36:10 |
| Y seguimos con el fijo... loadingwebsite [solucionado] | don benito | Temas Solucionados | 55 | 06/05/05 19:14:32 |
| problema con el vroomsearch | dasanlos | Foro Oficial de HijackThis en español | 5 | 05/05/05 11:31:01 |
| Hotoffers (Estoy muy emproblemado) | Emproblemado | Foro Oficial de HijackThis en español | 7 | 22/04/05 07:48:05 |