| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: Mi PC esta infectado con un troyano (trojan win 32) Hola leyda y con el permiso de Marianot realiza lo siguiente: Realiza lo indicado en : Virus en el cache de Java Luego: Apaga Restaurar Sistema Activa la Opcion Ver Archivos Ocultos Descargate OTMoveIt lo guardas en el Escritorio.
Cita:
Envía el informe (reporte) de OTMoveIt situado sobre C: \ _ OTMoveIt\MovedFiles. - Ejecuta Ccleaner en sus opciones de limpiador y registro no olvides hacer una copia de seguridad. - Reinicias en modo normal , activas la restauración y desactivas ver archivos ocultos. Finalmente realizas un escaneo online con : -Panda online dudas sobre este lees su manual y pegas su reporte. - Kaspersky Online Scanner cualquier duda sobre este último lees su manual y pegas el reporte que te da de resultado. Regresa y nos comentas. Saludos ![]() |
![]() | ![]() |
| ||||
| Re: Mi PC esta infectado con un troyano (trojan win 32) Por lo que estuve viendo este trojan recupera información con lo relacionado con bancos por lo que te reomiendo no lleves ninguna transacción ni compra. Intenta eliminarlo con nod32 en modo seguro si este no llegara a eliminarlo nos avisas que te explico como eliminarlo manaulmente. obiamente todo esto si no funciona lo que te dijo el amigo sikartus. ![]() |
![]() | ![]() |
| ||||
| Re: Mi PC esta infectado con un troyano (trojan win 32) holaz!! weno despues de todo hice todo lo ke me dijiste... muxas gracias por responder y ayudarme!! : Incidencia Estado Elemento Virus:Trj/Nabload.CIP Desinfectado Sistema Operativo Adware:adware/megatds No desinfectado Registro de Windows Herramienta potencialmente no deseada:application/funweb No desinfectado HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} Virus:Trj/Nabload.CIP Desinfectado C:\WINDOWS\SYSTEM32\NOR9973.EXE Virus:Trj/Nabload.CIP Desinfectado C:\WINDOWS\SYSTEM32\MMN9743.EXE Virus:Trj/Nabload.CIP Desinfectado C:\WINDOWS\SYSTEM32\NXK4413.EXE Virus:Trj/Nabload.CIP Desinfectado C:\WINDOWS\SYSTEM32\MEP2548.EXE Virus:Trj/Nabload.CIP Desinfectado C:\WINDOWS\SYSTEM32\ABQ3246.EXE Spyware:Cookie/WUpd No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@revenue[2].txt Spyware:Cookie/Searchportal No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@searchportal.information[1].txt Spyware:Cookie/GoClick No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@goclick[2].txt Spyware:Cookie/FastClick No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@fastclick[1].txt Spyware:Cookie/RealMedia No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@realmedia[2].txt Spyware:Cookie/Atlas DMT No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@atdmt[1].txt Spyware:Cookie/bravenetA No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@bravenet[1].txt Spyware:Cookie/Doubleclick No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@doubleclick[2].txt Spyware:Cookie/YieldManager No desinfectado C:\Documents and Settings\PC\Configuración local\Temp\Cookies\pc@ad.yieldmanager[2].txt Spyware:Cookie/Mysearch No desinfectado C:\Documents and Settings\PC\Cookies\pc@mysearch[1].txt Spyware:Cookie/Atlas DMT No desinfectado C:\Documents and Settings\PC\Cookies\pc@atdmt[1].txt Spyware:Cookie/YieldManager No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@ad.yieldmanag er[2].txt Spyware:Cookie/Atlas DMT No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@atdmt[1].txt Spyware:Cookie/2o7 No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@2o7[2].txt Spyware:Cookie/Sextracker No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@counter8.sext racker[1].txt Spyware:Cookie/cs.sexcounter No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@cs.sexcounter[2].txt Spyware:Cookie/Sextracker No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@counter9.sext racker[1].txt Spyware:Cookie/Sextracker No desinfectado C:\Documents and Settings\Dj.Charli\Cookies\dj.charli@sextracker[2].txt Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\WHH9200.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\DCH8882.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\YSS3553.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\XNN4733.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\DMS5046.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\QEH1534.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\FYI7225.E XE Virus:Trj/Nabload.CIP Desinfectado C:\_OTMoveIt\MovedFiles\WINDOWS\SYSTEM32\DHD777 .EXE kapersky Tuesday, October 23, 2007 6:35:21 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 24/10/2007 Kaspersky Anti-Virus database records: 416285 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics Total number of scanned objects 74120 Number of viruses found 2 Number of infected objects 16 Number of suspicious objects 0 Duration of the scan process 01:04:07 Infected Object Name Virus Name Last Action C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{6F10A1 21-4212-4833-9EBF-C6E04A1B6521}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb .log Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp .edb Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\DataStor e.edb Object is locked skipped C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\pc\NTUSER.DAT Object is locked skipped C:\Documents and Settings\pc\Configuración local\Temp\~DFF556.tmp Object is locked skipped C:\Documents and Settings\pc\Configuración local\Temp\~DFC277.tmp Object is locked skipped C:\Documents and Settings\pc\Configuración local\Temp\~DFF55B.tmp Object is locked skipped C:\Documents and Settings\pc\Configuración local\Temp\~DF314D.tmp Object is locked skipped C:\Documents and Settings\pc\Configuración local\Temp\~DF3152.tmp Object is locked skipped C:\Documents and Settings\pc\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\pc\Configuración local\Historial\History.IE5\MSHist0120071023200710 24\index.dat Object is locked skipped C:\Documents and Settings\pc\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\pc\Configuración local\Archivos temporales de Internet\PhishingFilter\45E13EC5-3DB7-4B3D-9F80-073A58AB5E82.dat Object is locked skipped C:\Documents and Settings\pc\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\pc\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\pc\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\char6_99@hotmail.com\real\members.stg Object is locked skipped C:\Documents and Settings\pc\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\char6_99@hotmail.com\shadow\members.stg Object is locked skipped C:\Documents and Settings\pc\Cookies\index.dat Object is locked skipped C:\Documents and Settings\pc\Datos de programa\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped C:\Documents and Settings\pc\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \eRT.jar-2ad5ac73-33fe50bb.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped C:\Documents and Settings\pc\Datos de programa\Sun\Java\Deployment\cache\javapi\v1.0\jar \eRT.jar-2ad5ac73-33fe50bb.zip ZIP: infected - 1 skipped C:\Documents and Settings\pc\ntuser.dat.LOG Object is locked skipped C:\Archivos de programa\ESET\logs\virlog.dat Object is locked skipped C:\Archivos de programa\ESET\logs\warnlog.dat Object is locked skipped C:\Archivos de programa\ESET\cache\CACHE.NDB Object is locked skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\change.log Object is locked skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000001.exe Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000002.exe Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000003.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000004.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000005.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000006.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000007.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000008.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000009.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000010.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000011.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000012.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000013.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped C:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\A0000014.EXE Infected: Trojan-Spy.Win32.Bancos.ajx skipped E:\System Volume Information\_restore{C3DC3690-F3B2-4200-8D56-7B04830F53C2}\RP1\change.log Object is locked skipped E:\Archivos de programa\DAP\Log\DAP_REPORT.LOG Object is locked skipped E:\Archivos de programa\DAP\History\pc\_lasthist.dat Object is locked skipped Scan process completed. Ot MOveIt C:\WINDOWS\system32\whh9200.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\dch8882.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\yss3553.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\xnn4733.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\dms5046.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\qeh1534.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\fyi7225.exe moved successfully. File/Folder not found. C:\WINDOWS\system32\dhd777.exe moved successfully. Created on 10/23/2007 15:40:18 weno eso es todo.. ahora?? jeje sorry..... muxas gracias por su ayuda.. estamos en comunicacion!! |
![]() | ![]() |
| ||||
| Re: Mi PC esta infectado con un troyano (trojan win 32) Elimina los virus de Java como Sikartus te indica.Cita:
Desinstala(si esta):
A continuación:• Apaga Restaurar Sistema (Sólo para Windows Me y XP). Haz un escaneo con Kaspersky Online Scanner. (Aqui el manual) y péganos el reporte que te genere. Realiza un escaneo online con "Panda ActiveScan Online" y nos dejas su reporte en este mismo mensaje. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Infectado con una variante de win32/Obfuscated | jmorinigo | Foro de Virus y Spywares | 3 | 14/08/07 07:55:10 |
| win32/agenteNFH (troyano)...(Solucionado) | cdomnanich | Temas Solucionados | 18 | 30/06/07 06:49:27 |
| Se me apaga el pc cada 8 min... =( (Solucionado) | Skboy | Temas Solucionados | 3 | 22/02/06 17:41:24 |
| No consigo eliminar Look2Me, y otros problemas (solucionado) | SeteSete | Temas Solucionados | 14 | 05/12/05 15:52:22 |
| ya tengo mi "log" please ayudenme | jdr | Foro Oficial de HijackThis en español | 10 | 21/11/05 14:34:29 |