![]() |
| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Infectado por Trojan-Downloader.Win 32.Agent.zan (Solucionado) Hola amigos, llevo tres días con el ordenador infectado. Ya he leído el caso de varios usuarios con problemas parecidos al mío. El fondo de pantalla se volvío azul y con un aviso de alerta por infección. Coincidiendo con esto se instaló un círculo rojo con aspas blancas en la barra de tareas, que lanza continuamente el mensaje: "Your computer is infected" y me deshabilitó el análisis en tiempo real del antivirus (Mcfee). Intenté limpiarlo con Ad-aware 2008 pero no lo conseguí y buscando información en google localicé este foro. Como ya he dicho, he podido comprobar que más de un usuario padece o ha padecido el mismo problema. No obstante, después de leer las normás antes de postear, he abierto este nuevo tema porque he observado que se dan soluciones distintas según el caso. Actualmente he conseguido (sinceramente no sé cómo) activar de nuevo el antivirus, pero como si nada y he analizado el ordenador con el Karspersky Online Scanner, cuyo informe es el siguiente: ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER INFORME viernes, 15 de agosto de 2008 14:08:19 Sistema operativo: Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600) Kaspersky Online Scanner versión: 5.0.84.1 Ultima actualización: 15/08/2008 Registros en la base antivirus: 973886 ------------------------------------------------------------------------------- Configuración del análisis: Analizar usando las siguientes bases: standard Analizar archivos: verdadero Analizar bases de correo: verdadero Objetivo a analizar - Mi PC: A:\ C:\ D:\ E:\ Estadísticas: Número de objetos analizados: 112880 Virus encontrados: 2 Objetos infectados: 4 / 0 Objetos sospechosos: 0 Duración del análisis: 03:43:06 Nombre del objeto infectado / Nombre del virus / Última acción C:\WINDOWS\system32\config\system.LOG Object is locked saltado C:\WINDOWS\system32\config\software.LOG Object is locked saltado C:\WINDOWS\system32\config\default.LOG Object is locked saltado C:\WINDOWS\system32\config\SECURITY Object is locked saltado C:\WINDOWS\system32\config\SAM Object is locked saltado C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado C:\WINDOWS\system32\config\SYSTEM Object is locked saltado C:\WINDOWS\system32\config\SOFTWARE Object is locked saltado C:\WINDOWS\system32\config\DEFAULT Object is locked saltado C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado C:\WINDOWS\system32\~.exe Infectados: Trojan-Downloader.Win32.Mutant.avx saltado C:\WINDOWS\system32\CatRoot2\edb.log Object is locked saltado C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked saltado C:\WINDOWS\system32\h323log.txt Object is locked saltado C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked saltado C:\WINDOWS\SoftwareDistribution\EventCache\{3B6DC7 FB-6E8F-446C-9C09-F8B49997FEF4}.bin Object is locked saltado C:\WINDOWS\WindowsUpdate.log Object is locked saltado C:\WINDOWS\SchedLgU.Txt Object is locked saltado C:\WINDOWS\Sti_Trace.log Object is locked saltado C:\WINDOWS\wiaservc.log Object is locked saltado C:\WINDOWS\wiadebug.log Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\McAfee\Common Framework\Db\Agent_DIONISIO1.log Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\McAfee\Common Framework\Db\PrdMgr_DIONISIO1.log Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\McAfee\DesktopProtection\OnAccessScanLog. txt Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\McAfee\DesktopProtection\AccessProtection Log.txt Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\McAfee\DesktopProtection\BufferOverflowPr otectionLog.txt Object is locked saltado C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked saltado C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked saltado C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked saltado C:\Documents and Settings\Dionisio\NTUSER.DAT Object is locked saltado C:\Documents and Settings\Dionisio\ntuser.dat.LOG Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Temp\hpodvd09.log Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Temp\NAILogs\UpdaterUI_DIONISIO1.log Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Historial\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Historial\History.IE5\MSHist0120080815200808 16\index.dat Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\Dionisio\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\Dionisio\Cookies\index.dat Object is locked saltado C:\Documents and Settings\Dionisio\Datos de programa\Real\Update\setup\data\gtb\GOOGLE_TOOLBAR \googletoolbarinstaller.exeInfectados: Trojan-Downloader.Win32.Agent.zan saltado C:\Documents and Settings\Dionisio\Datos de programa\Real\Update\setup\data\gtb_gds\GOOGLE_TOO LBAR\googletoolbarinstaller.exe Infectados: Trojan-Downloader.Win32.Agent.zan saltado C:\Archivos de programa\Archivos comunes\Real\GToolbar\GoogleToolbarInstaller.exe Infectados: Trojan Downloader.Win32.Agent.zan saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\inuse.txt Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\main.log Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\storydb.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\storydb.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\chn.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\chn.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_die.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_die.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_dnd.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_dnd.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_ext.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_ext.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_rcv.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs_rcv.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\prs.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\L0000004.FCS Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\chandir.dat Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\chandir.idx Object is locked saltado C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Users\Dionisio\Data\D0000000.FCS Object is locked saltado Análisis completado. Les agredecería mucho su ayuda y en cualquiera de los casos les felicito por la labor que he podido comprobar que realizan. Un saludo. Última edición por sebasbergo fecha: 15/08/08 a las 09:48:11. |
![]() | ![]() |
| ||||
| Re: Infectado por Trojan-Downloader.Win 32.Agent.zan Hola, te doy la bienvenida al Foro ![]() Descarga OTMoveIt y lo guardas en el Escritorio. Haz un doble clic sobre OTMoveIt.exe para ejecutarlo. Asegurate que este marcado "Unregister Dll's and Ocx's". Copia el texto que se encuentra en el recuadro de más abajo, y lo pegas en el cuadro Paste Standard List of Files / Folders Move Código: C:\WINDOWS\system32\~.exe C:\Documents and Settings\Dionisio\Datos de programa\Real\Update\setup\data\gtb_gds\GOOGLE_TOO LBAR\googletoolbarinstaller.exe C:\Archivos de programa\Archivos comunes\Real\GToolbar\GoogleToolbarInstaller.exe Clic en MoveIt! para iniciar la eliminación. Reinicia la PC (Este paso es importante), y busca el reporte que genera en: C: \ _ OTMoveIt\MovedFiles Luego:
1. Desactiva Restaurar Sistema 2. Reinicia en Modo Seguro 3. Haz una Limpieza con CCleaner, usa la opción Limpiador para borrar cookies y temporales, y la opción Registro para efectuar una limpieza del registro de Windows. 4. Ejecuta DelPSGuard 5. Ejecuta Malwarebytes' Anti-Malware (Es importante que seleccionar escaneo completo y la opción de quitar lo encontrado)* Reinicia en Modo Normal y pasa Panda, pegando aquí el reporte que genere. (Selecciona MiPC, para que el escaneo sea completo) *Una vez terminados los pasos, vuelve a activar Restaurar Sistema* *Nota: Es importante que sigas los pasos tal cual se detallan, para mayor comodidad, puedes imprimirlosMe dejas los reportes de Panda,Malwarebytes' y DelPSGuard Saludos Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Infectado por Trojan-Downloader.Win 32.Agent.zan Hola de nuevo. He realizado, paso por paso y en el orden indicado tus recomendaciones. Aunque el Panda ha detectado algún virus, al menos de momento la dichosa y molesta bola roja con aspas blancas parece que ha desaparecido. Te adjunto a continuación los reportes que me pedías: Panda: Código: ;*********************************************************************************************************************************************************************************** ANALYSIS: 2008-08-15 17:49:33 PROTECTIONS: 1 MALWARE: 13 SUSPECTS: 2 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== McAfee VirusScan Enterprise 8.5.0.781 No Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@casalemedia[1].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@doubleclick[1].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@atdmt[1].txt 00139535 Application/Processor HackTools No 0 No No C:\Documents and Settings\Dionisio\Escritorio\SDFix.exe[C:\Documents and Settings\Dionisio\Escritorio\SDFix.exe][SDFix\apps\Process.exe] 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@tradedoubler[2].txt 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@tribalfusion[2].txt 00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@statcounter[1].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@ad.yieldmanager[1].txt 00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@weborama[1].txt 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@adrevolver[2].txt 02526573 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Dionisio\Mis documentos\My Albums\key_illustrator_cs3_javo.zip[key illustrator cs3_javo/keygen.exe] 02526573 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Dionisio\Mis documentos\My Albums\key illustrator cs3_javo\KEYGEN.EXE 02902637 Rootkit/Nurech.BC HackTools No 1 Yes No C:\_OTMoveIt\MovedFiles\08142008_201744\WINDOWS\SYSTEM32\DLLCACHE\BEEP.SYS 02902637 Rootkit/Nurech.BC HackTools No 1 Yes No C:\_OTMoveIt\MovedFiles\08142008_201744\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS 03205018 Generic Trojan Virus/Trojan No 0 Yes No C:\Archivos de programa\DelPSGuard\IED.EXE ;=================================================================================================================================================================================== SUSPECTS Sent Location nv ;=================================================================================================================================================================================== No C:\_OTMoveIt\MovedFiles\08152008_151743\WINDOWS\SYSTEM32\~.EXE nv No C:\WINDOWS\SYSTEM32\RAXWVYLO.EXE nv ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description nv ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== Código: Malwarebytes' Anti-Malware 1.24
Versión de la Base de Datos: 1012
Windows 5.1.2600 Service Pack 3
16:08:39 15/08/2008
mbam-log-8-15-2008 (16-08-39).txt
Tipo de examen : Examen Completo (A:\|C:\|D:\|E:\|)
Objetos examinados: 140674
Tiempo transcurrido: 15 minute(s), 22 second(s)
Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 22
Valores del Registro Infectados: 5
Elementos de Datos del Registro Infectados: 0
Carpetas Infectadas: 14
Ficheros Infectados: 66
Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Claves del Registro Infectadas:
HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcau4j0elol (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\uninstall (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
Valores del Registro Infectados:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\buritos (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Elementos de Datos del Registro Infectados:
(No se han detectado elementos maliciosos)
Carpetas Infectadas:
C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Archivos de programa\akl (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\rhcau4j0elol\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
Ficheros Infectados:
C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Archivos de programa\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Archivos de programa\akl\akl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Archivos de programa\akl\uninstall.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\Archivos de programa\akl\unsetup.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\WINDOWS\buritos.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\phceu4j0elol.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dionisio\Datos de programa\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\administrator2\Configuración local\Temp\.tt9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\administrator2\Configuración local\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\administrator2\Configuración local\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\administrator2\Configuración local\Temp\.ttA.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
Código: DelPSGuard v 4.9.8 by www.ForoSpyware.com Reporte Creado: 15:46:13,32, 15/08/2008 SO: Microsoft Windows XP [Versi¢n 5.1.2600] Modo de Inicio: Seguro _________________________________________ »»»»»»»»»»»» Carpetas y Archivos infectados »»»»»»»»»»»» C:\WINDOWS\system32 \ntimage.gif Eliminado Malware.Bagle »»»»»»»»»»»»»»»»»»» Programas Malwares »»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»» FIN »»»»»»»»»»»»»»»»»»» Un saludo. |
![]() | ![]() |
| ||||
| Re: Infectado por Trojan-Downloader.Win 32.Agent.zan Descarga OTMoveIt y lo guardas en el Escritorio. Haz un doble clic sobre OTMoveIt.exe para ejecutarlo. Asegurate que este marcado "Unregister Dll's and Ocx's". Copia el texto que se encuentra en el recuadro de más abajo, y lo pegas en el cuadro Paste Standard List of Files / Folders Move Código: C:\Documents and Settings\Dionisio\Mis documentos\My Albums\key_illustrator_cs3_javo.zip C:\WINDOWS\SYSTEM32\RAXWVYLO.EXE Clic en MoveIt! para iniciar la eliminación. Reinicia la PC (Este paso es importante), y busca el reporte que genera en: C: \ _ OTMoveIt\MovedFiles El resto son falsos positivos Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Infectado por Trojan-Downloader.Win 32.Agent.zan Estimado Salba: He seguido nuevamente tus instrucciones con el OTMoveIt y el reporte es el siguiente: Código: C:\Documents and Settings\Dionisio\Mis documentos\My Albums\key_illustrator_cs3_javo.zip moved successfully. C:\WINDOWS\SYSTEM32\RAXWVYLO.EXE moved successfully. OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08162008_115335 Código: ;*********************************************************************************************************************************************************************************** ANALYSIS: 2008-08-16 15:32:36 PROTECTIONS: 1 MALWARE: 12 SUSPECTS: 2 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== McAfee VirusScan Enterprise 8.5.0.781 No Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@casalemedia[2].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@doubleclick[1].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@atdmt[2].txt 00139535 Application/Processor HackTools No 0 No No C:\Documents and Settings\Dionisio\Escritorio\SDFix.exe[C:\Documents and Settings\Dionisio\Escritorio\SDFix.exe][SDFix\apps\Process.exe] 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@tradedoubler[2].txt 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@tribalfusion[2].txt 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@mediaplex[1].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@ad.yieldmanager[1].txt 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@apmebf[2].txt 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@apmebf[1].txt 00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@weborama[1].txt 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Dionisio\Cookies\dionisio@adrevolver[1].txt 02902637 Rootkit/Nurech.BC HackTools No 1 Yes No C:\_OTMoveIt\MovedFiles\08142008_201744\WINDOWS\SYSTEM32\DLLCACHE\BEEP.SYS 02902637 Rootkit/Nurech.BC HackTools No 1 Yes No C:\_OTMoveIt\MovedFiles\08142008_201744\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS ;=================================================================================================================================================================================== SUSPECTS Sent Location 5A ;=================================================================================================================================================================================== No C:\_OTMoveIt\MovedFiles\08162008_115335\WINDOWS\SYSTEM32\RAXWVYLO.EXE 5A No C:\Documents and Settings\All Users\Datos de programa\DGDKNINA\vcjyvujm.exe.bak 5A ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description 5A ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== Finalmente quiero añadir que con la infección pasé tres días terribles, pero los doy por bien empleados por haberme dado la oportunidad de conocer vuestra labor. Resulta verdaderamente gratificante saber de personas que usan sus conocimientos para ayudar a los demás. Sinceramente muchas gracias. Un saludo. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Ayuda: Mil ventanas emergentes con publicidad | Nusska | Foro de Virus y Spywares | 32 | 17/09/08 17:21:24 |
| 2 virus, ayuda | coolrual | Foro de Virus y Spywares | 7 | 12/09/08 15:07:32 |
| virus en mi pendrive | Fabagnfr | Foro de Virus y Spywares | 7 | 10/08/08 23:01:34 |
| Your computer is infected! en la barra de tareas. (Solucionado) | andrisicus | Temas Solucionados | 22 | 30/04/08 13:58:15 |
| Miles de archivos .rar en la carpeta del incoming de emule Worm.W32/Archivarius@P2P | Assasina | Temas Solucionados | 36 | 04/04/08 15:59:10 |