| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| |||
| Podrian analizar este log? Gracias (solucionado) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:25:15, on 19/01/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Office Mouse Driver\MouseDrv.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\System32\spool\drivers\w32x86\3\E_FATIB VE.EXE C:\Users\TONI\AppData\Local\ceykg.exe C:\Windows\system32\conime.exe C:\Program Files\Lphant\eLePhantClient.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [WireLessMouse] C:\Program Files\Office Mouse Driver\StartAutorun.exe MouseDrv.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [recinfo] c:\recinfo\recinfo.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe O4 - HKCU\..\Run: [EPSON Stylus DX5000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIB VE.EXE /FU "C:\Windows\TEMP\E_S9C31.tmp" /EF "HKCU" O4 - HKCU\..\Run: [ceykg] "c:\users\toni\appdata\local\ceykg.exe" ceykg O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red') O4 - HKUS\S-1-5-18\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [fsc-reg] C:\ProgramData\fsc-reg\fscreg.exe (User 'Default user') O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestM anager\TestHandler.exe |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: Podrian analizar este log? Gracias Hola y bienvenido al foro... Descarga las siguientes herramientas pero no las ejecutes aún: Descarga el Ccleaner y lo usas en las opciones limpiador y luego en registro haciendo una copia del registro... Ejecuta las herramientas de la manera que te indico y en el orden que te lo indico:
Linux User Registered #453948 Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Podrian analizar este log? Gracias Muchas gracias por la rapida respuesta. Seguire las intrucciones al pie de la letra. |
![]() | ![]() |
| |||
| Re: Podrian analizar este log? Gracias Este es el log reportado tras la utilizacion del Malwarebytes: Malwarebytes' Anti-Malware 1.33 Versión de la Base de Datos: 1673 Windows 6.0.6001 Service Pack 1 21/01/2009 2:45:16 mbam-log-2009-01-21 (02-45-16).txt Tipo de examen : Examen Completo (C:\|M:\|) Objetos examinados: 134981 Tiempo transcurrido: 1 hour(s), 2 minute(s), 54 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 0 Claves del Registro Infectadas: 10 Valores del Registro Infectados: 2 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 9 Ficheros Infectados: 30 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\webmediaplayer (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully. Valores del Registro Infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\messengerskinner (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extens ions\Zango@Zango.com (Adware.Zango) -> Quarantined and deleted successfully. Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: C:\Program Files\MessengerSkinner (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\download (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\resources (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\skins (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\updates (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully. C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully. Ficheros Infectados: C:\Program Files\MessengerSkinner\MessengerSkinner.exe (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\download\defaultPack.cab (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\appconfig.xml (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btn.rgn (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnBnr.rgn (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnIn.rgn (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnInNormal.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnInOver.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnNormal.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnNormal.gif (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnNormalBnr.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnNormalBnr.gif (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnOver.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnOver.gif (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnOverBnr.bmp (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\btnOverBnr.gif (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\MessengerSkinner\resources\languages_v2.xml (Rogue.MessengerSkinner) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\sqlite3.dll (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\uninst.exe (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\resources\wmp_translation_fil e.xml (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\Program Files\WebMediaPlayer\skins\classic.skn (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA\ZangoSAau.dat (Adware.Zango) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA\ZangoSAEula.mht (Adware.Zango) -> Quarantined and deleted successfully. C:\ProgramData\ZangoSA\ZangoSA_kyf.dat (Adware.Zango) -> Quarantined and deleted successfully. C:\Users\Public\Desktop\WebMediaPlayer.lnk (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer (Rogue.WebMediaPlayer) -> Delete on reboot. |
![]() | ![]() |
| |||
| Re: Podrian analizar este log? Gracias ComboFix 09-01-19.05 - TONI 2009-01-21 2:56:01.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.3082.18.3327.2310 [GMT 1:00] Running from: c:\users\TONI\Downloads\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Confidencialidad.ur l c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Desinstalar.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\MessengerSkinner.ln k c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Términos y condiciones.url c:\programdata\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Website.url c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Confidencialidad.url c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Desinstalar.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Términos y condiciones.url c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\WebMediaPlayer.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\WebMediaPlayer\Website.url c:\users\TONI\AppData\Local\ceykg.dat c:\users\TONI\AppData\Local\ceykg.exe c:\users\TONI\AppData\Local\ceykg_nav.dat c:\users\TONI\AppData\Local\ceykg_navps.dat c:\users\TONI\AppData\Roaming\WeatherDPA c:\users\TONI\AppData\Roaming\WeatherDPA\Weather\S earchWeather.xml c:\users\TONI\AppData\Roaming\WeatherDPA\Weather\W eatherStartup.xml c:\users\TONI\AppData\Roaming\Zango . ((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 ))))))))))))))))))))))))))))))) . 2009-01-21 01:13 . 2009-01-21 01:13 <DIR> d-------- c:\users\TONI\AppData\Roaming\Malwarebytes 2009-01-21 01:13 . 2009-01-21 01:13 <DIR> d-------- c:\users\All Users\Malwarebytes 2009-01-21 01:13 . 2009-01-21 01:13 <DIR> d-------- c:\programdata\Malwarebytes 2009-01-21 01:13 . 2009-01-21 01:13 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2009-01-21 01:13 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys 2009-01-21 01:13 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys 2009-01-21 01:05 . 2009-01-21 01:05 <DIR> d-------- c:\program files\CCleaner 2009-01-19 15:00 . 2009-01-19 15:00 <DIR> d-------- c:\program files\Trend Micro 2009-01-14 07:48 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys 2009-01-10 19:47 . 2009-01-21 02:53 <DIR> d-------- c:\users\TONI\Tracing 2009-01-10 19:39 . 2009-01-10 19:39 <DIR> d-------- c:\program files\Microsoft Silverlight 2009-01-10 19:38 . 2009-01-10 19:38 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition 2009-01-10 19:38 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll 2009-01-10 19:36 . 2009-01-10 19:36 <DIR> d-------- c:\program files\Windows Live SkyDrive 2009-01-10 19:36 . 2009-01-10 19:36 <DIR> d-------- c:\program files\Microsoft 2009-01-10 19:15 . 2009-01-10 19:15 <DIR> d-------- c:\program files\Common Files\Windows Live 2008-12-22 16:18 . 2008-12-22 16:18 107,272 --a------ c:\windows\System32\drivers\avgtdix.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2009-01-16 14:27 --------- d-----w c:\program files\Common Files\Adobe 2009-01-16 13:44 --------- d-----w c:\programdata\UDL 2009-01-16 13:43 --------- d--h--w c:\program files\InstallShield Installation Information 2009-01-16 13:43 --------- d-----w c:\program files\EPSON 2009-01-16 10:18 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys 2009-01-15 00:42 --------- d-----w c:\programdata\Microsoft Help 2009-01-15 00:42 --------- d-----w c:\program files\Windows Mail 2009-01-10 18:39 --------- d-----w c:\program files\Windows Live 2008-12-22 15:18 10,520 ----a-w c:\windows\System32\avgrsstx.dll 2008-12-22 15:18 --------- d-----w c:\programdata\avg8 2008-12-18 18:46 --------- d-----w c:\program files\Driver Checker 2008-12-18 14:19 --------- d-----w c:\program files\Fujitsu Siemens Computers 2008-12-18 14:19 --------- d-----w c:\program files\Common Files\Fujitsu Siemens Computers 2008-12-15 19:57 --------- d-----w c:\programdata\Apple Computer 2008-12-15 19:57 --------- d-----w c:\programdata\Apple 2008-12-15 19:57 --------- d-----w c:\program files\Common Files\Apple 2008-12-15 19:57 --------- d-----w c:\program files\Apple Software Update 2008-12-14 10:51 410,984 ----a-w c:\windows\System32\deploytk.dll 2008-12-14 10:51 --------- d-----w c:\program files\Java 2008-12-05 14:41 --------- d-----w c:\programdata\Grisoft 2008-12-05 11:42 --------- d-----w c:\program files\VirtualDJ 2008-12-04 23:04 308,584 ----a-w c:\windows\WLXPGSS.SCR 2008-12-04 19:20 --------- d-----w c:\program files\MemoriesOnTV3 2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll 2008-11-30 11:31 --------- d-----w c:\programdata\EPSON 2008-11-28 13:02 --------- d-----w c:\programdata\eMule 2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll 2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll 2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll 2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll 2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll 2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll 2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll 2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe 2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll 2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll 2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll 2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll 2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini 2008-08-19 16:49 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\L ocal\Microsoft\Windows\History\History.IE5\MSHist0 12008081920080820\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920] "recinfo"="c:\recinfo\recinfo.exe" [2008-02-13 52224] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2008-12-02 3882312] "EPSON Stylus DX5000 Series"="c:\windows\system32\spool\DRIVERS\W32X86\ 3\E_FATIBVE.EXE" [2006-09-22 139264] "WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 c:\windows\System32\oobefldr.dll] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-05 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8530464] "NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2007-12-05 81920] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-22 1601304] "WireLessMouse"="c:\program files\Office Mouse Driver\StartAutorun.exe" [2005-11-30 94208] "QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTTask.exe" [2008-09-06 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "RtHDVCpl"="RtHDVCpl.exe" [2008-05-07 c:\windows\RtHDVCpl.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run] "fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 511248] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=G [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.tscc"= c:\progra~1\MpcStar\Codecs\tscc\tsccvid.dll [HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules] "TCP Query User{2547E168-7007-4899-9281-0D3626253E5C}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule "UDP Query User{8A0F7D46-7F58-4D95-AB33-13D1371B5E50}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule "TCP Query User{687F833B-2AB1-464C-BDE0-21CD61551C74}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "UDP Query User{85894427-60DF-4EBC-84DC-EFB397FB2E85}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer "TCP Query User{E786C75C-8703-4040-A78A-A730F0BF844E}c:\\users\\toni\\appdata\\local\\temp \\onlineupdate8\\setupxu.exe"= UDP:c:\users\toni\appdata\local\temp\onlineupdate8 \setupxu.exe:setupxu.exe "UDP Query User{9D21C97F-A0D7-4183-96DD-5FB0202FF867}c:\\users\\toni\\appdata\\local\\temp \\onlineupdate8\\setupxu.exe"= TCP:c:\users\toni\appdata\local\temp\onlineupdate8 \setupxu.exe:setupxu.exe "{ECC163EB-ABB4-4FD4-87B6-8C60F99FFFF9}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{2EEA1035-57E7-4975-8754-B19A35B00955}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{DAF561EE-E472-4559-AE9C-019C54A13158}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{A5C39F36-FEC2-4B0A-919D-A5D1B5AAFD34}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{A9AD146A-6517-4CBB-BBC0-81765BBD8626}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{318CC5EB-8A33-416B-8C17-FECB9AD72FBA}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe "TCP Query User{B306507C-BA99-4ABE-9FBE-8B02E0C27356}c:\\program files\\lphant\\elephantclient.exe"= UDP:c:\program files\lphant\elephantclient.exe:lphant Client "UDP Query User{5E56892A-B706-4234-9376-D1F199FDAB8D}c:\\program files\\lphant\\elephantclient.exe"= TCP:c:\program files\lphant\elephantclient.exe:lphant Client "{5A701D51-3654-4AC0-A1FB-152A14B67EC8}"= UDP:85:emule "{12D6E00D-E88C-4423-9361-60AF9DE1E554}"= TCP:1985:emule "TCP Query User{934651FF-50B4-4720-86EB-467E31BFBB4C}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= UDP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPl ayer "UDP Query User{E9DDF2DD-B357-4291-B92E-0F6A6B317403}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= TCP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPl ayer "{75162309-B6BE-4338-A087-CED58C663EC8}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server "{4DF3A9F3-4199-435C-A372-1195921BE894}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server "TCP Query User{259A8E6C-2F44-486F-AD65-1D30B6B3C4D5}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox "UDP Query User{06827337-2391-47D1-8F14-E5F47E5E20C7}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox "{AE3834D2-BC9E-46F4-AB54-100607D9D1D9}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe "TCP Query User{2CD2ABB9-005F-43A2-B116-3665DF3E56D1}m:\\juegos\\fm.exe"= UDP:m:\juegos\fm.exe:Football Manager 2008 "UDP Query User{3675DC3F-8EC9-480B-8420-F0CEF040FC7A}m:\\juegos\\fm.exe"= TCP:m:\juegos\fm.exe:Football Manager 2008 "{ACDA6DFA-CEEE-4C70-9302-A10E257A59EA}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2008-09-04 325128] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2008-12-22 107272] R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-09-04 298264] [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{6dd6e4ec-6e58-11dd-a409-806e6f6e6963}] \shell\AutoRun\command - g:\adobe_photoshop_elements\Setup.exe . - - - - ORPHANS REMOVED - - - - HKCU-Run-ceykg - c:\users\toni\appdata\local\ceykg.exe . ------- Supplementary Scan ------- . IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\TONI\AppData\Roaming\Mozilla\Firefox\Prof iles\gxd8x1x5.default\ FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector .dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin. dll FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin2 .dll FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin3 .dll FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin4 .dll FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin5 .dll FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260 .dll FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplu g.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true. ************************************************** ************************ catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-21 02:58:05 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ . Completion time: 2009-01-21 2:59:37 ComboFix-quarantined-files.txt 2009-01-21 01:59:35 Pre-Run: 131.867.238.400 bytes libres Post-Run: 131,833,282,560 bytes libres 193 --- E O F --- 2009-01-19 22:33:46 |
![]() | ![]() |
| ||||
| Re: Podrian analizar este log? Gracias Sube los siguientes archivos a virustotal y me colocas sus reportes: c:\programdata\fsc-reg\fscreg.exe c:\recinfo\recinfo.exe Linux User Registered #453948 Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Podrian analizar este log? Gracias Reporte de Virustotal del archivo recinfo.exe: Análisis del archivo recinfo.exe recibido el 21.01.2009 14:40:24 (CET) Motor antivirus Versión Última actualización Resultado a-squared 4.0.0.73 2009.01.21 - AhnLab-V3 5.0.0.2 2009.01.21 - AntiVir 7.9.0.57 2009.01.21 - Authentium 5.1.0.4 2009.01.20 - Avast 4.8.1281.0 2009.01.21 - AVG 8.0.0.229 2009.01.21 - BitDefender 7.2 2009.01.21 - CAT-QuickHeal 10.00 2009.01.20 - ClamAV 0.94.1 2009.01.21 - Comodo 940 2009.01.21 - DrWeb 4.44.0.09170 2009.01.21 - eSafe 7.0.17.0 2009.01.20 - eTrust-Vet 31.6.6319 2009.01.21 - F-Prot 4.4.4.56 2009.01.20 - F-Secure 8.0.14470.0 2009.01.21 - Fortinet 3.117.0.0 2009.01.15 - GData 19 2009.01.21 - Ikarus T3.1.1.45.0 2009.01.21 - K7AntiVirus 7.10.596 2009.01.20 - Kaspersky 7.0.0.125 2009.01.21 - McAfee 5501 2009.01.20 - McAfee+Artemis 5501 2009.01.20 - Microsoft 1.4205 2009.01.21 - NOD32 3785 2009.01.21 - Norman 5.93.01 2009.01.20 - nProtect 2009.1.8.0 2009.01.20 - Panda 9.5.1.2 2009.01.21 - PCTools 4.4.2.0 2009.01.21 - Rising 21.13.22.00 2009.01.21 - SecureWeb-Gateway 6.7.6 2009.01.21 - Sophos 4.37.0 2009.01.21 - Sunbelt 3.2.1835.2 2009.01.16 - Symantec 10 2009.01.21 - TheHacker 6.3.1.5.224 2009.01.20 - TrendMicro 8.700.0.1004 2009.01.20 - VBA32 3.12.8.10 2009.01.21 - ViRobot 2009.1.21.1572 2009.01.21 - VirusBuster 4.5.11.0 2009.01.20 - Información adicional Tamano archivo: 52224 bytes MD5...: fb94d196638a61c33b58c47149ce62a7 SHA1..: 07cb66d752d883f5230c7304b75f80813438c794 SHA256: e0e38853b9cf12f44685130ff3a4dfd600c5c1ba293654c1df 1983b134238db2 SHA512: 34e6a2ff09a9921993bc462ecb8792cf9afe7fe865d00a20b4 66cce7f826ac58<br>a59b47c996aaaf0a0d5a0a9c5ca825ab 75b4b0043c5bf5631619a8b01c2e89c2<br> ssdeep: 768:jBddHyP0ovc0n6+RKYYdFLbLSCTJd9VoHGEiBQBzt:lE/6uyFzSCTFVoHGEi<br>B<br> PEiD..: - TrID..: File type identification<br>Win64 Executable Generic (79.3%)<br>Win32 Executable Generic (7.9%)<br>Win32 Dynamic Link Library (generic) (7.0%)<br>Win16/32 Executable Delphi generic (1.9%)<br>Generic Win/DOS Executable (1.8%) PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x401000<br>timedatestamp.....: 0x47b2d861 (Wed Feb 13 11:45:37 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 6 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.code 0x1000 0x927 0xa00 4.98 de5c7cca303b817cfc64ce9062da4fa7<br>.text 0x2000 0xdfc 0xe00 6.25 a7cadac654f663f61dd275f79b5f19f4<br>.rdata 0x3000 0xb 0x200 0.19 5abc593b582acf97cc6a7763b503373c<br>.data 0x4000 0x6d24 0x6e00 5.64 3d19c4fe74907b55810537b11764a294<br>.rsrc 0xb000 0x3db0 0x3e00 6.13 eb61de1c791f5106ebb06d0dddb1333c<br>.flat 0xf000 0x3d 0x200 0.96 e97cd79fc0ad4d4895c5b1893493a844<br><br>( 7 imports ) <br>> CRTDLL.dll: memset, strncpy, strlen, strcat<br>> KERNEL32.dll: GetModuleHandleA, HeapCreate, CreateMutexA, GetLastError, GetUserDefaultUILanguage, HeapDestroy, ExitProcess, InitializeCriticalSection, GetCommandLineA, GetModuleFileNameA, HeapAlloc, MultiByteToWideChar, HeapFree, GetDriveTypeA, FindFirstFileA, FindClose, GetFileAttributesA, HeapReAlloc<br>> ntdll.dll: RtlWriteRegistryValue, RtlDeleteRegistryValue<br>> USER32.dll: CreateWindowExA, SetTimer, GetMessageA, TranslateMessage, DispatchMessageA, GetSystemMetrics, MoveWindow, ShowWindow, KillTimer, PostMessageA, DestroyWindow<br>> ATL.dll: AtlAxWinInit, AtlAxCreateControl, AtlAxGetControl<br>> OLE32.dll: CoInitialize, CoUninitialize<br>> SHLWAPI.dll: StrCatW, SHCreateMemStream, SHStrDupA<br><br>( 0 exports ) <br> Última edición por tonieme fecha: 21/01/09 a las 09:47:18. |
![]() | ![]() |
| ||||
| Re: Podrian analizar este log? Gracias Ese es el reporte del archivo recinfo.exe falta el reporte del archivo fscreg.exe Linux User Registered #453948 Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Podrian analizar este log? Gracias No encuentro este archivo.... |
![]() | ![]() |
| ||||
| Re: Podrian analizar este log? Gracias OK no hay problema.. El ultimo reporte de Combofix esta limpio por lo que al parecer ya todo esta bien ![]() Para terminar solo quedaría desinstalar CF de la siguiente manera:
Si no tienes mas problemas indícame para dar por solucionado el tema. Linux User Registered #453948 Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| otra vez con el mismo problema (eso creo) | elpana22 | Foro de Virus y Spywares | 11 | 19/01/09 19:59:12 |
| Me podeis analizar este log de Hijackthis? (solucionado) | krona | Temas Solucionados | 1 | 25/03/08 17:11:28 |
| Podrian revizar mi log x favor * pc muy lenta * Gracias (Solucionado) | Noni1018 | Temas Solucionados | 2 | 26/01/08 17:24:47 |
| Pueden analizar este log? (solucionado) | -:Marthe:- | Temas Solucionados | 8 | 15/12/07 18:28:52 |
| ayuda con este LOG por favor, gracias (Solucionado) | demonioxxx | Temas Solucionados | 2 | 19/03/07 13:13:29 |