A primera vista, estan usando el I.E. 6 ya obsoleto y sin actualizaciones de seguridad, y sistema operativo XP SIN NINGUN PARCHE !!!
Sistema Operativo: Microsoft Windows XP (v5.1.2600)
Internet Explorer: (v6.0.2600.0000)
De entrada esto es como conducir sin frenos... Abran el I,E., vayan a Herramientas y lancen un windowsupdate. Piensen que del SP2 al SP3 hay 1073 parches, y Vds parece que no tienen ni el SP1 ni el SP2...
Y ya entrando en el HOSTS ! saben lo que tienen allí dentro ??? es voluntario ??? Aparte de las cientos de lineas que descartamos por ser tipicas del SPYBOT, tienen todas estas redirecciones que solo Dios (y quizas Vds) saben porqué las han puesto:
Código: Seleccionar todo
O1 - Hosts: 202.165.102.205 972.aksjd11.com
O1 - Hosts: 202.165.102.205 w3og.cn
O1 - Hosts: 203.208.35.100 qazc.fourtw.cn
O1 - Hosts: 203.208.35.100 http://www.aujoy.cn
O1 - Hosts: 203.208.35.101 http://www.hao601.cn
O1 - Hosts: 203.208.35.101 http://www.psp476.cn
O1 - Hosts: 72.14.235.99 222.1212l112.net
O1 - Hosts: 72.14.235.99 444.1212l112.netn
O1 - Hosts: 72.14.235.99 555.1212l112.net
O1 - Hosts: 72.14.235.99 111.1212l112.net
O1 - Hosts: 65.55.21.250 111.3243l24.com
O1 - Hosts: 65.55.21.250 222.3243l24.com
O1 - Hosts: 65.55.21.250 333.3243l24.com
O1 - Hosts: 125.64.8.112 kao2.gmwo03.com
O1 - Hosts: 125.64.8.112 kao.gmwo06.com
O1 - Hosts: 125.64.8.112 444.gmwo07.com
O1 - Hosts: 116.252.185.15 ru.update365.us
O1 - Hosts: 116.252.185.15 ad.update365.us
O1 - Hosts: 207.46.232.182 popmails.net
O1 - Hosts: 203.208.37.99 3.goodhh.com
O1 - Hosts: 220.181.37.55 down.rwixr.com
O1 - Hosts: 160.79.42.52 http://www.xdj2008.com
O1 - Hosts: 63.175.76.152 http://www.revtr.cn
O1 - Hosts: 219.133.40.91 qq.ljsll.com
O1 - Hosts: 203.208.35.102 http://www.aassccwe.cn
O1 - Hosts: 209.132.177.50 973.aksjd11.com
O1 - Hosts: 209.132.177.50 974.aksjd11.com
O1 - Hosts: 209.132.177.50 971.aksjd11.com
O1 - Hosts: 209.132.177.50 975.aksjd11.com
O1 - Hosts: 72.14.235.104 user1.12-39.net
O1 - Hosts: 72.14.235.147 http://www.infomt.net
O1 - Hosts: 192.150.18.101 ata1.sysions.net
O1 - Hosts: 192.150.18.101 ata2.sysions.net
O1 - Hosts: 192.150.18.101 ata3.sysions.net
O1 - Hosts: 192.150.18.101 ata4.sysions.net
O1 - Hosts: 193.120.42.226 8nnnnn99.cn
O1 - Hosts: 24.39.54.34 http://www.haoaoao.cn
No habiamos visto nunca un ordenador con tantas redirecciones, aunque si son voluntarias, nada que decir, pero dudo que asi sea !
Las que no conozcan, eliminenlas !!!
Sigamos, esta clave:
O2 - BHO: (no name) - {18093456-9012-4568-9076-908765467181} - (no file) => procede eliminarla, procede de un troyano eliminado.
O2 - BHO: (no name) - {4A698102-5904-AFD0-20DF-CD1A65829CA4} - C:\WINDOWS\System32\zycbdime.dll (file missing) => es otra clave maliciosa, aunque quizás ya se haya borrado el fichero que lanza, en cualquier caso eliminarla, pues podría estar con atributos que no permitieran verlo... procede eliminarla tambien!
O2 - BHO: (no name) - {55694105-5108-9405-3695-954187462155} - C:\WINDOWS\System32\mpwdeapi.dll => envienos el fichero quye lanza para analizar y pasar a controlar con nuestras utilidades si aun no lo detectamos: C:\WINDOWS\System32\mpwdeapi.dll procede eliminarla tambien !
O2 - BHO: IncePrivate Class - {686488AF-13D5-9DDF-4FEF-9FB88698CFC1} - C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\SgwZeghvvV.dll => es desconocida y sospechosa al no haber ninguna referencia del fichero que lanza, enviennoslo para analizar: C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\SgwZeghvvV.dll
O2 - BHO: (no name) - {6C648541-1025-9650-9057-6541258720C6} - C:\WINDOWS\System32\mndhfdwd.dll (file missing) => Eliminala son restos del anterior
O2 - BHO: (no name) - {7A041F13-A111-12A3-B0CF-F99818AA68A7} - C:\WINDOWS\System32\zxmsdwin.dll (file missing) => Eliminala son restos del anterior
O2 - BHO: (no name) - {87FD640A-158F-48AC-FD14-1597F14A9778} - C:\WINDOWS\System32\mndshsrv.dll (file missing) => Eliminala son restos del anterior
Y la siguiente clave, peligrosa y está activa:
O2 - BHO: ThunderHlpObj Class - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll => debe eliminarse !!!
O2 - BHO: (no name) - {AA59145F-315D-BC23-AC1F-145DF81A34AA} - C:\WINDOWS\System32\zyzxjime.dll (file missing) => Eliminala
O2 - BHO: (no name) - {B629FF4F-ACDB-5C90-A098-FACB3456A26B} - (no file) => Eliminala
O4 - HKLM\..\Run: [winlog] C:\WINDOWS\Fonts\winlog.exe => Eliminala
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main => Eliminala
Esta es desconocida y sospechosa:
O4 - HKLM\..\RunOnce: [vuyhnwk61] %systemroot%\system32\Rundll32.exe %systemroot%\system32\vuyhnwk61.dll,DllUnregisterServer
No hay referencias del fichero, asi que enviennoslo para analizar
De todas formas, al ser una RUN ONCE, desaparece en el sguiente reinicio, posiblemente la instale algun congenere...
Esta eliminenla directamente: O9 - Extra button: ֪ʶ¿â - {06926B30-424E-4f1c-8EE3-543CD96573DC} - http://blank.la/?h (file missing)
y esta es de lo lindo :
O20 - AppInit_DLLs: NTNJXSJTVC.dll longasus.dll momusi.dll joasus.dll joliom.dll,tisqdtyu.dll,nhmxejkl.dll googleons.dll welycz.dll fackwir.dll pcibexl.dll cbplus.dll caotxb.dll ezcron.dll wcomipe.dll comremo.dll jsnoer.dll ceshleo.dll myasemt.dll mssetd.dll tiplict.dll businesn.dll wcnonpe.dll keyiftp.dll esceps.dll instok.dll baccops.dll aliens.dll offecao.dll cmonos.dll wdhotem.dll xpsbos.dll rmbsony.dll manleu.dll therbrek.dll jolin0.dll offscrl.dll squalle.dll crtnumo.dll tennfs.dll
no solo hay que eliminarla, sino eliminar tambien todas las DLL relacionadas con dicha clave !
y estas dos tambien eliminarlas, ya se hablaba del primer fichero anteriormente:
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O21 - SSODL: DesktopWin - {DA191DE0-AA86-4ED0-4B87-292A3D48BE99} - C:\WINDOWS\AppPatch\DesktopWin.dll (file missing)
y de la última ver :http://www.greatis.com/appdata/d/Windows/a/apppatch_desktopwin.dll.htm
asi que eliminar las dos !
y llegamos al monton de claves maliciosas que se deben haber creado en los reinicios, y deben eliminarse todas:
ShellExecuteHooks: {6319A1F1-9410-9654-3201-345FFA349136} - zywmfime.dll - (no file)
ShellExecuteHooks: {83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38} - yxfhcjpg.dll - (no file)
ShellExecuteHooks: {4FD45A54-9875-698F-E56E-65102358FDF4} - apsgdjba.dll - (no file)
ShellExecuteHooks: {CAED0F3B-DF8B-4DBF-BB20-8DFBC3199068} - - C:\WINDOWS\System32\jhrcar.dll (file missing)
ShellExecuteHooks: {4A069845-2036-6084-9054-6087502480A4} - ozfydbyt.dll - (no file)
ShellExecuteHooks: {6C8D1401-A58D-A81C-CD24-A5915C4517C6} - mnmhfsrv.dll - (no file)
ShellExecuteHooks: {33512378-9874-5641-1025-985420368733} - oswxcttb.dll - (no file)
ShellExecuteHooks: {8490415F-65F8-B5C5-D8BA-9405FB120548} - yzzthmsn.dll - (no file)
ShellExecuteHooks: {35671234-7890-ABCD-CDEF-567801237653} - yxcschlp.dll - (no file)
ShellExecuteHooks: {27AC9076-C898-B098-D098-A18319080972} - nhmxbjkl.dll - (no file)
ShellExecuteHooks: {32023698-6984-8541-9654-698745012523} - skqncbib.dll - (no file)
ShellExecuteHooks: {50940F85-F015-14F1-A05F-F69858AC6D05} - zptlcsys.dll - (no file)
ShellExecuteHooks: {81954FAC-1023-154F-895A-1458258AD818} - ypdjfbmp.dll - (no file)
ShellExecuteHooks: {7C8D1401-A58D-A81C-CD24-A5915C4517C7} - mnmhgsrv.dll - (no file)
ShellExecuteHooks: {13FD5987-65D2-C58D-D87E-987451F12531} - swsxachu.dll - (no file)
ShellExecuteHooks: {22596546-2036-9451-6058-658402589722} - opshbbty.dll - (no file)
ShellExecuteHooks: {91698482-6555-3666-1222-954784129019} - zxptejpg.dll - (no file)
ShellExecuteHooks: {1DB3C525-5271-46F7-887A-D4E1ADAA7632} - - C:\WINDOWS\System32\hfrdzx.dll (file missing)
ShellExecuteHooks: {45AADFAA-DD36-42AB-83AD-0521BBF58C24} - - C:\WINDOWS\System32\zycdex.dll (file missing)
ShellExecuteHooks: {4A698102-5904-AFD0-20DF-CD1A65829CA4} - zycbdime.dll - C:\WINDOWS\System32\zycbdime.dll (file missing)
ShellExecuteHooks: {18093456-9012-4568-9076-908765467181} - tisqatyu.dll - (no file)
ShellExecuteHooks: {B490415F-65F8-B5C5-D8BA-9405FB12054B} - yzztkmsn.dll - (no file)
ShellExecuteHooks: {1A698452-C5D8-C584-C256-C264C987C5A1} - ijdyapaw.dll - (no file)
ShellExecuteHooks: {5D098345-6785-1098-5413-678067AE03D5} - tysqbkol.dll - (no file)
ShellExecuteHooks: {5A069845-2036-6084-9054-6087502480A5} - ozfyebyt.dll - (no file)
ShellExecuteHooks: {7C69034A-F45F-D34D-A33A-C33C4D324FC7} - arjreler.dll - (no file)
ShellExecuteHooks: {60A345CD-ABCD-EFAB-CDEF-ABCD01020306} - pqzfajke.dll - (no file)
ShellExecuteHooks: {37AC9076-C898-B098-D098-A18319080973} - nhmxcjkl.dll - (no file)
ShellExecuteHooks: {A629FF4F-ACDB-5C90-A098-FACB3456A26A} - s2da2f323.dll - (no file)
ShellExecuteHooks: {528DF602-9541-A985-210A-984A698C6F25} - ptjhehlp.dll - C:\WINDOWS\System32\ptjhehlp.dll (file missing)
ShellExecuteHooks: {87FD640A-158F-48AC-FD14-1597F14A9778} - mndshsrv.dll - C:\WINDOWS\System32\mndshsrv.dll (file missing)
ShellExecuteHooks: {4A908760-8000-4000-A000-9000322145A4} - akjsdkaq.dll - (no file)
ShellExecuteHooks: {2B69874A-C58C-458D-69F0-698F874E41B2} - lassaplo.dll - (no file)
ShellExecuteHooks: {54FAE856-AD58-20CB-A025-CD4895FA6E45} - pjjxedwd.dll - (no file)
ShellExecuteHooks: {3C954872-1230-6541-9548-6541025884C3} - lijzclit.dll - (no file)
ShellExecuteHooks: {43512378-9874-5641-1025-985420368734} - oswxdttb.dll - (no file)
ShellExecuteHooks: {20909876-4567-3908-4056-909834565102} - erxybloe.dll - (no file)
ShellExecuteHooks: {6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6} - oohxebyt.dll - (no file)
ShellExecuteHooks: {7FD45A54-9875-698F-E56E-65102358FDF7} - apsggjba.dll - C:\WINDOWS\System32\apsggjba.dll (file missing)
ShellExecuteHooks: {7A041F13-A111-12A3-B0CF-F99818AA68A7} - zxmsdwin.dll - C:\WINDOWS\System32\zxmsdwin.dll (file missing)
ShellExecuteHooks: {55694105-5108-9405-3695-954187462155} - mpwdeapi.dll - C:\WINDOWS\System32\mpwdeapi.dll
ShellExecuteHooks: {B629FF4F-ACDB-5C90-A098-FACB3456A26B} - hdf453d.dll - (no file)
ShellExecuteHooks: {80AF1289-F140-A140-D012-C1458759FC08} - ypcqghlp.dll - C:\WINDOWS\System32\ypcqghlp.dll (file missing)
ShellExecuteHooks: {AA59145F-315D-BC23-AC1F-145DF81A34AA} - zyzxjime.dll - C:\WINDOWS\System32\zyzxjime.dll (file missing)
ShellExecuteHooks: {2A698452-C5D8-C584-C256-C264C987C5A2} - ijdybpaw.dll - C:\WINDOWS\System32\ijdybpaw.dll (file missing)
ShellExecuteHooks: {6C648541-1025-9650-9057-6541258720C6} - mndhfdwd.dll - C:\WINDOWS\System32\mndhfdwd.dll (file missing)
ShellExecuteHooks: {20618412-C528-C784-C056-C164D1F7C502} - detxbiua.dll - (no file)
ShellExecuteHooks: {37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73} - zywlcime.dll - (no file)
ShellExecuteHooks: {52023698-6984-8541-9654-698745012525} - skqnebib.dll - (no file)
ShellExecuteHooks: {7319A1F1-9410-9654-3201-345FFA349137} - zywmgime.dll - (no file)
ShellExecuteHooks: {C490415F-65F8-B5C5-D8BA-9405FB12054C} - yzztlmsn.dll - (no file)
ShellExecuteHooks: {8C8D1401-A58D-A81C-CD24-A5915C4517C8} - mnmhhsrv.dll - C:\WINDOWS\System32\mnmhhsrv.dll (file missing)
ShellExecuteHooks: {470165F1-9F65-569F-F895-F14F58F41074} - lofsdjbo.dll - C:\WINDOWS\System32\lofsdjbo.dll (file missing)
ShellExecuteHooks: {8A041F13-A111-12A3-B0CF-F99818AA68A8} - zxmsewin.dll - C:\WINDOWS\System32\zxmsewin.dll (file missing)
ShellExecuteHooks: {45671234-7890-ABCD-CDEF-567801237654} - yxcsdhlp.dll - C:\WINDOWS\System32\yxcsdhlp.dll (file missing)
ShellExecuteHooks: {8C954872-1230-6541-9548-6541025884C8} - fd233ds4f4.dll - C:\WINDOWS\System32\fd233ds4f4.dll (file missing)
ShellExecuteHooks: {C629FF4F-ACDB-5C90-A098-FACB3456A26C} - hdf453d1.dll - C:\WINDOWS\System32\hdf453d1.dll (file missing)
ShellExecuteHooks: {60940F85-F015-14F1-A05F-F69858AC6D06} - zptldsys.dll - C:\WINDOWS\System32\zptldsys.dll (file missing)
ShellExecuteHooks: {25FD6584-698F-BCD2-602C-698745210352} - rijxbkin.dll - C:\WINDOWS\System32\rijxbkin.dll
ShellExecuteHooks: {14698742-2059-3025-9058-954023874141} - jkhxaklo.dll - C:\WINDOWS\System32\jkhxaklo.dll (file missing)
ShellExecuteHooks: {A1954FAC-1023-154F-895A-1458258AD81A} - ypdjhbmp.dll - C:\WINDOWS\System32\ypdjhbmp.dll (file missing)
ShellExecuteHooks: {9319A1F1-9410-9654-3201-345FFA349139} - zywmiime.dll - C:\WINDOWS\System32\zywmiime.dll (file missing)
ShellExecuteHooks: {50618412-C528-C784-C056-C164D1F7C505} - detxeiua.dll - C:\WINDOWS\System32\detxeiua.dll (file missing)
ShellExecuteHooks: {57AC9076-C898-B098-D098-A18319080975} - nhmxejkl.dll - C:\WINDOWS\System32\nhmxejkl.dll (file missing)
ShellExecuteHooks: {47A924AF-1A5F-CF21-AB1D-1D5CF82A8A74} - zywldime.dll - C:\WINDOWS\System32\zywldime.dll (file missing)
ShellExecuteHooks: {97FD640A-158F-48AC-FD14-1597F14A9779} - mndsisrv.dll - C:\WINDOWS\System32\mndsisrv.dll (file missing)
ShellExecuteHooks: {49109876-7619-9101-7012-901938475194} - ietzdpaq.dll - C:\WINDOWS\System32\ietzdpaq.dll (file missing)
ShellExecuteHooks: {6A908760-8000-4000-A000-9000322145A6} - akjsfkaq.dll - C:\WINDOWS\System32\akjsfkaq.dll (file missing)
ShellExecuteHooks: {48093456-9012-4568-9076-908765467184} - tisqdtyu.dll - C:\WINDOWS\System32\tisqdtyu.dll (file missing)
ShellExecuteHooks: {4D698451-2015-6358-9871-2015987452D4} - apzhdtde.dll - C:\WINDOWS\System32\apzhdtde.dll (file missing)
ShellExecuteHooks: {6A069845-2036-6084-9054-6087502480A6} - ozfyfbyt.dll - C:\WINDOWS\System32\ozfyfbyt.dll
ShellExecuteHooks: {8FD45A54-9875-698F-E56E-65102358FDF8} - apsghjba.dll - C:\WINDOWS\System32\apsghjba.dll (file missing)
ShellExecuteHooks: {EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6} - - C:\WINDOWS\System32\fsrgeb.dll (file missing)
ShellExecuteHooks: {53D44DB6-E22B-4B17-97D3-572C96CCA6E1} - - C:\WINDOWS\System32\zsdgff.dll
ShellExecuteHooks: {28766E1C-74B0-4417-8C75-F12AE309EF35} - - C:\WINDOWS\System32\wzcfsw.dll
ShellExecuteHooks: {A9895933-6636-4281-BC58-EE6DE2AF96E3} - - C:\WINDOWS\System32\ddserh.dll
ShellExecuteHooks: {6E6CA8A1-81BC-4707-A54C-F4903DD70BAD} - - C:\WINDOWS\System32\zgxfdx.dll (file missing)
ShellExecuteHooks: {8C41B7F7-3168-400D-A702-0E7EFE0BA304} - - C:\WINDOWS\System32\sgdewg.dll
ShellExecuteHooks: {7914E0AA-ECCB-4311-B584-C49538227824} - - C:\WINDOWS\System32\jhfrxz.dll (file missing)
ShellExecuteHooks: {0B846B26-BFE6-4E8E-A948-1DB17B77B483} - - C:\WINDOWS\System32\tdfhex.dll
ShellExecuteHooks: {73AE86E6-7F03-4C3B-8980-FB1DA157D3C7} - - C:\WINDOWS\System32\fmcvxy.dll (file missing)
ShellExecuteHooks: {17DFD111-BF3A-4CB4-ADB0-88FCBFE69821} - - C:\WINDOWS\System32\hhrdxd.dll (file missing)
ShellExecuteHooks: {84143967-B645-4BFF-B873-DA1DC886E9A7} - - C:\WINDOWS\System32\cedafb.dll (file missing)
ShellExecuteHooks: {461D2AB4-29A5-45C2-9134-D52272D3DE38} - - C:\WINDOWS\System32\rfdswc.dll (file missing)
ShellExecuteHooks: {841529CB-7F77-4B99-A895-B5441E0D302F} - - C:\WINDOWS\System32\jfrwdh.dll (file missing)
ShellExecuteHooks: {259BF3CF-194D-4FE6-9ADB-DE6544B098B6} - - C:\WINDOWS\System32\dndsaf.dll (file missing)
ShellExecuteHooks: {4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4} - - C:\WINDOWS\System32\tdggrz.dll (file missing)
asi pues todas las indicadas en este grupo, al bote !
y estas:
O23 - Service: NVIDIA Compatible Windows Miniport Driver (cdralw) - Unknown owner - C:\WINDOWS\SYSTEM32\DRIVERS\nvmini.sys (file missing)
O23 - Service: Centrr - Unknown owner - C:\WINDOWS\System32\tcpip.exe
O23 - Service: eth8023 - Unknown owner - C:\WINDOWS\system32\drivers\eth8023.sys
O23 - Service: Compartilhamento remoto da área de trabalho do NetMeeting
Unknown service. () (mnmsrvc) - Microsoft Corporation - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: RESSDT - Unknown owner - C:\WINDOWS\System32\ssdtti.sys (file missing)
O23 - Service: Secdrv - Unknown owner - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys
O23 - Service: SenFilt Service (SenFiltService) - Sensaura - C:\WINDOWS\SYSTEM32\drivers\Senfilt.sys
las analizare posteriormente, en mi proximo post.
Por cierto, hay al final una de Symantec, y no debe haber mas de un antivirus en cada ordenador, debe ser un resto de una instalacion antigua, eliminarla:
O23 - Service: LiveUpdate - Unknown owner - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
Para el envio de muestras y la eliminacion de claves, seguir estas indicaciones:
¿Como enviar las muestras a zonavirus? - Para ello recordar:
https://foros.zonavirus.com/viewtopic.php?f=5&t=14253
y si no se ven con el HJT, probar el BUSCAREG:
BuscaReg (SATINFO)
Busca una cadena dentro del registro de windows, una vez encontradas permite borrarlas con tan solo pinchar encima de cada entrada encontrada, ademas realiza la exportacion de las claves eliminadas por si se necesitan restaurar las claves borradas.
Descargar BuscaReg
luego termino,
saludos
ms, 4 de Agosto de 2008