resulta que parece ser que estoy contaminadisimo de virus o yo que se.
El ordenador me va lento de hace semanas y el avast me comenta constantemente de mover al bahul virus como accion recomendada.
Normalmente uso discos extraibles tanto duros como mecheros de datos.
Uno de los virus que mas sale es el ckvoo y leyendo en un post vi que a traves de msconfig lo podia desactivar.
Luego en un post vuestro relacionado con el ckvo vi que podia utiliar el elistara y el elipen y los he pasado y en el reporte me ponia esto:
Thu Sep 18 11:04:44 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Detectado E:\Autorun.inf
OPEN=1U0O8BNQ.CMD
Thu Sep 18 11:04:55 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Detectado E:\Autorun.inf
OPEN=1U0O8BNQ.CMD
E:\Autorun.inf -> Renombrado a .OLD
Thu Sep 18 11:06:44 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Detectado C:\Autorun.inf
OPEN=PH.COM
C:\Autorun.inf -> Renombrado a .OLD
Unidad C:\ Protegida
Unidad C:\ YA esta Protegida
Error Creando TEST2.SAT
Unidad D:\ No se Pudo Proteger
Error Creando TEST2.SAT
Unidad D:\ No se Pudo Proteger
Thu Sep 18 11:07:08 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Error Creando TEST2.SAT
Unidad D:\ No se Pudo Proteger
Thu Sep 18 11:07:43 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Error Creando TEST2.SAT
Unidad D:\ No se Pudo Proteger
Thu Sep 18 17:20:28 2008
EliStartPage v16.98 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 17 de Septiembre del 2008)
--------------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\ALCMTR.EXE --> Eliminado SpyRealtek
Entrada Eliminada [HKLM\...\Run] "Alcmtr"="ALCMTR.EXE"
Eliminada Class, "{21FFB6C0-0DA1-11D5-A9D5-00500413153C}" -> NULL1
Thu Sep 18 17:24:40 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Detectado F:\Autorun.inf
OPEN=1U0O8BNQ.CMD
F:\Autorun.inf -> Renombrado a .OLD
Unidad F:\ Protegida
Thu Sep 18 17:25:20 2008
EliStartPage v16.98 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 17 de Septiembre del 2008)
--------------------------------------------------
Lista de Acciones (por Acción Directa):
Restaurada Clave: "SafeBoot\Minimal y Network"
No detectado SP3 de Windows XP
Thu Sep 18 17:25:56 2008
EliPen v1.8 (c)2008 S.G.H. / Satinfo S.L.
------------------------------------------
Unidad F:\ YA esta Protegida
Unidad F:\ YA esta Protegida
Como puse el reporte en un mensaje que no era el mio pues me comentasteis que:
Pero ya nos puedes ir enviando estos ficheros para analizar, y renombras su extension a .VIR para que no puedan ejecutarse:
C:\ph.com
F:\1U0O8BNQ.CMD
Lo cierto es he mirado en msconfig y vuelve a estar activado el ckvo y los archivos que mencionais no los veo por ningun lado. Tengo quitadas las pestañas de omitir extensiones y ocultar archivos.
Entre los virus que veo y me avisa el avast estan el :
win32:beable-AAW
y otro que pone Root:32
otro: c:\windows\system32\drivers\srosa.sys
otro: c:\windows\system32\drivers\212703.exe
MIrando en el la lista de avast esta esto:
Código: Seleccionar todo
16/07/2008 16:48:13 TENTENPIE 1316 Sign of "Win32:Adan-156 [Adw]" has been found in "c:\archivos de programa\divx\divx pro codec\gain_trickler_3102.exe" file.
16/07/2008 17:00:57 SYSTEM 484 Sign of "Win32:Horst-AAF [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\Adobe Flash CS3 Professional [esp]\Keygen.exe" file.
29/07/2008 10:43:04 SYSTEM 1988 Sign of "Win32:Trojan-gen {Other}" has been found in "Correo entrante '18 is not young :)' De: "Ellen" <tempenquiries@prospect-us.co.uk>, Para: <ccounting@culturadenia.com>\photo#1278645409\photo.scr" file.
08/08/2008 12:12:04 TENTENPIE 1988 Sign of "Win32:Agent-AAZG [Rtk]" has been found in "C:\Archivos de programa\eMule\Incoming\character studio 3ds max 6 crack.zip\24_gui_2.exe" file.
08/08/2008 12:13:18 TENTENPIE 1988 Sign of "Win32:Agent-AAZG [Rtk]" has been found in "C:\Archivos de programa\eMule\Incoming\character studio 3ds max 6 crack(osloskop.net).zip\24_gui_1.exe" file.
08/08/2008 12:14:02 TENTENPIE 1988 Sign of "Win32:Agent-AAZG [Rtk]" has been found in "C:\Archivos de programa\eMule\Incoming\character studio 3ds max 6 multilanguage.zip\24_gui_3.exe" file.
08/08/2008 12:14:11 TENTENPIE 1988 Sign of "Win32:Agent-AAZG [Rtk]" has been found in "C:\Archivos de programa\eMule\Incoming\character studio 3ds max 6 multilanguage\24_gui_3.exe" file.
08/08/2008 12:14:43 TENTENPIE 1988 Sign of "Win32:Agent-AAZG [Rtk]" has been found in "C:\Archivos de programa\eMule\Incoming\character studio 3ds max 6 multilanguage\24_gui_3.exe" file.
28/08/2008 15:19:03 SYSTEM 1548 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\SYSTEM32\CKVO0.DLL" file.
30/08/2008 12:28:04 SYSTEM 1516 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
01/09/2008 9:24:04 SYSTEM 1504 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
01/09/2008 19:49:15 SYSTEM 1556 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
01/09/2008 19:58:11 SYSTEM 1556 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
01/09/2008 23:24:36 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
02/09/2008 9:09:55 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
02/09/2008 11:29:00 SYSTEM 1460 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
03/09/2008 9:37:42 SYSTEM 1348 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
05/09/2008 10:46:23 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
05/09/2008 16:01:27 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
06/09/2008 13:19:11 SYSTEM 1524 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
09/09/2008 17:09:09 TENTENPIE 1532 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\TENTENPIE\Mis documentos\curro\acelobert\def sept\SEC 2-5\ACOPLAR.max (C:\Documents and Settings\TENTENPIE\Mis documentos\curro\acelobert\def sept\SEC 2-5\ACOPLAR.max) returning error, 00000005.
10/09/2008 0:37:33 SYSTEM 1552 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
10/09/2008 13:23:51 SYSTEM 1552 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
11/09/2008 13:45:58 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
11/09/2008 18:09:07 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
12/09/2008 0:48:15 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
12/09/2008 1:35:25 SYSTEM 1452 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
12/09/2008 9:39:53 SYSTEM 1448 Sign of "Win32:Trojan-gen {Other}" has been found in "F:\c9hehpa.bat" file.
12/09/2008 13:07:12 SYSTEM 1448 Sign of "Win32:Trojan-gen {Other}" has been found in "E:\c9hehpa.bat" file.
15/09/2008 12:19:58 SYSTEM 1960 Sign of "Win32:Monga [Trj]" has been found in "C:\WINDOWS\SYSTEM32\CKVO0.DLL" file.
15/09/2008 12:28:30 TENTENPIE 2536 Sign of "Win32:Monga [Trj]" has been found in "c:\ph.com" file.
15/09/2008 15:10:35 SYSTEM 1960 Sign of "Win32:Monga [Trj]" has been found in "E:\c9hehpa.bat" file.
15/09/2008 17:38:48 SYSTEM 1960 Sign of "Win32:Monga [Trj]" has been found in "C:\WINDOWS\SYSTEM32\CKVO0.DLL" file.
17/09/2008 8:56:47 SYSTEM 2020 Sign of "SWF:CVE-2007-0071 [Expl]" has been found in "http://pagead2.googlesyndication.com/pagead/imgad?id=CMW5tPuLk4v_zAEQ2AUYWjIIZqDbE4-somI" file.
17/09/2008 14:26:25 TENTENPIE 2064 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "f:\1u0o8bnq.cmd" file.
17/09/2008 20:33:17 TENTENPIE 3908 Sign of "Win32:Bifrose-CIQ [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Temp\WER8584.dir00\3dsmax.exe.hdmp" file.
17/09/2008 21:05:06 TENTENPIE 1192 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Archivos de programa\eMule\Incoming\LipSync_MX_2.0.3_[With_Crack](2).zip\LipSync_MX_2.0.3_[With_Crack].exe" file.
18/09/2008 10:36:59 TENTENPIE 1808 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
18/09/2008 10:37:22 TENTENPIE 1808 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\2008078.exe" file.
18/09/2008 10:40:30 TENTENPIE 1668 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
18/09/2008 10:45:54 TENTENPIE 1668 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\drivers\downld\400437.exe" file.
18/09/2008 10:46:34 TENTENPIE 1668 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\441109.exe" file.
18/09/2008 11:01:18 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\4D63KTI3\ELISTARA.BG%D8IB%D8%D8H[1].EXE\[UPX]" file.
18/09/2008 11:02:07 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 11:02:45 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\4D63KTI3\ELISTARA.BG%D8IB%D8%D8H[1].EXE\[UPX]" file.
18/09/2008 11:02:48 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 11:03:20 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 14:18:27 TENTENPIE 2616 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\4D63KTI3\b64_3[1].jpg" file.
18/09/2008 14:48:21 TENTENPIE 1668 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\drivers\downld\14947625.exe" file.
18/09/2008 14:53:26 TENTENPIE 2616 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\8DQ3SX6N\b64_3[1].jpg" file.
18/09/2008 14:53:36 TENTENPIE 1668 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\15260781.exe" file.
18/09/2008 14:53:54 TENTENPIE 2616 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\KP2FGXAR\b64_2[1].jpg" file.
18/09/2008 14:54:02 TENTENPIE 2616 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\OXM7C5IB\b64_2[1].jpg" file.
18/09/2008 15:05:54 TENTENPIE 2616 Sign of "Win32:Bifrose-CIQ [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Temp\WER8584.dir00\3dsmax.exe.hdmp" file.
18/09/2008 16:21:18 TENTENPIE 2616 Sign of "Win32:Downloader-BJP [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\curro\acelobert\7agost\recursos mov\Download 3d max bvh Faster with BitTorrent downloader.zip\BitTorrent_Downloader_1307_MS_DW_0299.EXE\%MAINDIR%\DWbrk01.exe" file.
18/09/2008 17:17:44 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 17:18:10 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\4PMBSLUZ\ELISTARA.BG%D8IB%D8%D8H[1].EXE\[UPX]" file.
18/09/2008 17:18:55 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 17:20:54 TENTENPIE 1668 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
18/09/2008 19:31:06 TENTENPIE 2616 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\plugins 3d\CAT Character Animation Toolkit v1.151 for 3DSMAX v6 x-PARADOX by efish.rar\paradox.exe" file.
19/09/2008 8:38:02 TENTENPIE 1572 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 8:38:19 TENTENPIE 1572 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\drivers\downld\75171.exe" file.
19/09/2008 8:38:37 TENTENPIE 1572 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\93609.exe" file.
19/09/2008 8:38:46 TENTENPIE 1572 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\drivers\downld\104250.exe" file.
19/09/2008 11:15:15 TENTENPIE 1664 Sign of "Win32:Beagle-AGB [Wrm]" has been found in "C:\WINDOWS\system32\wintems.exe" file.
19/09/2008 11:15:40 TENTENPIE 1664 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 11:18:08 TENTENPIE 1664 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\drivers\downld\253734.exe" file.
19/09/2008 11:18:26 TENTENPIE 1664 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\272328.exe" file.
19/09/2008 11:18:56 TENTENPIE 1664 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\drivers\downld\301453.exe" file.
19/09/2008 11:25:47 TENTENPIE 1656 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 11:26:29 TENTENPIE 1656 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\136140.exe" file.
19/09/2008 11:42:22 TENTENPIE 1652 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 11:43:17 TENTENPIE 1652 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\drivers\downld\137500.exe" file.
19/09/2008 11:43:32 TENTENPIE 1652 Sign of "Win32:Beagle-AGI [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\154453.exe" file.
19/09/2008 12:23:59 TENTENPIE 1664 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 12:24:33 TENTENPIE 1664 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\Documents and Settings\TENTENPIE\Configuración local\Archivos temporales de Internet\Content.IE5\KP2FGXAR\b64_3[1].jpg" file.
19/09/2008 12:24:39 TENTENPIE 1664 Sign of "Win32:Beagle-AFX [Wrm]" has been found in "C:\WINDOWS\system32\drivers\downld\146140.exe" file.
19/09/2008 12:24:45 TENTENPIE 1664 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\drivers\downld\156812.exe" file.
19/09/2008 12:46:10 TENTENPIE 1664 Sign of "Win32:Small-CPR [Trj]" has been found in "C:\Documents and Settings\TENTENPIE\Mis documentos\progs\antiviurs\ELISTARA.BGIBH.EXE\[UPX]" file.
19/09/2008 14:36:53 TENTENPIE 1644 Sign of "Win32:Beagle-AAW [Trj]" has been found in "C:\WINDOWS\system32\drivers\srosa.sys" file.
19/09/2008 14:38:43 TENTENPIE 1644 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\WINDOWS\system32\drivers\downld\212703.exe" file.
Y una ultima cosa el programita elistara desaparece de la carpeta donde esta ya que me parece que el avast lo reconoce como virus.
¿Hay algun modo de limpiar todo el ordenador y los discos duros?