me entro un troyano "agent.DPE", el cual me anulo el anitivirus y no me deja instalar ningun antivirus ( intente con el PANDA, BITDefender ). Al mismo lo detecte con el PANDA ON LINE, y lo elimina, pero vuelve aparecer.
Tambien pase el Elistar y Elitrip ( pego el informe ) que tambien lo detecto, y lo elimino, pero cada vez q vuelvo a pasar el PANDA ON LINE lo vuelve a detectar .
Espero q me puedan ayudar!!!
Muchas Gracias!!
Saludos
10-5-2009 06:01:43)
EliStartPage v18.57 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 8 de Mayo del 2009)
--------------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\ALCMTR.EXE --> Eliminado SpyRealtek
Entrada Eliminada [HKLM\...\Run] "Alcmtr"="ALCMTR.EXE"
Sospechosa Clave "HKLM\...\Image File Execution Options\a2service.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ArcaCheck.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\arcavir.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ashDisp.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ashEnhcd.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ashServ.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ashUpd.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\aswUpdSv.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\autoruns.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avadmin.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avcenter.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avcls.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avconfig.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avconsol.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avgnt.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avgrssvc.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avguard.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\AvMonitor.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avp.com"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avp.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\AVP32.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avscan.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avz.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avz4.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\avz_se.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\bdagent.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\bdinit.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\caav.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\caavguiscan.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\casecuritycenter.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\CCenter.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ccupdate.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\cfp.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\cfpupdat.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\cmdagent.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\drwadins.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\DRWEB32.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\drwebupw.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\ekrn.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\FAMEH32.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\filemon.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\FPAVServer.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\fpscan.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\FPWin.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\fsav32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\fsgk32st.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\FSMA32.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\GFRing3.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\guardgui.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\guardxservice.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\guardxup.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\HijackThis.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KASMain.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KASTask.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KAV32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KAVDX.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KAVPF.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KAVPFW.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KAVStart.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KPFW32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\KPFW32X.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Navapsvc.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Navapw32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\navigator.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\NAVNT.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\NAVSTUB.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\NAVW32.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\NAVWNT.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\niu.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\nod32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\nod32krn.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Nvcc.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\OllyDBG.EXE"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\outpost.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\preupd.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\procexp.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\pskdr.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\regedit.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\regmon.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\RegTool.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\scan32.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\SfFnUp.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Vba32arkit.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\vba32ldr.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\vsserv.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Zanda.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\zapro.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\Zlh.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\zonealarm.exe"
"Debugger"="NTSD -D"
Sospechosa Clave "HKLM\...\Image File Execution Options\zoneband.dll"
"Debugger"="NTSD -D"
Linea Eliminada del HOSTS --> 127.0.0.1 serial.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1
Linea Eliminada del HOSTS --> 127.0.0.1 images.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 trial.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 forum.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 support.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 users.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 shop.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 vodka.alcohol-soft.com
Linea Eliminada del HOSTS --> 127.0.0.1 alcohol-soft.com
No detectado SP3 de Windows XP
Eliminadas las Paginas de Inicio y de Busqueda del IE
Eliminados Ficheros Temporales del IE
(10-5-2009 06:02:23)
EliStartPage v18.57 (c)2009 S.G.H. / Satinfo S.L. (Actualizado el 8 de Mayo del 2009)
--------------------------------------------------
Lista de Acciones (por Exploración):
Explorando "C:\"
C:\Archivos de programa\Realtek\Audio\InstallShield\ALCMTR.EXE --> Eliminado, SpyRealtek
C:\WINDOWS\system32\CMDOW.EXE --> Eliminado, Tool-HideWindow
Nº Total de Directorios: 3438
Nº Total de Ficheros: 27264
Nº de Ficheros Analizados: 8250
Nº de Ficheros Infectados: 2
Nº de Ficheros Limpiados: 2