8) Hola Destroyer ya he actualisado el Ad-Ware perdona lo tenia que haber hecho antes he escaneado otra vez "aqui hay morralla" hechale un ojo ha ver que opinion te merece lo que aparece, aunque me acabo de dar cuenta que he estado conectado con el SpywareBlaster cerrado aunque dicen que que no es necesario el habrirlo para que haga su trabajo no se si esto que aparece es nuevo o tiene que ver algo con los DSO Exploit de los coj....... lo dejo tal como esta espero tu respuesta un saludo de
BluesPD Paso informe nuevo escaneoLavasoft Ad-aware Personal Build 6.181
Logfile creado:martes, 22 de junio de 2004 3:47:18
Created with Ad-aware Personal, free for private use.
Usando archivo de referencia:01R323 20.06.2004
______________________________________________________
Reffile status:
=========================
archivo de la referencia cargado:
Reference Number : 01R323 20.06.2004
Internal build : 255
File location : C:\ARCHIV~1\Lavasoft\AD-AWA~1\reflist.ref
Total size : 1263754 Bytes
Signature data size : 1243301 Bytes
Reference data size : 20389 Bytes
Signatures total : 27644
Target categories : 10
Target families : 505
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Non Intel
Memory available:48 %
Total physical memory:253424 kb
Available physical memory:120276 kb
Total page file size:620676 kb
Available on page file:437832 kb
Total virtual memory:2097024 kb
Available virtual memory:2055460 kb
OS:
Ad-aware Settings
=========================
Juego : Activar escaneo en profundidad
Juego : Modo seguro (siempre pide una confirmación)
Juego : Escanear procesos activos
Juego : Escanear registro
Juego : Escanear registro a fondo
Juego : Escanear Favorito de IE para los sitios prohibidos
Juego : Escanear dentro de los archivos
Juego : Scan my Hosts file
22-06-2004 3:47:18 - Scan started. (Custom mode)
Listando procesos activos
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 21-06-2004 21:21:21
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 21-06-2004 21:21:32
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 21-06-2004 21:21:33
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
Copyright : Copyright (C) Microsoft Corporation. Reservados todos los derechos.
CompanyName : Microsoft Corporation
FileDescription : Aplicaci
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Sistema operativo Microsoft
Created on : 24/08/2001 16:00:00
Last accessed : 22/06/2004 1:47:18
Last modified : 24/08/2001 16:00:00
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 21-06-2004 21:21:34
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 09/09/2002 17:51:32
Last accessed : 22/06/2004 1:47:18
Last modified : 09/09/2002 17:51:32
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 21-06-2004 21:21:38
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 24/08/2001 16:00:00
Last accessed : 22/06/2004 1:47:18
Last modified : 24/08/2001 16:00:00
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 21-06-2004 21:21:38
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 24/08/2001 16:00:00
Last accessed : 22/06/2004 1:47:18
Last modified : 24/08/2001 16:00:00
#:7 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 21-06-2004 21:21:40
BasePriority : Normal
FileSize : 983 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Explorador de Windows
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Sistema operativo Microsoft
Created on : 09/09/2002 17:51:28
Last accessed : 22/06/2004 1:47:18
Last modified : 09/09/2002 17:51:28
#:8 [ccsetmgr.exe]
FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\
ThreadCreationTime : 21-06-2004 21:21:40
BasePriority : Normal
FileSize : 229 KB
FileVersion : 2.0.0.635
ProductVersion : 2.0.0.635
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
OriginalFilename : ccSetMgr.exe
ProductName : Common Client
Created on : 19/08/2003 19:58:50
Last accessed : 22/06/2004 1:47:18
Last modified : 19/08/2003 19:58:50
#:9 [ccevtmgr.exe]
FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\
ThreadCreationTime : 21-06-2004 21:21:41
BasePriority : Normal
FileSize : 249 KB
FileVersion : 2.0.0.635
ProductVersion : 2.0.0.635
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
OriginalFilename : ccEvtMgr.exe
ProductName : Common Client
Created on : 19/08/2003 19:56:12
Last accessed : 22/06/2004 1:47:18
Last modified : 19/08/2003 19:56:12
#:10 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 21-06-2004 21:21:41
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 24/08/2001 16:00:00
Last accessed : 22/06/2004 1:47:18
Last modified : 24/08/2001 16:00:00
#:11 [mdm.exe]
FilePath : C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\
ThreadCreationTime : 21-06-2004 21:21:42
BasePriority : Normal
FileSize : 264 KB
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
Copyright : Copyright (C) Microsoft Corp. 1997-2000
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
OriginalFilename : mdm.exe
ProductName : Microsoft Development Environment
Created on : 23/02/2001 8:07:30
Last accessed : 22/06/2004 1:47:18
Last modified : 23/02/2001 8:07:30
#:12 [navapsvc.exe]
FilePath : C:\Archivos de programa\Norton AntiVirus\
ThreadCreationTime : 21-06-2004 21:21:43
BasePriority : Normal
FileSize : 155 KB
FileVersion : 10.00.2
ProductVersion : 10.00.2
Copyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright (c) 2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
OriginalFilename : NAVAPSVC.EXE
ProductName : Norton AntiVirus
Created on : 25/05/2004 8:19:40
Last accessed : 22/06/2004 1:47:19
Last modified : 12/05/2004 12:53:44
#:13 [savscan.exe]
FilePath : C:\Archivos de programa\Norton AntiVirus\
ThreadCreationTime : 21-06-2004 21:21:44
BasePriority : Normal
FileSize : 189 KB
FileVersion : 9.2.1.14
ProductVersion : 9.2
Copyright : Copyright (c) 2003 Symantec Corporation
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
OriginalFilename : SAVSCAN.EXE
ProductName : Symantec AntiVirus AutoProtect
Created on : 14/05/2004 11:37:32
Last accessed : 22/06/2004 1:47:19
Last modified : 07/11/2003 17:46:58
#:14 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 21-06-2004 21:21:44
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 24/08/2001 16:00:00
Last accessed : 22/06/2004 1:47:18
Last modified : 24/08/2001 16:00:00
#:15 [vsmon.exe]
FilePath : C:\WINDOWS\system32\ZoneLabs\
ThreadCreationTime : 21-06-2004 21:21:44
BasePriority : Normal
FileSize : 805 KB
FileVersion : 4.5.594.000
ProductVersion : 4.5.594.000
Copyright : Copyright
CompanyName : Zone Labs Inc.
FileDescription : TrueVector Service
InternalName : vsmon
OriginalFilename : vsmon.exe
ProductName : TrueVector Service
Created on : 09/06/2004 10:50:27
Last accessed : 22/06/2004 1:47:19
Last modified : 01/04/2004 7:29:14
#:16 [s3apphk.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 21-06-2004 21:21:53
BasePriority : Normal
FileSize : 28 KB
Created on : 15/01/2004 18:16:03
Last accessed : 22/06/2004 1:47:19
Last modified : 31/01/2002 10:14:50
#:17 [hpztsb05.exe]
FilePath : C:\WINDOWS\System32\spool\drivers\w32x86\3\
ThreadCreationTime : 21-06-2004 21:21:53
BasePriority : Normal
FileSize : 184 KB
FileVersion : 2,128,0,0
ProductVersion : 2,128,0,0
Copyright : Copyright (c) Hewlett-Packard Company 1999-2002
CompanyName : HP
ProductName : HP DeskJet
Created on : 16/01/2004 12:40:42
Last accessed : 22/06/2004 1:47:19
Last modified : 21/06/2002 10:10:35
#:18 [carpserv.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 21-06-2004 21:21:53
BasePriority : Normal
FileSize : 4 KB
FileVersion : 6.02.05
ProductVersion : 6.02.05
Copyright : Copyright
CompanyName : Conexant Systems, Inc.
FileDescription : carpserv
InternalName : carpserv
OriginalFilename : carpserv.exe
ProductName : SoftK56 Modem Driver
Created on : 25/03/2004 9:39:33
Last accessed : 22/06/2004 1:47:19
Last modified : 11/06/2003 10:54:32
#:19 [cnxdsltb.exe]
FilePath : C:\Archivos de programa\Telefónica\Kit ADSL USB\
ThreadCreationTime : 21-06-2004 21:21:53
BasePriority : Normal
FileSize : 412 KB
FileVersion : 2.099.084.000
ProductVersion : 2.099.084.000
CompanyName : Conexant Systems Inc.
FileDescription : Aplicaci
ProductName : Conexant AccessRunner ADSL
Created on : 15/04/2004 16:19:02
Last accessed : 22/06/2004 1:21:54
Last modified : 12/09/2003 9:51:52
#:20 [ccapp.exe]
FilePath : C:\Archivos de programa\Archivos comunes\Symantec Shared\
ThreadCreationTime : 21-06-2004 21:21:53
BasePriority : Normal
FileSize : 69 KB
FileVersion : 2.0.0.635
ProductVersion : 2.0.0.635
Copyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
CompanyName : Symantec Corporation
FileDescription : Symantec Common Client User Session
InternalName : ccApp
OriginalFilename : ccApp.exe
ProductName : Common Client
Created on : 19/08/2003 19:55:56
Last accessed : 22/06/2004 1:47:19
Last modified : 19/08/2003 19:55:56
#:21 [zlclient.exe]
FilePath : C:\ARCHIV~1\ZONELA~1\ZONEAL~1\
ThreadCreationTime : 21-06-2004 21:21:55
BasePriority : Normal
FileSize : 677 KB
FileVersion : 4.5.594.000
ProductVersion : 4.5.594.000
Copyright : Copyright
CompanyName : Zone Labs Inc.
FileDescription : Zone Labs Client
InternalName : zlclient
OriginalFilename : zlclient.exe
ProductName : Zone Labs Client
Created on : 09/06/2004 10:50:32
Last accessed : 22/06/2004 1:47:19
Last modified : 01/04/2004 7:30:04
#:22 [aimmon.exe]
FilePath : C:\Archivos de programa\Telefonica\KitAIM\
ThreadCreationTime : 21-06-2004 21:22:20
BasePriority : Normal
FileSize : 328 KB
FileVersion : 1, 5, 4, 1
ProductVersion : 1, 5, 4, 1
Copyright : Telef
CompanyName : Telef
FileDescription : Aplicaci
InternalName : AIMMon
OriginalFilename : AIMMon.EXE
ProductName : Aplicaci
Created on : 15/04/2004 16:10:49
Last accessed : 22/06/2004 1:47:19
Last modified : 09/11/2003 23:00:16
#:23 [msmsgs.exe]
FilePath : C:\Archivos de programa\Messenger\
ThreadCreationTime : 21-06-2004 21:37:39
BasePriority : Normal
FileSize : 1456 KB
FileVersion : 4.7.2009
ProductVersion : Version 4.7
Copyright : Copyright (c) Microsoft Corporation 1997-2003
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msmsgs
OriginalFilename : msmsgs.exe
ProductName : Messenger
Created on : 14/04/2003 17:30:14
Last accessed : 22/06/2004 1:40:18
Last modified : 14/04/2003 17:30:14
#:24 [ad-aware.exe]
FilePath : C:\ARCHIV~1\Lavasoft\AD-AWA~1\
ThreadCreationTime : 22-06-2004 1:47:08
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 09/06/2004 2:35:43
Last accessed : 22/06/2004 1:36:16
Last modified : 12/07/2003 19:00:20
Resultados Escaneo de la memoria:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 0
Inicio escaneo del Registro
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Resultados Escaneo del registro:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 0
Inicio escaneo profundo del Registro
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Posible secuestro del navegador : Software\Microsoft\Internet Explorer\SearchSearchAssistant.123mania.com
Possible Browser Hijack attempt Objeto reconocido!
Tipo : RegFecha
Fecha : "
http://www.123mania.com/ie.asp"
Categoria : Data Miner
Comentario : Posible secuestro del navegador
Rootkey : HKEY_LOCAL_MACHINE
Objeto : Software\Microsoft\Internet Explorer\Search
Valor : SearchAssistant
Fecha : "
http://www.123mania.com/ie.asp"
Resultados Escaneo Profundo del registro:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 1
Objetos encontrados hasta ahora: 1
Escaneando y examinando archivos en profundidad (A)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Resultados Escaneo del disco: A:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 1
Escaneando y examinando archivos en profundidad (C)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Matrix Technology Network Objeto reconocido!
Tipo : Archivo
Fecha : gidcai32[1].cab
Categoria : Malware
Comentario :
Objeto : C:\Documents and Settings\pc\Configuración local\Archivos temporales de Internet\Content.IE5\MPCRULM5\
FileSize : 22 KB
Created on : 07/06/2004 11:39:59
Last accessed : 22/06/2004 1:50:21
Last modified : 07/06/2004 11:40:00
Matrix Technology Network Objeto reconocido!
Tipo : Archivo
Fecha : gidcai32.dll
Categoria : Malware
Comentario :
Objeto : C:\Documents and Settings\pc\Configuración local\Temp\ICD1.tmp\
FileSize : 44 KB
FileVersion : 1, 1, 0, 12
ProductVersion : 1, 1, 0, 12
Copyright : Matrix Technology Network, S.A. 2004
CompanyName : Matrix Technology Network, S.A.
FileDescription : GIDCAI32.dll
InternalName : GIDCAI32
OriginalFilename : GIDCAI32.dll
ProductName : GIDCAI32.dll
Created on : 02/06/2004 8:12:30
Last accessed : 22/06/2004 1:50:32
Last modified : 02/06/2004 8:12:30
Resultados Escaneo del disco: C:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 3
Escaneando y examinando archivos en profundidad (D)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Resultados Escaneo del disco: D:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 3
Escaneando y examinando archivos en profundidad (E)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Resultados Escaneo del disco: E:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 3
Escaneando y examinando archivos en profundidad (F)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Resultados Escaneo del disco: F:\
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 3
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Hosts file scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
1 entries scanned.
Nuevos objetos:0
Objetos encontrados hasta ahora: 3
Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nuevos objetos: 0
Objetos encontrados hasta ahora: 3
3:55:36 Escaneo completo
Resumen Del escaneo
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total tiempo escaneo:00:08:17:586
Objetos Escaneados:93942
Objetos identificados:3
Objetos ignorados:0
Nuevos objetos:3