Infeccion con AV360 parte 2
Publicado: Mar Feb 24, 2009 10:43 pm
Se esta poniendo un poco mas inteligente este Virus. Como siempre, se recomienda re-nombrando el archivo de instalacion de Malwarebytes Antimalware y ahora, cuando intentas actualizarlo o ejecutar un Scan del sistema, AV360 lo cierra automaticamente. Usa Alt+Ctrl+Del o ejecuta manualmente el Administrador de Tareas de Windows y termina todos los procesos con nombre AV360. Despues, inmediatamente empieza el SCAN.
Malwarebytes' Anti-Malware 1.34
Database version: 1793
Windows 6.0.6000
2/24/2009 9:05:42 PM
mbam-log-2009-02-24 (21-05-42).txt
Scan type: Quick Scan
Objects scanned: 59706
Time elapsed: 3 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 8
Files Infected: 29
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\starware337 (Adware.Starware) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3e89f9d2a9698a17f3856721bd049c5b (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\bin (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
Files Infected:
C:\Windows\System32\winconfig.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\723_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\723_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\726_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Dating0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Free_Credit_Score0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Ringtones0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\A360\av360.exe (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\A360.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Help.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Registration.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\Desktop\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.34
Database version: 1793
Windows 6.0.6000
2/24/2009 9:05:42 PM
mbam-log-2009-02-24 (21-05-42).txt
Scan type: Quick Scan
Objects scanned: 59706
Time elapsed: 3 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 8
Files Infected: 29
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d263fa6d-84cc-48a8-9af6-c664362b7a5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5f90c0e3-4c0a-4d54-a8ac-5afe6163a99e} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\starware337 (Adware.Starware) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3e89f9d2a9698a17f3856721bd049c5b (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\bin (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360 (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
Files Infected:
C:\Windows\System32\winconfig.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\723_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\723_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\726_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Dating0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Free_Credit_Score0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\buttons\Ringtones0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\ProgramData\Starware337\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\A360\av360.exe (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\A360.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Help.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Registration.lnk (Rogue.A360Antivirus) -> Quarantined and deleted successfully.
C:\Users\Judy\Desktop\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.
C:\Users\Judy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\A360.lnk (Rogue.Antivirus360) -> Quarantined and deleted successfully.