Hoy estube peleando con un... virus llegue a la conclucion que el archivo data.sysera el sospechoso lo mande a revisar en http://virust total y me dio estos resultados: http://bit.ly/q4gXi
algunas caracteristicas o sintomas raros de mi PC con XP son:

| Motor antivirus | Versión | Última actualización | Resultado |
|---|---|---|---|
| a-squared | 4.5.0.41 | 2009.11.09 | Riskware.Win32.DelfInject!IK |
| AhnLab-V3 | 5.0.0.2 | 2009.11.06 | - |
| AntiVir | 7.9.1.61 | 2009.11.09 | TR/Buzus.clqs |
| Antiy-AVL | 2.0.3.7 | 2009.11.09 | - |
| Authentium | 5.2.0.5 | 2009.11.09 | - |
| Avast | 4.8.1351.0 | 2009.11.09 | Win32:Trojan-gen |
| AVG | 8.5.0.423 | 2009.11.09 | - |
| BitDefender | 7.2 | 2009.11.09 | - |
| CAT-QuickHeal | 10.00 | 2009.11.09 | - |
| ClamAV | 0.94.1 | 2009.11.09 | - |
| Comodo | 2899 | 2009.11.09 | - |
| DrWeb | 5.0.0.12182 | 2009.11.09 | Trojan.DownLoad1.2328 |
| eTrust-Vet | 35.1.7111 | 2009.11.09 | - |
| F-Prot | 4.5.1.85 | 2009.11.09 | - |
| F-Secure | 9.0.15370.0 | 2009.11.09 | - |
| Fortinet | 3.120.0.0 | 2009.11.09 | - |
| GData | 19 | 2009.11.09 | Win32:Trojan-gen |
| Ikarus | T3.1.1.74.0 | 2009.11.09 | VirTool.Win32.DelfInject |
| Jiangmin | 11.0.800 | 2009.11.09 | - |
| K7AntiVirus | 7.10.892 | 2009.11.09 | Trojan.Win32.Malware.1 |
| Kaspersky | 7.0.0.125 | 2009.11.09 | Trojan.Win32.Buzus.clzq |
| McAfee | 5797 | 2009.11.09 | - |
| McAfee+Artemis | 5797 | 2009.11.09 | Artemis!C175B43487B6 |
| McAfee-GW-Edition | 6.8.5 | 2009.11.09 | Trojan.Buzus.clqs |
| Microsoft | 1.5202 | 2009.11.09 | VirTool:Win32/DelfInject.gen!BA |
| NOD32 | 4589 | 2009.11.09 | a variant of Win32/Injector.AAT |
| Norman | 6.03.02 | 2009.11.09 | - |
| nProtect | 2009.1.8.0 | 2009.11.09 | - |
| Panda | 10.0.2.2 | 2009.11.09 | Trj/CI.A |
| PCTools | 7.0.3.5 | 2009.11.09 | - |
| Prevx | 3.0 | 2009.11.09 | High Risk Cloaked Malware |
| Rising | 22.21.00.08 | 2009.11.09 | - |
| Sophos | 4.47.0 | 2009.11.09 | - |
| Sunbelt | 3.2.1858.2 | 2009.11.09 | Trojan.Win32.Generic!BT |
| Symantec | 1.4.4.12 | 2009.11.09 | Suspicious.MH690.A |
| TheHacker | 6.5.0.2.063 | 2009.11.06 | - |
| TrendMicro | 9.0.0.1003 | 2009.11.09 | TROJ_IMAGE.MCL |
| VBA32 | 3.12.10.11 | 2009.11.09 | - |
| ViRobot | 2009.11.9.2027 | 2009.11.09 | - |
| VirusBuster | 4.6.5.0 | 2009.11.09 | - |
| Información adicional |
|---|
| Tamano archivo: 64000 bytes |
| MD5...: c175b43487b677545089ba902ccef27c |
| SHA1..: 9650a214f370136b1ec0373ababd3c57a7ef5e9d |
| SHA256: a976f6e828683124cd16fa9c232c45b82637ad449a3505c920a9c296c472c15f |
| ssdeep: 1536:kjg+vWhZz63l2MzUD/18hJBmw6IF9U4TPStDlaqMNx77IGD4:kkYW+39zS/ QeYzTSt1sJD4 |
| PEiD..: - |
| PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x3100 timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992) machinetype.......: 0x14c (I386) ( 8 sections ) name viradd virsiz rawdsiz ntrpy md5 CODE 0x1000 0x37e0 0x3800 6.38 07ccdd6bb48c10c7a4fbfcba7a4c373b DATA 0x5000 0x164 0x200 2.90 09cd222ab1e5dc25487b845f8e1f03d3 BSS 0x6000 0xcd9 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .idata 0x7000 0x1c2 0x200 3.71 b26037f20e090a504ae7452f11ccc2e7 .tls 0x8000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e .rdata 0x9000 0x18 0x200 0.20 464e11218533a2251856b8bc9db70ff1 .reloc 0xa000 0x4b0 0x600 5.68 20b8bac43c9b574a70a50d3714cb997d .rsrc 0xb000 0xb1b8 0xb200 7.90 d601c694f94a76c555d68bc28f7b1e1f ( 3 imports ) > kernel32.dll: GetCurrentThreadId, ExitProcess, RtlUnwind, RaiseException, TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA, FreeLibrary, HeapFree, HeapReAlloc, HeapAlloc, GetProcessHeap > oleaut32.dll: SysFreeString, SysReAllocStringLen > kernel32.dll: LoadLibraryA ( 0 exports ) |
| RDS...: NSRL Reference Data Set - |
| pdfid.: - |
| trid..: Win32 Executable Generic (38.4%) Win32 Dynamic Link Library (generic) (34.1%) Win16/32 Executable Delphi generic (9.3%) Generic Win/DOS Executable (9.0%) DOS Executable Generic (9.0%) |
| <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=8352D7F900DDE215FAAF0068A9D57500E1DC713D' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=8352D7F900DDE215FAAF0068A9D57500E1DC713D</a> |
| sigcheck: publisher....: n/a copyright....: n/a product......: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments.....: n/a signers......: - signing date.: - verified.....: Unsigned |
algunas caracteristicas o sintomas raros de mi PC con XP son:
- Bloquea paguinas en las que tratas de conseguir informacion antivirus o del virus
- Manda un enlace a un archivo *.zip por messenger msn con un mensaje aleatorio siempre a ciertas horas
- Traba messenger
- Crea un archivo data.sys en las USB
- Cambia el icono de disco removible por el icono de carpeta de windows
- A dejado inservible Mi Nod32



































