Problema con Trojan.Agent.AutoIt


#23

Vale, adjunto el reporte :crossed_fingers:t5:


Fix result of Farbar Recovery Scan Tool (x64) Version: 10.11.2018
Ran by Leire (11-11-2018 11:06:34) Run:1
Running from C:\Users\Leire\Desktop
Loaded Profiles: Leire (Available Profiles: Leire)
Boot Mode: Normal
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\Run: [66fe5029] => C:\ProgramData\66fe5029\66fe5029.exe [0 ] (AutoIt Team)
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\Run: [66fe50292] => C:\ProgramData\qdxvXBQt\66fe5029.exe [937776 2018-11-10] (AutoIt Team)
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\MountPoints2: {df6ea4af-2257-11e6-a8a1-50e549e848ee} - explorer.exe www.presto.es\index.html
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\MountPoints2: {fd742246-b3ae-11e5-98b0-50e549e848ee} - F:\STARTUP.EXE
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\...\MountPoints2: {fd74228d-b3ae-11e5-98b0-50e549e848ee} - K:\autorun.exe
Startup: C:\Users\Leire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b66fe5029d0f3009021030e6f2469239.lnk [2018-11-10]
ShortcutTarget: b66fe5029d0f3009021030e6f2469239.lnk -> C:\ProgramData\OkOAOn\66fe5029.exe (AutoIt Team)
ShortcutTarget: Last.fm Desktop Scrobbler.lnk -> C:\Users\Leire\AppData\Roaming\Microsoft\Installer\{EEF2F789-893F-47B8-A817-81066D427FD1}\_3C389C1899E83A28513401.exe ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-19]
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-27]
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-11-07]
S3 WinDefend; %ProgramFiles%\Windows Defender\mpsvc.dll [X]
S3 WMPNetworkSvc; "%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe" [X]
S3 EtronHub3; System32\Drivers\EtronHub3.sys [X]
S3 EtronXHCI; System32\Drivers\EtronXHCI.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2018-11-10 18:30 - 2018-11-10 18:30 - 000000000 ____D C:\ProgramData\qdxvXBQt
2018-11-10 10:31 - 2018-11-10 14:11 - 000000000 ____D C:\ProgramData\uudKFsUz
2018-11-09 15:51 - 2018-11-09 15:51 - 000000000 ____D C:\ProgramData\OkOAOn
2018-11-09 13:29 - 2018-11-09 13:29 - 000000000 ____D C:\ProgramData\XlRDgk
2018-11-09 12:43 - 2018-11-09 12:43 - 000000000 ____D C:\ProgramData\zfwOYJ
2018-11-09 11:49 - 2018-11-09 11:49 - 000000000 ____D C:\ProgramData\HXwANso
2018-11-10 14:36 - 2018-02-27 21:17 - 000002982 _____ C:\Windows\System32\Tasks\{68656588-3BCC-4BA6-A460-6E0D9010729A}
2018-11-10 14:36 - 2018-02-27 20:08 - 000002982 _____ C:\Windows\System32\Tasks\{95304FB1-B750-4C95-959F-60AB60262AA8}
2018-11-10 14:36 - 2017-12-13 11:25 - 000003172 _____ C:\Windows\System32\Tasks\{D716DE4F-F474-48E6-AE81-EBFEA1520A72}
2018-11-10 14:36 - 2017-12-01 14:07 - 000002910 _____ C:\Windows\System32\Tasks\{F1BD5EC7-15AC-475A-9F31-7A5F74AC1419}
2018-11-10 14:36 - 2017-10-30 14:41 - 000002950 _____ C:\Windows\System32\Tasks\{0DAC133D-B375-453F-B2D8-7686ADB20A25}
2018-11-10 14:36 - 2017-10-30 14:15 - 000002950 _____ C:\Windows\System32\Tasks\{F3F67E1B-4064-45B3-A3A7-3C77FA577DEE}
2018-11-10 14:36 - 2017-10-30 14:14 - 000002950 _____ C:\Windows\System32\Tasks\{742AAC86-20A7-4B7E-BA09-5CDD4787F631}
2018-11-10 14:36 - 2017-01-29 10:49 - 000003152 _____ C:\Windows\System32\Tasks\{D9258C07-F885-49F0-87D8-22EDA70742E5}
2018-11-10 14:36 - 2017-01-29 10:48 - 000003220 _____ C:\Windows\System32\Tasks\{A409177E-88DA-440B-B4C2-4324B118DE7A}
2018-11-10 14:36 - 2016-01-05 15:59 - 000003068 _____ C:\Windows\System32\Tasks\{18E33739-9B6C-4834-B587-A4B0DC39D839}
2018-11-10 14:36 - 2016-01-05 15:59 - 000003068 _____ C:\Windows\System32\Tasks\{1374C2A1-C4EC-4E4D-BE95-4D1D88136866}
2018-11-10 14:36 - 2015-11-17 22:03 - 000003158 _____ C:\Windows\System32\Tasks\{B044483D-22F7-4BC2-97F8-E44F6A3D6455}
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => C:\Users\Leire\Desktop\Windows Sidebar\sbdrop.dll -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`28hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0]

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: (0) Failed to create a restore point.
Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
"HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => removed successfully
"HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\Software\Microsoft\Windows\CurrentVersion\Run\\66fe5029" => removed successfully
"HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\Software\Microsoft\Windows\CurrentVersion\Run\\66fe50292" => removed successfully
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{df6ea4af-2257-11e6-a8a1-50e549e848ee} => removed successfully
HKLM\Software\Classes\CLSID\{df6ea4af-2257-11e6-a8a1-50e549e848ee} => not found
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd742246-b3ae-11e5-98b0-50e549e848ee} => removed successfully
HKLM\Software\Classes\CLSID\{fd742246-b3ae-11e5-98b0-50e549e848ee} => not found
HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd74228d-b3ae-11e5-98b0-50e549e848ee} => removed successfully
HKLM\Software\Classes\CLSID\{fd74228d-b3ae-11e5-98b0-50e549e848ee} => not found
C:\Users\Leire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b66fe5029d0f3009021030e6f2469239.lnk => moved successfully
C:\ProgramData\OkOAOn\66fe5029.exe => moved successfully
C:\Users\Leire\AppData\Roaming\Microsoft\Installer\{EEF2F789-893F-47B8-A817-81066D427FD1}\_3C389C1899E83A28513401.exe => moved successfully
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\Software\MozillaPlugins\wacom.com/WacomTabletPlugin => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\wacom.com/WacomTabletPlugin => removed successfully
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-10-19] => Error: No automatic fix found for this entry.
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-27] => Error: No automatic fix found for this entry.
CHR Extension: (Chrome Media Router) - C:\Users\Leire\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-11-07] => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\WinDefend => removed successfully
WinDefend => service removed successfully
HKLM\System\CurrentControlSet\Services\WMPNetworkSvc => removed successfully
WMPNetworkSvc => service removed successfully
HKLM\System\CurrentControlSet\Services\EtronHub3 => removed successfully
EtronHub3 => service removed successfully
HKLM\System\CurrentControlSet\Services\EtronXHCI => removed successfully
EtronXHCI => service removed successfully
HKLM\System\CurrentControlSet\Services\VGPU => removed successfully
VGPU => service removed successfully
C:\ProgramData\qdxvXBQt => moved successfully
C:\ProgramData\uudKFsUz => moved successfully
C:\ProgramData\OkOAOn => moved successfully
C:\ProgramData\XlRDgk => moved successfully
C:\ProgramData\zfwOYJ => moved successfully
C:\ProgramData\HXwANso => moved successfully
C:\Windows\System32\Tasks\{68656588-3BCC-4BA6-A460-6E0D9010729A} => moved successfully
C:\Windows\System32\Tasks\{95304FB1-B750-4C95-959F-60AB60262AA8} => moved successfully
C:\Windows\System32\Tasks\{D716DE4F-F474-48E6-AE81-EBFEA1520A72} => moved successfully
C:\Windows\System32\Tasks\{F1BD5EC7-15AC-475A-9F31-7A5F74AC1419} => moved successfully
C:\Windows\System32\Tasks\{0DAC133D-B375-453F-B2D8-7686ADB20A25} => moved successfully
C:\Windows\System32\Tasks\{F3F67E1B-4064-45B3-A3A7-3C77FA577DEE} => moved successfully
C:\Windows\System32\Tasks\{742AAC86-20A7-4B7E-BA09-5CDD4787F631} => moved successfully
C:\Windows\System32\Tasks\{D9258C07-F885-49F0-87D8-22EDA70742E5} => moved successfully
C:\Windows\System32\Tasks\{A409177E-88DA-440B-B4C2-4324B118DE7A} => moved successfully
C:\Windows\System32\Tasks\{18E33739-9B6C-4834-B587-A4B0DC39D839} => moved successfully
C:\Windows\System32\Tasks\{1374C2A1-C4EC-4E4D-BE95-4D1D88136866} => moved successfully
C:\Windows\System32\Tasks\{B044483D-22F7-4BC2-97F8-E44F6A3D6455} => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\Gadgets => removed successfully
"HKLM\Software\Classes\CLSID\{6B9228DA-9C15-419e-856C-19E768A13BDC}" => removed successfully
C:\ProgramData\Reprise => ":wupeogjxlctlfudivq`qsp`28hfm" ADS removed successfully
C:\ProgramData\Reprise => ":wupeogjxlctlfudivq`qsp`29hfm" ADS removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-1895503046-2164595843-4212185805-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


Adaptador de Ethernet Conexi¢n de  rea local:

   Sufijo DNS espec¡fico para la conexi¢n. . : euskaltel.es
   V¡nculo: direcci¢n IPv6 local. . . : fe80::50ae:4101:3421:c951%11
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.11
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.0.1

Adaptador de t£nel Teredo Tunneling Pseudo-Interface:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.euskaltel.es:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : euskaltel.es

========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci┬ó correctamente la cachÔÇÜ de resoluci┬ón de DNS.

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 22562583 B
Java, Flash, Steam htmlcache => 154772063 B
Windows/system/drivers => 8126917 B
Edge => 0 B
Chrome => 509558031 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 58558406 B
systemprofile32 => 66392 B
LocalService => 157636 B
NetworkService => 0 B
Leire => 55157658 B

RecycleBin => 0 B
EmptyTemp: => 779.5 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:06:55 ====

#24

Seg├║n todo ya no tengo amenazas en el PC. Creo que os quiero mucho.


#25

Hola zeit85

Sigue estos pasos, para eliminar las herramientas utilizadas:

Para hacerlo utiliza de nuevo/descarga >> DelFix.exe en tu escritorio.

  • Doble clic para ejecutarlo. (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador -).

  • Marca todas las casillas, y pulsas en Run

Se abrirá el informe (DelFix.txt), puedes cerrarlo.


Gracias a ti por confiar en ForoSpyware. Ha sido un placer ayudarte :manos:

Nos alegramos que se te haya resuelto :Bien: Damos el tema por solucionado.

Solucionado

Un saludo


#26

Este tema se cerr├│ autom├íticamente 2 d├şas despu├ęs del ├║ltimo post. No se permiten nuevas respuestas.