Ver Mensaje Individual
  post #1 (permalink)  
Antiguo 09/11/07, 20:43:14
rusile rusile está offline
Usuario
 
Registrado: nov 2007
Ubicación: España
Mensajes: 2
Alguien me puede decir si lo que tengo es Vundo Variant, Virtumonde o lo que sea?????

Estoy desesperado con las ventanitas..... Una ayudita porfavor

El SUPERAntispyware me ha detectado lo siguiente:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/09/2007 at 02:08 AM

Application Version : 3.9.1008

Core Rules Database Version : 3340
Trace Rules Database Version: 1341

Scan type : Complete Scan
Total Scan Time : 00:45:30

Memory items scanned : 474
Memory threats detected : 3
Registry items scanned : 7381
Registry threats detected : 21
File items scanned : 32794
File threats detected : 32

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\SSTTR.DLL
C:\WINDOWS\SYSTEM32\SSTTR.DLL

Trojan.Downloader-NewJuan/VM
C:\WINDOWS\SYSTEM32\UDKFSDBJ.DLL
C:\WINDOWS\SYSTEM32\UDKFSDBJ.DLL

Adware.eZula
C:\WINDOWS\SYSTEM32\GYGTSVMU.EXE
C:\WINDOWS\SYSTEM32\GYGTSVMU.EXE

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\FPFCOBFD.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{345E9405-B7F1-430D-AF56-F2943B07592A}
HKCR\CLSID\{345E9405-B7F1-430D-AF56-F2943B07592A}
HKCR\CLSID\{345E9405-B7F1-430D-AF56-F2943B07592A}\InprocServer32
HKCR\CLSID\{345E9405-B7F1-430D-AF56-F2943B07592A}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{345E9405-B7F1-430D-AF56-F2943B07592A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}

Adware.Vundo-Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{a754d91d-80f5-4287-8400-0d9f728aa155}
HKCR\CLSID\{A754D91D-80F5-4287-8400-0D9F728AA155}
HKCR\CLSID\{A754D91D-80F5-4287-8400-0D9F728AA155}\InprocServer32
HKCR\CLSID\{A754D91D-80F5-4287-8400-0D9F728AA155}\InprocServer32#ThreadingModel

Adware.Tracking Cookie
C:\Documents and Settings\Sandra\Cookies\sandra@ad.zanox[1].txt
C:\Documents and Settings\Sandra\Cookies\sandra@bestsellerantivirus[2].txt
C:\Documents and Settings\Sandra\Cookies\sandra@doubleclick[1].txt

Malware.LocusSoftware Inc/BestSellerAntivirus
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\CAQLYUVV.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\DLWIXOQL.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\DSWTMHMJ.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\EFCGXLVU.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\EXJEGPQB.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\GCAAQYQF.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\GFNSAQMF.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\GITOBXMN.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\HQHMHMDI.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\KJYMXIUQ.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\LPLLFRFY.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\MOFUGCLQ.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\NGPROXVF.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\PEUAGBSX.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\QRJATYDI.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\RHVQSUWB.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\SHEQIPOI.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\UJJIVNWV.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\URCLQECD.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\VNTMRYKT.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\XQEDQKPR.EXE
C:\DOCUMENTS AND SETTINGS\SANDRA\CONFIGURACIóN LOCAL\TEMP\YWUECXWM.EXE

Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\RTTSS.BAK1

Trojan.Downloader-Gen/Suspicious
C:\WINDOWS\SYSTEM32\SYSDL132.EXE

Trojan.Downloader-Gen/Multi
C:\WINDOWS\SYSTEM32\~.EXE





Hoy me ha detectado lo siguiente:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/10/2007 at 00:40 AM

Application Version : 3.9.1008

Core Rules Database Version : 3341
Trace Rules Database Version: 1342

Scan type : Complete Scan
Total Scan Time : 00:51:29

Memory items scanned : 172
Memory threats detected : 0
Registry items scanned : 7381
Registry threats detected : 1
File items scanned : 33386
File threats detected : 8

Unclassified.Unknown Origin
HKU\S-1-5-21-1487315275-457440767-1384297894-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}

Adware.Tracking Cookie
C:\Documents and Settings\Sandra\Cookies\sandra@ad.zanox[1].txt
C:\Documents and Settings\Sandra\Cookies\sandra@tradedoubler[2].txt
C:\Documents and Settings\Sandra\Cookies\sandra@cover19.adultfriend finder[1].txt
C:\Documents and Settings\Sandra\Cookies\sandra@msnportal.112.2o7[1].txt
C:\Documents and Settings\Sandra\Cookies\sandra@atdmt[2].txt
C:\Documents and Settings\Sandra\Cookies\sandra@doubleclick[1].txt
C:\Documents and Settings\Sandra\Cookies\sandra@statse.webtrendsliv e[2].txt

Adware.Vundo-Variant
C:\WINDOWS\SYSTEM32\XLCNLHYW.DLL



Todo esto está en cuarentena ¿Puedo eliminar los archivos? A ver qué me podéis aconsejar.... Gracias

Última edición por <¡D3vIL!> fecha: 11/11/07 a las 12:48:42.