Ver Mensaje Individual
  post #1 (permalink)  
Antiguo 21/07/08, 15:44:40
siux5 siux5 está offline
Usuario
 
Registrado: ene 2008
Ubicación: españa
Mensajes: 9
virus y no me lo consigo quitar (Solucionado)

llevo varios dias con el ordenador haciendo cosas extrañas he leido un poco el foro sobre los virus con publicidad ya que a mi me sale publicidad sin abrir el explorer

he reiniciado en modo seguro, he pasado el superantispyware y me pillo esto.:


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/21/2008 at 07:26 PM

Application Version : 4.15.1000

Core Rules Database Version : 3508
Trace Rules Database Version: 1499

Scan type : Complete Scan
Total Scan Time : 00:39:11

Memory items scanned : 154
Memory threats detected : 0
Registry items scanned : 5327
Registry threats detected : 0
File items scanned : 15064
File threats detected : 16

Adware.Tracking Cookie
C:\Documents and Settings\Administrador\Cookies\administrador@ad.za nox[2].txt
C:\Documents and Settings\Administrador\Cookies\administrador@2o7[1].txt
C:\Documents and Settings\Administrador\Cookies\administrador@ads.g lispa[2].txt
C:\Documents and Settings\Administrador\Cookies\administrador@panda software.112.2o7[1].txt
C:\Documents and Settings\Administrador\Cookies\administrador@adser ver.easyad[1].txt
C:\Documents and Settings\Administrador\Cookies\administrador@adopt .euroclick[2].txt
C:\Documents and Settings\Administrador\Cookies\administrador@ad.yi eldmanager[2].txt
.tribalfusion.com [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.2o7.net [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.2o7.net [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.pandasoftware.112.2o7.net [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.adultfriendfinder.com [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.adultfriendfinder.com [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.adultfriendfinder.com [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
.adultfriendfinder.com [ C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\s36e47dr.default \cookies.txt ]
C:\Documents and Settings\NetworkService\Cookies\system@ad.zanox[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.yieldman ager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.glispa[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adserver.ea syad[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@adopt.euroc lick[2].txt

Trojan.Unknown Origin
C:\WINDOWS\SYSTEM32\6LN0DYGS.EXE_
C:\WINDOWS\TEMP\3TCUY1DL.EXE
C:\WINDOWS\TEMP\3V2Y6MEF.EXE
C:\WINDOWS\TEMP\AB2DCJDQ.EXE


luego pase el navilog 1.:

Navipromo Removal version 3.6.1 started on 21/07/2008 at 19:35:14,60

Fix running from C:\Archivos de programa\navilog1
Actual User Account : "Administrador"

Updated on 19.07.2008 at 20h00 by IL-MAFIOSO


Microsoft Windows XP [Versi¢n 5.1.2600]
Internet Explorer : 6.0.2900.5512
Filesystem type : NTFS

Automatic removal
with Catchme and GNS results


Cleanning stage done in safe mode


*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)


*** Deleting with Backups GenericNaviSearch results ***

* Deletion in "C:\WINDOWS\System32" *


* Deletion in "C:\Documents and Settings\Administrador\config~1\datosd~1" *



*** Deleting folders in "C:\WINDOWS" ***


*** Deleting folders in "C:\Archivos de programa" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menini~1\progra~1" ***


*** Deleting folders in "C:\Documents and Settings\All Users\menini~1" ***


*** Deleting folders in "c:\docume~1\alluse~1\datosd~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrador\datosd~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrador\config~1\datosd~1" ***


*** Deleting folders in "C:\Documents and Settings\Administrador\menini~1\progra~1" ***



*** Deleting files ***


*** Deleting temporary files ***

Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Administrador\config~1\Temp done !

*** Complementary Search ***
(Search specific files)

1)Deletion with backups new Instant Access files:

2)Heuristic search and deletion with backups :


* In "C:\WINDOWS\system32" *


* In "C:\Documents and Settings\Administrador\config~1\datosd~1" *


*** Copy Registry to Safebackup folder ***

Backing up Registry done !

*** Cleaning Registry ***

Registry cleaned


*** Certificates ***

Egroup Certificate not found !
Electronic-Group Certificate not found !
OOO-Favorit Certificate not found !
Sunny-Day-Design-Ltd Certificate not found !

*** Suspicious Files not deleted by Navilog1 ***
!! Possible legitimate files, must be checked before deleting !!

Suspicious Files in "C:\Documents and Settings\Administrador\config~1\datosd~1" :

vqnwjlswk.exe found !


*** Cleaning stage complete on 21/07/2008 at 19:36:40,87 ***


y por ultimo le pase el panda active scan.:



Trj/Rebooter.J Virus
Latente
Ocultar + Info
1. C:\Archivos de programa\Navilog1\Reboot.exe
Peligrosidad baja (1)
Generic Malwar... Virus
Latente
Ocultar + Info
1. C:\WINDOWS\temp\vVgG2fL7.exe
2. C:\WINDOWS\system32\6LN0dYGS.exe


y coño esto ---> 6LN0dYGS.exe, en teoria estaba eliminado

me podeis echar una mano?

Última edición por siux5 fecha: 21/07/08 a las 15:46:44.
Responder Con Cita