Ver la Versión Completa : Problema con pop ups


dodox
14/10/06, 14:07:24
Buenas gente .

Bueno mi problema basicamente es que cada 2 por 3 empiezan a abrirse pop ups con propagandas y me salta un cartel que dice que mi computadora esta infectada y que blablabla e intenta instalarte un anti spyware .
La cuestion es q pase el spyboy y hay una entrada q no me puede borrar y despues le pase el kaspersky y aca les paso el resultado:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, October 14, 2006 2:59:23 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 14/10/2006
Kaspersky Anti-Virus database records: 218475
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 51120
Number of viruses found: 9
Number of infected objects: 20 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:13:04

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\rawlog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\seclog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\syslog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\tralog.log Object is locked skipped
C:\Archivos de programa\WinPoET\WrOS.EventLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\MSHist0120061014200610 15\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\Perflib_Perfdata_28c.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\~DFD016.tmp Object is locked skipped
C:\Documents and Settings\Juegos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\mailbase.dat Object is locked skipped
C:\Documents and Settings\Juegos\directx.sys Infected: Rootkit.Win32.Agent.l skipped
C:\Documents and Settings\Juegos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Juegos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Trabajo\directx.sys Infected: Rootkit.Win32.Agent.l skipped
C:\nwnmff_e15.exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r00.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r01.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r02.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r03.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r04.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r05.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r06.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r07.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r09.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r12.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r14.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r15.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r16.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r18.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r19.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r21.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r23.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r24.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r29.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r31.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r32.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r33.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r34.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r35.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r37.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r38.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r41.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r45.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r48.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r49.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r51.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r52.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r53.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r54.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r57.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r58.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r59.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r60.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r61.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r63.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r64.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r67.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r68.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r71.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r73.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r74.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.rar.bc! Object is locked skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP101\A0057994.sys Infected: Rootkit.Win32.Agent.l skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP102\A0058014.exe Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP102\A0058021.sys Infected: Rootkit.Win32.Agent.l skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP103\A0058048.exe Infected: Backdoor.Win32.Rbot.gen skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP113\A0066506.exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP114\change.log Object is locked skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP76\A0041526.exe Infected: Backdoor.Win32.Rbot.aeu skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP76\A0041527.exe Infected: Backdoor.Win32.SdBot.awk skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\fixmein.exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CnxDslWz.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\MTE3NDI6ODoxNg[1].exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\directx.sys Infected: Rootkit.Win32.Agent.l skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd1357.sys Object is locked skipped
C:\WINDOWS\system32\fpj6031se.dll Object is locked skipped
C:\WINDOWS\system32\fpp8037ue.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab skipped
C:\WINDOWS\system32\mssvcc.exe Infected: Backdoor.Win32.Rbot.aeu skipped
C:\WINDOWS\system32\pavjob.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\system32\wsap32.exe Infected: Backdoor.Win32.Rbot.gen skipped
C:\WINDOWS\system32\wyhnetbs.dll Object is locked skipped
C:\WINDOWS\Temp\PAV8342 Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.

Los felicito por la pagina !

Salu2 .

Fulgore
14/10/06, 14:28:16
Saludos. Intenta hacer lo sgte:


Descargate la herramienta DelPsguard (http://www.forospyware.com/t4239.html) pero no la ejecutes aun.

:1: Descarga la herramienta Killbox (http://www.forospyware.com/49-post6.html)
:2: Activa la opcion Ver Archivos Ocultos (http://www.forospyware.com/46-post3.html)
:3: Apaga la opcion Restaurar Sistema (http://www.forospyware.com/45-post2.html) si tienes Windows ME o XP.
:4: Entra en Modo Seguro (http://www.forospyware.com/47-post4.html)
:5: Ejecuta el killbox, y borra lo siguiente:

C:\Documents and Settings\Juegos\directx.sys

C:\nwnmff_e15.exe

C:\WINDOWS\fixmein.exe

C:\WINDOWS\system32\i

C:\WINDOWS\system32\mssvcc.exe

C:\WINDOWS\system32\directx.sys

C:\WINDOWS\system32\wsap32.exe



C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP101\A0057994.sys Infected: Rootkit.Win32.Agent.l skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP102\A0058014.exe Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP102\A0058021.sys Infected: Rootkit.Win32.Agent.l skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP103\A0058048.exe Infected: Backdoor.Win32.Rbot.gen skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP113\A0066506.exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP114\change.log Object is locked skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP76\A0041526.exe Infected: Backdoor.Win32.Rbot.aeu skipped
C:\System Volume Information\_restore{5422D23F-0975-4176-86F4-5917470FDED9}\RP76\A0041527.exe Infected: Backdoor.Win32.SdBot.awk skipped

Estos se eliminan cuando desactivas la opcion restaurar sistema



C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\MTE3NDI6ODoxNg[1].exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped

Estos se eliminan cuando borres todos los archivos temporales, con la aplicacion DiskCleaner (http://www.forospyware.com/48-post5.html)

Luego de que elimines esos archivos, en modo seguro aun, y con todos los programas cerrados, ejecuta la herramienta DELPSGUARD

Reinicia normalmente, y haz un escaneo online nuevamente con el ewido y el kaspersky, y nos pegas los reportes que estos te generen aqui.

Estaremos atentos.
Suerte :Bien:

dodox
14/10/06, 16:05:53
Bueno hize lo q me dijiste . El DelPsguard creo q no encontro nada :

DelPSGuard v 4.1.9
by www.ForoSpyware.com
Escaneo a las: 16:05:35,82, 14/10/2006
SO: Microsoft Windows XP [Versi˘n 5.1.2600]


»»»»»»»»»»»» Carpetas y Archivos infectados »»»»»»»»»»»»


»»»»»»»»»»»» Programas Malwares »»»»»»»»»»»»



»»»»»»»»»»»» FIN »»»»»»»»»»»»

Tenia que ejecutar la opcion 3 tb ? porq como no entendi lo q hacia solo ejecute la opcion 1

y esto es lo q me tiro el kaspersky :

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, October 14, 2006 5:04:48 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 14/10/2006
Kaspersky Anti-Virus database records: 218505
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\!KillBox\
C:\Archivos de programa\
C:\Documents and Settings\
C:\KPCMS\
C:\NVIDIA\
C:\Program Files\
C:\RECYCLER\
C:\System Volume Information\
C:\Temp\
C:\WINDOWS\

Scan Statistics:
Total number of scanned objects: 32291
Number of viruses found: 5
Number of infected objects: 6 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:28:37

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\rawlog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\seclog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\syslog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\tralog.log Object is locked skipped
C:\Archivos de programa\WinPoET\WrOS.EventLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\MSHist0120061014200610 15\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\BIT4.tmp Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\hsperfdata_Juegos\3508 Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\~DFFC43.tmp Object is locked skipped
C:\Documents and Settings\Juegos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\mailbase.dat Object is locked skipped
C:\Documents and Settings\Juegos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Juegos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Trabajo\directx.sys Infected: Rootkit.Win32.Agent.l skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CnxDslWz.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\MTE3NDI6ODoxNg[1].exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd1357.sys Object is locked skipped
C:\WINDOWS\system32\gp62l3jo1.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\jt8u07l9e.dll Object is locked skipped
C:\WINDOWS\system32\pavjob.log Object is locked skipped
C:\WINDOWS\system32\rFsadhlp.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\Temp\PAV1610 Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.


Salu2 !

Hardrive
14/10/06, 18:59:22
Holas. Sigue con los siguientes pasos:
1. - Entra en Modo Seguro (http://www.forospyware.com/47-post4.html) (Modo a Prueba de Fallos).
2. - Borra los siguientes archivos:
C:\Documents and Settings\Trabajo\directx.sys
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\MTE3NDI6ODoxNg[1].exe
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe
3. - Escanea con:
Tu antivirus actualizado (todos tus discos locales).
Ad-aware 1.06 SE Personal (http://www.infospyware.com/Anti-Spywares.htm) actualizado (Full Scan).
[/LIST]
4. - No salgas del modo seguro. Has lo siguiente en cada cuenta de usuario:

Cierra todas las ventanas.
Pasa el Disk Cleaner (http://www.infospyware.com/Herramientas.htm).
Limpia el registro con RegSeeker (http://www.infospyware.com/Herramientas.htm) (manual (http://www.forospyware.com/t713.html)).

5. - Escanea con Ewido y Kaspersky On-Line (http://www.forospyware.com/foro-de-virus-y-spywares/aviso-7.html) en ese orden y nos pegas los 2 reportes juntos, en este mismo tema.

Salu2

dodox
14/10/06, 23:33:55
Bueno hice lo q me dijeron y esto es lo q aparece ahora .

Kaspersky

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, October 14, 2006 11:38:46 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 15/10/2006
Kaspersky Anti-Virus database records: 218538
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 38267
Number of viruses found: 3
Number of infected objects: 4 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:04:05

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Archivos de programa\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\rawlog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\seclog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\syslog.log Object is locked skipped
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\Firewall\tralog.log Object is locked skipped
C:\Archivos de programa\WinPoET\WrOS.EventLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Historial\History.IE5\MSHist0120061014200610 15\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\fla2B8.tmp Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\hsperfdata_Juegos\3336 Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\Perflib_Perfdata_298.dat Object is locked skipped
C:\Documents and Settings\Juegos\Configuración local\Temp\~DFD8FF.tmp Object is locked skipped
C:\Documents and Settings\Juegos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\mail\mailbase.dat Object is locked skipped
C:\Documents and Settings\Juegos\Datos de programa\Opera\Opera\profile\cache4\opr04K73.tmp Object is locked skipped
C:\Documents and Settings\Juegos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Juegos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Pato\Downloads\Higurashi_no_Naku_Koro_ni_13_[wind][xvid][D138D940].avi.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r00.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r01.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r02.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r04.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r05.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r07.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r08.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r09.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r11.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r12.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r14.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r16.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r19.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r20.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r21.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r24.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r25.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r28.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r29.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r31.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r32.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r33.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r34.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r35.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r37.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r39.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r41.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r43.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r45.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r46.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r48.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r49.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r50.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r54.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r55.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r56.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r60.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r62.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r67.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r68.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r70.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r72.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r73.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r75.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.r76.bc! Object is locked skipped
C:\Pato\Downloads\www.bitreactor.to_Company.of.Her oes-LOADiNG\ld-coh.rar.bc! Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CnxDslWz.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg Infected: Trojan-Downloader.Win32.Adload.fo skipped
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe Infected: Trojan-Downloader.Win32.Adload.fv skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd1357.sys Object is locked skipped
C:\WINDOWS\system32\h00q0ad5ed0.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\nsmssvc.dll Object is locked skipped
C:\WINDOWS\system32\pavjob.log Object is locked skipped
C:\WINDOWS\system32\q886lils18q6.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped

Scan process completed.

Ewido

__________________________________________________
ewido anti-spyware online scanner
http://www.ewido.net
__________________________________________________


Name: TrackingCookie.2o7
Path: C:\Documents and Settings\Juegos\Cookies\juegos@2o7[2].txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: C:\Documents and Settings\Juegos\Cookies\juegos@ad.yieldmanager[1].txt
Risk: Medium

Name: TrackingCookie.Cpvfeed
Path: C:\Documents and Settings\Juegos\Cookies\juegos@cpvfeed[2].txt
Risk: Medium

Name: TrackingCookie.Reliablestats
Path: C:\Documents and Settings\Juegos\Cookies\juegos@stats1.reliablestat s[1].txt
Risk: Medium

Name: Adware.Look2Me
Path: [664] C:\WINDOWS\system32\nsmssvc.dll
Risk: Medium

Name: Adware.Look2Me
Path: [3144] C:\WINDOWS\system32\guard.tmp
Risk: Medium

Name: Not-A-Virus.Downloader.Win32.WinFixer.o
Path: C:\Documents and Settings\Trabajo\Datos de programa\winantiviruspro2006freeinstall_es[1].exe
Risk: Low

Name: Not-A-Virus.Downloader.Win32.WinFixer.o
Path: C:\Documents and Settings\Trabajo\Mis documentos\WinAntiVirusPro2006FreeInstall_es.exe
Risk: Low

Name: Not-A-Virus.Downloader.Win32.WinFixer.o
Path: C:\WINDOWS\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
Risk: Low

Name: Downloader.Adload.fv
Path: C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe
Risk: High

Name: Downloader.Adload.fu
Path: C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe
Risk: High

Name: Downloader.Adload.fv
Path: C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe
Risk: High

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\cpmres.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\ctrtmgr.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\dnsynth.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\dSdxof.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\f2l00c3mef.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\gpn4l35q1.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\gpnol3531.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\guard.tmp
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\h04mlah11d4.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\h62o0gf3e62.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\iheshare.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\ktpul7791.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\kxdarme.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\l60ulgd9160.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\lv4409hqe.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\m0rm0a91ed.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\o0lu0a39ed.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\u6rulg9916.dll
Risk: Medium

Name: Adware.Look2Me
Path: C:\WINDOWS\system32\vjs_ps.dll
Risk: Medium


Salu2

Fulgore
14/10/06, 23:44:40
Holas. Los archivos infectados que te mostro el ewido... Los eliminaste utilizando su opcion???

Mientras contestas, haz esto:


:1: Descarga la herramienta Killbox (http://www.forospyware.com/49-post6.html)
:2: Activa la opcion Ver Archivos Ocultos (http://www.forospyware.com/46-post3.html)
:3: Apaga la opcion Restaurar Sistema (http://www.forospyware.com/45-post2.html) si tienes Windows ME o XP.
:4: Entra en Modo Seguro (http://www.forospyware.com/47-post4.html)
:5: Ejecuta el killbox, y borra lo siguiente:

C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GABPHUJ0\loader[1].exe
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\drsmartload45a[1].exe
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\GSCX8M8D\newabc[1].jpg
C:\WINDOWS\system32\config\systemprofile\Configura ción local\Archivos temporales de Internet\Content.IE5\Y2XM3K7C\nwnmff_e[1].exe

Es importante que pases la herramienta Disk Cleaner (http://www.forospyware.com/48-post5.html) y elimines TODAS las cookies y temporales.

Realizas un nuevo escaneo online, y lo pegas para ver como queda todo.
Suerte :Bien:

© Copyright 2005 - 2008 InfoSpyware ® Todos los derechos reservados.
InfoSpyware Security Blog