Ver la Versión Completa : Virus Bush!!!


LorenaCai
30/06/07, 18:07:58
AYUDAA!!!!! Desde hace una semana, tengo el virus Bush en mi ordenador.... he probado como 6 Spyware distintos...::stress:: y ninguno da resultado!! he seguido consejos que habeis dado a otros usuarios aqui, como por ejemplo pasar el Ewido Scanner Online y despues el Kaspersky, y despues de pasar el Kaspersky esto es lo que he guardado:


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, June 30, 2007 11:12:12 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 30/06/2007
Kaspersky Anti-Virus database records: 356005
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 78622
Number of viruses found: 5
Number of infected objects: 17 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:09:34

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Archivos comunes\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDCON.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDFW.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Archivos de programa\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Archivos de programa\Norton AntiVirus\AVError.log Object is locked skipped
C:\Archivos de programa\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Archivos de programa\Norton AntiVirus\Savrt\0457NAV~.TMP Object is locked skipped
C:\Archivos de programa\Norton AntiVirus\Savrt\0539NAV~.TMP Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\HPPAppActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\HPPHomePageActivity.log Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\ApplicationHistory\hpqimzone.exe.12eac55c .ini.inuse Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\Perflib_Perfdata_d60.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\~DF171A.tmp Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\~DFBBB7.tmp Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\Historial\History.IE5\MSHist012007063020070 701\index.dat Object is locked skipped
C:\Documents and Settings\Lorena Vargas\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Lorena Vargas\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043606.inf Infected: Trojan.Win32.Agent.amp skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043607.inf Infected: Trojan.Win32.Agent.amp skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043608.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043609.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043610.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043611.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043612.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043613.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043614.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043615.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043616.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043617.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043618.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043619.exe Infected: Email-Worm.Win32.Brontok.q skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043620.exe Infected: Trojan.Win32.VB.aqt skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043621.dll Infected: not-a-virus:AdWare.Win32.Altnet.b skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP250\A0043622.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP252\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{81730E 46-134B-4702-9CFB-88AABA65620A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Ya no se que mas puedo hacer ... :chillando

Gracias

Sveshnikov
30/06/07, 18:38:29
Hola LorenaCai realiza lo siguiente:

1. Apaga restaurar sistema (http://www.forospyware.com/292280-post2.html)

2. Reinicia tu pc

3. Deshacer el paso 1.

4. Realiza un nuevo análisis con kaspersky y pega el reporte.

Nos comentas...

Salu2!!:Bien::Bien:

"El Dutche"
30/06/07, 18:42:28
Fijate aquí en este link donde una persona con tu mismo problema pudo solucionar su problema con el virus Bush.

http://www.forospyware.com/t71053.html

LorenaCai
01/07/07, 09:09:43
Hola, he seguido los pasos que me has marcado y he vuelto a pasar el Kaspersky, y este ha sido el resultado:



Sunday, July 01, 2007 3:04:10 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 1/07/2007
Kaspersky Anti-Virus database records: 356210


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics
Total number of scanned objects 72044
Number of viruses found 1
Number of infected objects 1
Number of suspicious objects 0
Duration of the scan process 01:12:07

Infected Object Name Virus Name Last Action
C:\Archivos de programa\ESET\cache\CACHE.NDB Object is locked skipped

C:\Archivos de programa\ESET\logs\virlog.dat Object is locked skipped

C:\Archivos de programa\ESET\logs\warnlog.dat Object is locked skipped

C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Datos de programa\Symantec\Norton AntiVirus\Quarantine\5EE11633.inf Infected: Trojan.Win32.Agent.amp skipped

C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\ApplicationHistory\hpqimzone.exe.12eac55c .ini.inuse Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\hpodvd09.log Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\~DFA6EE.tmp Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Configuración local\Temp\~DFF894.tmp Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Historial\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\Historial\History.IE5\MSHist012007070120070 702\index.dat Object is locked skipped

C:\Documents and Settings\Lorena Vargas\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Lorena Vargas\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Lorena Vargas\UserData\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{63A4945D-5EBF-4682-9870-D32280407B10}\RP1\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Pd: AH! y si tengo problemas con el messenger, se me bloquea, manda el virus a todos mis contactos continuamente, hace q me parpadee la pantalla e incluso abre el window messenger con otra cuenta q no es la mia y manda el virus tambien, y por mas q lo cierre, q quite la opcion del msn para q no se abra solo da igual... se abre.

Gracias ^^

thecat_re
01/07/07, 11:22:09
Hola



Pd: AH! y si tengo problemas con el messenger, se me bloquea, manda el virus a todos mis contactos continuamente, hace q me parpadee la pantalla e incluso abre el window messenger con otra cuenta q no es la mia y manda el virus tambien, y por mas q lo cierre, q quite la opcion del msn para q no se abra solo da igual... se abre.

Gracias ^^

Bueno el Reporte Muestra solo una Infeccion y esta en la Cuarentena del Norton, (Eliminalo) o Busca este Carpet y elimina su Contenido:

C:\Documents and Settings\All Users\Datos de programa\Symantec\Norton AntiVirus\Quarantine\ (El contenido, no la carpeta)


En Cuanto a tus Problemas con el Msn Realiza lo Siguiente:

Realiza los Pasos del msncleaner (http://www.forospyware.com/t92153.html#post398656)

Descargar Ccleaner-Manual (http://www.forospyware.com/t39511.html) y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad). Realiza Varios Analisis

Realiza estos dos Scan Online:

Ewido (http://www.forospyware.com/foro-de-virus-y-spywares/aviso-7.html) (lee el Manual (http://www.forospyware.com/t42048.html)) [Luego del Escaneo le das a Remove Infections]

Realiza un escaneo online con "Panda ActiveScan Online" (http://www.forospyware.com/foro-de-virus-y-spywares/aviso-7.html) y nos dejas sus reportes en este mismo mensaje.

Saludos Nos Comentas :Bien:

LorenaCai
01/07/07, 17:13:48
Incidencia Estado Elemento

Virus:Trj/Downloader.PDV Desinfectado C:\WINDOWS\Cabs.exe
Virus:Trj/Downloader.PDV Desinfectado C:\WINDOWS\kter.exe
Virus:Trj/Downloader.PDV Desinfectado C:\WINDOWS\noper.exe
Virus:Trj/Downloader.PDV Desinfectado C:\WINDOWS\system32\gido.exe
Virus:Trj/Downloader.PDV Desinfectado C:\WINDOWS\system32\sipu.exe
Esto es lo que he copiado despues de pasar el Panda Activescan ... ahora probare si me da problemas el msn o no... a cruzar los dedos! jejeje
Muchisimas gracias a todos

LorenaCai
01/07/07, 18:09:18
Bueno, ese resultado q he puesto del Panda ActiveScan se la he pasado a los discos duros, ahora se lo estoy pasando a "Mi PC" y ya va por 4 Spyware q no ha eliminado y 1 Herramientas de de hacking y rootkits... ::ups:: :chillando

LorenaCai
01/07/07, 18:29:07
Incidencia Estado Elemento

Virus:Trj/Downloader.PDV Desinfectado Sistema Operativo
Adware:adware/savenow No desinfectado Registro de Windows
Adware:adware/whenusearch No desinfectado Registro de Windows
Adware:adware/rxtoolbar No desinfectado Registro de Windows
Herramienta potencialmente no deseada:application/altnet No desinfectado HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496}
Spyware:Cookie/Atlas DMT No desinfectado C:\Documents and Settings\Lorena Vargas\Cookies\lorena_vargas@atdmt[2].txt




Este es el informe del Panda ActiveScan en Mi PC :chillando

Deoxys
01/07/07, 19:04:26
Olaaaaaaaaaaaaaaaaaa!

Como nadie esta, te atiendo :rolleyes:

Descarga la siguiente herramienta:

RegSeeker (http://www.forospyware.com/t713.html)


:1: Primero que nada, apagaremos restaurar sistema (http://www.forospyware.com/292280-post2.html), para evitarnos complicaciones :afirmar:

:2: Posterior a esto, desinstala todo lo que tenga que ver con el altnet (si lo tubieras) y si quieres algun programa P2P (para bajar musica) puedes optar por alguno de los que aparecen aca (http://www.forospyware.com/t7.html), que no tienen nada de malo :negar:

:3: Despues, como ya te han dicho, realiza un escaneo con Ewido Online Scanner (http://www.forospyware.com/t42048.html) y le das en Remove infections cuando acabe de escanear tu PC, nos pasas el reporte

:4: Y por ultimo limpias temporales con el CCleaner

Realizas otro escaneo y nos cuentas como te fue

Salu2!

© Copyright 2005 - 2008 InfoSpyware ® Todos los derechos reservados.
InfoSpyware Security Blog