| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| |||
| Problemas con virus Que tal, recurro a ustedes despues de haberme intentado deshacer de estos virus por casi todos los medios , tengo el Symantec Antivirus, que ha detectado el Troyan.Zlob, Troyan.Emcodec, Troyan.Zonebac y el W32.IMAUT.N, luego siguiendo la recomendacion de esta pagina le pase el Ewido (se cerro antes de completar el escaneo) lo mismo paso con el Panda (iban 6 virus detectados cuando se cerro) y Kaspersky (solo a las areas criticas, que si lo pasaba a todos los discos se demoraria un dia entero cuando menos, pues es uno de 80 GB y otro de 250GB casi llenos) y el informe es el siguiente:------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER INFORME viernes, 26 de octubre de 2007 11:50:50 Sistema operativo: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner versión: 5.0.84.1 Ultima actualización: 26/10/2007 Registros en la base antivirus: 419170 ------------------------------------------------------------------------------- Configuración del análisis: Analizar usando las siguientes bases: standard Analizar archivos: verdadero Analizar bases de correo: verdadero Objetivo a analizar - Áreas críticas: C:\WINDOWS C:\DOCUME~1\DLucero\CONFIG~1\Temp\ Estadísticas: Número de objeros analizados: 53824 Virus encontrados: 1 Objetos infectados: 1 / 0 Objetos sospechosos: 0 Duración del análisis: 00:43:51 Bombre del objeto infectado / Nombre del virus / Última acción C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado C:\WINDOWS\SchedLgU.Txt Object is locked saltado C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked saltado C:\WINDOWS\Sti_Trace.log Object is locked saltado C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\default Object is locked saltado C:\WINDOWS\system32\config\default.LOG Object is locked saltado C:\WINDOWS\system32\config\Internet.evt Object is locked saltado C:\WINDOWS\system32\config\ODiag.evt Object is locked saltado C:\WINDOWS\system32\config\OSession.evt Object is locked saltado C:\WINDOWS\system32\config\SAM Object is locked saltado C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\SECURITY Object is locked saltado C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado C:\WINDOWS\system32\config\software Object is locked saltado C:\WINDOWS\system32\config\software.LOG Object is locked saltado C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\system Object is locked saltado C:\WINDOWS\system32\config\system.LOG Object is locked saltado C:\WINDOWS\system32\drivers\sptd.sys Object is locked saltado C:\WINDOWS\system32\h323log.txt Object is locked saltado C:\WINDOWS\system32\secure32.html Infectados: Trojan.Win32.Harnig.a saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado C:\WINDOWS\Temp\Perflib_Perfdata_20c.dat Object is locked saltado C:\WINDOWS\wiadebug.log Object is locked saltado C:\WINDOWS\wiaservc.log Object is locked saltado C:\WINDOWS\WindowsUpdate.log Object is locked saltado C:\DOCUME~1\DLucero\CONFIG~1\Temp\~DF5AFB.tmp Object is locked saltado C:\DOCUME~1\DLucero\CONFIG~1\Temp\~DF5B16.tmp Object is locked saltado C:\DOCUME~1\DLucero\CONFIG~1\Temp\~DF69F2.tmp Object is locked saltado C:\DOCUME~1\DLucero\CONFIG~1\Temp\~DF98BB.tmp Object is locked saltado C:\DOCUME~1\DLucero\CONFIG~1\Temp\~DF9C01.tmp Object is locked saltado Análisis completado. Los problemas que me dan estos virus son: - Cada vez que doy anticlick en el boton Inicio, en el escritorio o en alguna carpeta del explorador de windows, me sale el aviso de configuracion del Symanyec, pidiendome un archivo y cuando lo cancelo me da el error 1706. - Cuando trabajo con el IE 7, sin mediar aviso empiezan a cargarse multiples pestañas, con lo cual saturan los recursos del sistema, y tengo que matar el proceso. Ojala puedan darme una mano con esto, pues no quisiera formatearla por la cantidad de informacion que tendria que mover y por los programas instalados con los que trabajo. Salu2. |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: Problemas con virus Hola Fox83 bienvenido al foro realiza lo siguiente: - Activas ver archivos ocultos. - Inicias en modo a prueba de fallos y buscas y eliminas: C:\WINDOWS\system32\secure32.html Eliminas lo marcado en rojo y si no puedes usa FileASSASSIN - Actulizas y ejecutas SUPERAntispyware. - Ejecuta Ccleaner en sus opciones de limpiador y registro este último pásalo hasta que no te salga nada, cualquier duda lees su manual. - Ejecuta Ewido-Micro no olvides darle al final en la opción REMOVE INFECTIONS. Luego reinicias en modo normal y realizas un escaneo online con: - Kaspersky Online Scanner cualquier duda sobre este último lees su manual y pegas el reporte que te da de resultado. PD pero hazlo no solo en las areas criticas pues sino en todo tu pc dado que puedes estar infectado mucho más y asi sabremos que tipo de infeccion tienes y nos ayudara para guiarte. Última edición por Sikartus fecha: 26/10/07 a las 14:47:47. |
![]() | ![]() |
| |||
| Re: Problemas con virus Gracias por la bienvenida y las recomendaciones Sikartus, he seguido todos los pasos, y despues de 8 horas de escaneo aqui les pongo el reporte del Kaspersky, he estado viendolo y la mayoria de virus que ha detectado son los que el symantec ya tiene en cuarentena, sin embargo, siguen dando lata, pues el problema del mensaje de windows update (cada vez que doy anticlick sobre el escritorio o exploraror d windows) sigue sucediendo, a ver si me pueden sugerir algun antivirus que mate a todos estos virus :S, salu2. ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Saturday, October 27, 2007 6:47:47 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 27/10/2007 Kaspersky Anti-Virus database records: 419645 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ Scan Statistics: Total number of scanned objects: 388614 Number of viruses found: 37 Number of infected objects: 123 Number of suspicious objects: 0 Duration of the scan process: 07:56:38 Infected Object Name / Virus Name / Last Action C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\master.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\mastlog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\model.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\modellog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\tempdb.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\Data\templog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL\LOG\ERRORLOG Object is locked skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00BC0000.VBN Infected: Email-Worm.Win32.Rays skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140000.VBN Infected: Trojan-Clicker.Win32.Costrat.af skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140001.VBN Infected: Trojan-Clicker.Win32.Costrat.af skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140002.VBN Infected: Trojan-PSW.Win32.Sinowal.bv skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140003.VBN Infected: Trojan-PSW.Win32.Sinowal.bv skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140004.VBN Infected: Email-Worm.Win32.Banwarum.l skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140005.VBN Infected: Email-Worm.Win32.Banwarum.l skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140006.VBN Infected: Trojan-Downloader.Win32.Small.dgk skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01140007.VBN Infected: Trojan-Downloader.Win32.Small.dgk skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\021C0000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\021C0001.VBN Infected: Trojan-Downloader.Win32.Small.edb skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02200001.VBN Infected: Email-Worm.Win32.Runouce.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02200002.VBN Infected: Net-Worm.Win32.Nimda skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02200003.VBN Infected: Net-Worm.Win32.Nimda skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02440001.VBN Infected: Trojan-Dropper.Win32.Small.apl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02540000.VBN Infected: Trojan-PSW.Win32.QQRob.hl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02580000.VBN Infected: Email-Worm.Win32.Rays skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600001.VBN Infected: Email-Worm.Win32.Runouce.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600002.VBN Infected: Net-Worm.Win32.Nimda skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600003.VBN Infected: Email-Worm.Win32.Runouce.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02680000.VBN Infected: Trojan-Downloader.JS.Agent.kd skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02700000.VBN Infected: Trojan-PSW.Win32.QQRob.hl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\027C0000.VBN Infected: Worm.Win32.Small.i skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02840000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00000.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00001.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00002.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00003.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00004.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02A00005.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02B40000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02B40001.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03D40000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04340000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00000.VBN/Setup.exe Infected: P2P-Worm.Win32.Kapucen.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00000.VBN ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00000.VBN CryptZ: infected - 1 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.alj skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN/stream Infected: Trojan-Downloader.Win32.Zlob.alj skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN NSIS: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00002.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00004.VBN Infected: Trojan-Downloader.Win32.Zlob.bai skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00006.VBN Infected: Trojan-Downloader.Win32.Zlob.bai skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.alj skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN/stream Infected: Trojan-Downloader.Win32.Zlob.alj skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN NSIS: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04C00008.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00000.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00001.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00002.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00003.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00004.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00005.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04D00006.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\054C0000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05540001.VBN Infected: Trojan-PSW.Win32.QQRob.hl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\055C0000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\066C0000.VBN Infected: Virus.VBS.Small.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\068C0000.VBN Infected: Trojan-PSW.Win32.QQRob.hl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06900000.VBN Infected: Trojan.Win32.Agent.fx skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06D40000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06D40001.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN Infected: Email-Worm.Win32.Brontok.q skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07200000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07900000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08500000.VBN/data0002 Infected: Trojan.Win32.VB.ami skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08500000.VBN NSIS: infected - 1 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08500000.VBN CryptZ: infected - 1 skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08900000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08980000.VBN Infected: Trojan-PSW.Win32.QQRob.hl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08BC0000.VBN Infected: Backdoor.Win32.Agent.ahj skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08BC0001.VBN Infected: Trojan.Win32.Agent.fx skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08CC0000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08CC0001.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E40001.VBN Infected: Trojan-Downloader.Win32.Zlob.bai skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E40002.VBN Infected: Trojan-Downloader.Win32.Zlob.bgf skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E40003.VBN Infected: Trojan-Downloader.Win32.Zlob.asl skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E40004.VBN Infected: Trojan-Downloader.Win32.Zlob.atg skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08E40005.VBN Infected: Trojan-Downloader.Win32.Zlob.atg skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09000000.VBN Infected: Worm.Win32.Small.i skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\093C0000.VBN Infected: Virus.Win32.AutoRun.ji skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09440000.VBN Infected: Net-Worm.Win32.Nimda skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09440001.VBN Infected: Net-Worm.Win32.Nimda skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09500000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09780000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\097C0000.VBN Infected: Trojan-Downloader.Win32.Agent.acd skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09B00000.VBN Infected: Email-Worm.Win32.Alanis skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09D00000.VBN Infected: Packed.Win32.NSAnti.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09E80000.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09E80001.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09E80002.VBN Infected: Worm.Win32.AutoIt.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A000000.VBN Infected: Worm.Win32.Sachiel.d skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A100000.VBN Infected: Trojan-Downloader.Win32.Agent.acd skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A300000.VBN Infected: Trojan-Downloader.Win32.Agent.acd skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A300001.VBN Infected: Trojan-Downloader.VBS.Mscount.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A680000.VBN Infected: Email-Worm.Win32.Brontok.q skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A940000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AB40000.VBN Infected: Backdoor.Win32.Tompai.b skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AC00000.VBN Infected: Trojan-Downloader.VBS.Mscount.a skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CC40000.VBN Infected: Trojan-PSW.Win32.Sinowal.bi skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CC40001.VBN Infected: Trojan-Downloader.VBS.Mscount.a skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRF{6046D8DD-7275-4F63-AE03-A495D851664B}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRS{0BE4E4CE-FA83-44BA-8C56-4270F7D2C968}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRS{20C24BA7-7F25-4E70-B476-CC637889AA95}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRS{84FE103E-3305-43D9-B4F2-897F76A24DDB}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRS{A3E23A5C-2916-4927-A61D-ED992E3F3670}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.Word\~WRS{BECD80FE-6BE0-4980-90E2-812C4498633C}.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Datos de programa\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Historial\History.IE5\MSHist0120071027200710 28\index.dat Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Temp\~DF4406.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Temp\~DF7097.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Temp\~DF9C85.tmp Object is locked skipped C:\Documents and Settings\DLucero\Configuración local\Temp\~DFCFB2.tmp Object is locked skipped C:\Documents and Settings\DLucero\Cookies\index.dat Object is locked skipped C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Plantillas\Normal.dotm Object is locked skipped C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\Guardado con Autorrecuperación de leonsito.asd Object is locked skipped C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRA0002.as$ Object is locked skipped C:\Documents and Settings\DLucero\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SUP ERANTISPYWARE.LOG Object is locked skipped C:\Documents and Settings\DLucero\Mis documentos\Leones\leonsito.doc Object is locked skipped C:\Documents and Settings\DLucero\Mis documentos\Leones\~WRL2332.tmp Object is locked skipped C:\Documents and Settings\DLucero\Mis documentos\Servicios Metálicos Ruiz.doc Object is locked skipped C:\Documents and Settings\DLucero\Mis documentos\~WRL1113.tmp Object is locked skipped C:\Documents and Settings\DLucero\NTUSER.DAT Object is locked skipped C:\Documents and Settings\DLucero\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped C:\WINDOWS\system32\config\OSession.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_21c.dat Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\EMule\Incoming\Autodesk 3Ds Max 9 Keygen updated-fixed 02-2007.rar/setup.exe Infected: P2P-Worm.Win32.Kapucen.b skipped D:\EMule\Incoming\Autodesk 3Ds Max 9 Keygen updated-fixed 02-2007.rar RAR: infected - 1 skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped E:\Archivos de programa\DAP\History\DLucero\20061029.dat Object is locked skipped E:\Archivos de programa\DAP\History\DLucero\_lasthist.dat Object is locked skipped E:\Archivos de programa\DAP\Log\DAP_REPORT.LOG Object is locked skipped E:\Archivos de programa\DAP\Log\DAP_WIZARD.LOG Object is locked skipped E:\Archivos de programa\DAP\Temp\ADS1C.tmp.dap Object is locked skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar/[Captivate][1.1.1290¡ÎÑ+¬®][Macromedia].rar/[Captivate][1.1.1290][Macromedia]/-+¤±+Ý+¦Macromedia Captivate1.1.1290/MACROMEDIA_CAPTIVATE_V1.0_key.exe/Attach Infected: Backdoor.Win32.Hupigon.abu skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar/[Captivate][1.1.1290¡ÎÑ+¬®][Macromedia].rar/[Captivate][1.1.1290][Macromedia]/-+¤±+Ý+¦Macromedia Captivate1.1.1290/MACROMEDIA_CAPTIVATE_V1.0_key.exe Infected: Backdoor.Win32.Hupigon.abu skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar/[Captivate][1.1.1290¡ÎÑ+¬®][Macromedia].rar/[Captivate][1.1.1290][Macromedia]/-+¤±+Ý+¦Macromedia Captivate1.1.1290/capcn.exe/Attach Infected: Backdoor.Win32.Hupigon.abu skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar/[Captivate][1.1.1290¡ÎÑ+¬®][Macromedia].rar/[Captivate][1.1.1290][Macromedia]/-+¤±+Ý+¦Macromedia Captivate1.1.1290/capcn.exe Infected: Backdoor.Win32.Hupigon.abu skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar/[Captivate][1.1.1290¡ÎÑ+¬®][Macromedia].rar Infected: Backdoor.Win32.Hupigon.abu skipped E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar RAR: infected - 5 skipped E:\Documents and Settings\All Users\Datos de programa\Microsoft\Dr Watson\user.dmp Object is locked skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\028C0000.VBN Infected: Backdoor.Win32.Tompai.b skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08100000.VBN Infected: Virus.VBS.Redlof.n skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09500000.VBN Infected: Trojan-Downloader.Win32.Zlob.aue skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0ADC0000.VBN Infected: Trojan-Downloader.Win32.Zlob.aue skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0B6C0000.VBN Infected: Trojan-Downloader.Win32.Zlob.aue skipped E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C680000.VBN Infected: Trojan-Downloader.Win32.Zlob.aue skipped E:\Documents and Settings\DLucero\Configuración local\Archivos temporales de Internet\Content.IE5\E737MJ1Q\index11[1].htm Infected: Trojan-Downloader.JS.Psyme.hz skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\Daniel\Samples\pro_reggaeton_kit4_2006.zip/pro_reggaeton_kit4_2006.exe/msnmsgr.exe Infected: Backdoor.Win32.SdBot.akr skipped F:\Daniel\Samples\pro_reggaeton_kit4_2006.zip/pro_reggaeton_kit4_2006.exe Infected: Backdoor.Win32.SdBot.akr skipped F:\Daniel\Samples\pro_reggaeton_kit4_2006.zip ZIP: infected - 2 skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000222.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000223.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000224.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000225.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000226.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000227.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000228.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000229.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000230.ver Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000231.inf Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000232.cat Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000233.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000234.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000235.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000236.ver Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000237.inf Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000238.cat Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000239.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000240.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000241.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000242.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000243.exe Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000244.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000245.dll Object is locked skipped F:\System Volume Information\_restore{81AC2875-C7CB-41C3-94F8-DA92879DB241}\RP7\A0000246.exe Object is locked skipped Scan process completed. |
![]() | ![]() |
| ||||
| Re: Problemas con virus Hola fox83 Realiza lo Siguiente: Apagar el "Restaurar Sistema" (solo Win Me y XP) en todas las unidades. Elimina la Cuarentena del Symantec , o elimina el CONTENIDO de la siguiente carpeta: C:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine E:\Documents and Settings\All Users\Datos de programa\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine Descargate OTMoveIt lo guardas en el Escritorio.
Cita:
Envía el informe (reporte) de OTMoveIt situado sobre C: \ _ OTMoveIt\MovedFiles. Descarga la herramienta SDFix y guardala y descomprimila en tu escritorio pero no la ejecutes aun. Reinicia el PC a Modo a prueba de fallos (Modo seguro)
Reinicia el PC a "Modo normal" Saludos nos comentas, "Lo difícil se hace y lo imposible se intenta" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Problemas con virus Que tal thecat_re, gracias por tu rapida respuesta, hice lo que me dijiste y estos son los resultados (por cierto, el problema sigue como siempre )Reporte OTMoveIt D:\EMule\Incoming\Autodesk 3Ds Max 9 Keygen updated-fixed 02-2007.rar moved successfully. E:\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar moved successfully. F:\Daniel\Samples\pro_reggaeton_kit4_2006.zip moved successfully. Created on 10/27/2007 19:49:38 Reporte SDFIX SDFix: Version 1.112 Run by DLucero on 27/10/2007 at 20:34 Microsoft Windows XP [Versi¢n 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting... Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\SYSTEM32\NSPRS.DLL - Deleted C:\WINDOWS\SYSTEM32\SERAUTH1.DLL - Deleted C:\WINDOWS\SYSTEM32\SERAUTH2.DLL - Deleted C:\WINDOWS\SYSTEM32\SSPRS.DLL - Deleted C:\277244~1 - Deleted C:\Documents and Settings\DLucero\Datos de programa\Install.dat - Deleted C:\DOCUME~1\DLucero\CONFIG~1\Temp\abc123.pid - Deleted Removing Temp Files... ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Archivos de programa\\Ares\\Ares.exe"="C:\\Archivos de programa\\Ares\\Ares.exe:*:Enabled:Ares" "C:\\Archivos de programa\\MSN Messenger\\msncall.exe"="C:\\Archivos de programa\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "C:\\Archivos de programa\\Messenger\\msmsgs.exe"="C:\\Archivos de programa\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Archivos de programa\\eMule\\emule.exe"="C:\\Archivos de programa\\eMule\\emule.exe:*:Enabled:eMule" "C:\\Archivos de programa\\Mozilla Firefox\\firefox.exe"="C:\\Archivos de programa\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox" "C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS \\system32\\rtcshare.exe:*:Disabled:Uso compartido de aplicaciones RTC" "C:\\Archivos de programa\\discreet\\combustion 4\\combustion.exe"="C:\\Archivos de programa\\discreet\\combustion 4\\combustion.exe:*:Enabled:combustion" "C:\\Archivos de programa\\Autodesk\\3dsMax8\\3dsmax.exe"="C:\\Arch ivos de programa\\Autodesk\\3dsMax8\\3dsmax.exe:*:Enabled: Autodesk 3ds Max 8" "C:\\Archivos de programa\\Autodesk\\backburner\\monitor.exe"="C:\\ Archivos de programa\\Autodesk\\backburner\\monitor.exe:*:Enab led:backburner 2.3 monitor" "C:\\Archivos de programa\\Autodesk\\backburner\\manager.exe"="C:\\ Archivos de programa\\Autodesk\\backburner\\manager.exe:*:Enab led:backburner 2.3 manager" "C:\\Archivos de programa\\Autodesk\\backburner\\server.exe"="C:\\A rchivos de programa\\Autodesk\\backburner\\server.exe:*:Enabl ed:backburner 2.3 server" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Archivos de programa\\FlashGet\\flashget.exe"="C:\\Archivos de programa\\FlashGet\\flashget.exe:*:Enabled:Flashge t" "C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook" "C:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove" "C:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote" "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"="C:\\WINDOWS\\system32\\spool\\drive rs\\w32x86\\3\\SAGENT4.EXE:*:Enabled:SAgent4" "C:\\Archivos de programa\\Chaos Group\\V-Ray\\3dsmax R9 for x86\\vrlserver.exe"="C:\\Archivos de programa\\Chaos Group\\V-Ray\\3dsmax R9 for x86\\vrlserver.exe:*:Enabled:VRLServer" "C:\\Archivos de programa\\Java\\jdk1.6.0_01\\jre\\bin\\java.exe"=" C:\\Archivos de programa\\Java\\jdk1.6.0_01\\jre\\bin\\java.exe:*: Enabled:Java(TM) Platform SE binary" "C:\\Archivos de programa\\Internet Explorer\\iexplore.exe"="C:\\Archivos de programa\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer" "C:\\Archivos de programa\\EA SPORTS\\2002 FIFA World Cup TM\\fifawc.exe"="C:\\Archivos de programa\\EA SPORTS\\2002 FIFA World Cup TM\\fifawc.exe:*:Enabled:fifawc" "C:\\Archivos de programa\\ASUS\\AsusUpdate\\Update.exe"="C:\\Archi vos de programa\\ASUS\\AsusUpdate\\Update.exe:*:Enabled:A SUS Update" "C:\\Documents and Settings\\DLucero\\Mis documentos\\Adlm\\mirc.exe"="C:\\Documents and Settings\\DLucero\\Mis documentos\\Adlm\\mirc.exe:*:Enabled:mIRC" [HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Archivos de programa\\MSN Messenger\\msncall.exe"="C:\\Archivos de programa\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files: --------------- File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: Mon 15 Jan 2007 88 ..SHR --- "C:\WINDOWS\system32\6555BF6F75.sys" Tue 23 Oct 2007 5,224 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys" Fri 24 Nov 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Fri 21 Sep 2007 75,264 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL0001.tmp" Sat 22 Sep 2007 32,768 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL0002.tmp" Mon 13 Aug 2007 1,596,416 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL0005.tmp" Thu 20 Sep 2007 39,936 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL0006.tmp" Mon 6 Aug 2007 1,597,952 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL0273.tmp" Mon 6 Aug 2007 44,032 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\~WRL2626.tmp" Fri 12 Nov 2004 37,376 ...H. --- "C:\Archivos de programa\Archivos comunes\Adobe\ESD\DLMCleanup.exe" Thu 23 Nov 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Thu 25 Jan 2007 25,088 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL0001.tmp" Fri 18 Aug 2006 24,064 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL0005.tmp" Tue 2 Jan 2007 33,792 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL3293.tmp" Mon 16 Jul 2007 52,224 ...H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL4004.tmp" Tue 28 Nov 2006 23,552 A..H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL{4C68E3A7-24A6-461B-95AC-2FDE0E78A55F}.tmp" Fri 10 Nov 2006 32,256 A..H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL{E0741285-FE4C-4B4C-990D-C885075235ED}.tmp" Mon 18 Sep 2006 24,064 A..H. --- "C:\Documents and Settings\DLucero\Mis documentos\SOBRINO\~WRL{F2FA4EF8-C68B-48E7-B5AB-2B0731458538}.tmp" Wed 2 May 2007 647,168 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL0002.tmp" Fri 7 Sep 2007 652,800 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL0003.tmp" Sat 6 Oct 2007 654,336 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL0004.tmp" Sun 3 Dec 2006 34,816 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL{3281C726-A5FB-45B0-ABE2-900433349C3F}.tmp" Mon 4 Dec 2006 23,552 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL{4B60DB18-785E-48DC-8349-D8BCE2B25715}.tmp" Sun 14 Jan 2007 794,624 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL{AC38B7AA-2107-494D-A09D-9F1A370D3A1C}.tmp" Sun 7 Jan 2007 22,528 ...H. --- "C:\Documents and Settings\DLucero\Datos de programa\Microsoft\Word\~WRL{FCF01E06-5CB6-4A9E-BC54-2B6664A10AD8}.tmp" Wed 30 May 2007 54,520 A..H. --- "C:\Documents and Settings\All Users\Datos de programa\Microsoft\visualstudio\7.1\vs000223.tmp" Finished! |
![]() | ![]() |
| |||
| Re: Problemas con virus Buenas, sigo intentando deshacerme de estos virus que se resisten.... en esta oportunidad le hice un escaneo completo con el Panda Online, este es el log, a ver si me echan una mano, gracias ![]() Incidencia Estado Elemento Adware:adware/comet No desinfectado Registro de Windows Spyware:Cookie/YieldManager No desinfectado C:\Documents and Settings\DLucero\Cookies\dlucero@ad.yieldmanager[1].txt Spyware:Cookie/Weborama No desinfectado C:\Documents and Settings\DLucero\Cookies\dlucero@weborama[1].txt Spyware:Cookie/Xiti No desinfectado C:\Documents and Settings\DLucero\Cookies\dlucero@xiti[1].txt Spyware:Cookie/Weborama No desinfectado C:\Documents and Settings\DLucero\Datos de programa\Mozilla\Firefox\Profiles\xizltb8v.default \cookies.txt[.weborama.fr/] Spyware:Cookie/Casalemedia No desinfectado C:\Documents and Settings\DLucero\Datos de programa\Mozilla\Firefox\Profiles\xizltb8v.default \cookies.txt[.casalemedia.com/] Herramienta potencialmente no deseada:Application/Processor No desinfectado C:\Documents and Settings\DLucero\Escritorio\SDFix.exe[SDFix\apps\Process.exe] Herramienta potencialmente no deseada:Application/Processor No desinfectado C:\SDFix\apps\Process.exe Virus:Bck/Hupigon.AZG No desinfectado C:\_OTMoveIt\MovedFiles\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar[[Captivate][1.1.1290¡+Ñ+¬¬ Virus:W95/Marburg No desinfectado C:\_OTMoveIt\MovedFiles\Archivos de programa\eMule\Incoming\Macromedia Studio 8 Full Edition (Dreamweaver 8, Flash Pro 8, Fireworks 8, Contribute 3, Flashpaper 2, Coldfusion Mx 7 Developer Edition, Freehand Mx 11.0.2, Captivate).rar[[Captivate][1.1.1290¡+Ñ+¬¬ Virus:W32/Puce.E.worm No desinfectado C:\_OTMoveIt\MovedFiles\EMule\Incoming\Autodesk 3Ds Max 9 Keygen updated-fixed 02-2007.rar[setup.exe] Hacktool:Hacktool/MailBomber.F No desinfectado D:\EMule\Incoming\Panopticum Fire v2.5 For Premiere.zip[PANOPTICUM.FIRE.V2.5.FOR.PREMIERE/TNTPF25P.ZIP][PanFire25Prm.rar][PanFire25Prm.exe] Hacktool:Hacktool/MailBomber.F No desinfectado D:\EMule\Incoming\Panopticum Fire v2.5 For Premiere.zip[PANOPTICUM.FIRE.V2.5.FOR.PREMIERE/TNTPF25P/PanFire25Prm.rar][PanFire25Prm.exe] Hacktool:Hacktool/MailBomber.F No desinfectado D:\EMule\Incoming\Panopticum Fire v2.5 For Premiere.zip[PANOPTICUM.FIRE.V2.5.FOR.PREMIERE/TNTPF25P/PanFire25Prm/PanFire25Prm.exe] Virus:Generic Trojan No desinfectado E:\Archivos de programa\eMule\Incoming\Corel Painter Essentials 3.0] Corel Painter Essentials v3.0.rar[patch.exe] Spyware:Cookie/Cgi-bin No desinfectado E:\Documents and Settings\DLucero\Cookies\dlucero@cgi-bin[1].txt Spyware:Cookie/Cgi-bin No desinfectado E:\Documents and Settings\DLucero\Cookies\dlucero@cgi-bin[2].txt Spyware:Cookie/ademails No desinfectado E:\Documents and Settings\DLucero\Datos de programa\Mozilla\Firefox\Profiles\ejatd7mg.default \cookies.txt[.www.ademails.com/] Virus:Generic Malware Desinfectado F:\3DMAX\Maxwell\WinRAR[1].v3.42.Spanish.WinALL.READ.NFO-CHiCNCREAM.ZIP[WinRAR.v3.42.Spanish.WinALL.READ.NFO-CHiCNCREAM/patch.exe] Virus:Generic Malware Desinfectado F:\3DMAX\Maxwell\WinRAR[1].v3.42.Spanish.WinALL.READ.NFO-CHiCNCREAM.ZIP[WinRAR.v3.42.Spanish.WinALL.READ.NFO-CHiCNCREAM/patch2.exe] Posible Virus. No desinfectado F:\Daniel\cursos\Gestion Empresarial\PEN\MismaSXS.rar[MismaSXS.exe] Adware:Adware/SaveNow No desinfectado F:\Daniel\cursos\Gestion Empresarial\Videos\bsplayer211[1].940_clip.exe[BSplayer_WhenUSave_InstallerInst.exe] Virus:Generic Malware No desinfectado F:\Daniel\NFSCars\designsciencemathtypev5.1keygens sg.zip[Keygen.rar][mtype_v5_1_keygen.exe] Adware:Adware/MediaTickets No desinfectado F:\Nueva Miscelánea\tres_prog\PHPTRIADSETUP2_11.EXE Adware:Adware/nCase No desinfectado F:\RECYCLER\S-1-5-21-861567501-1078081533-1801674531-1003\Dd5.exe[saap.exe] Spyware:Spyware/New No desinfectado F:\RECYCLER\S-1-5-21-861567501-1078081533-1801674531-1003\Dd8.exe Adware:Adware/NavHelper No desinfectado F:\System Volume Information\_restore{3A8F13FA-154B-4591-AA6A-8C6930FE33C3}\RP21\A0011899.exe Adware:Adware/NavHelper No desinfectado F:\System Volume Information\_restore{62A3EC49-5FC5-443F-8DC1-723FC1C6F480}\RP47\A0011600.exe Adware:Adware/NavHelper No desinfectado F:\System Volume Information\_restore{62A3EC49-5FC5-443F-8DC1-723FC1C6F480}\RP71\A0082222.exe |
![]() | ![]() |
| ||||
| Re: Problemas con virus Hola Nuevamente La mayoria son archivos infectados que descargaste de E-mule, veamos si le das un freno a eso y los compras o los descargas de su web oficial, programas bajados de p2p la gran mayoria salen infectados. Realiza lo Siguiente: Apagar el "Restaurar Sistema" (solo Win Me y XP) Descargate OTMoveIt lo guardas en el Escritorio.
Cita:
Envía el informe (reporte) de OTMoveIt situado sobre C: \ _ OTMoveIt\MovedFiles. Elimina la Herramienta SdFix Descargar Ccleaner-Manual y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad). Realiza Varios Analisis Prende Restaurar Sistema Saludos Nos Comentas-. ![]() "Lo difícil se hace y lo imposible se intenta" Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. Última edición por thecat_re fecha: 29/10/07 a las 19:58:32. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| P2P-Worm.Win32.VB.dw | tav | Foro de Virus y Spywares | 5 | 20/01/07 14:01:29 |
| iexplorer debe cerrarse | kiwiwi | Foro Oficial de HijackThis en español | 12 | 18/12/06 18:43:59 |
| Ayuda con....edlm y edlm2 | anmanadu | Foro de Virus y Spywares | 1 | 23/05/06 22:40:01 |
| Problemas varios derivados de Spyware: creo que tengo un virus (Solucionado) | xaneme | Temas Solucionados | 10 | 07/01/06 20:48:34 |
| tenco un problema con la bara de tarea (solucionado) | mohadip | Temas Solucionados | 9 | 04/12/05 21:02:32 |