Blog Registrarse Manuales Programas Glosario

Regresar   Foro de Spyware » Spyware - Adware - Hijackers - Malwares » Temas Solucionados
 

Para evitar Virus, Spyware y otros Malwares, te recomendamos mantenerte informado en: InfoSpyware Blog


Temas Solucionados Casos de HijackThis y Malwares resueltos.
(Solo lectura)

Respuesta
 
Enviar a: Herramientas
  post #1  
Antiguo 13/03/08, 23:46:02
Usuario
 
Registrado: ene 2006
Ubicación: Mexico
Mensajes: 14
Adware Vundo Variant Resident (cerrado)

Hola.

Otra vez yo, dando lata.

Me aparece el Adware.Vundo Variant/Resident con el SUPERANTISPYWARE. 2 en memoria.
15 en entradas de registro.

En la mañana me contagiaron a traves del messenger, y lo logre quitar aparentemente, en modo a prueba de fallos, utilizando el Ccleanes, Superantispyware, DelPSGuard, y el HJ.


Hoy por la tarde, cuando me volvi a conectar al Messenger me di cuenta que el SUPERANTISPYWARE estaba desactivado.

Esto más encontre:

Ahorita que estoy analizando el disco duro, me doy cuenta que otra vez esta infectado.

Tan pronto como termine de revisar pego el informe correspondiente.

Ojala me puedan ayudar.
Gracias.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/13/2008 at 09:51 PM

Application Version : 4.0.1154

Core Rules Database Version : 3419
Trace Rules Database Version: 1411

Scan type : Complete Scan
Total Scan Time : 01:18:15

Memory items scanned : 378
Memory threats detected : 1
Registry items scanned : 5943
Registry threats detected : 14
File items scanned : 206611
File threats detected : 4

Adware.Vundo Variant/Resident
C:\WINDOWS\SYSTEM32\SSTTS.DLL
C:\WINDOWS\SYSTEM32\SSTTS.DLL

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{0CF03575-048C-45F2-9ABE-227DEC79D109}
HKCR\CLSID\{0CF03575-048C-45F2-9ABE-227DEC79D109}
HKCR\CLSID\{0CF03575-048C-45F2-9ABE-227DEC79D109}\InprocServer32
HKCR\CLSID\{0CF03575-048C-45F2-9ABE-227DEC79D109}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{92415DD9-DC70-4BE6-9212-C4D779B1DC96}
HKCR\CLSID\{92415DD9-DC70-4BE6-9212-C4D779B1DC96}
HKCR\CLSID\{92415DD9-DC70-4BE6-9212-C4D779B1DC96}\InprocServer32
HKCR\CLSID\{92415DD9-DC70-4BE6-9212-C4D779B1DC96}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\MLLJI.DLL
HKLM\Software\Classes\CLSID\{DF851736-4CD2-45B7-AAE8-AF657251A1AF}
HKCR\CLSID\{DF851736-4CD2-45B7-AAE8-AF657251A1AF}
HKCR\CLSID\{DF851736-4CD2-45B7-AAE8-AF657251A1AF}\InprocServer32
HKCR\CLSID\{DF851736-4CD2-45B7-AAE8-AF657251A1AF}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0CF03575-048C-45F2-9ABE-227DEC79D109}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{DF851736-4CD2-45B7-AAE8-AF657251A1AF}

Adware.Tracking Cookie
C:\Documents and Settings\Administrador\Cookies\administrador@atdmt[1].txt

Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\IJLLM.INI


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:56 p.m., on 13/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Log de HijackThis borrado

Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector.
No ponga su log de HijackThis aquí !!



El Spysweper me acaba de detectar esto:
C:\windows\system32\awtursp.dll

Despues me dijo que se quiere instalar una cosa como barra del navegador. inprocserver o algo asi.
Le dije que lo bloqueara. pero sigue dando lata.

Esto más he encontrado:

Running Applications

DDCCB.DLL ADWARE/Adware.Vundo-Variant.Process More Info
Description
Adware.Vundo-Variant.Process

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
Unknown Company Url/Website


File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build





Browser Extensions, Toolbars and Registry Applications

DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{120C2020-7351-4930-A1C2-389FAF872070}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{BEBFBAFF-AEB9-428C-9340-D5D6857AB704}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{C272EDDB-FFD8-43FD-957F-4688DBA0F882}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{E1AEA068-7FE7-45F9-850C-94D6BF6C6084}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{1CF47A08-E0C6-49EA-B266-EED125FC5010}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{4CA24C11-C63E-4CE3-9BB7-797B81F3DC6D}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{708C3B90-ABA2-4E60-9BF8-07343037C94A}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{83DBBEAA-2EEC-4F81-94DC-817698062597}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{8ED9D857-E936-4280-B0B9-10D086BC0FBB}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{95F63E6C-DB21-439E-A587-6503CE4D50BE}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{AB752B7C-5A30-4155-A9B1-CA903CA67ABC}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




DDCCB.DLL TROJAN/Trojan.WinFixer.Process More Info
Description
WinFixer 2006 (Unregistered version) Application by WinFixer. Known for "sleazy" tactics of promotion and installation.

File Location on your Computer
C:\WINDOWS\SYSTEM32\DDCCB.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{B4A709E6-944A-4505-9CFA-BAA95233FC86}
File Size (bytes)
292352 MD5 Checksum/Fingerprint
52985262AC84B6D310632A523D39FE94

Company Name
WinSoftware, Ltd. Company Url/Website
www.winfixer.com

File Version Information Show/Hide Version Information

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build





Startup Applications


Unrecognized Applications and Files Show/Hide Info


Running Applications

EGUI.EXE C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EGUI.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EGUI.EXE
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
1443072 MD5 Checksum/Fingerprint
D2A76033BC698A2428BA149214DE880D

File Version Information Show/Hide Version Information

Company Name
ESET
File Description
ESET GUI File Version
3.0.645
Product Name
ESET SMART SECURITY Product Version
3.0.645
Internal Name
EGUI.EXE Original File Name
EGUI.EXE
Legal Copyright
COPYRIGHT (C) ESET 1992-2008. ALL RIGHTS RESERVED. Legal Trademarks
NOD, NOD32, AMON, ESET ARE REGISTERED TRADEMARKS OF ESET.
Private Build
Special Build




EKRN.EXE C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EKRN.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EKRN.EXE
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
472320 MD5 Checksum/Fingerprint
DB135AFAF1B2112FE5C45D99CC202B26

File Version Information Show/Hide Version Information

Company Name
ESET
File Description
ESET SERVICE File Version
3.0.645
Product Name
ESET SMART SECURITY Product Version
3.0.645
Internal Name
EKRN.EXE Original File Name
EKRN.EXE
Legal Copyright
COPYRIGHT (C) ESET 1992-2008. ALL RIGHTS RESERVED. Legal Trademarks
NOD, NOD32, AMON, ESET ARE REGISTERED TRADEMARKS OF ESET.
Private Build
Special Build




FNPLICENSINGSERVICE.EXE C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MACROVISION SHARED\FLEXNET PUBLISHER\FNPLICENSINGSERVICE.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MACROVISION SHARED\FLEXNET PUBLISHER\FNPLICENSINGSERVICE.EXE
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
654848 MD5 Checksum/Fingerprint
227846995AFEEFA70D328BF5334A86A5

File Version Information Show/Hide Version Information

Company Name
MACROVISION EUROPE LTD.
File Description
ACTIVATION LICENSING SERVICE File Version
11.03.005
Product Name
FLEXNET PUBLISHER (32 BIT) Product Version

Internal Name
Original File Name

Legal Copyright
COPYRIGHT 2005-2006, MACROVISION EUROPE LTD. ALL RIGHTS RESERVED. Legal Trademarks

Private Build
Special Build




RAYSAT_3DSMAX2008_32SERVER.EXE C:\ARCHIVOS DE PROGRAMA\AUTODESK\3DS MAX 2008\MENTALRAY\SATELLITE\RAYSAT_3DSMAX2008_32SERVE R.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\AUTODESK\3DS MAX 2008\MENTALRAY\SATELLITE\RAYSAT_3DSMAX2008_32SERVE R.EXE
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
65536 MD5 Checksum/Fingerprint
AA0C4A2C33CE075DF2C272D678734991

File Version Information Show/Hide Version Information

Company Name

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




SSU.EXE C:\ARCHIVOS DE PROGRAMA\WEBROOT\SPY SWEEPER\SSU.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\WEBROOT\SPY SWEEPER\SSU.EXE
Registry Path and CLSID where file was detected on your Computer


File Size (bytes)
214384 MD5 Checksum/Fingerprint
52F8D97D643D83A537B7416A56B4096F

File Version Information Show/Hide Version Information

Company Name

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build





Browser Extensions, Toolbars and Registry Applications

AWTURSP.DLL C:\WINDOWS\SYSTEM32\AWTURSP.DLL More Info
File Location on your Computer
C:\WINDOWS\SYSTEM32\AWTURSP.DLL
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Explorer \Browser Helper Objects
{9714A10A-FBC6-4427-BA95-8409A403D1EF}
File Size (bytes)
36352 MD5 Checksum/Fingerprint
178BA11E0482FC488D645388D0B66341

File Version Information Show/Hide Version Information

Company Name

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build





Startup Applications

EGUI.EXE C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EGUI.EXE More Info
File Location on your Computer
C:\ARCHIVOS DE PROGRAMA\ESET\ESET NOD32 ANTIVIRUS\EGUI.EXE
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Run

File Size (bytes)
1443072 MD5 Checksum/Fingerprint
D2A76033BC698A2428BA149214DE880D

File Version Information Show/Hide Version Information

Company Name
ESET
File Description
ESET GUI File Version
3.0.645
Product Name
ESET SMART SECURITY Product Version
3.0.645
Internal Name
EGUI.EXE Original File Name
EGUI.EXE
Legal Copyright
COPYRIGHT (C) ESET 1992-2008. ALL RIGHTS RESERVED. Legal Trademarks
NOD, NOD32, AMON, ESET ARE REGISTERED TRADEMARKS OF ESET.
Private Build
Special Build




XINSIDE.EXE C:\WINDOWS\RAIDTOOL\XINSIDE.EXE More Info
File Location on your Computer
C:\WINDOWS\RAIDTOOL\XINSIDE.EXE
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Run

File Size (bytes)
36864 MD5 Checksum/Fingerprint
DB4E2D9C09A5762CB2551222B5E443B2

File Version Information Show/Hide Version Information

Company Name

File Description
File Version

Product Name
Product Version

Internal Name
Original File Name

Legal Copyright
Legal Trademarks

Private Build
Special Build




XRAIDSETUP.EXE C:\WINDOWS\SYSTEM32\XRAIDSETUP.EXE More Info
File Location on your Computer
C:\WINDOWS\SYSTEM32\XRAIDSETUP.EXE
Registry Path and CLSID where file was detected on your Computer
Software\Microsoft\Windows\CurrentVersion\Run

File Size (bytes)
1953792 MD5 Checksum/Fingerprint
16BB8D55CFE3303CB03EC5DB1776D946

File Version Information Show/Hide Version Information

Company Name
GIGABYTE TECHNOLOGY CORP.
File Description
GIGABYTE RAID CONFIGURER File Version
1.17.19.03G
Product Name
GIGABYTE RAID CONFIGURER Product Version
1.17.19.03G
Internal Name
XRAIDSETUP Original File Name
XRAIDSETUP.EXE
Legal Copyright
COPYRIGHT (C) GIGABYTE 2005-2008 Legal Trademarks

Private Build
Special Build



y HKLM\software\microsoft\removerp\

Última edición por Astareth fecha: 14/03/08 a las 00:49:26.
Responder Con Cita
InfoSpyware

  post #2  
Antiguo 14/03/08, 01:46:15
Avatar de axl456
Moderador
 
Registrado: mar 2007
Ubicación: South Park
Mensajes: 7.302
Re: Adware Vundo Variant Resident

Hola..

Realiza lo siguiente:
Descarga los siguientes programas:

Ejecuta el ccleaner en las opciones limpiador y luego en registro haciendo una copia del registro..


Ejecuta Malwarebytes' Anti-Malware A continuación realiza un escaneo completo del PC y elimina las infecciones que este detecte
.
NOTA: Esto es fundamental, mandalas a cuarentena y eliminalas desde alli y pegas el reporte generado despues de la eliminación.

El reporte queda guardado en la pestaña "Logs" o "Registros" en español, abres el reporte y copias el contenido para pegarlo en este tema.

Ubuntu User #20783
Linux User Registered #453948


Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog


* Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando.
* Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
* No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.
Responder Con Cita
  post #3  
Antiguo 14/03/08, 02:49:54
Usuario
 
Registrado: ene 2006
Ubicación: Mexico
Mensajes: 14
Re: Adware Vundo Variant Resident

Ya estoy ejecutando el Malwarebytes.
Gracias.
Esperare a ver que pasa.

Mientras tanto te comento que en todo este proceso previo, edite las lineas del registro de manera manual, y quite algunas que identificó el Superantispyware.

Tambien vi el log del Hijack y detecte que trataba de cargar un archivo que no existia ya en el sistema.

Estos son los archivos que identifique tenían el VUNDO.

DDCCB.DLL
MLLJI.DLL
AWTURSP.DLL
IJLLM.INI
SSTTS.DLL

Me costo mucho trabajo eliminarlos, trate con el modo a prueba de fallos y el normal, pero el DDCB.DLL me bloqueaba el equipo y me ponia bluescreen varias veces, hasta que por fin, aparentemente lo elimino.

En una de esas, encontre unos archivos raros en el log del Hijack, y eliminé las entradas solamente.

Hay una linea en el registro que me detecta el spy sweeper
pero no se exactamente dónde se localice:

HKLM\software\microsoft\removerp

Gracias.
Esperare a ver los resultados.

Ah, También use una herramienta que me encontre de Symantec. Se llama FixVundo. Esa me encontro varios procesos en memoria y aparentemente los desactivo. Algo que ver con la utiliería de C.
Ya no la corri, la ultima vez que la ejecute, me reinicio la computadora.


Malwarebytes' Anti-Malware 1.08
Versión de la Base de Datos: 490

Tipo de examen : Examen Completo (C:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|)
Objetos examinados: 407046
Tiempo transcurrido: 3 hour(s), 42 minute(s), 29 second(s)

Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 0
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 0
Carpetas Infectadas: 0
Ficheros Infectados: 0

Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)

Claves del Registro Infectadas:
(No se han detectado elementos maliciosos)

Valores del Registro Infectados:
(No se han detectado elementos maliciosos)

Elementos de Datos del Registro Infectados:
(No se han detectado elementos maliciosos)

Carpetas Infectadas:
(No se han detectado elementos maliciosos)

Ficheros Infectados:
(No se han detectado elementos maliciosos)

Última edición por junio fecha: 15/03/08 a las 12:00:55. Razón: Ya pueden cerrar este mensaje. Muchas Gracias. Todo solucionado.
Responder Con Cita
Respuesta

Herramientas

Reglas del foro
No puedes crear nuevos temas
No puedes responder temas
No puedes subir adjuntos
No puedes editar tus mensajes

BB code is activado
Las caritas están activado
Código [IMG] está activado
Código HTML está desactivado
Trackbacks are desactivado
Pingbacks are activado
Refbacks are activado


Temas Similares
Tema Autor Foro Respuestas Último mensaje
PC infectado con VUNDO VARIANT y otros (Solucionado) yiangshu Temas Solucionados 4 01/02/08 16:02:38
Symantec emaul proxy + Adware. Vundo Variant Yashden Ashtar Foro Oficial de HijackThis en español 5 19/12/07 21:12:07
Alguien me puede decir si lo que tengo es Vundo Variant, Virtumonde o lo que sea????? rusile Foro de Virus y Spywares 3 11/11/07 13:54:06
tengo virus troyanos y spyware lucemat Foro de Virus y Spywares 4 22/04/07 22:40:50
Tengo miles de solicitudes de conexion :s week_bcn Ayuda General 1 26/02/07 17:23:58




Todas las horas son GMT -4. La hora es 05:20:10.


 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31