![]() |
| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| no puedoo eliminar virus win32 estos son los reportes de los antivirus q les pasee PANDA ;************************************************* ************************************************** ************************************************** ****************************** ANALYSIS: 2008-04-16 10:20:45 PROTECTIONS: 1 MALWARE: 10 SUSPECTS: 0 ;************************************************* ************************************************** ************************************************** ****************************** PROTECTIONS Description Version Active Updated ;================================================= ================================================== ================================================== ============================== NOD32 Antivirus 2.51.12 No Yes ;================================================= ================================================== ================================================== ============================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;================================================= ================================================== ================================================== ============================== 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Cookies\administrador@atdmt[2].txt 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Cookies\administrador@trade doubler[1].txt 00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Cookies\administrador@links ynergy[1].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[ad.yieldmanager.com/] 00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Administrador\Datos de programa\Mozilla\Firefox\Profiles\cnpyitya.default \cookies.txt[.adtech.de/] 02905323 Application/BarreraIntegral HackTools No 0 Yes No C:\Documents and Settings\Administrador\Configuración local\Temp\ProductPath\pgs.exe 02909988 Adware/VirusAlarma Adware No 0 Yes No C:\Documents and Settings\Administrador\Configuración local\Archivos temporales de Internet\Content.IE5\T4KSY5CE\install_es[1].cab 02913439 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\Administrador\Configuración local\Temp\jmomcbcu.dll 02913439 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\Administrador\Configuración local\Temp\fvoagplr.dll 02913439 Spyware/Virtumonde Spyware No 1 Yes No C:\VundoFix Backups\nvlnsjwe.dll.bad 02913439 Spyware/Virtumonde Spyware No 1 Yes No C:\Documents and Settings\Administrador\Configuración local\Temp\opfuyjcv.dll 02913546 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\oppwjrbb.dll 02913546 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\vpeknqyq.dll 02913546 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\gwhxtvxw.dll 02914224 Spyware/Virtumonde Spyware No 1 Yes No C:\WINDOWS\system32\umvctjgy.dll ;================================================= ================================================== ================================================== ============================== SUSPECTS Sent Location ;================================================= ================================================== ================================================== ============================== ;================================================= ================================================== ================================================== ============================== VULNERABILITIES Id Severity Description ;================================================= ================================================== ================================================== ============================== 182048 HIGH MS07-069 176382 HIGH MS07-057 170906 HIGH MS07-045 170904 HIGH MS07-043 164913 HIGH MS07-033 160623 HIGH MS07-027 150253 HIGH MS07-016 141030 HIGH MS06-072 137568 HIGH MS06-067 126083 HIGH MS06-042 120815 HIGH MS06-022 120814 HIGH MS06-021 114664 HIGH MS06-013 ;================================================= ================================================== ================================================== ============================== anti malware Malwarebytes' Anti-Malware 1.11 Versión de la Base de Datos: 599 Tipo de examen : Examen Completo (C:\|E:\|) Objetos examinados: 77702 Tiempo transcurrido: 33 minute(s), 30 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 2 Claves del Registro Infectadas: 14 Valores del Registro Infectados: 1 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 0 Ficheros Infectados: 6 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: C:\WINDOWS\system32\gtyqmxjq.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\ljJywVom.dll (Trojan.Vundo) -> Unloaded module successfully. Claves del Registro Infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{a162760e-236d-41b9-a44a-f1465746d3f6} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a162760e-236d-41b9-a44a-f1465746d3f6} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Valores del Registro Infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\BM6f145056 (Trojan.Agent) -> Quarantined and deleted successfully. Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: (No se han detectado elementos maliciosos) Ficheros Infectados: C:\WINDOWS\system32\gtyqmxjq.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\qjxmqytg.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ljJywVom.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\moVwyJjl.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\moVwyJjl.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yntivpcs.dll (Trojan.Agent) -> Delete on reboot. POR FAVBORR NECESITO AYUDAA |
![]() | ![]() |
| ||||
| Re: no puedoo eliminar virus win32 Descargate OTMoveIt lo guardas en el Escritorio.
Código HTML: C:\Documents and Settings\Administrador\Configuraci¢n local\Archivos temporales de Internet\Content.IE5\T4KSY5CE\install_es[1].cab C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\fvoagplr.dll C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\jmomcbcu.dll C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\opfuyjcv.dll C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\ProductPath\pgs.exe C:\VundoFix Backups\nvlnsjwe.dll.bad C:\WINDOWS\system32\gwhxtvxw.dll C:\WINDOWS\system32\oppwjrbb.dll C:\WINDOWS\system32\umvctjgy.dll C:\WINDOWS\system32\vpeknqyq.dll
Envía el informe (reporte) de OTMoveIt situado sobre C: \ _ OTMoveIt\MovedFiles. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no puedoo eliminar virus win32 < C:\Documents and Settings\Administrador\Configuraci¢n local\Archivos temporales de Internet\Content.IE5\T4KSY5CE\install_es[1].cab > File/Folder C:\Documents and Settings\Administrador\Configuraci¢n local\Archivos temporales de Internet\Content.IE5\T4KSY5CE\install_es[1].cab not found. File/Folder C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\fvoagplr.dll not found. File/Folder C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\jmomcbcu.dll not found. File/Folder C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\opfuyjcv.dll not found. File/Folder C:\Documents and Settings\Administrador\Configuraci¢n local\Temp\ProductPath\pgs.exe not found. C:\VundoFix Backups\nvlnsjwe.dll.bad moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\gwhxtvxw.dll C:\WINDOWS\system32\gwhxtvxw.dll NOT unregistered. C:\WINDOWS\system32\gwhxtvxw.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\oppwjrbb.dll C:\WINDOWS\system32\oppwjrbb.dll NOT unregistered. C:\WINDOWS\system32\oppwjrbb.dll moved successfully. LoadLibrary failed for C:\WINDOWS\system32\umvctjgy.dll C:\WINDOWS\system32\umvctjgy.dll NOT unregistered. C:\WINDOWS\system32\umvctjgy.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\vpeknqyq.dll C:\WINDOWS\system32\vpeknqyq.dll NOT unregistered. C:\WINDOWS\system32\vpeknqyq.dll moved successfully. OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04162008_191053 juann aca estaa el informeee me siguee apareciendoo este viruss El archivo puede ser eliminado. Verifique haber efectuado una copia de seguridad de cualquier dato importante antes de proceder con la desinfección. Suceso ocurrido cuando se produjo un intento de acceso al archivo por la aplicación \??\C:\WINDOWS\system32\winlogon.exe. Win32/adware.Virtumonde aplicacion C:\WINDOWS\system32\fccywuRH.dll saludooss |
![]() | ![]() |
| ||||
| Re: no puedoo eliminar virus win32 Elimina esta carpeta: C: \ _ OTMoveIt\ Realiza estos pasos: Descarga, ejecuta y actualiza CCleaner. Usar primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que éste te muestre como obsoletos, y luego usar su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad). Descarga y ejecuta MalwareBytes Anti-malware, examina por completo tu PC, elimina lo que éste te encuentre y reinicia. (dejanos el reporte que genere). Escanea tu PC con este antivirus on line:kaspersky on-line -Manual- (Deja su reporte) Recuerda volver y nos comentas si mejora o no tu PC, Saludos! Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no puedoo eliminar virus win32 Malwarebytes' Anti-Malware 1.11 Versión de la Base de Datos: 599 Tipo de examen : Examen Completo (C:\|E:\|) Objetos examinados: 76689 Tiempo transcurrido: 15 minute(s), 38 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 2 Claves del Registro Infectadas: 15 Valores del Registro Infectados: 1 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 0 Ficheros Infectados: 6 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: C:\WINDOWS\system32\oeutelxn.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\wvUnLCRl.dll (Trojan.Vundo) -> Unloaded module successfully. Claves del Registro Infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{f2417c68-45ff-43c8-ae19-0bc972fac6d5} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{f2417c68-45ff-43c8-ae19-0bc972fac6d5} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Valores del Registro Infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\BM6f145056 (Trojan.Agent) -> Quarantined and deleted successfully. Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: (No se han detectado elementos maliciosos) Ficheros Infectados: C:\WINDOWS\system32\oeutelxn.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\nxletueo.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wvUnLCRl.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\lRCLnUvw.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lRCLnUvw.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\txpapley.dll (Trojan.Agent) -> Delete on reboot. Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\.lmp] [HKEY_CLASSES_ROOT\.m8] [HKEY_CLASSES_ROOT\.mip] [HKEY_CLASSES_ROOT\.pak] [HKEY_CLASSES_ROOT\.pal] [HKEY_CLASSES_ROOT\.pcx] [HKEY_CLASSES_ROOT\.swl] [HKEY_CLASSES_ROOT\.tex] [HKEY_CLASSES_ROOT\.tga] [HKEY_CLASSES_ROOT\.wad] [HKEY_CLASSES_ROOT\.wal] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.ase] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.ase\OpenWithProgids] "Photoshop.ExchangeableSwatchFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.BIN] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.BIN\OpenWithList] "a"="daemon.exe" "MRUList"="ba" "b"="Alcohol.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.cin] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.cin\OpenWithProgids] "Photoshop.CINFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.cr2] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.cr2\OpenWithProgids] "Photoshop.CameraRawFileCanon2.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.crw] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.crw\OpenWithProgids] "Photoshop.CameraRawFileCanon.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.CUE] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.CUE\OpenWithList] "a"="daemon.exe" "MRUList"="ab" "b"="alcohol.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.dng] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.dng\OpenWithProgids] "Photoshop.CameraRawFileDigital.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.erf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.erf\OpenWithProgids] "Photoshop.CameraRawFileEpson.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.exr] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.exr\OpenWithProgids] "Photoshop.OpenEXRFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.hdr] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.hdr\OpenWithProgids] "Photoshop.PortableBitMapFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.jsx] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.jsx\OpenWithProgids] "JSXFile"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.jsxbin] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.jsxbin\OpenWithProgid s] "JSXBINFile"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mdf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mdf\OpenWithList] "a"="daemon.exe" "MRUList"="a" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mds] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mds\OpenWithList] "a"="daemon.exe" "MRUList"="a" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mnu] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mnu\OpenWithProgids] "Photoshop.MenuCustomizationFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mos] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mos\OpenWithProgids] "Photoshop.CameraRawFileLeaf.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mrw] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.mrw\OpenWithProgids] "Photoshop.CameraRawFileMinolta.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.nef] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.nef\OpenWithProgids] "Photoshop.CameraRawFileNikon.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.orf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.orf\OpenWithProgids] "Photoshop.CameraRawFileOlympus.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pbm] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pbm\OpenWithProgids] "Photoshop.RadianceFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pcd] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pcd\OpenWithProgids] "Photoshop.PCDFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pdd] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pdd\OpenWithProgids] "Photoshop.PDDFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pdp] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pdp\OpenWithProgids] "Photoshop.PDPFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pef] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pef\OpenWithProgids] "Photoshop.CameraRawFilePentax.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.psb] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.psb\OpenWithProgids] "Photoshop.PSBFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pxr] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.pxr\OpenWithProgids] "Photoshop.PXRFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.raf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.raf\OpenWithProgids] "Photoshop.CameraRawFileFujifilm.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.shh] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.shh\OpenWithProgids] "Photoshop.SHHFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.srf] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.srf\OpenWithProgids] "Photoshop.CameraRawFileSony.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.srt] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.srt\OpenWithList] "a"="bsplay.exe" "MRUList"="ab" "b"="MediaSub.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.ssa] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.ssa\OpenWithList] "a"="MediaSub.exe" "MRUList"="ba" "b"="VirtualDub.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.sta] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.sta\OpenWithProgids] "Photoshop.STAFile.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.sub] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.sub\OpenWithList] "a"="bsplay.exe" "MRUList"="a" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.x3f] [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\.x3f\OpenWithProgids] "Photoshop.CameraRawFileFoveon.10"=hex(0): [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\FileExts\OpenWithList] [HKEY_CLASSES_ROOT\CLSID\{24E9519B-3F70-429B-99BC-4B2B49B96F66}] [HKEY_CLASSES_ROOT\CLSID\{24E9519B-3F70-429B-99BC-4B2B49B96F66}\InprocServer32] @="C:\\WINDOWS\\system32\\nnnnOeEu.dll" "ThreadingModel"="Both" [HKEY_CLASSES_ROOT\CLSID\{432DFF09-B36A-4D21-BBE8-70843013EE88}] [HKEY_CLASSES_ROOT\CLSID\{432DFF09-B36A-4D21-BBE8-70843013EE88}\InprocServer32] @="C:\\WINDOWS\\system32\\hgGawTJc.dll" "ThreadingModel"="Both" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Installer\Folders] "C:\\Archivos de programa\\Steam\\"="1" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\App Management\ARPCache\{7935BBD1-D037-491A-A1A3-DE4AE7EC7534}] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff, ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\App Management\ARPCache\{C6F1E87D-F3E1-4874-97EC-F87DAB6D6878}] "SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff, ff,ff,ff,ff,ff,ff,00,00,00,\ 00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00 "Changed"=dword:00000000 [HKEY_CURRENT_USER\Software\Alcohol Soft] [HKEY_CURRENT_USER\Software\QuickTime Alternative] [HKEY_LOCAL_MACHINE\Software\UnitedAdmins] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "SBI"="C:\\Downloads\\install_sbd_es.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\Downloads\\install_sbd_es.exe"="Ordenador Seguro, Installer" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\A~NSISu_. exe"="A~NSISu_" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\is-9SSPT.tmp\\spybotsd152.tmp"="Setup/Uninstall" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\84233500\ \as2instff.exe"="Panda ActiveScan 2.0 Firefox Installer" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\is-BPQTB.tmp\\mbam-setup.tmp"="Setup/Uninstall" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\is-4HIIV.tmp\\is-LIM19.tmp"="Setup/Uninstall" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\is-JILHP.tmp\\is-4FG0J.tmp"="Setup/Uninstall" [HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell NoRoam\MUICache] "C:\\DOCUME~1\\ADMINI~1\\CONFIG~1\\Temp\\is-N7A2C.tmp\\is-NCM83.tmp"="Setup/Uninstall" |
![]() | ![]() |
| ||||
| Re: no puedoo eliminar virus win32 Hola, muy bien ![]() Recuerda dejarme el reporte del kaspersky para analizarlo. Saludos! Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no puedoo eliminar virus win32 miércoles, 16 de abril de 2008 20:35:24 Sistema operativo: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner versión: 5.0.84.1 Ultima actualización: 16/04/2008 Registros en la base antivirus: 637191 Configuración del análisis Analizar usando las siguientes bases standard Analizar archivos verdadero Analizar bases de correo verdadero Objetivo a analizar Mi PC A:\ C:\ D:\ E:\ F:\ Estadísticas Número de objeros analizados 52646 Virus encontrados 3 Objetos infectados 4 / 0 Objetos sospechosos 0 Duración del análisis 00:40:50 Bombre del objeto infectado Nombre del virus Última acción C:\Archivos de programa\Eset\cache\CACHE.NDB Object is locked saltado C:\Archivos de programa\Eset\infected\5R0H4ZBA.NQF Infectados: Trojan.Win32.KillAV.rf saltado C:\Archivos de programa\Eset\infected\SYJNNTBA.NQF Infectados: Trojan.Win32.KillAV.rf saltado C:\Archivos de programa\Eset\logs\virlog.dat Object is locked saltado C:\Archivos de programa\Eset\logs\warnlog.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\Logs\Dfsr00005.log Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\pending.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\Working\database_8A6C_277D_6C27_6 365\dfsr.db Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\Working\database_8A6C_277D_6C27_6 365\fsr.log Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\Working\database_8A6C_277D_6C27_6 365\fsrtmp.log Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Messenger\elcentu89@hotmail.com \SharingMetadata\Working\database_8A6C_277D_6C27_6 365\tmp.edb Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\elcentu89@hotmail.com\real\members.stg Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\elcentu89@hotmail.com\shadow\members.stg Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Historial\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Historial\History.IE5\MSHist0120080416200804 17\index.dat Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Temp\eraseme_02310.exe Infectados: Trojan.Win32.Agent.giv saltado C:\Documents and Settings\Administrador\Configuración local\Temp\temp_01.exe Infectados: Trojan.Win32.Agent.jyc saltado C:\Documents and Settings\Administrador\Configuración local\Temp\~DF32E6.tmp Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Temp\~DF3374.tmp Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Temp\~DFE8CB.tmp Object is locked saltado C:\Documents and Settings\Administrador\Configuración local\Temp\~DFE8F1.tmp Object is locked saltado C:\Documents and Settings\Administrador\Cookies\index.dat Object is locked saltado C:\Documents and Settings\Administrador\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\App Logs\SUPERANTISPYWARE-4-16-2008( 19-44-7 ).LOG Object is locked saltado C:\Documents and Settings\Administrador\Datos de programa\Teleca\Telecalib\Logging\Application logs\SpecificUSB_log.txt Object is locked saltado C:\Documents and Settings\Administrador\NTUSER.DAT Object is locked saltado C:\Documents and Settings\Administrador\NTUSER.DAT.LOG Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked saltado C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked saltado C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked saltado C:\System Volume Information\_restore{EFA63357-F623-4462-A42E-96251F7C31E1}\RP4\change.log Object is locked saltado C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado C:\WINDOWS\SchedLgU.Txt Object is locked saltado C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\default Object is locked saltado C:\WINDOWS\system32\config\default.LOG Object is locked saltado C:\WINDOWS\system32\config\SAM Object is locked saltado C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\SECURITY Object is locked saltado C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado C:\WINDOWS\system32\config\software Object is locked saltado C:\WINDOWS\system32\config\software.LOG Object is locked saltado C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\system Object is locked saltado C:\WINDOWS\system32\config\system.LOG Object is locked saltado C:\WINDOWS\system32\drivers\sptd.sys Object is locked saltado C:\WINDOWS\system32\efcCssSk.dll Object is locked saltado C:\WINDOWS\system32\fccywuRH.dll Object is locked saltado C:\WINDOWS\system32\fccywuRH.V00dll Object is locked saltado C:\WINDOWS\system32\fccywuRH.V06dll Object is locked saltado C:\WINDOWS\system32\fccywuRH.Vdll Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked saltado Análisis completado. estee els el krapesky juanii |
![]() | ![]() |
| ||||
| Re: no puedoo eliminar virus win32 Hola, elimina todos los archivos de esta carpeta: C:\Archivos de programa\Eset\infected Elimina estos archivos: C:\Documents and Settings\Administrador\Configuración local\Temp\eraseme_02310.exe C:\Documents and Settings\Administrador\Configuración local\Temp\temp_01.exe Si no se dejan eliminar utiliza: KillBox o Fileassassin. Como sigue tu PC? Tienes alguna duda? Saludos! Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no puedoo eliminar virus win32 JUANIII ME SIGUE DETECTANDOO EL VIRUSS DE SIEMPREE C:WINDOWS\system32\fccywuRH.dll Win32/adware.Virtumonde aplicacion El archivo puede ser eliminado. Verifique haber efectuado una copia de seguridad de cualquier dato importante antes de proceder con la desinfección. Suceso ocurrido cuando se produjo un intento de acceso al archivo por la aplicación \??\C:\WINDOWS\system32\winlogon.exe. esee es el uinicoo q no puedo eliminarr :S |
![]() | ![]() |
| ||||
| Re: no puedoo eliminar virus win32 Descargate OTMoveIt lo guardas en el Escritorio.
Código HTML: C:WINDOWS\system32\fccywuRH.dll
Envía el informe (reporte) de OTMoveIt situado sobre C: \ _ OTMoveIt\MovedFiles. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Como elimino las notificaciones?! (Finalizado) | OrlandoRd | Temas Solucionados | 40 | 01/06/07 15:31:55 |
| pc infectada, pero antivirus no los elimina ..ayuda | mizzuri | Foro Oficial de HijackThis en español | 4 | 02/05/07 00:34:32 |
| Necesito ayuda con el virus REG/Zapchast porfavor! | fabian_sl | Foro de Virus y Spywares | 8 | 29/04/07 10:53:22 |
| Zulú, virus made in Argentina (entrevista a fondo) | skiavi | Off-Topic | 6 | 16/12/06 03:15:56 |
| about:blank (solucionado) | rubentome | Temas Solucionados | 13 | 06/06/05 04:08:53 |