![]() |
| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Hola a todos! Les cuento a todos que soy nuevo en este foro y necesito su ayuda. Hace unos días mi computadora comenzó a funcionar muy lenta, se cuelga el windows explorer, no puedo acceder a ciertas paginas como yahoo, google, hotmail, gmai, ni ningun antivirus online. Tenia instalado el Nod32 y se me colgaba al 94% del analisis. Instale el Avira Antivir y me descubrio el TR/Crypt.XPACK.Gen pero no lo elimina ni lo pone en cuarentena. Un poco mas de informacion: mi computadora es una AMD Athlon dual core 3600+, 3 gb de ram y HD de 160gb (pero ahora me funciona como una comodore 64). Espero su ayuda pronto. Saludos |
![]() | ![]() |
| ||||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Paso 1- Descarga estas herramientas pero no las ejecutes aun:Paso 2- Reinicia he inicia en "Modo a prueba de fallos" (modo seguro con funciones a red) Paso 3- Ejecuta estas herramientas, de a una:
Paso 5- Realiza un analisis online con kaspersky online scanner como lo indica su manual y nos dejas su reporte. Si usas Firefox como navegador recuerda usar la extencion IE Tab para poder realizar algun scanner online. Reinicia y nos cuentas los resultados junto a los reportes generados por, MalwareByte's Antimalware, DelPsguard y Kaspersky online scanner. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Estimado firewall, gracias por los consejos que me diste. Segui todo al pie de la letra. Te comento que los reportes del DelPSGuard y del MalwareByte´s se perdieron cuando pase el CCleaner. Lo que te puedo decir es que el delPsguard no detecto nada y que el MalwareByte´s detecto 49 archivos infectados los cuales fueron corregidos. Con el CCleaner me limpio un monton de basura que tenia en el HD y el registro. La PC por ahora me anda mas rápido (pero no lo que quisiera) y el Avira no me detecta mas el virus. En este momento estoy corriendo el Kaspersky online como me dijiste. Despues te mando el reporte y me contas. Muchas gracias y saludos. |
![]() | ![]() |
| ||||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Ok amigo espero el reporte para proceder a evaluarlo. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen hola nuevamente. Perdon por la demora, pero mi pc comenzó a funcionar mal nuevamente. Como te comente hice el scan con el kaspersky on-line y no encontro nada. Despues de eso la pc comenzó a funcionar mas lenta nuevamente. Hice el scan con el Avira Antivir y este es el reporte: Avira AntiVir Premium Report file date: jueves, 07 de agosto de 2008 23:53 Scanning for 1540477 virus strains and unwanted programs. Licensed to: hiphop anonymous Serial number: 1101603756-PEPWE-0001 Platform: Windows Vista Windows version: (plain) [6.0.6000] Boot mode: Normally booted Username: Fede Computer name: SUPERPC Version information: BUILD.DAT : 8.1.0.362 20011 Bytes 11/07/2008 12:37:00 AVSCAN.EXE : 8.1.4.7 315649 Bytes 02/08/2008 16:03:29 AVSCAN.DLL : 8.1.4.0 40705 Bytes 02/08/2008 16:03:29 LUKE.DLL : 8.1.4.5 164097 Bytes 02/08/2008 16:03:29 LUKERES.DLL : 8.1.4.0 12033 Bytes 02/08/2008 16:03:29 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 15:33:34 ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 16:03:30 ANTIVIR2.VDF : 7.0.5.207 2316800 Bytes 04/08/2008 15:06:29 ANTIVIR3.VDF : 7.0.5.229 136192 Bytes 07/08/2008 18:14:02 Engineversion : 8.1.1.19 AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 14:58:21 AESCRIPT.DLL : 8.1.0.63 311673 Bytes 06/08/2008 18:13:56 AESCN.DLL : 8.1.0.23 119156 Bytes 02/08/2008 16:03:31 AERDL.DLL : 8.1.0.20 418165 Bytes 02/08/2008 16:03:31 AEPACK.DLL : 8.1.2.1 364917 Bytes 02/08/2008 16:03:31 AEOFFICE.DLL : 8.1.0.21 192891 Bytes 02/08/2008 16:03:31 AEHEUR.DLL : 8.1.0.47 1368437 Bytes 06/08/2008 18:13:52 AEHELP.DLL : 8.1.0.15 115063 Bytes 02/08/2008 16:03:31 AEGEN.DLL : 8.1.0.35 315764 Bytes 06/08/2008 18:13:44 AEEMU.DLL : 8.1.0.7 430452 Bytes 02/08/2008 16:03:31 AECORE.DLL : 8.1.1.8 172406 Bytes 02/08/2008 16:03:31 AEBB.DLL : 8.1.0.1 53617 Bytes 02/08/2008 16:03:31 AVWINLL.DLL : 1.0.0.12 15105 Bytes 02/08/2008 16:03:29 AVPREF.DLL : 8.0.2.0 38657 Bytes 02/08/2008 16:03:29 AVREP.DLL : 8.0.0.2 98344 Bytes 02/08/2008 16:03:31 AVREG.DLL : 8.0.0.1 33537 Bytes 02/08/2008 16:03:29 AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 13:29:23 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 02/08/2008 16:03:28 SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 22:28:02 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 02/08/2008 16:03:30 NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 17:05:10 RCIMAGE.DLL : 8.0.0.51 2564353 Bytes 02/08/2008 16:03:24 RCTEXT.DLL : 8.0.51.0 86273 Bytes 02/08/2008 16:03:24 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition premium\sysscan.avp Logging..........................: low Primary action...................: repair Secondary action.................: delete Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: on Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox, Macro heuristic..................: on File heuristic...................: high Start of the scan: jueves, 07 de agosto de 2008 23:53 Starting search for hidden objects. '83997' objects were checked, '0' hidden objects were found. The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'uTorrent.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'usnsvc.exe' - '1' Module(s) have been scanned Scan process 'unsecapp.exe' - '1' Module(s) have been scanned Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'egui.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'dwm.exe' - '1' Module(s) have been scanned Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'avwebgrd.exe' - '1' Module(s) have been scanned Scan process 'avmailc.exe' - '1' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SMSvcHost.exe' - '1' Module(s) have been scanned Scan process 'ekrn.exe' - '1' Module(s) have been scanned Scan process 'avesvc.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SLsvc.exe' - '1' Module(s) have been scanned Scan process 'audiodg.exe' - '0' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'lsm.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'wininit.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 48 processes with 48 modules were scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Starting to scan the registry. The registry was scanned ( '43' files ). Starting the file scan: Begin scan in 'C:\' C:\hiberfil.sys [WARNING] The file could not be opened! C:\pagefile.sys [WARNING] The file could not be opened! C:\Downloads\AV_Music_Morpher_Gold_v4.0.60_by_Love Pascal\av.music.morpher.gold.v4.0.60.license.exe [DETECTION] Is the TR/Agent.20480.LN Trojan [NOTE] A backup was created as '48c9b82f.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4cd30cb8.qua' ( QUARANTINE ) C:\Downloads\DAEMON Tools Pro Advanced v4.10.0218 And Patch\DAEMON Tools Pro Advanced v4.10.0218 And Patch\daemon.tools.pro.patch.exe [DETECTION] Is the TR/Agent.620544.A Trojan [NOTE] A backup was created as '4900b841.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d280432.qua' ( QUARANTINE ) C:\Program Files\DAEMON Tools Pro\daemon.tools.pro.patch.exe [DETECTION] Is the TR/Agent.620544.A Trojan [NOTE] A backup was created as '4900bce9.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d2608aa.qua' ( QUARANTINE ) C:\Program Files\DelPSGuard\IED.exe [DETECTION] Is the TR/Agent.77312.19 Trojan [NOTE] A backup was created as '48dfbce9.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4bb80f5a.qua' ( QUARANTINE ) C:\Users\Fede\AppData\Local\Microsoft\Windows\Temp orary Internet Files\Content.IE5\8E7WOZ91\kb671231[1] [DETECTION] Contains HEUR/Crypted suspicious code [NOTE] The detection was classified as suspicious. [NOTE] A backup was created as '48d22419.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4e7b9eaa.qua' ( QUARANTINE ) C:\Users\Fede\AppData\Local\Temp\cpgrfutv.dll [DETECTION] Contains HEUR/Crypted suspicious code [NOTE] The detection was classified as suspicious. [NOTE] A backup was created as '490325f2.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4a6deef3.qua' ( QUARANTINE ) C:\Users\Fede\AppData\Local\Temp\drdmmach.dll [WARNING] The file could not be opened! C:\Users\Fede\AppData\Local\Temp\njceroaa.dll [DETECTION] Contains HEUR/Crypted suspicious code [NOTE] The detection was classified as suspicious. [NOTE] A backup was created as '48ff25ed.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4ce3eeee.qua' ( QUARANTINE ) C:\Users\Fede\AppData\Local\Temp\njypjucd.dll [WARNING] The file could not be opened! C:\Users\Fede\AppData\Local\Temp\xvofxafp.dll [WARNING] The file could not be opened! C:\Windows\System32\awxmcrbs.dll [DETECTION] Is the TR/Monder.bcb Trojan [NOTE] A backup was created as '49143bdd.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d6c886e.qua' ( QUARANTINE ) C:\Windows\System32\ceyygpws.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49153c00.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d6a8fb1.qua' ( QUARANTINE ) C:\Windows\System32\danisqrr.dll [DETECTION] Is the TR/Monder.bcb Trojan [NOTE] A backup was created as '490a3c6a.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d778fdb.qua' ( QUARANTINE ) C:\Windows\System32\eqekoiys.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49013ce5.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d7b8f56.qua' ( QUARANTINE ) C:\Windows\System32\ivvfodlk.dll [DETECTION] Contains recognition pattern of the ADSPY/Virtumonde.AA9 adware or spyware [NOTE] A backup was created as '49123d71.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4a7a8ec2.qua' ( QUARANTINE ) C:\Windows\System32\kozzpb.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49163da1.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4a858e12.qua' ( QUARANTINE ) C:\Windows\System32\lfomgv.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '490b3db3.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d708e04.qua' ( QUARANTINE ) C:\Windows\System32\mrfpiura.dll [DETECTION] Contains HEUR/Crypted suspicious code [NOTE] The detection was classified as suspicious. [NOTE] A backup was created as '49023e0f.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4a6a8da0.qua' ( QUARANTINE ) C:\Windows\System32\mwrssvvu.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '490e3e66.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d7b8dd7.qua' ( QUARANTINE ) C:\Windows\System32\mxhrqbxx.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49043e81.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d848d32.qua' ( QUARANTINE ) C:\Windows\System32\oecqsvsn.dll [DETECTION] Contains recognition pattern of the ADSPY/Superjuan.bwn adware or spyware [NOTE] A backup was created as '48ff3ef4.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4c8b8d45.qua' ( QUARANTINE ) C:\Windows\System32\tuvTkjGA.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49124012.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d64f3a3.qua' ( QUARANTINE ) C:\Windows\System32\vomuqfjl.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49094042.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d74f3f3.qua' ( QUARANTINE ) C:\Windows\System32\xbrqvgfu.dll [DETECTION] Contains recognition pattern of the ADSPY/Superjuan.byv adware or spyware [NOTE] A backup was created as '490e40bd.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d70f30e.qua' ( QUARANTINE ) C:\Windows\System32\xkxxsk.dll [DETECTION] Contains recognition pattern of the ADSPY/Superjuan.bwn adware or spyware [NOTE] A backup was created as '491440c7.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d62f378.qua' ( QUARANTINE ) C:\Windows\System32\xqeqmd.dll [DETECTION] Contains recognition pattern of the ADSPY/Superjuan.byv adware or spyware [NOTE] A backup was created as '490140e7.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d7df358.qua' ( QUARANTINE ) C:\Windows\System32\ysxrregb.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '49144103.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4d6bf2b4.qua' ( QUARANTINE ) C:\Windows\System32\yxqevotx.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] A backup was created as '490d4109.qua' ( QUARANTINE ) [NOTE] Attempting to perform action using the ARK lib. [NOTE] A backup was created as '4a66f2ba.qua' ( QUARANTINE ) C:\Windows\System32\drivers\sptd.sys [WARNING] The file could not be opened! End of the scan: viernes, 08 de agosto de 2008 12:07 Used time: 12:13:58 Hour(s) The scan has been canceled! 18115 Scanning directories 557015 Files were scanned 21 viruses and/or unwanted programs were found 4 Files were classified as suspicious: 0 files were deleted 0 files were repaired 50 files were moved to quarantine 0 files were renamed 6 Files cannot be scanned 556984 Files not concerned 3116 Archives were scanned 6 Warnings 25 Notes 83997 Objects were scanned with rootkit scan 0 Hidden objects were found Espero que te sea de ayuda para poder ayudarme. Saludos |
![]() | ![]() |
| ||||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Primero que todo aclaremos algo, si no sigues los pasos al pie de la letra no sabre si el proceso esta dando resultado, antes que nada te pedi varios reportes pero tu dices que estaban limpio ok eso esta bien, pero yo nesecito verlos para saber si estas haciendolos bien, ya que nada ganamos con mandarte hacer scan o usar programas y no me pegas los reportes que por medio de ellos yo me guio y por ende el avira detecta virus y la pregunta porque si te mande a usar dos herramientas poderosas como MalwareByte's Antimalware , lo mas logico fue que hicistes el proceso mas no la desinfeccion, por lo cual te pido que hagas todos los pasos de nuevo y me pegues los reportes uno a uno esten limpios o no. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Estimado Firewall, aqui se envio los registros del DelPSGuard y del Malwarebytes. Espero que te sirvan para poder audarme. En este momento estoy realizando un nuevo scan con el kaspersky on line. Gracias. DelPSGuard v 4.9.8 by www.ForoSpyware.com Reporte Creado: 13:26:38,35, 10/08/2008 SO: Microsoft Windows [Versi¢n 6.0.6000] Modo de Inicio: Seguro _________________________________________ »»»»»»»»»»»» Carpetas y Archivos infectados »»»»»»»»»»»» »»»»»»»»»»»»»»»»»»» Programas Malwares »»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»» FIN »»»»»»»»»»»»»»»»»»» Malwarebytes' Anti-Malware 1.24 Versión de la Base de Datos: 1012 Windows 6.0.6000 15:58:13 10/08/2008 mbam-log-8-10-2008 (15-58-13).txt Tipo de examen : Examen Completo (C:\|) Objetos examinados: 288522 Tiempo transcurrido: 2 hour(s), 4 minute(s), 17 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 1 Claves del Registro Infectadas: 4 Valores del Registro Infectados: 0 Elementos de Datos del Registro Infectados: 2 Carpetas Infectadas: 0 Ficheros Infectados: 4 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: C:\Windows\System32\tuvTkjGA.dll (Trojan.Vundo) -> Delete on reboot. Claves del Registro Infectadas: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{c060d3c5-89bc-43b9-be30-740f20141e03} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c060d3c5-89bc-43b9-be30-740f20141e03} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Valores del Registro Infectados: (No se han detectado elementos maliciosos) Elementos de Datos del Registro Infectados: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvtkjga -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvtkjga -> Quarantined and deleted successfully. Carpetas Infectadas: (No se han detectado elementos maliciosos) Ficheros Infectados: C:\Windows\System32\tuvTkjGA.dll (Trojan.Vundo) -> Delete on reboot. C:\Windows\System32\AGjkTvut.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Windows\System32\AGjkTvut.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Windows\System32\HOSTS (Trojan.Agent) -> Quarantined and deleted successfully. Nuevamente Gracias. |
![]() | ![]() |
| ||||
| Re: Ayuda estoy infectado con el TR/Crypt.XPACK.Gen Ok vamos por buen camino ya muchas infecciones fueron borradas, asi que espero el reporte de karspesky y rematar. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Your computer is infected! en la barra de tareas. (Solucionado) | andrisicus | Temas Solucionados | 22 | 30/04/08 13:58:15 |
| Miles de archivos .rar en la carpeta del incoming de emule Worm.W32/Archivarius@P2P | Assasina | Temas Solucionados | 36 | 04/04/08 15:59:10 |
| Se me paraliza el internet... | XZeroAxl | Foro de Virus y Spywares | 7 | 03/08/07 22:33:53 |
| Necesito mucha ayuda, supongo spyfalcon | vittorio_01105 | Foro de Virus y Spywares | 7 | 16/03/06 17:43:54 |
| se me añade una carpeta a favoritos - [solucionado] | hardores | Foro de Virus y Spywares | 25 | 10/05/05 07:55:41 |