Hola a todos,
Desde hace un par de días tengo problemillas con el ordenador.
Cada vez que abro Internet Explorer, me aparecen páginas que dicen algo de search camel y, a veces, algo de virus defender. Además, desde que esto ocurre, no puedo acceder con normalidad a hotmail, facebook etc No sé si tendrá algo que ver pero, por si acaso, os lo digo :)
He estado echando un vistazo a otros posts similares y he seguido alguno de los pasos que habéis recomendado para acelerar el proceso. Básicamente, lo que he hecho ha sido esto:
Descarga, actualiza y ejecuta Malwarebytes’ Anti-Malware.
Realiza un examen completo del PC y elimina las infecciones que este detecte.
El reporte queda guardado en la pestaña "Logs" o "Registros" en español, abres el reporte y copias el contenido para pegarlo en este tema.
Descarga y ejecuta CCleaner .
Usa la opción Limpiador para borrar cookies y temporales,
y la opción Registro para efectuar una limpieza del registro de Windows.
Realiza un análisis completo del Pc con:
Ewido Online Scanner. Al terminar pulsa en "Remove Infections".
Descarga, actualiza y ejecuta Malwarebytes’ Anti-Malware.
Realiza un examen completo del PC y elimina las infecciones que este detecte.
El reporte queda guardado en la pestaña "Logs" o "Registros" en español, abres el reporte y copias el contenido para pegarlo en este tema.
Descarga y ejecuta CCleaner .
Usa la opción Limpiador para borrar cookies y temporales,
y la opción Registro para efectuar una limpieza del registro de Windows.
Realiza un análisis completo del Pc con:
Ewido Online Scanner. Al terminar pulsa en "Remove Infections".
Panda Active Scan 2.0.
Os copio primero el informe de Malwarebytes' Anti-Malware:
Malwarebytes' Anti-Malware 1.30
Versión de la Base de Datos: 1422
Windows 5.1.2600 Service Pack 3
25/11/2008 12:59:09
mbam-log-2008-11-25 (12-59-09).txt
Tipo de examen : Examen Completo (C:\|)
Objetos examinados: 36254
Tiempo transcurrido: 8 minute(s), 39 second(s)
Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 2
Claves del Registro Infectadas: 20
Valores del Registro Infectados: 6
Elementos de Datos del Registro Infectados: 2
Carpetas Infectadas: 0
Ficheros Infectados: 5
Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Módulos en Memoria Infectados:
C:\WINDOWS\system32\tijawani.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\muhodogu.dll (Trojan.BHO) -> Delete on reboot.
Claves del Registro Infectadas:
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{60b244be-559d-4269-b96e-cd264d828ec9} (Rogue.PCAntispy) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0b682cc1-fb40-4006-a5dd-99edd3c9095d} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{54645654-2225-4455-44a1-9f4543d34545} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{60b244be-559d-4269-b96e-cd264d828ec9} (Rogue.PCAntispy) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f06e2abe-3a50-4079-be25-fc100d9eaa25} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5dde5591-a8ab-4897-93ef-1e4e943f85a7} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60b244be-559d-4269-b96e-cd264d828ec9} (Rogue.PCAntispy) -> Quarantined and deleted successfully.
Valores del Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\e413971b (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{f06e2abe-3a50-4079-be25-fc100d9eaa25} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656a137-b161-cadd-9777-e37a75727e78} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
Elementos de Datos del Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: c:\windows\system32\muhodogu.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.BHO) -> Data: system32\muhodogu.dll -> Quarantined and deleted successfully.
Carpetas Infectadas:
(No se han detectado elementos maliciosos)
Ficheros Infectados:
C:\WINDOWS\system32\susalade.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\edalasus.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tijawani.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\inawajit.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\muhodogu.dll (Trojan.BHO) -> Delete on reboot.
Y ahora os dejo el informe que he obtenido del Panda:
***********************************************************************************************************************************************************************************
ANALYSIS: 2008-11-25 13:33:26
PROTECTIONS: 1
MALWARE: 5
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG Anti-Virus Free 8.0 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00046190 adware/slagent Adware No 0 Yes No c:\windows\mslagent
00063168 spyware/dluca Spyware No 1 Yes No c:\windows\system32\sncntr.exe
00063665 adware/pacimedia Adware No 0 Yes No c:\windows\system32\psoft1.exe
00063665 adware/pacimedia Adware No 0 Yes No c:\windows\system32\psof1.exe
00063665 adware/pacimedia Adware No 0 Yes No c:\windows\system32\ps1.exe
00101314 adware/intdel Adware No 0 Yes No c:\archivos de programa\inet delivery
00132710 dialer.xd Dialers No 0 Yes No c:\windows\system32\vbsys2.dll
;===================================================================================================================================================================================
SUSPECTS
Sent Location zb
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description zb
;===================================================================================================================================================================================
;===================================================================================================================================================================================
Muchas gracias!


Registrate para responder
Por favor, sigue estos pasos:
DESCARGA LO SIGUIENTE:
MALWAREBYTE y su MANUAL Lo instalas y actualizas (pero no lo ejecutes aun)
EJECUTA CCLEANER usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad).
Apaga RESTAURAR SISTEMA (SYSTEM RESTORE), muestra los ARCHIVOS OCULTOS e inicia EN MODO A PRUEBA DE ERRORES
EJECUTA MALWAREBYTE, seleccionas hacer un "escaneo completo" y una vez finalizado, si te detecta algo eliges " quitar lo seleccionado ". Si te pide reiniciar, lo haces y después te vas a la pestaña de "registros" para copiar y pegar el reporte generado en este tema.
Pasas CCLEANER nuevamente
INICIA en modo normal, prende EL restaurar sistema, oculta los archivos
Realiza un
KASPERSKY ONLINE SCANNER y pega su reporte aquì