| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | LinkBack | Herramientas |
![]() | ![]() |
| |||
| Virus ventanas emergentes (Solucionado) Buenas tardes: Soy nuevo en este foro, tengo un problema con el firefox, cuando estoy navegando, me salen ventanas emergentes cada dos por tres, y no se bien como quitarlo, he probado ya varios programas y no se que hacer. espero que alguien me pueda ayudas Un saludo |
![]() | ![]() |
| ||||
| Re: Virus ventanas emergentes Que tal bokeron_84, Bienvenid@
Una pregunta, la publicidad es dentro del propio navegador o se desborda al escritorio también ¿? Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Virus ventanas emergentes Vamos a ver, la ventana de publicidad sale en otra ventana independiente a la k tengo abierta. Espero que puedas ayudarme. Muchas gracias |
![]() | ![]() |
| ||||
| Tal vez esto se deba a que tienes un adware en tu Sistema Realiza un Scan con Panda y si detecta infecciones remuevelas, peganos el log que te genere aqui para verificar que no tengas virus. |
![]() | ![]() |
| |||
| Re: Virus ventanas emergentes Tendre que bajarme el panda,puesto que tengo avast cuando tenga el panda y lo pase y pongo el log. muchas gracias |
![]() | ![]() |
| ||||
| Re: Virus ventanas emergentes Cita:
Usalo como indica su manual: ]Panda ActiveScan+Manual y pega el reporte que genere. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Virus ventanas emergentes Aquí está el log, espero que me podais ayudar Código: PROTECTIONS: 1 MALWARE: 9 SUSPECTS: 10 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== avast! antivirus 4.8.1296 [VPS 081221-0] 4.8.1296 Yes No ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00029434 spyware/virtumonde Spyware No 1 Yes No hkey_local_machine\software\microsoft\ms juan 00029434 spyware/virtumonde Spyware No 1 Yes No hkey_local_machine\software\microsoft\ms track system 00257461 Application/ServUBased.A HackTools No 0 Yes No I:\Archivos de programa\Wingen\system.exe 00279006 Adware/StartPage.ATU Adware No 1 Yes No I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\Codeki\XviD.MPEG-4.video.codec.v.2.1 (XVID DIVX DX50)(3)(2).exe 00334836 W32/Puce.I.worm Virus/Worm No 0 No No I:\Documents and Settings\PATXI\Mis documentos\Programas\(ANTIVIRUS) NOD32 ESET.NOD.AntiVirus.v3.0.650.Business.Edition(32&64bit) updated-fixed 08-2008.rar[setup.exe] 00334836 W32/Puce.I.worm Virus/Worm No 0 No No K:\Mi música\Melon Diesel discografia completa incluye taxi libre 2005 updated-fixed 03-2008.rar[setup.exe] 00491698 Spyware/Virtumonde Spyware Yes 2 Yes No I:\WINDOWS\System32\frylxo.dll 00491698 Spyware/Virtumonde Spyware No 1 Yes No I:\WINDOWS\system32\vxyskcqi.dll 00492147 Spyware/Virtumonde Spyware No 1 Yes No I:\WINDOWS\system32\uduiqdso.dll 00492147 Spyware/Virtumonde Spyware No 1 Yes No I:\WINDOWS\system32\ebjnyuum.dll 00582261 Generic Trojan Virus/Trojan No 0 Yes No I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\winavivideoconverterv6.3patchicu.zip[patch.exe] 03864140 Bck/DService.TK Virus/Trojan No 1 No No I:\Documents and Settings\PATXI\Mis documentos\Programas\3D Studio Max 8.rar[Setup\Crack\KG.exe] 03938988 Generic Trojan Virus/Trojan No 0 No No I:\Documents and Settings\PATXI\Mis documentos\Programas\Daemon Tools 4.0 + crack.rar[Daemon Tools 4.0 + crack\Daemon-Tools-4.0-FR.EXE] ;=================================================================================================================================================================================== SUSPECTS Sent Location 3r ;=================================================================================================================================================================================== No I:\DOCUME~1\PATXI\DATOSD~1\MICROS~1\ieudinit.exe 3r No I:\WINDOWS\System32\drivers\logman.exe 3r No I:\Documents and Settings\PATXI\Configuración local\Temp\esentutl.exe 3r No I:\Documents and Settings\PATXI\Datos de programa\Microsoft\ieudinit.exe 3r No I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstinit.exe 3r No I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstsc.exe 3r No I:\Documents and Settings\PATXI\Datos de programa\Microsoft\rsvp.exe 3r No I:\Documents and Settings\PATXI\Datos de programa\Microsoft\sessmgr.exe 3r No I:\WINDOWS\comrepl.exe 3r No I:\WINDOWS\system32\drivers\logman.exe 3r ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description 3r ;=================================================================================================================================================================================== 184380 MEDIUM MS08-002 3r 184379 MEDIUM MS08-001 3r 182048 HIGH MS07-069 3r 182046 HIGH MS07-067 3r 182043 HIGH MS07-064 3r 179553 HIGH MS07-061 3r 176382 HIGH MS07-057 3r 176383 HIGH MS07-058 3r 170911 HIGH MS07-050 3r 170907 HIGH MS07-046 3r 170906 HIGH MS07-045 3r 170904 HIGH MS07-043 3r 164915 HIGH MS07-035 3r 164913 HIGH MS07-033 3r 164911 HIGH MS07-031 3r 160623 HIGH MS07-027 3r 157262 HIGH MS07-022 3r 157261 HIGH MS07-021 3r 157260 HIGH MS07-020 3r 157259 HIGH MS07-019 3r 156477 HIGH MS07-017 3r 150253 HIGH MS07-016 3r 150249 HIGH MS07-013 3r 150248 HIGH MS07-012 3r 150247 HIGH MS07-011 3r 150243 HIGH MS07-008 3r 150242 HIGH MS07-007 3r 150241 MEDIUM MS07-006 3r 145501 HIGH MS07-004 3r 141034 HIGH MS06-076 3r 141033 MEDIUM MS06-075 3r 137571 HIGH MS06-070 3r 133387 MEDIUM MS06-065 3r 133386 MEDIUM MS06-064 3r 133385 MEDIUM MS06-063 3r 133379 HIGH MS06-057 3r 129977 MEDIUM MS06-053 3r 129976 MEDIUM MS06-052 3r 126093 HIGH MS06-051 3r 126092 MEDIUM MS06-050 3r 126087 HIGH MS06-046 3r 126086 MEDIUM MS06-045 3r 126082 HIGH MS06-041 3r 126081 HIGH MS06-040 3r 123421 HIGH MS06-036 3r 123420 HIGH MS06-035 3r 120825 MEDIUM MS06-032 3r 120823 MEDIUM MS06-030 3r 120818 HIGH MS06-025 3r 120815 HIGH MS06-022 3r 117384 MEDIUM MS06-018 3r 114666 HIGH MS06-015 3r 108744 MEDIUM MS06-008 3r 108743 MEDIUM MS06-007 3r 108742 MEDIUM MS06-006 3r 104567 HIGH MS06-002 3r 104237 HIGH MS06-001 3r 96574 HIGH MS05-053 3r 93395 HIGH MS05-051 3r 93394 HIGH MS05-050 3r 93454 MEDIUM MS05-049 |
![]() | ![]() |
| ||||
| Re: Virus ventanas emergentes Descarga OTMoveit3 + MANUAL Ejecuta la Herramienta OTMoveIt:
Código HTML: :Files I:\Archivos de programa\Wingen\system.exe I:\DOCUME~1\PATXI\DATOSD~1\MICROS~1\ieudinit.exe 3r I:\Documents and Settings\PATXI\Configuraci¢n local\Temp\esentutl.exe 3r I:\Documents and Settings\PATXI\Datos de programa\Microsoft\ieudinit.exe 3r I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstinit.exe 3r I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstsc.exe 3r I:\Documents and Settings\PATXI\Datos de programa\Microsoft\rsvp.exe 3r I:\Documents and Settings\PATXI\Datos de programa\Microsoft\sessmgr.exe 3r I:\Documents and Settings\PATXI\Mis documentos\Programas\(ANTIVIRUS) NOD32 ESET.NOD.AntiVirus.v3.0.650.Business.Edition(32&64bit) updated-fixed 08-2008.rar I:\Documents and Settings\PATXI\Mis documentos\Programas\3D Studio Max 8.rar I:\Documents and Settings\PATXI\Mis documentos\Programas\Daemon Tools 4.0 + crack.rar I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\Codeki\XviD.MPEG-4.video.codec.v.2.1 (XVID DIVX DX50)(3)(2).exe I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\winavivideoconverterv6.3patchicu.zip I:\WINDOWS\comrepl.exe 3r 3r I:\WINDOWS\system32\drivers\logman.exe 3r I:\WINDOWS\system32\ebjnyuum.dll I:\WINDOWS\System32\frylxo.dll I:\WINDOWS\system32\uduiqdso.dll I:\WINDOWS\system32\vxyskcqi.dll K:\Mi m£sica\Melon Diesel discografia completa incluye taxi libre 2005 updated-fixed 03-2008.rar :Commands [emptytemp] [Reboot]
.-Descarga y actualiza <Malwarebytes' Anti-Malware+ Leer_manual> Usalo como indica su manual: Examen Completo/Quitar tod lo seleccionado/Reiniciar. Me dejas los reportes del OTMOveit , MalwareBytes y me comentas como va tu sistema. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Virus ventanas emergentes Muchas gracias, mi sistema ya va bien o por lo menos por ahora, te pongo los log del OTMoveIt 1º y del malware despues: Código: ========== FILES ========== I:\Archivos de programa\Wingen\system.exe moved successfully. File/Folder I:\DOCUME~1\PATXI\DATOSD~1\MICROS~1\ieudinit.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Configuraci¢n local\Temp\esentutl.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Datos de programa\Microsoft\ieudinit.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstinit.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstsc.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Datos de programa\Microsoft\rsvp.exe 3r not found. File/Folder I:\Documents and Settings\PATXI\Datos de programa\Microsoft\sessmgr.exe 3r not found. I:\Documents and Settings\PATXI\Mis documentos\Programas\(ANTIVIRUS) NOD32 ESET.NOD.AntiVirus.v3.0.650.Business.Edition(32&64bit) updated-fixed 08-2008.rar moved successfully. I:\Documents and Settings\PATXI\Mis documentos\Programas\3D Studio Max 8.rar moved successfully. I:\Documents and Settings\PATXI\Mis documentos\Programas\Daemon Tools 4.0 + crack.rar moved successfully. I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\Codeki\XviD.MPEG-4.video.codec.v.2.1 (XVID DIVX DX50)(3)(2).exe moved successfully. I:\Documents and Settings\PATXI\Mis documentos\Programas\Winavi\winavivideoconverterv6.3patchicu.zip moved successfully. File/Folder I:\WINDOWS\comrepl.exe 3r 3r not found. File/Folder I:\WINDOWS\system32\drivers\logman.exe 3r not found. LoadLibrary failed for I:\WINDOWS\system32\ebjnyuum.dll I:\WINDOWS\system32\ebjnyuum.dll NOT unregistered. File move failed. I:\WINDOWS\system32\ebjnyuum.dll scheduled to be moved on reboot. DllUnregisterServer procedure not found in I:\WINDOWS\System32\frylxo.dll I:\WINDOWS\System32\frylxo.dll NOT unregistered. I:\WINDOWS\System32\frylxo.dll moved successfully. LoadLibrary failed for I:\WINDOWS\system32\uduiqdso.dll I:\WINDOWS\system32\uduiqdso.dll NOT unregistered. File move failed. I:\WINDOWS\system32\uduiqdso.dll scheduled to be moved on reboot. DllUnregisterServer procedure not found in I:\WINDOWS\system32\vxyskcqi.dll I:\WINDOWS\system32\vxyskcqi.dll NOT unregistered. I:\WINDOWS\system32\vxyskcqi.dll moved successfully. File/Folder K:\Mi m£sica\Melon Diesel discografia completa incluye taxi libre 2005 updated-fixed 03-2008.rar not found. ========== COMMANDS ========== File delete failed. I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD06.tmp scheduled to be deleted on reboot. File delete failed. I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD07.tmp scheduled to be deleted on reboot. File delete failed. I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD08.tmp scheduled to be deleted on reboot. File delete failed. I:\DOCUME~1\PATXI\CONFIG~1\Temp\etilqs_HkHFOiK2rge7NiAG9SOV scheduled to be deleted on reboot. File delete failed. I:\DOCUME~1\PATXI\CONFIG~1\Temp\~DFD67C.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. I:\WINDOWS\temp\_avast4_\unp54371034.tmp scheduled to be deleted on reboot. File delete failed. I:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. I:\WINDOWS\temp\Perflib_Perfdata_5d0.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01072009_205552 Files moved on Reboot... File I:\WINDOWS\system32\ebjnyuum.dll not found! File I:\WINDOWS\system32\uduiqdso.dll not found! File I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD06.tmp not found! File I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD07.tmp not found! File I:\DOCUME~1\PATXI\CONFIG~1\Temp\AcrFD08.tmp not found! File I:\DOCUME~1\PATXI\CONFIG~1\Temp\etilqs_HkHFOiK2rge7NiAG9SOV not found! I:\DOCUME~1\PATXI\CONFIG~1\Temp\~DFD67C.tmp moved successfully. File I:\WINDOWS\temp\_avast4_\unp54371034.tmp not found! File move failed. I:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. File I:\WINDOWS\temp\Perflib_Perfdata_5d0.dat not found! I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_001_ moved successfully. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_002_ moved successfully. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_003_ moved successfully. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\Cache\_CACHE_MAP_ moved successfully. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\urlclassifier3.sqlite moved successfully. I:\Documents and Settings\PATXI\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\h1l1txt7.default\XUL.mfl moved successfully. Código: Malwarebytes' Anti-Malware 1.32
Versión de la Base de Datos: 1629
Windows 5.1.2600 Service Pack 2
08/01/2009 0:11:06
mbam-log-2009-01-08 (00-11-06).txt
Tipo de examen : Examen Completo (I:\|K:\|)
Objetos examinados: 149399
Tiempo transcurrido: 2 hour(s), 47 minute(s), 42 second(s)
Procesos en Memoria Infectados: 0
Módulos en Memoria Infectados: 0
Claves del Registro Infectadas: 2
Valores del Registro Infectados: 2
Elementos de Datos del Registro Infectados: 2
Carpetas Infectadas: 0
Ficheros Infectados: 9
Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Módulos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Claves del Registro Infectadas:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6523a9b1-9e4a-4896-bcce-08873eda5690} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6523a9b1-9e4a-4896-bcce-08873eda5690} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Valores del Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\IEudinit (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\mstsc (Trojan.Agent) -> Quarantined and deleted successfully.
Elementos de Datos del Registro Infectados:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: i:\windows\system32\drivers\logman.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: system32\drivers\logman.exe -> Quarantined and deleted successfully.
Carpetas Infectadas:
(No se han detectado elementos maliciosos)
Ficheros Infectados:
I:\WINDOWS\system32\frylxo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
I:\_OTMoveIt\MovedFiles\01072009_205552\WINDOWS\system32\frylxo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
I:\_OTMoveIt\MovedFiles\01072009_205552\WINDOWS\system32\vxyskcqi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
I:\Documents and Settings\PATXI\Datos de programa\Microsoft\ieudinit.exe (Trojan.Agent) -> Delete on reboot.
I:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
I:\WINDOWS\comrepl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
I:\WINDOWS\system32\drivers\logman.exe (Trojan.Agent) -> Quarantined and deleted successfully.
I:\Documents and Settings\PATXI\Datos de programa\Microsoft\mstsc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
I:\Documents and Settings\PATXI\Datos de programa\Microsoft\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
|
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| seguire infectado | flony | Foro de Virus y Spywares | 17 | 21/03/09 19:38:01 |
| infección con virus, troyanos, adware... (solucionado) | chondodave | Temas Solucionados | 5 | 07/11/08 15:21:39 |
| Zlob.PornMagPass en Drivers ATI | toros | Foro de Virus y Spywares | 3 | 15/02/07 17:30:01 |
| Smitfraud - Procesador saturado y pop-ups de falso Messenger indicando fallas | gus296 | Foro Oficial de HijackThis en español | 11 | 28/11/06 11:54:26 |
| Hotoffers (Estoy muy emproblemado) | Emproblemado | Foro Oficial de HijackThis en español | 7 | 22/04/05 07:48:05 |