| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex Hola ![]() Antes de comenzar Desactiva el Tea Timer del Spybot S & D. Luego intenta arreglar el modo seguro con estos pasos: Listado de procedimientos Despues:
Paso.- 1
Paso .-2 Ejecuta.
Paso.-3
Saludos. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex Muy bien acá espero esos reportes junto con tus comentarios ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex --- Search result list --- Win32.Agent.arnx: [SBI $50973D76] ID de clase (Clave del registro, nothing done) HKEY_CLASSES_ROOT\CLSID\{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09} Win32.Rungbu.a: [SBI $8819FA0B] ID de clase (Clave del registro, nothing done) HKEY_CLASSES_ROOT\CLSID\MADOWN --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) --- 2009-01-26 blindman.exe (1.0.0.8) 2009-01-26 SDFiles.exe (1.6.1.7) 2009-01-26 SDMain.exe (1.0.0.6) 2009-01-26 SDShred.exe (1.0.2.5) 2009-01-26 SDUpdate.exe (1.6.0.12) 2009-01-26 SpybotSD.exe (1.6.2.46) 2009-01-26 TeaTimer.exe (1.6.4.26) 2009-03-29 unins000.exe (51.49.0.0) 2009-01-26 Update.exe (1.6.0.7) 2009-01-26 advcheck.dll (1.6.2.15) 2007-04-02 aports.dll (2.1.0.0) 2008-06-14 DelZip179.dll (1.79.11.1) 2009-01-26 SDHelper.dll (1.6.2.14) 2008-06-19 sqlite3.dll 2009-01-26 Tools.dll (2.1.6.10) 2009-01-16 UninsSrv.dll (1.0.0.0) 2009-01-22 Includes\Adware.sbi (*) 2009-03-25 Includes\AdwareC.sbi (*) 2009-01-22 Includes\Cookies.sbi (*) 2009-03-25 Includes\Dialer.sbi (*) 2009-03-25 Includes\DialerC.sbi (*) 2009-01-22 Includes\HeavyDuty.sbi (*) 2009-02-10 Includes\Hijackers.sbi (*) 2009-03-03 Includes\HijackersC.sbi (*) 2009-03-17 Includes\Keyloggers.sbi (*) 2009-03-17 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2009-03-25 Includes\Malware.sbi (*) 2009-03-25 Includes\MalwareC.sbi (*) 2009-03-25 Includes\PUPS.sbi (*) 2009-03-25 Includes\PUPSC.sbi (*) 2009-01-22 Includes\Revision.sbi (*) 2009-01-13 Includes\Security.sbi (*) 2009-03-23 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2009-01-28 Includes\Spyware.sbi (*) 2009-01-28 Includes\SpywareC.sbi (*) 2009-03-25 Includes\Tracks.uti 2009-03-25 Includes\Trojans.sbi (*) 2009-03-25 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-12-24 Plugins\TCPIPAddress.dll --- System information --- Windows XP (Build: 2600) Service Pack 2 (5.1.2600) / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs / Windows / SP1: Microsoft National Language Support Downlevel APIs / Windows XP / SP0: Actualización de seguridad para Windows Internet Explorer 7 (KB938127-v2) / Windows XP / SP0: Actualización de seguridad para Windows Internet Explorer 7 (KB961260) / Windows XP / SP3: Actualización para Windows XP (KB898461) / Windows XP / SP3: Hotfix for Windows XP (KB915865) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB938464-v2) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB950760) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB950762) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB950974) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB951376-v2) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB951698) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB951748) / Windows XP / SP4: Revisión para Windows XP (KB952287) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB952954) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB954600) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB955069) / Windows XP / SP4: Actualización para Windows XP (KB955839) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB956802) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB956803) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB956841) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB957097) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB958644) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB958687) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB958690) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB960225) / Windows XP / SP4: Actualización de seguridad para Windows XP (KB960715) / Windows XP / SP4: Actualización para Windows XP (KB967715) / Windows XP OOB / SP10: High Definition Audio Driver Package - KB835221 --- Startup entries list --- Located: HK_LM:Run, BigDogPath command: C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera file: C:\WINDOWS\VM_STI.EXE size: 40960 MD5: 0C18CF0D16418E9FB7069ABB75860028 Located: HK_LM:Run, DLA command: C:\WINDOWS\System32\DLA\DLACTRLW.EXE file: C:\WINDOWS\System32\DLA\DLACTRLW.EXE size: 122940 MD5: 5B1D53E352DB12E14987DECDE1B17906 Located: HK_LM:Run, egui command: "C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice file: C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe size: 2021400 MD5: 861C702C4612B68FD9C36CB60245087B Located: HK_LM:Run, Google Desktop Search command: "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup file: C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe size: 30192 MD5: 9E37E0C528E1E3A79E215B6A4EEA2143 Located: HK_LM:Run, igfxhkcmd command: C:\WINDOWS\system32\hkcmd.exe file: C:\WINDOWS\system32\hkcmd.exe size: 77824 MD5: 82ADC58B63E069AC4641A33EA9841E54 Located: HK_LM:Run, igfxpers command: C:\WINDOWS\system32\igfxpers.exe file: C:\WINDOWS\system32\igfxpers.exe size: 114688 MD5: A0E2FFB7B0FCE82AA3BCC3105306C45C Located: HK_LM:Run, igfxtray command: C:\WINDOWS\system32\igfxtray.exe file: C:\WINDOWS\system32\igfxtray.exe size: 94208 MD5: 5656D65A9A9F1E3D68D64A350CFF1732 Located: HK_LM:Run, iTunesHelper command: "C:\Archivos de programa\iTunes\iTunesHelper.exe" file: C:\Archivos de programa\iTunes\iTunesHelper.exe size: 229952 MD5: CECCC68B54E8E27C93DBEDE85F160C96 Located: HK_LM:Run, mouseElf command: C:\ARCHIV~1\SCROLL~1\MouseElf.EXE file: C:\ARCHIV~1\SCROLL~1\MouseElf.EXE size: 438364 MD5: 44BD328A18133A541F96106A4F3ECD0B Located: HK_LM:Run, QuickTime Task command: "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime file: C:\Archivos de programa\QuickTime\qttask.exe size: 282624 MD5: D2C900031FD445B5464ABB5629388BE3 Located: HK_LM:Run, SigmatelSysTrayApp command: stsystra.exe file: C:\WINDOWS\stsystra.exe size: 393216 MD5: D283080D89D421DFF88509FACD8CB95B Located: HK_LM:Run, SNPSTD2 command: C:\WINDOWS\vsnpstd2.exe file: C:\WINDOWS\vsnpstd2.exe size: 40960 MD5: BC9ECBD26261B216F345C587ACAE6811 Located: HK_LM:Run, SunJavaUpdateSched command: "C:\Archivos de programa\Java\jre6\bin\jusched.exe" file: C:\Archivos de programa\Java\jre6\bin\jusched.exe size: 136600 MD5: B98FFA8288EFAABC436C30D198608345 Located: HK_CU:Run, CTFMON.EXE where: .DEFAULT... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A Located: HK_CU:Run, MsnMsgr where: .DEFAULT... command: "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background file: C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe size: 5674352 MD5: 011BFF1191C62BA8D48858B56091977A Located: HK_CU:RunOnce, nlsf where: .DEFAULT... command: cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" file: C:\WINDOWS\system32\cmd.exe size: 795648 MD5: 0E84DC65516E3E8057A17A838F58A288 Located: HK_CU:RunOnce, PackNoVs where: .DEFAULT... command: "C:\WINDOWS\BricoPacks\Vista Inspirat\Pack It!.exe" --unsetvs file: C:\WINDOWS\BricoPacks\Vista Inspirat\Pack It!.exe size: 94208 MD5: 663E3ABC82271BE10C141D4CE66ABB93 Located: HK_CU:RunOnce, tscuninstall where: .DEFAULT... command: %systemroot%\system32\tscupgrd.exe file: C:\WINDOWS\system32\tscupgrd.exe size: 44544 MD5: 0FDC2094FD70D807C3A7B7C630CF96CE Located: HK_CU:Run, CTFMON.EXE where: S-1-5-19... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A Located: HK_CU:RunOnce, nlsf where: S-1-5-19... command: cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" file: C:\WINDOWS\system32\cmd.exe size: 795648 MD5: 0E84DC65516E3E8057A17A838F58A288 Located: HK_CU:RunOnce, tscuninstall where: S-1-5-19... command: %systemroot%\system32\tscupgrd.exe file: C:\WINDOWS\system32\tscupgrd.exe size: 44544 MD5: 0FDC2094FD70D807C3A7B7C630CF96CE Located: HK_CU:Run, CTFMON.EXE where: S-1-5-20... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A Located: HK_CU:RunOnce, nlsf where: S-1-5-20... command: cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" file: C:\WINDOWS\system32\cmd.exe size: 795648 |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex MD5: 0E84DC65516E3E8057A17A838F58A288 Located: HK_CU:RunOnce, tscuninstall where: S-1-5-20... command: %systemroot%\system32\tscupgrd.exe file: C:\WINDOWS\system32\tscupgrd.exe size: 44544 MD5: 0FDC2094FD70D807C3A7B7C630CF96CE Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} where: S-1-5-21-842925246-861567501-725345543-500... command: "C:\Archivos de programa\Archivos comunes\Ahead\lib\NMBgMonitor.exe" file: C:\Archivos de programa\Archivos comunes\Ahead\lib\NMBgMonitor.exe size: 90112 MD5: 666BF0245BE370CFCF4B4057B8AF6E17 Located: HK_CU:Run, ctfmon.exe where: S-1-5-21-842925246-861567501-725345543-500... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A Located: HK_CU:Run, kava where: S-1-5-21-842925246-861567501-725345543-500... command: C:\WINDOWS\system32\kavo.exe file: C:\WINDOWS\system32\kavo.exe size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: HK_CU:Run, SpybotSD TeaTimer where: S-1-5-21-842925246-861567501-725345543-500... command: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe file: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe size: 2144088 MD5: 896A1DB9A972AD2339C2E8569EC926D1 Located: HK_CU:Run, CTFMON.EXE where: S-1-5-18... command: C:\WINDOWS\system32\CTFMON.EXE file: C:\WINDOWS\system32\CTFMON.EXE size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A Located: HK_CU:Run, MsnMsgr where: S-1-5-18... command: "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background file: C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe size: 5674352 MD5: 011BFF1191C62BA8D48858B56091977A Located: HK_CU:RunOnce, nlsf where: S-1-5-18... command: cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" file: C:\WINDOWS\system32\cmd.exe size: 795648 MD5: 0E84DC65516E3E8057A17A838F58A288 Located: HK_CU:RunOnce, PackNoVs where: S-1-5-18... command: "C:\WINDOWS\BricoPacks\Vista Inspirat\Pack It!.exe" --unsetvs file: C:\WINDOWS\BricoPacks\Vista Inspirat\Pack It!.exe size: 94208 MD5: 663E3ABC82271BE10C141D4CE66ABB93 Located: HK_CU:RunOnce, tscuninstall where: S-1-5-18... command: %systemroot%\system32\tscupgrd.exe file: C:\WINDOWS\system32\tscupgrd.exe size: 44544 MD5: 0FDC2094FD70D807C3A7B7C630CF96CE Located: Inicio (común), Monitor Apache Servers.lnk where: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio... command: C:\Archivos de programa\Apache Group\Apache2\bin\ApacheMonitor.exe file: C:\Archivos de programa\Apache Group\Apache2\bin\ApacheMonitor.exe size: 41042 MD5: 23A00993DB5CD0DF530842F214A66499 Located: Inicio (usuario), Stardock ObjectDock.lnk where: C:\Documents and Settings\Administrador\Menú Inicio\Programas\Inicio... command: C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe file: C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe size: 1826885 MD5: FFED2F0C2E32579F2E07404B2AB7E6BF Located: Inicio (usuario), Y'z ToolBar.lnk where: C:\Documents and Settings\Administrador\Menú Inicio\Programas\Inicio... command: C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe file: C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe size: 90112 MD5: B63A4CFCEF280F4CACF0A17E6C484D56 Located: Inicio (usuario), Stardock ObjectDock.lnk where: C:\WINDOWS\system32\config\systemprofile\Menú Inicio\Programas\Inicio... command: C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe file: C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe size: 1826885 MD5: FFED2F0C2E32579F2E07404B2AB7E6BF Located: Inicio (usuario), Y'z ToolBar.lnk where: C:\WINDOWS\system32\config\systemprofile\Menú Inicio\Programas\Inicio... command: C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe file: C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe size: 90112 MD5: B63A4CFCEF280F4CACF0A17E6C484D56 Located: Inicio (desactivado), Inicio rápido de Adobe Reader (DISABLED) command: C:\ARCHIV~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE file: C:\ARCHIV~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE size: 29696 MD5: DEB88AEF013DD1EEFB462D7CAD642166 Located: WinLogon, crypt32chain command: crypt32.dll file: crypt32.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cryptnet command: cryptnet.dll file: cryptnet.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cscdll command: cscdll.dll file: cscdll.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, igfxcui command: igfxdev.dll file: igfxdev.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, ScCertProp command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, Schedule command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, sclgntfy command: sclgntfy.dll file: sclgntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, SensLogn command: WlNotify.dll file: WlNotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, termsrv command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, wlballoon command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! --- Browser helper object list --- {4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac} (MyPlayCity Toolbar) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: MyPlayCity Toolbar Path: C:\Archivos de programa\MyPlayCity\ Long name: tbMyP0.dll {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: DriveLetterAccess description: Hewlett-Packard's DLA software classification: Unknown known filename: tfswshx.dll info link: info source: TonyKlein Path: C:\WINDOWS\System32\DLA\ Long name: DLASHX_W.DLL Short name: Date (created): 15/07/2007 12:24:54 p.m. Date (last access): 29/03/2009 11:05:12 a.m. Date (last write): 07/11/2005 05:20:00 a.m. Filesize: 110652 Attributes: archive MD5: A68BD98A43710FE5D19C92158E341F0C CRC32: A34F395A Version: 5.20.12.0 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (Java(tm) Plug-In SSV Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Java(tm) Plug-In SSV Helper Path: C:\Archivos de programa\Java\jre6\bin\ Long name: ssv.dll Short name: Date (created): 16/12/2008 05:38:08 p.m. Date (last access): 29/03/2009 11:08:16 a.m. Date (last write): 16/12/2008 05:38:08 p.m. Filesize: 320920 Attributes: archive MD5: 35E6FB6E6003BD54A5D69C9C1C762192 CRC32: 9699660C Version: 6.0.110.3 |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex {7E853D72-626A-48EC-A868-BA8D5E23E045} () location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Windows Live Sign-in Helper Path: C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\ Long name: WindowsLiveLogin.dll Short name: WINDOW~1.DLL Date (created): 31/08/2006 08:33:06 p.m. Date (last access): 29/03/2009 11:08:16 a.m. Date (last write): 31/08/2006 08:33:06 p.m. Filesize: 322368 Attributes: archive MD5: E43F7CFDEE2B00A22C96C168147B20D3 CRC32: 2AEACC43 Version: 4.100.313.1 {DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Java(tm) Plug-In 2 SSV Helper Path: C:\Archivos de programa\Java\jre6\bin\ Long name: jp2ssv.dll Short name: Date (created): 16/12/2008 05:38:06 p.m. Date (last access): 29/03/2009 11:02:26 a.m. Date (last write): 16/12/2008 05:38:06 p.m. Filesize: 34816 Attributes: archive MD5: 5D57FD3DF32DC69CEC3D1D54B4C43162 CRC32: D7C13FB2 Version: 6.0.110.3 {E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: JQSIEStartDetectorImpl CLSID name: JQSIEStartDetectorImpl Class Path: C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\ Long name: jqs_plugin.dll Short name: JQS_PL~1.DLL Date (created): 16/12/2008 05:38:08 p.m. Date (last access): 29/03/2009 11:01:54 a.m. Date (last write): 16/12/2008 05:38:08 p.m. Filesize: 73728 Attributes: archive MD5: F68EDAFE003F2B3523C0742CD3B8D673 CRC32: 9C709350 Version: 6.0.110.3 {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} (SingleInstance Class) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: SingleInstance Class Path: C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\ Long name: YTSingleInstance.dll Short name: YTSING~1.DLL Date (created): 28/07/2008 05:47:42 a.m. Date (last access): 29/03/2009 11:01:02 a.m. Date (last write): 28/07/2008 05:47:42 a.m. Filesize: 160496 Attributes: archive MD5: F64C4241FE5E519F62C47C361DC671D7 CRC32: 5F6F96A7 Version: 2008.7.28.1 --- ActiveX list --- {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) DPF name: CLSID name: MSN Photo Upload Tool Installer: C:\WINDOWS\Downloaded Program Files\MsnPUpld.inf Codebase: http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab Path: C:\WINDOWS\Downloaded Program Files\ Long name: MsnPUpld.dll Short name: Date (created): 20/06/2006 03:44:04 p.m. Date (last access): 29/03/2009 10:45:26 a.m. Date (last write): 20/06/2006 03:44:04 p.m. Filesize: 379704 Attributes: archive MD5: D2FB109C3F0DAAAA4A73E5921656DB3E CRC32: A13093E8 Version: 10.0.913.0 {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) DPF name: CLSID name: WUWebControl Class Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf Codebase: http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238291889625 Path: C:\WINDOWS\system32\ Long name: wuweb.dll Short name: Date (created): 15/07/2007 12:01:58 p.m. Date (last access): 29/03/2009 10:46:34 a.m. Date (last write): 16/10/2008 02:12:24 p.m. Filesize: 202776 Attributes: archive MD5: 0006DE8037F5A562F96B461B3C557C3C CRC32: 9B107DED Version: 7.2.6001.788 {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_11 Installer: C:\WINDOWS\Downloaded Program Files\jinstall-6u11.inf Codebase: http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688 description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M. Kolla Path: C:\Archivos de programa\Java\jre6\bin\ Long name: npjpi160_11.dll Short name: NPJPI1~1.DLL Date (created): 16/12/2008 05:38:06 p.m. Date (last access): 29/03/2009 09:41:30 a.m. Date (last write): 16/12/2008 05:38:06 p.m. Filesize: 132504 Attributes: archive MD5: D400116F6776ACB6EDB6B1F5EEB9F92D CRC32: CECB5751 Version: 6.0.110.3 {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) DPF name: Java Runtime Environment 1.4.2 CLSID name: Java Plug-in 1.4.2_06 Installer: Codebase: http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab Path: C:\Archivos de programa\Java\j2re1.4.2_06\bin\ Long name: NPJPI142_06.dll Short name: NPJPI1~1.DLL Date (created): 28/09/2004 08:26:10 p.m. Date (last access): 29/03/2009 09:37:02 a.m. Date (last write): 28/09/2004 08:26:00 p.m. Filesize: 65650 Attributes: archive MD5: 69E5147BA901A9238C4EB08C84E1A85B CRC32: 6CB34BCC Version: 1.4.2.60 {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_11 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Path: C:\Archivos de programa\Java\jre6\bin\ Long name: npjpi160_11.dll Short name: NPJPI1~1.DLL Date (created): 16/12/2008 05:38:06 p.m. Date (last access): 29/03/2009 11:49:32 a.m. Date (last write): 16/12/2008 05:38:06 p.m. Filesize: 132504 Attributes: archive MD5: D400116F6776ACB6EDB6B1F5EEB9F92D CRC32: CECB5751 Version: 6.0.110.3 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_11 Installer: Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Path: C:\Archivos de programa\Java\jre6\bin\ Long name: npjpi160_11.dll Short name: NPJPI1~1.DLL Date (created): 16/12/2008 05:38:06 p.m. Date (last access): 29/03/2009 11:49:32 a.m. Date (last write): 16/12/2008 05:38:06 p.m. Filesize: 132504 Attributes: archive MD5: D400116F6776ACB6EDB6B1F5EEB9F92D CRC32: CECB5751 Version: 6.0.110.3 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) DPF name: CLSID name: Shockwave Flash Object Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf Codebase: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab description: Macromedia Shockwave Flash Player classification: Legitimate known filename: info link: info source: Patrick M. Kolla Path: C:\WINDOWS\system32\Macromed\Flash\ Long name: Flash10a.ocx Short name: Date (created): 04/10/2008 10:16:26 p.m. Date (last access): 29/03/2009 11:25:10 a.m. Date (last write): 04/10/2008 10:16:26 p.m. Filesize: 3789728 Attributes: readonly archive MD5: 466C1355934925768822E380DA6E6E4A CRC32: 48EC1E52 Version: 10.0.12.36 --- Process list --- PID: 0 ( 0) [System] PID: 464 ( 4) \SystemRoot\System32\smss.exe size: 50688 PID: 536 ( 464) \??\C:\WINDOWS\system32\csrss.exe size: 6144 PID: 584 ( 464) \??\C:\WINDOWS\system32\winlogon.exe size: 505344 PID: 632 ( 584) C:\WINDOWS\system32\services.exe size: 108544 MD5: F9852F505E0699BB83D5C6321917040B PID: 644 ( 584) C:\WINDOWS\system32\lsass.exe size: 13312 MD5: 2B0B88652C9F6714FD4886839B3B0442 PID: 828 ( 632) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 876 ( 632) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 972 ( 632) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 1020 ( 632) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 1108 ( 632) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 1508 ( 632) C:\WINDOWS\system32\spoolsv.exe size: 57856 MD5: 1CF5AF263287CF6FEBF31539833EAF4A PID: 1576 (1460) C:\WINDOWS\Explorer.EXE size: 1883648 MD5: D9D4E78CF64320B9B4AD44598E6D0B09 PID: 1864 (1576) C:\WINDOWS\System32\DLA\DLACTRLW.EXE size: 122940 MD5: 5B1D53E352DB12E14987DECDE1B17906 PID: 1876 (1576) C:\WINDOWS\stsystra.exe size: 393216 MD5: D283080D89D421DFF88509FACD8CB95B PID: 1900 (1576) C:\WINDOWS\system32\hkcmd.exe size: 77824 MD5: 82ADC58B63E069AC4641A33EA9841E54 PID: 1916 (1576) C:\WINDOWS\system32\igfxpers.exe size: 114688 MD5: A0E2FFB7B0FCE82AA3BCC3105306C45C PID: 1928 (1576) C:\WINDOWS\VM_STI.EXE size: 40960 MD5: 0C18CF0D16418E9FB7069ABB75860028 PID: 1956 (1576) C:\WINDOWS\vsnpstd2.exe size: 40960 MD5: BC9ECBD26261B216F345C587ACAE6811 PID: 1968 (1576) C:\Archivos de programa\Java\jre6\bin\jusched.exe size: 136600 MD5: B98FFA8288EFAABC436C30D198608345 PID: 1984 ( 828) C:\WINDOWS\system32\igfxsrvc.exe size: 159744 MD5: 2888E77950D6E98A1B1D1BBD05FA4887 PID: 2016 (1576) C:\Archivos de programa\iTunes\iTunesHelper.exe size: 229952 MD5: CECCC68B54E8E27C93DBEDE85F160C96 PID: 152 (1576) C:\Archivos de programa\QuickTime\qttask.exe size: 282624 MD5: D2C900031FD445B5464ABB5629388BE3 PID: 172 (1576) C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe size: 30192 MD5: 9E37E0C528E1E3A79E215B6A4EEA2143 PID: 204 (1576) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe size: 2021400 MD5: 861C702C4612B68FD9C36CB60245087B PID: 216 (1576) C:\Archivos de programa\Archivos comunes\Ahead\lib\NMBgMonitor.exe size: 90112 MD5: 666BF0245BE370CFCF4B4057B8AF6E17 PID: 236 (1576) C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 25ECFA69AF1563FDE8DFD31F9954497A PID: 400 (1576) C:\Archivos de programa\Apache Group\Apache2\bin\ApacheMonitor.exe size: 41042 MD5: 23A00993DB5CD0DF530842F214A66499 PID: 456 (1576) C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe size: 1826885 MD5: FFED2F0C2E32579F2E07404B2AB7E6BF PID: 516 (1576) C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe size: 90112 MD5: B63A4CFCEF280F4CACF0A17E6C484D56 PID: 1892 ( 632) C:\Archivos de programa\Apache Group\Apache2\bin\Apache.exe size: 20541 MD5: 801B28C9171271686D608F112747B107 PID: 576 ( 632) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe size: 727720 MD5: D543E7E8BCAE3F5D256335EEE809ADF5 PID: 296 (1892) C:\Archivos de programa\Apache Group\Apache2\bin\Apache.exe size: 20541 MD5: 801B28C9171271686D608F112747B107 PID: 1124 ( 632) C:\Archivos de programa\Java\jre6\bin\jqs.exe size: 152984 MD5: 32192B4EBE8720ED8D49A455C962CB91 PID: 2592 ( 632) C:\mysql\bin\mysqld-nt.exe size: 2203648 MD5: 0476F23BD363BAD42D7E41A1142ECD71 PID: 2744 ( 632) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: FA03E1FC17F38FBDBA81470D08B3E416 PID: 3168 ( 632) C:\Archivos de programa\iPod\bin\iPodService.exe size: 451136 MD5: 216D2B5F6B9B81E5422E67416C7CE91C PID: 3316 ( 632) C:\WINDOWS\system32\wbem\wmiapsrv.exe size: 126464 MD5: 2710BF9B02BC92D352CFCABAC64918FA PID: 3788 ( 632) C:\WINDOWS\System32\alg.exe size: 44544 MD5: 906D6932D533F1591CAA84E846B9BA06 PID: 2996 (3880) C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe size: 5365592 MD5: 0477C2F9171599CA5BC3307FDFBA8D89 PID: 2800 (3880) C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe size: 2144088 MD5: 896A1DB9A972AD2339C2E8569EC926D1 PID: 2784 ( 172) C:\WINDOWS\system32\rundll32.exe size: 33280 MD5: 3175EB8EF1C6C38F440FCB2D1403B823 PID: 3688 (1576) C:\WINDOWS\system32\notepad.exe size: 62464 MD5: EDEBCA12518F602DFA7A9E8A6C5AAB8D PID: 4 ( 0) System |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex haozs1.dll c:\windows\system32 probablemente Trojan.Packed.191 Eliminado. bitdefender_totalsecurity_fp_2008_32b.exe/bdts.msi/stream023\livesrv.exe C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs\bitdefender _totalsecurity_fp_2008_ probablemente DLOADER.Trojan stream023 C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs Archivo comprimido contiene objetos infectados bdts.msi C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs Archivo comprimido contiene objetos infectados bitdefender_totalsecurity_fp_2008_32b.exe C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs Archivo comprimido contiene objetos infectados Movido. NOD32 Bisiness Edition.exe\key.exe C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs\NOD32 Bisiness Edition.exe Trojan.Iahonor NOD32 Bisiness Edition.exe C:\Documents and Settings\Administrador\Configuración local\Temp\ir_ext_temp_0\AutoPlay\Docs Archivo comprimido contiene objetos infectados Movido. RegUBP2b-Administrador.reg C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Eliminado. a1agmur.cmd D:\ Trojan.PWS.Wsgame.4983 Eliminado. dbrxubcw.com D:\ Trojan.PWS.Wsgame.4983 Eliminado. em8tqm.cmd D:\ Trojan.PWS.Wsgame.4983 Eliminado. gi2ky.exe D:\ Trojan.PWS.Wsgame.4983 Eliminado. i.com D:\ Trojan.PWS.Wsgame.4983 Eliminado. jm3cx96.bat D:\ Trojan.PWS.Wsgame.4983 Eliminado. luk1ylq.com D:\ Trojan.PWS.Wsgame.4983 Eliminado. u.com D:\ Trojan.PWS.Wsgame.4983 Eliminado. uxkl0apt.bat D:\ Trojan.PWS.Wsgame.4983 Eliminado. xdw.com D:\ Trojan.PWS.Wsgame.4983 Eliminado. |
![]() | ![]() |
| ||||
| Re: tengo virus...win.32rungbu.a win32agent.arnex Si envíame los reportes que falta y me vas comentando como va el funcionamiento de tu pc y si los problemas se van desapareciendo. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| seguire infectado | flony | Foro de Virus y Spywares | 17 | 21/03/09 20:38:01 |
| Ayuda con estos problemas!!!!! (Terminado - Formateo) | GASOLINAMAN | Temas Solucionados | 18 | 22/02/09 17:08:24 |
| Una SOLUCION para FS-FixBagle, Malware o Herramienta de desinfección?? (Solucionado) | labombarda | Temas Solucionados | 11 | 13/11/08 20:54:15 |
| Trojan/Toosrrr.SRR, Ayuda (Formateo) | chinty | Temas Solucionados | 14 | 10/09/08 16:12:33 |
| about:blank (solucionado) | rubentome | Temas Solucionados | 13 | 06/06/05 05:08:53 |