| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| |||
que tal gente de InfoSpyware, espero me puedan ayuda con este problema, ultimamente mi pc a estado algo lenta y me hackearon unos correos que tenia hace poco, recurri a este foro para buscar ayuda y realize los 11 pasos para eliminar malware de este foro le cual esta excelente por ultimo hize un escaneo con el Panda Active Scan 2.0 y me detecto esto, espero me puedan ayudar a eliminar lo que esta causando problemas ![]() Código: ;*********************************************************************************************************************************************************************************** ANALYSIS: 2009-05-28 19:59:45 PROTECTIONS: 1 MALWARE: 25 SUSPECTS: 6 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== ESET NOD32 Antivirus 3.0 3.0 No Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.atdmt.com/] 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.tribalfusion.com/] 00145732 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.as-eu.falkag.net/] 00145732 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.as-eu.falkag.net/] 00145732 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.as-eu.falkag.net/] 00145732 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.as-eu.falkag.net/] 00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.revenue.net/] 00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.xiti.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.advertising.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.ads.pointroll.com/] 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.realmedia.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.questionmarket.com/] 00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Pedro\Cookies\pedro@go[1].txt 00199981 Cookie/Seeq TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.www48.seeq.com/] 00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[searchportal.information.com/] 00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[searchportal.information.com/] 00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[searchportal.information.com/] 00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\Pedro\Cookies\pedro@target[1].txt 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.atwola.com/] 00278769 Application/PRScheduler HackTools No 0 Yes No C:\Documents and Settings\Jose\Application Data\TuneUp Software\TuneUp Utilities\StartUp Manager\Disabled objects\PowerReg Scheduler.exe 00525933 Trj/Banker.HIF Virus/Trojan No 1 No No C:\WINDOWS\system32\1170690616.exe[■%%\BrwsPtnr.dll] 00525933 Trj/Banker.HIF Virus/Trojan No 1 No No C:\WINDOWS\system32\winstlr32.exe[■%%\BrwsPtnr.dll] 01196325 Cookie/Enhance TrackingCookie No 0 Yes No C:\Documents and Settings\Jose\Application Data\altimit-dev\lolifox\Profiles\pen1yb6e.default\cookies.txt[.enhance.com/] 01299703 Trj/Banker.HIF Virus/Trojan No 1 No No C:\WINDOWS\system32\1170690616.exe[■%%\dmdtia.dll] 02885017 Trj/Downloader.RON Virus/Trojan No 1 No No C:\WINDOWS\system32\1170690616.exe[■%%\dxdtwa.dll] 02885017 Trj/Downloader.RON Virus/Trojan No 1 No No C:\WINDOWS\system32\winstlr32.exe[■%%\msclti32.dll] 02894004 Trj/Multidropper.RLH Virus/Trojan No 0 Yes No C:\WINDOWS\system32\1170690616.exe 03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Jose\My Documents\swiftoptimizer\setup.exe 03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Jose\My Documents\swiftoptimizer.zip[setup.exe] 03783579 Trj/Downloader.MDW Virus/Trojan No 0 Yes No C:\Documents and Settings\Jose\My Documents\AE7TC-plugins_jdwashere\AE7TC-plugins\Trapcode.Multikeygen.v1.3.exe 03783579 Trj/Downloader.MDW Virus/Trojan No 0 No No C:\Documents and Settings\Jose\Desktop\animeops\All Trapcode Plugins.rar[Trapcode-Keygen.exe] 04098633 Adware/AccesMembre Adware No 0 Yes No C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\setup.exe 04189006 Generic Trojan Virus/Trojan No 0 No No C:\Documents and Settings\Jose\My Documents\RENDERS\Flash_Favorite_1.8.1.rar[Flash Favorite 1.8.1\Keygen\FlashFavoritekeygen.exe] 04474683 Generic Trojan Virus/Trojan No 0 No No C:\Documents and Settings\Jose\Desktop\animeops\Profound.Effects.Nous.rar[Profound.Effects.Nous\Profound Effects Useful Assistants 1.0\Profound Effects Useful Assistants 1.0.rar][KEYGEN.EXE] ;=================================================================================================================================================================================== SUSPECTS Sent Location T ;=================================================================================================================================================================================== No C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\topazvivacity131.msi[unk_0055][_1C7CC64F6DD34C4EBAECE8718782A42D] No C:\Documents and Settings\Jose\My Documents\topazadjust_setup\topazadjust24_setup\topazadjust_setup.msi[unk_0054][_74950D0496914411B62E7FC608178E6E] No C:\Documents and Settings\Jose\My Documents\topazadjust_setup.zip[topazadjust24_setup/topazadjust_setup.msi][unk_0054][_74950D0496914411B62E7FC608178E6E] No C:\Program Files\Topaz Labs LLC\Topaz Vivacity\RegProduct.exe T No C:\WINDOWS\system32\mswinsck.oca T No C:\WINDOWS\system32\winstlr32.exe[■%%\mswinsck.oca] T ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description T ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== espero me ayuden con esto y gracias por su tiempo ![]() |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: Problemas detectados por panda active scan, ayuda porfavor Según el reporte de panda,
Descarga: OTMoveIt3 lo guardas en el Escritorio. • Haz un doble clic sobre OTMoveIt.exe para ejecutarlo. • Asegurate que este marcado : Unregister Dll's and Ocx's • Copia el texto que se encuentra en el cuadrado más abajo, y pega el texto en el marco de izquierdo de OTMoveIt nombrado : Paste List of Filas / Folders to be moved. • (archivos que van en cita) Código HTML: :files C:\Documents and Settings\Jose\Application Data\TuneUp Software\TuneUp Utilities\StartUp Manager\Disabled objects\PowerReg Scheduler.exe C:\Documents and Settings\Jose\Desktop\animeops\All Trapcode Plugins.rar C:\Documents and Settings\Jose\Desktop\animeops\Profound.Effects.Nous.rar C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\setup.exe C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\topazvivacity131.msi C:\Documents and Settings\Jose\My Documents\AE7TC-plugins_jdwashere\AE7TC-plugins\Trapcode.Multikeygen.v1.3.exe C:\Documents and Settings\Jose\My Documents\RENDERS\Flash_Favorite_1.8.1.rar C:\Documents and Settings\Jose\My Documents\swiftoptimizer.zip C:\Documents and Settings\Jose\My Documents\swiftoptimizer\setup.exe C:\Documents and Settings\Jose\My Documents\topazadjust_setup.zip C:\Documents and Settings\Jose\My Documents\topazadjust_setup\topazadjust24_setup\topazadjust_setup.msi C:\Program Files\Topaz Labs LLC\Topaz Vivacity\RegProduct.exe C:\WINDOWS\system32\1170690616.exe C:\WINDOWS\system32\mswinsck.oca C:\WINDOWS\system32\winstlr32.exe C:\WINDOWS\system32\winstlr32.exe :commands [emptytemp] [purity] [Reboot] Haz clic en MoveIt! Para lanzar la supresión. • Cuando el resultado aparece en el marco Results, haz clic en Exit. • Reinicia el PC (Este paso es muy importante) Envía el informe (reporte) de OTMoveIt situado sobre: C: \ _OTMoveIt\MovedFiles....tx Saludos espero los reportes. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Problemas detectados por panda active scan, ayuda porfavor Es excelente la asistencia rapida que danen este foro nuevamente muchas gracias y aqui va el log que me salio ![]() Código: ========== FILES ========== C:\Documents and Settings\Jose\Application Data\TuneUp Software\TuneUp Utilities\StartUp Manager\Disabled objects\PowerReg Scheduler.exe moved successfully. C:\Documents and Settings\Jose\Desktop\animeops\All Trapcode Plugins.rar moved successfully. C:\Documents and Settings\Jose\Desktop\animeops\Profound.Effects.Nous.rar moved successfully. C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\setup.exe moved successfully. C:\Documents and Settings\Jose\Desktop\animeops\Topaz_Vivacity_v1.3.1_for_Photoshop_-_GRiFFiN_L0uG3r0n3\Topaz Vivacity v1.3.1 for Photoshop - GRiFFiN L0uG3r0n3\topazvivacity131.msi moved successfully. C:\Documents and Settings\Jose\My Documents\AE7TC-plugins_jdwashere\AE7TC-plugins\Trapcode.Multikeygen.v1.3.exe moved successfully. C:\Documents and Settings\Jose\My Documents\RENDERS\Flash_Favorite_1.8.1.rar moved successfully. C:\Documents and Settings\Jose\My Documents\swiftoptimizer.zip moved successfully. C:\Documents and Settings\Jose\My Documents\swiftoptimizer\setup.exe moved successfully. C:\Documents and Settings\Jose\My Documents\topazadjust_setup.zip moved successfully. C:\Documents and Settings\Jose\My Documents\topazadjust_setup\topazadjust24_setup\topazadjust_setup.msi moved successfully. C:\Program Files\Topaz Labs LLC\Topaz Vivacity\RegProduct.exe moved successfully. C:\WINDOWS\system32\1170690616.exe moved successfully. C:\WINDOWS\system32\mswinsck.oca moved successfully. C:\WINDOWS\system32\winstlr32.exe moved successfully. File/Folder C:\WINDOWS\system32\winstlr32.exe not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_bTAPoeDDdEEUHDsjQxVc scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_bTAPoeDDdEEUHDsjQxVc-journal scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_zqP64LNyhTr2b6f8fxf3 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jose\LOCALS~1\Temp\Perflib_Perfdata_1c8.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jose\LOCALS~1\Temp\Perflib_Perfdata_cdc.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\Jose\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_98.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05282009_203209 Files moved on Reboot... File C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_bTAPoeDDdEEUHDsjQxVc not found! File C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_bTAPoeDDdEEUHDsjQxVc-journal not found! File C:\DOCUME~1\Jose\LOCALS~1\Temp\etilqs_zqP64LNyhTr2b6f8fxf3 not found! File C:\DOCUME~1\Jose\LOCALS~1\Temp\Perflib_Perfdata_1c8.dat not found! File C:\DOCUME~1\Jose\LOCALS~1\Temp\Perflib_Perfdata_cdc.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_98.dat not found! C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Jose\Local Settings\Application Data\Mozilla\Firefox\Profiles\r2c1sytg.default\XUL.mfl moved successfully. |
![]() | ![]() |
| ||||
| Re: Problemas detectados por panda active scan, ayuda porfavor Ahora realiza esto para eliminar otmoveit y su cuarentena: Cita:
Siguiendo su manual para mejorar un poco el rendimiento ejecuta: Limpia el registro con:
Reinicias y Después me comentas si el problema por el cual abriste el tema desaparece. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| imposible eliminar Rogue.Residue (solucionado) | angara | Temas Solucionados | 5 | 28/05/09 18:12:58 |
| Ayuda, qué virus es? Cómo eliminarlo? (Solucionado) | Pabs | Temas Solucionados | 9 | 15/03/09 18:00:56 |
| Virus casi indetectables :( | peg666 | Foro de Virus y Spywares | 8 | 12/02/09 12:48:06 |
| fu.zip y AVGUPSW:EXE virus | huichmex | Foro de Virus y Spywares | 6 | 10/02/09 15:33:57 |
| Ayuda con virus (Solucionado) | ekal | Temas Solucionados | 17 | 16/10/08 17:06:09 |