| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| |||
| no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola, he estado mirando aqui en el foro algunas soluciones a problemas que tengo y no soy capaz de solucionar nada. Os comento, ayer instale un .exe y me salieron unas letras chinas, desde entonces el antivirus se quedo inservible (AVG) me decia que no tenia ningun componente, entre para hacer los 11 pasos de eliminacion de malwares y no me deja hacer ninguno, cuando voy a ejecutar el ccleaner o el superantispyware me dice que no es una aplicacion win32 valida y no puedo pasar ninguno. Tampoco me deja arrancar en modo seguro, le doy a modo seguro y se vuelve a reiniciar y me hace un escaneo de c para volver a windows.He leido tambien un ejecutable que hay para que me deje entrar en modo seguro, pero tampoco em deja ejecutarlo (safemode). Ya no se que mas hacer, el caso es que estoy sin antivirus y he porbado ha hacer todo lo que recomendais y no me deja hacer nada, me tiene muy bloqueado, le he intentado pasar el drweb y en cuanto pincho en activar se reinicia el pc. El malwarebytes me ha encontrado 158 problemas, pero cuatro de ellos no puede quitarlos y me dice que tengo que reiniciar y al reiniciar el ordenador no apaga y tengo que apagarlo yo a la fuerza y no me borra esos cuatro. Espero haberme explicado bien, no soy un experto en la materia, espero vuestra ayuda. Un saludo. |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola, por favor sigue estos pasos que enumero. -Para tu comodidad te recomiendo imprimir los pasos.1º- Descarga / instala, estas herramientas.Pero no ejecutes a un: CCleaner y su manualNOTA: SI LAS HERRAMIENTAS NO PUDIERAS INSTALARLAS, LES CAMBIAS EL NOMBRE A LOS ARCHIVOS 2º- Apaga restaurar sistema Inicias tu pc en modo seguro---->si no puedes en modo seguro lo realizas en modo normal 3º- Ejecuta las herramientas de una en una y en este orden:
4º- Reinicias el pc a modo normal y activas restaurar sistema 5º- Realizas un scan con un antivirus online Pruebas con Panda ActiveScan 2.0 si es posible te suscribes a Panda ActiveScan 2.0 en su version gratuita En tu proximo mensaje, pones el reporte del antivirus online, FS-FixBagle y Malwarebytes' Anti-Malware saludos: Espero tu respuesta.Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola de nuevo, te envio los reportes del malwarebytes y del fixbagle, el del antvirus no puedo porque tarda muchisimo y se me corta, estoy intentando sacarlo. Espero que te puedan servir, te comento que aun me sale lo del el win 32 cuando intento ejecutar el superantispyware y el spybot, ademas cuando em pide reiniciar el sistema no apaga lo tengo que apagar yo, y cuando reinicia me sale una pantalla azul que me dice que no ha dejado iniciar por proteccion de windows y lo apago y lo enciando algunas veces y al final me deja entrar. Espero haberme explicado bien, un saludo. Malwarebytes' Anti-Malware 1.38 Versión de la Base de Datos: 2328 Windows 5.1.2600 Service Pack 3 2009-06-24 16:33:23 mbam-log-2009-06-24 (16-33-23).txt Tipo de examen : Examen Completo (C:\|) Objetos examinados: 140224 Tiempo transcurrido: 1 hour(s), 2 minute(s), 18 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 0 Claves del Registro Infectadas: 3 Valores del Registro Infectados: 3 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 2 Ficheros Infectados: 127 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\111111s1ro1s1a (Rootkit.Bagle) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\1 11111s1ro1s1a (Rootkit.Bagle) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\1 11111s1ro1s1a (Rootkit.Bagle) -> Quarantined and deleted successfully. Valores del Registro Infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\german.exe (Rootkit.Bagle) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\drvsyskit (Rootkit.Bagle) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\mule_st_key (Rootkit.Bagle) -> Delete on reboot. Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: c:\documents and settings\USUAR023\Datos de programa\m (Trojan.Agent) -> Delete on reboot. c:\documents and settings\USUAR023\Datos de programa\drivers\downld (Worm.Bagle) -> Quarantined and deleted successfully. Ficheros Infectados: c:\documents and settings\USUAR023\datos de programa\drivers\11s11ro1s1a2.sys (Rootkit.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\155765.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\171187.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\180062.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\186281.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\188703.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\191140.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\191781.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\201406.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\205109.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\209625.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\216093.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\217078.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\225390.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\227843.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\228812.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2470625.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2471046.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2471062.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\247937.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\252640.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\258687.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2589609.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2596921.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2601109.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2601218.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2606218.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2607531.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\2607562.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\262171.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\276718.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\279796.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\282187.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\283000.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\293062.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\296187.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\297312.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\297828.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\298875.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\301687.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\319843.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\343281.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\343546.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\354875.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\358046.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\358968.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\378453.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\388796.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\429359.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\504390.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\505234.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\505796.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\509703.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\510421.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\514078.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\514796.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\514812.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\524046.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\524093.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\524968.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\525546.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\525640.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\526140.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\527156.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\529546.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\530281.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\534203.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\534921.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\534937.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\545562.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\547609.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\548390.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\549609.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\549734.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\555265.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\556437.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\557156.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\560687.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\561421.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\564140.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\565828.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\565843.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\573421.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\574312.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\574906.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\576218.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\577890.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\578625.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\578640.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\581312.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\582000.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\582015.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\583359.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\585015.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\585609.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\587953.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\592937.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\594359.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\594953.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\599375.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\611843.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\628312.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\654796.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\655093.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\733765.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\734046.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\734062.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\768109.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\780406.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\783078.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\783187.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\784625.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\786843.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\836375.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\842343.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\846421.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\849031.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\849484.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\datos de programa\drivers\downld\850203.exe (Worm.Bagle) -> Quarantined and deleted successfully. c:\documents and settings\USUAR023\Datos de programa\drivers\winupgro.exe (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot. c:\documents and settings\USUAR023\Datos de programa\m\flec006.exe (Trojan.Agent) -> Delete on reboot. c:\documents and settings\USUAR023\Datos de programa\drivers\111wfs1intwq.sys (Rootkit.Bagle) -> Quarantined and deleted successfully. Este fue otro posterior que hice. Malwarebytes' Anti-Malware 1.38 Versión de la Base de Datos: 2328 Windows 5.1.2600 Service Pack 3 2009-06-24 18:42:35 mbam-log-2009-06-24 (18-42-35).txt Tipo de examen : Examen Completo (C:\|) Objetos examinados: 139898 Tiempo transcurrido: 56 minute(s), 49 second(s) Procesos en Memoria Infectados: 0 Módulos en Memoria Infectados: 0 Claves del Registro Infectadas: 0 Valores del Registro Infectados: 0 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 1 Ficheros Infectados: 0 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos en Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: (No se han detectado elementos maliciosos) Valores del Registro Infectados: (No se han detectado elementos maliciosos) Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: c:\documents and settings\USUAR023\Datos de programa\drivers\downld (Worm.Bagle) -> Quarantined and deleted successfully. Ficheros Infectados: (No se han detectado elementos maliciosos) fix-bagle. Microsoft Windows XP Professional (5.1.2600 32-bit) | Service Pack 3 Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz Internet Explorer 8.0.6001.18702 Usuario : USUAR023 | -> Firewall : Inactivo -> Antivirus : WebAdmin Client Antivirus 2008 [ Activo | Actualizar ] A:\ Unidad de disco de 3 1/2 pulgadas C:\ Disco fijo local 74.52 Go (63.83 Go free) NTFS D:\ Disco CD-ROM E:\ Disco CD-ROM Q:\ Conexión de red R:\ Conexión de red Inicio : 17:28:58 - DIA/MES/AÑO : 2009-06-24 -------------------|BAGLE PROCESOS -------------------|BAGLE ARCHIVOS C:\WINDOWS\system32\ban_list.txt - Eliminado -----> CARPETA PREFETCH 1313562.EXE-271881DA.pf - Eliminado 151484.EXE-028B2E51.pf - Eliminado 157187.EXE-150C94D0.pf - Eliminado 205562.EXE-25C45EEE.pf - Eliminado 230343.EXE-07775B32.pf - Eliminado 239593.EXE-307AB097.pf - Eliminado 262593.EXE-1737A06D.pf - Eliminado 277390.EXE-11AEA1C7.pf - Eliminado 296062.EXE-09A33BBC.pf - Eliminado 317281.EXE-103749A8.pf - Eliminado 416921.EXE-3157F6CA.pf - Eliminado 467343.EXE-0F4EDBD3.pf - Eliminado 482234.EXE-10185E52.pf - Eliminado 512734.EXE-0A174E28.pf - Eliminado 530656.EXE-1A99C636.pf - Eliminado 558062.EXE-3AF0DD6D.pf - Eliminado 581625.EXE-09E852AB.pf - Eliminado 584953.EXE-3998F4EC.pf - Eliminado 585578.EXE-09854AF2.pf - Eliminado 588359.EXE-02400171.pf - Eliminado 590437.EXE-098EEBDB.pf - Eliminado 617500.EXE-251C8F84.pf - Eliminado 632140.EXE-32C06902.pf - Eliminado 852359.EXE-16A78CB3.pf - Eliminado 856671.EXE-16F16A13.pf - Eliminado 877578.EXE-3744AA6C.pf - Eliminado FLEC006.EXE-1BD9EEB5.pf - Eliminado MDELK.EXE-1D176F91.pf - Eliminado WINTEMS.EXE-2A563F9B.pf - Eliminado WINUPGRO.EXE-034703C8.pf - Eliminado -------------------|BAGLE CARPETAS C:\DOCUME~1\USUAR023\DATOSD~1\drivers - Eliminada -------------------|BAGLE REGISTRO HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_SK9OU0S - Suprimido HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\ LEGACY_SK9OU0S - Suprimido HKEY_CURRENT_USER\Software\bisoft - Suprimido HKEY_CURRENT_USER\Software\DateTime4 - Suprimido HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro - Suprimido HKEY_USERS\S-1-5-21-38632685-600506973-1230779191-1045\Software\FFC - Suprimido HKEY_USERS\S-1-5-21-38632685-600506973-1230779191-1045\Software\MuleAppData - Suprimido Valor Run \\"drvsyskit" - Suprimido Valor Run \\"german.exe" - Suprimido Valor Run \\"mule_st_key" - Suprimido -------------------|ROGUE SOFTWARE -------------------|VERIFICAR [2009-06-01 18:51] - [23635392Bytes.] "C:\WINDOWS\system32\MRT.exe" -------------------|CLAVES RUN REGEDIT 4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "RTHDCPL"="RTHDCPL.EXE" "SkyTel"="SkyTel.EXE" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "Sr Agent"="\"C:\\Archivos de programa\\Sr\\SrLogon.exe\"" "OrderReminder"="C:\\Archivos de programa\\Hewlett-Packard\\OrderReminder\\OrderReminder.exe" "SunJavaUpdateSched"="\"C:\\Archivos de programa\\Java\\jre6\\bin\\jusched.exe\"" "QuickTime Task"="\"C:\\Archivos de programa\\QuickTime\\qttask.exe\" -atboottime" "NeroFilterCheck"="C:\\Archivos de programa\\Archivos comunes\\Ahead\\Lib\\NeroCheck.exe" "BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" "Adobe Reader Speed Launcher"="\"C:\\Archivos de programa\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" "Ad-Watch"="C:\\Archivos de programa\\Lavasoft\\Ad-Aware\\AAWTray.exe" "KernelFaultCheck"=hex(2):25,00,73,00,79,00,73,00, 74,00,65,00,6d,00,72,00,6f,\ 00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00 ,65,00,6d,00,33,00,32,00,\ 5c,00,64,00,75,00,6d,00,70,00,72,00,65,00,70,00,20 ,00,30,00,20,00,2d,00,6b,\ 00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents] @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\IMAIL] "Installed"="1" @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" @="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MSFS] "Installed"="1" @="" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.ex e" "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Archivos de programa\\Archivos comunes\\Ahead\\Lib\\NMBgMonitor.exe\"" "SpybotSD TeaTimer"="C:\\Archivos de programa\\Spybot - Search & Destroy\\TeaTimer.exe" -------------------|CATCHME REPORT catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-24 17:39:33 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 -------------------|FIN / EOF / END |
![]() | ![]() |
| ||||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Cita:
Cita:
Cita:
esto ya es mas extraño. Esperemos los resultados del antivirus online.Te paso otra herramienta para que la ejecutes antes del antivirus online, me traes el reporte que te de ![]() Descarga el ESET Smart Installer la ejecutas en modo normal
saludos Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Te paso el reporte del eset. ESETSmartInstaller@High as downloader log: all ok # version=6 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=81d30782f6669a4f940a026a7ee4e4c2 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-06-25 06:26:08 # local_time=2009-06-25 08:26:08 (+0100, Hora estándar romance) # country="Spain" # lang=3082 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=769 37 100 100 60434843750 # scanned=38501 # found=1 # cleaned=1 # scan_time=4655 C:\Downloads\DelPSGuard.zip probablemente una variante de Win32/Agent Troyano (eliminado - puesto en Cuarentena) 00000000000000000000000000000000 |
![]() | ![]() |
| ||||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola, el ESET solo encontro esto en tu pc DelPSGuard.zip nada importante. Parece ser que bagle ya no esta fue eliminado. Pero seria interesante ver el scan online y tu respuesta de como sigue todo ![]() saludos Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro te paso el infome del kaspersky. KASPERSKY ONLINE SCANNER INFORME viernes, 26 de junio de 2009 13:37:54 Sistema operativo: Microsoft Windows XP Professional, Service Pack 3 (Build 2600) Kaspersky Online Scanner versión: 5.0.84.2 Ultima actualización: 26/06/2009 Registros en la base antivirus: 2161768 Configuración del análisis Analizar usando las siguientes bases standard Analizar archivos verdadero Analizar bases de correo verdadero Objetivo a analizar Mi PC A:\ C:\ D:\ E:\ Q:\ R:\ Estadísticas Número de objeros analizados 39480 Virus encontrados 0 Objetos infectados 0 / 0 Objetos sospechosos 0 Duración del análisis 01:38:08 Bombre del objeto infectado Nombre del virus Última acción C:\Archivos de programa\Alwil Software\Avast4\DATA\aswResp.dat Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\Avast4.db Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\log\nshield.log Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\log\selfdef.log Object is locked saltado C:\Archivos de programa\Alwil Software\Avast4\DATA\report\Protección residente.txt Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked saltado C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\temp\Cookies\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\temp\History\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\Configuración local\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked saltado C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8091888C-6222-11DE-845F-00138FF5EEF7}.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Internet Explorer\Recovery\Active\{49687FFA-6223-11DE-845F-00138FF5EEF7}.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\Logs\Dfsr00005.log Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\pending.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\Working\database_FC14_F57E_14F5_3BE 8\dfsr.db Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\Working\database_FC14_F57E_14F5_3BE 8\fsr.log Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\Working\database_FC14_F57E_14F5_3BE 8\fsrtmp.log Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Messenger\tekym34@hotmail.com\S haringMetadata\Working\database_FC14_F57E_14F5_3BE 8\tmp.edb Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\tekym34@hotmail.com\real\members.stg Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\tekym34@hotmail.com\shadow\members.stg Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Historial\History.IE5\index.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Historial\History.IE5\MSHist0120090626200906 27\index.dat Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DF14D5.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DF4CF7.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DF4E26.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DF9E1B.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DF9E31.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Configuración local\Temp\~DFC62.tmp Object is locked saltado C:\Documents and Settings\USUAR023\Cookies\index.dat Object is locked saltado C:\Documents and Settings\USUAR023\IETldCache\index.dat Object is locked saltado C:\Documents and Settings\USUAR023\ntuser.dat Object is locked saltado C:\Documents and Settings\USUAR023\NtUser.dat.LOG Object is locked saltado C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked saltado C:\System Volume Information\_restore{5A4C250D-9677-4433-852F-C01DA39B91FF}\RP2\change.log Object is locked saltado C:\WINDOWS\bthservsdp.dat Object is locked saltado C:\WINDOWS\CSC\00000001 Object is locked saltado C:\WINDOWS\Debug\Netlogon.log Object is locked saltado C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado C:\WINDOWS\SchedLgU.Txt Object is locked saltado C:\WINDOWS\Sti_Trace.log Object is locked saltado C:\WINDOWS\system32\CatRoot2\edb.log Object is locked saltado C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked saltado C:\WINDOWS\system32\config\Antivirus.Evt Object is locked saltado C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\default Object is locked saltado C:\WINDOWS\system32\config\default.LOG Object is locked saltado C:\WINDOWS\system32\config\Internet.evt Object is locked saltado C:\WINDOWS\system32\config\SAM Object is locked saltado C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\SECURITY Object is locked saltado C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado C:\WINDOWS\system32\config\software Object is locked saltado C:\WINDOWS\system32\config\software.LOG Object is locked saltado C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado C:\WINDOWS\system32\config\system Object is locked saltado C:\WINDOWS\system32\config\system.LOG Object is locked saltado C:\WINDOWS\system32\h323log.txt Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado C:\WINDOWS\TEMP\Perflib_Perfdata_240.dat Object is locked saltado C:\WINDOWS\TEMP\Perflib_Perfdata_608.dat Object is locked saltado C:\WINDOWS\TEMP\_avast4_\Webshlock.txt Object is locked saltado C:\WINDOWS\wiadebug.log Object is locked saltado C:\WINDOWS\wiaservc.log Object is locked saltado Análisis completado. |
![]() | ![]() |
| ||||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola el reporte de kaspersky esta limpio de infecciones.Comentame como sigue el pc, y si todo estubiera bien para poder ir dando el tema como terminado ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Hola, te comento, aun no se apaga solo el pc, tengo que apagarlo yo, ya me deja pasarle el antispyware y el spy bot y no han encontrado nada. Aun tarda muchisimo en arrancar, no se si sera porque tengo que apagarlo a capon.Por lo demas creo que ya esta bien, al menos eso creo. No se si tengo que hacerle algo mas para solucionar lo de apagarse (no apaga ni reinicia solo). Un saludo y muchismas gracias por tu ayuda y atencion. |
![]() | ![]() |
| ||||
| Re: no me deja pasarle ningun antivirus ni arrancar en modo seguro Cita:
Sobre lo de apagarse eso si que es extraño haremos unos pasos para optimizar el pc haber si con eso conseguimos arreglar ese problema1º- Scandisk. 2º- Desfragmentador de disco 3º- actualiza Java 4º- Argente - Registry Cleaner y su manual 5º-Advanced SystemCare 3 y su manual saludos ya nos comentas Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Reporte de Kaspersky (solucionado) | alexis82 | Temas Solucionados | 5 | 27/08/08 00:15:29 |
| No se q pasa con mi PC | nicoduran | Ayuda General | 48 | 24/08/08 21:37:24 |
| Virus.VBS.Small.a no puedo eliminarlo | hergfmemez | Foro de Virus y Spywares | 2 | 21/07/08 18:57:32 |
| btask.dll | sahogu | Foro de Virus y Spywares | 20 | 23/05/08 09:26:29 |
| Eliminar virus de mi pc y.. (Solucionado) | kreisy | Temas Solucionados | 12 | 16/03/08 13:23:32 |