![]() |
| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Tengo un Download.Trojan y no puedo eliminarlo aqui esta mi log Logfile of HijackThis v1.99.1 Scan saved at 11:29:53 AM, on 4/18/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: E:\WINNT\System32\smss.exe E:\WINNT\system32\winlogon.exe E:\WINNT\system32\services.exe E:\WINNT\system32\lsass.exe E:\WINNT\system32\svchost.exe E:\WINNT\System32\WBEM\WinMgmt.exe E:\WINNT\Explorer.EXE E:\Program Files\Spybot - Search & Destroy\SpybotSD.exe E:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe E:\Program Files\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R3 - Default URLSearchHook is missing F2 - REG:system.ini: Shell=Explorer.exe, E:\WINNT\system32\kyblk.exe F2 - REG:system.ini: UserInit=E:\WINNT\SYSTEM32\Userinit.exe,vuiouba.ex e O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-92EA-EC65A294AE31} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [DrvLsnr] E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [MMTray] "E:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [IgfxTray] E:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] E:\WINNT\system32\hkcmd.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [DKQXEKRXB] E:\WINNT\DKQXEKRXB.exe O4 - HKLM\..\Run: [qzopgtcf] E:\WINNT\qzopgtcf.exe O4 - HKLM\..\Run: [mbsjqlun] E:\WINNT\mbsjqlun.exe O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [qzovcr] E:\WINNT\qzovcr.exe O4 - HKCU\..\Run: [ehgdcz] E:\WINNT\ehgdcz.exe O4 - HKCU\..\Run: [sraj] E:\WINNT\sraj.exe O4 - HKCU\..\Run: [avsdef] E:\WINNT\avsdef.exe O4 - HKCU\..\Run: [MyTraveler] E:\Documents and Settings\JassoAn\Application Data\MyTraveler\MyTraveler.exe O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZHxdm005YYMX O8 - Extra context menu item: E&xportar a Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - E:\WINNT\system32\dmonwv.dll O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - E:\WINNT\system32\dmonwv.dll O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\nge-kazemule-uk\index.html (file missing) O15 - Trusted Zone: *.delcoremy.com O15 - Trusted Zone: *.helpme.local O15 - Trusted Zone: *.remyinc.com O15 - Trusted Zone: *.root.local O15 - Trusted Zone: *.wwauto.com O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.solidworks.com/plugins/edrawings/download.cfm?Release=REL&Type=WEB&Language=English O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/es/SysWebTelecomInt.cab O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O16 - DPF: {8E65B894-C2E9-11D5-BCD3-00E018987509} - http://09.sharedsource.org/cabs/todoesotericomx.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = am.root.local O20 - Winlogon Notify: igfxcui - E:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - E:\WINNT\system32\NavLogon.dll O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - E:\WINNT\svchost.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - E:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe O23 - Service: Active Directory Migration Agent (OnePointDomainAdminService) - Unknown owner - E:\Program Files\OnePointDomainAgent\DCTAgentService.exe (file missing) O23 - Service: SAVRoam (SavRoam) - symantec - E:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - E:\Program Files\Symantec AntiVirus\Rtvscan.exe espero me puedan ayudar ya arranque la maquina en modo seguro corri mi symantec antivirus, adware, spy bot y el hijackThis 1.99.1 y nada agradeceria enormemente su ayuda |
![]() | ![]() |
| ||||
| Re: Tengo un Download Trojan y no puedo eliminarlo Hola y bienvenido al foro, no te olvides de pasar por WindowsUpdate periódicamente para tener actualizado el sistema, luego sigue estos pasos: 1.- Descarga la herramienta TZ-Kill.zip y descomprímelo en el escritorio de Windows pero no la ejecutes aún. 2.- Activa la opción Ver Archivos Ocultos 3.- Reinicia en Modo a Prueba de Fallos 4.- Haz doble click sobre el archivo "TZ-Kill.bat" y presiona cualquier tecla para continuar (automáticamente eliminara las entradas de sitios de confianza "015 - Trusted Zone") 5.- Cierra todos los programas, ejecuta HijackThis y dale "Fix Cheked" a estas entradas: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R3 - Default URLSearchHook is missing F2 - REG:system.ini: Shell=Explorer.exe, E:\WINNT\system32\kyblk.exe F2 - REG:system.ini: UserInit=E:\WINNT\SYSTEM32\Userinit.exe,vuiouba.ex e O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-92EA-EC65A294AE31} - (no file) O4 - HKLM\..\Run: [DKQXEKRXB] E:\WINNT\DKQXEKRXB.exe O4 - HKLM\..\Run: [qzopgtcf] E:\WINNT\qzopgtcf.exe O4 - HKLM\..\Run: [mbsjqlun] E:\WINNT\mbsjqlun.exe O4 - HKCU\..\Run: [qzovcr] E:\WINNT\qzovcr.exe O4 - HKCU\..\Run: [ehgdcz] E:\WINNT\ehgdcz.exe O4 - HKCU\..\Run: [sraj] E:\WINNT\sraj.exe O4 - HKCU\..\Run: [avsdef] E:\WINNT\avsdef.exe O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZHxdm005YYMX O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - E:\WINNT\system32\dmonwv.dll O9 - Extra button: Downloads - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\nge-kazemule-uk\index.html (file missing) O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} - http://ip.sponsoradulto.com/cab/3/es/SysWebTelecomInt.cab O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab 6.- Sin reiniciar, busca y elimina estos archivos, si no se dejan eliminar descarga el programa "Killbox" y sigue las indicaciones del mensaje, copia y pega los archivos para que los elimine al reiniciar. blank.htm E:\WINNT\system32\kyblk.exe vuiouba.exe E:\WINNT\DKQXEKRXB.exe E:\WINNT\qzopgtcf.exe E:\WINNT\mbsjqlun.exe E:\WINNT\qzovcr.exe E:\WINNT\ehgdcz.exe E:\WINNT\sraj.exe E:\WINNT\avsdef.exe E:\WINNT\system32\dmonwv.dll 7.- Pasa el Disk Cleaner para limpiar cookies y temporales 8.- Pasa el Regseeker para Limpiar el Registro, pásalo hasta q no quede nada para eliminar. 9.- Pasa el Ad-Aware SE actualizado e instala SpywareBlaster 10.- Reinicia la maquina y realiza un escaneo con Ewido Online, luego pega otro log de Hijackthis y nos cuentas como te fue. De preferencia imprime las indicaciones para que se te haga mas facil seguirlas. Saludos ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Tengo un Download Trojan y no puedo eliminarlo Gracias GPastor aunque batalle un poquito ya que lo hice dos veces por que a la primera no pude quitarlo (tal vez hicealgo mal) pero a la segunda se quito, mil gracias envio el Log. Logfile of HijackThis v1.99.1 Scan saved at 11:43:51 AM, on 4/21/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: E:\WINNT\System32\smss.exe E:\WINNT\system32\winlogon.exe E:\WINNT\system32\services.exe E:\WINNT\system32\lsass.exe E:\WINNT\system32\svchost.exe E:\WINNT\system32\spoolsv.exe E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe E:\Program Files\Symantec AntiVirus\DefWatch.exe E:\WINNT\System32\svchost.exe E:\Program Files\ewido anti-malware\ewidoctrl.exe E:\Program Files\ewido anti-malware\ewidoguard.exe E:\WINNT\system32\regsvc.exe E:\Program Files\Symantec AntiVirus\SavRoam.exe E:\WINNT\system32\MSTask.exe E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe E:\Program Files\Symantec AntiVirus\Rtvscan.exe E:\WINNT\System32\WBEM\WinMgmt.exe E:\WINNT\system32\svchost.exe E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe E:\WINNT\Explorer.EXE E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe E:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe E:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\WINNT\system32\igfxtray.exe E:\WINNT\system32\hkcmd.exe E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe E:\Program Files\Common Files\Symantec Shared\ccApp.exe E:\PROGRA~1\SYMANT~2\VPTray.exe E:\Program Files\Winamp\winampa.exe E:\Program Files\QuickTime\qttask.exe E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe E:\Program Files\MSN Messenger\msnmsgr.exe E:\Documents and Settings\JassoAn\Application Data\MyTraveler\MyTraveler.exe E:\Program Files\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [DrvLsnr] E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [MMTray] "E:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [IgfxTray] E:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] E:\WINNT\system32\hkcmd.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MyTraveler] E:\Documents and Settings\JassoAn\Application Data\MyTraveler\MyTraveler.exe O4 - HKCU\..\Run: [peual] E:\WINNT\system32\tpkhkv.exe reg_run O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.solidworks.com/plugins/edrawings/download.cfm?Release=REL&Type=WEB&Language=English O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145569527801 O16 - DPF: {8E65B894-C2E9-11D5-BCD3-00E018987509} - http://09.sharedsource.org/cabs/todoesotericomx.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = am.root.local O20 - Winlogon Notify: igfxcui - E:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - E:\WINNT\system32\NavLogon.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - E:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - E:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: SAVRoam (SavRoam) - symantec - E:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - E:\Program Files\Symantec AntiVirus\Rtvscan.exe gracias ![]() |
![]() | ![]() |
| ||||
| Re: Tengo un Download Trojan y no puedo eliminarlo Aún hay una entrada por reparar, sigue estos pasos: 1.- Activa la opción Ver Archivos Ocultos 2.- Reinicia en Modo a Prueba de Fallos 3.- Cierra todos los programas, ejecuta HijackThis y dale "Fix Cheked" a esta entrada: O4 - HKCU\..\Run: [peual] E:\WINNT\system32\tpkhkv.exe reg_run 4.- Sin reiniciar, busca y elimina este archivo, si no se deja eliminar descarga el programa "Killbox" y sigue las indicaciones del mensaje, copia y pega el archivo para que lo elimine al reiniciar. E:\WINNT\system32\tpkhkv.exe 5.- Pasa el Disk Cleaner para limpiar cookies y temporales 6.- Pasa el Regseeker para Limpiar el Registro, pásalo hasta q no quede nada para eliminar. 7.- Pasa el Ad-Aware SE actualizado. 8.- Reinicia la maquina y pega otro log de Hijackthis aqui mismo, luego nos cuentas como te fue. De preferencia imprime las indicaciones para que se te haga mas facil seguirlas. Saludos ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Tengo un Download Trojan y no puedo eliminarlo Excelente Se borro envio el Log y de nueva cuenta mil gracias Logfile of HijackThis v1.99.1 Scan saved at 4:55:37 PM, on 4/24/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: E:\WINNT\System32\smss.exe E:\WINNT\system32\winlogon.exe E:\WINNT\system32\services.exe E:\WINNT\system32\lsass.exe E:\WINNT\system32\svchost.exe E:\WINNT\system32\spoolsv.exe E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe E:\Program Files\Symantec AntiVirus\DefWatch.exe E:\WINNT\System32\svchost.exe E:\Program Files\ewido anti-malware\ewidoctrl.exe E:\Program Files\ewido anti-malware\ewidoguard.exe E:\WINNT\system32\regsvc.exe E:\Program Files\Symantec AntiVirus\SavRoam.exe E:\WINNT\system32\MSTask.exe E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe E:\Program Files\Symantec AntiVirus\Rtvscan.exe E:\WINNT\System32\WBEM\WinMgmt.exe E:\WINNT\system32\svchost.exe E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe E:\WINNT\Explorer.EXE E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe E:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe E:\Program Files\Common Files\Real\Update_OB\realsched.exe E:\WINNT\system32\igfxtray.exe E:\WINNT\system32\hkcmd.exe E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe E:\Program Files\Common Files\Symantec Shared\ccApp.exe E:\PROGRA~1\SYMANT~2\VPTray.exe E:\Program Files\Winamp\winampa.exe E:\Program Files\QuickTime\qttask.exe E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe E:\Program Files\MSN Messenger\msnmsgr.exe E:\Documents and Settings\JassoAn\Application Data\MyTraveler\MyTraveler.exe E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe E:\Program Files\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.paguito.com/portal/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINNT\System32\msdxm.ocx O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.d ll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [DrvLsnr] E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [MMTray] "E:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [IgfxTray] E:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] E:\WINNT\system32\hkcmd.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~2\VPTray.exe O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MyTraveler] E:\Documents and Settings\JassoAn\Application Data\MyTraveler\MyTraveler.exe O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) - http://www.solidworks.com/plugins/edrawings/download.cfm?Release=REL&Type=WEB&Language=English O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145569527801 O16 - DPF: {8E65B894-C2E9-11D5-BCD3-00E018987509} - http://09.sharedsource.org/cabs/todoesotericomx.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = am.root.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = am.root.local O20 - Winlogon Notify: igfxcui - E:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - E:\WINNT\system32\NavLogon.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - E:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - E:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - E:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: SAVRoam (SavRoam) - symantec - E:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - E:\Program Files\Symantec AntiVirus\Rtvscan.exe saludos ![]() |
![]() | ![]() |
| ||||
| Re: Tengo un Download Trojan y no puedo eliminarlo Muy bien, el log está limpio así que damos el tema por solucionado ![]() Saludos ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Tengo el Spyware Adwarepunisher y no lo puedo quitar (Solucionado) | mari83 | Temas Solucionados | 18 | 04/02/06 04:22:35 |
| tengo un virus llamado trojan horse startpage 19.j (solucionado) | Jeuda | Temas Solucionados | 11 | 16/07/05 20:56:38 |
| no puedo eliminar el dichoso Trojan Horse - (solucionado) | cazaboom4 | Temas Solucionados | 4 | 30/06/05 20:01:39 |
| problema con un hotbar no puedo eliminarlo - (solucionado) | Nixon | Temas Solucionados | 2 | 21/06/05 23:03:01 |
| problema con foo.exe y otras cosas (solucionado) | Deimus | Temas Solucionados | 3 | 31/05/05 18:10:16 |