| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| |||
| Un saludo a todos. Desde la semana pasada el ordenador se me ha vuelto loco. Cada poco, el explorer salta y se mete en paginas de publicidad. Le he pasado el adaware y me saca un monton de cosas que borra, menos estos dos archivos que dice que no puede: -guard.tmp - (signo de libra)684l6l916Q.dll tambien se me a instalado un programa que no se como quitarlo. me parece que se llama Serv-U FTP-Server v2.5i el norton systemworks salta cada poco diciendo que a neutralizado algún dialer. la verdad es que me esta volviendo loca el dichoso ordenador, ya no se que hacer. si alguien sabe como ayudarme. un saludo y gracias. |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: Problemas con publicidad Buenasss Ejecuta esta herramienta: Look2me-Destroyer Realiza un escaneo con 2 o 3 antivirus online y dejanos los reportes de los que detecten infecciones ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Problemas con publicidad le he pasado el Look2Me-Destroyer V1.0.12 y esto es lo que me pone: Look2Me-Destroyer V1.0.12 Scanning for infected files..... Scan started at 23/07/2006 23:23:04 Infected! C:\WINDOWS\system32\en82l1lo1.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064338.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064348.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064387.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064391.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064399.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064536.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064544.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064548.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064556.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064562.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064565.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064571.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064578.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064586.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064587.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064590.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065590.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065597.dll Infected! C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065602.dll Infected! C:\WINDOWS\system32\en82l1lo1.dll Infected! C:\WINDOWS\system32\i8nmli5118.dll Infected! C:\WINDOWS\system32\m6ls0g37e6.dll Infected! C:\WINDOWS\system32\vksapi.dll Attempting to delete infected files... Attempting to delete: C:\WINDOWS\system32\en82l1lo1.dll C:\WINDOWS\system32\en82l1lo1.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064338.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064338.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064348.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP242\A0064348.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064387.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064387.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064391.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064391.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064399.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064399.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064536.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064536.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064544.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064544.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064548.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064548.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064556.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064556.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064562.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064562.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064565.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064565.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064571.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064571.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064578.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064578.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064586.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064586.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064587.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064587.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064590.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0064590.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065590.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065590.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065597.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065597.dll Deleted successfully! Attempting to delete: C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065602.dll C:\System Volume Information\_restore{08A7BD03-5B03-442B-BD04-F724E11C6C1C}\RP243\A0065602.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\en82l1lo1.dll C:\WINDOWS\system32\en82l1lo1.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\i8nmli5118.dll C:\WINDOWS\system32\i8nmli5118.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\m6ls0g37e6.dll C:\WINDOWS\system32\m6ls0g37e6.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\vksapi.dll C:\WINDOWS\system32\vksapi.dll Deleted successfully! Making registry repairs. Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{D195969D-C6B4-457F-8F9F-A488B24272FA}" HKCR\Clsid\{D195969D-C6B4-457F-8F9F-A488B24272FA} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{B0C69A02-7A02-4F64-A68A-8D256FDF4031}" HKCR\Clsid\{B0C69A02-7A02-4F64-A68A-8D256FDF4031} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{B183F512-44F7-4C2C-ADBC-494D8EC7B720}" HKCR\Clsid\{B183F512-44F7-4C2C-ADBC-494D8EC7B720} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{84EF4531-3C69-42F1-8038-5847E7FB4179}" HKCR\Clsid\{84EF4531-3C69-42F1-8038-5847E7FB4179} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{565D51BD-953B-4556-A0D9-342125F157C7}" HKCR\Clsid\{565D51BD-953B-4556-A0D9-342125F157C7} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{FC38C1A8-A50E-40E1-B43F-473291CA348E}" HKCR\Clsid\{FC38C1A8-A50E-40E1-B43F-473291CA348E} Restoring Windows certificates. Replaced hosts file with default windows hosts file Restoring SeDebugPrivilege for Administradores - Succeeded |
![]() | ![]() |
| |||
| Re: Problemas con publicidad Le he pasado el panda desde la pagina web y esto me ha salido: Incidencia Estado Elemento Herramienta potencialmente no deseada:Application/HideExec.A No desinfectado c:\windows\system32\drivers\etc\lsass.exe Dialer:Dialer.HIH No desinfectado C:\WINDOWS\TEMP\winD0.tmp.exe Herramienta potencialmente no deseada:Application/ServUBased.A No desinfectado C:\WINDOWS\SYSTEM32\DRIVERS\etc\system.exe Herramienta potencialmente no deseada:application/winfixer2005 No desinfectado c:\windows\downloaded program files\USDR6Y_0001_D13M1007NetInstaller.exe Adware:adware/dollarrevenue No desinfectado c:\windows\keyboard1.dat Adware:adware/commad No desinfectado c:\windows\uninstall_nmon.vbs Adware:adware/sqwire No desinfectado Registro de Windows Hacktool:HackTool/EvID No desinfectado C:\Archivos de programa\Archivos comunes\Synacast\SynaLive\EvID4226Patch.exe Adware:Adware/MediaTickets No desinfectado C:\Archivos de programa\Cowabanga\uninstaller.exe Adware:Adware/DollarRevenue No desinfectado C:\Documents and Settings\issac\Configuración local\Archivos temporales de Internet\Content.IE5\8DKSRGI4\loader[1].exe Dialer:Dialer.HIH No desinfectado C:\Documents and Settings\issac\Configuración local\Archivos temporales de Internet\Content.IE5\GDAB49IJ\srvkfw[1].exe Spyware:Cookie/888 No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@888[1].txt Spyware:Cookie/888 No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@888[2].txt Spyware:Cookie/YieldManager No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@ad.yieldmanager[1].txt Spyware:Cookie/Advertising No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@advertising[1].txt Spyware:Cookie/Cassava No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@cassava[1].txt Spyware:Cookie/Cgi-bin No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@cgi-bin[1].txt Spyware:Cookie/Clickbank No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@clickbank[1].txt Spyware:Cookie/ErrorSafe No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@errorsafe[2].txt Spyware:Cookie/Mediaplex No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@mediaplex[1].txt Spyware:Cookie/Statcounter No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@statcounter[1].txt Spyware:Cookie/Reliablestats No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@stats1.reliablestats[1].txt Spyware:Cookie/ErrorSafe No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@www.errorsafe[2].txt Spyware:Cookie/Xiti No desinfectado C:\Documents and Settings\issac\Configuración local\Temp\Cookies\issac@xiti[1].txt Spyware:Cookie/YieldManager No desinfectado C:\Documents and Settings\issac\Cookies\issac@ad.yieldmanager[2].txt Adware:Adware/PurityScan No desinfectado C:\RECYCLER\NPROTECT\00000141.EXE Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000202.DLL Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000222.DLL Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000223.DLL Herramienta potencialmente no deseada:Application/SystemDoctor2006 No desinfectado C:\RECYCLER\NPROTECT\00000246.dll Adware:Adware/SystemDoctor No desinfectado C:\RECYCLER\NPROTECT\00000250.exe Herramienta potencialmente no deseada:Application/SystemDoctor2006 No desinfectado C:\RECYCLER\NPROTECT\00000254.exe Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000288.DLL Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000289.DLL Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000290.DLL Adware:Adware/Look2Me No desinfectado C:\RECYCLER\NPROTECT\00000291.dll Herramienta potencialmente no deseada:Application/Iroffer.A No desinfectado C:\WINDOWS\system32\drivers\etc\service.exe Spyware:Cookie/YieldManager No desinfectado C:\WINDOWS\Temp\Cookies\issac@ad.yieldmanager[2].txt Spyware:Cookie/Hbmediapro No desinfectado C:\WINDOWS\Temp\Cookies\issac@adopt.hbmediapro[2].txt Spyware:Cookie/Mediaplex No desinfectado C:\WINDOWS\Temp\Cookies\issac@mediaplex[1].txt Spyware:Cookie/Reliablestats No desinfectado C:\WINDOWS\Temp\Cookies\issac@stats1.reliablestats[2].txt Dialer:Dialer.HIH No desinfectado C:\WINDOWS\Temp\win27C.tmp.exe Dialer:Dialer.HIH No desinfectado C:\WINDOWS\Temp\win47.tmp Dialer:Dialer.HIH No desinfectado C:\WINDOWS\Temp\win47.tmp.exe |
![]() | ![]() |
| |||
| Re: Problemas con publicidad Hola. Parece que ElRengo acerto con lo del Look2ME y y te lo ha limpiado. Pero parece que todavia te quedan algunos spywares y dialers. Para terminar de limpiar tu PC te recomiendo que sigas los siguientes 6 pasos: Sigue los siguientes 6 pasos: - Apaga Restaurar Sistema si tienes Windows ME o XP. - Entra en Modo Seguro (Modo a Prueba de Fallos). - Escanea con:
- No salgas del modo seguro. Has lo siguiente en cada cuenta de usuario:
- Inicia en modo normal y escanea con:Nos pegas el reporte de cada uno. - Reactiva Restaurar Sistema.salu2 |
![]() | ![]() |
| |||
| Re: Problemas con publicidad Despues de unas horas limpiando el ordenador, siguiendo paso a paso los seis puntos, estos son los resultados de los analisis finales con ewido y kaspersky on-lines: - Kaspersky: ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Wednesday, July 26, 2006 1:04:52 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 26/07/2006 Kaspersky Anti-Virus database records: 197310 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - Critical Areas: C:\WINDOWS C:\DOCUME~1\issac\CONFIG~1\Temp\ Scan Statistics: Total number of scanned objects: 12837 Number of viruses found: 2 Number of infected objects: 4 / 0 Number of suspicious objects: 0 Duration of the scan process: 00:13:51 Infected Object Name / Virus Name / Last Action C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{8C4CB7 F9-F0ED-466D-9011-F24BD8CC8341}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\etc\service.exe Infected: Backdoor.Win32.Iroffer.b skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\winjjq32.dll Infected: Packed.Win32.Klone.g skipped C:\WINDOWS\Temp\win323.tmp.exe Infected: Packed.Win32.Klone.g skipped C:\WINDOWS\Temp\win6.tmp.exe Infected: Packed.Win32.Klone.g skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\DOCUME~1\issac\CONFIG~1\Temp\Perflib_Perfdata_b ac.dat Object is locked skipped C:\DOCUME~1\issac\CONFIG~1\Temp\~DF78CC.tmp Object is locked skipped Scan process completed. -Ewido: __________________________________________________ ewido anti-spyware online scanner http://www.ewido.net __________________________________________________ Name: Backdoor.Virkel.A Path: C:\Archivos de programa\Archivos comunes\Synacast\SynaLive\EvID4226Patch.exe Risk: High Name: Adware.PurityScan Path: C:\RECYCLER\NPROTECT\00000141.EXE Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000202.DLL Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000222.DLL Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000223.DLL Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000288.DLL Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000290.DLL Risk: Medium Name: Adware.Look2Me Path: C:\RECYCLER\NPROTECT\00000291.dll Risk: Medium Name: Not-A-Virus.Downloader.Win32.WinFixer.l Path: C:\WINDOWS\Downloaded Program Files\USDR6Y_0001_D13M1007NetInstaller.exe Risk: Low Name: Backdoor.Hupigon.hk Path: C:\WINDOWS\system32\drivers\etc\LSASS.exe Risk: High Name: Backdoor.Iroffer.b Path: C:\WINDOWS\system32\drivers\etc\service.exe Risk: High Un saludo y gracias por ayudarme. |
![]() | ![]() |
| |||
| Re: Problemas con publicidad Primero baja los siguientes programas:
Luego sigue los siguientes pasos: - Apaga Restaurar Sistema si tienes Windows ME o XP. - Entra en Modo Seguro (Modo a Prueba de Fallos). - Borra los siguientes archivos (si es necesario usa el KillBox):C:\WINDOWS\system32\drivers\etc\service.exe C:\WINDOWS\system32\winjjq32.dll C:\WINDOWS\Temp\win323.tmp.exe C:\WINDOWS\Temp\win6.tmp.exe - Escanea con:
- No salgas del modo seguro. Has lo siguiente en cada cuenta de usuario:
- Inicia en modo normal y escanea con:Nos pegas el reporte de cada uno. - Reactiva Restaurar Sistema.De preferencia imprime los pasos para que te sea mas facil. Suerte salu2 ![]() Última edición por Hardrive fecha: 25/07/06 a las 21:15:38. |
![]() | ![]() |
| |||
| Re: Problemas con publicidad He vuelto a hacer los pasos y esto es lo que me indica en los reportes del ewido y del kaspersky: KASPERSKY ONLINE SCANNER REPORT Thursday, July 27, 2006 11:36:31 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 27/07/2006 Kaspersky Anti-Virus database records: 197855 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics Total number of scanned objects 31934 Number of viruses found 16 Number of infected objects 51 / 0 Number of suspicious objects 0 Duration of the scan process 00:33:06 Infected Object Name Virus Name Last Action C:\!KillBox\jjj.jfd Infected: Packed.Win32.Klone.g skipped C:\!KillBox\winjjq32.dll Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDALRT.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDCON.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDDBG.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDFW.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDIDS.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSYS.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SPPolicy.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SPStart.log Object is locked skipped C:\Archivos de programa\Archivos comunes\Symantec Shared\SPStop.log Object is locked skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\02F2669D.exe Infected: Trojan-Downloader.Win32.Adload.db skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\0DE27E3B.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\155737E3.exe Infected: Trojan-Downloader.Win32.Adload.db skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\16443BCB.exe Infected: Trojan-Downloader.Win32.Adload.db skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\1EB97BB4.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\206F5AC8.exe Infected: Trojan-Downloader.Win32.Adload.de skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\29F97665.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\37A25FB5.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\3FD46E21.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\447A0792.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\452F72F9.exe Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\453841E4.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE/WISE0009.BIN Infected: Trojan-Downloader.Win32.TSUpdate.n skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE WiseSFX: infected - 4 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4727673C.EXE CryptFF: infected - 4 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\472B1138.EXE Infected: Trojan-Downloader.Win32.Adload.de skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\47316531.exe Infected: Trojan-Clicker.Win32.VB.nh skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4738392A.exe Infected: Trojan-Downloader.Win32.Small.buy skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\473B6326.exe Infected: Trojan-Downloader.Win32.Small.buy skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\473E0D23.exe Infected: Trojan-Downloader.Win32.VB.ada skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\473E0D23.tmp Infected: Trojan-Downloader.Win32.IstBar.gen skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4742371F.exe Infected: Trojan-Downloader.Win32.TSUpdate.o skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe/WISE0009.BIN Infected: Trojan-Downloader.Win32.TSUpdate.n skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe WiseSFX: infected - 4 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4745611B.exe CryptFF: infected - 4 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\474B3514.exe Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\49716470.exe Infected: Backdoor.Win32.SubSeven.22 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4DA01F81.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\4F363933.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\524615D4.000 Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\52493FD1.exe Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\524D69CD.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\525013CA.000 Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\525013CA.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\52533DC6.exe Infected: Trojan-Downloader.Win32.PurityScan.bv skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\5D0F1285.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\68B56008.exe Infected: Backdoor.Win32.SubSeven.22 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\6AA54DE6.exe Infected: Backdoor.Win32.SubSeven.22 skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\6BAF49DE.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\756A0293.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\7CFB2ED5.exe Infected: Packed.Win32.Klone.g skipped C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\Quarantine\7F6614FA.exe Infected: Trojan-Downloader.Win32.PurityScan.cl skipped C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Datos de programa\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\issac\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Historial\History.IE5\MSHist0120060727200607 28\index.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Temp\Perflib_Perfdata_608.dat Object is locked skipped C:\Documents and Settings\issac\Configuración local\Temp\~DF92A8.tmp Object is locked skipped C:\Documents and Settings\issac\Cookies\index.dat Object is locked skipped C:\Documents and Settings\issac\NTUSER.DAT Object is locked skipped C:\Documents and Settings\issac\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\issac\UserData\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\RECYCLER\NPROTECT\00000703.exe Infected: Backdoor.Win32.Iroffer.b skipped C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Tasks\SCHEDLGU.TXT Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\Programas\Alcohol 120\Alcohol 120\StarWind\logs\starwind.2006-07-27.22-09-52.log Object is locked skipped D:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed. __________________________________________________ ewido anti-spyware online scanner http://www.ewido.net __________________________________________________ Name: Backdoor.Virkel.A Path: C:\RECYCLER\NPROTECT\00000700.EXE Risk: High Name: Not-A-Virus.Downloader.Win32.WinFixer.l Path: C:\RECYCLER\NPROTECT\00000701.EXE Risk: Low Name: Backdoor.Hupigon.hk Path: C:\RECYCLER\NPROTECT\00000702.exe Risk: High Name: Backdoor.Iroffer.b Path: C:\RECYCLER\NPROTECT\00000703.exe Risk: High |
![]() | ![]() |
| ||||
| Re: Problemas con publicidad hola ILF 1)Ve a Inicio-->Ejecuta-->escribes-->!killbox-->Borra jjj.jfd skippedwinjjq32.dll y todo lo que se encuentre en esa carpeta 2)vacia la cuarentena de Norton AntiVirus 3)Limpia el registro con RegSeeker+Manual 4)Elimina cookies y temporales con Ccleaner+Manual 5)vacia la Papelera de Reciclaje Cita:
nos cuentas como esta tu computadora<¡D3ViL!> Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: Problemas con publicidad Buenas tardes. Despues de seguir todos vuestros pasos, ya porfin me han dejado de salir paginas no deseadas y mensajes raros. Me parece que se me ha quedado el ordenador más limpio que una patena y todo gracias a vuestra ayuda. De nuevo, gracias por vuestra ayuda y por alumbrarnos en este complicado mundo de la informática. |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| tenco un problema con la bara de tarea (solucionado) | mohadip | Temas Solucionados | 9 | 04/12/05 21:02:32 |
| Ayuda con el log de hijackthis (solucionado) | LaNegru87 | Temas Solucionados | 3 | 23/11/05 01:39:17 |
| ya tengo mi "log" please ayudenme | jdr | Foro Oficial de HijackThis en español | 10 | 21/11/05 14:34:29 |
| varios problemas con mensages de publicidad no deseada (solucionado) | marars | Temas Solucionados | 2 | 10/11/05 17:05:49 |
| Hola les agradecere me brinden su ayuda | valfrev | Foro Oficial de HijackThis en español | 20 | 17/08/05 14:14:06 |