• Registrarse
  • Iniciar sesión


  • Resultados 1 al 3 de 3

    Malware Qvo 6

    Hola, este mensaje me arroja AT-Destroyer: ######################## AT-Destroyer [2.1] By Infospyware. Hora/Día/Mes/Año: 23:01:45 \\\ 01/04/2013 AT-Destroyer 2.1 By Infospyware ---> InfoSpyware Última actualización: 30/11/2012 Opción escogida: 2 :Buscar y Destruir Versión Internet Explorer:9.0.8112.16421 Privilegios: Ecomotors&Segurigas ...

    1. #1
      Usuario Avatar de segurigas
      Registrado
      abr 2013
      Ubicación
      Ecuador
      Mensajes
      3

      Malware Qvo 6

      Hola, este mensaje me arroja AT-Destroyer:
      ######################## AT-Destroyer [2.1] By Infospyware.
      Hora/Día/Mes/Año: 23:01:45 \\\ 01/04/2013
      AT-Destroyer 2.1 By Infospyware ---> InfoSpyware
      Última actualización: 30/11/2012
      Opción escogida: 2 :Buscar y Destruir
      Versión Internet Explorer:9.0.8112.16421
      Privilegios: Ecomotors&Segurigas - Administrador
      Modo Actual: Modo Normal.
      Nombre del pc: ECOMOTORS
      Información del sistema operativo:X64-WIN_7-Service Pack 1
      nombre del usuario:Ecomotors&Segurigas
      Lenguaje del sistema: Español



      >>>>>>> Servicios <<<<<<<



      >>>>>> Carpetas <<<<<<

      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\1B6A409F6D73420E8391D1B474785A29 (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\1B6A409F6D73420E8391D1B474785A29\smileyswelove_v5p2.exe (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\847C6BCD60A24AA7A1FFBB2B5DA7ECE7 (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\847C6BCD60A24AA7A1FFBB2B5DA7ECE7\LatestDLMgr.exe (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\847C6BCD60A24AA7A1FFBB2B5DA7ECE7\RegistryReviverSetup_AFF.exe (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy\847C6BCD60A24AA7A1FFBB2B5DA7ECE7\RegistryReviverSetup_AFF_p3v1.exe (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\OpenCandy (W32/Adware.OpenCandy)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\Babylon\log_file.txt (W32/PND.Babylon Toolbar)
      C:\Users\Ecomotors&Segurigas\AppData\Roaming\Babylon (W32/PND.Babylon Toolbar)
      C:\ProgramData\Babylon (W32/PND.Babylon Toolbar)


      >>>>>> Archivos <<<<<<



      >>>>>> Registro <<<<<<

      HKEY_CURRENT_USER\Software\DataMngr
      HKEY_LOCAL_MACHINE\SOFTWARE\DataMngr
      HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}


      >>>>>> Heurística <<<<<<



      >>>>>> Internet Explorer <<<<<<

      Start Page==www.google.com
      Local Page==C:\Windows\SysWOW64\blank.htm
      Search Page==http://go.microsoft.com/fwlink/?LinkId=54896
      Default_search_url==http://go.microsoft.com/fwlink/?LinkId=54896
      Default_Page_URL==http://www.qvo6.com/?utm_source=b&utm_medium=mlv&from=mlv&uid=TOSHIBAXMK6476GSX_5253S7TXSXX5253S7TXS&ts=1364848571


      ''HKCU\Software\Microsoft\Internet Explorer\Main''
      Start Page==www.google.com
      Local Page==C:\Windows\system32\blank.htm
      Search Page==http://go.microsoft.com/fwlink/?LinkId=54896
      Default_search_url==
      Default_Page_URL==http://g.msn.com/CQALL/30


      HKEY_USERS\S-1-5-21-804172496-2425045684-604147769-1000\Software\Microsoft\Internet Explorer\Main''
      Start Page==www.google.com
      Local Page==C:\Windows\system32\blank.htm
      Search Page==http://go.microsoft.com/fwlink/?LinkId=54896
      Default_search_url==
      Default_Page_URL==http://g.msn.com/CQALL/30


      >>>>>> Extensiones Firefox <<<<<<



      >>>>>> Plugins Firefox <<<<<<

      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0
      HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader


      >>>>>> Extensiones Google Chrome <<<<<<


      ======== Listado ===========

      [ 05/03/2013 8:20] [ 05/03/2013 7:41] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Autodesk
      [27/03/2013 22:02] [27/03/2013 22:02] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
      [01/04/2013 21:00] [01/04/2013 15:36] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Desk 365
      [01/04/2013 15:35] [01/04/2013 15:35] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\eIntaller
      [16/01/2013 11:28] [15/01/2013 14:22] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Hewlett-Packard
      [14/02/2013 17:47] [15/01/2013 14:18] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\hpqlog
      [15/01/2013 14:22] [15/01/2013 14:22] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Identities
      [15/01/2013 14:23] [15/01/2013 14:23] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Intel Corporation
      [16/01/2013 11:16] [16/01/2013 11:16] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Macromedia
      [01/04/2013 10:41] [15/01/2013 14:16] [SDI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Microsoft
      [27/03/2013 22:22] [27/03/2013 22:22] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\PDF Architect
      [27/03/2013 22:19] [27/03/2013 22:19] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\pdfforge
      [27/03/2013 22:22] [27/03/2013 22:21] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\SmileysWeLove
      [27/03/2013 22:25] [16/01/2013 11:20] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\SoftGrid Client
      [15/01/2013 14:23] [15/01/2013 14:23] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Synaptics
      [01/04/2013 21:34] [01/04/2013 13:05] [D] C:\Users\Ecomotors&Segurigas\AppData\Roaming\Systweak
      [16/01/2013 11:20] [16/01/2013 11:19] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\TP
      [17/01/2013 20:58] [16/01/2013 11:36] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\WildTangent
      [ 05/03/2013 7:33] [ 05/03/2013 7:24] [DI] C:\Users\Ecomotors&Segurigas\AppData\Roaming\WinRAR
      [05/03/2013 7:52] [05/03/2013 7:52] [D] C:\Program Files (x86)\Autodesk
      [28/03/2013 17:32] [13/07/2009 22:20] [D] C:\Program Files (x86)\Common Files
      [14/08/2012 15:09] [14/08/2012 15:06] [D] C:\Program Files (x86)\CyberLink
      [01/04/2013 21:32] [01/04/2013 15:36] [D] C:\Program Files (x86)\Desk 365
      C:\Program Files (x86)\desktop.ini [HSA] 174 bytes( 0)
      [28/03/2013 17:02] [27/03/2013 11:36] [D] C:\Program Files (x86)\DsNET Corp
      [21/04/2012 3:16] [21/04/2012 3:16] [D] C:\Program Files (x86)\Evernote
      [28/03/2013 17:20] [20/03/2013 9:03] [D] C:\Program Files (x86)\Google
      [14/02/2013 17:47] [21/04/2012 3:12] [D] C:\Program Files (x86)\Hewlett-Packard
      [21/04/2012 3:25] [21/04/2012 3:20] [D] C:\Program Files (x86)\HP Games
      [14/08/2012 15:08] [14/08/2012 15:08] [D] C:\Program Files (x86)\HP SimplePass
      [28/03/2013 17:40] [27/03/2013 22:21] [D] C:\Program Files (x86)\Iminent
      [14/02/2013 17:49] [21/04/2012 3:33] [HD] C:\Program Files (x86)\InstallShield Installation Information
      [14/08/2012 15:00] [14/08/2012 14:56] [D] C:\Program Files (x86)\Intel
      [13/03/2013 9:13] [13/07/2009 22:20] [D] C:\Program Files (x86)\Internet Explorer
      [28/03/2013 17:11] [14/08/2012 15:11] [D] C:\Program Files (x86)\Microsoft
      [22/03/2013 9:33] [22/03/2013 9:33] [D] C:\Program Files (x86)\Microsoft Analysis Services
      [27/01/2013 21:28] [16/01/2013 11:19] [D] C:\Program Files (x86)\Microsoft Application Virtualization Client
      [22/03/2013 9:35] [21/04/2012 3:27] [D] C:\Program Files (x86)\Microsoft Office
      [12/03/2013 21:17] [12/03/2013 21:17] [D] C:\Program Files (x86)\Microsoft Silverlight
      [22/03/2013 9:35] [21/04/2012 3:29] [D] C:\Program Files (x86)\Microsoft SQL Server Compact Edition
      [22/03/2013 9:35] [22/03/2013 9:35] [D] C:\Program Files (x86)\Microsoft Sync Framework
      [22/03/2013 9:35] [22/03/2013 9:35] [D] C:\Program Files (x86)\Microsoft Synchronization Services
      [22/03/2013 9:34] [22/03/2013 9:34] [D] C:\Program Files (x86)\Microsoft Visual Studio 8
      [22/03/2013 9:35] [27/01/2013 20:36] [D] C:\Program Files (x86)\Microsoft.NET
      [01/04/2013 13:05] [01/04/2013 13:05] [D] C:\Program Files (x86)\Mozilla Firefox
      [22/03/2013 9:36] [14/07/2009 0:32] [D] C:\Program Files (x86)\MSBuild
      [01/04/2013 13:04] [01/04/2013 13:04] [D] C:\Program Files (x86)\MSECache
      [14/08/2012 15:08] [14/08/2012 15:08] [D] C:\Program Files (x86)\Norton Internet Security
      [14/08/2012 15:08] [14/08/2012 15:08] [D] C:\Program Files (x86)\NortonInstaller
      [15/01/2013 14:17] [21/04/2012 3:16] [RD] C:\Program Files (x86)\Online Services
      [27/03/2013 22:19] [27/03/2013 22:19] [D] C:\Program Files (x86)\PDFCreator
      [14/08/2012 15:00] [14/08/2012 14:58] [D] C:\Program Files (x86)\Realtek
      [14/07/2009 0:32] [14/07/2009 0:32] [D] C:\Program Files (x86)\Reference Assemblies
      [27/01/2013 21:23] [27/01/2013 21:23] [RD] C:\Program Files (x86)\Skype
      [14/08/2012 15:11] [14/08/2012 15:11] [D] C:\Program Files (x86)\SymSilent
      [14/08/2012 14:58] [14/08/2012 14:58] [HD] C:\Program Files (x86)\Temp
      [13/07/2009 23:57] [13/07/2009 23:57] [HD] C:\Program Files (x86)\Uninstall Information
      [16/01/2013 11:36] [21/04/2012 3:20] [D] C:\Program Files (x86)\WildTangent Games
      [21/04/2012 12:35] [14/07/2009 0:32] [D] C:\Program Files (x86)\Windows Defender
      [21/04/2012 3:29] [21/04/2012 3:28] [D] C:\Program Files (x86)\Windows Live
      [21/04/2012 12:35] [13/07/2009 22:20] [D] C:\Program Files (x86)\Windows Mail
      [21/04/2012 12:35] [14/07/2009 0:32] [D] C:\Program Files (x86)\Windows Media Player
      [14/07/2009 0:32] [13/07/2009 22:20] [D] C:\Program Files (x86)\Windows NT
      [21/04/2012 12:35] [14/07/2009 0:32] [D] C:\Program Files (x86)\Windows Photo Viewer
      [20/11/2010 22:31] [14/07/2009 0:32] [D] C:\Program Files (x86)\Windows Portable Devices
      [15/01/2013 14:17] [14/07/2009 0:32] [D] C:\Program Files (x86)\Windows Sidebar
      [05/03/2013 7:24] [05/03/2013 7:24] [D] C:\Program Files (x86)\WinRAR
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Application Data
      [05/03/2013 8:20] [05/03/2013 7:41] [DI] C:\ProgramData\Autodesk
      [14/08/2012 15:10] [14/08/2012 15:10] [DI] C:\ProgramData\CyberLink
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Datos de programa
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Desktop
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Documentos
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Documents
      [14/08/2012 15:08] [14/08/2012 15:08] [DI] C:\ProgramData\Downloaded Installations
      [01/04/2013 21:32] [01/04/2013 15:36] [DI] C:\ProgramData\eSafe
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Escritorio
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Favorites
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Favoritos
      [05/03/2013 8:10] [05/03/2013 8:07] [DI] C:\ProgramData\FLEXnet
      [14/08/2012 15:19] [21/04/2012 3:28] [DI] C:\ProgramData\Hewlett-Packard
      [14/08/2012 15:17] [14/08/2012 15:00] [DI] C:\ProgramData\Intel
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Menú Inicio
      [28/03/2013 17:11] [13/07/2009 22:20] [SDI] C:\ProgramData\Microsoft
      [01/04/2013 21:54] [11/02/2013 13:35] [DI] C:\ProgramData\Microsoft Help
      C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc [AI] 153 bytes 0
      [15/01/2013 14:22] [14/08/2012 15:08] [DI] C:\ProgramData\Norton
      [14/08/2012 15:08] [14/08/2012 15:08] [DI] C:\ProgramData\NortonInstaller
      [28/03/2013 17:04] [28/03/2013 17:04] [DI] C:\ProgramData\PDF Architect
      [15/01/2013 14:16] [15/01/2013 14:16] [HSDLI] C:\ProgramData\Plantillas
      [14/08/2012 14:58] [14/08/2012 14:58] [DI] C:\ProgramData\Ralink Driver
      [27/01/2013 21:23] [21/04/2012 3:28] [DI] C:\ProgramData\Skype
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Start Menu
      [14/08/2012 15:17] [14/08/2012 15:17] [DI] C:\ProgramData\Synaptics
      [05/03/2013 8:20] [14/08/2012 15:05] [DAI] C:\ProgramData\Temp
      [14/07/2009 0:08] [14/07/2009 0:08] [HSDLI] C:\ProgramData\Templates
      [09/02/2013 14:54] [16/01/2013 11:22] [DI] C:\ProgramData\TrueSuite
      [12/02/2013 8:42] [17/01/2013 11:16] [DI] C:\ProgramData\VirtualizedApplications
      [17/01/2013 21:03] [21/04/2012 3:20] [DI] C:\ProgramData\WildTangent
      [14/02/2013 17:46] [14/02/2013 17:46] [DI] C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}

      ==================== EOF ==================

    2. #2
      Usuario Avatar de segurigas
      Registrado
      abr 2013
      Ubicación
      Ecuador
      Mensajes
      3

      Re: Malware Qvo 6

      Hola he realizado todos los pasos y este mensaje me arroja AdwCleaner:
      # AdwCleaner v2.115 - Fichero creado el 01/04/2013 a 2308
      # Actualizado el 17/03/2013 por Xplode
      # Sistema operativo : Windows 7 Home Basic Service Pack 1 (64 bits)
      # Usuario : Ecomotors&Segurigas - ECOMOTORS
      # Modo de inicio : Normal
      # Ejecutado desde : C:\Users\Ecomotors&Segurigas\Desktop\adwcleaner.exe
      # Opción [Supresión]


      ***** [Servicios] *****


      ***** [Ficheros / Carpetas] *****

      Carpeta Suprimido : C:\Program Files (x86)\Desk 365
      Carpeta Suprimido : C:\Program Files (x86)\Iminent
      Carpeta Suprimido : C:\Users\Ecomotors&Segurigas\AppData\LocalLow\Toolbar4
      Carpeta Suprimido : C:\Users\Ecomotors&Segurigas\AppData\Roaming\Desk 365
      Carpeta Suprimido : C:\Users\Ecomotors&Segurigas\AppData\Roaming\pdfforge

      ***** [Registro] *****

      Clave Supprimida : HKCU\Software\APN PIP
      Clave Supprimida : HKCU\Software\BabylonToolbar
      Clave Supprimida : HKCU\Software\DataMngr_Toolbar
      Clave Supprimida : HKCU\Software\Iminent
      Clave Supprimida : HKCU\Software\Softonic
      Clave Supprimida : HKCU\Software\524db88b43eee42
      Clave Supprimida : HKLM\Software\Babylon
      Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Prod.cap
      Clave Supprimida : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
      Clave Supprimida : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
      Clave Supprimida : HKLM\Software\Iminent
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASAPI32
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASMANCS
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
      Clave Supprimida : HKLM\Software\PIP
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\524db88b43eee42
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
      Clave Supprimida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
      Valor Supprimida : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]

      ***** [Navegadores] *****

      -\\ Internet Explorer v9.0.8112.16470

      [OK] El registro no contiene ninguna entrada ilegítima.

      *************************

      AdwCleaner[S1].txt - [11900 octets] - [01/04/2013 2308]

      ########## EOF - C:\AdwCleaner[S1].txt - [11961 octets] ##########

    3. #3
      Usuario Avatar de segurigas
      Registrado
      abr 2013
      Ubicación
      Ecuador
      Mensajes
      3

      Re: Malware Qvo 6

      Hola, el sistema sigue trabajando igual al abrir el explorador vuelve y aparece Qvo 6