![]() |
| |||||||
![]() | Registrarse | Lista de usuarios | AntiSpywares | AntiVirus | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Necesito que revisen mi log de HijackThis para poder detectar la infeccion. Ya he corrido el DelPSGuard y el Elistara; en el primero no encontró nada y en el segundo sí. os envío también su log Gracias de antemano. Log HijackThis Logfile of HijackThis v1.99.1 Scan saved at 12:09:50 a.m., on 09/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\explorer.exe C:\WINDOWS\NOTEPAD.EXE C:\AntiSpys\HijackThis_1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com.mx R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe O4 - HKLM\..\Run: [beep copy type glue] C:\Documents and Settings\All Users\Application Data\Test once beep copy\wavethe.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [AttuneClientEngine] C:\PROGRA~1\Aveo\Attune\bin\attune_ce.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MeowCdrom] C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\link help grid.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Inicio rápido de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Abrir en nueva ficha de fondo - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/229?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: Abrir en nueva ficha en primer plano - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/230?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{F026FAC6-7DE4-4737-9412-363662EE4A5F}: NameServer = 207.248.224.71,207.248.224.72 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Servicio de registro de McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Log de Elistara Fri Feb 09 00:04:57 2007 EliStartPage v13.29 (c)2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\WT\WEBDRIVER.DLL --> Eliminado Linea Eliminada del HOSTS --> 127.0.0.1 bin.errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 de.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 de.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.systemdoctor.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.windrivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 dynamique.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 es.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 fr.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 fr.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 hk.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 jsp.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 kb.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 kb.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 nl.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 se.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispam.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispy.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 support.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 trial.updates.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 ulog.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winfixer2006.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.systemdoctor.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.utils.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.win-anti-virus-pro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.win-virus-pro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispam.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispy.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantiviruspro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivesafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer2006.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winsoftware.com ## added by CiD Eliminada Carpeta "%WinSys%\LogFiles" Restaurado fichero de Configuración del IE, (IERESET.INF) Eliminadas las Paginas de Inicio y de Busqueda del IE Eliminados Ficheros Temporales del IE Fri Feb 09 00:05:16 2007 EliStartPage v13.29 (c)2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Program Files\HP Games\FATE\HELP.EXE --> AutoExtraible C:\Program Files\HP Games\FATE\inst\INSTALLWIRE.EXE --> AutoExtraible C:\Program Files\Microsoft Works\WKDBOLE.DLL --> Eliminado, ZangoSA (BHO) C:\Program Files\Microsoft Works\WKSSOLE.DLL --> Eliminado, ZangoSA (BHO) C:\SWSetup\MSWorks\16\PFiles\MSWorks\WKDBOLE.DLL --> Eliminado, ZangoSA (BHO) C:\SWSetup\MSWorks\16\PFiles\MSWorks\WKSSOLE.DLL --> Eliminado, ZangoSA (BHO) C:\WINDOWS\SETDEBUG.EXE --> Eliminado, HackTool-SRunner Quedo en espera de su respuesta Salu2 |
![]() | ![]() |
| ||||
| Re: tengo el virus svchost.exe Hola, el svchost es una archivo válido del sistema siempre y cuando se encuentre dentro de la carpeta system32. Mas información El log presenta infecciones sigue estos pasos: 1.- Apaga el "Restaurar Sistema" 2.- Activa la opción Ver Archivos Ocultos 3.- Reinicia en Modo Seguro y desinstala todo lo relacionado a AttuneClientEngine 4.- Cierra todos los programas, ejecuta HijackThis y dale "Fix Cheked" a estas entradas: O4 - HKLM\..\Run: [beep copy type glue] C:\Documents and Settings\All Users\Application Data\Test once beep copy\wavethe.exe O4 - HKLM\..\Run: [AttuneClientEngine] C:\PROGRA~1\Aveo\Attune\bin\attune_ce.exe O4 - HKCU\..\Run: [MeowCdrom] C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\link help grid.exe 5.- Sin reiniciar, busca y elimina estas carpetas con todo su contenido: C:\Documents and Settings\All Users\Application Data\Test once beep copy\ C:\PROGRA~1\Aveo\ C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\ 6.- Pasa el Disk Cleaner para limpiar cookies y temporales 7.- Pasa el Regseeker para Limpiar el Registro, pásalo hasta que no quede nada para eliminar. 8.- Pasa el Ad-Aware SE actualizado e instala SpywareBlaster 9.- Reinicia la máquina y realiza un escaneo con Ewido Online, luego pega otro log de Hijackthis y nos cuentas como te fue. 10.- Deshaz los pasos 1 y 2. De preferencia imprime las indicaciones para que se te haga mas fácil seguirlas. Saludos ![]()
__________________ Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: tengo el virus svchost.exe Gracias por la ayuda que me estan brindando. Os informo que mi compu aun esta infectada con lo mismo, ya hice los pasos que con anterioridad me habeis dicho y aun no queda limpia, tampoco puedo borrar la carpeta de: C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\ Es mas, ni siquiera la puedo observar aunq haya puesto la opcion de mostrar archivos ocultos. Intenté eliminarla a traves de MS-DOS sin exito y tambien lo intenté a traves del KILLBOX y tampoco se pudo. Ademas de lo que me habeis dicho ejecuté tambien ELISTARA y me borró varias infecciones. EWIDO no detectó nada Os envio los logs de HijackThis, ELISTARA y Ad-Aware SE para que los analicen y se pueda diagnosticar una solución Log HijackThis Logfile of HijackThis v1.99.1 Scan saved at 10:49:27 p.m., on 11/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE G:\HijackThis_1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.forospyware.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe O4 - HKLM\..\Run: [beep copy type glue] C:\Documents and Settings\All Users\Application Data\Test once beep copy\wavethe.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [AttuneClientEngine] C:\PROGRA~1\Aveo\Attune\bin\attune_ce.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MeowCdrom] C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\link help grid.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Inicio rápido de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Abrir en nueva ficha de fondo - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/229?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: Abrir en nueva ficha en primer plano - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/230?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F026FAC6-7DE4-4737-9412-363662EE4A5F}: NameServer = 207.248.224.71,207.248.224.72 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Servicio de registro de McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Log ELISTARA Fri Feb 09 00:04:57 2007 EliStartPage v13.29 (c)2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Acción Directa): C:\WINDOWS\WT\WEBDRIVER.DLL --> Eliminado Linea Eliminada del HOSTS --> 127.0.0.1 bin.errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 br.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 cdn.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 de.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 de.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.cdn.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.systemdoctor.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.windrivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 download.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 dynamique.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 es.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 fr.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 fr.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 go.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 hk.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 instlog.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 jsp.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 kb.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 kb.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 nl.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 se.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispam.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantispy.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 secure.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 support.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 trial.updates.winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 ulog.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 utils.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winfixer2006.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 winsoftware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.drivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.errorprotector.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.errorsafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.systemdoctor.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.utils.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.win-anti-virus-pro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.win-virus-pro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispam.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispy.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantispyware.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantivirus.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winantiviruspro.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivecleaner.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.windrivesafe.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winfixer2006.com ## added by CiD Linea Eliminada del HOSTS --> 127.0.0.1 www.winsoftware.com ## added by CiD Eliminada Carpeta "%WinSys%\LogFiles" Restaurado fichero de Configuración del IE, (IERESET.INF) Eliminadas las Paginas de Inicio y de Busqueda del IE Eliminados Ficheros Temporales del IE Fri Feb 09 00:05:16 2007 EliStartPage v13.29 (c)2007 S.G.H. / Satinfo S.L. -------------------------------------------------- Lista de Acciones (por Exploración): Explorando Unidad C:\ C:\Program Files\HP Games\FATE\HELP.EXE --> AutoExtraible C:\Program Files\HP Games\FATE\inst\INSTALLWIRE.EXE --> AutoExtraible C:\Program Files\Microsoft Works\WKDBOLE.DLL --> Eliminado, ZangoSA (BHO) C:\Program Files\Microsoft Works\WKSSOLE.DLL --> Eliminado, ZangoSA (BHO) C:\SWSetup\MSWorks\16\PFiles\MSWorks\WKDBOLE.DLL --> Eliminado, ZangoSA (BHO) C:\SWSetup\MSWorks\16\PFiles\MSWorks\WKSSOLE.DLL --> Eliminado, ZangoSA (BHO) C:\WINDOWS\SETDEBUG.EXE --> Eliminado, HackTool-SRunner log de Ad-Aware SE Ad-Aware SE Build 1.06r1 Logfile Created on:Domingo, 11 de Febrero de 2007 09:41:48 p.m. Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R150 09.02.2007 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» » References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Other(TAC index:5):1 total references Tracking Cookie(TAC index:3):3 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 11-02-2007 09:41:48 p.m. - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 632 ThreadCreationTime : 12-02-2007 03:32:08 a.m. BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 688 ThreadCreationTime : 12-02-2007 03:32:12 a.m. BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 712 ThreadCreationTime : 12-02-2007 03:32:13 a.m. BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 756 ThreadCreationTime : 12-02-2007 03:32:16 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 768 ThreadCreationTime : 12-02-2007 03:32:16 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 920 ThreadCreationTime : 12-02-2007 03:32:18 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 988 ThreadCreationTime : 12-02-2007 03:32:19 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1100 ThreadCreationTime : 12-02-2007 03:32:20 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1116 ThreadCreationTime : 12-02-2007 03:32:20 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1176 ThreadCreationTime : 12-02-2007 03:32:20 a.m. BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1768 ThreadCreationTime : 12-02-2007 03:32:27 a.m. BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:12 [iexplore.exe] FilePath : C:\Program Files\Internet Explorer\ ProcessID : 1924 ThreadCreationTime : 12-02-2007 03:34:56 a.m. BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:13 [ad-aware.exe] FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\ ProcessID : 2016 ThreadCreationTime : 12-02-2007 03:41:20 a.m. BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Other Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\aveo Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 1 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : rafael@mediaplex[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:1 Value : Cookie:rafael@mediaplex.com/ Expires : 21-06-2009 06:00:00 p.m. LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : rafael@adtech[2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:2 Value : Cookie:rafael@adtech.de/ Expires : 08-02-2017 09:39:10 p.m. LastSync : Hits:2 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : rafael@doubleclick[1].txt TAC Rating : 3 Category : Data Miner Comment : Hits:3 Value : Cookie:rafael@doubleclick.net/ Expires : 10-02-2010 09:39:08 p.m. LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 3 Objects found so far: 4 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 Deep scanning and examining files (D:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for D:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 4 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 4 09:51:12 p.m. Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:09:24.0 Objects scanned:205524 Objects identified:4 Objects ignored:0 New critical objects:4 Quedo en espera de vuestra respuesta Saludos |
![]() | ![]() |
| ||||
| Re: tengo el virus svchost.exe El log está igual al anterior, debes repetir los pasos de mi anterior post al pie de la letra. Para poder eliminar la carpeta: C:\DOCUME~1\Rafael\APPLIC~1\INTRAV~1\ Dale doble clic al ícono MI Pc luego copia y pega esta ruta en la barra de direcciones: C:\DOCUME~1\Rafael\APPLIC~1\ Busca la carpeta en mención y la eliminas, recuerda que debes hacerlo en Modo Seguro. Saludos ![]()
__________________ Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: tengo el virus svchost.exe Ya hice los pasos que me habeis dicho; sin embargo no pude desintalar a través del panel de control todo lo relacionado con ATTUNE 2.3.2 así que lo busqué de manera manual y había una carpeta completa en el software de CorelDraw con esa información y la borré manualmente, a partir de ahí ya no manda el mensaje de error con el archivo svchost.exe En el panel de control (Agregar o quitar programas) aún aparece el programa de ATTUNE 2.3.2 como instalado pero no se puede desintalar ni en modo a prueba de fallos. Os envío el log de HijackThis para que lo verifiques y podamos sersiorarnos de que la computadora ya está libre de infecciones. Logfile of HijackThis v1.99.1 Scan saved at 02:13:29 p.m., on 13/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\AntiSpys\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.forospyware.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Inicio rápido de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Abrir en nueva ficha de fondo - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/229?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: Abrir en nueva ficha en primer plano - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/230?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/spanish/kavwebscan_unicode.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F026FAC6-7DE4-4737-9412-363662EE4A5F}: NameServer = 207.248.224.71,207.248.224.72 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Servicio de registro de McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Gracias y quedo en espera de vuestra respuesta Saludos |
![]() | ![]() |
| ||||
| Re: tengo el virus svchost.exe El log está limpio de infecciones ![]() Cita:
Saludos ![]()
__________________ Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| ||||
| Re: tengo el virus svchost.exe Bien, damos este tema por solucionado y movemos tu nuevo tema como nueva post ya que se trata de otro equipo. Saludos ![]()
__________________ Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: tengo el virus svchost.exe (Solucionado) Hola GPastor, gracias por la ayuda que me has dado. Quiero comentarte que la computadora sigue con el problema, parecía que ya se había solucionado pero tristemente sigue apareciendo el mensaje de error con el archivo SVCHOST.EXE Si aún podemos seguir tratando el tema os envío mi log para que lo verifiques y me des las indicaciones necesarias para corregir el error. Logfile of HijackThis v1.99.1 Scan saved at 07:06:11 p.m., on 15/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\mqsvc.exe C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\WINDOWS\system32\mqtgsvc.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\dwwin.exe C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\WINDOWS\explorer.exe C:\AntiSpys\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.forospyware.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Inicio rápido de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Abrir en nueva ficha de fondo - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/229?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: Abrir en nueva ficha en primer plano - res://C:\Program Files\Windows Live Toolbar\Components\es-mx\msntabres.dll.mui/230?341455ca275e49cd93ab6a3c9a2a523c O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/spanish...an_unicode.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F026FAC6-7DE4-4737-9412-363662EE4A5F}: NameServer = 207.248.224.71,207.248.224.72 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Servicio de registro de McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Gracias y quedo en espera de vuestra respuesta |
![]() | ![]() |
| ||||
| Re: tengo el virus svchost.exe (Solucionado) El log está limpio ¿cual es exactamente el mensaje de error? Saludos ![]()
__________________ Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
| | |||||
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| P2P-Worm.Win32.VB.dw | tav | Foro de Virus y Spywares | 5 | 20/01/07 13:01:29 |
| Tengo virus! va el reporte de Kaspersky! (Solucionado) | dieguillo | Temas Solucionados | 9 | 04/10/06 11:33:01 |
| Tengo un virus troyano y no se como eliminarlo (Solucionado) | flip_rowley_777 | Temas Solucionados | 2 | 13/07/06 18:41:44 |
| ¿que virus tengo? (Solucionado) | moteropa | Temas Solucionados | 13 | 18/03/06 11:37:56 |
| problema con el vroomsearch | dasanlos | Foro Oficial de HijackThis en español | 5 | 05/05/05 11:31:01 |