¿Cómo eliminar virus de un archivo .exe?
Resuelto
roni034
Mensajes publicados
138
Fecha de registro
Estado
Miembro
Última intervención
-
fix200 Mensajes publicados 3365 Estado Colaborador de seguridad -
fix200 Mensajes publicados 3365 Estado Colaborador de seguridad -
Hola,
He intentado instalar un programa de procesamiento de texto, naturalmente ejecuté el archivo setup.exe de este programa que me dieron; pero durante la ejecución mi antivirus detectó un virus llamado vitro que aparentemente está incrustado en el archivo setup.exe y no puedo eliminar el virus sin que el archivo se borre también (lo mismo para la cuarentena). ¿Hay alguna manera de aislar el virus para poder recuperar el archivo setup sano?
Gracias por tu ayuda
roni
He intentado instalar un programa de procesamiento de texto, naturalmente ejecuté el archivo setup.exe de este programa que me dieron; pero durante la ejecución mi antivirus detectó un virus llamado vitro que aparentemente está incrustado en el archivo setup.exe y no puedo eliminar el virus sin que el archivo se borre también (lo mismo para la cuarentena). ¿Hay alguna manera de aislar el virus para poder recuperar el archivo setup sano?
Gracias por tu ayuda
roni
Configuración: Windows Vista Internet Explorer 8.0
16 respuestas
-
Re,
Hola roni ;)
Eh... ¡no ha terminado! ^^
Hazme un RSIT de nuevo, por favor. -
Hola,
Espero que no hayas ejecutado el archivo. Si no, estarás infectado por el peor malware del mundo...!
Vamos a intentar ver:
Descarga Random's System Information Tool (RSIT) de random/random y guárdalo en tu Escritorio.
▶ Haz doble clic en RSIT.exe para iniciarlo.
▶ Haz clic en "Continuar" en la pantalla "Renuncia de garantía".
▶ Si la herramienta HijackThis (versión actualizada) no está presente o no es detectada en el ordenador, RSIT la descargará y tendrás que aceptar la licencia.
▶ Cuando el análisis haya terminado, se abrirán dos archivos de texto.
=> Publica el contenido de log.txt (que se mostrará) así como de info.txt (que estará minimizado en la Barra de Tareas).
Nota: Los dos informes también se guardan aquí: C:\rsit -
Gracias por tu atención, te envío esto en unos instantes, el archivo se encuentra en una memoria USB... pero imagino que pudo haber infectado el ordenador... hasta luego.
-
Voici el archivo de información:
info.txt registro del sistema de la herramienta de información de random 1.06 2009-09-06 11:47:57
======Lista de desinstalación======
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
-->MsiExec.exe /I{2EA870FA-585F-4187-903D-CB9FFD21E2E0}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31403E22-2FDB-452F-AE9E-20854633226D}\Setup.exe" -uninst
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B804C424-B66D-447A-84BD-C6B88C392C3A}\setup.exe" -uninstall
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\setup.exe" -uninstall
Instalador de componentes HP CIO de 32 bits-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Acer Arcade Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\setup.exe" -uninstall
Cámara web Acer Crystal Eye-->C:\Program Files\InstallShield Installation Information\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}\setup.exe -runfromtemp -l0x040c -removeonly -u
Cámara web Acer Crystal Eye-->C:\Program Files\InstallShield Installation Information\{AA047D7C-5E7C-4878-B75C-77589151B563}\setup.exe -runfromtemp -l0x0009 -removeonly
Acer GridVista-->C:\Windows\UnInst32.exe GridV.UNI
Plug-in de Acer Mobility Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11316260-6666-467B-AC34-183FCB5D4335}\setup.exe" -l0x40c -removeonly
Protector de pantalla Acer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
Tour de Acer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
Acoolsoft PPT2Video Converter 3.0.0.38-->"C:\Program Files\Acoolsoft\PPT2Video Converter\unins000.exe"
Asistente de activación para las suites de Microsoft Office 2007-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
Adobe Reader 8.1.4-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
Soporte de dispositivo móvil de Apple-->MsiExec.exe /I{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}
Actualización de software de Apple-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Descompresor WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Asistente de conexión de Windows Live ID-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Bricks of Egypt-->"C:\Program Files\Acer GameZone\Bricks of Egypt\Uninstall.exe" "C:\Program Files\Acer GameZone\Bricks of Egypt\install.log"
Controlador integrado de gigabit Broadcom-->MsiExec.exe /X{D3B3B9B2-FE73-44CB-8C0A-F737D92F991B}
CCleaner (solo eliminar)-->"C:\Program Files\CCleaner\uninst.exe"
CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Ciel Auto-entrepreneur Facile 1.40-->MsiExec.exe /I{AF86BA3B-B465-4E12-B771-E12208FDB89B}
DavkaWriter Platinum-->MsiExec.exe /I{7CCF4B02-5AAB-455C-904F-3347DBD542D9}
Cliente FileZilla 3.2.6.1-->C:\Program Files\FileZilla FTP Client\uninstall.exe
Galapago-->"C:\Program Files\Acer GameZone\Galapago\Uninstall.exe" "C:\Program Files\Acer GameZone\Galapago\install.log"
Garmin WebUpdater-->MsiExec.exe /X{366FFC89-C800-4366-B903-B9C4314109A5}
Gestor para dispositivos Windows Mobile-->MsiExec.exe /I{1F2A5DF9-40E1-4644-ADBD-D80F347BA6C8}
GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Toolbar para Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_9DE96A29E721D90A.exe" /uninstall
Google Toolbar para Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HDAUDIO Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118\UIU32m.exe -U -IAcrZUn32z.inf
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Actualización para Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Actualización para Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Programa de participación del cliente de HP 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
Funciones del dispositivo de imagen de HP 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
Software de OCR de HP 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
Software del controlador todo en uno de HP Photosmart 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
Asistente de productos de HP-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
Centro de soluciones de HP 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
Actualización de HP-->MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
Instalación de Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Instalación de Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
Intel PROSet Wireless-->Intel PROSet Wireless
iTunes-->MsiExec.exe /I{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}
IziSpot 4-->MsiExec.exe /X{117F577F-E35E-458A-87C5-FBF96879C5CE}
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jewel Quest Solitaire-->"C:\Program Files\Acer GameZone\Jewel Quest Solitaire\Uninstall.exe" "C:\Program Files\Acer GameZone\Jewel Quest Solitaire\install.log"
K-Lite Codec Pack 3.9.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Launch Manager-->C:\Windows\UnInst32.exe QtZgAcer.UNI
LMSOFT Web Creator Pro 5-->C:\Program Files\Mindscape\LMSOFT Web Creator Pro 5\Uninstall.exe
Luxor 2-->"C:\Program Files\Acer GameZone\Luxor 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Luxor 2\install.log"
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (Francés) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (Francés) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Francés) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
Microsoft Office Outlook MUI (Francés) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Francés) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Árabe) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Holandés) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (Inglés) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (Francés) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Alemán) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Español) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Francés) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Francés) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (Francés) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (Francés) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Actualización de Microsoft Visual C++ 2005 ATL kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Redistribuible de Microsoft Visual C++ 2005-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Actualización de Microsoft Visual C++ 2008 ATL kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Redistribuible de Microsoft Visual C++ 2008 - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
Actualización del controlador del Gestor para dispositivos Windows Mobile-->MsiExec.exe /X{CB8CA439-DA83-419C-A4CF-5A0A50025144}
Módulo de compatibilidad para Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Mozilla Firefox (2.0)-->C:\Program Files\Mozilla Firefox\uninstall\uninst.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Mystery Case Files - Prime Suspects-->"C:\Program Files\Acer GameZone\Mystery Case Files - Prime Suspects\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files - Prime Suspects\install.log"
Mystery Case Files Ravenhearst-->"C:\Program Files\Acer GameZone\Mystery Case Files Ravenhearst\Uninstall.exe" "C:\Program Files\Acer GameZone\Mystery Case Files Ravenhearst\install.log"
NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
Controladores de NVIDIA-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
Herramienta de actualización de Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Herramienta de descarga de Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
pdfforge Toolbar v1.0-->MsiExec.exe /X{B8B0FC8B-E69B-4215-AF1A-4BDFF20D794B}
PDF-XChange 3.0-->"C:\Program Files\PDF-XChange 3 Pro\unins000.exe"
PowerProducer 3.72-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Controlador de audio de alta definición Realtek-->RtlUpd.exe -r -m
Controlador de controlador de medios flash RICOH R5C83x/84x Ver.3.52.02-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\Setup.exe" -l0x40c anything
SIW versión 2008-07-15-->"C:\Program Files\SIW\unins000.exe"
Controlador del dispositivo apuntador Synaptics-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TeamViewer 4-->C:\Program Files\TeamViewer\Version4\uninstall.exe
Tesoros del Profundo-->"C:\Program Files\Acer GameZone\Treasures of the Deep\Uninstall.exe" "C:\Program Files\Acer GameZone\Treasures of the Deep\install.log"
Actualización para Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Controladores Winbond CIR-->MsiExec.exe /X{427967BF-09F8-46D5-9275-37001CCBBA5D}
Llamada de Windows Live-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Plataforma de Comunicaciones de Windows Live-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Complemento de Firefox para Windows Media Player-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
======Información del centro de seguridad======
AS: Windows Defender (deshabilitado) (obsoleto)
======Registro de eventos del sistema======
Nombre del equipo: AharonBloch
Código de evento: 4374
Mensaje: Windows Servicing ha determinado que este paquete KB958644 (Actualización de seguridad) no es aplicable a este sistema.
Número de registro: 69909
Nombre de origen: Microsoft-Windows-Servicing
Hora escrita: 20081023202213.000000-000
Tipo de evento: Advertencia
Usuario: AUTORIDAD NT\SISTEMA
Nombre del equipo: AharonBloch
Código de evento: 4374
Mensaje: Windows Servicing ha determinado que este paquete KB958644 (Actualización de seguridad) no es aplicable a este sistema.
Número de registro: 69910
Nombre de origen: Microsoft-Windows-Servicing
Hora escrita: 20081023202213.000000-000
Tipo de evento: Advertencia
Usuario: AUTORIDAD NT\SISTEMA
Nombre del equipo: AharonBloch
Código de evento: 4227
Mensaje: TCP/IP no pudo establecer una conexión saliente porque el punto final local seleccionado se ha utilizado recientemente para conectarse al mismo punto final remoto. Este error ocurre generalmente cuando las conexiones salientes se abren y cierran a un ritmo elevado, provocando el uso de todos los puertos locales disponibles y obligando a TCP/IP a reutilizar un puerto local para una conexión saliente. Para reducir el riesgo de alteración de datos, la norma TCP/IP exige que transcurra un tiempo mínimo entre conexiones sucesivas de un punto final local a un punto final remoto.
Número de registro: 69926
Nombre de origen: Tcpip
Hora escrita: 20081023202704.101807-000
Tipo de evento: Advertencia
Usuario:
Nombre del equipo: AharonBloch
Código de evento: 6008
Mensaje: La parada del sistema anterior a las 01:02:56 del 24/10/2008 no fue programada.
Número de registro: 69931
Nombre de origen: EventLog
Hora escrita: 20081024053949.000000-000
Tipo de evento: Error
Usuario:
Nombre del equipo: AharonBloch
Código de evento: 4
Mensaje: Broadcom NetLink (TM) Gigabit Ethernet: El enlace de red está caído. Asegúrese de que el cable de red esté correctamente conectado.
Número de registro: 69942
Nombre de origen: b57nd60x
Hora escrita: 20081024053908.031325-000
Tipo de evento: Advertencia
Usuario:
=====Registro de eventos de aplicación=====
Nombre del equipo: AharonBloch
Código de evento: 63
Mensaje: El proveedor OffPr
Aquí está el archivo de registro
Registro de la herramienta de información del sistema de random 1.06 (escrito por random/random)
Ejecutado por Aharon en 2009-09-06 11:58:03
Microsoft® Windows Vista™ Edición Familiar Premium Service Pack 1
El disco del sistema C: tiene 34 GB (30%) libres de 114 GB
Total de RAM: 3070 MB (39% libres)
Registro de Trend Micro HijackThis v2.0.2
Escaneo guardado en 11:58:08, el 06/09/2009
Plataforma: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Modo de arranque: Normal
Procesos en ejecución:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\pdfforge Toolbar\SearchSettings.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\WerCon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
C:\Program Files\Davka Corp\DavkaWriter\davwrite.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Aharon\Desktop\RSIT.exe
C:\Program Files\trend micro\Aharon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tropal.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (sin nombre) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (sin nombre) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (sin archivo)
O2 - BHO: Ayudante de enlace de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Plugin de descarga y grabación de RealPlayer para Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (sin nombre) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (sin archivo)
O2 - BHO: Programa de ayuda del Asistente de conexión de Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ayudante de Google Toolbar - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Ayudante de Google Toolbar Notifier - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: barra de herramientas pdfforge - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: Compresión de diccionario de Google sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Ayudante SSV de Java(tm) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 -
Re,
Tus llaves USB están infectadas, + una barra de herramientas infectada.
Empezamos ^^' :
▶ Bajo Vista :
Desactiva el UAC que puede molestar mucho el procedimiento de desinfección. :
▶ Menú Inicio > Panel de control.
▶ Haz clic en el icono " Cuentas de usuario " y luego en " Activar o desactivar el control de cuentas de usuario " .
▶ Desmarca la casilla: " Usar el control de cuentas de usuario para ayudar a proteger su computadora "
▶ Confirma con Aceptar, se te pedirá reiniciar el PC, ¡hazlo! .
▶ Para ayudarte: Tutorial 1 - Tutorial 2 - Tutorial 3
========================
▶ MUY IMPORTANTE:
* Durante todo el procedimiento de desinfección, verifica que el UAC esté bien desactivado.
* Siempre ejecuta los programas de desinfección como administrador (Clic derecho > "Ejecutar como administrador..." )
========================
Descarga ToolBar S&D ( de Eric_71/Team IDN )
▶ Inicia la instalación del programa ejecutando el archivo descargado y deja que te guíe durante la instalación ..
! Desconéctate y cierra todas tus aplicaciones en curso durante el tiempo de la manipe !
▶ Haz clic derecho sobre el acceso directo ToolbarS&D y selecciona "Ejecutar como administrador"
▶ Escribe 2 ( limpieza ) y presiona [Entrar].
▶ No toques nada durante el escaneo
▶ Se generará un informe al final del proceso: publica su contenido en tu próxima respuesta
NOTA:
El informe se guarda aquí -> C:\TB.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
**********************************************************
********************* Vista_Opción 1 (búsqueda) ****************
**********************************************************
Desactiva el UAC
Descarga UsbFix (de C_XX , Chiquitine29 , & Chimay8)
> O aquí: UsbFix
▶ Ejecuta el archivo descargado, no toques los parámetros de la instalación !.
▶ Conecta tus fuentes de datos externas a tu PC (memoria USB, disco duro externo, etc...) que puedan haber sido infectadas (!) sin abrirlas (!)
▶ Haz clic derecho sobre el acceso directo UsbFix presente en tu escritorio y selecciona "Ejecutar como administrador" .
▶ En el menú principal elige la opción " F " para francés y presiona [entrar] .
▶ En el segundo menú elige la opción 1 (búsqueda)
▶ Deja que la herramienta trabaje
▶ Luego publica el informe UsbFix.txt que aparecerá
Notas:
1- el informe UsbFix.txt se guarda en la raíz del disco
2- Si el escritorio no reaparece presiona Ctrl + Alt + Supr, pestaña "Archivo", "Nueva tarea", escribe explorer.exe y confirma
3- "Process.exe", un componente de la herramienta, es detectado por algunos antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) como un RiskTool.
No es un virus, sino una utilidad destinada a detener procesos.
Puesto en malas manos, esta utilidad podría detener software de seguridad (Antivirus, Firewall...) de ahí la alerta emitida por estos antivirus. -
RE
aquí está el informe TB :
-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft® Windows Vista™ Edición Familiar Premium ( v6.0.6001 ) Service Pack 1
PC basado en X86 ( Multiprocesador Libre : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : ZD1 v1.3809 3H09
USUARIO : Aharon ( No Administrador ! )
BOOT : Arranque normal
C:\ (Disco local) - NTFS - Total:111 Go (Libre:33 Go)
D:\ (Disco local) - NTFS - Total:108 Go (Libre:107 Go)
E:\ (Disco local) - FAT32 - Total:149 Go (Libre:131 Go)
F:\ (CD o DVD)
G:\ (USB) - FAT32 - Total:3816 Mo (Libre:2 Go)
"C:\ToolBar SD" ( ACT : 22-08-2009|18:42 )
Opción : [2] ( 06/09/2009|12:27 )
[ UAC => 0 ]
-----------\\ SUPRESIÓN
¡Elimina! - C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
-----------\\ Búsqueda de Archivos / Carpetas ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"SEARCH PAGE"="http://ww12.cherche.us"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"SearchMigratedDefaultURL"="http://ww12.cherche.us{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page_bak"="http://ww12.cherche.us"
"Search Bar"="http://ww12.cherche.us"
"Default_Search_URL"="http://www.cherche.us/keyword/%s"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://fr.yahoo.com/"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\Windows\\System32\\blank.htm"
--------------------\\ Búsqueda de otras infecciones
¡Ninguna otra infección encontrada!
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 06/09/2009|12:27 - Opción : [2]
-----------\\ Fin del informe a 12:27:49,63
Aquí está el informe USBfix
############################## | UsbFix V6.026 |
Usuario : Aharon (Administradores) # AHARONBLOCH
Actualización el 06/09/2009 por Chiquitine29, C_XX & Chimay8
Inicio a las: 12:29:27 | 06/09/2009
Sitio web : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
Microsoft® Windows Vista™ Edición Familiar Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 8.0.6001.18813
Estado del Firewall de Windows : Activado
C:\ -> Disco duro local # 111,69 Go (34,09 Go libres) [ACER] # NTFS
D:\ -> Disco duro local # 108,19 Go (107,83 Go libres) [DATA] # NTFS
E:\ -> Disco duro local # 149,01 Go (131,88 Go libres) [FREECOM HDD] # FAT32
F:\ -> Disco CD-ROM
G:\ -> Disco extraíble # 3,73 Go (2,92 Go libres) [AHARON] # FAT32
############################## | Procesos activos |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\pdfforge Toolbar\SearchSettings.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\WerCon.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
################## | Archivos # Carpetas infectados |
¡Presente! D:\install.exe
¡Presente! G:\MS32DLL.dll.vbs
¡Presente! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
¡Presente! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
################## | ¡Sospechoso ! ... | https://www.virustotal.com/gui/ |
################## | Registro # Claves Run infectadas |
################## | Registro # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}
shell\AutoRun\command =E:\EXPLORER.EXE
shell\explore\Command =E:\EXPLORER.EXE
shell\open\Command =E:\EXPLORER.EXE
HKCU\..\..\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}
shell\AutoRun\command =i.exe
shell\explore\Command =i.exe
shell\open\Command =i.exe
################## | ¡Fin del informe # UsbFix V6.026 ! |
¡MUCHAS GRACIAS! -
¡Además del conficker en tu memoria! ¡En fin, estás en problemas! :x
**********************************************************
********************* Vista_Opción 2 (Limpieza) ***************
**********************************************************
Siempre con el UAC desactivado:
▶ Conecta tus fuentes de datos externas a tu PC, (memoria USB, disco duro externo, etc...) que podrían haber sido infectados (!) sin abrirlos (!)
▶ Haz clic derecho en el acceso directo UsbFix que está en tu escritorio y elige "Ejecutar como administrador".
▶ En el menú principal, elige la opción "F" para francés y presiona [intro].
▶ En el segundo menú, elige la opción 2 (Eliminación)
▶ Tu escritorio desaparecerá y el PC se reiniciará.
▶ Al reiniciar, UsbFix escaneará tu PC, deja que la herramienta trabaje.
▶ Después publica el informe UsbFix.txt que aparecerá con el escritorio.
▶ Nota: El informe UsbFix.txt se guarda en la raíz del disco. (C:\UsbFix.txt)
Ayuda: Cómo utilizar UsbFix
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Desactiva el UAC
**********************************************************
********************* Opción S (Escaneo) *********************
**********************************************************
Descarga AD-Remover (de C_XX) en tu escritorio:
¡Desconéctate y cierra todas las aplicaciones en ejecución!
• Haz doble clic en "AD-R.exe" para iniciar la instalación y deja los parámetros de instalación predeterminados.
• Haz clic derecho en el acceso directo Ad-remover que está en tu escritorio y elige "Ejecutar como administrador".
• En el menú principal, elige la opción "S" y presiona [intro].
• Deja que la herramienta trabaje y no toques nada...
--> Publica el informe que aparezca al final, en el foro... <--
Notas:
1- El informe también se guarda en C:\Ad-report-scan.log
2- "Process.exe", un componente de la herramienta, es detectado por algunos antivirus:
(AntiVir, Dr.Web, Kaspersky Anti-Virus) como un RiskTool.
No se trata de un virus, sino de una utilidad destinada a finalizar procesos.
En malas manos, esta utilidad podría detener software de seguridad (Antivirus, Firewall...) de ahí la alerta emitida por esos antivirus.
-
aquí está el registro de usbfix
############################## | UsbFix V6.026 |
Usuario: Aharon (Administradores) # AHARONBLOCH
Actualización el 06/09/2009 por Chiquitine29, C_XX & Chimay8
Inicio a: 12:59:14 | 06/09/2009
Sitio web: http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
Microsoft® Windows Vista™ Edición Familiar Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 8.0.6001.18813
Estado del Firewall de Windows: Habilitado
C:\ -> Disco duro local # 111,69 Go (34,09 Go libre) [ACER] # NTFS
D:\ -> Disco duro local # 108,19 Go (107,83 Go libre) [DATA] # NTFS
E:\ -> Disco duro local # 149,01 Go (131,88 Go libre) [FREECOM HDD] # FAT32
F:\ -> Disco CD-ROM
G:\ -> Disco extraíble # 3,73 Go (2,92 Go libre) [AHARON] # FAT32
############################## | Procesos activos |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Aharon\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\ehome\ehRecvr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\conime.exe
################## | Archivos # Carpetas infecciosas |
¡Presente! D:\install.exe
¡Presente! G:\MS32DLL.dll.vbs
¡Presente! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
¡Presente! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
################## | ¡Sospechoso!... | https://www.virustotal.com/gui/ |
################## | Registro # Claves Run infecciosas |
################## | Registro # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}
shell\AutoRun\command =E:\EXPLORER.EXE
shell\explore\Command =E:\EXPLORER.EXE
shell\open\Command =E:\EXPLORER.EXE
HKCU\..\..\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}
shell\AutoRun\command =i.exe
shell\explore\Command =i.exe
shell\open\Command =i.exe
################## | ! Fin del informe # UsbFix V6.026 ! |
aquí está el registro de ad-report
.
======= INFORME DE AD-REMOVER 1.1.4.5_T | SOLAMENTE XP/VISTA/7 =======
.
Actualizado por C_XX el 05/09/2009 a las 12:20 PM
Contacto: AdRemover.contact@gmail.com
Sitio web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Ejecutado a: 13:02:17, 06/09/2009 | Modo Normal | Opción: ESCANEAR
Ejecutado desde: C:\Program Files\Ad-Remover\
Sistema operativo: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
Nombre del PC: AHARONBLOCH | Usuario actual: Aharon
.
============== ELEMENTO(S) ENCONTRADO(S) ==============
.
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
.
C:\Users\Aharon\AppData\LocalLow\Search Settings
C:\Windows\Installer\a9ccaa.msi
C:\Program Files\Windows Live\Messenger\Riched20.dll
.
============== Escaneo adicional ==============
.
.
* Mozilla FireFox Versión 2.0 *
.
Nombre del perfil: ahe19kzn.default (Aharon)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.cherche.us/");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
.
.
.
* Internet Explorer Versión 8.0.6001.18813 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Página de inicio: hxxp://www.google.fr/
PÁGINA DE BÚSQUEDA: hxxp://www.cherche.us
Página de inicio_bak: hxxp://www.cherche.us
Barra de búsqueda: hxxp://www.cherche.us
URL_Búsqueda_Predeterminada: hxxp://www.cherche.us/keyword/%s
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Página de inicio: hxxp://www.msn.com/
URL_Página_Predeterminada: hxxp://fr.fr.acer.yahoo.com
URL_Búsqueda_Predeterminada: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Página de búsqueda: hxxp://go.microsoft.com/fwlink/?LinkId=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Pestañas: res://ieframe.dll/tabswelcome.htm
.
===================================
.
2249 Octet(s) - C:\Ad-Report-SCAN.log
.
107 Archivo(s) - C:\Users\Aharon\AppData\Local\Temp
30 Archivo(s) - C:\Windows\Temp
.
1 Archivo(s) - C:\Program Files\Ad-Remover\BACKUP
0 Archivo(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin a: 13:32:25 | 06/09/2009
.
============== E.O.F ==============
muchas gracias -
Re,
Revisa las manipulaciones por favor; ¡UsbFix opción 2!
**********************************************************
********************* Opción L (limpieza) *********************
**********************************************************
¡Desconéctate y cierra todas las aplicaciones en curso!
• haz clic derecho en el acceso directo Ad-remover que está en tu escritorio y elige "ejecutar como administrador".
• En el menú principal elige la opción "L" y presiona [entrada].
• Deja trabajar la herramienta y no toques nada...
--> Publica el informe que aparece al final, en el foro... <--
Notas:
1- El informe también se guarda en C:\Ad-report-clean.log
2- "Process.exe", un componente de la herramienta, es detectado por algunos antivirus:
(AntiVir, Dr.Web, Kaspersky Anti-Virus) como un RiskTool.
No es un virus, sino una utilidad destinada a terminar procesos.
En manos equivocadas, esta utilidad podría detener programas de seguridad (Antivirus, Firewall...) por lo que estos antivirus emiten una alerta.
Ayuda en imágenes (Limpieza)
**********************************************************
********************* Vista_Opción 2 (Limpieza) ***************
**********************************************************
Siempre con el UAC desactivado:
▶ Conecta tus fuentes de datos externas a tu PC, (unidad USB, disco duro externo, etc...) que puedan haber sido infectadas (!) sin abrirlas (!)
▶ Haz clic derecho en el acceso directo UsbFix presente en tu escritorio y elige "Ejecutar como administrador".
▶ En el menú principal elige la opción "F" para francés y presiona [entrada].
▶ En el segundo menú elige la opción 2 (Eliminación)
▶ Tu escritorio desaparecerá y el PC se reiniciará.
▶ Al reiniciar, UsbFix escaneará tu PC, deja trabajar la herramienta.
▶ Luego publica el informe UsbFix.txt que aparecerá con el escritorio.
▶ Nota: El informe UsbFix.txt se guarda en la raíz del disco.(C:\UsbFix.txt)
Ayuda: Cómo Utilizar UsbFix -
rapport usbfix
############################## | UsbFix V6.026 |
Utilisateur : Aharon (Administrateurs) # AHARONBLOCH
Mis à jour le 06/09/2009 par Chiquitine29, C_XX & Chimay8
Démarrez à : 17:57:14 | 06/09/2009
Site web : http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32 bits) # Service Pack 1
Internet Explorer 8.0.6001.18813
Statut du Pare-feu Windows : Activé
C:\ -> Disque fixe local # 111,69 Go (33,67 Go libres) [ACER] # NTFS
D:\ -> Disque fixe local # 108,19 Go (107,83 Go libres) [DATA] # NTFS
F:\ -> Disque CD-ROM
G:\ -> Disque amovible # 3,73 Go (2,92 Go libres) [AHARON] # FAT32
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Calendar\WinCal.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! D:\install.exe
Supprimé ! G:\MS32DLL.dll.vbs
Supprimé ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Supprimé ! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
################## | Autres |
################## | Suspect ! ... | https://www.virustotal.com/gui/ |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{2648f02c-93e9-11dd-b1fa-001e6817d35b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{76845ae3-e2da-11dd-9a35-001e6817d35b}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[21/12/2007 07:23|--a------|3377] C:\-20071221.log
[21/05/2008 20:56|--a------|3913] C:\-20080521.log
[06/09/2009 13:32|--a------|2565] C:\Ad-Report-SCAN.log
[18/09/2006 23:43|--a------|24] C:\autoexec.bat
[19/01/2008 09:45|-rahs----|333203] C:\bootmgr
[21/12/2007 13:31|-ra-s----|8192] C:\BOOTSECT.BAK
[18/09/2006 23:43|--a------|10] C:\config.sys
[11/08/2008 12:47|--a------|117] C:\finfos.txt
[?|?|?] C:\hiberfil.sys
[06/09/2009 11:35|--a------|1029] C:\InstallHelper.log
[11/08/2008 12:50|-rahs----|0] C:\IO.SYS
[11/11/2008 01:09|--a------|7] C:\ISACER.id
[16/08/2005 09:49|---------|40960] C:\junction.exe
[28/06/2007 10:44|--a------|512] C:\MDR.iss
[22/02/2008 18:11|--a------|20] C:\Medion.ini
[11/08/2008 12:46|--a------|438] C:\mpeg.txt
[11/08/2008 12:50|-rahs----|0] C:\MSDOS.SYS
[29/02/2004 17:44|--a------|52576] C:\orange.bmp
[?|?|?] C:\pagefile.sys
[22/02/2008 18:08|--a------|60] C:\Partition.txt
[22/02/2008 18:01|--a------|426] C:\RHDSetup.log
[21/12/2007 07:09|--a------|178] C:\setup.log
[25/03/2009 00:58|--ah-----|268] C:\sqmdata00.sqm
[30/04/2009 20:58|--ah-----|232] C:\sqmdata01.sqm
[01/05/2009 10:41|--ah-----|232] C:\sqmdata02.sqm
[02/05/2009 22:28|--ah-----|232] C:\sqmdata03.sqm
[03/05/2009 02:32|--ah-----|232] C:\sqmdata04.sqm
[21/06/2009 01:23|--ah-----|232] C:\sqmdata05.sqm
[07/07/2009 15:49|--ah-----|232] C:\sqmdata06.sqm
[01/02/2009 19:04|--ah-----|232] C:\sqmdata07.sqm
[01/02/2009 19:10|--ah-----|232] C:\sqmdata08.sqm
[01/02/2009 19:18|--ah-----|232] C:\sqmdata09.sqm
[17/02/2009 15:44|--ah-----|232] C:\sqmdata10.sqm
[17/02/2009 18:36|--ah-----|232] C:\sqmdata11.sqm
[04/03/2009 16:43|--ah-----|232] C:\sqmdata12.sqm
[04/03/2009 16:45|--ah-----|232] C:\sqmdata13.sqm
[04/03/2009 17:27|--ah-----|232] C:\sqmdata14.sqm
[06/03/2009 15:04|--ah-----|232] C:\sqmdata15.sqm
[08/03/2009 09:53|--ah-----|232] C:\sqmdata16.sqm
[08/03/2009 12:51|--ah-----|232] C:\sqmdata17.sqm
[08/03/2009 12:51|--ah-----|232] C:\sqmdata18.sqm
[08/03/2009 13:35|--ah-----|232] C:\sqmdata19.sqm
[25/03/2009 00:58|--ah-----|244] C:\sqmnoopt00.sqm
[30/04/2009 20:58|--ah-----|244] C:\sqmnoopt01.sqm
[01/05/2009 10:41|--ah-----|244] C:\sqmnoopt02.sqm
[02/05/2009 22:28|--ah-----|244] C:\sqmnoopt03.sqm
[03/05/2009 02:32|--ah-----|244] C:\sqmnoopt04.sqm
[21/06/2009 01:23|--ah-----|244] C:\sqmnoopt05.sqm
[07/07/2009 15:49|--ah-----|244] C:\sqmnoopt06.sqm
[01/02/2009 19:04|--ah-----|244] C:\sqmnoopt07.sqm
[01/02/2009 19:10|--ah-----|244] C:\sqmnoopt08.sqm
[01/02/2009 19:18|--ah-----|244] C:\sqmnoopt09.sqm
[17/02/2009 15:44|--ah-----|244] C:\sqmnoopt10.sqm
[17/02/2009 18:36|--ah-----|244] C:\sqmnoopt11.sqm
[04/03/2009 16:43|--ah-----|244] C:\sqmnoopt12.sqm
[04/03/2009 16:45|--ah-----|244] C:\sqmnoopt13.sqm
[04/03/2009 17:27|--ah-----|244] C:\sqmnoopt14.sqm
[06/03/2009 15:04|--ah-----|244] C:\sqmnoopt15.sqm
[08/03/2009 09:53|--ah-----|244] C:\sqmnoopt16.sqm
[08/03/2009 12:51|--ah-----|244] C:\sqmnoopt17.sqm
[08/03/2009 12:51|--ah-----|244] C:\sqmnoopt18.sqm
[08/03/2009 13:35|--ah-----|244] C:\sqmnoopt19.sqm
[06/09/2009 12:27|--a------|2236] C:\TB.txt
[06/09/2009 18:01|--a------|6895] C:\UsbFix.txt
[07/11/2007 08:00|--a------|17734] D:\eula.1028.txt
[07/11/2007 08:00|--a------|17734] D:\eula.1031.txt
[07/11/2007 08:00|--a------|10134] D:\eula.1033.txt
[07/11/2007 08:00|--a------|17734] D:\eula.1036.txt
[07/11/2007 08:00|--a------|17734] D:\eula.1040.txt
[07/11/2007 08:00|--a------|118] D:\eula.1041.txt
[07/11/2007 08:00|--a------|17734] D:\eula.1042.txt
[07/11/2007 08:00|--a------|17734] D:\eula.2052.txt
[07/11/2007 08:00|--a------|17734] D:\eula.3082.txt
[07/11/2007 08:00|--a------|1110] D:\globdata.ini
[07/11/2007 08:00|--a------|843] D:\install.ini
[07/11/2007 08:03|--a------|76304] D:\install.res.1028.dll
[07/11/2007 08:03|--a------|96272] D:\install.res.1031.dll
[07/11/2007 08:03|--a------|91152] D:\install.res.1033.dll
[07/11/2007 08:03|--a------|97296] D:\install.res.1036.dll
[07/11/2007 08:03|--a------|95248] D:\install.res.1040.dll
[07/11/2007 08:03|--a------|81424] D:\install.res.1041.dll
[07/11/2007 08:03|--a------|79888] D:\install.res.1042.dll
[07/11/2007 08:03|--a------|75792] D:\install.res.2052.dll
[07/11/2007 08:03|--a------|96272] D:\install.res.3082.dll
[05/01/2002 11:48|--a------|974848] D:\mfc70.dll
[05/01/2002 11:36|--a------|964608] D:\mfc70u.dll
[05/01/2002 10:37|--a------|344064] D:\msvcr70.dll
[07/11/2007 08:00|--a------|5686] D:\vcredist.bmp
[07/11/2007 08:09|--a------|1442522] D:\VC_RED.cab
[07/11/2007 08:12|--a------|232960] D:\VC_RED.MSI
[18/06/2009 00:44|---h-----|1150464] G:\~WRL0004.tmp
[05/09/2009 23:44|--a------|1622] G:\BOOTEX.LOG
################## | Upload |
Veuillez envoyer le fichier : C:\Users\Aharon\Desktop\UsbFix_Upload_Me_AharonBloch.zip : https://www.androidworld.fr/
Merci pour votre contribution .
rapport ad-report
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_T | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 05/09/2009 à 12:20 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 18:05:13, 06/09/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1 v6.0.6001
Nom du PC: AHARONBLOCH | Utilisateur actuel: Aharon
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
.
C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128
C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp
C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp\ws-14490.log
C:\Users\Aharon\AppData\LocalLow\Search Settings\kb128\temp\ws-14493.log
C:\Users\Aharon\AppData\LocalLow\Search Settings
C:\Windows\Installer\a9ccaa.msi
C:\Program Files\Windows Live\Messenger\riched20.dll
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 2.0 *
.
Nom du profil: ahe19kzn.default (Aharon)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Google");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.cherche.us/");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1");
.
.
.
* Internet Explorer Version 8.0.6001.18813 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Page de démarrage : Titre de la fenêtre
PAGE DE RECHERCHE : hxxp://www.cherche.us
Page de démarrage_bak : hxxp://www.cherche.us
Barre de recherche : hxxp://go.microsoft.com/fwlink/?linkid=54896
URL_de_recherche_par_défaut : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URL_de_page_par_défaut : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Page de démarrage : hxxp://fr.msn.com/
URL_de_page_par_défaut : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
URL_de_recherche_par_défaut : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Page de recherche : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Barre de recherche : hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Onglets : res://ieframe.dll/tabswelcome.htm
.
===================================
.
2735 Octet(s) - C:\Ad-Report-CLEAN.log
2565 Octet(s) - C:\Ad-Report-SCAN.log
.
1 Fichier(s) - C:\Users\Aharon\AppData\Local\Temp
1 Fichier(s) - C:\Windows\Temp
.
21 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
2 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à : 18:36:37 | 06/09/2009
.
============== E.O.F ==============
. -
Re,
¡Muy bien ...! ;)
Rehaz RSIT y pega el informe obtenido para el análisis.
++ -
Aquí tienes la traducción: voilà :)
Registro del sistema de información aleatoria 1.06 (escrito por random/random)
Ejecutado por Aharon el 2009-09-06 19:28:14
Microsoft® Windows Vista™ Edición Familiar Premium Service Pack 1
La unidad del sistema C: tiene 39 GB (34%) libres de 114 GB
Total de RAM: 3070 MB (55% libres)
Registro de Trend Micro HijackThis v2.0.2
Escaneo guardado a las 19:28:33, el 06/09/2009
Plataforma: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Modo de arranque: Normal
Procesos en ejecución:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Aharon\Desktop\RSIT.exe
C:\Program Files\trend micro\Aharon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Título de la ventana
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Predeterminado) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - El gancho de búsqueda predeterminado está faltando
O1 - Hosts: ::1 localhost
O2 - BHO: (sin nombre) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (sin archivo)
O2 - BHO: Asistente de enlace de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Plugin de descarga y grabación de RealPlayer para Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (sin nombre) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (sin archivo)
O2 - BHO: Programa de ayuda del asistente de conexión de Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Asistente de Google Toolbar - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Toolbar pdfforge - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: Compresión de diccionario de Google sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Barra de herramientas: Toolbar pdfforge - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O3 - Barra de herramientas: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (Usuario 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (Usuario 'SERVICIO DE RED')
O4 - Inicio Global: Lanzador de Tecnología de Empoderamiento.lnk = ?
O8 - Elemento adicional del menú contextual: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Botón extra: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Botón extra: (sin nombre) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Elemento del menú 'Herramientas' extra: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Botón extra: Investigación - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Botón extra: (sin nombre) - cmdmapping - (sin archivo) (HKCU)
O13 - Prefijo Gopher:
O15 - Zona de confianza: http://www.secuser.com
O16 - DPF: Plug-In de Comunicador Garmin - https://my.garmin.com/mygarmin/m/GarminAxControl.CAB
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O23 - Servicio: Servicio de ALaunch (ALaunchService) - Propietario desconocido - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Servicio: Dispositivo Móvil de Apple - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Servicio: Servicio de Control iAVS4 de avast! (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Servicio: Antivirus avast! - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Servicio: Escáner de correo de avast! - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Servicio: Escáner web de avast! - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Servicio: Servicio de Licencia de Symantec NetConnect (CLTNetCnService) - Propietario desconocido - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (archivo faltante)
O23 - Servicio: Servicio de eRecovery (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Servicio: Registro de Eventos de Intel® PROSet/Wireless (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Servicio: Actualizador de software de Google (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Servicio: Gestor de Tablas de InstallDriver (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Servicio: Servicio de iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Servicio: Servicio de etiquetado directo de LightScribe (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Servicio: MobilityService - Propietario desconocido - C:\Acer\Mobility Center\MobilityService.exe
O23 - Servicio: NMSAccessU - Propietario desconocido - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Servicio: Servicio de registro de Intel® PROSet/Wireless (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Servicio: Servicio de RichVideo de Cyberlink (CRVS) (RichVideo) - Propietario desconocido - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Servicio: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Servicio: Servicio de XAudio - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
Fin del archivo - 8800 bytes
======Carpeta de tareas programadas======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\User_Feed_Synchronization-{4CC4458E-AF2E-4351-B93C-B22A63D5170E}.job
======Volcado del registro======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Asistente de enlace de Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
Plugin de descarga y grabación de RealPlayer para Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-03-26 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programa de ayuda del asistente de conexión de Windows Live ID - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Asistente de Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-06 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-09-06 761840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
Toolbar pdfforge - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Compresión de diccionario de Google sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-06 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - Toolbar pdfforge - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-06 256112]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"ALaunch"=C:\Acer\ALaunch\AlaunchClient.exe []
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-12-14 102400]
"Acer Tour"= []
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-12-14 4702208]
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-01-02 707080]
"PLFSet"=C:\Windows\PLFSet.dll [2007-04-25 45056]
"eRecoveryService"= []
"Acer Tour Reminder"=C:\Acer\AcerTour\Reminder.exe [2007-08-01 151552]
"WarReg_PopUp"=C:\Acer\WR_PopUp\WarReg_PopUp.exe [2006-11-05 57344]
"pdfSaver3"= []
"NvSvc"=C:\Windows\system32\nvsvc.dll [2007-12-14 86016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-12-14 8501792]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-12-14 81920]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-03-26 198160]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-09-06 122368]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"=C:\Acer\AcerTour\Reminder.exe [2007-08-01 151552]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-05-11 68856]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanalPlayer]
C:\Program Files\Lecteur CANALPLAY\CanalPlayer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Aharon\AppData\Local\Google\Update\GoogleUpdate.exe /c []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe [2007-12-05 200704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-01-02 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Aharon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Orion.lnk]
C:\Convesoft\Orion\Messenger.exe []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=1
"EnableUIADesktopToggle"=0
"UacDisableNotify"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=FFFFFFFF
"NoDriveTypeAutoRun"=255
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======Asociaciones de archivos======
.js - editar - C:\Windows\System32\Notepad.exe %1
.js - abrir - C:\Windows\System32\WScript.exe "%1" %*
======Lista de archivos/carpetas creados en el último mes======
2009-09-06 17:57:10 ----A---- C:\UsbFix.txt
2009-09-06 13:02:14 ----D---- C:\Program Files\Ad-Remover
2009-09-06 12:29:08 ----D---- C:\UsbFix
2009-09-06 12:27:03 ----A---- C:\TB.txt
2009-09-06 12:25:37 ----D---- C:\ToolBar SD
2009-09-06 11:47:42 ----D---- C:\Program Files\trend micro
2009-09-06 11:47:41 ----D---- C:\rsit
2009-09-06 10:57:38 ----D---- C:\Program Files\Microsoft Visual Studio
2009-09-06 10:48:08 ----D---- C:\Program Files\Microsoft Visual Studio 8
2009-09-06 10:45:28 ----RHD---- C:\MSOCache
2009-09-02 23:31:41 ----A---- C:\Windows\system32\Apphlpdm.dll
2009-09-02 23:31:40 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-09-01 18:20:42 ----A---- C:\Windows\system32\kerberos.dll
2009-09-01 18:20:41 ----A---- C:\Windows\system32\msv1_0.dll
2009-09-01 18:20:40 ----A---- C:\Windows\system32\wdigest.dll
2009-09-01 18:20:39 ----A---- C:\Windows\system32\lsasrv.dll
2009-09-01 18:20:38 ----A---- C:\Windows\system32\schannel.dll
2009-09-01 18:20:36 ----A---- C:\Windows\system32\secur32.dll
2009-09-01 18:20:36 ----A---- C:\Windows\system32\lsass.exe
2009-08-30 15:56:28 ----D---- C:\Program Files\Acoolsoft
2009-08-30 15:31:50 ----D---- C:\Users\Aharon\AppData\Roaming\TeamViewer
2009-08-30 15:31:46 ----D---- C:\Program Files\TeamViewer
2009-08-30 14:41:56 ----D---- C:\Users\Aharon\AppData\Roaming\gtk-2.0
2009-08-30 14:25:54 ----D---- C:\Program Files\GIMP-2.0
2009-08-27 19:51:13 ----D---- C:\Users\Aharon\AppData\Roaming\LMSOFT
2009-08-27 19:41:28 ----D---- C:\Program Files\Mindscape
2009-08-27 14:38:51 ----A---- C:\Windows\system32\tzres.dll
2009-08-14 15:53:23 ----D---- C:\Program Files\Maïdo Production
2009-08-14 01:52:22 ----D---- C:\Program Files\LimeWire
2009-08-12 16:21:17 ----A---- C:\Windows\system32\atl.dll
2009-08-12 16:21:14 ----A---- C:\Windows\system32\wkssvc.dll
2009-08-12 16:21:06 ----A---- C:\Windows\system32\wmp.dll
2009-08-12 16:21:05 ----A---- C:\Windows\system32\wmpdxm.dll
2009-08-12 16:21:04 ----A---- C:\Windows\system32\spwmp.dll
2009-08-12 16:21:03 ----A---- C:\Windows\system32\dxmasf.dll
2009-08-12 16:21:02 ----A---- C:\Windows\system32\wmploc.DLL
2009-08-12 16:20:59 ----A---- C:\Windows\system32\avifil32.dll
2009-08-12 16:20:55 ----A---- C:\Windows\system32\mstscax.dll
======Lista de archivos/carpetas modificadas en el último mes======
2009-09-06 19:28:25 ----D---- C:\Windows\Prefetch
2009-09-06 19:28:18 ----D---- C:\Windows\Temp
2009-09-06 19:27:08 ----RSD---- C:\Windows\Fonts
2009-09-06 19:14:33 ----SHD---- C:\Información de volumen del sistema
2009-09-06 19:13:07 ----D---- C:\Windows\System32
2009-09-06 19:13:07 ----D---- C:\Windows\inf
2009-09-06 19:13:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-09-06 19:11:08 ----SHD---- C:\Windows\Installer
2009-09-06 18:01:09 ----SD---- C:\Windows\Archivos de programa descargados
2009-09-06 17:59:23 ----D---- C:\Windows\Tasks
2009-09-06 17:59:01 ----SHD---- C:\$RECYCLE.BIN
2009-09-06 17:06:22 ----D---- C:\Program Files\Google
2009-09-06 13:02:14 ----RD---- C:\Program Files
2009-09-06 11:40:04 ----HD---- C:\Program Files\Información de Instalación de InstallShield
2009-09-06 11:36:00 ----D---- C:\ProgramData\eBay
2009-09-06 11:09:52 ----D---- C:\ProgramData\Ayuda de Microsoft
2009-09-06 11:09:47 ----D---- C:\Program Files\Archivos Comunes\microsoft shared
2009-09-06 11:09:01 ----D---- C:\Windows\ShellNew
2009-09-06 11:08:48 ----A---- C:\Windows\win.ini
2009-09-06 11:08:39 ----D---- C:\Program Files\Archivos Comunes\Sistema
2009-09-06 11:04:16 ----RSD---- C:\Windows\assembly
2009-09-06 11:04:06 ----D---- C:\Windows\winsxs
2009-09-06 11:00:28 ----D---- C:\ProgramData\Pinnacle
2009-09-06 10:59:12 ----D---- C:\Program Files\Microsoft Works
2009-09-06 10:58:17 ----D---- C:\Program Files\MSBuild
2009-09-06 10:57:46 ----D---- C:\Program Files\Microsoft Office
2009-09-06 10:56:08 ----SD---- C:\ProgramData\Microsoft
2009-09-06 10:40:09 ----D---- C:\ProgramData\Actualizador de Google -
Re,
OK este informe está limpio :)
Tengo una pregunta: ¿la memoria USB, trabajas con ella? Si es así, tu PC de trabajo está infectado por Conficker, podemos desinfectarlo si lo deseas, pero una vez que esté desinfectado, te abriré un tema escribiendo tu apodo...
En fin, seguimos:
Descarga MalwareBytes' Anti-Malware (MBAM).
▶ Haz doble clic en el archivo descargado para iniciar el proceso de instalación, elige "Español" y acepta cuando te soliciten actualizarlo.
▶ Observa bien este tutorial para utilizar bien el programa.
! Desconéctate, cierra todas las aplicaciones en curso !
⇒ Inicia MBAM.
▶ En la pestaña de configuración, marca la casilla: "Detener Internet Explorer durante la eliminación"
▶ Ahora haz clic en la pestaña de búsqueda y marca la casilla: "Realizar un análisis rápido".
▶ Luego haz clic en "Buscar".
▶ Deja que escanee el PC...
▶ Una vez que el análisis haya terminado, haz clic en "OK", luego en "Mostrar resultados"
▶ Verifica que todo esté marcado y haz clic en "Eliminar selección."
▶ Puede que te pida reiniciar para finalizar la eliminación de los malware, acepta haciendo clic en "Sí".
▶ Al final se abrirá un informe, guárdalo de manera que lo puedas encontrar para publicarlo en el foro.
▶ Vuelve al foro y copia y pega el informe en tu próxima respuesta.
Nota: los informes también están guardados en la pestaña Informe/Log -
Hola, perdón por esta larga ausencia, tuve que irme unos días...
aquí está el registro
gracias
Malwarebytes' Anti-Malware 1.41
Versión de la base de datos: 2775
Windows 6.0.6001 Service Pack 1
12/09/2009 22:30:49
mbam-log-2009-09-12 (22-30-49).txt
Tipo de búsqueda: Análisis rápido
Elementos examinados: 104581
Tiempo transcurrido: 6 minuto(s), 10 segundo(s)
Proceso(s) de memoria infectado(s): 0
Módulo(s) de memoria infectado(s): 0
Clave(s) del Registro infectada(s): 1
Valor(es) del Registro infectado(s): 0
Elemento(s) de datos del Registro infectado(s): 0
Carpeta(s) infectada(s): 0
Archivo(s) infectado(s): 0
Proceso(s) de memoria infectado(s):
(Ningún elemento dañino detectado)
Módulo(s) de memoria infectado(s):
(Ningún elemento dañino detectado)
Clave(s) del Registro infectada(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Puesta en cuarentena y eliminada con éxito.
Valor(es) del Registro infectado(s):
(Ningún elemento dañino detectado)
Elemento(s) de datos del Registro infectado(s):
(Ningún elemento dañino detectado)
Carpeta(s) infectada(s):
(Ningún elemento dañino detectado)
Archivo(s) infectado(s):
(Ningún elemento dañino detectado) -
Re,
Hola :)
¡Responde las preguntas!
Tengo una pregunta: ¿trabajas con el usb? Si es así, tu PC de trabajo está infectado por Conficker, podemos desinfectarlo si lo deseas, pero una vez desinfectado, te abriré un tema escribiendo tu apodo...
¿Cómo va tu PC? ¿Mejor?? -
hola
el pc va mejor
gracias por tu ayuda
hasta pronto