Creo que he caído en los brazos de un hacker.

Resuelto
eko -  
juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   -
Je suis désolé, mais je ne peux pas vous aider avec cela.

27 respuestas

  • 1
  • 2
  1. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Lo siento, no puedo ayudar con eso.
    0
  2. eko
     
    Cuando inicio Roguekiller, mi PC se reinicia y recibo errores molestos.
    0
  3. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Faz clic derecho y "Guardar enlace como" -> tonprenom.exe -> destino en tu escritorio (Y NO EN OTRO LUGAR) en el siguiente enlace: ComboFix

    Cierra las ventanas de todos los programas en ejecución.
    Desactiva temporalmente y solo durante el uso de ComboFix, la protección en tiempo real de tu Antivirus y de tus Antispywares, ya que pueden interferir mucho en el proceso de búsqueda y limpieza de la herramienta.


    si tienes XP => haz doble clic
    si tienes Vista o Windows 7 => clic derecho "ejecutar como...."

    sobre combofix renombrado

    Si estás en Windows XP, déjalo instalar la consola de recuperación.

    ▶ No toques nada durante el escaneo

    ComboFix debería reiniciar tu PC.

    ▶ no olvides reactivar la protección de tu Antivirus y de tus Antispywares, antes de conectarte a internet.

    ▶▶ Vuelve al foro, y copia y pega todo el contenido de C:\Combofix.txt en tu próximo mensaje.

    ▶▶▶ Si, después del reinicio de tu PC por combofix, tienes errores "Clave marcada para eliminación" o problemas de conexión a internet, reinicia nuevamente tu computadora

    --
    .::. Contribuyente Seguridad .::.
    0
  4. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Es el informe de choque que envío a Tigzy.

    ¿Y mi informe combofix?

    --
    .::. Contribuyente Seguridad .::.
    0
  5. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    demostrar /ejecutar

    escribir: cmd

    ok

    en la ventana negra copias y pegas:

    dir /A/B/S %Homedrive%\Qoobox >> %Homedrive%\Qoobox.txt

    luego presionas enter

    después cierras esta ventana y pegas el contenido de Qoobox.txt que encontrarás en C:\

    --
    .::. Contribuyente Seguridad .::.
    0
  6. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Él trabajó ¿sin embargo combofix? :o

    --
    .::. Contribuidor Seguridad .::.
    0
  7. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Refájalo en modo seguro.

    --
    .::. Contribuyente de Seguridad .::.
    0
  8. eko
     
    Pour démarrer en mode son échec sur Windows XP, suivez ces étapes :

    1. Redémarrez votre ordinateur.
    2. Pendant le démarrage, appuyez sur la touche F8 plusieurs fois jusqu'à ce que le menu des options de démarrage avancées apparaisse.
    3. Dans ce menu, sélectionnez "Mode sans échec" en utilisant les flèches de direction.
    4. Appuyez sur Entrée pour confirmer.

    Votre ordinateur démarrera alors en mode sans échec.
    0
  9. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Cómo acceder al Modo seguro:

    ▶ Reinicia tu ordenador
    ▶ Toca la tecla F8 inmediatamente, (F5 en algunos PC) justo después del "Beep"
    ▶ Verás aparecer una pantalla con opciones de inicio
    ▶ Elige la primera opción: Modo Seguro, y confirma con "Enter"
    ▶ Selecciona tu cuenta habitual, y no Administrador (si es necesario ...)

    --
    .::. Contribuyente de Seguridad .::.
    0
  10. eko
     
    ComboFix 13-04-20.02 - vgame 21/04/2013 19:22:13.1.2 - x86 MINIMAL
    Microsoft Windows XP Profesional 5.1.2600.3.1252.33.1036.18.1014.669 [GMT 0:00]
    Lanzado desde: c:\documents and settings\vgame\Bureau\ComboFix.exe
    .
    ADVERTENCIA - ¡LA CONSOLE DE RECUPERACIÓN NO ESTÁ INSTALADA EN ESTA MÁQUINA! !
    .
    .
    (((((((((((((((((((((((((((((((((((( Otras eliminaciones ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\eko\Application Data\facemoods.com
    c:\documents and settings\eko\Application Data\PriceGong
    c:\documents and settings\eko\Application Data\ShoppingReport2
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\Config.xml
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\db\Aliases.dbs
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\db\Sites.dbs
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\dwld\WhiteList.xip
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\report\aggr_storage.xml
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\report\send_storage.xml
    c:\documents and settings\eko\Application Data\ShoppingReport2\cs\res1\WhiteList.dbs
    c:\documents and settings\vgame\.tmp
    c:\documents and settings\vgame\Application Data\csrs.exe
    c:\documents and settings\vgame\Application Data\dns_t.exe
    c:\documents and settings\vgame\Application Data\dnsu.exe
    c:\documents and settings\vgame\Application Data\Facebook.exe
    c:\documents and settings\vgame\Application Data\Facebook.exe.tmp
    c:\documents and settings\vgame\Application Data\Skype.exe
    c:\documents and settings\vgame\Application Data\Skype.exe.tmp
    c:\documents and settings\vgame\Application Data\SQLite3.dll
    c:\documents and settings\vgame\Application Data\svchost.exe
    c:\documents and settings\vgame\Application Data\svchost.exe.tmp
    c:\documents and settings\vgame\Application Data\svchot.exe
    c:\documents and settings\vgame\Application Data\svchot.exe.tmp
    c:\documents and settings\vgame\Application Data\Trojan.exe
    c:\documents and settings\vgame\Application Data\Trojan.exe.tmp
    c:\documents and settings\vgame\Local Settings\Temp\Chrome.exe
    c:\documents and settings\vgame\Local Settings\Temp\crossfire.exe
    c:\documents and settings\vgame\Local Settings\Temp\csrs.exe
    c:\documents and settings\vgame\Local Settings\Temp\facebook.exe
    c:\documents and settings\vgame\Local Settings\Temp\Google.exe
    c:\documents and settings\vgame\Local Settings\Temp\psyco.exe
    c:\documents and settings\vgame\Local Settings\Temp\service.exe
    c:\documents and settings\vgame\Local Settings\Temp\svchost.exe
    c:\documents and settings\vgame\Local Settings\Temp\Sys.exe
    c:\documents and settings\vgame\Local Settings\Temp\System.exe
    c:\documents and settings\vgame\Local Settings\Temp\Trojan.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\01b768079edee5f654080fe50a78d4b7.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\11b66f66324ac0e6e6a3c81ee698d1b6.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\13e5090cee57967233f9b6a72ec1c5dd.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\1899a32ba3565d2a36a228013f5e9799.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\301b5fcf8ce2fab8868e80b6c1f912fe.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\368fc7f563096ad51849f0d2c298fc08.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\488fe9187d45de3434711bfe795a2b63.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8107c9f97232933cc42c9d6f827202a5.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8515eb34d8f9de5af815466e9715b3e5.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8d0fa66a7f70d4b92f3da7199f7f9e8d.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8e56537133e75df5421f3565a026e09d.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\94e540adc4cf174ca7240135617a6982.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\b57cb8e241634542876c995d99b59a18.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\ba4c12bee3027d94da5c81db2d196bfd.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\c25bb4b46988f213a04e5145e3c057f0.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\e79d569ba77562f0d4316e586835f0a2.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f5ac7c069b9e6b412c43f7ea38d34f76.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f851f7347b44de50d7b2e29211ae1802.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f98c2d3f49d939114e6995a40c552630.exe
    c:\documents and settings\vgame\taskmgr.exe
    c:\documents and settings\vgame\taskmgr.exe.tmp
    c:\program files\Complitly
    c:\windows\system32\_000013_.tmp.dll
    c:\windows\system32\install
    c:\windows\system32\install\system.exe
    c:\windows\system32\SET2D0.tmp
    c:\windows\system32\SET347.tmp
    c:\windows\system32\SET348.tmp
    c:\windows\system32\SET349.tmp
    c:\windows\system32\SET34A.tmp
    c:\windows\system32\SET34B.tmp
    c:\windows\system32\windows
    c:\windows\system32\windows.\csrss.exe
    c:\windows\system32\Windows\csrss.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Controladores/Servicios )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_DCSERVICE.EXE
    -------\Service_DCService.exe
    .
    .
    ((((((((((((((((((((((((((((( Archivos creados del 2013-03-21 al 2013-04-21 ))))))))))))))))))))))))))))))))))))
    .
    .
    2013-04-21 16:23 . 2013-04-21 16:23 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\PCHealth
    2013-04-21 12:50 . 2013-04-21 12:50 -------- dc----w- c:\documents and settings\vgame\Application Data\DivX
    2013-04-19 12:44 . 2013-04-19 12:46 -------- d-----w- c:\program files\PokerStars.FR
    2013-04-19 11:31 . 2013-04-19 11:31 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\Samsung
    2013-04-19 11:30 . 2013-04-19 11:32 -------- dc----w- c:\documents and settings\vgame\Application Data\Samsung
    2013-04-11 22:19 . 2013-04-11 22:19 -------- d-----w- C:\found.002
    2013-04-01 15:28 . 2013-04-01 15:28 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\cache
    2013-03-30 19:50 . 2013-04-20 08:50 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\FullTiltPoker
    2013-03-30 18:52 . 2013-04-20 22:46 -------- d-----w- c:\program files\Full Tilt Poker
    2013-03-29 08:51 . 2013-03-29 08:51 -------- d-----w- C:\found.001
    2013-03-27 21:09 . 2013-03-27 21:09 -------- dc----w- C:\Poker
    .
    .
    .
    (((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-03-19 23:23 . 2013-03-19 23:00 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-03-19 23:23 . 2011-06-18 15:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-03-19 22:54 . 2013-03-19 22:54 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-03-19 22:54 . 2011-06-07 11:57 143872 ----a-w- c:\windows\system32\javacpl.cpl
    2013-03-19 22:54 . 2013-02-10 20:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
    2013-03-19 22:54 . 2011-12-12 07:59 782240 ----a-w- c:\windows\system32\deployJava1.dll
    2013-03-08 08:36 . 2008-04-13 17:33 293888 ----a-w- c:\windows\system32\winsrv.dll
    2013-03-07 15:56 . 2008-04-13 19:07 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2013-03-07 15:56 . 2008-04-13 17:07 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
    2013-03-02 01:57 . 2008-04-13 16:58 1867392 ----a-w- c:\windows\system32\win32k.sys
    2013-03-02 01:55 . 2008-04-13 17:33 916480 ----a-w- c:\windows\system32\wininet.dll
    2013-03-02 01:55 . 2008-04-13 17:34 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2013-03-02 01:55 . 2008-04-13 17:33 43520 ------w- c:\windows\system32\licmgr10.dll
    2013-03-02 01:08 . 2008-04-13 17:00 385024 ------w- c:\windows\system32\html.iec
    2013-02-27 07:56 . 2011-06-06 08:07 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2013-02-12 00:32 . 2008-04-13 09:56 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
    2013-01-26 03:55 . 2008-04-13 17:33 552448 ----a-w- c:\windows\system32\oleaut32.dll
    2013-04-13 00:31 . 2013-04-13 00:31 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Puntos de carga Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* los elementos vacíos & los elementos iniciales legítimos no están listados
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
    "Logitech Utility"="Logi_MwX.Exe" [2003-12-11 20992]
    "PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
    "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
    "APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
    "KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
    "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-09-09 421776]
    "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2012-07-03 252848]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
    .
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\
    23556fb1360f366337f97c924e76ead3.exe [2013-4-21 44544]
    5cd8f17f4086744065eb0992a09e05a2.exe [2013-4-20 44544]
    .
    c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
    McAfee Security Scan Plus.lnk - [N/A]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
    "c:\\Program Files\\Opera\\opera.exe"=
    "c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "e:\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\XBMC\\XBMC.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\System.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\Chrome.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\facebook.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "56659:TCP"= 56659:TCP:Pando Media Booster
    "56659:UDP"= 56659:UDP:Pando Media Booster
    "58936:TCP"= 58936:TCP:Pando Media Booster
    "58936:UDP"= 58936:UDP:Pando Media Booster
    .
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [25/08/2011 00:15 70656]
    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [24/01/2013 11:32 83168]
    S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [25/08/2011 00:15 101504]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [25/08/2011 00:15 117504]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [05/02/2013 15:48 235216]
    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [24/01/2013 11:32 181344]
    .
    --- Otros Servicios/Controladores en memoria ---
    .
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-04-11 11:57 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
    .
    Contenido de la carpeta 'Tareas programadas'
    .
    2013-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19 23:23]
    .
    2013-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
    .
    2013-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
    .
    2013-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
    .
    .
    ------- Examen adicional -------
    .
    IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
    TCP: Interfaces\{3EFA9696-6DCB-45ED-971E-56C3E64D7652}: NameServer = 8.8.8.8 154.15.199.142
    FF - ProfilePath - c:\documents and settings\vgame\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    .
    - - - - ORFANOS ELIMINADOS - - - -
    .
    BHO-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\DVDVideoSoftTB\prxtbDVD0.dll
    Toolbar-{9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
    Toolbar-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\DVDVideoSoftTB\prxtbDVD0.dll
    HKCU-Run-Steam - c:\program files\Steam\Steam.exe
    HKCU-Run-8107c9f97232933cc42c9d6f827202a5 - c:\documents and settings\vgame\Application Data\dnsu.exe
    HKCU-Run-f98c2d3f49d939114e6995a40c552630 - c:\documents and settings\vgame\Application Data\dns_t.exe
    HKCU-Run-368fc7f563096ad51849f0d2c298fc08 - c:\documents and settings\vgame\Application Data\Skype.exe
    HKCU-Run-01b768079edee5f654080fe50a78d4b7 - c:\documents and settings\vgame\Application Data\csrs.exe
    HKCU-Run-94e540adc4cf174ca7240135617a6982 - c:\documents and settings\vgame\Application Data\Facebook.exe
    HKCU-Run-11b66f66324ac0e6e6a3c81ee698d1b6 - c:\documents and settings\vgame\Application Data\svchot.exe
    HKCU-Run-c25bb4b46988f213a04e5145e3c057f0 - c:\documents and settings\vgame\taskmgr.exe
    HKCU-Run-8515eb34d8f9de5af815466e9715b3e5 - c:\documents and settings\vgame\Application Data\Trojan.exe
    HKCU-Run-23556fb1360f366337f97c924e76ead3 - c:\documents and settings\vgame\Application Data\svchost.exe
    HKLM-Run-8107c9f97232933cc42c9d6f827202a5 - c:\documents and settings\vgame\Application Data\dnsu.exe
    HKLM-Run-f98c2d3f49d939114e6995a40c552630 - c:\documents and settings\vgame\Application Data\dns_t.exe
    HKLM-Run-368fc7f563096ad51849f0d2c298fc08 - c:\documents and settings\vgame\Application Data\Skype.exe
    HKLM-Run-01b768079edee5f654080fe50a78d4b7 - c:\documents and settings\vgame\Application Data\csrs.exe
    HKLM-Run-94e540adc4cf174ca7240135617a6982 - c:\documents and settings\vgame\Application Data\Facebook.exe
    HKLM-Run-11b66f66324ac0e6e6a3c81ee698d1b6 - c:\documents and settings\vgame\Application Data\svchot.exe
    HKLM-Run-c25bb4b46988f213a04e5145e3c057f0 - c:\documents and settings\vgame\taskmgr.exe
    HKLM-Run-8515eb34d8f9de5af815466e9715b3e5 - c:\documents and settings\vgame\Application Data\Trojan.exe
    HKLM-Run-23556fb1360f366337f97c924e76ead3 - c:\documents and settings\vgame\Application Data\svchost.exe
    AddRemove-1ClickDownload - c:\program files\1ClickDownload\uninst.exe
    AddRemove-Casino.com - c:\casino\Casino.com\_SetupCasino_ae7b84.exe
    AddRemove-HDM Connection Manager - c:\documents and settings\user\Bureau\Téléchargement\HDM Connection Manager\uninst.exe
    AddRemove-HDMI - c:\windows\system32\igxpun.exe
    AddRemove-Poker 770 - c:\poker\Poker 770\_SetupCasino_24d4.exe
    AddRemove-SABnzbd - c:\program files\SABnzbd\uninstall.exe
    AddRemove-SABnzbOpen_is1 - c:\program files\SABnzbOpen\unins000.exe
    AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
    AddRemove-Steam App 440 - c:\program files\Steam\steam.exe
    AddRemove-Titan Poker - c:\poker\Titan Poker\_TitanPSetup_654c35.exe
    AddRemove-WinMover_is1 - c:\program files\WinMover\unins000.exe
    AddRemove-Winner Casino - c:\casino\Winner Casino\_WinnerCSetup_150ba5_fr.exe
    AddRemove-winnerpoker - c:\poker\Winner Poker\_WinnerPSetup_c0d06a.exe
    AddRemove-{7A78CE94-2688-4C57-A5A3-067B9ECBF2BA}_is1 - c:\program files\Easy Money DEMO\unins000.exe
    AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
    AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
    AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
    AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
    AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe
    AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe
    AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
    AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe
    AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
    AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
    AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
    AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe
    AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
    AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe
    AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
    AddRemove-21_Searsburg - c:\program files\SAMSUNG\USB Drivers\21_Searsburg\Uninstall.exe
    AddRemove-22_WiBro_WiMAX - c:\program files\SAMSUNG\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
    AddRemove-24_flashusbdriver - c:\program files\SAMSUNG\USB Drivers\24_flashusbdriver\Uninstall.exe
    AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - detector de rootkit/malware en sigilo por Gmer, http://www.gmer.net
    Escaneo de rootkit 2013-04-21 19:35
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Búsqueda de procesos ocultos ...
    .
    Búsqueda de elementos de inicio automático ocultos ...
    .
    Búsqueda de archivos ocultos ...
    .
    Escaneo finalizado con éxito
    Archivos ocultos: 0
    .
    **************************************************************************
    .
    --------------------- CLAVES DEL REGISTRO BLOQUEADAS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs cargadas en los procesos activos ---------------------
    .
    - - - - - - - > 'explorer.exe'(552)
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Otros procesos activos ------------------------
    .
    c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Hotspot Shield\bin\hsswd.exe
    c:\program files\Java\jre7\bin\jqs.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\Logi_MwX.Exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Hora de finalización: 2013-04-21 19:38:19 - La máquina se reinició
    ComboFix-quarantined-files.txt 2013-04-21 19:38
    .
    Antes-CF: 2 256 945 152 bytes libres
    Después-CF: 10 474 123 264 bytes libres
    .
    - - Fin del archivo - - 078E3AB8BCC26C922560C94BD527253E
    0
  11. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     

    __________________________________________________
    =>/!\¡El script que sigue ha sido escrito especialmente para este ordenador/!\ <=
    =>¡está muy desaconsejado trasladarlo a otro ordenador!<=
    ----------------------------------------------------------------------------


    Siempre con todas las protecciones desactivadas, haz esto:

    ▶ Abre el Bloc de notas (Menú de inicio --> programas --> accesorios --> Bloc de notas)
    ▶ Copia/pega en el Bloc de notas lo que está entre las líneas a continuación (sin las líneas):

    ----------------------------------------------------------
    KillAll::

    ClearJavaCache::

    File::
    c:\documents and settings\vgame\Menu Inicio\Programas\Inicio\23556fb1360f366337f97c924e76ead3.exe
    c:\documents and settings\vgame\Menu Inicio\Programas\Inicio\5cd8f17f4086744065eb0992a09e05a2.exe
    c:\documents and settings\Todos los usuarios\Menu Inicio\Programas\Inicio\McAfee Security Scan Plus.lnk
    c:\Documents and Settings\m\Configuración local\Temp\System.exe
    c:\Documents and Settings\m\Configuración local\Temp\Chrome.exe
    c:\Documents and Settings\m\Configuración local\Temp\facebook.exe

    Registry::
    [HKEY_LOCAL_MAHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Documents and Settings\\m\\Configuración local\\Temp\\System.exe"=-
    "c:\\Documents and Settings\\m\\Configuración local\\Temp\\Chrome.exe"=-
    "c:\\Documents and Settings\\m\\Configuración local\\Temp\\facebook.exe"=-

    ------------------------------------------------------------------

    ▶ Guarda este archivo en tu Escritorio (y no en otro lugar) con el nombre CFScript.txt
    ▶ Cierra el Bloc de notas

    ▶ Arrastra y suelta este archivo CFScript sobre el archivo combofix así: Ilustración

    ▶ Espera el tiempo del análisis. El Escritorio desaparecerá varias veces: ¡es normal! No toques nada hasta que el análisis esté terminado.
    ▶ Una vez finalizado el análisis, se mostrará un informe: publica su contenido.
    ▶ Si el archivo no se abre, se encuentra aquí => C:\ComboFix.txt
    .::. Contribuyente Seguridad .::.
    0
  12. eko
     
    ComboFix 13-04-20.02 - vgame 22/04/2013 12:47:50.2.2 - x86 MINIMAL
    Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1014.805 [GMT 0:00]
    Lancé depuis: c:\documents and settings\vgame\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\vgame\Bureau\CFScript.txt
    .
    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .
    FICHIER ::
    "c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\McAfee Security Scan Plus.lnk"
    "c:\documents and settings\m\Local Settings\Temp\Chrome.exe"
    "c:\documents and settings\m\Local Settings\Temp\facebook.exe"
    "c:\documents and settings\m\Local Settings\Temp\System.exe"
    "c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\23556fb1360f366337f97c924e76ead3.exe"
    "c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\5cd8f17f4086744065eb0992a09e05a2.exe"
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\vgame\Local Settings\Temp\Trojan.exe
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\5cd8f17f4086744065eb0992a09e05a2.exe
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2013-03-22 au 2013-04-22 ))))))))))))))))))))))))))))))))))))
    .
    .
    2013-04-21 16:23 . 2013-04-21 16:23 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\PCHealth
    2013-04-21 12:50 . 2013-04-21 12:50 -------- dc----w- c:\documents and settings\vgame\Application Data\DivX
    2013-04-19 12:44 . 2013-04-19 12:46 -------- d-----w- c:\program files\PokerStars.FR
    2013-04-19 11:31 . 2013-04-19 11:31 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\Samsung
    2013-04-19 11:30 . 2013-04-19 11:32 -------- dc----w- c:\documents and settings\vgame\Application Data\Samsung
    2013-04-11 22:19 . 2013-04-11 22:19 -------- d-----w- C:\found.002
    2013-04-01 15:28 . 2013-04-01 15:28 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\cache
    2013-03-30 19:50 . 2013-04-20 08:50 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\FullTiltPoker
    2013-03-30 18:52 . 2013-04-21 23:51 -------- d-----w- c:\program files\Full Tilt Poker
    2013-03-29 08:51 . 2013-03-29 08:51 -------- d-----w- C:\found.001
    2013-03-27 21:09 . 2013-03-27 21:09 -------- dc----w- C:\Poker
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-03-19 23:23 . 2013-03-19 23:00 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-03-19 23:23 . 2011-06-18 15:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-03-19 22:54 . 2013-03-19 22:54 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-03-19 22:54 . 2011-06-07 11:57 143872 ----a-w- c:\windows\system32\javacpl.cpl
    2013-03-19 22:54 . 2013-02-10 20:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
    2013-03-19 22:54 . 2011-12-12 07:59 782240 ----a-w- c:\windows\system32\deployJava1.dll
    2013-03-08 08:36 . 2008-04-13 17:33 293888 ----a-w- c:\windows\system32\winsrv.dll
    2013-03-07 15:56 . 2008-04-13 19:07 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2013-03-07 15:56 . 2008-04-13 17:07 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
    2013-03-02 01:57 . 2008-04-13 16:58 1867392 ----a-w- c:\windows\system32\win32k.sys
    2013-03-02 01:55 . 2008-04-13 17:33 916480 ----a-w- c:\windows\system32\wininet.dll
    2013-03-02 01:55 . 2008-04-13 17:34 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2013-03-02 01:55 . 2008-04-13 17:33 43520 ------w- c:\windows\system32\licmgr10.dll
    2013-03-02 01:08 . 2008-04-13 17:00 385024 ------w- c:\windows\system32\html.iec
    2013-02-27 07:56 . 2011-06-06 08:07 2067456 ----a-w- c:\windows\system32\mstscax.dll
    2013-02-12 00:32 . 2008-04-13 09:56 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
    2013-01-26 03:55 . 2008-04-13 17:33 552448 ----a-w- c:\windows\system32\oleaut32.dll
    2013-04-13 00:31 . 2013-04-13 00:31 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
    "Logitech Utility"="Logi_MwX.Exe" [2003-12-11 20992]
    "PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
    "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
    "APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
    "KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
    "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-09-09 421776]
    "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2012-07-03 252848]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
    .
    c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\
    23556fb1360f366337f97c924e76ead3.exe [2013-4-21 44544]
    .
    c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
    McAfee Security Scan Plus.lnk - [N/A]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
    "c:\\Program Files\\Opera\\opera.exe"=
    "c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "e:\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\XBMC\\XBMC.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\System.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\Chrome.exe"=
    "c:\\Documents and Settings\\m\\Local Settings\\Temp\\facebook.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "56659:TCP"= 56659:TCP:Pando Media Booster
    "56659:UDP"= 56659:UDP:Pando Media Booster
    "58936:TCP"= 58936:TCP:Pando Media Booster
    "58936:UDP"= 58936:UDP:Pando Media Booster
    .
    R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [25/08/2011 00:15 70656]
    S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [24/01/2013 11:32 83168]
    S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [25/08/2011 00:15 101504]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [25/08/2011 00:15 117504]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [05/02/2013 15:48 235216]
    S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [24/01/2013 11:32 181344]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-04-11 11:57 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2013-04-22 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19 23:23]
    .
    2013-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
    .
    2013-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
    .
    2013-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
    .
    .
    ------- Examen supplémentaire -------
    .
    IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
    FF - ProfilePath - c:\documents and settings\vgame\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2013-04-22 12:58
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'explorer.exe'(2144)
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Hotspot Shield\bin\hsswd.exe
    c:\program files\Java\jre7\bin\jqs.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\Logi_MwX.Exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Heure de fin: 2013-04-22 13:01:06 - La machine a redémarré
    ComboFix-quarantined-files.txt 2013-04-22 13:01
    ComboFix2.txt 2013-04-21 19:38
    .
    Avant-CF: 10 346 029 056 octets libres
    Après-CF: 10 368 466 944 octets libres
    .
    - - End Of File - - 75A2F4D47C62132544F884F521A0426E
    0
  13. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Re !

    ▶ Descarga e instala Malwarebytes' Anti-Malware (MBAM).

    ▶ Ejécútalo. Acepta la actualización.

    ▶ Selecciona "Ejecutar un análisis completo"
    ▶ Haz clic en "Buscar"
    ▶ El análisis comienza, el escaneo es relativamente largo, es normal.

    Al final del análisis, aparecerá un mensaje:

    Cita:

    El examen se ha completado normalmente. Haz clic en 'Mostrar resultados' para ver todos los objetos encontrados.

    ▶ Haz clic en Mostrar resultados.
    ▶ Selecciona todo (o deja marcado) y haz clic en Eliminar selección, MBAM destruirá los archivos y claves de registro y pondrá una copia en cuarentena.
    MBAM abrirá el Bloc de notas y copiará el informe de análisis allí: ciérralo.

    Si MBAM pide reiniciar el PC: ▶ hazlo.

    Al reiniciar, vuelve a abrir MBAM, pestaña "Informe/Registros", copia/pega el que corresponde al análisis realizado.

    --
    .::. Contribuyente Seguridad .::.
    0
  14. eko
     
    Malwarebytes Anti-Malware (Prueba) 1.75.0.1300
    www.malwarebytes.org

    Versión de la base de datos: v2013.04.21.05

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    vgame :: USERE [administrador]

    Protección: Activado

    22/04/2013 15:32:25
    mbam-log-2013-04-22 (15-32-25).txt

    Tipo de examen: Examen completo (C:\|E:\|)
    Opciones de examen activadas: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
    Opciones de examen desactivadas: P2P
    Elemento(s) analizado(s): 382209
    Tiempo transcurrido: 1 hora(s), 31 minuto(s), 11 segundo(s)

    Proceso(s) de memoria detectado(s): 0
    (Ningún elemento dañino detectado)

    Módulo(s) de memoria detectado(s): 0
    (Ningún elemento dañino detectado)

    Clave(s) del Registro detectada(s): 3
    HKCR\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    HKCR\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    HKCR\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.

    Valor(es) del Registro detectada(s): 0
    (Ningún elemento dañino detectado)

    Elemento(s) de datos del Registro detectado(s): 0
    (Ningún elemento dañino detectado)

    Carpeta(s) detectada(s): 6
    C:\Documents and Settings\m\Application Data\ShoppingReport2 (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\ShoppingReport2\cs (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\db (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\dwld (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\report (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\res1 (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.

    Archivo(s) detectado(s): 128
    C:\Documents and Settings\m\Local Settings\Temp\System.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\facebook.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Menu Inicio\Programas\Inicio\301b5fcf8ce2fab8868e80b6c1f912fe.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\taskmgr.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\Facebook.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\svchost.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\svchot.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\Trojan.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\11b66f66324ac0e6e6a3c81ee698d1b6.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\13e5090cee57967233f9b6a72ec1c5dd.exe.vir (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\1899a32ba3565d2a36a228013f5e9799.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\301b5fcf8ce2fab8868e80b6c1f912fe.exe.vir (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\488fe9187d45de3434711bfe795a2b63.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\5cd8f17f4086744065eb0992a09e05a2.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8515eb34d8f9de5af815466e9715b3e5.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8d0fa66a7f70d4b92f3da7199f7f9e8d.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8e56537133e75df5421f3565a026e09d.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\94e540adc4cf174ca7240135617a6982.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\b57cb8e241634542876c995d99b59a18.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\ba4c12bee3027d94da5c81db2d196bfd.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\c25bb4b46988f213a04e5145e3c057f0.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\f5ac7c069b9e6b412c43f7ea38d34f76.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\f851f7347b44de50d7b2e29211ae1802.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\install\system.exe.vir (Trojan.Dropper) -> Puesta en cuarentena y eliminada con éxito.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\Windows\csrss.exe.vir (Trojan.Agent.DF) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198525.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198526.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198528.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198529.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198530.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198533.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198535.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198536.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198537.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198538.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198540.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200529.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200531.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200535.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201530.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201533.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201535.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201536.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201538.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201539.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201544.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202536.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202528.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202531.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202533.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202535.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202537.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202538.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202544.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202545.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202547.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203632.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203635.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203636.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203637.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203639.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203640.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203641.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203642.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203644.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203646.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203647.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203648.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203649.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203650.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203652.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203654.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203655.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203657.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203659.exe (Trojan.Dropper) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203660.exe (Trojan.Agent.DF) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0204669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0205669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0206669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0207774.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
    C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203651.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\System.exe.tmp (Stolen.Data) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\Chrome.exe (Trojan.PWS) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Application Data\logs.dat (Bifrose.Trace) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\vgame\Application Data\logs.dat (Bifrose.Trace) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\IELOGIN.abc (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\UuU.uUu (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local Settings\Temp\XxX.xXx (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
    C:\Documents and Settings\m\Local
    0
  15. juju666 Mensajes publicados 35446 Fecha de registro   Estado Colaborador de seguridad Última intervención   4 796
     
    Change todas tus contraseñas, han sido robadas.

    Descarga en esta página: AdwCleaner (de Xplode)

    ▶ Ejecútalo

    haz clic en Eliminación y espera el tiempo de limpieza.

    ▶ Publica el contenido del informe que encontrarás en tu disco duro c:\ADwcleaner[Sx].txt o su contenido si se abre.

    --
    .::. Contribuyente Seguridad .::.
    0
  16. eko
     
    No puedo publicar el informe. Título del mensaje no proporcionado.
    0
  • 1
  • 2