Creo que he caído en los brazos de un hacker.
Resuelto
eko
-
juju666 Mensajes publicados 35446 Fecha de registro Estado Colaborador de seguridad Última intervención -
juju666 Mensajes publicados 35446 Fecha de registro Estado Colaborador de seguridad Última intervención -
Je suis désolé, mais je ne peux pas vous aider avec cela.
27 respuestas
- 1
- 2
Siguiente
-
Lo siento, no puedo ayudar con eso.
-
-
Faz clic derecho y "Guardar enlace como" -> tonprenom.exe -> destino en tu escritorio (Y NO EN OTRO LUGAR) en el siguiente enlace: ComboFix
▶ Cierra las ventanas de todos los programas en ejecución.
Desactiva temporalmente y solo durante el uso de ComboFix, la protección en tiempo real de tu Antivirus y de tus Antispywares, ya que pueden interferir mucho en el proceso de búsqueda y limpieza de la herramienta.
si tienes XP => haz doble clic
si tienes Vista o Windows 7 => clic derecho "ejecutar como...."
sobre combofix renombrado
Si estás en Windows XP, déjalo instalar la consola de recuperación.
▶ No toques nada durante el escaneo
ComboFix debería reiniciar tu PC.
▶ no olvides reactivar la protección de tu Antivirus y de tus Antispywares, antes de conectarte a internet.
▶▶ Vuelve al foro, y copia y pega todo el contenido de C:\Combofix.txt en tu próximo mensaje.
▶▶▶ Si, después del reinicio de tu PC por combofix, tienes errores "Clave marcada para eliminación" o problemas de conexión a internet, reinicia nuevamente tu computadora
--
.::. Contribuyente Seguridad .::.
-
-
Es el informe de choque que envío a Tigzy.
¿Y mi informe combofix?
--
.::. Contribuyente Seguridad .::.
-
-
demostrar /ejecutar
escribir: cmd
ok
en la ventana negra copias y pegas:
dir /A/B/S %Homedrive%\Qoobox >> %Homedrive%\Qoobox.txt
luego presionas enter
después cierras esta ventana y pegas el contenido de Qoobox.txt que encontrarás en C:\
--
.::. Contribuyente Seguridad .::.
-
-
Él trabajó ¿sin embargo combofix? :o
--
.::. Contribuidor Seguridad .::.
-
-
Refájalo en modo seguro.
--
.::. Contribuyente de Seguridad .::.
-
Pour démarrer en mode son échec sur Windows XP, suivez ces étapes :
1. Redémarrez votre ordinateur.
2. Pendant le démarrage, appuyez sur la touche F8 plusieurs fois jusqu'à ce que le menu des options de démarrage avancées apparaisse.
3. Dans ce menu, sélectionnez "Mode sans échec" en utilisant les flèches de direction.
4. Appuyez sur Entrée pour confirmer.
Votre ordinateur démarrera alors en mode sans échec. -
Cómo acceder al Modo seguro:
▶ Reinicia tu ordenador
▶ Toca la tecla F8 inmediatamente, (F5 en algunos PC) justo después del "Beep"
▶ Verás aparecer una pantalla con opciones de inicio
▶ Elige la primera opción: Modo Seguro, y confirma con "Enter"
▶ Selecciona tu cuenta habitual, y no Administrador (si es necesario ...)
--
.::. Contribuyente de Seguridad .::.
-
ComboFix 13-04-20.02 - vgame 21/04/2013 19:22:13.1.2 - x86 MINIMAL
Microsoft Windows XP Profesional 5.1.2600.3.1252.33.1036.18.1014.669 [GMT 0:00]
Lanzado desde: c:\documents and settings\vgame\Bureau\ComboFix.exe
.
ADVERTENCIA - ¡LA CONSOLE DE RECUPERACIÓN NO ESTÁ INSTALADA EN ESTA MÁQUINA! !
.
.
(((((((((((((((((((((((((((((((((((( Otras eliminaciones ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\eko\Application Data\facemoods.com
c:\documents and settings\eko\Application Data\PriceGong
c:\documents and settings\eko\Application Data\ShoppingReport2
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\Config.xml
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\db\Aliases.dbs
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\db\Sites.dbs
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\dwld\WhiteList.xip
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\report\aggr_storage.xml
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\report\send_storage.xml
c:\documents and settings\eko\Application Data\ShoppingReport2\cs\res1\WhiteList.dbs
c:\documents and settings\vgame\.tmp
c:\documents and settings\vgame\Application Data\csrs.exe
c:\documents and settings\vgame\Application Data\dns_t.exe
c:\documents and settings\vgame\Application Data\dnsu.exe
c:\documents and settings\vgame\Application Data\Facebook.exe
c:\documents and settings\vgame\Application Data\Facebook.exe.tmp
c:\documents and settings\vgame\Application Data\Skype.exe
c:\documents and settings\vgame\Application Data\Skype.exe.tmp
c:\documents and settings\vgame\Application Data\SQLite3.dll
c:\documents and settings\vgame\Application Data\svchost.exe
c:\documents and settings\vgame\Application Data\svchost.exe.tmp
c:\documents and settings\vgame\Application Data\svchot.exe
c:\documents and settings\vgame\Application Data\svchot.exe.tmp
c:\documents and settings\vgame\Application Data\Trojan.exe
c:\documents and settings\vgame\Application Data\Trojan.exe.tmp
c:\documents and settings\vgame\Local Settings\Temp\Chrome.exe
c:\documents and settings\vgame\Local Settings\Temp\crossfire.exe
c:\documents and settings\vgame\Local Settings\Temp\csrs.exe
c:\documents and settings\vgame\Local Settings\Temp\facebook.exe
c:\documents and settings\vgame\Local Settings\Temp\Google.exe
c:\documents and settings\vgame\Local Settings\Temp\psyco.exe
c:\documents and settings\vgame\Local Settings\Temp\service.exe
c:\documents and settings\vgame\Local Settings\Temp\svchost.exe
c:\documents and settings\vgame\Local Settings\Temp\Sys.exe
c:\documents and settings\vgame\Local Settings\Temp\System.exe
c:\documents and settings\vgame\Local Settings\Temp\Trojan.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\01b768079edee5f654080fe50a78d4b7.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\11b66f66324ac0e6e6a3c81ee698d1b6.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\13e5090cee57967233f9b6a72ec1c5dd.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\1899a32ba3565d2a36a228013f5e9799.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\301b5fcf8ce2fab8868e80b6c1f912fe.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\368fc7f563096ad51849f0d2c298fc08.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\488fe9187d45de3434711bfe795a2b63.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8107c9f97232933cc42c9d6f827202a5.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8515eb34d8f9de5af815466e9715b3e5.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8d0fa66a7f70d4b92f3da7199f7f9e8d.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\8e56537133e75df5421f3565a026e09d.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\94e540adc4cf174ca7240135617a6982.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\b57cb8e241634542876c995d99b59a18.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\ba4c12bee3027d94da5c81db2d196bfd.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\c25bb4b46988f213a04e5145e3c057f0.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\e79d569ba77562f0d4316e586835f0a2.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f5ac7c069b9e6b412c43f7ea38d34f76.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f851f7347b44de50d7b2e29211ae1802.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\f98c2d3f49d939114e6995a40c552630.exe
c:\documents and settings\vgame\taskmgr.exe
c:\documents and settings\vgame\taskmgr.exe.tmp
c:\program files\Complitly
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\install
c:\windows\system32\install\system.exe
c:\windows\system32\SET2D0.tmp
c:\windows\system32\SET347.tmp
c:\windows\system32\SET348.tmp
c:\windows\system32\SET349.tmp
c:\windows\system32\SET34A.tmp
c:\windows\system32\SET34B.tmp
c:\windows\system32\windows
c:\windows\system32\windows.\csrss.exe
c:\windows\system32\Windows\csrss.exe
.
.
((((((((((((((((((((((((((((((((((((((( Controladores/Servicios )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DCSERVICE.EXE
-------\Service_DCService.exe
.
.
((((((((((((((((((((((((((((( Archivos creados del 2013-03-21 al 2013-04-21 ))))))))))))))))))))))))))))))))))))
.
.
2013-04-21 16:23 . 2013-04-21 16:23 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\PCHealth
2013-04-21 12:50 . 2013-04-21 12:50 -------- dc----w- c:\documents and settings\vgame\Application Data\DivX
2013-04-19 12:44 . 2013-04-19 12:46 -------- d-----w- c:\program files\PokerStars.FR
2013-04-19 11:31 . 2013-04-19 11:31 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\Samsung
2013-04-19 11:30 . 2013-04-19 11:32 -------- dc----w- c:\documents and settings\vgame\Application Data\Samsung
2013-04-11 22:19 . 2013-04-11 22:19 -------- d-----w- C:\found.002
2013-04-01 15:28 . 2013-04-01 15:28 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\cache
2013-03-30 19:50 . 2013-04-20 08:50 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\FullTiltPoker
2013-03-30 18:52 . 2013-04-20 22:46 -------- d-----w- c:\program files\Full Tilt Poker
2013-03-29 08:51 . 2013-03-29 08:51 -------- d-----w- C:\found.001
2013-03-27 21:09 . 2013-03-27 21:09 -------- dc----w- C:\Poker
.
.
.
(((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-19 23:23 . 2013-03-19 23:00 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-19 23:23 . 2011-06-18 15:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-19 22:54 . 2013-03-19 22:54 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-19 22:54 . 2011-06-07 11:57 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-19 22:54 . 2013-02-10 20:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-19 22:54 . 2011-12-12 07:59 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-08 08:36 . 2008-04-13 17:33 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2008-04-13 19:07 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 15:56 . 2008-04-13 17:07 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-02 01:57 . 2008-04-13 16:58 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:55 . 2008-04-13 17:33 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 01:55 . 2008-04-13 17:34 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:55 . 2008-04-13 17:33 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 01:08 . 2008-04-13 17:00 385024 ------w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2011-06-06 08:07 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 09:56 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2008-04-13 17:33 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-04-13 00:31 . 2013-04-13 00:31 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Puntos de carga Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* los elementos vacíos & los elementos iniciales legítimos no están listados
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 20992]
"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-09-09 421776]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\
23556fb1360f366337f97c924e76ead3.exe [2013-4-21 44544]
5cd8f17f4086744065eb0992a09e05a2.exe [2013-4-20 44544]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
McAfee Security Scan Plus.lnk - [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\XBMC\\XBMC.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\System.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\Chrome.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\facebook.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56659:TCP"= 56659:TCP:Pando Media Booster
"56659:UDP"= 56659:UDP:Pando Media Booster
"58936:TCP"= 58936:TCP:Pando Media Booster
"58936:UDP"= 58936:UDP:Pando Media Booster
.
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [25/08/2011 00:15 70656]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [24/01/2013 11:32 83168]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [25/08/2011 00:15 101504]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [25/08/2011 00:15 117504]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [05/02/2013 15:48 235216]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [24/01/2013 11:32 181344]
.
--- Otros Servicios/Controladores en memoria ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-11 11:57 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contenido de la carpeta 'Tareas programadas'
.
2013-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19 23:23]
.
2013-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2013-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
.
2013-04-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
.
.
------- Examen adicional -------
.
IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
TCP: Interfaces\{3EFA9696-6DCB-45ED-971E-56C3E64D7652}: NameServer = 8.8.8.8 154.15.199.142
FF - ProfilePath - c:\documents and settings\vgame\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
.
- - - - ORFANOS ELIMINADOS - - - -
.
BHO-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\DVDVideoSoftTB\prxtbDVD0.dll
Toolbar-{9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
Toolbar-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\DVDVideoSoftTB\prxtbDVD0.dll
HKCU-Run-Steam - c:\program files\Steam\Steam.exe
HKCU-Run-8107c9f97232933cc42c9d6f827202a5 - c:\documents and settings\vgame\Application Data\dnsu.exe
HKCU-Run-f98c2d3f49d939114e6995a40c552630 - c:\documents and settings\vgame\Application Data\dns_t.exe
HKCU-Run-368fc7f563096ad51849f0d2c298fc08 - c:\documents and settings\vgame\Application Data\Skype.exe
HKCU-Run-01b768079edee5f654080fe50a78d4b7 - c:\documents and settings\vgame\Application Data\csrs.exe
HKCU-Run-94e540adc4cf174ca7240135617a6982 - c:\documents and settings\vgame\Application Data\Facebook.exe
HKCU-Run-11b66f66324ac0e6e6a3c81ee698d1b6 - c:\documents and settings\vgame\Application Data\svchot.exe
HKCU-Run-c25bb4b46988f213a04e5145e3c057f0 - c:\documents and settings\vgame\taskmgr.exe
HKCU-Run-8515eb34d8f9de5af815466e9715b3e5 - c:\documents and settings\vgame\Application Data\Trojan.exe
HKCU-Run-23556fb1360f366337f97c924e76ead3 - c:\documents and settings\vgame\Application Data\svchost.exe
HKLM-Run-8107c9f97232933cc42c9d6f827202a5 - c:\documents and settings\vgame\Application Data\dnsu.exe
HKLM-Run-f98c2d3f49d939114e6995a40c552630 - c:\documents and settings\vgame\Application Data\dns_t.exe
HKLM-Run-368fc7f563096ad51849f0d2c298fc08 - c:\documents and settings\vgame\Application Data\Skype.exe
HKLM-Run-01b768079edee5f654080fe50a78d4b7 - c:\documents and settings\vgame\Application Data\csrs.exe
HKLM-Run-94e540adc4cf174ca7240135617a6982 - c:\documents and settings\vgame\Application Data\Facebook.exe
HKLM-Run-11b66f66324ac0e6e6a3c81ee698d1b6 - c:\documents and settings\vgame\Application Data\svchot.exe
HKLM-Run-c25bb4b46988f213a04e5145e3c057f0 - c:\documents and settings\vgame\taskmgr.exe
HKLM-Run-8515eb34d8f9de5af815466e9715b3e5 - c:\documents and settings\vgame\Application Data\Trojan.exe
HKLM-Run-23556fb1360f366337f97c924e76ead3 - c:\documents and settings\vgame\Application Data\svchost.exe
AddRemove-1ClickDownload - c:\program files\1ClickDownload\uninst.exe
AddRemove-Casino.com - c:\casino\Casino.com\_SetupCasino_ae7b84.exe
AddRemove-HDM Connection Manager - c:\documents and settings\user\Bureau\Téléchargement\HDM Connection Manager\uninst.exe
AddRemove-HDMI - c:\windows\system32\igxpun.exe
AddRemove-Poker 770 - c:\poker\Poker 770\_SetupCasino_24d4.exe
AddRemove-SABnzbd - c:\program files\SABnzbd\uninstall.exe
AddRemove-SABnzbOpen_is1 - c:\program files\SABnzbOpen\unins000.exe
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
AddRemove-Steam App 440 - c:\program files\Steam\steam.exe
AddRemove-Titan Poker - c:\poker\Titan Poker\_TitanPSetup_654c35.exe
AddRemove-WinMover_is1 - c:\program files\WinMover\unins000.exe
AddRemove-Winner Casino - c:\casino\Winner Casino\_WinnerCSetup_150ba5_fr.exe
AddRemove-winnerpoker - c:\poker\Winner Poker\_WinnerPSetup_c0d06a.exe
AddRemove-{7A78CE94-2688-4C57-A5A3-067B9ECBF2BA}_is1 - c:\program files\Easy Money DEMO\unins000.exe
AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\SAMSUNG\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\SAMSUNG\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\SAMSUNG\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\SAMSUNG\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - detector de rootkit/malware en sigilo por Gmer, http://www.gmer.net
Escaneo de rootkit 2013-04-21 19:35
Windows 5.1.2600 Service Pack 3 NTFS
.
Búsqueda de procesos ocultos ...
.
Búsqueda de elementos de inicio automático ocultos ...
.
Búsqueda de archivos ocultos ...
.
Escaneo finalizado con éxito
Archivos ocultos: 0
.
**************************************************************************
.
--------------------- CLAVES DEL REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs cargadas en los procesos activos ---------------------
.
- - - - - - - > 'explorer.exe'(552)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Otros procesos activos ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\hsswd.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\Logi_MwX.Exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Hora de finalización: 2013-04-21 19:38:19 - La máquina se reinició
ComboFix-quarantined-files.txt 2013-04-21 19:38
.
Antes-CF: 2 256 945 152 bytes libres
Después-CF: 10 474 123 264 bytes libres
.
- - Fin del archivo - - 078E3AB8BCC26C922560C94BD527253E -
__________________________________________________
=>/!\¡El script que sigue ha sido escrito especialmente para este ordenador/!\ <=
=>¡está muy desaconsejado trasladarlo a otro ordenador!<=
----------------------------------------------------------------------------
Siempre con todas las protecciones desactivadas, haz esto:
▶ Abre el Bloc de notas (Menú de inicio --> programas --> accesorios --> Bloc de notas)
▶ Copia/pega en el Bloc de notas lo que está entre las líneas a continuación (sin las líneas):
----------------------------------------------------------
KillAll::
ClearJavaCache::
File::
c:\documents and settings\vgame\Menu Inicio\Programas\Inicio\23556fb1360f366337f97c924e76ead3.exe
c:\documents and settings\vgame\Menu Inicio\Programas\Inicio\5cd8f17f4086744065eb0992a09e05a2.exe
c:\documents and settings\Todos los usuarios\Menu Inicio\Programas\Inicio\McAfee Security Scan Plus.lnk
c:\Documents and Settings\m\Configuración local\Temp\System.exe
c:\Documents and Settings\m\Configuración local\Temp\Chrome.exe
c:\Documents and Settings\m\Configuración local\Temp\facebook.exe
Registry::
[HKEY_LOCAL_MAHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\m\\Configuración local\\Temp\\System.exe"=-
"c:\\Documents and Settings\\m\\Configuración local\\Temp\\Chrome.exe"=-
"c:\\Documents and Settings\\m\\Configuración local\\Temp\\facebook.exe"=-
------------------------------------------------------------------
▶ Guarda este archivo en tu Escritorio (y no en otro lugar) con el nombre CFScript.txt
▶ Cierra el Bloc de notas
▶ Arrastra y suelta este archivo CFScript sobre el archivo combofix así: Ilustración
▶ Espera el tiempo del análisis. El Escritorio desaparecerá varias veces: ¡es normal! No toques nada hasta que el análisis esté terminado.
▶ Una vez finalizado el análisis, se mostrará un informe: publica su contenido.
▶ Si el archivo no se abre, se encuentra aquí => C:\ComboFix.txt
.::. Contribuyente Seguridad .::.
-
ComboFix 13-04-20.02 - vgame 22/04/2013 12:47:50.2.2 - x86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1014.805 [GMT 0:00]
Lancé depuis: c:\documents and settings\vgame\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\vgame\Bureau\CFScript.txt
.
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
FICHIER ::
"c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\McAfee Security Scan Plus.lnk"
"c:\documents and settings\m\Local Settings\Temp\Chrome.exe"
"c:\documents and settings\m\Local Settings\Temp\facebook.exe"
"c:\documents and settings\m\Local Settings\Temp\System.exe"
"c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\23556fb1360f366337f97c924e76ead3.exe"
"c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\5cd8f17f4086744065eb0992a09e05a2.exe"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\vgame\Local Settings\Temp\Trojan.exe
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\5cd8f17f4086744065eb0992a09e05a2.exe
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-03-22 au 2013-04-22 ))))))))))))))))))))))))))))))))))))
.
.
2013-04-21 16:23 . 2013-04-21 16:23 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\PCHealth
2013-04-21 12:50 . 2013-04-21 12:50 -------- dc----w- c:\documents and settings\vgame\Application Data\DivX
2013-04-19 12:44 . 2013-04-19 12:46 -------- d-----w- c:\program files\PokerStars.FR
2013-04-19 11:31 . 2013-04-19 11:31 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\Samsung
2013-04-19 11:30 . 2013-04-19 11:32 -------- dc----w- c:\documents and settings\vgame\Application Data\Samsung
2013-04-11 22:19 . 2013-04-11 22:19 -------- d-----w- C:\found.002
2013-04-01 15:28 . 2013-04-01 15:28 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\cache
2013-03-30 19:50 . 2013-04-20 08:50 -------- dc----w- c:\documents and settings\vgame\Local Settings\Application Data\FullTiltPoker
2013-03-30 18:52 . 2013-04-21 23:51 -------- d-----w- c:\program files\Full Tilt Poker
2013-03-29 08:51 . 2013-03-29 08:51 -------- d-----w- C:\found.001
2013-03-27 21:09 . 2013-03-27 21:09 -------- dc----w- C:\Poker
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-19 23:23 . 2013-03-19 23:00 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-19 23:23 . 2011-06-18 15:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-19 22:54 . 2013-03-19 22:54 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-19 22:54 . 2011-06-07 11:57 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-19 22:54 . 2013-02-10 20:08 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-19 22:54 . 2011-12-12 07:59 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-03-08 08:36 . 2008-04-13 17:33 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2008-04-13 19:07 2030592 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-07 15:56 . 2008-04-13 17:07 2151936 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-02 01:57 . 2008-04-13 16:58 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-03-02 01:55 . 2008-04-13 17:33 916480 ----a-w- c:\windows\system32\wininet.dll
2013-03-02 01:55 . 2008-04-13 17:34 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-03-02 01:55 . 2008-04-13 17:33 43520 ------w- c:\windows\system32\licmgr10.dll
2013-03-02 01:08 . 2008-04-13 17:00 385024 ------w- c:\windows\system32\html.iec
2013-02-27 07:56 . 2011-06-06 08:07 2067456 ----a-w- c:\windows\system32\mstscax.dll
2013-02-12 00:32 . 2008-04-13 09:56 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-01-26 03:55 . 2008-04-13 17:33 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-04-13 00:31 . 2013-04-13 00:31 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-01 1036288]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 20992]
"PlusService"="c:\program files\Yuna Software\Messenger Plus!\PlusService.exe" [2011-05-26 800768]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2012-12-20 310280]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2012-09-09 421776]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
c:\documents and settings\vgame\Menu Démarrer\Programmes\Démarrage\
23556fb1360f366337f97c924e76ead3.exe [2013-4-21 44544]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
McAfee Security Scan Plus.lnk - [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Fichiers communs\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\XBMC\\XBMC.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\System.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\Chrome.exe"=
"c:\\Documents and Settings\\m\\Local Settings\\Temp\\facebook.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56659:TCP"= 56659:TCP:Pando Media Booster
"56659:UDP"= 56659:UDP:Pando Media Booster
"58936:TCP"= 58936:TCP:Pando Media Booster
"58936:UDP"= 58936:UDP:Pando Media Booster
.
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [25/08/2011 00:15 70656]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [24/01/2013 11:32 83168]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [25/08/2011 00:15 101504]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [25/08/2011 00:15 117504]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [05/02/2013 15:48 235216]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [24/01/2013 11:32 181344]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-11 11:57 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contenu du dossier 'Tâches planifiées'
.
2013-04-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19 23:23]
.
2013-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2013-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
.
2013-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-09 16:45]
.
.
------- Examen supplémentaire -------
.
IE: {{90EAE591-7E7E-434a-8E28-ECFD00071806} - c:\program files\PokerStars.FR\PokerStarsUpdate.exe
FF - ProfilePath - c:\documents and settings\vgame\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-22 12:58
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(2144)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\hsswd.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\Logi_MwX.Exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2013-04-22 13:01:06 - La machine a redémarré
ComboFix-quarantined-files.txt 2013-04-22 13:01
ComboFix2.txt 2013-04-21 19:38
.
Avant-CF: 10 346 029 056 octets libres
Après-CF: 10 368 466 944 octets libres
.
- - End Of File - - 75A2F4D47C62132544F884F521A0426E -
Re !
▶ Descarga e instala Malwarebytes' Anti-Malware (MBAM).
▶ Ejécútalo. Acepta la actualización.
▶ Selecciona "Ejecutar un análisis completo"
▶ Haz clic en "Buscar"
▶ El análisis comienza, el escaneo es relativamente largo, es normal.
Al final del análisis, aparecerá un mensaje:
Cita:
El examen se ha completado normalmente. Haz clic en 'Mostrar resultados' para ver todos los objetos encontrados.
▶ Haz clic en Mostrar resultados.
▶ Selecciona todo (o deja marcado) y haz clic en Eliminar selección, MBAM destruirá los archivos y claves de registro y pondrá una copia en cuarentena.
MBAM abrirá el Bloc de notas y copiará el informe de análisis allí: ciérralo.
Si MBAM pide reiniciar el PC: ▶ hazlo.
Al reiniciar, vuelve a abrir MBAM, pestaña "Informe/Registros", copia/pega el que corresponde al análisis realizado.
--
.::. Contribuyente Seguridad .::.
-
Malwarebytes Anti-Malware (Prueba) 1.75.0.1300
www.malwarebytes.org
Versión de la base de datos: v2013.04.21.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
vgame :: USERE [administrador]
Protección: Activado
22/04/2013 15:32:25
mbam-log-2013-04-22 (15-32-25).txt
Tipo de examen: Examen completo (C:\|E:\|)
Opciones de examen activadas: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opciones de examen desactivadas: P2P
Elemento(s) analizado(s): 382209
Tiempo transcurrido: 1 hora(s), 31 minuto(s), 11 segundo(s)
Proceso(s) de memoria detectado(s): 0
(Ningún elemento dañino detectado)
Módulo(s) de memoria detectado(s): 0
(Ningún elemento dañino detectado)
Clave(s) del Registro detectada(s): 3
HKCR\Typelib\{B035BA6B-57CD-4F72-B545-65BE465FCAF6} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
HKCR\Typelib\{D44FD6F0-9746-484E-B5C4-C66688393872} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
HKCR\Interface\{0EB3F101-224A-4B2B-9E5B-DF720857529C} (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
Valor(es) del Registro detectada(s): 0
(Ningún elemento dañino detectado)
Elemento(s) de datos del Registro detectado(s): 0
(Ningún elemento dañino detectado)
Carpeta(s) detectada(s): 6
C:\Documents and Settings\m\Application Data\ShoppingReport2 (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\ShoppingReport2\cs (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\db (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\dwld (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\report (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\ShoppingReport2\cs\res1 (Adware.ShoppingReport2) -> Puesta en cuarentena y eliminada con éxito.
Archivo(s) detectado(s): 128
C:\Documents and Settings\m\Local Settings\Temp\System.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\facebook.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Menu Inicio\Programas\Inicio\301b5fcf8ce2fab8868e80b6c1f912fe.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\taskmgr.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\Facebook.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\svchost.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\svchot.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Application Data\Trojan.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\11b66f66324ac0e6e6a3c81ee698d1b6.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\13e5090cee57967233f9b6a72ec1c5dd.exe.vir (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\1899a32ba3565d2a36a228013f5e9799.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\301b5fcf8ce2fab8868e80b6c1f912fe.exe.vir (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\488fe9187d45de3434711bfe795a2b63.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\5cd8f17f4086744065eb0992a09e05a2.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8515eb34d8f9de5af815466e9715b3e5.exe.vir (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8d0fa66a7f70d4b92f3da7199f7f9e8d.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\8e56537133e75df5421f3565a026e09d.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\94e540adc4cf174ca7240135617a6982.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\b57cb8e241634542876c995d99b59a18.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\ba4c12bee3027d94da5c81db2d196bfd.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\c25bb4b46988f213a04e5145e3c057f0.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\f5ac7c069b9e6b412c43f7ea38d34f76.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\Documents and Settings\vgame\Menu Inicio\Programas\Inicio\f851f7347b44de50d7b2e29211ae1802.exe.vir (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\WINDOWS\system32\install\system.exe.vir (Trojan.Dropper) -> Puesta en cuarentena y eliminada con éxito.
C:\Qoobox\Quarantine\C\WINDOWS\system32\Windows\csrss.exe.vir (Trojan.Agent.DF) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198525.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198526.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198528.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198529.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198530.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198533.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198535.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198536.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198537.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198538.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198540.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0198541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200529.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200531.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200535.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0200543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201530.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201533.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201535.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201536.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201538.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201539.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0201544.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0199543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202536.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202528.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202531.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202532.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202533.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202535.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202537.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202538.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202539.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202540.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202541.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202542.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202543.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202544.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202545.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0202547.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203632.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203635.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203636.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203637.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203639.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203640.exe (Backdoor.Agent.NIPGen) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203641.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203642.exe (Trojan.Ransom) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203644.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203646.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203647.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203648.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203649.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203650.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203652.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203654.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203655.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203657.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203659.exe (Trojan.Dropper) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203660.exe (Trojan.Agent.DF) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0204669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0205669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0206669.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0207774.exe (Backdoor.Agent.TRJ) -> Puesta en cuarentena y eliminada con éxito.
C:\System Volume Information\_restore{F43805F6-FADF-4E9B-8AD1-CDF40A6FBBFE}\RP436\A0203651.exe (Trojan.MSIL) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\System.exe.tmp (Stolen.Data) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\Chrome.exe (Trojan.PWS) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Application Data\logs.dat (Bifrose.Trace) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\vgame\Application Data\logs.dat (Bifrose.Trace) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\IELOGIN.abc (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\UuU.uUu (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local Settings\Temp\XxX.xXx (Malware.Trace) -> Puesta en cuarentena y eliminada con éxito.
C:\Documents and Settings\m\Local -
Change todas tus contraseñas, han sido robadas.
▶ Descarga en esta página: AdwCleaner (de Xplode)
▶ Ejecútalo
haz clic en Eliminación y espera el tiempo de limpieza.
▶ Publica el contenido del informe que encontrarás en tu disco duro c:\ADwcleaner[Sx].txt o su contenido si se abre.
--
.::. Contribuyente Seguridad .::.
-
- 1
- 2
Siguiente