Ver Mensaje Individual
  #12 (permalink)  
Antiguo 03/03/2006, 11:58
Avatar de DARIODD
DARIODD
 
Fecha de Ingreso: febrero-2006
Ubicación: san martin de los andes
Mensajes: 425
Antigüedad: 18 años, 3 meses
Puntos: 0
y lo otro

Look2Me-Destroyer V1.0.7

Scanning for infected files.....
Scan started at 03/03/2006 14:46:02

Infected! C:\WINDOWS\system32\s2pu0c79ef.dll
Infected! C:\WINDOWS\system32\wgaudsdk.dll
Infected! C:\WINDOWS\system32\ijetcplc.dll
Infected! C:\WINDOWS\system32\lv4q09h5e.dll
Infected! C:\WINDOWS\system32\cgmodem.dll
Infected! C:\WINDOWS\system32\WSLogonNtf.dll
Infected! C:\WINDOWS\system32\s2pu0c79ef.dll
Infected! C:\WINDOWS\system32\dymasf.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000003.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000004.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000005.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000006.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000007.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000009.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000010.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000011.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000012.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000045.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000056.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000064.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000075.dll
Infected! C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000081.dll
Infected! C:\WINDOWS\System32\guard.tmp

Attempting to delete infected files...

Attempting to delete: C:\WINDOWS\system32\s2pu0c79ef.dll
C:\WINDOWS\system32\s2pu0c79ef.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\wgaudsdk.dll
C:\WINDOWS\system32\wgaudsdk.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\ijetcplc.dll
C:\WINDOWS\system32\ijetcplc.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\lv4q09h5e.dll
C:\WINDOWS\system32\lv4q09h5e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\cgmodem.dll
C:\WINDOWS\system32\cgmodem.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\WSLogonNtf.dll
C:\WINDOWS\system32\WSLogonNtf.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\s2pu0c79ef.dll
C:\WINDOWS\system32\s2pu0c79ef.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\dymasf.dll
C:\WINDOWS\system32\dymasf.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000003.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000003.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000004.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000004.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000005.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000005.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000006.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000006.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000007.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000007.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000009.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000009.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000010.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000010.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000011.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000011.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000012.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000012.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000045.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000045.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000056.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000056.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000064.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000064.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000075.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000075.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000081.dll
C:\System Volume Information\_restore{2050C50B-1005-4E17-AA74-483352F9BFC3}\RP1\A0000081.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\System32\guard.tmp
C:\WINDOWS\System32\guard.tmp Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{495AB892-0AFD-4856-979A-0CA617CECBC5}"
HKCR\Clsid\{495AB892-0AFD-4856-979A-0CA617CECBC5}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{AD7C5AF9-DCA9-45DB-88DC-141A725EF743}"
HKCR\Clsid\{AD7C5AF9-DCA9-45DB-88DC-141A725EF743}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{FD8F32FA-5642-4F5D-9F4B-7ACFD63F03AA}"
HKCR\Clsid\{FD8F32FA-5642-4F5D-9F4B-7ACFD63F03AA}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{77D47AB0-F5CE-4188-B677-C0B003E9D919}"
HKCR\Clsid\{77D47AB0-F5CE-4188-B677-C0B003E9D919}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{C47942C4-5CB6-47AA-A38E-0D9F9EB3C9F9}"
HKCR\Clsid\{C47942C4-5CB6-47AA-A38E-0D9F9EB3C9F9}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administradores - Succeeded
__________________
"WIIIIIIIIIIIIIIIIIII"