QUOTE(zerokus @ 23.01.2009 12:34)

de momento, no me salta nada, el cliente vendra dentro de unos minutos a recogerlo, no me cierren el pos por si acaso le vuelve a ocurrir, ya os aviso
gracias por todo
Deberías eliminar estos ficheros:
2009-01-23 10:16 . 2009-01-23 10:16 95,744 -r-hs---- c:\windows\system32\nmdfgds1.dll
2009-01-23 10:15 . 2009-01-23 10:15 95,744 --------- c:\windows\system32\nmdfgds0.dll
2
2009-01-22 12:24 . 2009-01-22 12:24 244 --ah----- C:\sqmnoopt19.sqm
2009-01-22 12:24 . 2009-01-22 12:24 232 --ah----- C:\sqmdata19.sqm
2009-01-22 11:46 . 2009-01-23 10:16 107,385 -r-hs---- C:\w98.com
2009-01-22 11:38 . 2009-01-22 11:38 268 --ah----- C:\sqmdata18.sqm
2009-01-22 11:38 . 2009-01-22 11:38 244 --ah----- C:\sqmnoopt18.sqm
2009-01-22 11:22 . 2009-01-22 11:22 268 --ah----- C:\sqmdata17.sqm
2009-01-22 11:22 . 2009-01-22 11:22 244 --ah----- C:\sqmnoopt17.sqm
2009-01-21 12:10 . 2009-01-21 12:10 268 --ah----- C:\sqmdata16.sqm
2009-01-21 12:10 . 2009-01-21 12:10 244 --ah----- C:\sqmnoopt16.sqm
2009-01-21 11:54 . 2009-01-21 11:54 268 --ah----- C:\sqmdata15.sqm
2009-01-21 11:54 . 2009-01-21 11:54 244 --ah----- C:\sqmnoopt15.sqm
2009-01-21 10:50 . 2009-01-21 10:50 268 --ah----- C:\sqmdata14.sqm
2009-01-21 10:50 . 2009-01-21 10:50 244 --ah----- C:\sqmnoopt14.sqm
2009-01-20 22:39 . 2009-01-20 22:39 268 --ah----- C:\sqmdata13.sqm
2009-01-20 22:39 . 2009-01-20 22:39 244 --ah----- C:\sqmnoopt13.sqm
2009-01-20 21:13 . 2009-01-20 21:13 268 --ah----- C:\sqmdata12.sqm
2009-01-20 21:13 . 2009-01-20 21:13 244 --ah----- C:\sqmnoopt12.sqm
2009-01-20 17:57 . 2009-01-20 17:57 268 --ah----- C:\sqmdata11.sqm
2009-01-20 17:57 . 2009-01-20 17:57 244 --ah----- C:\sqmnoopt11.sqm
2009-01-20 17:13 . 2009-01-20 17:13 268 --ah----- C:\sqmdata10.sqm
2009-01-20 17:13 . 2009-01-20 17:13 244 --ah----- C:\sqmnoopt10.sqm
2009-01-20 12:27 . 2009-01-20 12:27 268 --ah----- C:\sqmdata09.sqm
2009-01-20 12:27 . 2009-01-20 12:27 244 --ah----- C:\sqmnoopt09.sqm
2009-01-20 10:35 . 2009-01-20 10:35 268 --ah----- C:\sqmdata08.sqm
2009-01-20 10:35 . 2009-01-20 10:35 244 --ah----- C:\sqmnoopt08.sqm
2009-01-20 10:13 . 2009-01-20 23:07 108,869 -r-hs---- C:\gy.exe
2009-01-20 10:13 . 2009-01-23 10:16 107,882 -r-hs---- c:\windows\system32\olhrwef.exe
2009-01-20 10:09 . 2009-01-20 10:09 268 --ah----- C:\sqmdata07.sqm
2009-01-20 10:09 . 2009-01-20 10:09 244 --ah----- C:\sqmnoopt07.sqm
2009-01-20 09:56 . 2009-01-20 09:56 268 --ah----- C:\sqmdata06.sqm
2009-01-20 09:56 . 2009-01-20 09:56 244 --ah----- C:\sqmnoopt06.sqm
2009-01-19 20:26 . 2009-01-19 20:26 268 --ah----- C:\sqmdata05.sqm
2009-01-19 20:26 . 2009-01-19 20:26 244 --ah----- C:\sqmnoopt05.sqm
2009-01-19 18:21 . 2009-01-19 18:21 268 --ah----- C:\sqmdata04.sqm
2009-01-19 18:21 . 2009-01-19 18:21 244 --ah----- C:\sqmnoopt04.sqm
2009-01-19 18:11 . 2009-01-23 10:10 244 --ah----- C:\sqmnoopt03.sqm
2009-01-19 18:11 . 2009-01-23 10:10 232 --ah----- C:\sqmdata03.sqm
y estas entradas del registro:
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdoosoft]
-r-hs---- 2009-01-23 10:16 107882 c:\windows\system32\olhrwef.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\1gk8ha.bat
\Shell\explore\Command - C:\1gk8ha.bat
\Shell\open\Command - C:\1gk8ha.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\1gk8ha.bat
\Shell\explore\Command - D:\1gk8ha.bat
\Shell\open\Command - D:\1gk8ha.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{259574ba-cb84-11dd-84b7-00196684be20}]
\Shell\AutoRun\command - J:\2u.com
\Shell\explore\Command - J:\2u.com
\Shell\open\Command - J:\2u.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d4050ba-b097-11dd-847b-00196684be20}]
\Shell\AutoRun\command - J:\1gk8ha.bat
\Shell\explore\Command - J:\1gk8ha.bat
\Shell\open\Command - J:\1gk8ha.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cb105d0-a012-11dd-8458-00196684be20}]
\Shell\AutoRun\command - J:\xlk9.com
\Shell\explore\Command - J:\xlk9.com
\Shell\open\Command - J:\xlk9.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{949f3741-e726-11dd-84cc-00196684be20}]
\Shell\AutoRun\command - J:\gy.exe
\Shell\open\Command - J:\gy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5a840f3-a29f-11dd-8461-00196684be20}]
\Shell\AutoRun\command - J:\gy.exe
\Shell\open\Command - J:\gy.exe
Luegos en modo seguro pasas el superantispyware y el kaspersky.