Hola,, primero si las actualizaciones
Luego pasas un antivirus
luego haces esto :
1.- This procedure terminates the running malware process from memory. You will need the name(s) of the file(s) detected earlier.
Open Windows Task Manager, press
CTRL+SHIFT+ESC, then click the Processes tab.
In the list of running programs*, locate the malware file(s) detected earlier.
Select one of the detected files, then press the End Process button.
Do the same for all detected malware files in the list of running processes.
To check if the malware process has been terminated, close Task Manager, and then open it again.
Close Task Manager.
2.- Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware from executing during startup.
Open Registry Editor. To do this, click Start>Run, type Regedit, then press Enter.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry or entries:
avserve.exe = %Windows%\avserve.exe
(Note: %Windows% refers to the Windows folder, which is usually C:\Windows or C:\WINNT.)
Close Registry Editor.
--------------------------------------------------------------------------------
Y aplica este parche
APPLYING PATCHES
Download the latest patches. Information on the vulnerability exploited by this malware and corresponding patch can be found at the following link:
http://www.microsoft.com/technet/sec.../ms04-011.mspx