Bienvenido: ( Identificarse | Registrarse )      
Foros de Trucos Windows
 1 2
Closed TopicStart new topicStart Poll

Outline · [ Estándar ] · Lineal+

> Log de pc de casa

demiannn
post Jun 27 2005, 02:16 AM
Publicado: #1


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



Hola, ya me has reparado el ordenador de mi trabajo, ahora queda el de mi casa, aqui te dejo el log, el pc aqui hace unas cosas raras, salen ventanas , se abre el mozilla solo saliendo una ip llevandome a una pagina rara (no se la pagina ya que nunca le di tiempo a que cargue bien) y en fins, el log :

Logfile of HijackThis v1.99.1
Scan saved at 3:11:53, on 27/06/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\dvdlv1.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Archivos de programa\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\dsw2091oe.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rsvp.exe
C:\Archivos de programa\BitLord\BitLord.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 9 run
O4 - HKLM\..\Run: [q79k35e] dvdlv1.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Archivos de programa\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [bwqqRRKme] dsw2091oe.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab27571.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab28578.cab
O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\lvjm0911e.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\Rfgistry.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Aver que me dices yes.gif Saludos.


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Jun 27 2005, 05:07 AM
Publicado: #2


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 18.689
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Lo primero que debes hacer es actualizar tu sist. Oper. y el Int. Explr.:
Actualizar el SO o el IE:
http://www.windowsupdate.com
Otra forma:
Actualizar IE:
http://www.vsantivirus.com/descarga-ie6sp1.htm

Luego pasar este programa :
Bajar trial ewido security suite:
http://www.ewido.net/en/download/
actualizarlo acá:
http://www.ewido.net/en/download/updates/
La limpieza la tienes que realizar deshabilitando Restaurar sistema y en modo Seguro( si tienes XP o ME )
Si no sabes cómo hacer algunos de los procedimientos mira esto:
http://www.arwinianos.net/foro/index.php?topic=39

Para despues ejecutar el hijack y poner un nuevo log.
Salu2
Caito


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
demiannn
post Jun 27 2005, 09:33 AM
Publicado: #3


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



El S.O no puedo actualizarlo, ya que mi windows es una copia de seguridad new18.gif , aver si hay otra opcion, el IE ya ta actualizado, dime que hago .

Saludos


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Jun 27 2005, 10:34 AM
Publicado: #4


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 18.689
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Podrías hacer lo segundo que te aconsejé ?
Salu2
Caito
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
demiannn
post Jun 27 2005, 05:23 PM
Publicado: #5


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



Realizado todo menos lo del SO que no hay forma susel.gif aqui el log :

Logfile of HijackThis v1.99.1
Scan saved at 18:21:34, on 27/06/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
C:\Archivos de programa\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 9 run
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Archivos de programa\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [bwqqRRKme] dsw2091oe.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab27571.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab28578.cab
O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\e020lafm1d2a.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\Rfgistry.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Aver que tal va ahora, por cierto que manera de matar malwares y trojanos ranting.gif

Saludos.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Arwing
post Jun 27 2005, 10:50 PM
Publicado: #6


Maestro Perfecto
Group Icon

Grupo: Miembros Vitalicios
Mensajes: 1.738
Registrado: 10-January 04
Miembro nº: 62



Hola,

Desactiva la Opción de Restaurar el Sistema. Una vez que tu sistema esté limpio puedes volver a activarlo.

Habilita a todas las carpetas para que Muestren Carpetas y Archivos Ocultos

Reinicia en Modo Seguro.

Abre HijackThis, asegúrate que sea el único programa abierto en la Barra de Tareas y selecciona las siguientes entradas (las que estén presentes):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - HKCU\..\Run: [bwqqRRKme] dsw2091oe.exe

O16 - DPF: {73F0FD85-BD47-4A95-86D1-DE38860462C1} (PremiumHTML Class) -

O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\e020lafm1d2a.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\Rfgistry.dll (file missing)


Y da click en el botón "Fix Checked"

Borra todos los archivos temporales con Disk Cleaner.

Ahora busca los siguientes archivos y/o carpetas y bórralos (puede que no existan algunos):

dsw2091oe.exe

Reinicia el sistema y pruébalo, dime si ha mejorado. Postea otro Log para ver si tu sistema ha quedado limpio de malware.

Saludos
Arwing
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
demiannn
post Jun 28 2005, 01:26 AM
Publicado: #7


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



Bueno , aver estas entradas no me aparecieron ahora

O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\e020lafm1d2a.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\Rfgistry.dll (file missing)

cosa rara notengoidea.gif

Lo otro lo borre , y aqui te dejo el nuevo log :

Logfile of HijackThis v1.99.1
Scan saved at 2:24:34, on 28/06/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
C:\Archivos de programa\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 9 run
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Archivos de programa\Yahoo!\Messenger\ypager.exe -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab27571.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab28578.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...StatsClient.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\lvn2095oe.dll
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Espero que este limpio , Saludos y Gracias.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Jun 28 2005, 10:28 AM
Publicado: #8


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 18.689
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



La entrada 020 va cambiando aleatoriamente y se hace difícil eliminar la infección.

Baja este programa :
http://www.mwti.net/antivirus/mwav.asp
Ejecútalo y pon el log que te arroje solo de los archivos infectados, no te va a limpiar ( a menos que lo compres ) pero ta va a dar la ruta de esos archivos y así podremos eliminarlos.
Salu2
Caito

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
demiannn
post Jun 29 2005, 09:54 AM
Publicado: #9


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



Bueno ejecute el programa , aqui te dejo el log (es largo) :

File C:\WINDOWS\system32\naprint.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\eajml1111.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\dgrgui.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\mzrating.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\IWSENG.DLL tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\mvrepl40.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\dKdramp.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\sqlogcfg.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\tGpi32.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\system32\cwyptsvc.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\MUPRPES.DLL tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\vcar332.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\pIutoenr.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\SnmpleResize.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\idagx5.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\nmtapi32.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\system32\naprint.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Object "Alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "saap Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mxoaldr Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "SearchEXE Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\IberoDialerHTML.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\EGAUTH.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\LiveService_5.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\IberoDialerHTML.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\EGAUTH.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Archivos comunes\Borland Shared\BDE\BDEADMIN.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Archivos comunes\Borland Shared\BDE\BDEADMIN.CNT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Archivos comunes\Borland Shared\BDE\BDEADMIN.HLP". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Archivos comunes\Borland Shared\BDE\BDEADMIN.TOC". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\SYSTEM\BDEADMIN.CPL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Activision Value". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Archivos de programa\Activision Value\Street Legal". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{10D5F9E1-0360-11D5-8F2A-0080C84E9C39}" refers to invalid object "C:\WINDOWS\System32\clnav.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{12BFC30E-9FFB-4003-8928-4A809A724B16}" refers to invalid object "C:\WINDOWS\system32\myl_hp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{175652E8-8BCC-47C4-B591-0D630F469C19}" refers to invalid object "C:\Archivos de programa\Hotbar\bin\4.5.1.0\contact.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}" refers to invalid object "C:\Archivos de programa\Hotbar\bin\4.5.1.0\HbCoreSrv.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{248DD896-BB45-11CF-9ABC-0080C7E7B78D}" refers to invalid object "C:\DOCUME~1\D3mian\CONFIG~1\Temp\Rar$EX00.451\MSWINSCK.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{248DD897-BB45-11CF-9ABC-0080C7E7B78D}" refers to invalid object "C:\DOCUME~1\D3mian\CONFIG~1\Temp\Rar$EX00.451\MSWINSCK.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2B80DB3B-22AF-49D4-9973-263A7D6581C0}" refers to invalid object "swcmpegvfw.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2DC9D850-144D-11E1-B3C9-10805E499D95}" refers to invalid object "C:\WINDOWS\System32\mplay32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3404D0CE-4DEB-4D51-ADE5-84966DA5D01F}" refers to invalid object "C:\WINDOWS\System32\clnav.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{35BBFE16-D16F-440A-B261-833534102C31}" refers to invalid object "C:\WINDOWS\System32\NetSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3902B4C0-1C41-423E-BEE6-66D72678C2CB}" refers to invalid object "C:\WINDOWS\System32\MJ2Source.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3902B4C6-1C41-423E-BEE6-66D72678C2CB}" refers to invalid object "C:\WINDOWS\System32\MJ2Source.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{47CE0591-C4D5-4B41-BED7-28F59AD76228}" refers to invalid object "C:\WINDOWS\System32\D2VSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{491BCAC0-6FCA-4C41-ADED-F95E47C67923}" refers to invalid object "C:\Documents and Settings\D3mian\Configuración local\Datos de programa\microsoft\internet explorer\V0.15.dat". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Archivos de programa\Yahoo!\Messenger\yhexbmes0521.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4F5AF8E3-AD6E-4536-A0FB-E7D1384A5834}" refers to invalid object "C:\WINDOWS\System32\ElecardFileListSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{53022B5B-F982-4886-B0B9-CF185F40332A}" refers to invalid object "C:\WINDOWS\System32\multiple_mpeg2_source.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{53C5833F-1695-47C2-AEF8-2AC858D36309}" refers to invalid object "C:\WINDOWS\System32\multiple_mpeg2_source.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6AD07386-736A-435D-82D7-BDD632B40352}" refers to invalid object "swcjpegvfw.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9991857A-DC6D-4951-BD98-D7E35F6C906C}" refers to invalid object "C:\WINDOWS\system32\guard.tmp". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9B5929BE-030E-4620-85DF-FBE85520569F}" refers to invalid object "C:\WINDOWS\system32\wbvdmod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B4A7BE85-551D-4594-BDC7-832B09185041}" refers to invalid object "C:\WINDOWS\System32\dtssource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B59810A1-EEFF-11D4-8B80-00D05C00AE53}" refers to invalid object "C:\WINDOWS\System32\bfsource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B63FB74C-5C0C-4DB7-AA89-5F13073C2C3E}" refers to invalid object "C:\PROGRAM FILES\LIVEUPDATE\Remind.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}" refers to invalid object "C:\WINDOWS\system32\ukhisapi.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C7A80962-67CE-11D5-88D9-0050BA13292C}" refers to invalid object "C:\WINDOWS\System32\clnav.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DB76D7F0-97CC-11CF-A096-00805F6CAB83}" refers to invalid object "C:\WINDOWS\System32\bfsource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EB7B504F-0FA9-4247-B4AE-430B83D01546}" refers to invalid object "C:\WINDOWS\system32\SYLAD2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EBF63179-83D8-4EF9-9D2D-7724292537E1}" refers to invalid object "C:\WINDOWS\System32\NetSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F24EB316-6A7F-4591-892F-E0041F0CF129}" refers to invalid object "SwcDvvfw.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F6F91D08-A1A0-4A2A-85BE-51FF62FF2351}" refers to invalid object "C:\WINDOWS\System32\NetSource.ax". Action Taken: No Action Taken.
Entry "HKCR\Hotbar.HbTravelCompareBar.1" refers to invalid object "{FF6B2FD5-093C-4D4F-BB98-5641130A9DE6}". Action Taken: No Action Taken.
Entry "HKCR\IberoDialerHTML.IberoDialerHTML" refers to invalid object "{73F0FD85-BD47-4a95-86D1-DE38860462C1}". Action Taken: No Action Taken.
Entry "HKCR\Ypager.Messenger" refers to invalid object "{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}". Action Taken: No Action Taken.
Entry "HKCR\Ypager.Messenger.1" refers to invalid object "{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}". Action Taken: No Action Taken.
File C:\WINDOWS\itwain.exe infected by "Email-Worm.Win32.Mabutu.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\lvjekmickey32.exe infected by "Email-Worm.Win32.Mabutu.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\vjekmickey32.exe infected by "Email-Worm.Win32.Mabutu.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\System32\dolay.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\System32\en0ql1d51.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\en82l1lo1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\en8ql1l51.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\System32\enjml1111.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\enlql1351.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\g0jo0a13ed.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\hr8605lse.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\hrl8053ue.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\hrlq0535e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\hrnq0555e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\hrpu0579e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\i0jq0a15ed.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\i8nm0i51e8.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\System32\kt4sl7h71.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\ktn8l75u1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\lvj2091oe.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\msts32.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\WINDOWS\System32\mtvcp50.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINDOWS\System32\n4r20e9oeh.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\nqdsbcli.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\p2n8lc5u1f.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\qk-mt331.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINDOWS\System32\t08u0al9edq.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\DOCUME~1\D3mian\CONFIG~1\Temp\se.exe tagged as "not-a-virus:AdWare.WindowEnhancer". Action Taken: No Action Taken.

Saludos y si ese no era el log, dimelo.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Jun 29 2005, 11:04 AM
Publicado: #10


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 18.689
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Baja este programa :
http://www.atribune.org/downloads/l2mfix.exe
Guárdalo en tu escritorio.
Haz doble click en l2mfix.exe
Instálalo siguiendo las instrucciones y al aparecer este archivo : “ l2mfix “haz doble clic en : “l2mfix.bat” y elige la opción “#1” para correr “find log” poniendo 1
Y dándole Enter
Tardará unos minutos y luego se abrirá el Notepad y te dará un log que tendrás que copiar y pegar como respuesta a este post.
Es importante no darle a la opción “#2” o a otra a no ser que te lo diga en mi próximo post.
Salu2
Caito






User is offlineProfile CardPM
Go to the top of the page
+Quote Post
demiannn
post Jun 30 2005, 06:47 PM
Publicado: #11


Miembro
**

Grupo: Members
Mensajes: 40
Registrado: 10-October 04
Miembro nº: 24.527



Aqui el log que me has pedido :

L2MFIX find log 1.03
These are the registry keys present
********************************************************************************
**
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\hrn4055qe.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

********************************************************************************
**
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{DBDFEABB-6920-8437-D8CC-18B9B0136AAA}"=""

********************************************************************************
**
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Hoja de propiedades de archivos multimedia"
"{176d6597-26d3-11d1-b350-080036a75b03}"="Administraci¢n de esc ner ICM"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="P gina de seguridad NTFS"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="P gina de propiedades del archivo de documentos OLE"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensiones de interfaz para uso compartido"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del adaptador de pantalla"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del monitor de pantalla"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n de paneo de pantalla del Panel de control"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="P gina de seguridad DS"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="P gina de compatibilidad"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Extensi¢n de copia de discos"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensiones del shell para objetos de la red de Microsoft Windows"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Administraci¢n de monitor ICM"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Administraci¢n de impresora ICM"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensiones del shell para compresi¢n de archivos"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Extensi¢n del shell de impresora en Web"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Men£ de contexto de cifrado"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Malet¡n"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extensi¢n de icono de HyperTerminal"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fuentes"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Perfil de ICC"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="P gina de seguridad de impresoras"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensiones de interfaz para uso compartido"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n PKO cifrada"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n de firma cifrada"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Conexiones de red"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Conexiones de red"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&C maras y esc neres"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&C maras y esc neres"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="&C maras y esc neres"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&C maras y esc neres"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&C maras y esc neres"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensiones del shell para Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="V¡nculos a datos de Microsoft"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tareas programadas"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barra de tareas y men£ Inicio"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Buscar"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ejecutar..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Correo electr¢nico"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fuentes"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Herramientas administrativas"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barra de herramientas de Microsoft Internet"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Estado de la descarga"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Carpeta Shell aumentada"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Carpeta 2 Shell aumentada"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Banda del explorador de Microsoft"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Banda de b£squeda"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Banda multimedia"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="B£squeda en panel"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="B£squeda Web"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilidad de opciones del rbol de Registro"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Direcci¢n"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Cuadro de la direcci¢n"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Autocompletar de Microsoft"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="Lista autocompleta MRU"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Lista autocompleta MRU personalizada"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Barra de progreso emergente"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analizador de Barra de direcciones"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lista autocompleta de la historia de Microsoft"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Lista autocompleta de la carpeta Shell de Microsoft"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Contenedor de la Lista m£ltiple de Microsoft"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Men£ de sitio de bandas Shell"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barra de escritorio Shell"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Asistencia al usuario"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Configuraci¢n de carpeta global"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Servicio de Historial de las direcciones URL de Microsoft"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="Historial"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Hook de b£squeda de direcciones URL de Microsoft"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Pantalla de bienvenida de IE4 Suite"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Banda de Explorador"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="Carpeta del cach‚ de ActiveX"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Carpeta de suscripciones"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Administrador de aplicaciones de Shell"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Enumerador de aplicaciones instaladas"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extractor de vistas en miniatura de archivos GDI+"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Controlador de la informaci¢n de resumen para vistas en miniatura (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extractor de vistas en miniatura HTML"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Asistente para la publicaci¢n en Web"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Pedido de impresiones v¡a web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objeto de Asistente de publicaci¢n de shell"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Asistente para obtener pasaporte"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="Cuentas de usuario"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Carpeta de archivos sin conexi¢n"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Personas..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Carpetas Web"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.5 Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.5 DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.5 Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.5 Property Sheet Shell Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{B8323370-FF27-11D2-97B6-204C4F4F5020}"="SmartFTP Shell Extension DLL"
"{2B3453E4-49DF-11D3-8229-0080BE509050}"="GMail Drive"
"{2B3453E4-49DF-11D3-8229-0080BE509052}"="GMailFS Property Sheet"
"{2B3453E4-49DF-11D3-8229-0080BE509054}"="GMailFS Drop Handler"
"{2B3453E4-49DF-11D3-8229-0080BE509056}"="GMailFS Context Menu"
"{9B8DE758-78D8-4C3F-B1C4-6E37C2D024ED}"=""
"{4F0E6F69-40F7-4651-B183-89F6E84D365E}"=""
"{5863A958-2EAB-4601-9AA2-75457F38415A}"=""
"{0B906887-147B-45B1-80C2-289BD940C635}"=""
"{9991857A-DC6D-4951-BD98-D7E35F6C906C}"=""
"{A5A20E5B-65DF-40B8-B231-6FB9C6DA6231}"=""
"{D9295E42-4F9F-4D6D-B4AB-0214A8E4A52F}"=""
"{CAE19676-ADD7-4C1D-8C39-1D4DBD9B8023}"=""
"{37C46BC5-3AEA-4C75-9E8D-8FBBFDB49349}"=""
"{D37D4386-8187-4939-87A0-312D3FAA1F6E}"=""
"{0F297484-6056-4BB4-895B-736A8F7F9ECD}"=""
"{98CD65BB-16C3-470B-AF09-C14EDD6ED2BD}"=""
"{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}"=""
"{9B5929BE-030E-4620-85DF-FBE85520569F}"=""
"{EB7B504F-0FA9-4247-B4AE-430B83D01546}"=""
"{27590C61-676C-413A-838F-D1B790DBC994}"=""
"{12BFC30E-9FFB-4003-8928-4A809A724B16}"=""
"{E59AE762-23E9-48A3-8F81-B53FC04586D8}"=""
"{177D4884-033C-480D-9D3D-BB099FDEB457}"=""
"{42C88F78-3D5B-46D2-96E0-6B5EC73214BF}"=""
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Archivo de canal"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Acceso directo al canal"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Objeto de control de canal"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{EDA7118D-498D-4F4C-936B-45099ABC5494}"=""
"{AF96A126-457A-4F83-B9AC-2866B881AF20}"=""
"{A12A2343-268E-4F69-8441-7AECDDEDF318}"=""
"{08A0D4D5-4FE2-45A2-93D8-75AA7EE8E8EE}"=""

********************************************************************************
**
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0B906887-147B-45B1-80C2-289BD940C635}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0B906887-147B-45B1-80C2-289BD940C635}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0B906887-147B-45B1-80C2-289BD940C635}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0B906887-147B-45B1-80C2-289BD940C635}\InprocServer32]
@="C:\\WINDOWS\\system32\\eajml1111.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9991857A-DC6D-4951-BD98-D7E35F6C906C}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9991857A-DC6D-4951-BD98-D7E35F6C906C}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9991857A-DC6D-4951-BD98-D7E35F6C906C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9991857A-DC6D-4951-BD98-D7E35F6C906C}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A5A20E5B-65DF-40B8-B231-6FB9C6DA6231}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5A20E5B-65DF-40B8-B231-6FB9C6DA6231}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5A20E5B-65DF-40B8-B231-6FB9C6DA6231}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A5A20E5B-65DF-40B8-B231-6FB9C6DA6231}\InprocServer32]
@="C:\\WINDOWS\\system32\\dgrgui.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D9295E42-4F9F-4D6D-B4AB-0214A8E4A52F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9295E42-4F9F-4D6D-B4AB-0214A8E4A52F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9295E42-4F9F-4D6D-B4AB-0214A8E4A52F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D9295E42-4F9F-4D6D-B4AB-0214A8E4A52F}\InprocServer32]
@="C:\\WINDOWS\\system32\\mzrating.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{CAE19676-ADD7-4C1D-8C39-1D4DBD9B8023}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CAE19676-ADD7-4C1D-8C39-1D4DBD9B8023}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CAE19676-ADD7-4C1D-8C39-1D4DBD9B8023}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CAE19676-ADD7-4C1D-8C39-1D4DBD9B8023}\InprocServer32]
@="C:\\WINDOWS\\system32\\IWSENG.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{37C46BC5-3AEA-4C75-9E8D-8FBBFDB49349}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{37C46BC5-3AEA-4C75-9E8D-8FBBFDB49349}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{37C46BC5-3AEA-4C75-9E8D-8FBBFDB49349}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{37C46BC5-3AEA-4C75-9E8D-8FBBFDB49349}\InprocServer32]
@="C:\\WINDOWS\\system32\\mvrepl40.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D37D4386-8187-4939-87A0-312D3FAA1F6E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D37D4386-8187-4939-87A0-312D3FAA1F6E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D37D4386-8187-4939-87A0-312D3FAA1F6E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D37D4386-8187-4939-87A0-312D3FAA1F6E}\InprocServer32]
@="C:\\WINDOWS\\system32\\dKdramp.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0F297484-6056-4BB4-895B-736A8F7F9ECD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0F297484-6056-4BB4-895B-736A8F7F9ECD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0F297484-6056-4BB4-895B-736A8F7F9ECD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0F297484-6056-4BB4-895B-736A8F7F9ECD}\InprocServer32]
@="C:\\WINDOWS\\system32\\sqlogcfg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{98CD65BB-16C3-470B-AF09-C14EDD6ED2BD}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{98CD65BB-16C3-470B-AF09-C14EDD6ED2BD}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{98CD65BB-16C3-470B-AF09-C14EDD6ED2BD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{98CD65BB-16C3-470B-AF09-C14EDD6ED2BD}\InprocServer32]
@="C:\\WINDOWS\\system32\\tGpi32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}]
@=""
"IDEx"="AD"

[HKEY_CLASSES_ROOT\CLSID\{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B7A49E5E-E021-4867-A2FD-5EB8F5B2965E}\InprocServer32]
@="C:\\WINDOWS\\system32\\ukhisapi.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9B5929BE-030E-4620-85DF-FBE85520569F}]
@=""
"IDEx"="AD"

[HKEY_CLASSES_ROOT\CLSID\{9B5929BE-030E-4620-85DF-FBE85520569F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9B5929BE-030E-4620-85DF-FBE85520569F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9B5929BE-030E-4620-85DF-FBE85520569F}\InprocServer32]
@="C:\\WINDOWS\\system32\\wbvdmod.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{EB7B504F-0FA9-4247-B4AE-430B83D01546}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EB7B504F-0FA9-4247-B4AE-430B83D01546}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EB7B504F-0FA9-4247-B4AE-430B83D01546}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EB7B504F-0FA9-4247-B4AE-430B83D01546}\InprocServer32]
@="C:\\WINDOWS\\system32\\SYLAD2.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{27590C61-676C-413A-838F-D1B790DBC994}]
@=""
"IDEx"="AD"

[HKEY_CLASSES_ROOT\CLSID\{27590C61-676C-413A-838F-D1B790DBC994}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{27590C61-676C-413A-838F-D1B790DBC994}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{27590C61-676C-413A-838F-D1B790DBC994}\InprocServer32]
@="C:\\WINDOWS\\system32\\cwyptsvc.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{12BFC30E-9FFB-4003-8928-4A809A724B16}]
@=""
"IDEx"="AD"

[HKEY_CLASSES_ROOT\CLSID\{12BFC30E-9FFB-4003-8928-4A809A724B16}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{12BFC30E-9FFB-4003-8928-4A809A724B16}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{12BFC30E-9FFB-4003-8928-4A809A724B16}\InprocServer32]
@="C:\\WINDOWS\\system32\\myl_hp.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E59AE762-23E9-48A3-8F81-B53FC04586D8}]
@=""
"IDEx"="AD"

[HKEY_CLASSES_ROOT\CLSID\{E59AE762-23E9-48A3-8F81-B53FC04586D8}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E59AE762-23E9-48A3-8F81-B53FC04586D8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E59AE762-23E9-48A3-8F81-B53FC04586D8}\InprocServer32]
@="C:\\WINDOWS\\system32\\MUPRPES.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{177D4884-033C-480D-9D3D-BB099FDEB457}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{177D4884-033C-480D-9D3D-BB099FDEB457}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{177D4884-033C-480D-9D3D-BB099FDEB457}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{177D4884-033C-480D-9D3D-BB099FDEB457}\InprocServer32]
@="C:\\WINDOWS\\system32\\vcar332.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{42C88F78-3D5B-46D2-96E0-6B5EC73214BF}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{42C88F78-3D5B-46D2-96E0-6B5EC73214BF}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{42C88F78-3D5B-46D2-96E0-6B5EC73214BF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{42C88F78-3D5B-46D2-96E0-6B5EC73214BF}\InprocServer32]
@="C:\\WINDOWS\\system32\\pIutoenr.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{EDA7118D-498D-4F4C-936B-45099ABC5494}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EDA7118D-498D-4F4C-936B-45099ABC5494}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EDA7118D-498D-4F4C-936B-45099ABC5494}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EDA7118D-498D-4F4C-936B-45099ABC5494}\InprocServer32]
@="C:\\WINDOWS\\system32\\SnmpleResize.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{AF96A126-457A-4F83-B9AC-2866B881AF20}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{AF96A126-457A-4F83-B9AC-2866B881AF20}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{AF96A126-457A-4F83-B9AC-2866B881AF20}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{AF96A126-457A-4F83-B9AC-2866B881AF20}\InprocServer32]
@="C:\\WINDOWS\\system32\\idagx5.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A12A2343-268E-4F69-8441-7AECDDEDF318}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A12A2343-268E-4F69-8441-7AECDDEDF318}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A12A2343-268E-4F69-8441-7AECDDEDF318}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A12A2343-268E-4F69-8441-7AECDDEDF318}\InprocServer32]
@="C:\\WINDOWS\\system32\\nmtapi32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{08A0D4D5-4FE2-45A2-93D8-75AA7EE8E8EE}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{08A0D4D5-4FE2-45A2-93D8-75AA7EE8E8EE}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{08A0D4D5-4FE2-45A2-93D8-75AA7EE8E8EE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{08A0D4D5-4FE2-45A2-93D8-75AA7EE8E8EE}\InprocServer32]
@="C:\\WINDOWS\\system32\\naprint.dll"
"ThreadingModel"="Apartment"

********************************************************************************
**
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
cwyptsvc.dll Tue 21 Jun 2005 12:29:26 ..S.R 234.784 229,28 K
dolay.dll Mon 27 Jun 2005 13:26:52 ..S.R 236.778 231,23 K
en8ql1~1.dll Tue 21 Jun 2005 12:29:30 ..S.R 234.813 229,31 K
enl8l1~1.dll Tue 28 Jun 2005 2:18:46 ..S.R 236.714 231,16 K
hrn405~1.dll Tue 28 Jun 2005 2:13:22 ..S.R 233.732 228,25 K
i0jq0a~1.dll Mon 9 May 2005 20:23:44 ..S.R 223.001 217,77 K
i8nm0i~1.dll Mon 27 Jun 2005 13:24:26 ..S.R 234.445 228,95 K
idagx5.dll Mon 27 Jun 2005 18:14:40 ..S.R 233.246 227,78 K
mtvcp50.dll Thu 16 Jun 2005 22:56:50 ..S.R 234.784 229,28 K
muprpes.dll Sun 26 Jun 2005 5:03:04 ..S.R 234.272 228,78 K
naprint.dll Tue 28 Jun 2005 10:07:42 ..S.R 233.732 228,25 K
nmtapi32.dll Tue 28 Jun 2005 2:18:44 ..S.R 234.752 229,25 K
piutoenr.dll Mon 27 Jun 2005 10:09:28 ..S.R 235.899 230,37 K
snmple~1.dll Mon 27 Jun 2005 13:24:22 ..S.R 234.391 228,89 K
t08u0a~1.dll Thu 16 Jun 2005 23:04:28 ..S.R 235.464 229,95 K
tgpi32.dll Mon 9 May 2005 20:23:42 A.... 225.546 220,26 K
vcar332.dll Sun 26 Jun 2005 20:47:44 ..S.R 234.391 228,89 K

17 items found: 17 files (16 H/S), 0 directories.
Total of file sizes: 3.970.744 bytes 3,79 M
Locate .tmp files:

No matches found.
********************************************************************************
**
Directory Listing of system files:
El volumen de la unidad C no tiene etiqueta.
El n£mero de serie del volumen es: 303A-6FEF

Directorio de C:\WINDOWS\System32

28/06/2005 10:07 233.732 naprint.dll
28/06/2005 10:01 <DIR> dllcache
28/06/2005 02:18 236.714 enl8l13u1.dll
28/06/2005 02:18 234.752 nmtapi32.dll
28/06/2005 02:13 233.732 hrn4055qe.dll
27/06/2005 18:14 233.246 idagx5.dll
27/06/2005 13:26 236.778 dolay.dll
27/06/2005 13:24 234.445 i8nm0i51e8.dll
27/06/2005 13:24 234.391 SnmpleResize.dll
27/06/2005 10:09 235.899 pIutoenr.dll
26/06/2005 20:47 234.391 vcar332.dll
26/06/2005 05:03 234.272 MUPRPES.DLL
21/06/2005 12:29 234.813 en8ql1l51.dll
21/06/2005 12:29 234.784 cwyptsvc.dll
16/06/2005 23:04 235.464 t08u0al9edq.dll
16/06/2005 22:56 234.784 mtvcp50.dll
09/05/2005 20:23 223.001 i0jq0a15ed.dll
24/03/2005 13:06 223.139 lvj2091oe.dll
01/02/2005 17:40 225.546 p2n8lc5u1f.dll
25/01/2005 21:35 223.323 n4r20e9oeh.dll
25/01/2005 21:23 223.939 hrlq0535e.dll
25/01/2005 21:23 224.951 kt4sl7h71.dll
18/01/2005 11:30 223.041 hrnq0555e.dll
17/01/2005 23:56 224.296 g0jo0a13ed.dll
17/01/2005 06:06 226.298 ktn8l75u1.dll
14/01/2005 16:30 224.132 hrpu0579e.dll
14/01/2005 15:36 225.663 enlql1351.dll
14/01/2005 15:19 225.243 enjml1111.dll
14/01/2005 15:05 224.067 hrl8053ue.dll
14/01/2005 15:04 224.733 en0ql1d51.dll
14/01/2005 04:31 225.154 en82l1lo1.dll
13/01/2005 15:07 223.382 hr8605lse.dll
31/12/2004 11:42 5.852 KGyGaAvL.sys
20/12/2004 18:57 56 3D56B6BEFD.sys
03/08/2004 18:15 <DIR> Microsoft
33 archivos 7.118.013 bytes
2 dirs 54.159.114.240 bytes libres

Saludos
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Jun 30 2005, 09:20 PM
Publicado: #12


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 18.689
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Con todas las aplicaciones cerradas ejecuta otra vez el "l2MFix":

Ahora vuelve a ejecutar el l2mfix y haz doble click en l2mfix.bat y selecciona la opción “#2” para que corra el F