Holaaaaa!!!!! bueno aqui los paso lo que encontre con distintos escaneos:
---------------------------------------------------------
ewido anti-malware - Report de exploración
---------------------------------------------------------
+ Creado en: 02:33:07 a.m., 09/05/2006
+ Report-Checksum: 4075B69B
+ Scan result:
[948] VM_00B00000 -> Trojan.Pakes : Error durante limpieza
C:\WINDOWS\antyvirk.exe -> Heuristic.Win32.Dialer : Limpio con backup
C:\WINDOWS\Downloaded Program Files\910134_nocreditcardneeded_.exe607 -> Trojan.Dialer.kj : Limpio con backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnAR1463.exe -> Downloader.Small.ayl : Limpio con backup
C:\WINDOWS\Downloaded Program Files\gdnMX1463.exe -> Downloader.Small.ayl : Limpio con backup
C:\WINDOWS\Downloaded Program Files\int_ver32b.ocx -> Dialer.Creazione.x : Limpio con backup
C:\WINDOWS\Downloaded Program Files\PrevAdX.dll -> Adware.WinAD : Limpio con backup
C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll -> Adware.PeerNet : Limpio con backup
C:\WINDOWS\system32\70tovmto.ini -> Adware.Sahat : Limpio con backup
C:\WINDOWS\system32\SpoonUninstall.exe -> Dropper.Agent.ano : Limpio con backup
C:\WINDOWS\system32\сhkntfs.exe -> Adware.PurityScan : Limpio con backup
::Fin Report
-----------------------------------------------------------------------------------
Activescan
Incident Status Location
Spyware:Spyware/IESearchToolbar Not disinfected C:\Archivos deprograma\TS Webclient\toolbar.exe
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\Cookies\gus@ccbill[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\Cookies\gus@google.com[1].txt
Dialer:Dialer.GHB Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\delwbi.tmp
Dialer:Dialer.FGG Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\ghajjmnd.exe
Adware:Adware/WinAD Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\ICD1.tmp\PrevAdX.dll
Adware:Adware/WUpd Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\ICD2.tmp\MediaGatewayX.dll
Adware:Adware/WUpd Not disinfected C:\Documents and Settings\Gus\Configuración local\Temp\MediaGateway.exe
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\Gus\Cookies\gus@c.goclick[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Gus\Cookies\gus@google.com[1].txt
Adware:adware/azesearch Not disinfected C:\myvbs.vbs
Adware:Adware/WUpd Not disinfected C:\Program Files\Preview AdService\PrevAdComm.dll
Adware:Adware/WUpd Not disinfected C:\Program Files\Preview AdService\PrevAdKeep.exe
Adware:Adware/EliteBar Not disinfected C:\WINDOWS\blocklist.reg
Dialer:Dialer.CIF Not disinfected C:\WINDOWS\Downloaded Program Files\910134_nocreditcardneeded_.exe607
Dialer:Dialer.NO Not disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnAR1463.exe
Dialer:Dialer.NO Not disinfected C:\WINDOWS\Downloaded Program Files\gdnMX1463.exe
Adware:Adware/WinAD Not disinfected C:\WINDOWS\Downloaded Program Files\PrevAdX.dll
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll
Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\keyboard71.dat
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\mstasks1.exe
Dialer:Dialer.Gen Not disinfected C:\WINDOWS\switchagreement.txt
Adware:adware/keenvalue Not disinfected C:\WINDOWS\system32\drivers\etc\hosts.bho
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\?hkntfs.exe --------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 03:41:30 p.m., on 08/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Gus\Escritorio\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O3 - Toolbar: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\ARCHIV~1\TEXTAL~1\TAForIE.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARCHIV~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [eDonkey2000] "C:\Archivos de programa\eDonkey2000\eDonkey2000.exe" -t
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [StartFoxie] C:\Archivos de programa\Foxie Suite\StartFoxie.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dmuer.exe] C:\WINDOWS\system32\dmuer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RealPlayer] "C:\Archivos de programa\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: PC Alert 4.lnk = C:\Archivos de programa\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Google Search - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Investigador - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {0D62A517-E7C6-4E1F-A577-07D4AC549A48} (Progetto1.int_ver32) -
http://advnt01.com/dialer/int_ver32b.CABO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineS...er.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
http://secure2.comned.com/signuptemplates/...login-devel.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {D35B74F6-E099-4CDD-91E0-9EA7C30059D1} (Main Class) -
http://www.dialer-shop.com/webdial/webdial24106.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{7AE9B376-B4B2-4D6F-846F-1C4DC0AC16B6}: NameServer = 85.255.115.38,85.255.112.152
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6D3DB31-5C39-4D09-BC2B-AA1A98E5C26E}: NameServer = 85.255.115.38,85.255.112.152
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARCHIV~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
-------------------------------------------------------------------------
Espero que les sirva y me puedan ayudar a solucionar esto , desde ya infinitas gracias!!!!!!!!!!
gussss