Bienvenido: ( Identificarse | Registrarse )      
Foros de Trucos Windows
 
Closed TopicStart new topicStart Poll

Outline · [ Estándar ] · Lineal+

> Mi log... aver si me ayudais con esto, Gracias por la ayuda

titometal
post Dec 17 2007, 09:56 PM
Publicado: #1


**Fatal exception**
Group Icon

Grupo: Moderadores
Mensajes: 2.953
Registrado: 14-May 06
Desde: Soria (España)
Miembro nº: 168.660



Es muy probable que esté infectado por algún bicho ya que últimamente estoy navegando por sitios de riesgo. Espero que ayuden con mi log, gracias amigos.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:53:34, on 17/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\nod32kui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Folding@Home\winfah.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ADSTechnology module - {831CBAC0-8283-4653-9D81-FEB9F3F6E47C} - C:\Program Files\ADSTechnology\ADSTechnology.dll
O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - Startup: Folding@home 4.00.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 5159 bytes

Saludos yaahooo.gif

PD: Lo siento, muevan el post, me colé new18.gif


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Dec 17 2007, 11:24 PM
Publicado: #2


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 17.509
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Actualiza tu sistema acá :

http://update.microsoft.com/microsoftupdat...ault.aspx?ln=es

(Si por algun motivo no puedes actualizar sigue con los demás pasos)


Borra todas las cookies y el registro con CCleaner:

http://www.ccleaner.com/download/downloadpage.aspx?f=2

Vete a Panel de Control--> Java y elimina todos los archivos temporales. (Si utilizas JAVA)

Pasale el Avg-antispyware. (Actualizalo, y al acabar el Scaneo elije la opcion eliminar, despues guarda el report y lo pegas)

http://www.ewido.net/en/download/

Haz un scan on line acá:
http://www.nod32.com.uy/online-scanner/
Debes usar el Internet Explorer y aceptar los active x
Le pones que elimine lo que te detecte.
Nos copias ese reporte, el del AVG y un nuevo log del hijack
Salu2
Caito



User is offlineProfile CardPM
Go to the top of the page
+Quote Post
titometal
post Dec 18 2007, 03:10 PM
Publicado: #3


**Fatal exception**
Group Icon

Grupo: Moderadores
Mensajes: 2.953
Registrado: 14-May 06
Desde: Soria (España)
Miembro nº: 168.660



El report del AVG:
---------------------------------------------------------
AVG Anti-Spyware - Informe del análisis
---------------------------------------------------------

+ Creado en: 12:50:12 18/12/2007

+ Resultado del análisis:



C:\Windows\System32\1196982842.exe -> Adware.BHO : Limpios.
C:\Windows\System32\dsaoms.dll -> Adware.BHO : Limpios.
C:\Windows\System32\~isdqt.tmp -> Adware.BHO : Limpios.
[2664] C:\Windows\system32\dsaoms.dll -> Adware.BHO : Limpios.
[3088] C:\Windows\system32\dsaoms.dll -> Adware.BHO : Limpios.
[3700] C:\Windows\system32\dsaoms.dll -> Adware.BHO : Limpios.
C:\Windows\System32\wkcajax.dll -> Adware.VB : Limpios.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Limpios.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@banner.casinolasvegas[2].txt -> TrackingCookie.Casinolasvegas : Limpios.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@casinolasvegas[1].txt -> TrackingCookie.Casinolasvegas : Limpios.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@doubleclick[1].txt -> TrackingCookie.Doubleclick : Limpios.
:mozilla.7:C:\Users\titometal\AppData\Roaming\Mozilla\Firefox\Profiles\injxmw2p.default\cookies.txt -> TrackingCookie.Netflame : Limpios.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Limpios.


::Fin del informe

El NOD32 Online no me detecta nada

El log nuevo:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:09:28, on 18/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\nod32kui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Folding@Home\winfah.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ADSTechnology module - {831CBAC0-8283-4653-9D81-FEB9F3F6E47C} - C:\Program Files\ADSTechnology\ADSTechnology.dll
O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - Startup: Folding@home 4.00.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O13 - Gopher Prefix:
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 5429 bytes


Gracias amigo, saludos thumbsup.gif




User is offlineProfile CardPM
Go to the top of the page
+Quote Post
yosoydoug
post Dec 18 2007, 03:40 PM
Publicado: #4


AnTi_MaLwArE
Group Icon

Grupo: Moderadores
Mensajes: 4.394
Registrado: 11-January 07
Desde: Paraguay
Miembro nº: 190.609



Combo Fix
1. Descarga Combofix.exe en el escritorio
2. Haz Doble click en combofix.exe y lo ejecutas, sigues los avisos
3. Al finalizar la ejecuccion produce un log localizado en: (C:\ComboFix.txt).

pegas ese report y un nuevo log

Un saludo
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
titometal
post Dec 18 2007, 06:44 PM
Publicado: #5


**Fatal exception**
Group Icon

Grupo: Moderadores
Mensajes: 2.953
Registrado: 14-May 06
Desde: Soria (España)
Miembro nº: 168.660



Report ComboFix:
ComboFix 07-12-18.1 - titometal 2007-12-18 18:16:01.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.3082.18.930 [GMT 1:00]
Se ejecuta desde: C:\Users\titometal\Desktop\ComboFix.exe
* Creado un nuevo punto de restauración
.

(((((((((((((((((( Archivos creados desde 2007-11-18 - 2007-12-18 )))))))))))))))))))))))))))))))))
.

2007-12-18 12:53 . 2007-12-18 15:06 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2007-12-18 12:25 . 2007-12-18 12:25 <DIR> d-------- C:\Users\titometal\AppData\Roaming\Grisoft
2007-12-18 12:25 . 2007-12-18 12:25 <DIR> d-------- C:\Users\All Users\Grisoft
2007-12-18 12:25 . 2007-12-18 12:25 <DIR> d-------- C:\ProgramData\Grisoft
2007-12-18 12:25 . 2007-05-30 13:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2007-12-18 12:17 . 2007-12-18 12:17 <DIR> d-------- C:\Program Files\CCleaner
2007-12-17 21:53 . 2007-12-17 21:53 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-16 13:55 . 2007-12-16 13:55 <DIR> d--h----- C:\Program Files\FX Uninstall Information
2007-12-13 08:51 . 2007-12-13 08:51 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-13 08:49 . 2007-12-13 08:49 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-13 08:49 . 2007-12-13 08:49 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-13 08:49 . 2007-12-13 08:49 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-13 08:49 . 2007-12-13 08:49 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-13 08:49 . 2007-12-13 08:49 56,320 --a------ C:\Windows\System32\iesetup.dll
2007-12-13 08:49 . 2007-12-13 08:49 26,624 --a------ C:\Windows\System32\ieUnatt.exe
2007-12-13 08:48 . 2007-12-13 08:48 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-13 08:48 . 2007-12-13 08:48 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-13 08:48 . 2007-12-13 08:48 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-04 18:06 . 2007-12-04 18:06 <DIR> d-------- C:\Windows\Sun
2007-12-04 18:03 . 2007-05-22 17:39 61,555 --a------ C:\Windows\System32\jpicpl32.cpl
2007-12-04 18:02 . 2007-12-04 18:03 <DIR> d-------- C:\Program Files\Java
2007-12-04 18:01 . 2007-12-04 18:01 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-04 17:06 . 2007-12-04 17:06 <DIR> d-------- C:\Users\All Users\TechSmith
2007-12-04 17:06 . 2007-12-04 17:06 <DIR> d-------- C:\ProgramData\TechSmith
2007-12-04 17:06 . 2007-12-04 17:06 <DIR> d-------- C:\Program Files\TechSmith
2007-12-04 17:06 . 2007-12-04 17:06 <DIR> d-------- C:\Program Files\Common Files\TechSmith Shared
2007-12-04 17:06 . 2007-08-27 10:53 107,864 --a------ C:\Windows\System32\tsccvid.dll
2007-12-04 16:30 . 2007-12-04 16:30 <DIR> d-------- C:\Windows\System32\Camtasia.Studio.v5.0.Spanish [Intercambiosvirtuales.blogspot.com]
2007-12-04 15:53 . 2007-12-04 15:55 <DIR> d-------- C:\Program Files\Fake Webcam
2007-12-04 15:53 . 2005-08-23 11:35 344,064 --a------ C:\Windows\System32\MSVCR70.DLL
2007-11-28 08:47 . 2007-11-28 08:47 <DIR> d-------- C:\Program Files\Aspyr
2007-11-28 08:47 . 2007-07-19 18:14 3,727,720 --a------ C:\Windows\System32\d3dx9_35.dll
2007-11-28 08:47 . 2007-04-04 18:53 81,768 --a------ C:\Windows\System32\xinput1_3.dll
2007-11-28 08:25 . 2007-11-28 08:25 639,224 --a------ C:\Windows\System32\drivers\sptd.sys
2007-11-28 08:05 . 2007-11-28 08:05 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-11-27 23:53 . 2007-11-28 08:20 <DIR> d-------- C:\Users\titometal\AppData\Roaming\BitTorrent
2007-11-27 23:53 . 2007-11-27 23:53 <DIR> d-------- C:\Program Files\BitTorrent
2007-11-22 22:49 . 2007-11-22 22:49 <DIR> d-------- C:\Program Files\Hyplay
2007-11-22 22:49 . 2007-11-22 22:49 <DIR> d-------- C:\Program Files\Common Files\Hypnotizer
2007-11-19 17:59 . 2007-11-19 17:59 <DIR> d-------- C:\Users\titometal\AppData\Roaming\Media Player Classic
2007-11-19 15:15 . 2007-11-19 15:15 <DIR> d-------- C:\Program Files\Common Files\NSIS
2007-11-19 08:17 . 2007-11-19 08:17 268 --ah----- C:\sqmdata01.sqm
2007-11-19 08:17 . 2007-11-19 08:17 244 --ah----- C:\sqmnoopt01.sqm
2007-11-18 03:01 . 2007-11-18 03:01 1,244,672 --a------ C:\Windows\System32\mcmde.dll

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2038-10-04 21:03 174 --sha-w C:\Program Files\desktop.ini
2038-10-04 21:01 --------- d-----w C:\Program Files\Windows Defender
2038-10-04 21:01 --------- d-----w C:\Program Files\Windows Calendar
2007-12-17 03:01 --------- d-----w C:\Program Files\eMule
2007-12-13 07:51 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-13 07:50 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 07:50 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-13 07:50 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 14:17 --------- d-----w C:\Program Files\Folding@Home
2007-11-27 19:45 --------- d-----w C:\Program Files\Turbo Torrent
2007-11-22 21:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-19 17:00 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-11-15 07:51 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-15 07:51 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-15 07:51 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-15 07:51 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-15 07:51 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-15 07:51 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-15 07:51 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-15 07:51 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-15 07:51 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-15 07:51 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-15 07:51 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-15 07:50 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-15 07:50 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-15 07:50 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-15 07:50 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-15 07:50 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-15 07:50 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-15 07:50 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-15 07:50 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2007-11-15 07:49 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 21:55 --------- d-----w C:\Users\titometal\AppData\Roaming\fretsonfire
2007-11-14 21:53 --------- d-----w C:\Program Files\Frets on Fire
2007-11-09 13:31 --------- d-----w C:\Program Files\Codemasters
2007-11-07 22:48 737,280 ----a-w C:\Windows\iun6002.exe
2007-11-07 22:48 --------- d-----w C:\Program Files\Caratulator
2007-11-02 12:55 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2007-11-02 12:55 --------- d--h--r C:\Users\titometal\AppData\Roaming\SecuROM
2007-11-02 12:42 --------- d-----w C:\Program Files\KONAMI
2007-11-02 04:03 --------- d-----w C:\Program Files\ADSTechnology
2007-11-02 04:03 --------- d-----w C:\Program Files\ActivationManager
2007-10-28 18:42 --------- d-----w C:\ProgramData\QuickTime
2007-10-28 18:42 --------- d-----w C:\Program Files\QuickTime
2007-10-25 19:24 --------- d-----w C:\Program Files\MIKSOFT
2007-10-25 19:22 --------- d-----w C:\Program Files\Acala 3GP Movies Free
2007-10-25 19:17 --------- d-----w C:\Program Files\3GP Player
2007-10-21 19:46 --------- d-----w C:\Program Files\Paragon Software
2007-10-21 19:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-21 13:41 --------- d-----w C:\Program Files\Analog Devices
2007-10-21 13:40 --------- d-----w C:\Users\titometal\AppData\Roaming\InstallShield
2007-10-21 11:51 --------- d-----w C:\Program Files\RegSeeker
2007-10-21 11:26 --------- d-----w C:\Users\titometal\AppData\Roaming\AdobeUM
2007-10-11 06:50 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-11 06:50 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-11 06:50 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-11 06:50 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-11 06:49 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-11 06:49 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-10-11 06:48 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-06 02:54 229,888 ----a-w C:\Windows\System32\msshsq.dll
2007-10-04 21:00 4,096 ----a-w C:\Windows\System32\25492.sys
2007-10-04 20:56 8,192 ----a-w C:\Windows\System32\riched32.dll
2007-10-04 20:56 77,824 ----a-w C:\Windows\System32\rascfg.dll
2007-10-04 20:56 694,784 ----a-w C:\Windows\System32\localspl.dll
2007-10-04 20:56 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2007-10-04 20:56 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2007-10-04 20:56 33,280 ----a-w C:\Windows\System32\traffic.dll
2007-10-04 20:56 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2007-10-04 20:56 286,208 ----a-w C:\Windows\System32\ipnathlp.dll
2007-10-04 20:56 22,016 ----a-w C:\Windows\System32\rasser.dll
2007-10-04 20:56 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-10-04 20:56 13,824 ----a-w C:\Windows\System32\wshqos.dll
2007-10-04 20:56 13,824 ----a-w C:\Windows\System32\icsunattend.exe
2007-10-04 20:55 87,040 ----a-w C:\Windows\System32\msoert2.dll
2007-10-04 20:55 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2007-10-04 20:55 36,864 ----a-w C:\Windows\System32\cdd.dll
2007-10-04 20:55 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2007-10-04 20:55 134,656 ----a-w C:\Windows\System32\dps.dll
2007-10-04 20:54 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2007-10-04 20:54 376,320 ----a-w C:\Windows\System32\winsrv.dll
2007-10-04 20:52 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2007-10-04 20:52 61,952 ----a-w C:\Windows\System32\cmifw.dll
2007-10-04 20:52 414,208 ----a-w C:\Windows\System32\msscp.dll
2007-10-04 20:52 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2007-10-04 20:52 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2007-10-04 20:52 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2007-10-04 20:52 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2007-10-04 20:51 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2007-10-04 20:51 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2007-10-04 20:51 25,600 ----a-w C:\Windows\System32\LangCleanupSysprepAction.dll
2007-10-04 20:51 23,552 ----a-w C:\Windows\System32\lpremove.exe
2007-10-04 20:51 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2007-10-04 20:51 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2007-10-04 20:51 166,912 ----a-w C:\Windows\System32\lpksetup.exe
2007-10-04 20:51 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2007-10-04 20:51 10,240 ----a-w C:\Windows\System32\MUILanguageCleanup.dll
2007-10-04 20:51 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2007-10-04 20:50 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2007-10-04 20:50 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
.

((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{831CBAC0-8283-4653-9D81-FEB9F3F6E47C}]
2007-10-25 13:49 118784 --a------ C:\Program Files\ADSTechnology\ADSTechnology.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86A44EF7-78FC-4e18-A564-B18F806F7F56}]
2007-10-25 13:48 233472 --a------ C:\Program Files\ActivationManager\ActivationManager.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DVO]
@={0C50F454-9710-4949-A68E-3AF0738CC121}

[HKEY_CLASSES_ROOT\CLSID\{0C50F454-9710-4949-A68E-3AF0738CC121}]
2001-01-01 15:32 94208 --------- C:\Windows\system32\dsaoms.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:33]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 15:14]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-10-04 21:53]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-10-04 21:47]
"NvSvc"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"NvCplDaemon"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-19 04:34]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-28 19:42]

C:\Users\titometal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Folding@home 4.00.lnk - C:\Program Files\Folding@Home\winfah.exe [2007-10-13 02:39:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

R0 hotcore3;hotcore3;C:\Windows\system32\drivers\hotcore3.sys [2007-03-19 17:05]
R0 nvstor32;nvstor32;C:\Windows\system32\DRIVERS\nvstor32.sys [2007-07-02 23:37]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\Windows\system32\drivers\sfsync03.sys [2006-07-11 08:30]
R2 25492;25492;C:\Windows\system32\25492.sys [2007-10-04 22:00]
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-11 21:28]
S0 OemBiosDevice;Royalty OEM BIOS Extension;C:\Windows\system32\DRIVERS\royal.sys [2007-03-02 07:19]

*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-18 18:40:39
Windows 6.0.6000 NTFS

escaneando procesos ocultos ...

escaneando entradas ocultas de autostart ...

escaneando archivos ocultos ...

el escaneo se completo con exito
archivos ocultos: 0

**************************************************************************
.
Tiempo completado: 2007-12-18 18:41:18
.
2007-12-13 07:52:16 --- E O F ---

Log nuevo:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:44:26, on 18/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\nod32kui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Folding@Home\winfah.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ADSTechnology module - {831CBAC0-8283-4653-9D81-FEB9F3F6E47C} - C:\Program Files\ADSTechnology\ADSTechnology.dll
O2 - BHO: ActivationManager module - {86A44EF7-78FC-4e18-A564-B18F806F7F56} - C:\Program Files\ActivationManager\ActivationManager.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - Startup: Folding@home 4.00.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll
O13 - Gopher Prefix:
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 4969 bytes

Saludos thumbsup.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Dec 18 2007, 10:58 PM
Publicado: #6


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 17.509
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Elimina esta :
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
y comenta si tienes algun problema
salu2
Caito
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
titometal
post Dec 18 2007, 11:12 PM
Publicado: #7


**Fatal exception**
Group Icon

Grupo: Moderadores
Mensajes: 2.953
Registrado: 14-May 06
Desde: Soria (España)
Miembro nº: 168.660



Eliminado... bueno antes me saltaba a menudo una ventanita con caractéres asiáticos... de momento parece que no ha vuelto a salir... muchas gracias por todo bye1.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Caito
post Dec 18 2007, 11:13 PM
Publicado: #8


No Spiware
Group Icon

Grupo: Supervisor Global
Mensajes: 17.509
Registrado: 15-August 04
Desde: Argentina
Miembro nº: 13.043



Nos alegra que lo hayas arreglado smile.gif
Damos x solucionado este tema
Salu2
Caito
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

 
Closed TopicTopic OptionsStart new topic

Collapse

> Topicos similares

Es verdad esto? fabio_mar 90 3 Oct 9 2008, 11:31 AM
By: rioj
Mm... como enchufo esto ? jajajaja jask 70 2 Oct 4 2008, 07:23 PM
By: jask
donde consigo esto solosanta 153 9 Oct 2 2008, 12:01 PM
By: patricioirrazabal
Lean esto k mendaron al E-mail Torresltp 167 9 Sep 10 2008, 09:49 PM
By: Torresltp
no se como empesar esto aventurero1407 67 1 Aug 31 2008, 09:57 PM
By: Caito