scaravaggio |  |
| 2010-10-12 19:20 - Respuestas: 3 - Tema nº: 2724524
Hola a todos, no puedo conectarme a internet en modo normal, solo en safe mode.
ya he leido otros casos pero sigguo teniendo el mismo problema y he utilizados los siguente programas
Este es mi report hijackthis (en modo normal)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:57:22, on 12/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
I:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
I:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Adobe Photoshop Element 7\Adobe Photoshop Element 7\PhotoshopElementsFileAgent.exe
I:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
I:\Program Files\cFosSpeed\spd.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\New Folder (2)\Nero\Nero8\Nero BackItUp\NBService.exe
I:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\TuneUpUtilitiesService32.exe
I:\Program Files\devolo\dlanaudioextender\VaudioServer.exe
I:\Program Files\Wi2Geo\Magic Scanner\Wi2Geo.MagicScanner.exe
C:\Program Files\TuneUpUtilitiesApp32.exe
I:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\CpuIdle\cpuidle.exe
I:\Program Files\Common Files\Java\Java Update\jusched.exe
I:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Advanced SystemCare 3\Advanced SystemCare 3\AWC.exe
I:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
I:\Documents and Settings\Luca\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
I:\Program Files\devolo\dlanaudioextender\audioselector\audioselectorapp.exe
I:\Program Files\devolo\informer\devinf.exe
I:\Program Files\Winamp Remote\bin\Orb.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: -.com4 Toolbar - {0974848a-b5bc-49f2-9778-307742b4a55d} - I:\Program Files\-.com4\tbsoft.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget2 urlcatch - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - C:\Program Files\FlashGet universal\ComDlls\bhoCATCH.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - I:\Program Files\real\IEeREAD.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - I:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - I:\Program Files\Windows Live\Protección infantil\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - I:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - I:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - I:\Program Files\real\WebHook.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - I:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - I:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - i:\program files\google\googletoolbar1.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - I:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - I:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - I:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - i:\program files\google\googletoolbar1.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - I:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - I:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - I:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: -.com4 Toolbar - {0974848a-b5bc-49f2-9778-307742b4a55d} - I:\Program Files\-.com4\tbsoft.dll
O4 - HKLM\..\Run: [ccApp] I:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE I:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CpuIdle] C:\Program Files\CpuIdle\cpuidle.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "I:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\Advanced SystemCare 3\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [Orb] "I:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "I:\Documents and Settings\Luca\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [devolo AudioSelector] I:\Program Files\devolo\dlanaudioextender\audioselector\audioselectorapp.exe
O4 - HKCU\..\RunOnce: [] I:\Program Files\Internet Explorer\iexplore.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: -
O4 - Global Startup: -
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
O9 - Extra 'Tools' menuitem: GigaSize Toolbar - {18955D47-882E-48fc-B903-A4BDD030E7FD} - (no file)
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - I:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - I:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) -
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E36E7850-363E-41A7-B448-868206759FD7}: NameServer =
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - I:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - I:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - I:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SASWINLO.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - I:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe Photoshop Element 7\Adobe Photoshop Element 7\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - I:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Servicio Bonjour (Bonjour Service) - Apple Inc. - I:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - I:\Program Files\cFosSpeed\spd.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - I:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - I:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - I:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - I:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - I:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\New Folder (2)\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - I:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - I:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - I:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - I:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - I:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - I:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUpUtilitiesService32.exe
O23 - Service: Utilità di pianificazione di LiveUpdate automatico - Symantec Corporation - I:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Virtual Audio Service (VAService) - Unknown owner - I:\Program Files\devolo\dlanaudioextender\VaudioServer.exe
O23 - Service: Wi2Geo Magic Scanner (Wi2GeoMagicScanner) - Wi2Geo - I:\Program Files\Wi2Geo\Magic Scanner\Wi2Geo.MagicScanner.exe
O23 - Service: XoftSpyService - ParetoLogic Inc. - I:\Program Files\Common Files\XoftSpySE\6\xoftspyservice.exe
End of file - 16046 bytes
| |
swissman |  |
Re: No puedo conectarme a internet en modo normal - 2010-10-12 19:28 - Respuesta 2
hola, desinstala todas las toolbar y programas que no sirvan y despues de pasar cclenaer y regcleaner, reincias y pegas un nuevo log, pero usa la version más reciente, la 2.0.4 | |
scaravaggio |  |
Re: No puedo conectarme a internet en modo normal - 2010-10-21 09:37 - Respuesta 3
hola, para tu informacion, todos mis problemas empezaron cuando instale el programa uniblue powersuite 2010, hice limpieza del pc y despues ya no me conectaba a internet.
aui tiene el report del anitvirus
avira antivir personal
report file date: miércoles, 20 de octubre de 2010 23:50
scanning for 1990003 virus strains and unwanted programs.
the program is running as an unrestricted full version.
online services are available:
licensee : avira antivir personal - free antivirus
serial number : 0000149996-adjie-0000001
platform : windows xp
windows version : (service pack 3) [5.1.2600]
boot mode : safe mode with network
username : luca
computer name : luca-be76798cb1
version information:
build.dat : 32097 bytes 4/19/2010 15:07:00
avscan.exe : 433832 bytes 4/1/2010 11:37:40
avscan.dll : 46440 bytes 4/1/2010 11:57:06
luke.dll : 104296 bytes 3/7/2010 17:33:06
lukeres.dll : 12648 bytes 2/10/2010 22:40:50
vbase000.vdf : 19875328 bytes 11/6/2009 08:05:36
vbase001.vdf : 1372672 bytes 11/19/2009 18:27:50
vbase002.vdf : 3143680 bytes 1/20/2010 16:37:44
vbase003.vdf : 996864 bytes 1/26/2010 15:37:44
vbase004.vdf : 1579008 bytes 3/5/2010 10:29:04
vbase005.vdf : 2048 bytes 3/5/2010 10:29:04
vbase006.vdf : 2048 bytes 3/5/2010 10:29:04
vbase007.vdf : 2048 bytes 3/5/2010 10:29:04
vbase008.vdf : 2048 bytes 3/5/2010 10:29:04
vbase009.vdf : 2048 bytes 3/5/2010 10:29:04
vbase010.vdf : 2048 bytes 3/5/2010 10:29:04
vbase011.vdf : 2048 bytes 3/5/2010 10:29:04
vbase012.vdf : 2048 bytes 3/5/2010 10:29:04
vbase013.vdf : 153088 bytes 3/8/2010 14:43:22
vbase014.vdf : 99328 bytes 3/10/2010 14:24:22
vbase015.vdf : 107008 bytes 3/11/2010 16:41:42
vbase016.vdf : 92672 bytes 3/12/2010 08:25:54
vbase017.vdf : 119808 bytes 3/15/2010 08:40:00
vbase018.vdf : 112640 bytes 3/18/2010 12:01:26
vbase019.vdf : 139776 bytes 3/18/2010 09:24:58
vbase020.vdf : 113152 bytes 3/22/2010 06:04:24
vbase021.vdf : 108032 bytes 3/23/2010 08:23:04
vbase022.vdf : 123904 bytes 3/24/2010 16:47:52
vbase023.vdf : 279552 bytes 3/25/2010 18:11:24
vbase024.vdf : 202240 bytes 3/26/2010 16:53:50
vbase025.vdf : 187904 bytes 3/30/2010 12:56:48
vbase026.vdf : 130560 bytes 4/1/2010 04:56:22
vbase027.vdf : 136192 bytes 4/6/2010 08:43:56
vbase028.vdf : 232448 bytes 4/7/2010 08:59:24
vbase029.vdf : 124416 bytes 4/12/2010 11:43:18
vbase030.vdf : 2048 bytes 4/12/2010 11:43:18
vbase031.vdf : 17408 bytes 4/12/2010 11:43:18
engineversion :
aevdf.dll : 106868 bytes 2/13/2010 11:16:22
aes-c-r-i-p-t.dll : 1282425 bytes 4/1/2010 15:05:28
aescn.dll : 127347 bytes 2/25/2010 17:38:42
aesbx.dll : 254323 bytes 3/17/2010 10:09:48
aerdl.dll : 541043 bytes 3/17/2010 10:09:48
aepack.dll : 426358 bytes 3/19/2010 11:34:52
aeoffice.dll : 201083 bytes 3/17/2010 10:09:48
aeheur.dll : 2503031 bytes 3/26/2010 17:43:14
aehelp.dll : 242039 bytes 4/1/2010 15:05:26
aegen.dll : 373108 bytes 4/1/2010 15:05:26
aeemu.dll : 393587 bytes 11/10/2009 08:04:22
aecore.dll : 188790 bytes 4/1/2010 15:05:26
aebb.dll : 53618 bytes 9/10/2009 11:15:06
avwinll.dll : 19304 bytes 1/14/2010 11:03:40
avpref.dll : 44904 bytes 1/14/2010 11:03:36
avrep.dll : 62209 bytes 2/18/2010 15:47:42
avreg.dll : 53096 bytes 4/1/2010 11:35:48
avscplr.dll : 83816 bytes 4/1/2010 11:39:52
avarkt.dll : 227176 bytes 4/1/2010 11:22:14
avevtlog.dll : 203112 bytes 1/26/2010 08:53:32
sqlite3.dll : 355688 bytes 1/28/2010 11:58:00
avsmtp.dll : 63848 bytes 3/16/2010 14:38:58
netnt.dll : 11624 bytes 2/19/2010 13:41:02
rcimage.dll : 2550120 bytes 1/28/2010 12:10:22
rctext.dll : 97128 bytes 4/9/2010 13:14:30
configuration settings for the scan:
jobname..: complete system scan
configuration file..................: i:\program files\avira\antivir desktop\sysscan.avp
logging..: low
primary action......................: interactive
secondary action....................: ignore
scan master boot sector.............: on
scan boot sector....................: on
boot sectors........................: c:, d:, i:,
process scan........................: on
extended process scan...............: on
scan registry.......................: on
search for rootkits.................: on
integrity checking of system files..: off
scan all files......................: all files
scan archives.......................: on
recursion depth.....................: 20
smart extensions....................: on
macro heuristic.....................: on
file heuristic......................: medium
deviating risk categories...........: +appl,+game,+joke,+pck,+pfs,+spr,
start of the scan: miércoles, 20 de octubre de 2010 23:50
starting search for hidden objects.
the driver could not be initialized.
the scan of running processes will be started
scan process 'avscan.exe' - '61' module(s) have been scanned
scan process 'avcenter.exe' - '87' module(s) have been scanned
scan process 'winzip32.exe' - '91' module(s) have been scanned
scan process 'iexplore.exe' - '78' module(s) have been scanned
scan process 'avgnt.exe' - '84' module(s) have been scanned
scan process 'winzip32.exe' - '106' module(s) have been scanned
scan process 'iexplore.exe' - '71' module(s) have been scanned
scan process 'rundll32.exe' - '52' module(s) have been scanned
scan process 'iexplore.exe' - '91' module(s) have been scanned
scan process 'iexplore.exe' - '106' module(s) have been scanned
scan process 'notepad.exe' - '80' module(s) have been scanned
scan process 'ctfmon.exe' - '25' module(s) have been scanned
scan process 'superantispyware.exe' - '118' module(s) have been scanned
scan process 'explorer.exe' - '147' module(s) have been scanned
scan process 'aawtray.exe' - '21' module(s) have been scanned
scan process 'wmiprvse.exe' - '42' module(s) have been scanned
scan process 'unsecapp.exe' - '36' module(s) have been scanned
scan process 'aawservice.exe' - '67' module(s) have been scanned
scan process 'svchost.exe' - '32' module(s) have been scanned
scan process 'svchost.exe' - '102' module(s) have been scanned
scan process 'svchost.exe' - '39' module(s) have been scanned
scan process 'svchost.exe' - '50' module(s) have been scanned
scan process 'lsass.exe' - '49' module(s) have been scanned
scan process 'services.exe' - '27' module(s) have been scanned
scan process 'winlogon.exe' - '82' module(s) have been scanned
scan process 'csrss.exe' - '14' module(s) have been scanned
scan process 'smss.exe' - '2' module(s) have been scanned
starting master boot sector scan:
master boot sector hd0
[info] no virus was found!
master boot sector hd1
[info] no virus was found!
master boot sector hd2
[info] no virus was found!
master boot sector hd3
[info] no virus was found!
master boot sector hd4
[info] no virus was found!
master boot sector hd5
[info] no virus was found!
start scanning boot sectors:
boot sector 'c:\'
[info] no virus was found!
boot sector 'd:\'
[info] no virus was found!
boot sector 'i:\'
[info] no virus was found!
starting to scan executable files (registry).
the registry was scanned ( '2056' files ).
starting the file scan:
begin scan in 'c:\'
[warning] the file could not be opened!
begin scan in 'd:\'
begin scan in 'i:\'
i:\documents and settings\all users\application data\symantec\shared\qbackup\{0e808553-a1e7-45ec-bb73-ac428cac1dd4}\{ae9492da-a7f2-479e-b344-226198a12f80}.qbd
[0] archive type: hidden
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
> fil\\\?\i:\documents and settings\all users\application data\symantec\shared\qbackup\{0e808553-a1e7-45ec-bb73-ac428cac1dd4}\{ae9492da-a7f2-479e-b344-226198a12f80}.qbd
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
i:\documents and settings\all users\application data\symantec\shared\qbackup\{763f4ac3-703f-41ee-9c3d-d7fb5158c07f}\{224dd681-3bd7-4167-b272-72b1abb81abb}.qbd
[0] archive type: hidden
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
> fil\\\?\i:\documents and settings\all users\application data\symantec\shared\qbackup\{763f4ac3-703f-41ee-9c3d-d7fb5158c07f}\{224dd681-3bd7-4167-b272-72b1abb81abb}.qbd
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
beginning disinfection:
i:\documents and settings\all users\application data\symantec\shared\qbackup\{763f4ac3-703f-41ee-9c3d-d7fb5158c07f}\{224dd681-3bd7-4167-b272-72b1abb81abb}.qbd
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
[note] the file was moved to the quarantine directory under the name '4e8b7983.qua'.
i:\documents and settings\all users\application data\symantec\shared\qbackup\{0e808553-a1e7-45ec-bb73-ac428cac1dd4}\{ae9492da-a7f2-479e-b344-226198a12f80}.qbd
[detection] this file has been compressed using unusual runtime compression (pck/telock). please verify the origin of this file.
[note] the file was moved to the quarantine directory under the name '57e95613.qua'.
end of the scan: jueves, 21 de octubre de 2010 08:25
used time: 2:38:31 hour(s)
the scan has been done completely.
37261 scanned directories
907063 files were scanned
2 viruses and/or unwanted programs were found
0 files were classified as suspicious
0 files were deleted
0 viruses and unwanted programs were repaired
2 files were moved to quarantine
0 files were renamed
1 files cannot be scanned
907060 files not concerned
11071 archives were scanned
1 warnings
2 notes
y esto es el hijack report
logfile of trend micro hijackthis v2.0.4
scan saved at 8:55:05, on 21/10/2010
platform: windows xp sp3 (winnt 5.01.2600)
msie: internet explorer v8.00 (8.00.6001.18702)
boot mode: normal
running processes:
i:\program files\common files\symantec shared\ccsvchst.exe
i:\program files\lavasoft\ad-aware\aawservice.exe
i:\program files\avira\antivir desktop\sched.exe
i:\program files\common files\arcsoft\connection service\bin\acservice.exe
c:\program files\adobe photoshop element 7\adobe photoshop element 7\photoshopelementsfileagent.exe
i:\program files\avira\antivir desktop\avguard.exe
i:\program files\symantec\liveupdate\aluschedulersvc.exe
i:\program files\avira\antivir desktop\avshadow.exe
i:\program files\cfosspeed\spd.exe
c:\program files\malwarebytes' anti-malware\mbamservice.exe
c:\program files\new folder (2)\nero\nero8\nero backitup\nbservice.exe
i:\program files\dell support center\bin\sprtsvc.exe
c:\program files\tuneuputilitiesservice32.exe
i:\program files\devolo\dlanaudioextender\vaudioserver.exe
i:\program files\wi2geo\magic scanner\wi2geo.magicscanner.exe
c:\program files\tuneuputilitiesapp32.exe
i:\program files\lavasoft\ad-aware\aawtray.exe
i:\program files\common files\symantec shared\ccsvchst.exe
c:\program files\cpuidle\cpuidle.exe
i:\program files\common files\java\java update\jusched.exe
i:\program files\dell support center\bin\sprtcmd.exe
i:\program files\avira\antivir desktop\avgnt.exe
c:\program files\advanced systemcare 3\advanced systemcare 3\awc.exe
i:\program files\winamp remote\bin\orbtray.exe
c:\program files\spybot - search & destroy\teatimer.exe
i:\documents and settings\luca\local settings\application data\google\update\googleupdate.exe
i:\program files\devolo\dlanaudioextender\audioselector\audioselectorapp.exe
i:\program files\winamp remote\bin\orb.exe
i:\program files\devolo\informer\devinf.exe
i:\program files\symantec\liveupdate\aupdate.exe
i:\program files\symantec\liveupdate\lucomserver_3_4.exe
i:\program files\symantec\liveupdate\lucallbackproxy.exe
i:\documents and settings\luca\my documents\limpieza\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page =
o2 - bho: aplicación auxiliar de vínculos de adobe pdf reader - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - i:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
o2 - bho: acroiehelperstub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - i:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
o2 - bho: windows live onecare family safety browser helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - i:\program files\windows live\protección infantil\fssbho.dll
o2 - bho: spybot-s&d ie protection - {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\sdhelper.dll
o2 - bho: nco 2.0 ie bho - {602adb0e-4aff-4217-8aa1-95dac4dfa408} - i:\program files\common files\symantec shared\coshared\browser\2.6\coieplg.dll
o2 - bho: addtask class - {6a19c29d-ed45-4483-8999-9f939c8161f2} - i:\program files\real\webhook.dll
o2 - bho: symantec intrusion prevention - {6d53ec84-6aae-4787-aeee-f4628f01010c} - i:\progra~1\common~1\symant~1\ids\ipsbho.dll
o2 - bho: windows live sign-in helper - {9030d464-4c02-4abf-8ecc-5164760863c6} - i:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
o2 - bho: google toolbar helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - i:\program files\google\googletoolbar1.dll
o2 - bho: google toolbar notifier bho - {af69de43-7d58-4638-b6fa-ce66b5ad205d} - i:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
o2 - bho: java(tm) plug-in 2 ssv helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - i:\program files\java\jre6\bin\jp2ssv.dll
o2 - bho: jqsiestartdetectorimpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - i:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
o3 - toolbar: &google - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - i:\program files\google\googletoolbar1.dll
o3 - toolbar: (no name) - {db87bfa2-a2e3-451e-8e5a-c89982d87cbf} - (no file)
o3 - toolbar: show norton toolbar - {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - i:\program files\common files\symantec shared\coshared\browser\2.6\coieplg.dll
o4 - hklm\..\run: [ccapp] i:\program files\common files\symantec shared\ccapp.exe
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe i:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nvmediacenter] rundll32.exe i:\windows\system32\nvmctray.dll,nvtaskbarinit
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [cpuidle] c:\program files\cpuidle\cpuidle.exe
o4 - hklm\..\run: [sunjavaupdatesched] "i:\program files\common files\java\java update\jusched.exe"
o4 - hklm\..\run: [dellsupportcenter] "i:\program files\dell support center\bin\sprtcmd.exe" /p dellsupportcenter
o4 - hklm\..\run: [avgnt] "i:\program files\avira\antivir desktop\avgnt.exe" /min
o4 - hkcu\..\run: [advanced systemcare 3] "c:\program files\advanced systemcare 3\advanced systemcare 3\awc.exe" /startup
o4 - hkcu\..\run: [orb] "i:\program files\winamp remote\bin\orbtray.exe" /background
o4 - hkcu\..\run: [spybotsd teatimer] c:\program files\spybot - search & destroy\teatimer.exe
o4 - hkcu\..\run: [ctfmon.exe] i:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [google update] "i:\documents and settings\luca\local settings\application data\google\update\googleupdate.exe" /c
o4 - hkcu\..\run: [devolo audioselector] i:\program files\devolo\dlanaudioextender\audioselector\audioselectorapp.exe
o4 - hkcu\..\run: [superantispyware] c:\program files\new folder (3)\superantispyware.exe
o4 - hkcu\..\runonce: [] i:\program files\internet explorer\iexplore.exe
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] i:\windows\system32\ctfmon.exe (user 'local service')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] i:\windows\system32\ctfmon.exe (user 'network service')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] i:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] i:\windows\system32\ctfmon.exe (user 'default user')
o6 - hkcu\software\policies\microsoft\internet explorer\toolbars\restrictions present
o6 - hklm\software\policies\microsoft\internet explorer\toolbars\restrictions present
o9 - extra button: agregar entrada - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - i:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra 'tools' menuitem: &agregar entrada en windows live writer - {219c3416-8cb2-491a-a3c7-d9fcddc9d600} - i:\program files\windows live\writer\writerbrowserextension.dll
o9 - extra button: send to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - i:\progra~1\microsoft office\office12\onbttnie.dll
o9 - extra 'tools' menuitem: s&end to onenote - {2670000a-7350-4f3c-8081-5663ee0c6c49} - i:\progra~1\microsoft office\office12\onbttnie.dll
o9 - extra button: research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - i:\progra~1\microsoft office\office12\refiebar.dll
o9 - extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - c:\progra~1\spybot - search & destroy\sdhelper.dll
o9 - extra 'tools' menuitem: spybot - search & destroy configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - c:\progra~1\spybot - search & destroy\sdhelper.dll
o9 - extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - i:\windows\network diagnostic\xpnetdiag.exe
o9 - extra 'tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - i:\windows\network diagnostic\xpnetdiag.exe
o16 - dpf: {0cca191d-13a6-4e29-b746-314dee697d83} (facebook photo uploader 5 control) -
o16 - dpf: {2bc66f54-93a8-11d3-beb6-00105aa9b6ae} (symantec antivirus scanner) -
o16 - dpf: {644e432f-49d3-41a1-8dd5-e099162eeec5} (symantec rufsi utility class) -
o16 - dpf: {6a344d34-5231-452a-8a57-d064ac9b7862} (symantec download manager) -
o16 - dpf: {78abdc59-d8e7-44d3-9a76-9a0918c52b4a} (dloader class) -
o16 - dpf: {9191f686-7f0a-441d-8a98-2fe3ac1bd913} (activescan 2.0 installer class) -
o16 - dpf: {cf40acc5-e1bb-4aff-ac72-04c2f616bca7} (get_atlcom class) -
o16 - dpf: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} -
o18 - protocol: groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - i:\program files\microsoft office\office12\groovesystemservices.dll
o18 - protocol: skype4com - {ffc8b962-9b40-4dff-9458-1830c7dd7f5d} - i:\progra~1\common~1\skype\skype4com.dll
o20 - winlogon notify: !saswinlogon - c:\program files\new folder (3)\saswinlo.dll
o22 - sharedtaskscheduler: browseui preloader - {438755c2-a8ba-11d1-b96b-00a0c90312e1} - i:\windows\system32\browseui.dll
o22 - sharedtaskscheduler: component categories cache daemon - {8c7461ef-2b13-11d2-be35-3078302c2030} - i:\windows\system32\browseui.dll
o23 - service: arcsoft connect daemon (acdaemon) - arcsoft inc. - i:\program files\common files\arcsoft\connection service\bin\acservice.exe
o23 - service: adobe active file monitor v7 (adobeactivefilemonitor7.0) - adobe systems incorporated - c:\program files\adobe photoshop element 7\adobe photoshop element 7\photoshopelementsfileagent.exe
o23 - service: avira antivir scheduler (antivirschedulerservice) - avira gmbh - i:\program files\avira\antivir desktop\sched.exe
o23 - service: avira antivir guard (antivirservice) - avira gmbh - i:\program files\avira\antivir desktop\avguard.exe
o23 - service: apple mobile device - apple inc. - i:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
o23 - service: ares chatroom server (areschatserver) - ares development group - c:\program files\ares\chatserver.exe
o23 - service: automatic liveupdate scheduler - symantec corporation - i:\program files\symantec\liveupdate\aluschedulersvc.exe
o23 - service: servicio bonjour (bonjour service) - apple inc. - i:\program files\bonjour\mdnsresponder.exe
o23 - service: symantec event manager (ccevtmgr) - symantec corporation - i:\program files\common files\symantec shared\ccsvchst.exe
o23 - service: symantec settings manager (ccsetmgr) - symantec corporation - i:\program files\common files\symantec shared\ccsvchst.exe
o23 - service: cfosspeed system service (cfosspeeds) - cfos software gmbh - i:\program files\cfosspeed\spd.exe
o23 - service: symantec lic netconnect service (cltnetcnservice) - symantec corporation - i:\program files\common files\symantec shared\ccsvchst.exe
o23 - service: com host (comhost) - symantec corporation - i:\program files\common files\symantec shared\vascanner\comhost.exe
o23 - service: flexnet licensing service - macrovision europe ltd. - i:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe
o23 - service: installdriver table manager (idrivert) - macrovision corporation - i:\program files\common files\installshield\driver\1050\intel 32\idrivert.exe
o23 - service: ipod service - apple inc. - i:\program files\ipod\bin\ipodservice.exe
o23 - service: java quick starter (javaquickstarterservice) - sun microsystems, inc. - i:\program files\java\jre6\bin\jqs.exe
o23 - service: lavasoft Ad-Aware service - lavasoft - i:\program files\lavasoft\ad-aware\aawservice.exe
o23 - service: liveupdate - symantec corporation - i:\program files\symantec\liveupdate\lucomserver_3_4.exe
o23 - service: liveupdate notice - symantec corporation - i:\program files\common files\symantec shared\ccsvchst.exe
o23 - service: mbamservice - malwarebytes corporation - c:\program files\malwarebytes' anti-malware\mbamservice.exe
o23 - service: nero backitup scheduler 3 - nero ag - c:\program files\new folder (2)\nero\nero8\nero backitup\nbservice.exe
o23 - service: nmindexingservice - nero ag - i:\program files\common files\nero\lib\nmindexingservice.exe
o23 - service: nvidia display driver service (nvsvc) - nvidia corporation - i:\windows\system32\nvsvc32.exe
o23 - service: pclepci - pinnacle systems gmbh - i:\windows\system32\drivers\pclepci.sys
o23 - service: plflash deviceiocontrol service - prolific technology inc. - i:\windows\system32\ioctlsvc.exe
o23 - service: supportsoft sprocket service (dellsupportcenter) (sprtsvc_dellsupportcenter) - supportsoft, inc. - i:\program files\dell support center\bin\sprtsvc.exe
o23 - service: symantec core lc - unknown owner - i:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe
o23 - service: symantec remoteassist - symantec, inc. - i:\program files\common files\symantec shared\support controls\ssrc.exe
o23 - service: tuneup utilities service (tuneup.utilitiessvc) - tuneup software - c:\program files\tuneuputilitiesservice32.exe
o23 - service: utilità di pianificazione di liveupdate automatico - symantec corporation - i:\program files\symantec\liveupdate\aluschedulersvc.exe
o23 - service: virtual audio service (vaservice) - unknown owner - i:\program files\devolo\dlanaudioextender\vaudioserver.exe
o23 - service: wi2geo magic scanner (wi2geomagicscanner) - wi2geo - i:\program files\wi2geo\magic scanner\wi2geo.magicscanner.exe
end of file - 14292 bytes | |
swissman |  |
Re: No puedo conectarme a internet en modo normal - 2010-10-22 08:36 - Respuesta 4
hola, desinstala todos los antivirus, toolbars y p2p que tengas, cualquier programa tipu tuneup y antimalware, deja solo lo esencial para que el pc funcione y solo los programas que realmente usas.
luego pasas ccleaner y regcleaner, reincias y desfragmentas, vuelves a reiniciar y pegas un nuevo log. | |