Aunque no esté navegando, se abren periódicamente páginas de publicidad en mi pc

- 07/02/2013 08:54:57 - Pregunta nº.: 60.691

Win7 Ultimate Intel core 2 duo 2,4 ghz

Aunque no esté navegando, se abren periódicamente páginas de publicidad en mi pc.
Me dicen que es un programa espía pero por mas revisión y limpieza que he hecho no consigo eliminar el problema.
Tengo instalado Avast y no detecta nada, he instalado varios antimalwares y nada, utilicé el activescan online de panda y nada.
Tengo instalado el navegador firefox y nunca me había sucedido esto.
¿Como hago para solucionarlo?

Coprdialmente, Senatutor.
#1 victorhck (4.712 Posts) - 07/02/2013 12:03:37
Instala Hijacthis y analiza tu equipo. generará un fichero log con lo encontrado. Pégalo aqui para que sea analizado.
- tutorial hijackthis uso basico

“Beethoven era un buen compositor porque utilizaba ideas nuevas en combinación con ideas antiguas. Nadie, ni siquiera Beethoven podría inventar la música desde cero. Es igual con la informática“Richard Stallman


- No olvides leer las normas del foro.
- Visita la sección Tutoriales de esta web donde encontrarás abundante información.
- Todas las consultas a través del foro. NO acepto consultas por privado.
#2 senatutor (8 Posts) - 08/02/2013 07:48:39

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:34:22 a.m., on 08/02/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\ \ Windows\ \ system32\ \ taskhost.exe
C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamgui.exe
C:\ \ Windows\ \ system32\ \ Dwm.exe
C:\ \ Windows\ \ Explorer.EXE
C:\ \ Program Files\ \ tutoriales100_co_5\ \ tutoriales100_co_5.exe
C:\ \ Program Files\ \ Mozilla Firefox\ \ firefox.exe
C:\ \ Program Files\ \ Mozilla Firefox\ \ plugin-container.exe
C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerPlugin_11_5_502_146.exe
C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerPlugin_11_5_502_146.exe
C:\ \ Program Files\ \ Mozilla Firefox\ \ plugin-container.exe
C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerPlugin_11_5_502_149.exe
C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerPlugin_11_5_502_149.exe
C:\ \ Users\ \ senatutor\ \ Downloads\ \ HijackThis.exe

R1 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,SearchAssistant =
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,CustomizeSearch =
R0 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ Acrobat\ \ ActiveX\ \ AcroIEHelperShim.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ Windows Live\ \ WindowsLiveLogin.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ jp2ssv.dll
O2 - BHO: BrowserHelper Class - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\ \ Program Files\ \ My Backup Drive\ \ LivedriveExplorerExtensions.dll
O2 - BHO: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\ \ Program Files\ \ PutLockerDownloader\ \ smarterdownloader.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O4 - HKLM\ \ .\ \ Run: [tutoriales100_co_5] \ "C:\ \ Program Files\ \ tutoriales100_co_5\ \ tutoriales100_co_5.exe\ "
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to DVD Converter - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeyoutubetodvdconverter.htm
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ OFFICE14\ \ MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\ \ progra~2\ \ browse~1\ \ 23796~1.11\ \ {16cdf~1\ \ browse~1.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\ \ Program Files\ \ Common Files\ \ ArcSoft\ \ Connection Service\ \ Bin\ \ ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ ARM\ \ 1.0\ \ armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\ \ Program Files\ \ Common Files\ \ Apple\ \ Mobile Device Support\ \ AppleMobileDeviceService.exe
O23 - Service: BasicSeek Service - Unknown owner - C:\ \ Program Files\ \ BasicSeek\ \ basicseek.exe
O23 - Service: Livedrive VSS Service (LivedriveVSSService) - Unknown owner - C:\ \ Program Files\ \ My Backup Drive\ \ VSSService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\ \ Program Files\ \ Mozilla Maintenance Service\ \ maintenanceservice.exe
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\ \ Program Files\ \ Nitro\ \ Pro 8\ \ NitroPDFDriverService8.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\ \ Windows\ \ system32\ \ NLSSRV32.EXE
O23 - Service: H+H Phantom Drive Management Service (VBurnSecs) - H+H Software GmbH - C:\ \ Program Files\ \ Phantom Drive\ \ VBurnSecs.exe

End of file - 6220 bytes

Coprdialmente, Senatutor.
#3 elbueno55 (2.718 Posts) - 08/02/2013 08:01:53
Hola,si quieres antes de hacer lo que te dice victorhck . Prueba con este programa

spybot s d i instalación y utilizacion basica

responder si se ha solucionado el problema. Gracias
#4 marinalope (25.539 Posts) - 08/02/2013 09:59:50
Cierra todos los programas incluido el navegador,abre el HijackThis,pulsa do a system scan only y marca estas entradas:
Todas las R3
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O4 - HKLM\ \ .\ \ Run: [tutoriales100_co_5] \ "C:\ \ Program Files\ \ tutoriales100_co_5\ \ tutoriales100_co_5.exe\ "
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce

Pulsa fix checked.

Elimina manualmente lo siguiente:
C:\ \ Program Files\ \ tutoriales100_co_5

Pasa Ccleaner,(limpiador y registro),reinicia,pega un nuevo log y comentanós.

Cuando pongas una pregunta,recuerda refrescar la página para ver si has tenido alguna respuesta.Puedes hacerlo pulsando F5.
#5 senatutor (8 Posts) - 10/02/2013 17:15:44
Agradezco la ayuda.
Dejaron de abrirse las ventanas de publicidad pero, ahora se presentan nuevos problemas:
1- Cada vez que abro una página, se abre un cuadro de notificación de Avast EasyPass que nunca he instalado.

2- Se abre un cuadro de dialogo de conexión a internet, aunque mi conexión esté funcionando normal.

3- Se congela frecuentemente el computador por cerca de 25 segundos.
4- Cuando trato de visualizar algunos videos, no puedo hacerlo porque recibo un mensaje acerca de \ "Fallo del plug in de Flash\ ".
Asumo que todo se debe a lo que se ha borrado.
Como puedo corregir?
Este es el último log obtenido de Hijack:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:24:59 p.m., on 08/02/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\ \ Windows\ \ system32\ \ taskhost.exe
C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamgui.exe
C:\ \ Windows\ \ system32\ \ Dwm.exe
C:\ \ Windows\ \ Explorer.EXE
C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe
C:\ \ Windows\ \ system32\ \ taskeng.exe
C:\ \ Users\ \ senatutor\ \ Downloads\ \ HijackThis.exe
R1 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,SearchAssistant =
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,CustomizeSearch =
R0 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ Acrobat\ \ ActiveX\ \ AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ Windows Live\ \ WindowsLiveLogin.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ jp2ssv.dll
O2 - BHO: BrowserHelper Class - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\ \ Program Files\ \ My Backup Drive\ \ LivedriveExplorerExtensions.dll
O2 - BHO: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\ \ Program Files\ \ PutLockerDownloader\ \ smarterdownloader.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O4 - HKLM\ \ .\ \ Run: [SDTray] \ "C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe\ "
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to DVD Converter - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeyoutubetodvdconverter.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O9 - Extra \ 'Tools\ ' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ OFFICE14\ \ MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\ \ progra~2\ \ browse~1\ \ 23796~1.11\ \ {16cdf~1\ \ browse~1.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\ \ Program Files\ \ Common Files\ \ ArcSoft\ \ Connection Service\ \ Bin\ \ ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ ARM\ \ 1.0\ \ armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\ \ Program Files\ \ Common Files\ \ Apple\ \ Mobile Device Support\ \ AppleMobileDeviceService.exe
O23 - Service: BasicSeek Service - Unknown owner - C:\ \ Program Files\ \ BasicSeek\ \ basicseek.exe
O23 - Service: Livedrive VSS Service (LivedriveVSSService) - Unknown owner - C:\ \ Program Files\ \ My Backup Drive\ \ VSSService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\ \ Program Files\ \ Mozilla Maintenance Service\ \ maintenanceservice.exe
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\ \ Program Files\ \ Nitro\ \ Pro 8\ \ NitroPDFDriverService8.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\ \ Windows\ \ system32\ \ NLSSRV32.EXE
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDWSCSvc.exe
O23 - Service: H+H Phantom Drive Management Service (VBurnSecs) - H+H Software GmbH - C:\ \ Program Files\ \ Phantom Drive\ \ VBurnSecs.exe
End of file - 6581 bytes

Coprdialmente, Senatutor.
#6 swissman (39.814 Posts) - 10/02/2013 18:18:53
Eso del roboform, no me fiaria, no lo conozco, pero que un programa ajeno pueda tener mis contraseñas, como que no, te sugiero que lo desinstales y si acaso, uses papel y lapiz para recordar las contraseñas.

sube a www.virustotal.com el archivo C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll y nos cuentas el resultado.

este EldosMountNotificator, ¿lo conoces, sabes qué es? tampoco me gusta y no sé qué es.

selecciona y marca fix a los siguiente:
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)

pulsa fix select y después de reiniciar y responder mis dudas, pega un nuevo log

#7 senatutor (8 Posts) - 12/02/2013 09:05:19
1- Yo no instalé Roboform, se coló de alguna manera pero ya lo borré.
2- Ninguno de los antivirus en Virustotal.com reportan nada raro de CbFsMntNtf3.dll
3- No se que es EldosMountNotificator, ni lo encuentro por parte alguna.

Al iniciar Hijack recibo el siguiente mensaje:
\ "For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this.
If that happens, you need to edit the file yourself. To do this, click start, run and type:
notepad C:\ \ Windows\ \ System32\ \ drivers\ \ etc\ \ hosts
and press Enter. Find the line(s) HijackThis reports and delete then.
Save the file as ´hosts´. (with quotes), and reboot.\ "

Traté de hacerlo pero encuentro la carpeta hosts vacía y como pueden observar en el log adjunto, solo se borraron las líneas R3 iniciales y la linea de la carpeta tutoriales100 que borré manualmente.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:35:10 a.m., on 12/02/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\ \ Windows\ \ system32\ \ taskhost.exe
C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamgui.exe
C:\ \ Windows\ \ system32\ \ Dwm.exe
C:\ \ Windows\ \ Explorer.EXE
C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe
C:\ \ Users\ \ senatutor\ \ Downloads\ \ HijackThis.exe
C:\ \ Windows\ \ system32\ \ NOTEPAD.EXE
C:\ \ Windows\ \ system32\ \ NOTEPAD.EXE

R1 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,SearchAssistant =
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,CustomizeSearch =
R0 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ Acrobat\ \ ActiveX\ \ AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ Windows Live\ \ WindowsLiveLogin.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ jp2ssv.dll
O2 - BHO: BrowserHelper Class - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\ \ Program Files\ \ My Backup Drive\ \ LivedriveExplorerExtensions.dll
O2 - BHO: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\ \ Program Files\ \ PutLockerDownloader\ \ smarterdownloader.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O4 - HKLM\ \ .\ \ Run: [SDTray] \ "C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe\ "
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce
O4 - HKCU\ \ .\ \ Run: [Google Update] \ "C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ Google\ \ Update\ \ GoogleUpdate.exe\ " /c
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to DVD Converter - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeyoutubetodvdconverter.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O9 - Extra \ 'Tools\ ' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ OFFICE14\ \ MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\ \ progra~2\ \ browse~1\ \ 23796~1.11\ \ {16cdf~1\ \ browse~1.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\ \ Program Files\ \ Common Files\ \ ArcSoft\ \ Connection Service\ \ Bin\ \ ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ ARM\ \ 1.0\ \ armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\ \ Program Files\ \ Common Files\ \ Apple\ \ Mobile Device Support\ \ AppleMobileDeviceService.exe
O23 - Service: BasicSeek Service - Unknown owner - C:\ \ Program Files\ \ BasicSeek\ \ basicseek.exe
O23 - Service: Livedrive VSS Service (LivedriveVSSService) - Unknown owner - C:\ \ Program Files\ \ My Backup Drive\ \ VSSService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\ \ Program Files\ \ Mozilla Maintenance Service\ \ maintenanceservice.exe
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\ \ Program Files\ \ Nitro\ \ Pro 8\ \ NitroPDFDriverService8.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\ \ Windows\ \ system32\ \ NLSSRV32.EXE
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDWSCSvc.exe
O23 - Service: H+H Phantom Drive Management Service (VBurnSecs) - H+H Software GmbH - C:\ \ Program Files\ \ Phantom Drive\ \ VBurnSecs.exe

End of file - 6718 bytes

Coprdialmente, Senatutor.
#8 swissman (39.814 Posts) - 12/02/2013 13:30:57
¿sabes qué es My Backup Drive y PutLockerDownloader?
respone a lo que te pregunto antes de hacer lo de abajo

marca y dale fix a :
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O2 - BHO: BrowserHelper Class - {EDF48A39-1442-463F-9F4E-F376A78D034A} -
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce
O8 - Extra context menu item: Free YouTube to DVD Converter - C:\ \ Users\ \ senatutor\ \ AppData\ \ Roaming\ \ DVDVideoSoftIEHelpers\ \ freeyoutubetodvdconvert er.htm
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll

#9 senatutor (8 Posts) - 13/02/2013 07:48:47
My Backup Drive es un programa que vengo usando desde hace mas de un año para mantener copia de respaldo en la nube y PutLockerDownloader es una utilidad freeware que ocasionalmente empleo para descargar y compartir archivos con mis alumnos.

Al dar Fix Checked, Hijack responde con el siguiente mensaje de error:
“An unexpected error has occurred at procedure:
modBackup_MakeBackup(sItem=O22 – SharedTaskScheduler: VirtualStorage Mount Notification –
¬{5FF49FE8-B332-4CB9-B102-FB6951629E55} – C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll)
Error #5 – Llamada a procedimiento o argumento no válidos”

Aquí el log que muestra lo mismo que el anterior:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:44:57 a.m., on 13/02/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\ \ Windows\ \ system32\ \ taskhost.exe
C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamgui.exe
C:\ \ Windows\ \ system32\ \ Dwm.exe
C:\ \ Windows\ \ Explorer.EXE
C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe
C:\ \ Windows\ \ system32\ \ taskeng.exe
C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe
C:\ \ Windows\ \ system32\ \ taskeng.exe
C:\ \ Program Files\ \ FinalMediaPlayer\ \ FMPCheckForUpdates.exe
C:\ \ Users\ \ senatutor\ \ Downloads\ \ HijackThis.exe

R1 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,SearchAssistant =
R0 - HKLM\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Search,CustomizeSearch =
R0 - HKCU\ \ Software\ \ Microsoft\ \ Internet Explorer\ \ Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ Acrobat\ \ ActiveX\ \ AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ Windows Live\ \ WindowsLiveLogin.dll
O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - (no file)
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\ \ Program Files\ \ Java\ \ jre7\ \ bin\ \ jp2ssv.dll
O2 - BHO: BrowserHelper Class - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\ \ Program Files\ \ My Backup Drive\ \ LivedriveExplorerExtensions.dll
O2 - BHO: smartdownloader Class - {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\ \ Program Files\ \ PutLockerDownloader\ \ smarterdownloader.dll
O3 - Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - (no file)
O3 - Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - !{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - (no file)
O3 - Toolbar: avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\ \ Program Files\ \ Siber Systems\ \ AI RoboForm\ \ roboform.dll
O4 - HKLM\ \ .\ \ Run: [SDTray] \ "C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDTray.exe\ "
O4 - HKLM\ \ .\ \ RunOnce: [upt100_co_5.exe] C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ tutoriales100_co_5\ \ upt100_co_5.exe -runonce
O4 - HKCU\ \ .\ \ Run: [Google Update] \ "C:\ \ Users\ \ senatutor\ \ AppData\ \ Local\ \ Google\ \ Update\ \ GoogleUpdate.exe\ " /c
O4 - HKUS\ \ S-1-5-19\ \ .\ \ Run: [Sidebar] %ProgramFiles%\ \ Windows Sidebar\ \ Sidebar.exe /autoRun (User \ 'LOCAL SERVICE\ ')
O4 - HKUS\ \ S-1-5-19\ \ .\ \ RunOnce: [mctadmin] C:\ \ Windows\ \ System32\ \ mctadmin.exe (User \ 'LOCAL SERVICE\ ')
O4 - HKUS\ \ S-1-5-20\ \ .\ \ Run: [Sidebar] %ProgramFiles%\ \ Windows Sidebar\ \ Sidebar.exe /autoRun (User \ 'NETWORK SERVICE\ ')
O4 - HKUS\ \ S-1-5-20\ \ .\ \ RunOnce: [mctadmin] C:\ \ Windows\ \ System32\ \ mctadmin.exe (User \ 'NETWORK SERVICE\ ')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ \ PROGRA~1\ \ MICROS~3\ \ Office14\ \ EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O9 - Extra \ 'Tools\ ' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\ \ program files\ \ common files\ \ microsoft shared\ \ windows live\ \ wlidnsp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\ \ Program Files\ \ Common Files\ \ Microsoft Shared\ \ OFFICE14\ \ MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\ \ progra~2\ \ browse~1\ \ 23796~1.11\ \ {16cdf~1\ \ browse~1.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\ \ Windows\ \ system32\ \ CbFsMntNtf3.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\ \ Program Files\ \ Common Files\ \ ArcSoft\ \ Connection Service\ \ Bin\ \ ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\ \ Program Files\ \ Common Files\ \ Adobe\ \ ARM\ \ 1.0\ \ armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\ \ Windows\ \ system32\ \ Macromed\ \ Flash\ \ FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\ \ Program Files\ \ Common Files\ \ Apple\ \ Mobile Device Support\ \ AppleMobileDeviceService.exe
O23 - Service: BasicSeek Service - Unknown owner - C:\ \ Program Files\ \ BasicSeek\ \ basicseek.exe
O23 - Service: Livedrive VSS Service (LivedriveVSSService) - Unknown owner - C:\ \ Program Files\ \ My Backup Drive\ \ VSSService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\ \ Program Files\ \ Malwarebytes\ ' Anti-Malware\ \ mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\ \ Program Files\ \ Mozilla Maintenance Service\ \ maintenanceservice.exe
O23 - Service: NitroPDFDriverCreatorReadSpool8 (NitroDriverReadSpool8) - Nitro PDF Software - C:\ \ Program Files\ \ Nitro\ \ Pro 8\ \ NitroPDFDriverService8.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\ \ Windows\ \ system32\ \ NLSSRV32.EXE
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\ \ Program Files\ \ Spybot - Search & Destroy 2\ \ SDWSCSvc.exe
O23 - Service: H+H Phantom Drive Management Service (VBurnSecs) - H+H Software GmbH - C:\ \ Program Files\ \ Phantom Drive\ \ VBurnSecs.exe

End of file - 6989 bytes

Coprdialmente, Senatutor.
#10 Mega-tron (24.583 Posts) - 13/02/2013 07:51:42
Hola, ve a windows, buscar escribe msconfig.msc, clikeas sobre el y luego te vas a inicio y desactiva totorales100

esto es una firma:

El sabio no dice lo que sabe y el necio no sabe lo que dice.
#11 Mega-tron (24.583 Posts) - 13/02/2013 07:53:53
Generas el nuevo log para que swissman lo analice, y comentas lo que notas

esto es una firma:

El sabio no dice lo que sabe y el necio no sabe lo que dice.
#12 marinalope (25.539 Posts) - 13/02/2013 11:10:12
Genera en nuevo log haciendo clic derecho sobre HijackThis y eligiendo \ "Ejecutar como admonistrador\ ".

Cuando pongas una pregunta,recuerda refrescar la página para ver si has tenido alguna respuesta.Puedes hacerlo pulsando F5.
