CHEKO_CONK | |
| 2007-12-18 17:14 - Respuestas: 2 - Tema nº: 2488646
Características: Windows Vista, 1GB MEMORIA, CORE DUO2, VELOCIDAD NO LA SE, 80 GB DD.
SE ME OCURRIO PRESTAR MI COMPU A MI ESPOSA Y OTRO TIPO LE MOVIO NO SE QUE HIZO PERO ME DIO UN MENSAJE DE ERROR AL INICIARLA Y WINDOWS SE RESTAURO SOLO, PERO AHORA SE ME CONGELA DEREPENTE Y TENGO QWUE REINICIARLA PARA SEGUIR TRABAJANDO ACABO DE INSTALARA HIJACKTHIS Y ESTO ES LO QUE ME ARROJA ESPERO PUEDAN AYUDARME
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:53:10 a.m., on 18/12/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\\Windows\\System32\\smss.exe
C:\\Windows\\system32\\csrss.exe
C:\\Windows\\system32\\wininit.exe
C:\\Windows\\system32\\csrss.exe
C:\\Windows\\system32\\services.exe
C:\\Windows\\system32\\lsass.exe
C:\\Windows\\system32\\lsm.exe
C:\\Windows\\system32\\winlogon.exe
C:\\Windows\\system32\\svchost.exe
C:\\Program Files\\PC Tools Firewall Plus\\FWService.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\system32\\SLsvc.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\system32\\WLANExt.exe
C:\\Windows\\System32\\spoolsv.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\system32\\Dwm.exe
C:\\Windows\\system32\\taskeng.exe
C:\\Windows\\Explorer.EXE
C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe
C:\\Windows\\system32\\svchost.exe
C:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe
C:\\Windows\\system32\\svchost.exe
C:\\Program Files\\Common Files\\McAfee\\HackerWatch\\HWAPI.exe
C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcsysmon.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\system32\\svchost.exe
C:\\Program Files\\Intel\\Wireless\\Bin\\RegSrvc.exe
C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatch9.exe
C:\\Windows\\system32\\STacSV.exe
C:\\Windows\\system32\\svchost.exe
C:\\Windows\\System32\\svchost.exe
C:\\Windows\\system32\\SearchIndexer.exe
C:\\Windows\\system32\\DRIVERS\\xaudio.exe
C:\\Program Files\\Spybot - Search & Destroy\\SDWinSec.exe
C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxMediaDB9.exe
C:\\Windows\\system32\\taskeng.exe
C:\\Windows\\system32\\wbem\\wmiprvse.exe
C:\\Program Files\\Eset\\nod32krn.exe
C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe
C:\\Windows\\OEM02Mon.exe
C:\\Program Files\\Sigmatel\\C-Major Audio\\WDM\\sttray.exe
C:\\Windows\\System32\\rundll32.exe
C:\\Windows\\System32\\rundll32.exe
C:\\Program Files\\PC Tools Firewall Plus\\FirewallGUI.exe
C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe
C:\\Program Files\\Nero\\PhotoShow 5\\data\\Xtras\\mssysmgr.exe
C:\\Program Files\\Windows Media Player\\wmpnscfg.exe
C:\\Windows\\System32\\rundll32.exe
C:\\Windows\\system32\\wbem\\wmiprvse.exe
C:\\Program Files\\Windows Media Player\\wmpnetwk.exe
C:\\Program Files\\Eset\\nod32kui.exe
C:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn0\\yt.dll
O1 - Hosts: 89.149.243.46 boveda.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.boveda.banamex.com.mx
O1 - Hosts: 89.149.243.46 bancanetempresarial.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.bancanetempresarial.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.banamex.com.mx
O1 - Hosts: 89.149.243.46 banamex.com.mx
O1 - Hosts: 89.149.243.46 www.banamex.com
O1 - Hosts: 89.149.243.46 banamex.com
O1 - Hosts: 89.149.243.46 boveda.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.boveda.banamex.com.mx
O1 - Hosts: 89.149.243.46 bancanetempresarial.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.bancanetempresarial.banamex.com.mx
O1 - Hosts: 89.149.243.46 www.banamex.com.mx
O1 - Hosts: 89.149.243.46 banamex.com.mx
O1 - Hosts: 89.149.243.46 www.banamex.com
O1 - Hosts: 89.149.243.46 banamex.com
O1 - Hosts: 89.149.243.46 www.hacktheworld.comä¾d¤MÝ-œtÙœ!•8•ù¤ÿB™ë2‡‹Iuß/“³y‡êäãóã°‰ˆeKwT4
O1 - Hosts: ÞºOûÎ92𨩀Bž`Ý÷ž+ åreëÞ-¾j¤÷3K
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn0\\yt.dll
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\\Program Files\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelper.dll
O2 - BHO: FGCatchUrl - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\\Program Files\\FlashGet\\jccatch.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\\PROGRA~1\\MEGAUP~1\\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\\Program Files\\Yahoo!\\Common\\yiesrvcmx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\\PROGRA~1\\MICROS~3\\Office12\\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files\\Java\\jre1.6.0_03\\bin\\ssv.dll
O2 - BHO:s-c-r-i-p-tproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\\program files\\mcafee\\virusscan\\s-c-r-i-p-tcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\\Program Files\\BAE\\BAE.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\\Program Files\\FlashGet\\getflash.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\\PROGRA~1\\MEGAUP~1\\MEGAUP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files\\Yahoo!\\Companion\\Installs\\cpn0\\yt.dll
O4 - HKLM\\..\\Run: [SynTPEnh] C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe
O4 - HKLM\\..\\Run: [OEM02Mon.exe] C:\\Windows\\OEM02Mon.exe
O4 - HKLM\\..\\Run: [SigmatelSysTrayApp] C:\\Program Files\\SigmaTel\\C-Major Audio\\WDM\\sttray.exe
O4 - HKLM\\..\\Run: [NvSvc] RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart
O4 - HKLM\\..\\Run: [NvCplDaemon] RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup
O4 - HKLM\\..\\Run: [NvMediaCenter] RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\\..\\Run: [NVHotkey] rundll32.exe C:\\Windows\\system32\\nvHotkey.dll,Start
O4 - HKLM\\..\\Run: [00PCTFW] \"C:\\Program Files\\PC Tools Firewall Plus\\FirewallGUI.exe\" -s
O4 - HKLM\\..\\Run: [GrooveMonitor] \"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\"
O4 - HKLM\\..\\Run: [nod32kui] \"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE
O4 - HKLM\\..\\Run: [AVP] \"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe\"
O4 - HKCU\\..\\Run: [Nero PhotoShow Media Manager] C:\\PROGRA~1\\Nero\\PHOTOS~1\\data\\Xtras\\mssysmgr.exe
O4 - HKCU\\..\\Run: [WMPNSCFG] C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe
O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'SERVICIO LOCAL\')
O4 - HKUS\\S-1-5-19\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User \'SERVICIO LOCAL\')
O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'Servicio de red\')
O8 - Extra context menu item: &Descargar con Fl&ashGet - C:\\Program Files\\FlashGet\\jc_link.htm
O8 - Extra context menu item: &Descargar todo con Flas&hGet - C:\\Program Files\\FlashGet\\jc_all.htm
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\\PROGRA~1\\MICROS~3\\Office12\\EXCEL.EXE/3000
O8 - Extra context menu item: Enviar imagen al dispositivo &Bluetooth... - c:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm
O8 - Extra context menu item: Enviar página al dispositivo &Bluetooth... - c:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.6.0_03\\bin\\ssv.dll
O9 - Extra \'Tools\' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.6.0_03\\bin\\ssv.dll
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnIE.dll
O9 - Extra \'Tools\' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~3\\Office12\\ONBttnIE.dll
O9 - Extra button: Yahoo! Servicios - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\\Program Files\\Yahoo!\\Common\\yiesrvcmx.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~3\\Office12\\REFIEBAR.DLL
O9 - Extra button: Barra de búsqueda de Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\\Program Files\\Common Files\\Microsoft Shared\\Encarta Search Bar\\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm
O9 - Extra \'Tools\' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\\Program Files\\FlashGet\\FlashGet.exe
O9 - Extra \'Tools\' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\\Program Files\\FlashGet\\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\\Users\\Sergio\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\IMVU\\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O9 - Extra \'Tools\' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\\Program Files\\Yahoo!\\Common\\yinsthelper.dll
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\\PROGRA~1\\MICROS~3\\Office12\\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\\Program Files\\Ares\\chatServer.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\\Program Files\\Common Files\\Autodesk Shared\\Service\\AdskScSrv.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\\PROGRA~1\\COMMON~1\\McAfee\\EmProxy\\emproxy.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files\\Common Files\\InstallShield\\Driver\\1050\\Intel 32\\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\\Program Files\\Common Files\\Macromedia Shared\\Service\\Macromedia Licensing.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\\Program Files\\Common Files\\McAfee\\HackerWatch\\HWAPI.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\\PROGRA~1\\COMMON~1\\mcafee\\redirsvc\\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\\PROGRA~1\\McAfee\\VIRUSS~1\\mcsysmon.exe
O23 - Service: NMIndexingService - Nero AG - C:\\Program Files\\Common Files\\Nero\\Lib\\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\\Program Files\\Eset\\nod32krn.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\\Program Files\\PC Tools Firewall Plus\\FWService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\\Program Files\\Intel\\Wireless\\Bin\\RegSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\\Program Files\\Spybot - Search & Destroy\\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\\Windows\\system32\\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\\Program Files\\Common Files\\SureThing Shared\\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\\Windows\\system32\\DRIVERS\\xaudio.exe
End of file - 13348 bytes
Comentarios adicionales: No había instalado ningún programa, ni cambiado nada de hardware en el PC.
-
Comentario del Moderador: Por favor no escribas en mayúsculas es sinónimo de gritar y además no se lee bien.
[Mensaje editado por angel32 con fecha: 18-12-2007 17:16:55]. | |
|