Ver Mensaje Individual
  post #1 (permalink)  
Antiguo 19/06/05, 12:05:01
pablocm pablocm está offline
Usuario
 
Registrado: jun 2005
Ubicación: Suiza
Mensajes: 4
Bien No puedo eliminar barras creadas por messenger plus (solucionado)

Recientemente instalé dos programas, primero el messenger plus y tambíen el msn poligamy 7x, después de esto se crearon dos barras en el internet explorer (una arriba que dice Search y tiene unos botones y no hay forma de sacarla, y la otra abajo de fondo azul que dice Make money, Music, Casino, etc, la cual se carga al iniciar el iexplorer pero que puedo cerrarla). Además se me cambió la página de inicio, la página de error, aparecieron varios íconos en el escritorio, y comenzaron a aparecer popups continuamente.
Pase el Microsoft AntiSpyware Beta y detecto el Messenger Plus como spywares y otros más y los removio, la página de inicio fue restaurada. Pero lo que persistio fue las barras del explorer y la página de error.
He intentado de todo: desinstalando totalmente el iexplorer, volviendo a instalar el messenger plus y desinstalandolo, he pasado el Spyware Doctor y el AD-Aware SE, diskcleaner, siempren encontraban algo pero nunca pudieron eliminar las barras y los popups de publicidad siguen.
He hecho casi de todo y sigo con el problema. Aquí pego mi log.
Agradeceré mucho su ayuda.

Logfile of HijackThis v1.99.1
Scan saved at 11:00:25 AM, on 19/06/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\S24EvMon.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\ibmsmbus.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\RegSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\RNRPSvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\TpKmpSVC.exe
C:\PROGRA~1\UMS\Director\bin\twgipcsv.exe
C:\PROGRA~1\UMS\Director\bin\twgipc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\UMS\Director\bin\twgescli.exe
C:\PROGRA~1\UMS\Director\bin\twgmonit.exe
C:\PROGRA~1\UMS\Director\bin\twgperf.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis1.e xe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINNT\system32\internat.exe
D:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\pc20871\Start Menu\Programs\Startup\KillSfw2.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\Documents and Settings\pc20871\Desktop\hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://inside.abb.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 169.254.119.51:4480
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v1] C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis1.e xe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [RdrLoudBibFork] C:\Documents and Settings\All Users\Application Data\BoltAudioRdrLoud\refmulti.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [multi platform] C:\DOCUME~1\pc20871\APPLIC~1\CHICTO~1\CreativeRoad .exe
O4 - Startup: KillSfw2.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: JavaConnect - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\JavaC onnect.cab
O16 - DPF: Sametime BroadCast Client ST25PF1 - file://C:\DOCUME~1\ADMINI~1.PEA\LOCALS~1\Temp\WrapGLF16D\ STBroadCastClient.cab
O16 - DPF: Sametime BroadCast Client ST30IF3 - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\STBro adCastClient.cab
O16 - DPF: Sametime Directory Applet ST25PF1 - file://C:\DOCUME~1\ADMINI~1.PEA\LOCALS~1\Temp\WrapGLF16D\ STDirectoryApplet.cab
O16 - DPF: Sametime Directory Applet ST30SP1 - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\STDir ectoryApplet.cab
O16 - DPF: Sametime Meeting Room Client ST25PF1 - file://C:\DOCUME~1\ADMINI~1.PEA\LOCALS~1\Temp\WrapGLF16D\ STMeetingRoomClient.cab
O16 - DPF: Sametime Meeting Room Client ST30IF3 - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\STMee tingRoomClient.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {24CEC0BF-C8BC-4bcb-B804-226326B319EF} (JNILoader Control) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\STJNI Loader.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {A25BE7A9-3102-46B4-BAAE-462471B60ACB} (STConnectivityAgent Control) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WrapGLF2B\Insta llSTConnAgent.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = americas.abb.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = americas.abb.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = americas.abb.com
O20 - Winlogon Notify: tphotkey - C:\WINNT\SYSTEM32\tphklock.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: SMBus Upgrade Service for Windows 2000 and above (ibmsmbus) - International Business Machines Corp. - C:\WINNT\System32\ibmsmbus.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: ABB MMS Server for AC 800M/C (MMSService) - Unknown owner - D:\Program Files\ABB Industrial IT\Control IT\Common Files\MMSServer\MMSService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\system32\RegSrvc.exe
O23 - Service: ABB RNRP Service (RnrpSvc) - ABB - C:\WINNT\system32\RNRPSvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe
O23 - Service: IBM Director Support Program (TWGIPC) - IBM Corporation - C:\PROGRA~1\UMS\Director\bin\twgipcsv.exe
Responder Con Cita