Ver Mensaje Individual
  post #1 (permalink)  
Antiguo 18/08/05, 14:38:50
Diegol Diegol está offline
Usuario
 
Registrado: ago 2005
Ubicación: Argentina
Mensajes: 1
Pregunta Problemas con IE

Hola amigos!
Espero me puedan ayudar. Al tratar de entrar a Internet Explorer se cambia a about blank y se abren ventanas informando que tengo espias, he utilizado ya varios antivirus y nada da resultado. Esto me detecta el hijackthis: Espero me ayuden, muchas gracias!
Logfile of HijackThis v1.99.1
Scan saved at 15:11:55, on 08/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Norton AntiVirus\navapsvc.exe
C:\Archivos de programa\Norton AntiVirus\SAVScan.exe
C:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exe
C:\Archivos de programa\Archivos comunes\Symantec Shared\Security Center\SymWSC.exe
C:\Archivos de programa\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\ipyk32.exe
C:\ARCHIV~1\PANICW~1\POP-UP~1\PSFree.exe
C:\program files\InterMute\SpySubtract\SpySub.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\INTERNAT.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nqdnn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 168.96.132.19:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = .unl.edu.ar;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Archivos de programa\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {DEC23984-57DA-169D-2ABC-89B52CDC9100} - C:\WINDOWS\mfcxb.dll
O2 - BHO: Class - {F7C45676-146F-4E38-1143-6511A08788D4} - C:\WINDOWS\iefl.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Archivos de programa\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\ARCHIV~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ipyk32.exe] C:\WINDOWS\ipyk32.exe
O4 - HKLM\..\RunOnce: [msmr.exe] C:\WINDOWS\msmr.exe
O4 - HKLM\..\RunOnce: [netjq.exe] C:\WINDOWS\system32\netjq.exe
O4 - HKLM\..\RunOnce: [ipoi32.exe] C:\WINDOWS\ipoi32.exe
O4 - HKLM\..\RunOnce: [apiyo32.exe] C:\WINDOWS\apiyo32.exe
O4 - HKLM\..\RunOnce: [winmu32.exe] C:\WINDOWS\winmu32.exe
O4 - HKLM\..\RunOnce: [crrp.exe] C:\WINDOWS\crrp.exe
O4 - HKLM\..\RunOnce: [winbr32.exe] C:\WINDOWS\system32\winbr32.exe
O4 - HKLM\..\RunOnce: [d3en32.exe] C:\WINDOWS\d3en32.exe
O4 - HKLM\..\RunOnce: [iprq.exe] C:\WINDOWS\iprq.exe
O4 - HKLM\..\RunOnce: [ntbx32.exe] C:\WINDOWS\ntbx32.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\system32\atlgr32.exe
O4 - HKLM\..\RunOnce: [sysso.exe] C:\WINDOWS\system32\sysso.exe
O4 - HKLM\..\RunOnce: [javaxq.exe] C:\WINDOWS\javaxq.exe
O4 - HKLM\..\RunOnce: [crqt.exe] C:\WINDOWS\system32\crqt.exe
O4 - HKLM\..\RunOnce: [ipri.exe] C:\WINDOWS\system32\ipri.exe
O4 - HKLM\..\RunOnce: [appek32.exe] C:\WINDOWS\system32\appek32.exe
O4 - HKLM\..\RunOnce: [d3rh.exe] C:\WINDOWS\system32\d3rh.exe
O4 - HKLM\..\RunOnce: [netfj32.exe] C:\WINDOWS\netfj32.exe
O4 - HKLM\..\RunOnce: [ietm32.exe] C:\WINDOWS\ietm32.exe
O4 - HKLM\..\RunOnce: [sdkzg.exe] C:\WINDOWS\sdkzg.exe
O4 - HKLM\..\RunOnce: [mfchp32.exe] C:\WINDOWS\mfchp32.exe
O4 - HKLM\..\RunOnce: [ievs32.exe] C:\WINDOWS\system32\ievs32.exe
O4 - HKLM\..\RunOnce: [mfcmo32.exe] C:\WINDOWS\mfcmo32.exe
O4 - HKLM\..\RunOnce: [sysrk32.exe] C:\WINDOWS\system32\sysrk32.exe
O4 - HKLM\..\RunOnce: [apiuw.exe] C:\WINDOWS\apiuw.exe
O4 - HKLM\..\RunOnce: [appqi.exe] C:\WINDOWS\appqi.exe
O4 - HKLM\..\RunOnce: [ipox32.exe] C:\WINDOWS\system32\ipox32.exe
O4 - HKLM\..\RunOnce: [cref.exe] C:\WINDOWS\system32\cref.exe
O4 - HKLM\..\RunOnce: [sysaj32.exe] C:\WINDOWS\system32\sysaj32.exe
O4 - HKLM\..\RunOnce: [d3rj.exe] C:\WINDOWS\system32\d3rj.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\system32\msxg32.exe
O4 - HKLM\..\RunOnce: [mfcgm.exe] C:\WINDOWS\system32\mfcgm.exe
O4 - HKLM\..\RunOnce: [javawb32.exe] C:\WINDOWS\javawb32.exe
O4 - HKLM\..\RunOnce: [msmj.exe] C:\WINDOWS\msmj.exe
O4 - HKLM\..\RunOnce: [appqn32.exe] C:\WINDOWS\system32\appqn32.exe
O4 - HKLM\..\RunOnce: [syszv.exe] C:\WINDOWS\syszv.exe
O4 - HKLM\..\RunOnce: [winfk32.exe] C:\WINDOWS\system32\winfk32.exe
O4 - HKLM\..\RunOnce: [sysuh32.exe] C:\WINDOWS\sysuh32.exe
O4 - HKLM\..\RunOnce: [javayd32.exe] C:\WINDOWS\javayd32.exe
O4 - HKLM\..\RunOnce: [wintx32.exe] C:\WINDOWS\wintx32.exe
O4 - HKLM\..\RunOnce: [atlgt32.exe] C:\WINDOWS\system32\atlgt32.exe
O4 - HKLM\..\RunOnce: [crgb.exe] C:\WINDOWS\crgb.exe
O4 - HKLM\..\RunOnce: [ntkn.exe] C:\WINDOWS\system32\ntkn.exe
O4 - HKLM\..\RunOnce: [iezc32.exe] C:\WINDOWS\iezc32.exe
O4 - HKLM\..\RunOnce: [addqk.exe] C:\WINDOWS\addqk.exe
O4 - HKLM\..\RunOnce: [apito32.exe] C:\WINDOWS\system32\apito32.exe
O4 - HKLM\..\RunOnce: [msiq32.exe] C:\WINDOWS\system32\msiq32.exe
O4 - HKLM\..\RunOnce: [crdu.exe] C:\WINDOWS\system32\crdu.exe
O4 - HKLM\..\RunOnce: [netck32.exe] C:\WINDOWS\system32\netck32.exe
O4 - HKLM\..\RunOnce: [appbz.exe] C:\WINDOWS\appbz.exe
O4 - HKLM\..\RunOnce: [d3ap32.exe] C:\WINDOWS\d3ap32.exe
O4 - HKLM\..\RunOnce: [ntqw32.exe] C:\WINDOWS\system32\ntqw32.exe
O4 - HKLM\..\RunOnce: [sdkym.exe] C:\WINDOWS\system32\sdkym.exe
O4 - HKLM\..\RunOnce: [ntyn.exe] C:\WINDOWS\ntyn.exe
O4 - HKLM\..\RunOnce: [msoc32.exe] C:\WINDOWS\system32\msoc32.exe
O4 - HKLM\..\RunOnce: [addmj32.exe] C:\WINDOWS\system32\addmj32.exe
O4 - HKLM\..\RunOnce: [syshv.exe] C:\WINDOWS\system32\syshv.exe
O4 - HKLM\..\RunOnce: [sdkgl32.exe] C:\WINDOWS\system32\sdkgl32.exe
O4 - HKLM\..\RunOnce: [apiws32.exe] C:\WINDOWS\apiws32.exe
O4 - HKLM\..\RunOnce: [netei.exe] C:\WINDOWS\netei.exe
O4 - HKLM\..\RunOnce: [apifi.exe] C:\WINDOWS\system32\apifi.exe
O4 - HKLM\..\RunOnce: [javacy32.exe] C:\WINDOWS\javacy32.exe
O4 - HKLM\..\RunOnce: [ietf32.exe] C:\WINDOWS\ietf32.exe
O4 - HKLM\..\RunOnce: [d3or.exe] C:\WINDOWS\system32\d3or.exe
O4 - HKLM\..\RunOnce: [addsb.exe] C:\WINDOWS\system32\addsb.exe
O4 - HKLM\..\RunOnce: [javagx32.exe] C:\WINDOWS\javagx32.exe
O4 - HKLM\..\RunOnce: [d3rq32.exe] C:\WINDOWS\system32\d3rq32.exe
O4 - HKLM\..\RunOnce: [netwn32.exe] C:\WINDOWS\system32\netwn32.exe
O4 - HKLM\..\RunOnce: [d3zy.exe] C:\WINDOWS\d3zy.exe
O4 - HKLM\..\RunOnce: [sdkdk32.exe] C:\WINDOWS\sdkdk32.exe
O4 - HKLM\..\RunOnce: [apits.exe] C:\WINDOWS\system32\apits.exe
O4 - HKLM\..\RunOnce: [syssh32.exe] C:\WINDOWS\system32\syssh32.exe
O4 - HKLM\..\RunOnce: [crqx32.exe] C:\WINDOWS\crqx32.exe
O4 - HKLM\..\RunOnce: [d3qn.exe] C:\WINDOWS\d3qn.exe
O4 - HKLM\..\RunOnce: [mswc32.exe] C:\WINDOWS\mswc32.exe
O4 - HKLM\..\RunOnce: [d3ky32.exe] C:\WINDOWS\system32\d3ky32.exe
O4 - HKLM\..\RunOnce: [ippv32.exe] C:\WINDOWS\system32\ippv32.exe
O4 - HKLM\..\RunOnce: [mssg32.exe] C:\WINDOWS\system32\mssg32.exe
O4 - HKLM\..\RunOnce: [winxl.exe] C:\WINDOWS\winxl.exe
O4 - HKLM\..\RunOnce: [sysxt32.exe] C:\WINDOWS\system32\sysxt32.exe
O4 - HKLM\..\RunOnce: [iemi32.exe] C:\WINDOWS\iemi32.exe
O4 - HKLM\..\RunOnce: [sdkrm32.exe] C:\WINDOWS\sdkrm32.exe
O4 - HKLM\..\RunOnce: [sysmy32.exe] C:\WINDOWS\sysmy32.exe
O4 - HKLM\..\RunOnce: [appzc.exe] C:\WINDOWS\system32\appzc.exe
O4 - HKLM\..\RunOnce: [addzc32.exe] C:\WINDOWS\addzc32.exe
O4 - HKLM\..\RunOnce: [ntjj.exe] C:\WINDOWS\ntjj.exe
O4 - HKLM\..\RunOnce: [msyy32.exe] C:\WINDOWS\system32\msyy32.exe
O4 - HKLM\..\RunOnce: [addwf.exe] C:\WINDOWS\system32\addwf.exe
O4 - HKLM\..\RunOnce: [apisj32.exe] C:\WINDOWS\system32\apisj32.exe
O4 - HKLM\..\RunOnce: [appck.exe] C:\WINDOWS\system32\appck.exe
O4 - HKLM\..\RunOnce: [atlpg32.exe] C:\WINDOWS\system32\atlpg32.exe
O4 - HKLM\..\RunOnce: [atlwd32.exe] C:\WINDOWS\atlwd32.exe
O4 - HKLM\..\RunOnce: [msbz32.exe] C:\WINDOWS\system32\msbz32.exe
O4 - HKLM\..\RunOnce: [atlel32.exe] C:\WINDOWS\atlel32.exe
O4 - HKLM\..\RunOnce: [netip.exe] C:\WINDOWS\netip.exe
O4 - HKLM\..\RunOnce: [apijq32.exe] C:\WINDOWS\apijq32.exe
O4 - HKLM\..\RunOnce: [mfcyn32.exe] C:\WINDOWS\mfcyn32.exe
O4 - HKLM\..\RunOnce: [sysdr32.exe] C:\WINDOWS\sysdr32.exe
O4 - HKLM\..\RunOnce: [apigd32.exe] C:\WINDOWS\system32\apigd32.exe
O4 - HKLM\..\RunOnce: [ntkh.exe] C:\WINDOWS\system32\ntkh.exe
O4 - HKLM\..\RunOnce: [iplh32.exe] C:\WINDOWS\system32\iplh32.exe
O4 - HKLM\..\RunOnce: [netae.exe] C:\WINDOWS\system32\netae.exe
O4 - HKLM\..\RunOnce: [ipft.exe] C:\WINDOWS\system32\ipft.exe
O4 - HKLM\..\RunOnce: [wintx.exe] C:\WINDOWS\wintx.exe
O4 - HKLM\..\RunOnce: [ntnj.exe] C:\WINDOWS\system32\ntnj.exe
O4 - HKLM\..\RunOnce: [apicq.exe] C:\WINDOWS\system32\apicq.exe
O4 - HKLM\..\RunOnce: [crsl32.exe] C:\WINDOWS\crsl32.exe
O4 - HKLM\..\RunOnce: [atlst.exe] C:\WINDOWS\system32\atlst.exe
O4 - HKLM\..\RunOnce: [winwx32.exe] C:\WINDOWS\winwx32.exe
O4 - HKLM\..\RunOnce: [d3um.exe] C:\WINDOWS\system32\d3um.exe
O4 - HKLM\..\RunOnce: [nettc32.exe] C:\WINDOWS\system32\nettc32.exe
O4 - HKLM\..\RunOnce: [appjj32.exe] C:\WINDOWS\appjj32.exe
O4 - HKLM\..\RunOnce: [atlrz.exe] C:\WINDOWS\atlrz.exe
O4 - HKLM\..\RunOnce: [appsa.exe] C:\WINDOWS\system32\appsa.exe
O4 - HKLM\..\RunOnce: [ntwj.exe] C:\WINDOWS\ntwj.exe
O4 - HKLM\..\RunOnce: [iphp32.exe] C:\WINDOWS\iphp32.exe
O4 - HKLM\..\RunOnce: [crgw32.exe] C:\WINDOWS\crgw32.exe
O4 - HKLM\..\RunOnce: [sdkbi.exe] C:\WINDOWS\sdkbi.exe
O4 - HKLM\..\RunOnce: [atlay32.exe] C:\WINDOWS\atlay32.exe
O4 - HKLM\..\RunOnce: [sysqf.exe] C:\WINDOWS\system32\sysqf.exe
O4 - HKLM\..\RunOnce: [javapv32.exe] C:\WINDOWS\system32\javapv32.exe
O4 - HKLM\..\RunOnce: [addhf.exe] C:\WINDOWS\system32\addhf.exe
O4 - HKLM\..\RunOnce: [netnk32.exe] C:\WINDOWS\netnk32.exe
O4 - HKLM\..\RunOnce: [ipns32.exe] C:\WINDOWS\ipns32.exe
O4 - HKLM\..\RunOnce: [sysuv32.exe] C:\WINDOWS\sysuv32.exe
O4 - HKLM\..\RunOnce: [crxt32.exe] C:\WINDOWS\system32\crxt32.exe
O4 - HKLM\..\RunOnce: [mfcxb.exe] C:\WINDOWS\mfcxb.exe
O4 - HKLM\..\RunOnce: [addaf.exe] C:\WINDOWS\system32\addaf.exe
O4 - HKLM\..\RunOnce: [netqc32.exe] C:\WINDOWS\netqc32.exe
O4 - HKLM\..\RunOnce: [javaok32.exe] C:\WINDOWS\javaok32.exe
O4 - HKLM\..\RunOnce: [ntjn.exe] C:\WINDOWS\system32\ntjn.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\system32\appid32.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\ARCHIV~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: SpySubtract.lnk = C:\program files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: SmartShopper - Compare product prices - {679B2A8D-B2FF-41ed-B3ED-C5CFB8564CB0} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: SmartShopper - Compare travel rates - {9E4DF170-217F-4658-A11F-590664542B73} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: ShopperReports - Compare product prices - {E77EDA01-3C56-4a96-8D08-02B42891C169} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5615897E-D578-469D-8B24-11784C0C0E58}: Domain = unl.edu.ar
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = fiqus.unl.edu.ar
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = fiqus.unl.edu.ar
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = fiqus.unl.edu.ar
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\msmr.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
O23 - Service: Servicio Auto-Protect de Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Archivos de programa\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Archivos de programa\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARCHIV~1\ARCHIV~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\Security Center