Hola Seba, este PC tiene un virus del tipo guano llamado W32/Sdbot-XV por lo que ejecuta HijackThis y dale FIX a estas entradas:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O2 - BHO: seykzyaikrruhqusgrnd - {0bd8007d-b81f-4f17-9971-4ee1d15d57ee} - C:\DOCUME~1\Seba\APPLIC~1\lassoavibr.dll (file missing)
O2 - BHO: (no name) - {ACB3E0B7-7D0C-40B7-99B3-3EEACDF86BFB} - C:\WINDOWS\mslagent\4b_1,0,1,1_mslagent.dll (file missing)
O3 - Toolbar: ossfeagigis - {7523173c-6eaf-4816-937a-80460b481c98} - C:\DOCUME~1\Seba\APPLIC~1\lassoavibr.dll (file missing)
O4 - HKLM\..\RunServices: [Windows kev Messenger] mskev.exe
O4 - HKCU\..\RunServices: [Windows kev Messenger] mskev.exe
O4 - Startup: netdb.exe
O9 - Extra button: Descargas - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\euro-kazemule-0023\index.html (file missing)
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - http://akamai.downloadv3.com/binaries/IA/dtc32_EN_XP.cab
O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} - http://akamai.downloadv3.com/binaries/IA/netia32_EN_XP.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqlar/downloads/sysinfo.cab
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {86EEF11E-FF16-48CE-B1A2-474B663041A9} - http://acces-direct.net/20222/adh1_sexarea.exe
O16 - DPF: {B3A5878E-5B4C-4D12-9156-4D7FD8D0AF6C} (Cltbuilder Class) - http://akamai.downloadv3.com/binaries/one2one/one2oneSvcES.cab
O16 - DPF: {CAAF9105-A683-4ED1-89CC-18F6D194DD84} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_6_EN_XP.cab
O16 - DPF: {EEECA057-AD0F-44A7-8BE5-8634CEDBDBD1} - http://akamai.downloadv3.com/binaries/IA/netpe32_EN_XP.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.230.146.53/EPlugin.cab
Sin reiniciar y busca y si estan borra estos archivos:
mskev.exe
netdb.exe
Usa el
Disk Cleaner para limpiar cookies y temporales y
RegSeeker para limpiar el registro de Win.
Reinicia y
nos contas los resultados.
Salu2