Ver la Versión Completa : paginas buscadores y otras se redireccionan a una pagina en espesifico


luishi5
30/03/08, 17:20:53
estimados oficiales de hijackthis tengo el problema de que trato de entrar a una pagina de busqueda por ej.msn,google,yahoo y otras que no son de busqueda y automaticamente me redireccionan a una pagina llamada regeringen och regeringskanslient.Tengo como antivirus avg e probado kaspersky,nod32,norton,panda y como antispyware tengo avg antispyware e probado xoftspy que me identifica muchas trojano le doy remover,pero scaneo nuevamente,pero vuelven a salir.Actualmente tengo tambien spybot y spyhunter trabajando al mismo tiempo tengo ccleaner los e utilizado de diferentes formas sigue igual espero su contestacion pronto
nota:no soy muy diestro en lo tecnico pero me defiendo
gracias

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:36:51 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\USB Storage RW\udsi.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\HP\KBD\KBD.EXE
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\DNA\btdna.exe
C:\Documents and Settings\Owner\My Documents\programas\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 81.216.70.132 www.msn.com
O1 - Hosts: 81.216.70.132 www.msn.no
O1 - Hosts: 81.216.70.132 www.msn.se
O1 - Hosts: 81.216.70.132 www.msn.co.uk
O1 - Hosts: 81.216.70.132 www.msn.de
O1 - Hosts: 81.216.70.132 www.msn.dk
O1 - Hosts: 81.216.70.132 se.msn.com
O1 - Hosts: 81.216.70.132 no.msn.com
O1 - Hosts: 81.216.70.132 dk.msn.com
O1 - Hosts: 81.216.70.132 de.msn.com
O1 - Hosts: 81.216.70.132 uk.msn.com
O1 - Hosts: 81.216.70.132 msn.com
O1 - Hosts: 81.216.70.132 msn.no
O1 - Hosts: 81.216.70.132 msn.se
O1 - Hosts: 81.216.70.132 msn.co.uk
O1 - Hosts: 81.216.70.132 msn.de
O1 - Hosts: 81.216.70.132 msn.dk
O1 - Hosts: 81.216.70.132 www.google.com
O1 - Hosts: 81.216.70.132 www.google.no
O1 - Hosts: 81.216.70.132 www.google.se
O1 - Hosts: 81.216.70.132 www.google.dk
O1 - Hosts: 81.216.70.132 www.google.de
O1 - Hosts: 81.216.70.132 www.google.co.uk
O1 - Hosts: 81.216.70.132 google.com
O1 - Hosts: 81.216.70.132 google.no
O1 - Hosts: 81.216.70.132 google.se
O1 - Hosts: 81.216.70.132 google.dk
O1 - Hosts: 81.216.70.132 google.de
O1 - Hosts: 81.216.70.132 google.co.uk
O1 - Hosts: 81.216.70.132 www.altavista.com
O1 - Hosts: 81.216.70.132 www.altavista.no
O1 - Hosts: 81.216.70.132 www.altavista.se
O1 - Hosts: 81.216.70.132 www.altavista.dk
O1 - Hosts: 81.216.70.132 www.altavista.de
O1 - Hosts: 81.216.70.132 www.altavista.co.uk
O1 - Hosts: 81.216.70.132 altavista.com
O1 - Hosts: 81.216.70.132 altavista.no
O1 - Hosts: 81.216.70.132 altavista.se
O1 - Hosts: 81.216.70.132 altavista.dk
O1 - Hosts: 81.216.70.132 altavista.de
O1 - Hosts: 81.216.70.132 altavista.co.uk
O1 - Hosts: 81.216.70.132 www.thepiratebay.com
O1 - Hosts: 81.216.70.132 www.thepiratebay.org
O1 - Hosts: 81.216.70.132 www.thepiratebay.net
O1 - Hosts: 81.216.70.132 thepiratebay.com
O1 - Hosts: 81.216.70.132 thepiratebay.org
O1 - Hosts: 81.216.70.132 thepiratebay.net
O1 - Hosts: 81.216.70.132 www.isohunt.com
O1 - Hosts: 81.216.70.132 isohunt.com
O1 - Hosts: 81.216.70.132 www.torrentreactor.net
O1 - Hosts: 81.216.70.132 www.torrentreactor.com
O1 - Hosts: 81.216.70.132 www.torrentreactor.to
O1 - Hosts: 81.216.70.132 torrentreactor.net
O1 - Hosts: 81.216.70.132 torrentreactor.com
O1 - Hosts: 81.216.70.132 torrentreactor.to
O1 - Hosts: 81.216.70.132 www.sharethefiles.com
O1 - Hosts: 81.216.70.132 sharethefiles.com
O1 - Hosts: 81.216.70.132 www.torrentazos.com
O1 - Hosts: 81.216.70.132 www.torrentbox.com
O1 - Hosts: 81.216.70.132 www.bittorrent.com
O1 - Hosts: 81.216.70.132 www.torrentspy.com
O1 - Hosts: 81.216.70.132 www.utorrent.com
O1 - Hosts: 81.216.70.132 www.download.com
O1 - Hosts: 81.216.70.132 www.arespremium.com
O1 - Hosts: 81.216.70.132 www.fixmypcsite.com
O1 - Hosts: 81.216.70.132 www.dehsoftware.com
O1 - Hosts: 81.216.70.132 www.bitcomet.com
O1 - Hosts: 81.216.70.132 www.kazaa.com
O1 - Hosts: 81.216.70.132 www.tntdownloads.com
O1 - Hosts: 81.216.70.132 www.emule-project.net
O1 - Hosts: 81.216.70.132 www.emule.com
O1 - Hosts: 81.216.70.132 www.emule.org
O1 - Hosts: 81.216.70.132 www.yahoo.com
O1 - Hosts: 81.216.70.132 www.yahoo.net
O1 - Hosts: 81.216.70.132 www.microsoft.net
O1 - Hosts: 81.216.70.132 torrentazos.com
O1 - Hosts: 81.216.70.132 torrentbox.com
O1 - Hosts: 81.216.70.132 bittorrent.com
O1 - Hosts: 81.216.70.132 torrentspy.com
O1 - Hosts: 81.216.70.132 utorrent.com
O1 - Hosts: 81.216.70.132 download.com
O1 - Hosts: 81.216.70.132 arespremium.com
O1 - Hosts: 81.216.70.132 fixmypcsite.com
O1 - Hosts: 81.216.70.132 dehsoftware.com
O1 - Hosts: 81.216.70.132 bitcomet.com
O1 - Hosts: 81.216.70.132 kazaa.com
O1 - Hosts: 81.216.70.132 tntdownloads.com
O1 - Hosts: 81.216.70.132 emule-project.net
O1 - Hosts: 81.216.70.132 emule.com
O1 - Hosts: 81.216.70.132 emule.org
O1 - Hosts: 81.216.70.132 yahoo.com
O1 - Hosts: 81.216.70.132 yahoo.net
O1 - Hosts: 81.216.70.132 microsoft.net
O1 - Hosts: 81.216.70.132 video.google.com
O1 - Hosts: 81.216.70.132 www.qx.se
O1 - Hosts: 81.216.70.132 www.tradera.com
O1 - Hosts: 81.216.70.132 www.tradera.se
O1 - Hosts: 81.216.70.132 qx.se
O1 - Hosts: 81.216.70.132 www.qx.se
O1 - Hosts: 81.216.70.132 www.qruiser.com
O1 - Hosts: 81.216.70.132 qruiser.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_UDSI] "C:\Program Files\USB Storage RW\udsi.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpyHunter Security Suite] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" -minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1206074342828
O23 - Service: BugSoft AnyTrial (AnyTrial) - Dr.Pc Putte Corp ;) - C:\WINDOWS\AnyTrial.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 13112 bytes

ElPiedra
01/04/08, 04:31:57
Hola luishi5, te doy la bienvenida al Foro de InfoSpyware.


Descarga, actualiza y ejecuta el programa:
SUPERAntiSpyware
Malwarebytes' Anti-Malware
*Nota* Es importante que envíes a "Cuarentena" todo lo que este detecte antes de copiar y pegarnos su reporte.


Descarga CCleaner (http://www.forospyware.com/t105564.html) y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad).


.:cf_icon:. - Descarga la herramienta ComboFix.exe (http://www.forospyware.com/sUBs/ComboFix.exe) y guárdala en el escritorio.
Desactiva temporalmente el Antivirus y/o Antispyware.
Cierra todas las ventanas abiertas.
Hacele doble clic al archivo ComboFix.exe y seguí las instrucciones.
Cuando termine, generara un registro en C:\ComboFix.txt.

*Nota* Mientras CF este trabajando no mover el mouse ya que pararía su proceso.
*Nota* ComboFix puede reiniciar automáticamente el PC para completar el proceso de eliminación.

Atención!! No use ComboFix a menos que se le haya indicado específicamente en su mensaje por un integrante de nuestro Staff (http://www.forospyware.com/showgroups.php). Es una herramienta de gran alcance destinada por su creador a ser usada bajo la orientación y supervisión de un experto, no para uso privado. El uso de ComboFix incorrectamente podría generar problemas en su sistema. Por favor, lea las "Negaciones de la Garantía" de ComboFix.



Reinicia y pega el reporte de C:\ComboFix.txt en este mismo mensaje.




Salu2

© Copyright 2005 - 2008 InfoSpyware ® Todos los derechos reservados.
InfoSpyware Security Blog