![]() |
| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Hola.hice todo lo que ustedes recomiendan,arranque en modo seguro,habilite los archivos ocultos,etc,etc,etc,pase los dos anti-virus on-line,pase spybot,adware,doctor spyware,et,etc,me limpio muchisimos spyware y malwares,pero sigo sin poder navegar,en firefox me aparece megaclick,y en el explorer hace directamente como si no tuviera conexion a internet.Adjunto el log de hijackthis,con la esperanza de que me puedan ayudar.gracias desde ya. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:32:36 PM, on 3/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtim e.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/spanish/kavwebscan_unicode.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6472 bytes Este es el log de combofix ComboFix 08-03-06.4 - Administrator 2008-03-07 11:38:25.2 - NTFSx86 NETWORK Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.327 [GMT -6:00] Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-02-07 to 2008-03-07 ))))))))))))))))))))))))))))))) . 2008-03-07 10:28 . 2008-03-07 10:28 <DIR> d-------- C:\Documents and Settings\Dee\Application Data\Malwarebytes 2008-03-07 09:30 . 2008-03-07 09:30 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-03-07 09:30 . 2008-03-07 09:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-03-07 09:30 . 2008-03-07 09:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes 2008-03-06 19:05 . 2008-03-07 11:29 <DIR> d-------- C:\Program Files\Opera 2008-03-06 10:37 . 2008-03-06 10:37 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-03-05 20:28 . 2008-03-05 20:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com 2008-03-05 20:10 . 2008-03-05 20:10 <DIR> d-------- C:\Archivos de programa 2008-03-05 20:04 . 2008-03-05 20:04 <DIR> d-------- C:\Program Files\FileASSASSIN 2008-03-05 18:36 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys 2008-03-05 18:36 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys 2008-03-05 18:36 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys 2008-03-05 18:36 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys 2008-03-05 18:35 . 2008-03-05 21:58 <DIR> d-------- C:\Program Files\Spyware Doctor 2008-03-05 18:35 . 2008-03-05 18:35 <DIR> d-------- C:\Documents and Settings\Dee\Application Data\PC Tools 2008-03-05 18:35 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2008-03-05 18:31 . 2008-03-05 18:31 <DIR> d-------- C:\Program Files\Lavasoft 2008-03-05 18:31 . 2008-03-05 18:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-03-05 18:28 . 2008-03-07 11:22 <DIR> d-------- C:\Program Files\Disk Cleaner 2008-03-05 17:29 . 2008-03-06 18:36 <DIR> d-------- C:\Program Files\SUPERAntiSpyware 2008-03-05 17:29 . 2008-03-05 17:29 <DIR> d-------- C:\Documents and Settings\Dee\Application Data\SUPERAntiSpyware.com 2008-03-05 17:29 . 2008-03-05 17:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-03-05 15:10 . 2008-03-05 15:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot 2008-03-05 15:10 . 2008-01-04 20:34 163,696 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys 2008-03-05 15:10 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys 2008-03-05 15:10 . 2008-01-04 20:34 21,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys 2008-03-05 15:10 . 2008-01-04 20:34 20,336 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys 2008-03-05 15:09 . 2008-03-05 15:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot 2008-03-05 15:09 . 2008-03-05 15:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot 2008-03-05 15:09 . 2008-01-04 20:56 1,526,640 --a------ C:\WINDOWS\WRSetup.dll 2008-03-05 15:08 . 2008-03-05 15:08 164 --a------ C:\install.dat 2008-03-05 15:02 . 2008-03-05 15:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7 2008-03-05 14:55 . 2008-03-07 10:28 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-03-05 14:51 . 2008-03-06 13:58 <DIR> d-------- C:\Program Files\SpywareBlaster 2008-03-05 14:34 . 2008-03-05 14:34 <DIR> d-------- C:\Documents and Settings\Mami\Application Data\Grisoft 2008-03-05 13:03 . 2008-03-06 14:36 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat 2008-03-05 13:02 . 2008-03-05 13:02 <DIR> d-------- C:\Program Files\Zone Labs 2008-03-05 13:01 . 2008-03-07 11:32 <DIR> d-------- C:\WINDOWS\Internet Logs 2008-03-05 12:37 . 2008-03-05 12:37 <DIR> d-------- C:\Program Files\CCleaner 2008-03-05 12:36 . 2008-03-05 12:36 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback 2008-03-05 12:31 . 2008-03-05 18:29 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-03-05 12:06 . 2008-03-05 12:03 691,545 --a------ C:\WINDOWS\unins000.exe 2008-03-05 12:06 . 2008-03-05 12:06 2,548 --a------ C:\WINDOWS\unins000.dat 2008-03-05 12:00 . 2008-03-05 12:08 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-03-05 12:00 . 2008-03-07 10:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-03-05 11:49 . 2005-08-27 13:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-03-05 11:49 . 2005-08-27 13:23 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc 2008-03-05 11:49 . 2005-08-27 13:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel 2008-03-01 11:43 . 2008-03-01 11:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-03-01 11:43 . 2008-03-01 11:43 1,409 --a------ C:\WINDOWS\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2008-03-07 16:21 19,072,155 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_07_10_09_44_full.dmp. zip 2008-03-07 16:08 19,069,089 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_07_09_26_21_full.dmp. zip 2008-03-07 01:19 155,648 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp 2008-03-07 01:19 1,981,440 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp 2008-03-06 15:25 96,256 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp 2008-03-06 15:25 1,932,288 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp 2008-03-06 02:14 123,904 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp 2008-03-06 02:14 1,887,232 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp 2008-03-06 00:15 208,896 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp 2008-03-06 00:15 1,747,456 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp 2008-03-05 21:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7 2008-02-29 14:00 --------- d-----w C:\Documents and Settings\Dee\Application Data\AVG7 2008-02-25 07:45 --------- d-----w C:\Program Files\Dl_cats 2008-02-23 06:31 --------- d-----w C:\Program Files\Common Files\Ahead 2008-02-14 06:26 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-01-29 06:08 --------- d-----w C:\Documents and Settings\Mami\Application Data\Talkback 2008-01-29 06:08 --------- d-----w C:\Documents and Settings\Mami\Application Data\AVG7 2007-07-26 14:48 60,968 ----a-w C:\Documents and Settings\Dee\GoToAssistDownloadHelper.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce] "SpybotDeletingB7036"="command /c del C:\Program Files\DriveCleaner Free\Appbase\AE_CD_Cr.dat" [ ] "SpybotDeletingD3251"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\AE_CD_Cr.dat" [ ] "SpybotDeletingB8817"="command /c del C:\Program Files\DriveCleaner Free\Appbase\AReadr4.dat" [ ] "SpybotDeletingD5478"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\AReadr4.dat" [ ] "SpybotDeletingB3646"="command /c del C:\Program Files\DriveCleaner Free\Appbase\AReadr5.dat" [ ] "SpybotDeletingD5798"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\AReadr5.dat" [ ] "SpybotDeletingB1609"="command /c del C:\Program Files\DriveCleaner Free\Appbase\ASDSEEpv.dat" [ ] "SpybotDeletingD3587"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\ASDSEEpv.dat" [ ] "SpybotDeletingB1489"="command /c del C:\Program Files\DriveCleaner Free\Appbase\ASPack.dat" [ ] "SpybotDeletingD8643"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\ASPack.dat" [ ] "SpybotDeletingB8886"="command /c del C:\Program Files\DriveCleaner Free\Appbase\Babylon.dat" [ ] "SpybotDeletingD8195"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\Babylon.dat" [ ] "SpybotDeletingB3572"="command /c del C:\Program Files\DriveCleaner Free\Appbase\BDelphi5.dat" [ ] "SpybotDeletingD1741"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\BDelphi5.dat" [ ] "SpybotDeletingB6042"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CatchUp.dat" [ ] "SpybotDeletingD5091"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CatchUp.dat" [ ] "SpybotDeletingB4057"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CBuildr5.dat" [ ] "SpybotDeletingD5075"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CBuildr5.dat" [ ] "SpybotDeletingB9867"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CCGA.dat" [ ] "SpybotDeletingD5220"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CCGA.dat" [ ] "SpybotDeletingB3506"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CManager.dat" [ ] "SpybotDeletingD6791"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CManager.dat" [ ] "SpybotDeletingB4825"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CuteFTP4.dat" [ ] "SpybotDeletingD8009"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CuteFTP4.dat" [ ] "SpybotDeletingB7045"="command /c del C:\Program Files\DriveCleaner Free\Appbase\CuteHTML.dat" [ ] "SpybotDeletingD7872"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\CuteHTML.dat" [ ] "SpybotDeletingB1170"="command /c del C:\Program Files\DriveCleaner Free\Appbase\DAcceler.dat" [ ] "SpybotDeletingD2846"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\DAcceler.dat" [ ] "SpybotDeletingB4956"="command /c del C:\Program Files\DriveCleaner Free\Appbase\DiscJug.dat" [ ] "SpybotDeletingD1895"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\DiscJug.dat" [ ] "SpybotDeletingB9215"="command /c del C:\Program Files\DriveCleaner Free\Appbase\ECDCreat4.dat" [ ] "SpybotDeletingD8461"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\ECDCreat4.dat" [ ] "SpybotDeletingB2805"="command /c del C:\Program Files\DriveCleaner Free\Appbase\Far.dat" [ ] "SpybotDeletingD7706"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\Far.dat" [ ] "SpybotDeletingB2232"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FFTsks.dat" [ ] "SpybotDeletingD8779"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FFTsks.dat" [ ] "SpybotDeletingB4164"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FlashFXP.dat" [ ] "SpybotDeletingD1076"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FlashFXP.dat" [ ] "SpybotDeletingB422"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FrntPage.dat" [ ] "SpybotDeletingD5004"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FrntPage.dat" [ ] "SpybotDeletingB4464"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FrontPEx.dat" [ ] "SpybotDeletingD1041"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FrontPEx.dat" [ ] "SpybotDeletingB6817"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FtpEXP.dat" [ ] "SpybotDeletingD3774"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FtpEXP.dat" [ ] "SpybotDeletingB9328"="command /c del C:\Program Files\DriveCleaner Free\Appbase\FtpVoya.dat" [ ] "SpybotDeletingD1191"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\FtpVoya.dat" [ ] "SpybotDeletingB323"="command /c del C:\Program Files\DriveCleaner Free\Appbase\GetRight.dat" [ ] "SpybotDeletingD6058"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\GetRight.dat" [ ] "SpybotDeletingB2440"="command /c del C:\Program Files\DriveCleaner Free\Appbase\GoZilla.dat" [ ] "SpybotDeletingD3301"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\GoZilla.dat" [ ] "SpybotDeletingB5360"="command /c del C:\Program Files\DriveCleaner Free\Appbase\GravMRU.dat" [ ] "SpybotDeletingD4110"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\GravMRU.dat" [ ] "SpybotDeletingB2522"="command /c del C:\Program Files\DriveCleaner Free\Appbase\H_TxtPad.dat" [ ] "SpybotDeletingD5010"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\H_TxtPad.dat" [ ] "SpybotDeletingB7965"="command /c del C:\Program Files\DriveCleaner Free\Appbase\HomeSite.dat" [ ] "SpybotDeletingD6516"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\HomeSite.dat" [ ] "SpybotDeletingB7028"="command /c del C:\Program Files\DriveCleaner Free\Appbase\HotDogPr.dat" [ ] "SpybotDeletingD7856"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\HotDogPr.dat" [ ] "SpybotDeletingB5257"="command /c del C:\Program Files\DriveCleaner Free\Appbase\IconExtr.dat" [ ] "SpybotDeletingD5917"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\IconExtr.dat" [ ] "SpybotDeletingB9463"="command /c del C:\Program Files\DriveCleaner Free\Appbase\iMesh.dat" [ ] "SpybotDeletingD912"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\iMesh.dat" [ ] "SpybotDeletingB5573"="command /c del C:\Program Files\DriveCleaner Free\Appbase\ImgReady3.dat" [ ] "SpybotDeletingD5637"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\ImgReady3.dat" [ ] "SpybotDeletingB3573"="command /c del C:\Program Files\DriveCleaner Free\Appbase\InsShExp.dat" [ ] "SpybotDeletingD5052"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\InsShExp.dat" [ ] "SpybotDeletingB9221"="command /c del C:\Program Files\DriveCleaner Free\Appbase\JASC_P_P.dat" [ ] "SpybotDeletingD3003"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\JASC_P_P.dat" [ ] "SpybotDeletingB340"="command /c del C:\Program Files\DriveCleaner Free\Appbase\KaZaA.dat" [ ] "SpybotDeletingD6328"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\KaZaA.dat" [ ] "SpybotDeletingB2922"="command /c del C:\Program Files\DriveCleaner Free\Appbase\LView.dat" [ ] "SpybotDeletingD7053"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\LView.dat" [ ] "SpybotDeletingB3556"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MacDir.dat" [ ] "SpybotDeletingD6664"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MacDir.dat" [ ] "SpybotDeletingB7072"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MacDrWea.dat" [ ] "SpybotDeletingD460"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MacDrWea.dat" [ ] "SpybotDeletingB5127"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MicAng.dat" [ ] "SpybotDeletingD1748"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MicAng.dat" [ ] "SpybotDeletingB8686"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MicDes.dat" [ ] "SpybotDeletingD9749"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MicDes.dat" [ ] "SpybotDeletingB816"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MM_CON.dat" [ ] "SpybotDeletingD1304"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MM_CON.dat" [ ] "SpybotDeletingB3725"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MMUnDisk.dat" [ ] "SpybotDeletingD5411"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MMUnDisk.dat" [ ] "SpybotDeletingB8857"="command /c del C:\Program Files\DriveCleaner Free\Appbase\Morpheus.dat" [ ] "SpybotDeletingD6752"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\Morpheus.dat" [ ] "SpybotDeletingB7268"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MPaint.dat" [ ] "SpybotDeletingD5207"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MPaint.dat" [ ] "SpybotDeletingB4027"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MPicPub.dat" [ ] "SpybotDeletingD96"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MPicPub.dat" [ ] "SpybotDeletingB4920"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MPImaGal.dat" [ ] "SpybotDeletingD4560"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MPImaGal.dat" [ ] "SpybotDeletingB190"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MSExplorer.dat" [ ] "SpybotDeletingD8241"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MSExplorer.dat" [ ] "SpybotDeletingB4235"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MSoffice.dat" [ ] "SpybotDeletingD2381"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MSoffice.dat" [ ] "SpybotDeletingB3392"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MSRegEdit.dat" [ ] "SpybotDeletingD1203"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MSRegEdit.dat" [ ] "SpybotDeletingB7088"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MSWMP.dat" [ ] "SpybotDeletingD785"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MSWMP.dat" [ ] "SpybotDeletingB6858"="command /c del C:\Program Files\DriveCleaner Free\Appbase\MSWordPad.dat" [ ] "SpybotDeletingD2338"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\MSWordPad.dat" [ ] "SpybotDeletingB7279"="command /c del C:\Program Files\DriveCleaner Free\Appbase\Nero.dat" [ ] "SpybotDeletingD8126"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\Nero.dat" [ ] "SpybotDeletingB9751"="command /c del C:\Program Files\DriveCleaner Free\Appbase\NetShow.dat" [ ] "SpybotDeletingD309"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\NetShow.dat" [ ] "SpybotDeletingB4617"="command /c del C:\Program Files\DriveCleaner Free\Appbase\NTBackup.dat" [ ] "SpybotDeletingD8259"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\NTBackup.dat" [ ] "SpybotDeletingB175"="command /c del C:\Program Files\DriveCleaner Free\Appbase\PhotShel.dat" [ ] "SpybotDeletingD9894"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\PhotShel.dat" [ ] "SpybotDeletingB1545"="command /c del C:\Program Files\DriveCleaner Free\Appbase\PHPCoder.dat" [ ] "SpybotDeletingD1584"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\PHPCoder.dat" [ ] "SpybotDeletingB9926"="command /c del C:\Program Files\DriveCleaner Free\Appbase\PowerZIP.dat" [ ] "SpybotDeletingD1485"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\PowerZIP.dat" [ ] "SpybotDeletingB6416"="command /c del C:\Program Files\DriveCleaner Free\Appbase\RapidBr.dat" [ ] "SpybotDeletingD1197"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\RapidBr.dat" [ ] "SpybotDeletingB231"="command /c del C:\Program Files\DriveCleaner Free\Appbase\RealAuPl.dat" [ ] "SpybotDeletingD6767"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\RealAuPl.dat" [ ] "SpybotDeletingB6955"="command /c del C:\Program Files\DriveCleaner Free\Appbase\RealDown.dat" [ ] "SpybotDeletingD5562"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\RealDown.dat" [ ] "SpybotDeletingB6193"="command /c del C:\Program Files\DriveCleaner Free\Appbase\SecurCRT.dat" [ ] "SpybotDeletingD7674"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\SecurCRT.dat" [ ] "SpybotDeletingB3589"="command /c del C:\Program Files\DriveCleaner Free\Appbase\SL_BlWin.dat" [ ] "SpybotDeletingD8193"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\SL_BlWin.dat" [ ] "SpybotDeletingB1180"="command /c del C:\Program Files\DriveCleaner Free\Appbase\SmartClr.dat" [ ] "SpybotDeletingD7756"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\SmartClr.dat" [ ] "SpybotDeletingB2976"="command /c del C:\Program Files\DriveCleaner Free\Appbase\Sonique.dat" [ ] "SpybotDeletingD5859"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\Sonique.dat" [ ] "SpybotDeletingB6152"="command /c del C:\Program Files\DriveCleaner Free\Appbase\StuffIt.dat" [ ] "SpybotDeletingD6584"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\StuffIt.dat" [ ] "SpybotDeletingB1095"="command /c del C:\Program Files\DriveCleaner Free\Appbase\TelepPro.dat" [ ] "SpybotDeletingD8076"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\TelepPro.dat" [ ] "SpybotDeletingB4624"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UGifAnim.dat" [ ] "SpybotDeletingD2455"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UGifAnim.dat" [ ] "SpybotDeletingB3022"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UltraEd.dat" [ ] "SpybotDeletingD1562"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UltraEd.dat" [ ] "SpybotDeletingB4399"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UMedStud.dat" [ ] "SpybotDeletingD7481"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UMedStud.dat" [ ] "SpybotDeletingB48"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UPhImpV.dat" [ ] "SpybotDeletingD5271"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UPhImpV.dat" [ ] "SpybotDeletingB4430"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UPhotoEx.dat" [ ] "SpybotDeletingD8916"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UPhotoEx.dat" [ ] "SpybotDeletingB2183"="command /c del C:\Program Files\DriveCleaner Free\Appbase\UVidStud.dat" [ ] "SpybotDeletingD332"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\UVidStud.dat" [ ] "SpybotDeletingB400"="command /c del C:\Program Files\DriveCleaner Free\Appbase\VNC.dat" [ ] "SpybotDeletingD8703"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\VNC.dat" [ ] "SpybotDeletingB2604"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WebFeret.dat" [ ] "SpybotDeletingD2395"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WebFeret.dat" [ ] "SpybotDeletingB9262"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WebReap.dat" [ ] "SpybotDeletingD4192"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WebReap.dat" [ ] "SpybotDeletingB8388"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WinACE.dat" [ ] "SpybotDeletingD2543"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WinACE.dat" [ ] "SpybotDeletingB6530"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WinGate.dat" [ ] "SpybotDeletingD1319"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WinGate.dat" [ ] "SpybotDeletingB6305"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WinRAR.dat" [ ] "SpybotDeletingD5107"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WinRAR.dat" [ ] "SpybotDeletingB1949"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WinZIP.dat" [ ] "SpybotDeletingD2579"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WinZIP.dat" [ ] "SpybotDeletingB2075"="command /c del C:\Program Files\DriveCleaner Free\Appbase\WiseInst.dat" [ ] "SpybotDeletingD8802"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\WiseInst.dat" [ ] "SpybotDeletingB7113"="command /c del C:\Program Files\DriveCleaner Free\Appbase\wordslst.xda" [ ] "SpybotDeletingD2930"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\wordslst.xda" [ ] "SpybotDeletingB985"="command /c del C:\Program Files\DriveCleaner Free\Appbase\YahooPl.dat" [ ] "SpybotDeletingD5470"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\YahooPl.dat" [ ] "SpybotDeletingB7210"="command /c del C:\Program Files\DriveCleaner Free\Appbase\ZipMagic.dat" [ ] "SpybotDeletingD9595"="cmd /c del C:\Program Files\DriveCleaner Free\Appbase\ZipMagic.dat" [ ] "SpybotDeletingB2831"="command /c del C:\Program Files\Common Files\DriveCleaner Free\DNSE.exe" [ ] "SpybotDeletingD2628"="cmd /c del C:\Program Files\Common Files\DriveCleaner Free\DNSE.exe" [ ] "SpybotDeletingB1648"="command /c del C:\Program Files\DriveCleaner Free\ResErrors.log" [ ] "SpybotDeletingD8821"="cmd /c del C:\Program Files\DriveCleaner Free\ResErrors.log" [ ] "SpybotDeletingB3976"="command /c del C:\Program Files\DriveCleaner Free\Schedule.dat" [ ] "SpybotDeletingD5592"="cmd /c del C:\Program Files\DriveCleaner Free\Schedule.dat" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54 919016] "Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-08-01 17:16 4382720] [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM] --a------ 2006-08-01 14:35 67112 C:\Program Files\AIM\aim.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] --a------ 2004-10-18 17:42 79448 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer] --a------ 2004-10-20 08:40 34904 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] --a------ 2004-09-13 15:33 155648 C:\Program Files\Apoint\Apoint.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp] --a------ 2005-03-15 14:33 48752 C:\Program Files\Common Files\Symantec Shared\ccApp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-04 04:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dcsm] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Photo AIO Printer 942] --a------ 2005-02-03 02:08 294912 C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet] --a------ 2005-03-04 10:26 606208 C:\Program Files\Dell\QuickSet\quickset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellHelp] --a------ 2004-04-01 14:51 1589248 C:\Dell\DellHelp\DellHelp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellMCM] --a------ 2004-07-27 08:08 262144 C:\Program Files\Dell Photo AIO Printer 942\memcard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport] --a------ 2007-03-15 10:09 460784 C:\Program Files\DellSupport\DSAgnt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla] --a------ 2004-12-06 00:05 127035 C:\WINDOWS\system32\dla\tfswctrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DNSE] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] --------- 2005-02-23 15:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eazkzizq] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] --a------ 2004-11-03 15:03 125528 C:\Program Files\Common Files\AOL\1136532457\EE\AOLHostManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] --a------ 2005-02-15 14:02 126976 C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] --a------ 2005-02-15 14:02 155648 C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless] --a------ 2004-10-30 13:59 385024 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2004-07-27 15:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2004-07-27 15:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2007-03-14 18:05 257088 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask] --a------ 2004-09-14 07:50 53248 C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray] --a------ 2004-09-14 07:50 131072 C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup] C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] --------- 2004-04-11 19:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-02-16 09:54 282624 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] --a------ 2005-08-27 13:27 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wzdmg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] --a------ 2006-03-21 15:58 3325952 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zzzHPSETUP] D:\Setup.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "C:\\Program Files\\America Online 9.0\\waol.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\America Online 9.0a\\waol.exe"= "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"= "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"= "C:\\Program Files\\Common Files\\AOL\\1136532457\\EE\\AOLServiceHost.exe"= "C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"= "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"= "C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Internet Explorer\\iexplore.exe"= . Contents of the 'Scheduled Tasks' folder "2007-05-15 13:57:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-02-23 02:18:25 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Dee.job" - C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task: "2008-03-07 17:28:00 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDetect.exe . ************************************************** ************************ catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-07 11:41:10 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************** ************************ . Completion time: 2008-03-07 11:41:52 ComboFix-quarantined-files.txt 2008-03-07 17:41:43 ComboFix2.txt 2008-03-07 16:05:43 . 2007-12-29 01:59:35 --- E O F --- Despues de pasar el combofix y el Malbarebytes y limpiarlo con el ccleaner en modo seguro si puedo navegar ,ya sea por firefox o explorer,y puedo abrir mis correos,pero una vez que reseteo y vuelvo a arrancar en forma normal,todo para atras,pasa lo mismo,y aparece ese maldito megaclick....YA NO SE QUE HACER!!!!!POR FAVOR,AYUDA,y gracias desde ya. ![]() Última edición por scorpion666 fecha: 07/03/08 a las 11:50:45. Razón: Agregar informacion |
![]() | ![]() |
| ||||
| Re: No me abre ninguna pagina en explorer ni en firefox...ayuda!!!!!!!! Hola, la herramienta ComboFix no es para libre uso y sólo debe ejecutarse a pedido de una persona experimentada en su manejo, ya que su mal manejo puede ser perjudicial para el sistema. Sigue estos pasos: - Desactiva el Tea Timer y el Ad-Watch para que no interfieran en la limpieza y reinicia el sistema. - Desinstala todo lo relacionado a DriveCleaner Free y a New.Net 1.-Abrir el Notepad
2.- Ahora copia y pega este código dentro del Notepad Código HTML: KillAll:: Folder:: C:\Program Files\DriveCleaner Free\ C:\PROGRA~1\NEWDOT~1\ Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "SpybotDeletingB7036"=- "SpybotDeletingD3251"=- "SpybotDeletingB8817"=- "SpybotDeletingD5478"=- "SpybotDeletingB3646"=- "SpybotDeletingD5798"=- "SpybotDeletingB1609"=- "SpybotDeletingD3587"=- "SpybotDeletingB1489"=- "SpybotDeletingD8643"=- "SpybotDeletingB8886"= "SpybotDeletingD8195"=- "SpybotDeletingB3572"=- "SpybotDeletingD1741"=- "SpybotDeletingB6042"=- "SpybotDeletingD5091"=- "SpybotDeletingB4057"=- "SpybotDeletingD5075"=- "SpybotDeletingB9867"=- "SpybotDeletingD5220"=- "SpybotDeletingB3506"=- "SpybotDeletingD6791"=- "SpybotDeletingB4825"=- "SpybotDeletingD8009"=- "SpybotDeletingB7045"=- "SpybotDeletingD7872"=- "SpybotDeletingB1170"=- "SpybotDeletingD2846"=- "SpybotDeletingB4956"=- "SpybotDeletingD1895"=- "SpybotDeletingB9215"=- "SpybotDeletingD8461"=- "SpybotDeletingB2805"=- "SpybotDeletingD7706"=- "SpybotDeletingB2232"=- "SpybotDeletingD8779"=- "SpybotDeletingB4164"=- "SpybotDeletingD1076"=- "SpybotDeletingB422"="- "SpybotDeletingD5004"=- "SpybotDeletingB4464"=- "SpybotDeletingD1041"=- "SpybotDeletingB6817"=- "SpybotDeletingD3774"=- "SpybotDeletingB9328"=- "SpybotDeletingD1191"=- "SpybotDeletingB323"=- "SpybotDeletingD6058"=- "SpybotDeletingB2440"=- "SpybotDeletingD3301"=- "SpybotDeletingB5360"=- "SpybotDeletingD4110"=- "SpybotDeletingB2522"=- "SpybotDeletingD5010"=- "SpybotDeletingB7965"=- "SpybotDeletingD6516"=- "SpybotDeletingB7028"=- "SpybotDeletingD7856"=- "SpybotDeletingB5257"=- "SpybotDeletingD5917"=- "SpybotDeletingB9463"=- "SpybotDeletingD912"=- "SpybotDeletingB5573"=- "SpybotDeletingD5637"=- "SpybotDeletingB3573"=- "SpybotDeletingD5052"=- "SpybotDeletingB9221"=- "SpybotDeletingD3003"=- "SpybotDeletingB340"=- "SpybotDeletingD6328"=- "SpybotDeletingB2922"=- "SpybotDeletingD7053"=- "SpybotDeletingB3556"=- "SpybotDeletingD6664"=- "SpybotDeletingB7072"=- "SpybotDeletingD460"=- "SpybotDeletingB5127"=- "SpybotDeletingD1748"=- "SpybotDeletingB8686"=- "SpybotDeletingD9749"=- "SpybotDeletingB816"=- "SpybotDeletingD1304"=- "SpybotDeletingB3725"=- "SpybotDeletingD5411"=- "SpybotDeletingB8857"=- "SpybotDeletingD6752"=- "SpybotDeletingB7268"=- "SpybotDeletingD5207"=- "SpybotDeletingB4027"=- "SpybotDeletingD96"=- "SpybotDeletingB4920"=- "SpybotDeletingD4560"=- "SpybotDeletingB190"=- "SpybotDeletingD8241"=- "SpybotDeletingB4235"=- "SpybotDeletingD2381"=- "SpybotDeletingB3392"=- "SpybotDeletingD1203"=- "SpybotDeletingB7088"=- "SpybotDeletingD785"=- "SpybotDeletingB6858"=- "SpybotDeletingD2338"=- "SpybotDeletingB7279"=- "SpybotDeletingD8126"=- "SpybotDeletingB9751"=- "SpybotDeletingD309"=- "SpybotDeletingB4617"=- "SpybotDeletingD8259"=- "SpybotDeletingB175"=- "SpybotDeletingD9894"=- "SpybotDeletingB1545"=- "SpybotDeletingD1584"=- "SpybotDeletingB9926"=- "SpybotDeletingD1485"=- "SpybotDeletingB6416"=- "SpybotDeletingD1197"=- "SpybotDeletingB231"=- "SpybotDeletingD6767"=- "SpybotDeletingB6955"=- "SpybotDeletingD5562"=- "SpybotDeletingB6193"=- "SpybotDeletingD7674"=- "SpybotDeletingB3589"=- "SpybotDeletingD8193"=- "SpybotDeletingB1180"=- "SpybotDeletingD7756"=- "SpybotDeletingB2976"=- "SpybotDeletingD5859"=- "SpybotDeletingB6152"=- "SpybotDeletingD6584"=- "SpybotDeletingB1095"=- "SpybotDeletingD8076"=- "SpybotDeletingB4624"=- "SpybotDeletingD2455"=- "SpybotDeletingB3022"=- "SpybotDeletingD1562"=- "SpybotDeletingB4399"=- "SpybotDeletingD7481"=- "SpybotDeletingB48"=- "SpybotDeletingD5271"=- "SpybotDeletingB4430"=- "SpybotDeletingD8916"=- "SpybotDeletingB2183"=- "SpybotDeletingD332"=- "SpybotDeletingB400"=- "SpybotDeletingD8703"=- "SpybotDeletingB2604"=- "SpybotDeletingD2395"=- "SpybotDeletingB9262"=- "SpybotDeletingD4192"=- "SpybotDeletingB8388"=- "SpybotDeletingD2543"=- "SpybotDeletingB6530"=- "SpybotDeletingD1319"=- "SpybotDeletingB6305"=- "SpybotDeletingD5107"=- "SpybotDeletingB1949"=- "SpybotDeletingD2579"=- "SpybotDeletingB2075"=- "SpybotDeletingD8802"=- "SpybotDeletingB7113"=- "SpybotDeletingD2930"=- "SpybotDeletingB985"=- "SpybotDeletingD5470"=- "SpybotDeletingB7210"=- "SpybotDeletingD9595"=- "SpybotDeletingB2831"=- "SpybotDeletingD2628"=- "SpybotDeletingB1648"=- "SpybotDeletingD8821"=- "SpybotDeletingB3976"=- "SpybotDeletingD5592"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eazkzizq] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wzdmg] 4.- Arrastrar y soltar el archivo CFScript.txt dentro del archivo ComboFix.exe como lo muestra la animación de abajo. Esto activara ComboFix nuevamente. ![]() Reinicia y nos cuentas los resultados. junto con un nuevo reporte de ComboFix y uno de Hijackthis. Saludos ![]() Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: No me abre ninguna pagina en explorer ni en firefox...ayuda!!!!!!!! Cita:
|
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| me revisais el log? | puesyomismo | Foro Oficial de HijackThis en español | 7 | 05/01/07 18:35:22 |
| exmodul32f.i.exe troyano? (Formateo) | josealb2 | Temas Solucionados | 17 | 26/12/06 10:16:25 |
| problema con antivirus (Terminado) | sire180 | Temas Solucionados | 10 | 17/11/06 20:05:48 |
| Conime.exe (Solucionado) | dsaasd | Temas Solucionados | 13 | 03/09/06 21:00:15 |
| 2 iexplorer.exe | Birkoff_zero | Foro de Virus y Spywares | 4 | 15/08/06 20:14:55 |