![]() |
| |||||||
| Temas Solucionados Casos de HijackThis y Malwares resueltos. (Solo lectura) |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| no hay forma le pase todos los programas q decis aqui le puse en modo prueba de fallos le rece a san @ y na no hay forma se siguen abriendo las jodidas ventanitas a ve si me ayudais q toy q me tiro de los pelos gracias Logfile of HijackThis v1.99.1 Scan saved at 11:42:32, on 04/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Archivos de programa\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\odClientService.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSrvc.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Archivos de programa\CPUCooL\CooLSrv.exe C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe C:\ARCHIV~1\NORTON~1\NORTON~1\NPROTECT.EXE C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\SAVScan.exe C:\ARCHIV~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE C:\WINDOWS\system32\svchost.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\Archivos de programa\Apoint2K\Apoint.exe C:\Archivos de programa\Power Manager\PM.exe C:\Archivos de programa\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\OdTray.exe C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe C:\Archivos de programa\Microsoft AntiSpyware\gcasServ.exe C:\Archivos de programa\Apoint2K\Apntex.exe C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe C:\WINDOWS\system32\hkcmd.exe C:\Archivos de programa\Microsoft AntiSpyware\gcasDtServ.exe C:\Archivos de programa\Java\jre1.5.0_05\bin\jusched.exe C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE C:\Archivos de programa\Common Files\VCClient\VCMain.exe C:\Archivos de programa\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe C:\Archivos de programa\palmOne\Palm.exe C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE C:\Archivos de programa\HJT\HijackThis.exe C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.es R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/ O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [Apoint] C:\Archivos de programa\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [PowerManager] C:\Archivos de programa\Power Manager\PM.exe O4 - HKLM\..\Run: [OdTray.exe] "C:\Archivos de programa\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\OdTray.exe" O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [gcasServ] "C:\Archivos de programa\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [ccApp] "C:\Archivos de programa\Archivos comunes\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_05\bin\jusched.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE" O4 - HKCU\..\Run: [CU2] C:\Archivos de programa\Common Files\VCClient\VCMain.exe O4 - Global Startup: Picture Package VCD Maker.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Google Search - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Crear un favorito móvil - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\inetrepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\inetrepl.dll O9 - Extra 'Tools' menuitem: Crear un favorito móvil... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\inetrepl.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131219161065 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/fs5/ax/ActiveXWebCam.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{34C551E7-545E-42D7-845D-01BB3FAB9F44}: NameServer = 192.168.10.1 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARCHIV~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\fpno0353e.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\ccSetMgr.exe O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:\Archivos de programa\CPUCooL\CooLSrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Servicio Auto-Protect de Norton AntiVirus (navapsvc) - Symantec Corporation - C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\ARCHIV~1\NORTON~1\NORTON~1\NPROTECT.EXE O23 - Service: Odyssey Client for Fujitsu Siemens Computers (odClientService) - Funk Software, Inc. - C:\Archivos de programa\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens Computers\odClientService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Archivos de programa\Norton SystemWorks\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARCHIV~1\ARCHIV~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\ARCHIV~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE O23 - Service: Symantec Core LC - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Archivos de programa\TuneUp Utilities 2006\WinStylerThemeSvc.exe |
![]() | ![]() |
| ||||
| Re: ventanas q se abren solas no hay forma Hola!!! Descarga L2mfix : 1) Guarda el archivo en el escritorio y dale doble click a l2mfix.exe. 2) Dale click al botón Install para extraer los archivos y sigue las indicaciones. 3) Abre la carpeta l2mfix que acaba de crearse en tu escritorio. Dale doble click a l2mfix.bat y elige la opción número 1 para ejecutar "Run Find Log" (Crear informe de búsqueda) pulsando 1 y Enter. 4) A continuación comenzará el análisis y se abrirá el bloc de notas con un informe, el cual nos debes pegar aquí. IMPORTANTE!!!: NO ejecutes la opción número 2 o ningún otro archivo de la carpeta l2mfix hasta que te lo indique. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: ventanas q se abren solas no hay forma muchas gracias x la ayuda ya no sabia q mas hacer L2MFIX find log 010406 These are the registry keys present ************************************************** ******************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33, 00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e, 00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OdysseyClient] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000001 "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "DllName"=hex(2):6f,00,64,00,79,00,45,00,76,00,65, 00,6e,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OdysseyClient\ev ent] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run-] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\fp6403jqe.dl l" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEven t" "Logoff"="UnregisterTicketExpiredNotificationEvent " "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ************************************************** ******************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform] "{A1E55ACA-C736-12AA-FDCA-D75818EA3507}"="" ************************************************** ******************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Hoja de propiedades de archivos multimedia" "{176d6597-26d3-11d1-b350-080036a75b03}"="Administraci¢n de esc*ner ICM" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="P*gina de seguridad NTFS" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="P*gina de propiedades del archivo de documentos OLE" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensiones de interfaz para uso compartido" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del adaptador de pantalla" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del monitor de pantalla" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="P*gina de seguridad DS" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="P*gina de compatibilidad" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extensi¢n de copia de discos" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensiones del shell para objetos de la red de Microsoft Windows" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Administraci¢n de monitor ICM" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Administraci¢n de impresora ICM" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extensi¢n del shell de impresora en Web" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Malet¡n" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extensi¢n de icono de HyperTerminal" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fuentes" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Perfil de ICC" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="P*gina de seguridad de impresoras" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensiones de interfaz para uso compartido" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n PKO cifrada" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n de firma cifrada" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Conexiones de red" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Conexiones de red" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&C*maras y esc*neres" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&C*maras y esc*neres" "{905667aa-acd6-11d2-8080-00805f6596d2}"="&C*maras y esc*neres" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&C*maras y esc*neres" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&C*maras y esc*neres" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensiones del shell para Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="V¡nculos a datos de Microsoft" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tareas programadas" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barra de tareas y men£ Inicio" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Buscar" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ejecutar..." "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Correo electr¢nico" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fuentes" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Herramientas administrativas" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barra de herramientas de Microsoft Internet" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Estado de la descarga" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Carpeta Shell aumentada" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Carpeta 2 Shell aumentada" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Banda del explorador de Microsoft" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Banda de b£squeda" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="B£squeda en panel" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="B£squeda Web" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilidad de opciones del *rbol de Registro" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Direcci¢n" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Cuadro de la direcci¢n" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Autocompletar de Microsoft" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="Lista autocompleta MRU" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Lista autocompleta MRU personalizada" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barra de progreso emergente" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lista autocompleta de la historia de Microsoft" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Lista autocompleta de la carpeta Shell de Microsoft" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Contenedor de la Lista m£ltiple de Microsoft" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Men£ de sitio de bandas Shell" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barra de escritorio Shell" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Asistencia al usuario" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Configuraci¢n de carpeta global" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Servicio de Historial de las direcciones URL de Microsoft" "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historial" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Hook de b£squeda de direcciones URL de Microsoft" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Pantalla de bienvenida de IE4 Suite" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Banda de Explorador" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="Carpeta del cach‚ de ActiveX" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Carpeta de suscripciones" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Administrador de aplicaciones de Shell" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Enumerador de aplicaciones instaladas" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extractor de vistas en miniatura de archivos GDI+" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Controlador de la informaci¢n de resumen para vistas en miniatura (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extractor de vistas en miniatura HTML" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Asistente para la publicaci¢n en Web" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Pedido de impresiones v¡a web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objeto de Asistente de publicaci¢n de shell" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Asistente para obtener pasaporte" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Cuentas de usuario" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Archivo de canal" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Acceso directo al canal" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Objeto de control de canal" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Carpeta de archivos sin conexi¢n" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Personas..." "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu" "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension" "{2B3453E4-49DF-11D3-8229-0080BE509050}"="GMail Drive" "{2B3453E4-49DF-11D3-8229-0080BE509052}"="GMailFS Property Sheet" "{2B3453E4-49DF-11D3-8229-0080BE509054}"="GMailFS Drop Handler" "{2B3453E4-49DF-11D3-8229-0080BE509056}"="GMailFS Context Menu" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}"="TuneUp Shredder Shell Context Menu Extension" "{3C88B7C0-1CC9-439C-B933-BDEEADBAA4C3}"="" "{226D4187-49D5-46C2-B83D-230DE8C81097}"="" "{A7D47271-5856-4F2C-B8D2-6DB658BCC25C}"="" "{E14DB2A6-7016-42F4-B10D-D7356AF0021B}"="" "{E005489B-A21B-4C2C-B543-9973A791ED38}"="" "{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}"="" ************************************************** ******************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\InprocServer32] @="C:\\WINDOWS\\system32\\rngapi.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\InprocServer32] @="C:\\WINDOWS\\system32\\guard.tmp" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\InprocServer32] @="C:\\WINDOWS\\system32\\LECMP11n.DLL" "ThreadingModel"="Apartment" ************************************************** ******************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ avisynth.dll Fri 7 Oct 2005 18:14:52 A.... 308.224 301,00 K browseui.dll Thu 24 Nov 2005 1:01:52 ..... 1.022.464 998,50 K cdfview.dll Fri 21 Oct 2005 4:41:04 A.... 151.552 148,00 K danim.dll Sat 5 Nov 2005 4:17:26 A.... 1.056.256 1,00 M divx.dll Wed 7 Dec 2005 18:05:52 A.... 573.952 560,50 K divx_x~1.dll Wed 7 Dec 2005 18:05:50 A.... 679.936 664,00 K divx_x~2.dll Wed 7 Dec 2005 18:05:50 A.... 679.936 664,00 K divx_x~3.dll Wed 7 Dec 2005 18:05:50 A.... 663.552 648,00 K dpl100.dll Thu 27 Oct 2005 20:37:46 A.... 86.016 84,00 K dpu10.dll Thu 27 Oct 2005 20:37:44 A.... 294.912 288,00 K dpu11.dll Thu 27 Oct 2005 20:37:44 A.... 294.912 288,00 K dpugui10.dll Thu 27 Oct 2005 20:37:48 A.... 53.248 52,00 K dpugui11.dll Thu 27 Oct 2005 20:37:46 A.... 593.920 580,00 K dpus11.dll Thu 27 Oct 2005 20:37:44 A.... 339.968 332,00 K dpv11.dll Thu 27 Oct 2005 20:37:44 A.... 57.344 56,00 K dtu100.dll Thu 27 Oct 2005 20:37:44 A.... 200.704 196,00 K dxtrans.dll Fri 21 Oct 2005 4:41:04 A.... 205.312 200,50 K esent.dll Thu 20 Oct 2005 23:26:00 A.... 1.095.168 1,04 M extmgr.dll Fri 21 Oct 2005 4:41:04 A.... 55.808 54,50 K fp6403~1.dll Thu 5 Jan 2006 18:16:58 ..S.R 236.729 231,18 K g2220c~1.dll Thu 5 Jan 2006 18:49:02 ..S.R 233.920 228,44 K gccoll~1.dll Tue 15 Nov 2005 12:12:08 A.... 126.680 123,71 K gcunco~1.dll Tue 15 Nov 2005 12:12:06 A.... 95.448 93,21 K hashlib.dll Tue 15 Nov 2005 12:12:08 A.... 117.976 115,21 K iepeers.dll Fri 21 Oct 2005 4:41:04 A.... 251.392 245,50 K inseng.dll Fri 21 Oct 2005 4:41:06 A.... 96.768 94,50 K legitc~1.dll Fri 4 Nov 2005 16:27:24 A.... 534.280 521,76 K mshtml.dll Thu 24 Nov 2005 1:01:54 A.... 3.013.632 2,87 M mshtmled.dll Fri 21 Oct 2005 4:41:06 A.... 448.512 438,00 K msrating.dll Fri 21 Oct 2005 4:41:08 A.... 146.432 143,00 K mstime.dll Fri 21 Oct 2005 4:41:08 A.... 530.944 518,50 K odgina~1.dll Sat 5 Nov 2005 20:29:28 A.... 417.792 408,00 K odyevent.dll Sat 5 Nov 2005 20:29:28 A.... 106.496 104,00 K odygina.dll Sat 5 Nov 2005 20:29:30 A.... 118.784 116,00 K pncrt.dll Fri 16 Dec 2005 1:09:48 A.... 278.528 272,00 K pndx5016.dll Fri 16 Dec 2005 1:09:48 A.... 6.656 6,50 K pndx5032.dll Fri 16 Dec 2005 1:09:48 A.... 5.632 5,50 K pngfilt.dll Fri 21 Oct 2005 4:41:08 A.... 39.424 38,50 K rmoc3260.dll Fri 16 Dec 2005 1:09:52 A.... 176.167 172,04 K s32evnt1.dll Thu 1 Dec 2005 12:14:20 A.... 86.091 84,07 K shdocvw.dll Thu 1 Dec 2005 5:01:16 A.... 1.492.992 1,42 M shlwapi.dll Fri 21 Oct 2005 4:41:08 A.... 474.112 463,00 K sirenacm.dll Thu 13 Oct 2005 0:11:06 A.... 118.784 116,00 K spmsg.dll Thu 13 Oct 2005 0:13:28 ..... 15.584 15,22 K tsccvid.dll Tue 25 Oct 2005 10:22:26 A.... 102.400 100,00 K urlmon.dll Sat 5 Nov 2005 4:17:30 A.... 605.184 591,00 K wininet.dll Fri 21 Oct 2005 4:41:08 A.... 660.992 645,50 K winsusrm.dll Fri 2 Dec 2005 17:32:04 A.... 264 0,26 K winsusrx.dll Fri 2 Dec 2005 16:43:16 A.... 120 0,12 K __dele~1.dll Thu 5 Jan 2006 18:51:20 A.... 236.729 231,18 K 50 items found: 50 files (2 H/S), 0 directories. Total of file sizes: 19.188.628 bytes 18,30 M Locate .tmp files: C:\WINDOWS\SYSTEM32\ guard.tmp Thu 5 Jan 2006 19:31:20 ..S.R 236.729 231,18 K 1 item found: 1 file (1 H/S), 0 directories. Total of file sizes: 236.729 bytes 231,18 K ************************************************** ******************************** Directory Listing of system files: El volumen de la unidad C es 434301 El n£mero de serie del volumen es: 38E6-C041 Directorio de C:\WINDOWS\System32 05/01/2006 07:31 236.729 guard.tmp 05/01/2006 06:55 <DIR> dllcache 05/01/2006 06:49 233.920 g2220cfoef2c0.dll 05/01/2006 06:16 236.729 fp6403jqe.dll 05/10/2005 05:48 <DIR> Microsoft 30/09/1999 07:21 166.672 mstext35.dll 28/09/1999 09:42 1.050.896 msjet35.dll 09/09/1999 10:06 252.688 msexcl35.dll 09/09/1999 10:06 168.720 msltus35.dll 25/08/1999 02:57 415.504 msrepl35.dll 10/06/1999 09:34 24.848 msjter35.dll 10/06/1999 09:34 123.664 msjint35.dll 07/06/1999 06:59 250.128 mspdox35.dll 25/04/1999 05:00 287.504 Msxbse35.dll 25/04/1999 05:00 368.912 Vbar332.dll 25/04/1999 05:00 252.176 Msrd2x35.dll 14 archivos 4.069.090 bytes 2 dirs 22.549.094.400 bytes libres |
![]() | ![]() |
| ||||
| Re: ventanas q se abren solas no hay forma Cierra todos los programas incluido el navegador y abre la carpeta l2mfix que hay en tu escritorio. Dale doble click a l2mfix.bat, selecciona la opción numero 2 (Run Fix), dale Enter y luego a cualquier tecla para que se reinicie el sistema. Después de que reinicie el Pc puede que los iconos y parte del escritorio no se vean (esto es normal). L2mfix continuará explorando el sistema y cuando termine se abre nuevamente el bloc de notas con un nuevo registro el cual tienes que pegarlo en este mensaje para ver como quedó. Junto a este registro déjanos tambien un nuevo log de HijackThis. Saludos Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() | ![]() |
| |||
| Re: ventanas q se abren solas no hay forma weno pues esto es lo q me da el L2MFIX L2MFIX find log 010406 These are the registry keys present ************************************************** ******************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33, 00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e, 00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OdysseyClient] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000001 "Startup"="WLEventStartup" "Shutdown"="WLEventShutdown" "Logon"="WLEventLogon" "Logoff"="WLEventLogoff" "DllName"=hex(2):6f,00,64,00,79,00,45,00,76,00,65, 00,6e,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OdysseyClient\ev ent] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run-] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\fp6403jqe.dl l" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69, 00,66,00,79,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEven t" "Logoff"="UnregisterTicketExpiredNotificationEvent " "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 ************************************************** ******************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform] "{A1E55ACA-C736-12AA-FDCA-D75818EA3507}"="" ************************************************** ******************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Shell Extensions\Approved] "{00022613-0000-0000-C000-000000000046}"="Hoja de propiedades de archivos multimedia" "{176d6597-26d3-11d1-b350-080036a75b03}"="Administraci¢n de esc ner ICM" "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="P gina de seguridad NTFS" "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="P gina de propiedades del archivo de documentos OLE" "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensiones de interfaz para uso compartido" "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension" "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del adaptador de pantalla" "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extensi¢n CPL del monitor de pantalla" "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="P gina de seguridad DS" "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="P gina de compatibilidad" "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler" "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extensi¢n de copia de discos" "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensiones del shell para objetos de la red de Microsoft Windows" "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Administraci¢n de monitor ICM" "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Administraci¢n de impresora ICM" "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extensi¢n del shell de impresora en Web" "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI" "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Malet¡n" "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extensi¢n de icono de HyperTerminal" "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fuentes" "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Perfil de ICC" "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="P gina de seguridad de impresoras" "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensiones de interfaz para uso compartido" "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension" "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n PKO cifrada" "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extensi¢n de firma cifrada" "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Conexiones de red" "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Conexiones de red" "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&C maras y esc neres" "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&C maras y esc neres" "{905667aa-acd6-11d2-8080-00805f6596d2}"="&C maras y esc neres" "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&C maras y esc neres" "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&C maras y esc neres" "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension" "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensiones del shell para Windows Script Host" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="V¡nculos a datos de Microsoft" "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler" "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension" "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tareas programadas" "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults" "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension" "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barra de tareas y men£ Inicio" "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Buscar" "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico" "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ayuda y soporte t‚cnico" "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ejecutar..." "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet" "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Correo electr¢nico" "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fuentes" "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Herramientas administrativas" "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page" "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions" "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler" "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler" "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler" "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler" "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler" "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor" "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barra de herramientas de Microsoft Internet" "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Estado de la descarga" "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Carpeta Shell aumentada" "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Carpeta 2 Shell aumentada" "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy" "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Banda del explorador de Microsoft" "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Banda de b£squeda" "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="B£squeda en panel" "{07798131-AF23-11d1-9111-00A0C98BA67D}"="B£squeda Web" "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilidad de opciones del rbol de Registro" "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Direcci¢n" "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Cuadro de la direcci¢n" "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Autocompletar de Microsoft" "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor" "{6756A641-DE71-11d0-831B-00AA005B4383}"="Lista autocompleta MRU" "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Lista autocompleta MRU personalizada" "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible" "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barra de progreso emergente" "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Lista autocompleta de la historia de Microsoft" "{03C036F1-A186-11D0-824A-00AA005B4383}"="Lista autocompleta de la carpeta Shell de Microsoft" "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Contenedor de la Lista m£ltiple de Microsoft" "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Men£ de sitio de bandas Shell" "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp" "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barra de escritorio Shell" "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite" "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Asistencia al usuario" "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Configuraci¢n de carpeta global" "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band" "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service" "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer" "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture" "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut" "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Servicio de Historial de las direcciones URL de Microsoft" "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historial" "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet" "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Archivos temporales de Internet" "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Hook de b£squeda de direcciones URL de Microsoft" "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Pantalla de bienvenida de IE4 Suite" "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook" "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC" "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC" "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet" "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space" "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Banda de Explorador" "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service" "{88C6C381-2E85-11D0-94DE-444553540000}"="Carpeta del cach‚ de ActiveX" "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr" "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Carpeta de suscripciones" "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent" "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent" "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent" "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent" "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent" "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler" "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Administrador de aplicaciones de Shell" "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Enumerador de aplicaciones instaladas" "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher" "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs" "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory" "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow" "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extractor de vistas en miniatura de archivos GDI+" "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Controlador de la informaci¢n de resumen para vistas en miniatura (DOCFILES)" "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extractor de vistas en miniatura HTML" "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler" "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Asistente para la publicaci¢n en Web" "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Pedido de impresiones v¡a web" "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objeto de Asistente de publicaci¢n de shell" "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Asistente para obtener pasaporte" "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Cuentas de usuario" "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler" "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target" "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Archivo de canal" "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Acceso directo al canal" "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Objeto de control de canal" "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu" "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties" "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder" "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview" "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext" "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control" "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control" "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control" "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control" "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control" "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI" "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object" "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find" "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find" "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI" "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs" "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook" "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target" "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties" "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu" "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options" "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Carpeta de archivos sin conexi¢n" "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler" "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell" "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%" "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler" "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer" "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Personas..." "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler" "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler" "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices" "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu" "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension" "{2B3453E4-49DF-11D3-8229-0080BE509050}"="GMail Drive" "{2B3453E4-49DF-11D3-8229-0080BE509052}"="GMailFS Property Sheet" "{2B3453E4-49DF-11D3-8229-0080BE509054}"="GMailFS Drop Handler" "{2B3453E4-49DF-11D3-8229-0080BE509056}"="GMailFS Context Menu" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band" "{00DF1F20-0849-A4D1-0239-00D0AF3E9CB0}"="TuneUp Shredder Shell Context Menu Extension" "{3C88B7C0-1CC9-439C-B933-BDEEADBAA4C3}"="" "{226D4187-49D5-46C2-B83D-230DE8C81097}"="" "{A7D47271-5856-4F2C-B8D2-6DB658BCC25C}"="" "{E14DB2A6-7016-42F4-B10D-D7356AF0021B}"="" "{E005489B-A21B-4C2C-B543-9973A791ED38}"="" "{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}"="" ************************************************** ******************************** HKEY ROOT CLASSIDS: Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E14DB2A6-7016-42F4-B10D-D7356AF0021B}\InprocServer32] @="C:\\WINDOWS\\system32\\rngapi.dll" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E005489B-A21B-4C2C-B543-9973A791ED38}\InprocServer32] @="C:\\WINDOWS\\system32\\guard.tmp" "ThreadingModel"="Apartment" Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{C9D9BADD-84E9-466C-B5DF-C8C84EABB657}\InprocServer32] @="C:\\WINDOWS\\system32\\LECMP11n.DLL" "ThreadingModel"="Apartment" ************************************************** ******************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ avisynth.dll Fri 7 Oct 2005 18:14:52 A.... 308.224 301,00 K browseui.dll Thu 24 Nov 2005 1:01:52 ..... 1.022.464 998,50 K cdfview.dll Fri 21 Oct 2005 4:41:04 A.... 151.552 148,00 K danim.dll Sat 5 Nov 2005 4:17:26 A.... 1.056.256 1,00 M divx.dll Wed 7 Dec 2005 18:05:52 A.... 573.952 560,50 K divx_x~1.dll Wed 7 Dec 2005 18:05:50 A.... 679.936 664,00 K divx_x~2.dll Wed 7 Dec 2005 18:05:50 A.... 679.936 664,00 K divx_x~3.dll Wed 7 Dec 2005 18:05:50 A.... 663.552 648,00 K dpl100.dll Thu 27 Oct 2005 20:37:46 A.... 86.016 84,00 K dpu10.dll Thu 27 Oct 2005 20:37:44 A.... 294.912 288,00 K dpu11.dll Thu 27 Oct 2005 20:37:44 A.... 294.912 288,00 K dpugui10.dll Thu 27 Oct 2005 20:37:48 A.... 53.248 52,00 K dpugui11.dll Thu 27 Oct 2005 20:37:46 A.... 593.920 580,00 K dpus11.dll Thu 27 Oct 2005 20:37:44 A.... 339.968 332,00 K dpv11.dll Thu 27 Oct 2005 20:37:44 A.... 57.344 56,00 K dtu100.dll Thu 27 Oct 2005 20:37:44 A.... 200.704 196,00 K dxtrans.dll Fri 21 Oct 2005 4:41:04 A.... 205.312 200,50 K esent.dll Thu 20 Oct 2005 23:26:00 A.... 1.095.168 1,04 M extmgr.dll Fri 21 Oct 2005 4:41:04 A.... 55.808 54,50 K fp6403~1.dll Thu 5 Jan 2006 18:16:58 ..S.R 236.729 231,18 K g2220c~1.dll Thu 5 Jan 2006 18:49:02 ..S.R 233.920 228,44 K gccoll~1.dll Tue 15 Nov 2005 12:12:08 A.... 126.680 123,71 K gcunco~1.dll Tue 15 Nov 2005 12:12:06 A.... 95.448 93,21 K hashlib.dll Tue 15 Nov 2005 12:12:08 A.... 117.976 115,21 K iepeers.dll Fri 21 Oct 2005 4:41:04 A.... 251.392 245,50 K inseng.dll Fri 21 Oct 2005 4:41:06 A.... 96.768 94,50 K legitc~1.dll Fri 4 Nov 2005 16:27:24 A.... 534.280 521,76 K mshtml.dll Thu 24 Nov 2005 1:01:54 A.... 3.013.632 2,87 M mshtmled.dll Fri 21 Oct 2005 4:41:06 A.... 448.512 438,00 K msrating.dll Fri 21 Oct 2005 4:41:08 A.... 146.432 143,00 K mstime.dll Fri 21 Oct 2005 4:41:08 A.... 530.944 518,50 K odgina~1.dll Sat 5 Nov 2005 20:29:28 A.... 417.792 408,00 K odyevent.dll Sat 5 Nov 2005 20:29:28 A.... 106.496 104,00 K odygina.dll Sat 5 Nov 2005 20:29:30 A.... 118.784 116,00 K pncrt.dll Fri 16 Dec 2005 1:09:48 A.... 278.528 272,00 K pndx5016.dll Fri 16 Dec 2005 1:09:48 A.... 6.656 6,50 K pndx5032.dll Fri 16 Dec 2005 1:09:48 A.... 5.632 5,50 K pngfilt.dll Fri 21 Oct 2005 4:41:08 A.... 39.424 38,50 K rmoc3260.dll Fri 16 Dec 2005 1:09:52 A.... 176.167 172,04 K s32evnt1.dll Thu 1 Dec 2005 12:14:20 A.... 86.091 84,07 K shdocvw.dll Thu 1 Dec 2005 5:01:16 A.... 1.492.992 1,42 M shlwapi.dll Fri 21 Oct 2005 4:41:08 A.... 474.112 463,00 K sirenacm.dll Thu 13 Oct 2005 0:11:06 A.... 118.784 116,00 K spmsg.dll Thu 13 Oct 2005 0:13:28 ..... 15.584 15,22 K tsccvid.dll Tue 25 Oct 2005 10:22:26 A.... 102.400 100,00 K urlmon.dll Sat 5 Nov 2005 4:17:30 A.... 605.184 591,00 K wininet.dll Fri 21 Oct 2005 4:41:08 A.... 660.992 645,50 K winsusrm.dll Fri 2 Dec 2005 17:32:04 A.... 264 0,26 K winsusrx.dll Fri 2 Dec 2005 16:43:16 A.... 120 0,12 K __dele~1.dll Thu 5 Jan 2006 18:51:20 A.... 236.729 231,18 K 50 items found: 50 files (2 H/S), 0 directories. Total of file sizes: 19.188.628 bytes 18,30 M Locate .tmp files: C:\WINDOWS\SYSTEM32\ guard.tmp Thu 5 Jan 2006 19:31:20 ..S.R 236.729 231,18 K 1 item found: 1 file (1 H/S), 0 directories. Total of file sizes: 236.729 bytes 231,18 K ************************************************** ******************************** Directory Listing of system files: El volumen de la unidad C es 434301 El n£mero de serie del volumen es: 38E6-C041 Directorio de C:\WINDOWS\System32 05/01/2006 07:31 236.729 guard.tmp 05/01/2006 06:55 <DIR> dllcache 05/01/2006 06:49 233.920 g2220cfoef2c0.dll 05/01/2006 06:16 236.729 fp6403jqe.dll 05/10/2005 05:48 <DIR> Microsoft 30/09/1999 07:21 166.672 mstext35.dll 28/09/1999 09:42 1.050.896 msjet35.dll 09/09/1999 10:06 252.688 msexcl35.dll 09/09/1999 10:06 168.720 msltus35.dll 25/08/1999 02:57 415.504 msrepl35.dll 10/06/1999 09:34 24.848 msjter35.dll 10/06/1999 09:34 123.664 msjint35.dll 07/06/1999 06:59 250.128 mspdox35.dll 25/04/1999 05:00 287.504 Msxbse35.dll 25/04/1999 05:00 368.912 Vbar332.dll 25/04/1999 05:00 252.176 Msrd2x35.dll 14 archivos 4.069.090 bytes 2 dirs 22.549.094.400 bytes libres -------------------------------------------------------------------------- El caso es q ya no me salen ventanas pero cuando paso el panda online de SpyXposer me da como q tengo esto : Adware:adware/secure32 No desinfectado C:\WINDOWS\system32\drivers\etc\hosts |
![]() | ![]() |
| |||
| Re: ventanas q se abren solas no hay forma -------------------------------------------------------------------------- y esto es lo q tiene mi hosts: # Copyright (c) 1993-1999 Microsoft Corp. # Éste es un ejemplo de archivo HOSTS usado por Microsoft TCP/IP para Windows. # Este archivo contiene las asignaciones de las direcciones IP a los nombres de # host. Cada entrada debe permanecer en una línea individual. La dirección IP # debe ponerse en la primera columna, seguida del nombre de host correspondiente. # La dirección IP y el nombre de host deben separarse con al menos un espacio. # También pueden insertarse comentarios (como éste) en líneas individuales # o a continuación del nombre de equipo indicándolos con el símbolo "#" # Por ejemplo: # 102.54.94.97 rhino.acme.com # servidor origen # 38.25.63.10 x.acme.com # host cliente x 127.0.0.1 localhost 127.0.0.1 sds-qckads.com 127.0.0.1 status.qckads.com 127.0.0.1 www.qoolaid.com 127.0.0.1 www.qoologic.com 127.0.0.1 www.CLKPrecision.com 127.0.0.1 www.urllogic.com 127.0.0.1 www.clkoptimizer.com 127.0.0.1 www.isearch.com 127.0.0.1 isearch.com 127.0.0.1 www.idownload.com 127.0.0.1 idownload.com 127.0.0.1 www.mytotalsearch.com 127.0.0.1 mytotalsearch.com 127.0.0.1 www.lop.com 127.0.0.1 lop.com 127.0.0.1 www.websearch.com 127.0.0.1 websearch.com 127.0.0.1 www.page-not-found.net 127.0.0.1 page-not-found.net 127.0.0.1 www.isearchhere.com 127.0.0.1 isearchhere.com 127.0.0.1 as.adwave.com 127.0.0.1 sr.adwave.com 127.0.0.1 www.adwave.com 127.0.0.1 adwave.com 127.0.0.1 www.pacimedia.com 127.0.0.1 www.exactsearch.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 www.contextplus.net 127.0.0.1 1.httpdads.com #SpySweeperCASS 127.0.0.1 207-87-18-203.wsmg.digex.net #SpySweeperCASS 127.0.0.1 a.mktw.net #SpySweeperCASS 127.0.0.1 a.tribalfusion.com #SpySweeperCASS 127.0.0.1 a207.p.f.qz3.net #SpySweeperCASS 127.0.0.1 a3.suntimes.com #SpySweeperCASS 127.0.0.1 actionsplash.com #SpySweeperCASS 127.0.0.1 ad.abcnews.com #SpySweeperCASS 127.0.0.1 ad.adsmart.net #SpySweeperCASS 127.0.0.1 ad.adtraq.com #SpySweeperCASS 127.0.0.1 ad.atlas.cz #SpySweeperCASS 127.0.0.1 ad.au.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.be.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.blm.net #SpySweeperCASS 127.0.0.1 ad.ca.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.ch.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.de.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.dogpile.com #SpySweeperCASS 127.0.0.1 ad.doubleclick.com #SpySweeperCASS 127.0.0.1 ad.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.fr.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.harmony-central.com #SpySweeperCASS 127.0.0.1 ad.horvitznewspapers.net #SpySweeperCASS 127.0.0.1 ad.howstuffworks.com #SpySweeperCASS 127.0.0.1 ad.img.yahoo.co.kr #SpySweeperCASS 127.0.0.1 ad.infoseek.com #SpySweeperCASS 127.0.0.1 ad.iwin.com #SpySweeperCASS 127.0.0.1 ad.jp.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.kimo.com.tw #SpySweeperCASS 127.0.0.1 ad.linkexchange.com #SpySweeperCASS 127.0.0.1 ad.linksynergy.com #SpySweeperCASS 127.0.0.1 ad.moscowtimes.ru #SpySweeperCASS 127.0.0.1 ad.net-service.de #SpySweeperCASS 127.0.0.1 ad.nl.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.no.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.openfind.com.tw #SpySweeperCASS 127.0.0.1 ad.preferances.com #SpySweeperCASS 127.0.0.1 ad.preferences.com #SpySweeperCASS 127.0.0.1 ad.sales.olympics.com #SpySweeperCASS 127.0.0.1 ad.se.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.sg.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.sma.punto.net #SpySweeperCASS 127.0.0.1 ad.tomshardware.com #SpySweeperCASS 127.0.0.1 ad.trafficmp.com #SpySweeperCASS 127.0.0.1 ad.uk.doubleclick.net #SpySweeperCASS 127.0.0.1 ad.usatoday.com #SpySweeperCASS 127.0.0.1 ad.vol.at #SpySweeperCASS 127.0.0.1 ad.washingtonpost.com #SpySweeperCASS 127.0.0.1 ad.webprovider.com #SpySweeperCASS 127.0.0.1 ad01.mediacorpsingapore.com #SpySweeperCASS 127.0.0.1 ad08.focalink.com #SpySweeperCASS 127.0.0.1 ad1.aaddzz.com #SpySweeperCASS 127.0.0.1 ad1.peel.comwww.xbn.ru #SpySweeperCASS 127.0.0.1 ad10.doubleclick.net #SpySweeperCASS 127.0.0.1 ad11.doubleclick.net #SpySweeperCASS 127.0.0.1 ad12.doubleclick.net #SpySweeperCASS 127.0.0.1 ad13.doubleclick.net #SpySweeperCASS 127.0.0.1 ad14.doubleclick.net #SpySweeperCASS 127.0.0.1 ad15.doubleclick.net #SpySweeperCASS 127.0.0.1 ad16.doubleclick.net #SpySweeperCASS 127.0.0.1 ad17.doubleclick.net #SpySweeperCASS 127.0.0.1 ad18.doubleclick.net #SpySweeperCASS 127.0.0.1 ad19.doubleclick.net #SpySweeperCASS 127.0.0.1 ad2.adcept.net #SpySweeperCASS 127.0.0.1 ad2.doubleclick.net #SpySweeperCASS 127.0.0.1 ad2.peel.com #SpySweeperCASS 127.0.0.1 ad20.doubleclick.net #SpySweeperCASS 127.0.0.1 ad3.doubleclick.net #SpySweeperCASS 127.0.0.1 ad3.peel.com #SpySweeperCASS 127.0.0.1 ad4.doubleclick.net #SpySweeperCASS 127.0.0.1 ad5.doubleclick.net #SpySweeperCASS 127.0.0.1 ad6.doubleclick.net #SpySweeperCASS 127.0.0.1 ad7.doubleclick.net #SpySweeperCASS 127.0.0.1 ad7.internetadserver.com #SpySweeperCASS 127.0.0.1 ad8.doubleclick.net #SpySweeperCASS 127.0.0.1 ad9.doubleclick.net #SpySweeperCASS 127.0.0.1 ad-adex3.flycast.com #SpySweeperCASS 127.0.0.1 adbanner.sweepsclub.com #SpySweeperCASS 127.0.0.1 adbot.com #SpySweeperCASS 127.0.0.1 adbureau.net #SpySweeperCASS 127.0.0.1 adcodes.bla-bla.com #SpySweeperCASS 127.0.0.1 adcontent.gamespy.com #SpySweeperCASS 127.0.0.1 adcontroller.unicast.com #SpySweeperCASS 127.0.0.1 adcount.hollywood.com #SpySweeperCASS 127.0.0.1 adcreative.tribuneinteractive.com #SpySweeperCASS 127.0.0.1 adcreatives.imaginemedia.com #SpySweeperCASS 127.0.0.1 add.yaho.com #SpySweeperCASS 127.0.0.1 adengine.theglobe.com #SpySweeperCASS 127.0.0.1 adex3.flycast.com #SpySweeperCASS 127.0.0.1 adfarm.mediaplex.com #SpySweeperCASS 127.0.0.1 adforce.ads.imgis.com #SpySweeperCASS 127.0.0.1 adforce.adtech.de #SpySweeperCASS 127.0.0.1 adforce.imgis.com #SpySweeperCASS 127.0.0.1 adfu.blockstackers.com #SpySweeperCASS 127.0.0.1 adi.mainichi.co.jp #SpySweeperCASS 127.0.0.1 adimage.asia1.com.sg #SpySweeperCASS 127.0.0.1 adimage.asiaone.com.sg #SpySweeperCASS 127.0.0.1 adimage.bankrate.com #SpySweeperCASS 127.0.0.1 adimage.blm.net #SpySweeperCASS 127.0.0.1 adimages.earthweb.com #SpySweeperCASS 127.0.0.1 adimages.go.com #SpySweeperCASS 127.0.0.1 adimg.com.com #SpySweeperCASS 127.0.0.1 adimg.egroups.com #SpySweeperCASS 127.0.0.1 adimg1.chosun.com #SpySweeperCASS 127.0.0.1 adlink.deh.de #SpySweeperCASS 127.0.0.1 adlog.com.com #SpySweeperCASS 127.0.0.1 adlui001.adlink.de #SpySweeperCASS 127.0.0.1 admedia.xoom.com #SpySweeperCASS 127.0.0.1 adng.ascii24.com #SpySweeperCASS 127.0.0.1 adpick.switchboard.com #SpySweeperCASS 127.0.0.1 adpop.theglobe.com #SpySweeperCASS 127.0.0.1 adpulse.ads.targetnet.com #SpySweeperCASS 127.0.0.1 adremote.pathfinder.com #SpySweeperCASS 127.0.0.1 ads*.focalink.com #SpySweeperCASS 127.0.0.1 ads.1for1.com #SpySweeperCASS 127.0.0.1 ads.adflight.com #SpySweeperCASS 127.0.0.1 ads.ad-flow.com #SpySweeperCASS 127.0.0.1 ads.admaximize.com #SpySweeperCASS 127.0.0.1 ads.admonitor.net #SpySweeperCASS 127.0.0.1 ads.adtegrity.net #SpySweeperCASS 127.0.0.1 ads.advance.net #SpySweeperCASS 127.0.0.1 ads.adviva.net #SpySweeperCASS 127.0.0.1 ads.amazingmedia.com #SpySweeperCASS 127.0.0.1 ads.as4x.tmcs.net #SpySweeperCASS 127.0.0.1 ads.astalavista.us #SpySweeperCASS 127.0.0.1 ads.belointeractive.com #SpySweeperCASS 127.0.0.1 ads.bfast.com #SpySweeperCASS 127.0.0.1 ads.bianca.com #SpySweeperCASS 127.0.0.1 ads.bigcitytools.com #SpySweeperCASS 127.0.0.1 ads.bitsonthewire.com #SpySweeperCASS 127.0.0.1 ads.bloomberg.com #SpySweeperCASS 127.0.0.1 ads.cashsurfers.com #SpySweeperCASS 127.0.0.1 ads.cbc.ca #SpySweeperCASS 127.0.0.1 ads.centralohio.com #SpySweeperCASS 127.0.0.1 ads.clearbluemedia.com #SpySweeperCASS 127.0.0.1 ads.clearchannel.com #SpySweeperCASS 127.0.0.1 ads.clickagents.com #SpySweeperCASS 127.0.0.1 ads.clickhouse.com #SpySweeperCASS 127.0.0.1 ads.colo.kiva.net #SpySweeperCASS 127.0.0.1 ads.columbian.com #SpySweeperCASS 127.0.0.1 ads.courierpostonline.com #SpySweeperCASS 127.0.0.1 ads.criticalmass.com #SpySweeperCASS 127.0.0.1 ads.csi.emcweb.com #SpySweeperCASS 127.0.0.1 ads.currantbun.com #SpySweeperCASS 127.0.0.1 ads.dai.net #SpySweeperCASS 127.0.0.1 ads.democratandchronicle.com #SpySweeperCASS 127.0.0.1 ads.desmoinesregister.com #SpySweeperCASS 127.0.0.1 ads.detelefoongids.nl #SpySweeperCASS 127.0.0.1 ads.developershed.com #SpySweeperCASS 127.0.0.1 ads.devx.com #SpySweeperCASS 127.0.0.1 ads.digitalmedianet.com #SpySweeperCASS 127.0.0.1 ads.discovery.com #SpySweeperCASS 127.0.0.1 ads.doubleclick.com #SpySweeperCASS 127.0.0.1 ads.doubleclick.net #SpySweeperCASS 127.0.0.1 ads.ecircles.com #SpySweeperCASS 127.0.0.1 ads.enliven.com #SpySweeperCASS 127.0.0.1 ads.erotism.com #SpySweeperCASS 127.0.0.1 ads.eu.msn.com #SpySweeperCASS 127.0.0.1 ads.exhedra.com #SpySweeperCASS 127.0.0.1 ads.fairfax.com.au #SpySweeperCASS 127.0.0.1 ads.filez.com #SpySweeperCASS 127.0.0.1 ads.floridatoday.com #SpySweeperCASS 127.0.0.1 ads.fool.com #SpySweeperCASS 127.0.0.1 ads.forbes.com #SpySweeperCASS 127.0.0.1 ads.forbes.net #SpySweeperCASS 127.0.0.1 ads.fortunecity.com #SpySweeperCASS 127.0.0.1 ads.fredericksburg.com #SpySweeperCASS 127.0.0.1 ads.freshmeat.net #SpySweeperCASS 127.0.0.1 ads.gameanswers.com #SpySweeperCASS 127.0.0.1 ads.gamespy.com #SpySweeperCASS 127.0.0.1 ads.globeandmail.com #SpySweeperCASS 127.0.0.1 ads.god.co.uk #SpySweeperCASS 127.0.0.1 ads.granadamedia.com #SpySweeperCASS 127.0.0.1 ads.greensboro.com #SpySweeperCASS 127.0.0.1 ads.guardian.co.uk #SpySweeperCASS 127.0.0.1 ads.guardianunlimited.co.uk #SpySweeperCASS 127.0.0.1 ads.hitcents.com #SpySweeperCASS 127.0.0.1 ads.hollywood.com #SpySweeperCASS 127.0.0.1 ads.hyperbanner.net #SpySweeperCASS 127.0.0.1 ads.i33.com #SpySweeperCASS 127.0.0.1 ads.iafrica.com #SpySweeperCASS 127.0.0.1 ads.iambic.com #SpySweeperCASS 127.0.0.1 ads.icq.com #Spy |