• Registrarse
  • Iniciar sesión


  • Resultados 1 al 6 de 6

    pc muy lenta....

    Resumen del tema: pc muy lenta.... - hola,mi problema es que mi pc esta muy lenta y se demora en subir y abrir paginas aqui dejo mi log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:05:22 PM, on 3/25/2009 Platform: ...

    1. #1
      Usuario Avatar de cumshooter
      Registrado
      dic 2006
      Ubicación
      PR
      Mensajes
      36

      pc muy lenta....

      hola,mi problema es que mi pc esta muy
      lenta y se demora en subir y abrir paginas
      aqui dejo mi log:



      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:05:22 PM, on 3/25/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\BOOTVRFYN.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\SYSTEM32\BelkinMonitor.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\SYSTEM32\rundll32.exe
      C:\WINDOWS\SYSTEM32\taskmgr.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\AVG\AVG8\aAvgApi.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
      R3 - Default URLSearchHook is missing
      F2 - REG:system.ini: Shell=Explorer.exe,
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: BrowserConnector Object - {0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - C:\WINDOWS\system32\syssetupi.dll
      O2 - BHO: {53147b0e-d945-80b9-c534-7bab6edd54e1} - {1e45dde6-bab7-435c-9b08-549de0b74135} - C:\WINDOWS\system32\eoksbc.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {8b385487-b12f-4689-b1a2-f09525dfc948} - C:\WINDOWS\system32\wolijuke.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
      O3 - Toolbar: (no name) - {D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [24e4e8ce] rundll32.exe "C:\WINDOWS\system32\yazemiya.dll",b
      O4 - HKLM\..\Run: [CPM27d7db52] Rundll32.exe "c:\windows\system32\jutizowi.dll",a
      O4 - HKLM\..\RunServices: [wmplayer] p2pnetworking.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\RunOnce: [SpybotDeletingD9746] cmd.exe /c del "c:\windows\system32\jezegunu.dll_old"
      O4 - HKUS\S-1-5-19\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\RunOnce: [POSTRBT] (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [POSTRBT] (User 'Default user')
      O4 - Global Startup: Belkin 11Mbps Wireless Desktop Network Card Monitor.lnk = C:\WINDOWS\SYSTEM32\BelkinMonitor.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O8 - Extra context menu item: &Search - ?p=ZUfox000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
      O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://locator.cdn.imageservr.com
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-CL/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146332182953
      O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient_japan/SpinTopGamesLauncher.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: C:\WINDOWS\system32\dimsntfym.dll C:\WINDOWS\system32\nayazezi.dll c:\windows\system32\jezegunu.dll C:\WINDOWS\system32\suliweya.dll gojfvx.dll c:\windows\system32\jutizowi.dll eoksbc.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O20 - Winlogon Notify: URL - C:\WINDOWS\
      O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jutizowi.dll
      O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jutizowi.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: System kernel integrity service (Scprtn) - SearchHelp, Inc. - C:\WINDOWS\system32\BOOTVRFYN.EXE
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: Wyyo Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Wyyo\wyyo125.exe

      --
      End of file - 11134 bytes



      gracias de antemano

    2. #2
      Moderador
      Avatar de <¡D3vIL!>
      Registrado
      may 2006
      Ubicación
      Chile
      Mensajes
      10.807

      Re: pc muy lenta....

      Hola cumshooter, te doy la bienvenida al Foro de InfoSpyware.

      Realiza estos pasos

      Paso 1.- Descarga, Instala y/o actualiza estas herramientas: (pero no los ejecutes aun)

      Paso 2.- Con todos los programas cerrados, ejecuta HijackThis y dale a las siguientes entradas:

      • O2 - BHO: BrowserConnector Object - {0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - C:\WINDOWS\system32\syssetupi.dll
      • O2 - BHO: {53147b0e-d945-80b9-c534-7bab6edd54e1} - {1e45dde6-bab7-435c-9b08-549de0b74135} - C:\WINDOWS\system32\eoksbc.dll
      • O2 - BHO: (no name) - {8b385487-b12f-4689-b1a2-f09525dfc948} - C:\WINDOWS\system32\wolijuke.dll
      • O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)


      • O3 - Toolbar: (no name) - {D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)


      • O4 - HKLM\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s
      • O4 - HKLM\..\Run: [24e4e8ce] rundll32.exe "C:\WINDOWS\system32\yazemiya.dll",b
      • O4 - HKLM\..\Run: [CPM27d7db52] Rundll32.exe "c:\windows\system32\jutizowi.dll",a
      • O4 - HKLM\..\RunServices: [wmplayer] p2pnetworking.exe
      • O4 - HKCU\..\RunOnce: [SpybotDeletingD9746] cmd.exe /c del "c:\windows\system32\jezegunu.dll_old"
      • O4 - HKUS\S-1-5-19\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s (User 'LOCAL SERVICE')
      • O4 - HKUS\S-1-5-20\..\Run: [pirelikeme] Rundll32.exe "C:\WINDOWS\system32\hihogufe.dll",s (User 'NETWORK SERVICE')


      • O8 - Extra context menu item: &Search - ?p=ZUfox000


      • O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
      • O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)


      • O20 - AppInit_DLLs: C:\WINDOWS\system32\dimsntfym.dll C:\WINDOWS\system32\nayazezi.dll c:\windows\system32\jezegunu.dll C:\WINDOWS\system32\suliweya.dll gojfvx.dll c:\windows\system32\jutizowi.dll eoksbc.dll
      • O20 - Winlogon Notify: URL - C:\WINDOWS\


      • O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jutizowi.dll

      • O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jutizowi.dll


      • O23 - Service: Wyyo Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Wyyo\wyyo125.exe



      Paso 3.- Ejecuta estas herramientas, de a una:
      • Malwarebytes' Anti-Malware
        *Nota* Es importante que envíes a "Cuarentena" todo lo que este detecte antes de copiar y pegarnos su reporte.

      • Antes de usar ComboFix....
      • Desactiva temporalmente el Antivirus y/o Antispyware.
      • Cierra todas las ventanas abiertas.
      • Hacele doble clic al archivo ComboFix.exe y seguí las instrucciones.
      • Cuando termine, generara un registro en C:\ComboFix.txt.
        • *Nota* Mientras CF este trabajando no mover el mouse ya que pararía su proceso.
        • *Nota*ComboFix puede reiniciar automáticamente el PC para completar el proceso de eliminación.


      Paso 4.- Descarga CCleaner y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad).

      Paso 5.- Reinicia el PC y nos dejas los reportes de:
      • HijackThis
      • Malwarebytes' Anti-Malware
      • C:\ComboFix.txt en este mismo mensaje.


      **Nota **
      - Para mayor comodidad imprime los pasos.
      - Recuerda regresar y contarnos los resultados.

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    3. #3
      Usuario Avatar de cumshooter
      Registrado
      dic 2006
      Ubicación
      PR
      Mensajes
      36

      Re: pc muy lenta....

      aqui estan los logs:



      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 4:18:39 PM, on 3/25/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\BOOTVRFYN.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\AVG\AVG8\avgcsrvx.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\RunOnce: [SpybotDeletingD9746] cmd.exe /c del "c:\windows\system32\jezegunu.dll_old"
      O4 - Global Startup: Belkin 11Mbps Wireless Desktop Network Card Monitor.lnk = C:\WINDOWS\SYSTEM32\BelkinMonitor.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://locator.cdn.imageservr.com
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-CL/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146332182953
      O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://download-games.pogo.com/online2/pogo/mahjong_escape_ancient_japan/SpinTopGamesLauncher.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: System kernel integrity service (Scprtn) - SearchHelp, Inc. - C:\WINDOWS\system32\BOOTVRFYN.EXE
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      --
      End of file - 8285 bytes






      ComboFix 09-03-23.01 - CHILENA 2009-03-25 15:58:57.1 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.123 [GMT -4:00]
      Running from: c:\documents and settings\CHILENA\My Documents\ComboFix.exe
      AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
      * Created a new restore point
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\CHILENA\Application Data\FNTS~1
      c:\documents and settings\CHILENA\Application Data\Sskdmns.dll
      c:\documents and settings\CHILENA\Application Data\STEM~1
      c:\documents and settings\CHILENA\Application Data\YSTEM~1
      c:\documents and settings\CHILENA\My Documents\CROSOF~1
      c:\documents and settings\CHILENA\My Documents\MBOLS~1
      c:\documents and settings\CHILENA\My Documents\PPPATC~1
      c:\documents and settings\CHILENA\My Documents\PPPATC~1\??mbols\
      c:\documents and settings\CHILENA\My Documents\PPPATC~1\??pPatch\
      c:\documents and settings\CHILENA\My Documents\SEMBLY~1
      c:\program files\Common Files\{24E4E~1
      c:\program files\Common Files\asembl~1
      c:\program files\Common Files\simtest
      c:\program files\Common Files\svchostsys
      c:\program files\Common Files\svchostsys\svchostsys.exe.config
      c:\program files\Common Files\svchostsys\svchostupdate.exe.config
      c:\program files\Common Files\svchostsys\Version.txt
      c:\program files\Common Files\ymbols~1
      c:\program files\crosof~1.net
      c:\program files\outlook
      c:\program files\tclock\tclock_install.exe
      c:\program files\windows
      c:\windows\crosof~1
      c:\windows\dobe~1
      c:\windows\fnts~1
      c:\windows\racle~1
      c:\windows\system32\ayimezay.ini
      c:\windows\system32\besohaki.dll
      c:\windows\SYSTEM32\bqtjon.dll
      c:\windows\system32\bszip.dll
      c:\windows\system32\eoksbc.dll
      c:\windows\system32\fekidafa.dll
      c:\windows\system32\geehsr.dll
      c:\windows\system32\gojfvx.dll
      c:\windows\system32\hamewina.dll
      c:\windows\system32\hihogufe.dll
      c:\windows\system32\icroso~1.net
      c:\windows\system32\ikahoseb.ini
      c:\windows\system32\iyepafiy.ini
      c:\windows\system32\jutizowi.dll
      c:\windows\system32\mantec~1
      c:\windows\system32\mozulavo.dll
      c:\windows\system32\muhodogu.dll
      c:\windows\system32\nayazezi.dll.vir
      c:\windows\system32\nevihezu.dll
      c:\windows\system32\pefideyi.dll
      c:\windows\system32\sojepefe.dll
      c:\windows\system32\sstem3~1
      c:\windows\system32\suliweya.dll
      c:\windows\system32\supokazi.dll
      c:\windows\system32\tapeyeni.dll
      c:\windows\system32\taskkill.com
      c:\windows\system32\taskkill.exe
      c:\windows\system32\tb.dr
      c:\windows\system32\tvtugp.dll
      c:\windows\system32\vnpqka.dll
      c:\windows\system32\wcptr.exe
      c:\windows\system32\wolijuke.dll
      c:\windows\SYSTEM32\xbeeg.bak1
      c:\windows\SYSTEM32\xbeeg.bak2
      c:\windows\system32\xbeeg.ini
      c:\windows\system32\xbeeg.ini2
      c:\windows\SYSTEM32\xbeeg.tmp
      c:\windows\system32\xknpckqb.ini
      c:\windows\system32\yazemiya.dll
      c:\windows\system32\zibuyiri.dll
      c:\windows\system32\zifirobo.dll
      c:\windows\win32077361898142006.exe
      c:\windows\win32083618981472006.exe

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_WINDOWS_OVERLAY_COMPONENTS


      ((((((((((((((((((((((((( Files Created from 2009-02-25 to 2009-03-25 )))))))))))))))))))))))))))))))
      .

      2009-03-25 12:04 . 2009-03-25 12:04 <DIR> d-------- c:\program files\Trend Micro
      2009-03-24 23:38 . 2009-03-25 01:50 <DIR> d--h----- C:\$AVG8.VAULT$
      2009-03-24 23:25 . 2009-03-24 23:25 <DIR> d-------- c:\windows\SYSTEM32\DRIVERS\Avg
      2009-03-24 23:25 . 2009-03-25 00:02 <DIR> d-------- c:\documents and settings\CHILENA\Application Data\AVGTOOLBAR
      2009-03-24 23:25 . 2009-03-24 23:25 325,640 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
      2009-03-24 23:25 . 2009-03-24 23:25 107,912 --a------ c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
      2009-03-24 23:25 . 2009-03-24 23:25 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
      2009-03-24 23:24 . 2009-03-24 23:24 <DIR> d-------- c:\program files\AVG
      2009-03-24 23:24 . 2009-03-24 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
      2009-03-23 19:56 . 2009-03-23 19:56 <DIR> d-------- c:\program files\WinAVI Video Converter
      2009-03-23 19:53 . 2009-03-23 19:55 <DIR> d-------- c:\program files\WinAVI Video Capture
      2009-03-23 17:30 . 2009-03-23 17:30 <DIR> d-------- c:\documents and settings\CHILENA\Application Data\Media Player Classic
      2009-03-23 17:28 . 2009-03-23 17:28 <DIR> d-------- c:\program files\Real Alternative
      2009-03-19 00:55 . 2009-03-19 14:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
      2009-03-16 23:20 . 2009-03-16 23:20 <DIR> d-------- c:\documents and settings\CHILENA\Application Data\Memeo
      2009-03-16 23:19 . 2009-03-16 23:23 <DIR> d-------- c:\program files\Common Files\eSellerate
      2009-03-02 17:20 . 2009-03-02 17:20 <DIR> d-------- c:\program files\uTorrent
      2009-03-02 17:20 . 2009-03-18 14:40 <DIR> d-------- c:\documents and settings\CHILENA\Application Data\uTorrent

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-03-25 19:59 --------- d-----w c:\program files\TClock
      2009-03-24 16:20 --------- d-----w c:\program files\Spybot - Search & Destroy
      2009-03-24 04:22 --------- d-----w c:\program files\QuickTime
      2009-03-24 04:20 --------- d-----w c:\program files\IZArc
      2009-03-24 04:17 --------- d-----w c:\program files\OpenOffice.org 2.3
      2009-03-24 04:11 --------- d-----w c:\program files\Windows Live
      2009-03-24 01:37 --------- d-----w c:\documents and settings\CHILENA\Application Data\OpenOffice.org2
      2009-03-19 07:15 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2009-03-12 23:06 --------- d-----w c:\documents and settings\CHILENA\Application Data\Image Zone Express
      2009-03-12 22:34 --------- d-----w c:\program files\Wyyo
      2009-03-11 13:49 --------- d-----w c:\documents and settings\All Users\Application Data\Wyyo
      2009-02-15 23:44 --------- d-----w c:\program files\Freeze.com
      2009-02-15 03:03 --------- d-----w c:\program files\Microsoft
      2009-02-15 02:55 --------- d-----w c:\program files\Common Files\Windows Live
      2009-02-13 20:30 --------- d-----w c:\program files\MySpace
      2009-02-07 00:03 307,576 ----a-w c:\windows\WLXPGSS.SCR
      2009-02-01 18:56 --------- d-----w c:\program files\Winferno
      2009-01-29 22:44 --------- d-----w c:\documents and settings\CHILENA\Application Data\Walgreens
      1989-12-12 14:10 520,000 -csh--r c:\windows\jiyrzxk.exe
      2007-02-02 03:21 965,330 -csh--w c:\windows\Microsoft.NET\mcps.bak1
      2007-02-03 02:23 969,664 -csh--w c:\windows\Microsoft.NET\mcps.bak2
      2007-02-03 03:45 989,117 -csh--w c:\windows\Microsoft.NET\mcps.ini2
      2008-08-06 22:10 32,768 -csha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008080620080807\index.dat
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
      "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
      "SpybotDeletingD9746"="del" [X]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
      "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
      "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
      "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-10-08 458752]
      "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
      "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
      "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-24 1932568]

      c:\documents and settings\All Users\Start Menu\Programs\Startup\
      Belkin 11Mbps Wireless Desktop Network Card Monitor.lnk - c:\windows\SYSTEM32\BelkinMonitor.exe [2005-09-02 372736]
      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
      Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-20 67128]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
      2009-03-24 23:25 10520 c:\windows\SYSTEM32\avgrsstx.dll

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KmReg]
      @="Event log"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NtLclIpc]
      @="Event log"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Scprtn]
      @="Service"

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "UpdatesDisableNotify"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

      R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2009-03-24 325640]
      R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2009-03-24 107912]
      R1 KmReg;System kernel configuration;c:\windows\SYSTEM32\NTIOY804.SYS [2009-01-26 38784]
      R1 NtLclIpc;Remote Procedure Call RT4s;c:\windows\SYSTEM32\ANSIY.SYS [2009-01-26 131072]
      R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-24 908056]
      R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-24 298264]
      R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
      R2 Scprtn;System kernel integrity service;c:\windows\SYSTEM32\BOOTVRFYN.EXE [2009-01-26 185856]
      R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-05-27 24652]
      R3 BEL6001P;Belkin 11Mbps Wireless Desktop Adapter (F5D6001 V.2);c:\windows\SYSTEM32\DRIVERS\BEL6001P.sys [2005-09-02 78720]
      S3 MmedFilter;MmedFilter;\??\c:\windows\system32\Drivers\MmedFilter.sys --> c:\windows\system32\Drivers\MmedFilter.sys [?]
      S3 pcand5bk;PCAND5BK PCANDIS5 Protocol Driver;c:\windows\SYSTEM32\PCAND5BK.SYS [2005-09-02 15104]
      S4 Wyyo Service;Wyyo Service;c:\documents and settings\All Users\Application Data\Wyyo\wyyo125.exe [2009-03-11 54752]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5b7f4-f612-11d9-bf40-00038a000015}]
      \Shell\AutoRun\command - E:\setupSNK.exe
      .
      Contents of the 'Scheduled Tasks' folder

      2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

      2009-03-25 c:\windows\Tasks\PCConfidential.job
      - c:\program files\Winferno\PC Confidential\PCConfidential.exe []

      2009-03-25 c:\windows\Tasks\User_Feed_Synchronization-{3C9BB55C-CC45-4766-99D1-052ABC6F3A01}.job
      - c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
      .
      - - - - ORPHANS REMOVED - - - -

      BHO-{0D84AC30-5186-4CD9-8FD8-4A1382D5F0F3} - (no file)
      BHO-{8b385487-b12f-4689-b1a2-f09525dfc948} - c:\windows\system32\wolijuke.dll
      BHO-{f94d8063-7cf6-47b4-becd-ce97963c8678} - (no file)
      WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)
      HKU-Default-RunOnce-POSTRBT - (no file)
      Notify-URL - (no file)


      .
      ------- Supplementary Scan -------
      .
      uInternet Connection Wizard,ShellNext = iexplore
      uInternet Settings,ProxyOverride = 127.0.0.1;localhost
      Trusted Zone: imageservr.com\locator.cdn
      Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://download-games.pogo.com/online2/pogo/mahjong_escape_ancient_japan/SpinTopGamesLauncher.cab
      FF - ProfilePath - c:\documents and settings\CHILENA\Application Data\Mozilla\Firefox\Profiles\d1sqdppl.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?v=1&q=
      FF - prefs.js: browser.search.selectedEngine - Google
      FF - prefs.js: browser.startup.homepage -
      FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?v=1&q=
      FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
      FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
      FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
      FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
      FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

      ---- FIREFOX POLICIES ----
      FF - user.js: yahoo.homepage.dontask - true.

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-03-25 16:05:32
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      c:\windows\SYSTEM32\HPZipm12.exe
      c:\program files\Logitech\Video\FxSvr2.exe
      c:\progra~1\AVG\AVG8\avgrsx.exe
      c:\progra~1\AVG\AVG8\avgnsx.exe
      c:\program files\HP\Digital Imaging\bin\hpqste08.exe
      c:\program files\AVG\AVG8\avgcsrvx.exe
      c:\program files\iPod\bin\iPodService.exe
      c:\windows\SYSTEM32\wscntfy.exe
      .
      **************************************************************************
      .
      Completion time: 2009-03-25 16:12:09 - machine was rebooted [CHILENA]
      ComboFix-quarantined-files.txt 2009-03-25 20:11:32

      Pre-Run: 14,750,175,232 bytes free
      Post-Run: 14,705,811,456 bytes free

      WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

      258 --- E O F --- 2008-12-10 23:05:36

    4. #4
      Usuario Avatar de cumshooter
      Registrado
      dic 2006
      Ubicación
      PR
      Mensajes
      36

      Re: pc muy lenta....

      alguna ayuda aqui?

    5. #5
      Moderador
      Avatar de <¡D3vIL!>
      Registrado
      may 2006
      Ubicación
      Chile
      Mensajes
      10.807

      Re: pc muy lenta....

      Hola cumshooter

      Antes de comenzar te cuento que ForoSpyware lo mantenemos voluntarios que tenemos nuestros trabajos y obligaciones fuera, por lo que no estamos 24/7, a lo que te pedimos paciencia en el análisis y respuesta de tu caso. Si luego de dejarnos los nuevos reporten pasaran mas de 48hrs y no obtengas otra respuesta de mi parte, me puedes enviar un MP (Mensaje Privado) de recordatorio.

      Haber, con todos los programas cerrados ejecuta HijackThis y dale "FIX Cheked" a estas entradas:

      • O4 - HKCU\..\RunOnce: [SpybotDeletingD9746] cmd.exe /c del "c:\windows\system32\jezegunu.dll_old"


      La unica entrada que faltaria dar FIX, tiene otro problema o sigues con el mismo problema dinos como va la cosa.

      Salu2

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    6. #6
      Usuario Avatar de cumshooter
      Registrado
      dic 2006
      Ubicación
      PR
      Mensajes
      36

      Re: pc muy lenta....

      muchas gracias,ya esta resulto el problema...