![]() |
| |||||||
| Foro Oficial de HijackThis en español Analizamos tu log de HijackThis para eliminar Hijackers, Spyware, Adware, ToolBars, Virus, Troyanos y Malwares en gral. Antes lea las Políticas del Foro de HijackThis. |
![]() |
| | Herramientas |
![]() | ![]() |
| |||
| Logfile of HijackThis v1.99.1 Scan saved at 08:08:02 p.m., on 13/06/05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\ATLMG.EXE C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE C:\ARCHIVOS DE PROGRAMA\NETWORK ASSOCIATES\VIRUSSCAN\AVSYNMGR.EXE C:\WINDOWS\SYSTEM\MDM.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\SYSGH.EXE C:\WINDOWS\EXPLORER.EXE C:\ARCHIVOS DE PROGRAMA\ZONE LABS\ZONEALARM\ZLCLIENT.EXE C:\WINDOWS\LOADQM.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\RUNDLL32.EXE C:\WINDOWS\ANVSHELL.EXE C:\WINDOWS\SYSTEM\CMR.EXE C:\ARCHIVOS DE PROGRAMA\NETWORK ASSOCIATES\VIRUSSCAN\VSSTAT.EXE C:\ARCHIVOS DE PROGRAMA\NETWORK ASSOCIATES\VIRUSSCAN\AVCONSOL.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\MSXC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\ATLMG.EXE C:\ARCHIVOS DE PROGRAMA\NETWORK ASSOCIATES\VIRUSSCAN\VSHWIN32.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\ARCHIVOS DE PROGRAMA\MOZILLA FIREFOX\FIREFOX.EXE C:\WINDOWS\SYSTEM\IESA.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\ATLMG.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\ESCRITORIO\BROOD_GARM2\HIJACK THIS\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=localhost:1043 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\ARCHIVOS DE PROGRAMA\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\SYSTEM\BRIDGE.DLL O2 - BHO: Class - {B7B608A1-3C0D-13E8-78EE-41C5182942D9} - C:\WINDOWS\SYSTEM\MFCAW32.DLL O2 - BHO: Class - {0DC955CF-6038-C66F-8C89-325BB89B4B32} - C:\WINDOWS\SYSTEM\NTQN32.DLL O2 - BHO: Class - {D199E121-7C3B-041C-38EE-1EC2DB4BFA8D} - C:\WINDOWS\SYSTEM\D3FV.DLL O2 - BHO: Class - {FC8CAC2E-E32B-0FD0-16A5-10FEAEDA2D44} - C:\WINDOWS\IPQM32.DLL O2 - BHO: Class - {C4322B27-0B19-D263-F955-4B1DF8B80E2E} - C:\WINDOWS\NTTZ.DLL O2 - BHO: Class - {B901C34F-49B0-8A0B-D0FC-6B347CE1F3F0} - C:\WINDOWS\SYSTEM\SDKZC32.DLL O2 - BHO: Class - {8A71C47B-9917-B588-625B-79254D40A325} - C:\WINDOWS\IEKY32.DLL O2 - BHO: Class - {C6D6D264-D1BF-2B26-E95A-909FFD54938F} - C:\WINDOWS\SDKKT.DLL O2 - BHO: Class - {D6D41230-B4B7-D9FC-EDDA-A50821C38898} - C:\WINDOWS\SYSTEM\NTTA.DLL O2 - BHO: Class - {16CE9345-E97C-9903-46A0-6FBEE12FCD33} - C:\WINDOWS\IPVO.DLL O2 - BHO: Class - {EDCBB3FD-788F-D69A-C205-FAE58398A2D6} - C:\WINDOWS\IPKQ32.DLL O2 - BHO: Class - {13C3D1A3-A53A-6BFB-F6CA-8FA7292FE0F0} - C:\WINDOWS\SDKYR.DLL O2 - BHO: Class - {2A67970B-4CAA-474C-81A3-091789DA44E2} - C:\WINDOWS\WINBA32.DLL O2 - BHO: Class - {71604D4E-04BE-AC2F-9285-3BDCB48262EA} - C:\WINDOWS\SYSTEM\IPUC32.DLL O2 - BHO: Class - {DA81932E-29FB-B935-6516-E875DF84849C} - C:\WINDOWS\WINZJ.DLL O2 - BHO: Class - {69A8956B-7ACA-79FD-92BF-5F3E74F6063C} - C:\WINDOWS\SYSTEM\SYSOE32.DLL O2 - BHO: Class - {843F1365-75DF-8C62-2A68-0FBD9E681AFE} - C:\WINDOWS\SYSTEM\ADDJB32.DLL O2 - BHO: Class - {6DF861D0-BA9B-A44C-C0CF-FBF8C53F788C} - C:\WINDOWS\NETLB32.DLL O2 - BHO: Class - {6CC20879-C19B-36EE-23FF-A64629ED9B7E} - C:\WINDOWS\SYSTEM\CRAK.DLL O2 - BHO: Class - {0F8EB263-D23D-B227-0B4D-E0CDFED83FF4} - C:\WINDOWS\SYSTEM\MSTM32.DLL O2 - BHO: Class - {625A3020-0C09-DD3E-5940-A24D5AF0E210} - C:\WINDOWS\SYSTEM\SDKGW32.DLL O2 - BHO: Class - {F6EE85DC-5845-7F00-8948-5648F4D9CAC5} - C:\WINDOWS\SYSTEM\MFCPL32.DLL O2 - BHO: Class - {CBCD81C3-5DC7-B253-6CB6-D4DCDCB4A988} - C:\WINDOWS\APPSP.DLL O2 - BHO: Class - {E3828D84-4E06-2C16-3DD3-0FB832F75880} - C:\WINDOWS\MSSA.DLL O2 - BHO: Class - {9F97B6E9-C174-2E0C-BAF8-5BB263486A64} - C:\WINDOWS\ATLKN32.DLL O2 - BHO: Class - {E2FF7285-6F6F-9283-CBCD-D4E370856A52} - C:\WINDOWS\NTBZ32.DLL O2 - BHO: Class - {2D884AA4-5362-6D9F-DBFC-16455C462B7B} - C:\WINDOWS\SYSPO.DLL O2 - BHO: Class - {CFE85B4A-22AA-786D-10A6-8C8EABB85CE4} - C:\WINDOWS\SYSTEM\APIBQ.DLL O2 - BHO: Class - {3516BA73-6D3D-BE5D-10FF-AD33BF11BB40} - C:\WINDOWS\SYSTEM\D3KX32.DLL O2 - BHO: Class - {967871F3-038A-F72E-C5FF-CE710FAFDEA8} - C:\WINDOWS\CRUJ32.DLL O2 - BHO: Class - {D3DD24BD-375D-1229-E7E9-92878A1D7DBE} - C:\WINDOWS\WINFN32.DLL O2 - BHO: Class - {F3229D57-F62B-1F6E-54F4-EAF76321F1C8} - C:\WINDOWS\MFCSP.DLL O2 - BHO: Class - {A486CC8D-4D69-0934-1BCA-4CAF770BA94E} - C:\WINDOWS\SYSTEM\APICH32.DLL O2 - BHO: Class - {6CC45311-CFEB-E078-79D6-2ED797DCF228} - C:\WINDOWS\SYSTEM\NETLQ32.DLL O2 - BHO: Class - {5BA8ED10-55C0-B29D-A8F3-E37E146D4B4A} - C:\WINDOWS\SYSTEM\MFCJL32.DLL O2 - BHO: Class - {D800AD07-3198-4760-E8A4-33F3BB42B482} - C:\WINDOWS\APPCN.DLL O2 - BHO: Class - {E3394C70-FCAF-52D8-D7BC-D6A3A175F490} - C:\WINDOWS\NTCK.DLL O2 - BHO: Class - {67837E43-EFA1-5C25-5079-728566B2822D} - C:\WINDOWS\SYSTEM\SYSBP32.DLL O2 - BHO: Class - {E735AC74-28A4-0705-2A77-4CF61C5B76F1} - C:\WINDOWS\SYSTEM\IEPE32.DLL O2 - BHO: Class - {B850B1D0-7AA0-61EC-ECFE-A372B0057E40} - C:\WINDOWS\SYSTEM\WINPR.DLL O2 - BHO: Class - {A59EE127-10FE-394A-52D8-3E8D49F05B49} - C:\WINDOWS\IPFM.DLL O2 - BHO: Class - {D884B5A0-3017-DC89-792D-96559276EAEB} - C:\WINDOWS\SYSTEM\SDKKS32.DLL O2 - BHO: Class - {064905B7-0C45-8757-3090-1BEF98713F25} - C:\WINDOWS\JAVASE.DLL O2 - BHO: Class - {575F15E9-011B-8A3A-A265-D37719F26F78} - C:\WINDOWS\SYSTEM\NTNW.DLL O2 - BHO: Class - {8E85E371-7E71-258D-DA20-032B0FCC2088} - C:\WINDOWS\MSVD.DLL O2 - BHO: Class - {FD1F84BF-150A-AC66-F794-C3D1EAEC146E} - C:\WINDOWS\SYSTEM\D3VS.DLL O4 - HKLM\..\Run: [IESA.EXE] C:\WINDOWS\SYSTEM\IESA.EXE O4 - HKLM\..\Run: [MSN Messenger] C:\WINDOWS\SYSTEM\msmsgs.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Zone Labs Client] C:\ARCHIV~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\SYSTEM\BRIDGE.DLL",Load O4 - HKLM\..\Run: [br0ken] barint.exe O4 - HKLM\..\Run: [powerdll] SpyElim.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LiveNote] livenote.exe O4 - HKLM\..\Run: [anvshell] anvshell.exe O4 - HKLM\..\Run: [systray] C:\WINDOWS\SYSTEM\A.EXE O4 - HKLM\..\Run: [checkrun] C:\WINDOWS\SYSTEM\ELITEOYB32.EXE O4 - HKLM\..\RunServices: [ATLMG.EXE] C:\WINDOWS\SYSTEM\ATLMG.EXE /s O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Archivos de programa\Network Associates\VirusScan\AVSYNMGR.EXE O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [NTAC.EXE] C:\WINDOWS\NTAC.EXE /s O4 - HKLM\..\RunServices: [SYSLC.EXE] C:\WINDOWS\SYSTEM\SYSLC.EXE /s O4 - HKLM\..\RunServices: [WINYE32.EXE] C:\WINDOWS\WINYE32.EXE /s O4 - HKLM\..\RunServices: [WINMB.EXE] C:\WINDOWS\WINMB.EXE /s O4 - HKLM\..\RunServices: [SDKBH.EXE] C:\WINDOWS\SYSTEM\SDKBH.EXE /s O4 - HKLM\..\RunServices: [D3RJ32.EXE] C:\WINDOWS\D3RJ32.EXE /s O4 - HKLM\..\RunServices: [WINCU32.EXE] C:\WINDOWS\WINCU32.EXE /s O4 - HKLM\..\RunServices: [CRVU.EXE] C:\WINDOWS\SYSTEM\CRVU.EXE /s O4 - HKLM\..\RunServices: [JAVAUK32.EXE] C:\WINDOWS\JAVAUK32.EXE /s O4 - HKLM\..\RunServices: [IPML32.EXE] C:\WINDOWS\SYSTEM\IPML32.EXE /s O4 - HKLM\..\RunServices: [APIHE32.EXE] C:\WINDOWS\SYSTEM\APIHE32.EXE /s O4 - HKLM\..\RunServices: [D3TK32.EXE] C:\WINDOWS\D3TK32.EXE /s O4 - HKLM\..\RunServices: [SYSGH.EXE] C:\WINDOWS\SYSTEM\SYSGH.EXE /s O4 - HKLM\..\RunServices: [APPWO32.EXE] C:\WINDOWS\SYSTEM\APPWO32.EXE /s O4 - HKLM\..\RunServices: [APPQW32.EXE] C:\WINDOWS\APPQW32.EXE /s O4 - HKLM\..\RunServices: [MSLX.EXE] C:\WINDOWS\SYSTEM\MSLX.EXE /s O4 - HKLM\..\RunServices: [MSXC.EXE] C:\WINDOWS\MSXC.EXE /s O4 - HKLM\..\RunServices: [SDKOY.EXE] C:\WINDOWS\SYSTEM\SDKOY.EXE /s O4 - HKLM\..\RunServices: [NTGH.EXE] C:\WINDOWS\SYSTEM\NTGH.EXE /s O4 - HKCU\..\Run: [msnmsgr] "C:\ARCHIVOS DE PROGRAMA\MSN MESSENGER\MSNMSGR.EXE" /background O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [barint] sound64.exe O4 - HKCU\..\Run: [WTFCTF] stuffmon.exe O4 - HKCU\..\Run: [RtlFindVal] msag.exe O4 - HKCU\..\Run: [Dcu] C:\WINDOWS\SYSTEM\cmr.exe O4 - Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE O15 - Trusted Zone: http://*.63.219.181.7 O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = vtr.net O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.50.184.85,195.225.176.37 |
![]() | ![]() |
| ||||
| Re: Aqui esta mi log...¿que debo borrar? Madre mia, ese PC está infectadísimo. Hay que eliminar muchas cosas: 1 - Reinicia el equipo en "Modo a prueba de fallos". 2 - Con todos los programas cerrados, ejecuta HijackThis, marca las siguientes entradas y haces FIX: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\glpkx.dll/sp.html#12345 R3 - Default URLSearchHook is missing O2 - BHO: brdg Class - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\SYSTEM\BRIDGE.DLL O2 - BHO: Class - {B7B608A1-3C0D-13E8-78EE-41C5182942D9} - C:\WINDOWS\SYSTEM\MFCAW32.DLL O2 - BHO: Class - {0DC955CF-6038-C66F-8C89-325BB89B4B32} - C:\WINDOWS\SYSTEM\NTQN32.DLL O2 - BHO: Class - {D199E121-7C3B-041C-38EE-1EC2DB4BFA8D} - C:\WINDOWS\SYSTEM\D3FV.DLL O2 - BHO: Class - {FC8CAC2E-E32B-0FD0-16A5-10FEAEDA2D44} - C:\WINDOWS\IPQM32.DLL O2 - BHO: Class - {C4322B27-0B19-D263-F955-4B1DF8B80E2E} - C:\WINDOWS\NTTZ.DLL O2 - BHO: Class - {B901C34F-49B0-8A0B-D0FC-6B347CE1F3F0} - C:\WINDOWS\SYSTEM\SDKZC32.DLL O2 - BHO: Class - {8A71C47B-9917-B588-625B-79254D40A325} - C:\WINDOWS\IEKY32.DLL O2 - BHO: Class - {C6D6D264-D1BF-2B26-E95A-909FFD54938F} - C:\WINDOWS\SDKKT.DLL O2 - BHO: Class - {D6D41230-B4B7-D9FC-EDDA-A50821C38898} - C:\WINDOWS\SYSTEM\NTTA.DLL O2 - BHO: Class - {16CE9345-E97C-9903-46A0-6FBEE12FCD33} - C:\WINDOWS\IPVO.DLL O2 - BHO: Class - {EDCBB3FD-788F-D69A-C205-FAE58398A2D6} - C:\WINDOWS\IPKQ32.DLL O2 - BHO: Class - {13C3D1A3-A53A-6BFB-F6CA-8FA7292FE0F0} - C:\WINDOWS\SDKYR.DLL O2 - BHO: Class - {2A67970B-4CAA-474C-81A3-091789DA44E2} - C:\WINDOWS\WINBA32.DLL O2 - BHO: Class - {71604D4E-04BE-AC2F-9285-3BDCB48262EA} - C:\WINDOWS\SYSTEM\IPUC32.DLL O2 - BHO: Class - {DA81932E-29FB-B935-6516-E875DF84849C} - C:\WINDOWS\WINZJ.DLL O2 - BHO: Class - {69A8956B-7ACA-79FD-92BF-5F3E74F6063C} - C:\WINDOWS\SYSTEM\SYSOE32.DLL O2 - BHO: Class - {843F1365-75DF-8C62-2A68-0FBD9E681AFE} - C:\WINDOWS\SYSTEM\ADDJB32.DLL O2 - BHO: Class - {6DF861D0-BA9B-A44C-C0CF-FBF8C53F788C} - C:\WINDOWS\NETLB32.DLL O2 - BHO: Class - {6CC20879-C19B-36EE-23FF-A64629ED9B7E} - C:\WINDOWS\SYSTEM\CRAK.DLL O2 - BHO: Class - {0F8EB263-D23D-B227-0B4D-E0CDFED83FF4} - C:\WINDOWS\SYSTEM\MSTM32.DLL O2 - BHO: Class - {625A3020-0C09-DD3E-5940-A24D5AF0E210} - C:\WINDOWS\SYSTEM\SDKGW32.DLL O2 - BHO: Class - {F6EE85DC-5845-7F00-8948-5648F4D9CAC5} - C:\WINDOWS\SYSTEM\MFCPL32.DLL O2 - BHO: Class - {CBCD81C3-5DC7-B253-6CB6-D4DCDCB4A988} - C:\WINDOWS\APPSP.DLL O2 - BHO: Class - {E3828D84-4E06-2C16-3DD3-0FB832F75880} - C:\WINDOWS\MSSA.DLL O2 - BHO: Class - {9F97B6E9-C174-2E0C-BAF8-5BB263486A64} - C:\WINDOWS\ATLKN32.DLL O2 - BHO: Class - {E2FF7285-6F6F-9283-CBCD-D4E370856A52} - C:\WINDOWS\NTBZ32.DLL O2 - BHO: Class - {2D884AA4-5362-6D9F-DBFC-16455C462B7B} - C:\WINDOWS\SYSPO.DLL O2 - BHO: Class - {CFE85B4A-22AA-786D-10A6-8C8EABB85CE4} - C:\WINDOWS\SYSTEM\APIBQ.DLL O2 - BHO: Class - {3516BA73-6D3D-BE5D-10FF-AD33BF11BB40} - C:\WINDOWS\SYSTEM\D3KX32.DLL O2 - BHO: Class - {967871F3-038A-F72E-C5FF-CE710FAFDEA8} - C:\WINDOWS\CRUJ32.DLL O2 - BHO: Class - {D3DD24BD-375D-1229-E7E9-92878A1D7DBE} - C:\WINDOWS\WINFN32.DLL O2 - BHO: Class - {F3229D57-F62B-1F6E-54F4-EAF76321F1C8} - C:\WINDOWS\MFCSP.DLL O2 - BHO: Class - {A486CC8D-4D69-0934-1BCA-4CAF770BA94E} - C:\WINDOWS\SYSTEM\APICH32.DLL O2 - BHO: Class - {6CC45311-CFEB-E078-79D6-2ED797DCF228} - C:\WINDOWS\SYSTEM\NETLQ32.DLL O2 - BHO: Class - {5BA8ED10-55C0-B29D-A8F3-E37E146D4B4A} - C:\WINDOWS\SYSTEM\MFCJL32.DLL O2 - BHO: Class - {D800AD07-3198-4760-E8A4-33F3BB42B482} - C:\WINDOWS\APPCN.DLL O2 - BHO: Class - {E3394C70-FCAF-52D8-D7BC-D6A3A175F490} - C:\WINDOWS\NTCK.DLL O2 - BHO: Class - {67837E43-EFA1-5C25-5079-728566B2822D} - C:\WINDOWS\SYSTEM\SYSBP32.DLL O2 - BHO: Class - {E735AC74-28A4-0705-2A77-4CF61C5B76F1} - C:\WINDOWS\SYSTEM\IEPE32.DLL O2 - BHO: Class - {B850B1D0-7AA0-61EC-ECFE-A372B0057E40} - C:\WINDOWS\SYSTEM\WINPR.DLL O2 - BHO: Class - {A59EE127-10FE-394A-52D8-3E8D49F05B49} - C:\WINDOWS\IPFM.DLL O2 - BHO: Class - {D884B5A0-3017-DC89-792D-96559276EAEB} - C:\WINDOWS\SYSTEM\SDKKS32.DLL O2 - BHO: Class - {064905B7-0C45-8757-3090-1BEF98713F25} - C:\WINDOWS\JAVASE.DLL O2 - BHO: Class - {575F15E9-011B-8A3A-A265-D37719F26F78} - C:\WINDOWS\SYSTEM\NTNW.DLL O2 - BHO: Class - {8E85E371-7E71-258D-DA20-032B0FCC2088} - C:\WINDOWS\MSVD.DLL O2 - BHO: Class - {FD1F84BF-150A-AC66-F794-C3D1EAEC146E} - C:\WINDOWS\SYSTEM\D3VS.DLL O4 - HKLM\..\Run: [IESA.EXE] C:\WINDOWS\SYSTEM\IESA.EXE O4 - HKLM\..\Run: [MSN Messenger] C:\WINDOWS\SYSTEM\msmsgs.exe O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\SYSTEM\BRIDGE.DLL",Load O4 - HKLM\..\Run: [br0ken] barint.exe O4 - HKLM\..\Run: [powerdll] SpyElim.exe O4 - HKLM\..\Run: [systray] C:\WINDOWS\SYSTEM\A.EXE O4 - HKLM\..\Run: [checkrun] C:\WINDOWS\SYSTEM\ELITEOYB32.EXE O4 - HKLM\..\RunServices: [ATLMG.EXE] C:\WINDOWS\SYSTEM\ATLMG.EXE /s O4 - HKLM\..\RunServices: [NTAC.EXE] C:\WINDOWS\NTAC.EXE /s O4 - HKLM\..\RunServices: [SYSLC.EXE] C:\WINDOWS\SYSTEM\SYSLC.EXE /s O4 - HKLM\..\RunServices: [WINYE32.EXE] C:\WINDOWS\WINYE32.EXE /s O4 - HKLM\..\RunServices: [WINMB.EXE] C:\WINDOWS\WINMB.EXE /s O4 - HKLM\..\RunServices: [SDKBH.EXE] C:\WINDOWS\SYSTEM\SDKBH.EXE /s O4 - HKLM\..\RunServices: [D3RJ32.EXE] C:\WINDOWS\D3RJ32.EXE /s O4 - HKLM\..\RunServices: [WINCU32.EXE] C:\WINDOWS\WINCU32.EXE /s O4 - HKLM\..\RunServices: [CRVU.EXE] C:\WINDOWS\SYSTEM\CRVU.EXE /s O4 - HKLM\..\RunServices: [JAVAUK32.EXE] C:\WINDOWS\JAVAUK32.EXE /s O4 - HKLM\..\RunServices: [IPML32.EXE] C:\WINDOWS\SYSTEM\IPML32.EXE /s O4 - HKLM\..\RunServices: [APIHE32.EXE] C:\WINDOWS\SYSTEM\APIHE32.EXE /s O4 - HKLM\..\RunServices: [D3TK32.EXE] C:\WINDOWS\D3TK32.EXE /s O4 - HKLM\..\RunServices: [SYSGH.EXE] C:\WINDOWS\SYSTEM\SYSGH.EXE /s O4 - HKLM\..\RunServices: [APPWO32.EXE] C:\WINDOWS\SYSTEM\APPWO32.EXE /s O4 - HKLM\..\RunServices: [APPQW32.EXE] C:\WINDOWS\APPQW32.EXE /s O4 - HKLM\..\RunServices: [MSLX.EXE] C:\WINDOWS\SYSTEM\MSLX.EXE /s O4 - HKLM\..\RunServices: [MSXC.EXE] C:\WINDOWS\MSXC.EXE /s O4 - HKLM\..\RunServices: [SDKOY.EXE] C:\WINDOWS\SYSTEM\SDKOY.EXE /s O4 - HKLM\..\RunServices: [NTGH.EXE] C:\WINDOWS\SYSTEM\NTGH.EXE /s O4 - HKCU\..\Run: [barint] sound64.exe O4 - HKCU\..\Run: [WTFCTF] stuffmon.exe O4 - HKCU\..\Run: [RtlFindVal] msag.exe O4 - HKCU\..\Run: [Dcu] C:\WINDOWS\SYSTEM\cmr.exe O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.161.126/5/s1//q.chm::/file.exe 3 - Localiza y elimina (usa KillBox si es necesario): C:\WINDOWS\system\glpkx.dll C:\WINDOWS\SYSTEM\BRIDGE.DLL C:\WINDOWS\SYSTEM\MFCAW32.DLL C:\WINDOWS\SYSTEM\ATLMG.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\SYSGH.EXE C:\WINDOWS\SYSTEM\CMR.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\MSXC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\ATLMG.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\SYSTEM\IESA.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\SYSTEM\ATLMG.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE C:\WINDOWS\SYSTEM\NTGH.EXE C:\WINDOWS\SYSTEM\SYSLC.EXE C:\WINDOWS\NTAC.EXE C:\WINDOWS\WINYE32.EXE C:\WINDOWS\D3TK32.EXE Luego limpia el registro con un programa como RegSeeker por ejemplo. 4 - Reinicia en "Modo a prueba de fallos" o "Modo seguro" y escanea el equipo con Ad-Aware SE y Spybot Search&Destroy. Escanea el sistema con un par de antivirus, siguiendo los pasos que ahí aparecen. 5 - Usa el Disk Cleaner para limpiar cookies y temporales. 6 - Reinicia y nos cuentas los resultados. **NOTA: Actualiza el sistema operativo y el navegador. Saludos. Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog * Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando. * Para evitar Virus y Spywares al navegar por internet, USE FIREFOX !! * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro. |
![]() |
| Herramientas | |
|
|
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| simplemente aqui esta mi log, ¿que opinas de beinsync? | oliver castro | Foro Oficial de HijackThis en español | 1 | 09/05/05 20:34:10 |
| tambien sufro del newgenlook, aquí está mi log, cuando puedan porfis - [solucionado] | Valor | Temas Solucionados | 7 | 03/05/05 22:26:48 |
| Problemas varios aqui esta mi log (solucionado) | Anfylion17 | Temas Solucionados | 3 | 13/04/05 13:10:18 |
| Mensajes de "Warning Spyware", pagina de inicio cambiada, aqui esta mi log | lely1co | Foro Oficial de HijackThis en español | 7 | 08/04/05 13:22:32 |
| Ayuda a eliminar spyware, aqui esta mi log | Noemi | Foro Oficial de HijackThis en español | 1 | 04/04/05 14:48:32 |