El problema comenzó con el msn, que dejo de funcionar y finalmente dejo de arrancar. La versión que venia usando es la "live msn". La versión anterior, en cambio, sigue arrancando pero cuando la minimizo desaparece de la barra de tareas
Además al arrancar la máquina en el administrador de tareas me figura dos veces la extensión msmmsgr.exe ejecutándose aunque yo no haya intentado abrir el programa. Intente desinstalar y reinstalar el programa pero no resultó. La Pc, en general anda un poco lenta, sobre todo en internet.
Ademas les comento que con el Spyboot encontre en la entrada "msnmsgr.exe" de inicio del sistema, que no aparecia ejecutando el msconfig, el "SDBOT.MH WORM"
Esta entrada la eliminé
Ademas aparecen otras 4 entradas que no se bien a que pertenecen:
Located: HK_LM:Run, IMJPMIG8.1 (DISABLED)
command: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
file: C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
size: 208952
MD5: 7bbe4cf421aecc7f0226edd75f12079f
Located: HK_LM:Run, MSPY2002 (DISABLED)
command: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
file: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
size: 59392
MD5: 1b17e09c1223f6d17336d2dd7a1af4f4
Located: HK_LM:Run, PHIME2002A (DISABLED)
command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
size: 455168
MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6
Located: HK_LM:Run, PHIME2002ASync (DISABLED)
command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
size: 455168
MD5: 024dc0f68df5fd6ae9dd82dfbaf479d6
Hasta ahora probè todo lo que conocía, Kasperisky y Panda online, CCleaner y Nod en modo a prueba de fallos, etc.
---------------------------------------------------------
AVG Anti-Spyware - Informe del análisis
---------------------------------------------------------
+ Creado en:
06:25:53 p.m. 14/08/2007
+ Resultado del análisis:
:mozilla.117:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.2o7 : Limpios.
:mozilla.89:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.90:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.91:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.92:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.93:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.94:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.95:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.96:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.97:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adbrite : Limpios.
:mozilla.84:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adengage : Limpios.
:mozilla.226:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adtech : Limpios.
:mozilla.227:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Adtech : Limpios.
:mozilla.162:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Advertising : Limpios.
:mozilla.164:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Advertising : Limpios.
:mozilla.255:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Clickzs : Limpios.
:mozilla.256:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Clickzs : Limpios.
:mozilla.257:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Clickzs : Limpios.
:mozilla.163:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Doubleclick : Limpios.
:mozilla.235:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Fastclick : Limpios.
:mozilla.236:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Fastclick : Limpios.
:mozilla.237:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Fastclick : Limpios.
:mozilla.139:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Googleadservices : Limpios.
:mozilla.326:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Googleadservices : Limpios.
:mozilla.340:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Googleadservices : Limpios.
:mozilla.165:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Imrworldwide : Limpios.
:mozilla.166:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Imrworldwide : Limpios.
:mozilla.34:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Netflame : Limpios.
:mozilla.35:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Netflame : Limpios.
:mozilla.144:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Paypal : Limpios.
:mozilla.265:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Sexlist : Limpios.
:mozilla.82:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Specificclick : Limpios.
:mozilla.83:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Specificclick : Limpios.
:mozilla.85:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Specificclick : Limpios.
:mozilla.86:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Specificclick : Limpios.
:mozilla.100:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.101:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.102:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.87:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.88:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.98:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.99:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Statcounter : Limpios.
:mozilla.337:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Tribalfusion : Limpios.
:mozilla.320:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Webtrends : Limpios.
:mozilla.339:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Webtrendslive : Limpios.
:mozilla.293:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yadro : Limpios.
:mozilla.177:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.178:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.179:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.180:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.181:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.182:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Yieldmanager : Limpios.
:mozilla.229:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Zedo : Limpios.
:mozilla.230:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Zedo : Limpios.
:mozilla.231:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Zedo : Limpios.
:mozilla.232:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Zedo : Limpios.
:mozilla.234:C:\Documents and Settings\Mariano\Application Data\Mozilla\Firefox\Profiles\j0a8lgt5.default\cookies.txt -> TrackingCookie.Zedo : Limpios.
::Fin del informe
Tue Aug 14 18:56:04 2007
EliStartPage v14.50 (c)2007 S.G.H. / Satinfo S.L.
--------------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\ALCMTR.EXE --> Eliminado SpyRealtek
Entrada Eliminada [HKLM\...\Run] "Msconfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto"
Eliminada Clave "HKLM\...\Image File Execution Options\Your Image File Name Here without a path"
Restaurado archivo de Configuración del IE, (IERESET.INF)
Eliminadas las Paginas de Inicio y de Busqueda del IE
Eliminados Ficheros Temporales del IE
Tue Aug 14 18:56:42 2007
EliStartPage v14.50 (c)2007 S.G.H. / Satinfo S.L.
--------------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\Program Files\Realtek\InstallShield\ALCMTR.EXE --> Eliminado, SpyRealtek
C:\Program Files\NewTech Infosystems\NTI Backup NOW! 4.5\PART32.DLL --> Eliminado, WinAntiVirus Pro 2006 (cpl)
C:\Program Files\Microsoft IntelliPoint 5.2\SETUPSTB.EXE --> Eliminado, WinAntiVirus Pro 2006 (BHO)
C:\Program Files\Microsoft IntelliPoint 5.2\IPoint\SETUP\Files\DPGMKB.DLL --> Eliminado, CommanderNET (TB)
C:\Program Files\Microsoft IntelliPoint\DPGMKB.DLL --> Eliminado, CommanderNET (TB)
Log hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:22:36 p.m., on 14/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Empowering Technology\eLock\LockServ.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Eset\nod32kui.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Acer\Empowering Technology\eLock\Monitor\LockMon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 1: Taringa! - Inteligencia Colectiva -
Gracias y perdon por lo largo del mensaje, pero creí que era mejor contar lo mejor posible la situación.