Se satura la Conexion a internet (SOLUCIONADO)

Cerrado
Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Se satura la Conexion a internet (SOLUCIONADO)

Mensaje por maxibanez77 » 02 Ago 2007, 18:19

Hola, lamentablemente soy yo de nuevo:



El problema que se me presenta es que luego de un tiempo de estar conectado, 1 a 2 minutos, inclusive si no estoy explorando la internet o bajando software o actualizaciones de ningun tipo, la conexion a internet se satura y el Internet explorer no llega a cargar ni siquiera Google o Yahoo.

Tengo instalado el Spybot S&D, Spyware Blaster, AVG 7.5, actualizados los tres, los paso en modo normal y a prueba de fallos y nada, pase el ElistarA, el Elitriip, y el HJT y les dejo los logs para que los vean, no parece haber nada fuera de lo normal pero bueno mejor sus ojos de buen entendedor para revisarlos.



el Log de ElistarA dice:
[quote]
Thu Aug 02 12:55:11 2007

EliStartPage v14.50 (c)2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Acción Directa):

Eliminada Clave "HKLM\...\Image File Execution Options\Your Image File Name Here without a path"

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



Thu Aug 02 12:56:22 2007

EliStartPage v14.50 (c)2007 S.G.H. / Satinfo S.L.

--------------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\
[/quote]


y el de HJT:


[quote]Logfile of HijackThis v1.99.1

Scan saved at 01:08:48 p.m., on 02/08/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe

C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Archivos de programa\SiteAdvisor\6066\SAService.exe

C:\WINDOWS\Explorer.EXE

C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe

C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Archivos de programa\SiteAdvisor\6066\SiteAdv.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Archivos de programa\SlySoft\AnyDVD\AnyDVD.exe

C:\Documents and Settings\All Users\Documentos\virus\HijackThis.exe

C:\WINDOWS\system32\Notepad.exe



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos

R3 - URLSearchHook: Yahoo! Barra de herramientas - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Archivos de programa\SiteAdvisor\6066\SiteAdv.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Complemento del Asistente para Internet de Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL

O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Archivos de programa\SiteAdvisor\6066\SiteAdv.dll

O3 - Toolbar: Asistente para Internet de Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL

O3 - Toolbar: Yahoo! Barra de herramientas - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [RemoteControl] "C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [SiteAdvisor] C:\Archivos de programa\SiteAdvisor\6066\SiteAdv.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [AnyDVD] "C:\Archivos de programa\SlySoft\AnyDVD\AnyDVD.exe"

O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 - DPF: {0D140783-9D5D-4A88-A62E-D75E808710FD} (MyHTTPTransferX.MyHTTPTransferControl) - http://www.mixplay.tv/applets/HTTPManagerX.CAB

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://maxibanez77.spaces.live.com//PhotoUpload/MsnPUpld.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185816329828

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab

O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Archivos de programa\SiteAdvisor\6066\SiteAdv.dll

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Archivos de programa\SiteAdvisor\6066\SAService.exe
[/quote]


simplemente espero que "no sea nada" :?

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 19:23

Log limpio y aparentemente no es motivo de sogtware, pero lanza estos AV ONLINE y comentanos el resultado



[url=https://www.eset.es/analisis-online/][b][color=Darknesred]Antivirus ONLINE aconsejado[/color][/b][/url]



y una manera facil y rapida de saber si se tiene virus en memoria es lanzar este escaneo ONLINE que tarda menos de 1 minuto:



testeo ONLINE de virus en memoria



[url=https://www.pandasecurity.com/spain/homeusers/solutions/online-antivirus/][b][color=Darknesred]testeo ONLINE de virus en memoria[/color][/b][/url]



Suponiendo que no detectes nada, mira la temperatura de la CPU, que ayudado por la temperatura ambiental, puede pasarse de rosca...



Para ello , sugiero usar el [url=http://www.zonavirus.com/datos/descargas/28/EVEREST_Home_Edition.asp][b]AIDA32[/b][/url] o el [url=http://www.zonavirus.com/datos/descargas/108/everest-home-edition.asp][b]Everest Home Edition[/b][/url] y para conocer la temperatura, acceda la parte que pone ORDENADOR y a continuacion a SENSOR:



[b]Programas Recomendados:[/b]

· [url=http://www.zonavirus.com/datos/descargas/28/EVEREST_Home_Edition.asp][b]Descargar AIDA32[/b][/url]

· [url=http://www.zonavirus.com/datos/descargas/108/everest-home-edition.asp][b]Descargar Everest Home Edition[/b][/url]





saludos



ms, 2-08-2007

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 20:09

Y diganos si usa o simplemente tiene wireless... por si algun vecino chupara de su ADSL:..



Si lo hace por cable pero tiene el router tiene wireless, hay uninterruptor p switch para desactivarlo, hagalo



Si usa el wireless, prteja su ADSL con MacAdress, por si acaso...



saludos



ms, 2-08-2007

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 02 Ago 2007, 20:10

Bueno he seguido los pasos indicados y los resultados son los siguientes:



el NANOScan de panda dio este resultado:
[quote]Resultado del análisis

Resumen:

No tienes virus en tu PC



Detalle:

Peligroso Nombre de la amenaza (0) Tipo Estado



Tiempo:

41 segundos

Antivirus:

GRISOFT AVG 7.5.476 (activo y actualizado)


[/quote]


el everest dijo:
[quote]--------[ EVEREST Home Edition (c) 2003, 2004 Lavalys, Inc. ]-----------------------------------------------------------



Versión EVEREST v1.51.195/es

Sitio Web http://www.lavalys.com/

Tipo de informe Informe rápido

Ordenador IBAÑEZ

Generador Maximiliano

Sistema operativo Microsoft Windows XP Professional 5.1.2600 (WinXP Retail)

Fecha 2007-08-02

Hora 14:59





--------[ Sensor ]-----------------------------------------------------------------------------------------------------



Propiedades del sensor :

Tipo de sensor Winbond W83647HF (ISA 290h)



Temperaturas :

Placa base 32 °C (90 °F)

Procesador 46 °C (115 °F)

Aux 49 °C (120 °F)

WDC WD800BB-22JHC0 37 °C (99 °F)



Ventiladores :

Procesador 4754 RPM

Chasis 2616 RPM



Valores de voltaje :

Núcleo CPU 1.16 V

CPU Auxiliar 3.68 V

+3.3 V 3.36 V

+5 V 5.56 V

+12 V 12.71 V

-12 V 2.12 V

-5 V -7.11 V

Puesta en espera +5 V 4.95 V

Batería VBAT 2.94 V

Debug Info V AC E6 D2 CF D1 CF 0C 20 (03)

Debug Info T 32 46 49





--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------



B00 D00 F00: Intel 82848P/865G/865GV/865P/865PE Memory Controller Hub [A-2]



Offset 00: 86 80 70 25 06 01 90 20 02 00 00 06 00 00 00 00

Offset 10: 08 00 00 EC 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 43 10 57 81

Offset 30: 00 00 00 00 E4 00 00 00 00 00 00 00 00 00 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 02 08 00 40 80 1C 00 00 00 00 00 00 00 00 00

Offset 60: 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 10 11 11 00 00 33 33 00 00 00 00 00 00 0A 38 00

Offset A0: 02 00 30 00 1B 4A 00 1F 12 0B 00 00 00 00 00 00

Offset B0: 80 00 00 00 30 00 00 00 00 50 00 00 20 10 00 00

Offset C0: 00 00 00 00 00 20 0D 04 00 00 00 00 00 00 00 00

Offset D0: 02 28 04 0E 0B 0D 00 00 00 00 00 00 00 00 30 01

Offset E0: 00 00 00 00 09 A0 06 01 00 02 00 00 00 00 00 00

Offset F0: 00 00 00 00 02 00 00 00 68 0F 03 00 00 00 00 00



B00 D01 F00: Intel 82848P/865G/865GV/865P/865PE AGP Controller



Offset 00: 86 80 71 25 07 01 A0 00 02 00 04 06 00 40 01 00

Offset 10: 00 00 00 00 00 00 00 00 00 01 01 40 D0 D0 A0 22

Offset 20: 00 FA E0 FB 00 F0 F0 F8 00 00 00 00 00 00 00 00

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 68 0F 03 00 00 00 00 00



B00 D06 F00: Intel 82848P/865G/865GV/865P/865PE I/O Memory Interface



Offset 00: 86 80 76 25 02 00 80 00 02 00 80 08 00 00 00 00

Offset 10: 00 00 CF FE 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 40: 40 65 00 04 00 00 00 00 04 00 00 00 00 00 00 00

Offset 50: 01 00 8F 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 55 05 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 20 08 00

Offset B0: 00 00 00 00 F0 43 FC 7D 01 00 00 00 09 00 00 00

Offset C0: 00 08 00 00 20 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 FF FF FF FF FF FF FF 3F

Offset E0: 00 00 00 00 00 00 01 02 FF 0E 00 00 00 00 04 00

Offset F0: 00 0C 02 00 00 00 00 00 68 0F 03 00 74 FC 00 00



B00 D1D F00: Intel 82801EB ICH5 - USB Universal Host Controller



Offset 00: 86 80 D2 24 05 00 80 02 02 00 03 0C 00 00 80 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 01 B8 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 2F 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1D F01: Intel 82801EB ICH5 - USB Universal Host Controller



Offset 00: 86 80 D4 24 05 00 80 02 02 00 03 0C 00 00 00 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 01 C0 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 13 02 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 2F 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1D F02: Intel 82801EB ICH5 - USB Universal Host Controller



Offset 00: 86 80 D7 24 05 00 80 02 02 00 03 0C 00 00 00 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 01 C4 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 12 03 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 2F 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1D F03: Intel 82801EB ICH5 - USB Universal Host Controller



Offset 00: 86 80 DE 24 05 00 80 02 02 00 03 0C 00 00 00 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 01 C8 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 2F 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1D F07: Intel 82801EB(M) ICH5(-M) - Enhanced USB2 Controller



Offset 00: 86 80 DD 24 06 01 90 02 02 20 03 0C 00 00 00 00

Offset 10: 00 FC FF F9 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 50 00 00 00 00 00 00 00 17 04 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 01 58 C2 C9 00 00 00 00 0A 00 A0 20 00 00 00 00

Offset 60: 20 20 FF 01 00 00 00 00 01 00 00 00 00 00 00 C0

Offset 70: 00 00 CF 3F 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 55 55 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 80 00 00 88 83 40 00 66 0F 05 00 06 14 00 00



B00 D1E F00: Intel 82801EB I/O Controller Hub 5 (ICH5)



Offset 00: 86 80 4E 24 07 01 80 00 C2 00 04 06 00 00 01 00

Offset 10: 00 00 00 00 00 00 00 00 00 02 02 40 E0 E0 80 22

Offset 20: F0 FB F0 FB F0 FF 00 00 00 00 00 00 00 00 00 00

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 06 00

Offset 40: 02 28 30 76 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 02 64 73 00 00 00 00 00 50 01 34 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 90 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 01 00 02 00 00 00 C0 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 53 33



B00 D1F F00: Intel 82801EB ICH5 - LPC Bridge



Offset 00: 86 80 D0 24 0F 00 80 02 02 00 01 06 00 00 80 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 40: 01 08 00 00 10 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 81 04 00 00 10 00 00 00

Offset 60: 8A 85 85 83 D0 00 00 00 80 80 80 8B 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: FF FC 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 20 02 00 00 00 00 00 00 0D 00 00 00 00 03 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 86 21 00 00 02 0F 00 00 04 00 00 00 00 00 00 00

Offset E0: 00 00 00 80 00 00 08 14 33 22 11 00 00 00 67 45

Offset F0: 00 00 45 00 04 00 00 00 66 0F 05 3E 00 00 00 00



B00 D1F F01: Intel 82801EB ICH5 - ATA-100 IDE Controller



Offset 00: 86 80 DB 24 07 00 80 02 02 8A 01 01 00 00 00 00

Offset 10: 01 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00

Offset 20: 01 FC 00 00 00 FC EF FF 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00

Offset 40: 07 A3 03 A3 00 00 00 00 05 00 01 02 00 00 00 00

Offset 50: 00 00 00 00 30 10 00 00 00 00 00 00 00 00 00 00

Offset 60: 08 00 00 00 00 00 00 00 08 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1F F03: Intel 82801EB ICH5 - SMBus Controller



Offset 00: 86 80 D3 24 01 00 80 02 02 00 05 0C 00 00 00 00

Offset 10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 01 04 00 00 00 00 00 00 00 00 00 00 43 10 A6 80

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00

Offset 40: 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B00 D1F F05: Intel 82801EB ICH5 - AC'97 Audio Controller



Offset 00: 86 80 D5 24 07 00 90 02 02 00 01 04 00 00 00 00

Offset 10: 01 B4 00 00 01 B0 00 00 00 F8 FF F9 00 F4 FF F9

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 43 10 0F 81

Offset 30: 00 00 00 00 50 00 00 00 00 00 00 00 11 02 00 00

Offset 40: 09 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 01 00 C2 C9 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 66 0F 05 00 00 00 00 00



B01 D00 F00: MSI FX5200 (MS-8936) Video Adapter



Offset 00: DE 10 22 03 07 00 B0 02 A1 00 00 03 00 F8 00 00

Offset 10: 00 00 00 FA 08 00 00 F0 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 62 14 60 93

Offset 30: 00 00 00 00 60 00 00 00 00 00 00 00 10 01 05 01

Offset 40: 62 14 60 93 02 00 30 00 1B 0E 00 1F 12 43 00 1F

Offset 50: 01 00 00 00 01 00 00 00 CE D6 23 00 0F 00 00 00

Offset 60: 01 44 02 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00



B02 D0D F00: Realtek RTL8139 Fast Ethernet Adapter



Offset 00: EC 10 39 81 05 01 90 02 10 00 00 02 00 40 00 00

Offset 10: 01 E8 00 00 00 FC FF FB 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 43 10 09 81

Offset 30: 00 00 00 00 50 00 00 00 00 00 00 00 17 01 20 40

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 01 00 C2 F7 00 01 00 00 00 00 00 00 00 00 00 00

Offset 60: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 70: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 90: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00



PCI-8086-2570: Intel i848/865/875/E7210 MMR



Offset 00: 08 08 08 08 08 08 08 08 00 00 00 00 00 00 00 00

Offset 10: 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

Offset 60: 95 0D E4 56 C6 42 14 00 71 62 10 20 00 00 00 00





--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------



C000:0000 U.z.K7400.L.w.VIDEO ....8.&...IBM VGA Compatible........08/01/03

C000:0040 ....................b.`.?.0~. ..........".........PMIDl.o.......

C000:0080 .....3...........NV..'.&x" 4.................P.P.wM...<X=.DJD^D

C000:00C0 ..3..n...........&.`...0W...o.o.o.o.p.p.o............V.W........

C000:0100 ...w..................................Hp4...(#..end bmp.PCIR..".

C000:0140 ........z.......GeForce FX 5200 BIOS..MSIN8936MS.100............

C000:0180 .................................Version 4.34.20.22.00 ...Copyri

C000:01C0 ght (C) 1996-2003 NVIDIA Corp...................................

C000:0200 ................NV34 Board - p162-2nz..............Chip Rev ..

C000:0240 ..................1.......@.......J...I.o.L.....a.....+le.M.....

C000:0280 ..........n.....q...G.t.....2.x...B.,.f`....o................u..

C000:02C0 fa....f`3....fa....C.*....R.......u.........8...t......2.....t..

C000:0300 Q.........Y.f..7.....df.#....f........u...d.f..7...f........u..|

C000:0340 d.f..7...f+.........u.S..r[.Gj.f`f...h...tf.....f3.f..f......>df

C000:0380 .....f.q..../dfa.........".C...C..u............C..u..........f..

C000:03C0 ....C...."'C..'C..u...B.J..f............f......C..'C..u..f.....Q





------------------------------------------------------------------------------------------------------------------------



The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
[/quote]


y el resultado del CA online que se acaba de terminar es:
[quote]No viruses found.



File Infection Status Path

- No Infections
[/quote]

realmente estoy anonadado parece ser que mi maquina esta mas limpia y funcional de lo que debiera...sera eso?¿ sera que no esta acostumbrada?¿



[b]edit:[/b] No uso Wireles, tengo un modem ADSL ZyXEL P600 Series solo para esta maquina
Última edición por maxibanez77 el 02 Ago 2007, 20:18, editado 1 vez en total.

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 20:16

Indica:



Procesador 46 °C (115 °F)

Aux 49 °C (120 °F)





pues muy bien.



y sin virus ni troyanos... , ¿qué me dice de lo del wireless que le indicaba en mi ultimo post ???



saludos



ms, 2-08-2007
Última edición por msc hotline sat el 02 Ago 2007, 20:45, editado 1 vez en total.

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 02 Ago 2007, 20:19

por las dudas repito: No uso wireless, Uso un modem ADSL ZyXEL P600 Series solo para esta maquina, ni siquiera la tengo en lan

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 20:22

Muy bien, pero ... est router emite wireless ???



voy a ver si encuentro descripcion.

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 02 Ago 2007, 20:25

NONO es simplemente un modem/router pero por cable solamente.. (es el baratito que entrega telefonica jeje) el modelo exacto seria Prestige 600R-61C.



He revisado el rendimiento de las conecciones de red y sin navegar ni hacer nada me dice "Speedy conectado a 100mb 0,23% en uso" lo cierto es que la conexion (que la realizo por PPoE) es de 512k lo que significa que el uso real es mucho mayor, estoy en lo cierto?, que sera no lo se pero si no se soluciona no puedo navegar siquiera

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 20:34

Bueno, los hay que son wireless, de esta serie, como puede ver en



http://www.tomshw.it/forum/showthread.php?t=61792



pero si esta seguro que el suyo no lo es, menos riesgo de uso "pirata" de su ADSL



Ello hubiera poido ser la causa de su pérdida de prestaciones, al chupar un vecino su misma ADSL...



Si no es el caso voy a pensar que puede ser



saludos



ms, 2-08-2007
Última edición por msc hotline sat el 02 Ago 2007, 20:45, editado 1 vez en total.

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 02 Ago 2007, 20:43

Desde ya y como siempre les agradezco su gran preocupacion por absolutamente todos los problemas que se postean en el foro... espero que encontremos solucion a este:). si lo soluciono posteo el como y el porque sinno seguire revisando el post por respuestas, gracias

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 20:53

Releyendo el Tema, dice "no estoy explorando la internet o bajando software", veamos, tiene o usa algun sistema de descargas tipo P2P ??? no he visto emule, pando, Ares, BitTorret, pero no sé si tendrá algo similar, en cuyo caso aunque Vd no descargue nada, le pueden estar descargando de Vd, y ocupando la linea... por si acaso, digamen si tiene o usa algo de ello, y aunque no sea el caso, tengalo en cuenta, siempre va bein saberlo



sigo pensando... (luego existo :wink: )



saludos



ms, 2-08-2007

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 Ago 2007, 21:18

Y si no es el caso de lo de P2P, puedes probar de eliminar esta clave:



O16 - DPF: {0D140783-9D5D-4A88-A62E-D75E808710FD} (MyHTTPTransferX.MyHTTPTransferControl) - http://www.mixplay.tv/applets/HTTPManagerX.CAB



Es una DPF (Downloaded Program Files)descargado un fichero, que uno de los AV de Virus Total lo encuentra sospechoso, y por si las moscas, liquidemoslo...



ya sabes como:





->[b] Para ello recordar[/b]: https://foros.zonavirus.com/viewtopic.php?f=2&t=45334





Y cuentanos el resultado, a ver si realmente era es0 ???



la verdad que ahora ya es ir dando palos de ciego, a bulto...



saludos



ms, 2-08-2007

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 02 Ago 2007, 21:34

La clave fue eliminada, te cuento que http://www.mixplay.tv es un sitio de videos como YouTube y probablemente se haya bajado el archivo en algun momento explorando ese sitio, por otro lado la conexion se sigue saturando y como ejemplo te cuento que donde dice los bytes recibidos y enviados tengo:



Enviados: 8.130.227 bytes

Recibidos: 1.218.880 bytes



y eso en solo 3 minutos de conectado!! quiza la cifra sea normal pero no lo se, y lo que va al problema la conexion sigue lenta, lentisima tanto que la pagina del foro que solia cargar casi al instante tarda casi 1 minuto en cargar con esta conexion de 512kb mentirosos de Speedy, (osea son "HASTA" 512kb no?)



A por cierto no uso programas de P2p, ninguno de ellos, pero tuve instalado Emule hasta hace unos dias

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

A ver si es esto

Mensaje por maxibanez77 » 03 Ago 2007, 00:31

Sres. a ver si esto ayuda:



realice un "netstat" bajo ventana de DOS sin conexion a internet y solo tengo 4 tcp en modo listen



luego conecte a speedy.......



hete aqui que hice el netstat y tuve que interrumpirlo porque es infinita la cantidad de puertos que arbe incluso sin tener abierto iexplore ni ningun programa mas que la propia ventana de DOS verifique con "netstat -b" que programa los abre y son todos abiertos por services.exe.... y van a lugares inusitados...... sera un virus nuevo? quieren muestra del services.exe? quiza este ahi la solucion a todo! no lo se pero estoy/amos en eso

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 03 Ago 2007, 09:32

Si quieres enviala, claro, pero ya será para despues de vacaciones pues hoy cerramos por vacaciones y como no te des prisa...



De todas formas, subela al VirusTotal y sabrás si es el bicho que supones:



https://www.virustotal.com/es/



y nos comentas el resultado, gracias



saludos



ms, 3-08-2007

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

A la carga de nuevo

Mensaje por maxibanez77 » 07 Ago 2007, 23:20

hola de nuevo viendo que sus vacaciones en este momento han sido "figurativas" vuelvo a la carga y les comento los avances del problema:



- he instalado la ultima version de ZoneAlarm

- Spybot S&D

- Spyware Blaster

- Corri todos los soft de antivirus y antispyware que tengo en modo a prueba de fallos



el tema sigue asi.. la conexion se satura de datos de salida y no de entrada, el Zonealarm ya lleva bloqueadas muchas de estas salidas pero... se sigue saturando la conexion y los datos salientes va a lugares como: -mail.fiaip.it ; msx-sg1-8.hinet.net ; sinbad.lookandfeel ; 51.pool85-61-100.dynamic.orange.es.........



y la lista es interminable y cambia constantemente. sin contar por supuesto las respuestas de ping de los dns de telefonica.



mi pregunta a esta altura y quiza uds me la puedan despejar, es: puede ser que tenga metido algo en el sistema que hasta ahora los soft de evaluacion no han podido detectar por quien sabe que razon, y que genera estas salidas con digamos datos de mi pc (por decir algo)?



espero que le demos por donde le corresponde al problema porque la verdad me tiene muy intrigado y se que la solucion rapida sera format c: (a lo cual no quiero llegar por supuesto)

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 08 Ago 2007, 07:32

Previo a meterme en el Tema y respecto a lo que dice de mis vacaciones, no se fie porque tengo un pie en el avion, que mi amigo del lago Ness me está esperando ...



Y lo que dice del software de evaluacion, todas las utilidades antivirus son provisionales, y detectan solo lo conocido hasta el momento, a pesar de que heuristicamente se intente extrapolar y detectar algo por similitud sin conocerlo a ciencia cierta, de ahí los falsos positivos que a veces se dan, pero no tenemos la bola de cristal que quisieramos ...



Y voy a releer todo el Tema a ver si vemos algo mas



___



Bueno, deciamos


[quote]De todas formas, subela al VirusTotal y sabrás si es el bicho que supones:



https://www.virustotal.com/es/



y nos comentas el resultado, gracias [/quote]


no nos has posteado el resultado, y la muestra ue quizas nos enviaste, al estar SATINFO cerrado por vacaciones (el servicio de emergencia es solo para clientes con contrato de asistencia tecnica), no lo veremos hasta que volvamos de vacaciones, allá por el 27.



Pues veamos el resultado del analisis del VirusTotal y obraremos en consecuencia



saludos



ms, 8-08-2007



y como que ya probaste el ELISTARA, y pudiere haber algun intento de intrusion por desbordamiento de dicho SERVICES.EXE que pudiere ser del sistema, prueba el ELITRIIP :





ELITRIIP:

http://www.zonavirus.com/descargas/elitriip.asp



Tras probarlo, reiniciar y postearnos el contenido de C:\infosat.txt para ver el resultado del proceso





saludos



ms, 8-08-2007

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Mensaje por maxibanez77 » 08 Ago 2007, 17:51

Antes que nada lo de las vacaciones fue mas pena por ud que otra cosa (por supuesto su dedicacion a esto es indiscutible e irreprochable)



Por otro lado se que las utilidades que nos ofrecen no son bolas de cristal (lo cual yo tambien quisiera ;) )



A lo nuestro: la verificacion de "services.exe" las 3 copias que hay en mi sistema las analice en https://www.virustotal.com/es/ y el resultado fue 0/32 o sea que los 32 motores de revision no encontraron nada sospechoso.



el EliTriip dio este resultado:
[quote]Wed Aug 08 10:42:44 2007

EliTriIP v3.78 (c)2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Acción Directa):



Wed Aug 08 10:42:46 2007

EliTriIP v3.78 (c)2007 S.G.H. / Satinfo S.L.

---------------------------------------------

Lista de Acciones (por Exploración):

Explorando Unidad C:\
[/quote]


[b]ahora le comento que he bajado una utilidad "tcp view" y por las dudas pego el log para que vea la actividad a la que hacemos referencia y quiza luego de tanto analisis no este provocada por services.exe sino otro que llama a ese servicio (quien sabe)[/b]



Log de TCP View
[quote][System Process]:0 TCP ibañez:3380 194.88.50.3:smtp TIME_WAIT

[System Process]:0 TCP ibañez:3351 poi004-43749-net-adsl-02.altohiway.com:smtp TIME_WAIT

[System Process]:0 TCP ibañez:3345 *.s7a1.psmtp.com:smtp TIME_WAIT

[System Process]:0 TCP ibañez:3476 server112.appriver.com:smtp TIME_WAIT

alg.exe:1688 TCP ibañez:1026 ibañez:0 LISTENING

iexplore.exe:3928 UDP ibañez:1859 *:*

iexplore.exe:3928 TCP ibañez:3177 viruskill2.hispasec.com:http ESTABLISHED

iexplore.exe:3928 TCP ibañez:3387 viruskill2.hispasec.com:http ESTABLISHED

lsass.exe:688 UDP ibañez:isakmp *:*

lsass.exe:688 UDP ibañez:4500 *:*

services.exe:676 TCP ibañez:2655 server46.appriver.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:2744 205.147.255.207:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3042 mail4.readyserver.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3047 netkeycom.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3152 mail.rediffmail.com:smtp LAST_ACK

services.exe:676 TCP ibañez:3154 sna2.ihostsxode.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3158 ug-in-f27.google.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3171 mail.rediffmail.com:smtp LAST_ACK

services.exe:676 TCP ibañez:3180 com1.ht-systems.ru:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3190 *.s8a2.psmtp.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3209 gator275.hostgator.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3210 relay.desenvolvimento.gov.br:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3214 correo.fac.mil.co:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3215 ms47a.hinet.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3236 smtp2.adhost.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3246 mb.stack.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3273 fixitanywhere.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3286 ox.nodex.ru:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3290 217.107.216.26:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3316 mta-v1.mail.vip.re3.yahoo.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3318 correo.fac.mil.co:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3319 mail.rediffmail.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3322 mxl.lds.co.uk:smtp FIN_WAIT2

services.exe:676 TCP ibañez:3324 www6a.your-server.co.za:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3327 secure02.secure-transact.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3346 host34-76-static.116-81-b.business.telecomitalia.it:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3353 217.107.216.26:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3362 mail.rediffmail.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3366 correo.fac.mil.co:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3368 88.208.201.22:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3389 207.97.249.207:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3390 194.109.24.134:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3392 mta-v1.mail.vip.re3.yahoo.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3394 64.217.185.170:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3399 mta-v1.mail.vip.re3.yahoo.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3403 207.233.140.6:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3409 168.95.5.57:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3412 207.114.81.172:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3420 195.96.72.10:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3430 host34-76-static.116-81-b.business.telecomitalia.it:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3434 66.155.187.28:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3435 216.236.177.11:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3439 *.s5a1.psmtp.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3445 correo.fac.mil.co:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3447 221.135.102.2:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3455 *.s8a1.psmtp.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3456 68.23.235.210:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3458 mail-fwd.mx.g14.rapidsite.net:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3460 199.185.95.14:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3468 202.168.56.130:smtp FIN_WAIT2

services.exe:676 TCP ibañez:3475 202.24.68.1:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3485 203.201.220.170:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3490 69.90.236.23:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3491 207.114.81.172:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3493 213.8.234.243:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3494 216.87.61.141:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3496 69.30.97.237:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3498 212.247.182.136:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3501 221.135.102.2:smtp FIN_WAIT2

services.exe:676 TCP ibañez:3505 155.13.48.3:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3506 mail.rediffmail.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3509 correo.fac.mil.co:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3513 85.21.137.34:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3520 83.103.80.250:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3522 12.110.137.251:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3524 217.20.127.133:smtp ESTABLISHED

services.exe:676 TCP ibañez:3528 74.95.93.73:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3529 195.245.244.221:smtp ESTABLISHED

services.exe:676 TCP ibañez:3532 195.96.224.7:smtp ESTABLISHED

services.exe:676 TCP ibañez:3534 195.66.85.80:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3541 mta1.pa.level3.mail.vip.re2.yahoo.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3544 211.110.195.30:smtp ESTABLISHED

services.exe:676 TCP ibañez:3546 mxl144v2.mxlogic.net:smtp ESTABLISHED

services.exe:676 TCP ibañez:3547 216.39.53.1:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3548 199.165.223.7:smtp ESTABLISHED

services.exe:676 TCP ibañez:3552 84.22.161.74:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3556 207.35.197.62:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3559 193.151.32.48:smtp ESTABLISHED

services.exe:676 TCP ibañez:3562 65.174.233.39:smtp ESTABLISHED

services.exe:676 TCP ibañez:3563 193.180.251.48:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3564 62.118.215.200:smtp ESTABLISHED

services.exe:676 TCP ibañez:3565 62.33.137.7:smtp ESTABLISHED

services.exe:676 TCP ibañez:3570 217.196.76.28:smtp ESTABLISHED

services.exe:676 TCP ibañez:3572 222.231.3.18:smtp ESTABLISHED

services.exe:676 TCP ibañez:3573 mta1-a.rog.mail.vip.scd.yahoo.com:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3574 203.166.119.147:smtp ESTABLISHED

services.exe:676 TCP ibañez:3576 83.236.223.34:smtp ESTABLISHED

services.exe:676 TCP ibañez:3577 204.10.64.148:smtp ESTABLISHED

services.exe:676 TCP ibañez:3581 209.132.200.251:smtp ESTABLISHED

services.exe:676 TCP ibañez:3587 80.91.16.19:smtp FIN_WAIT1

services.exe:676 TCP ibañez:3589 mta-v1.mail.vip.re3.yahoo.com:smtp ESTABLISHED

services.exe:676 TCP ibañez:3591 216.12.200.84:smtp ESTABLISHED

services.exe:676 TCP ibañez:3592 smtp-in.orange.fr:smtp ESTABLISHED

services.exe:676 TCP ibañez:3594 203.216.227.209:smtp ESTABLISHED

services.exe:676 TCP ibañez:3595 209.90.82.67:smtp ESTABLISHED

services.exe:676 TCP ibañez:3597 194.186.78.68:smtp ESTABLISHED

services.exe:676 TCP ibañez:3598 208.42.176.123:smtp SYN_SENT

services.exe:676 TCP ibañez:3600 69.50.194.150:smtp ESTABLISHED

services.exe:676 TCP ibañez:3601 194.186.94.94:smtp LAST_ACK

services.exe:676 TCP ibañez:3602 85.21.137.34:smtp ESTABLISHED

services.exe:676 TCP ibañez:3603 65.248.81.141:smtp ESTABLISHED

services.exe:676 TCP ibañez:3605 204.74.99.100:smtp ESTABLISHED

services.exe:676 TCP ibañez:3606 *.s8a1.psmtp.com:smtp ESTABLISHED

services.exe:676 TCP ibañez:3607 81.29.82.108:smtp ESTABLISHED

services.exe:676 TCP ibañez:3608 69.20.116.76:smtp ESTABLISHED

services.exe:676 TCP ibañez:3609 64.246.178.122:smtp SYN_SENT

services.exe:676 TCP ibañez:3610 209.242.145.131:smtp ESTABLISHED

services.exe:676 TCP ibañez:3611 195.149.172.142:smtp ESTABLISHED

services.exe:676 TCP ibañez:3613 mail.rediffmail.com:smtp ESTABLISHED

services.exe:676 TCP ibañez:3614 221.135.102.2:smtp ESTABLISHED

services.exe:676 TCP ibañez:3615 66.98.145.180:smtp SYN_SENT

services.exe:676 TCP ibañez:3616 mta-v8.mail.vip.mud.yahoo.com:smtp ESTABLISHED

services.exe:676 TCP ibañez:3617 65.248.165.249:smtp ESTABLISHED

services.exe:676 TCP ibañez:3618 65.107.237.29:smtp ESTABLISHED

services.exe:676 TCP ibañez:3619 203.88.127.138:smtp SYN_SENT

services.exe:676 TCP ibañez:3620 216.117.199.18:smtp SYN_SENT

services.exe:676 TCP ibañez:3621 64.115.191.105:smtp ESTABLISHED

services.exe:676 TCP ibañez:3622 193.180.251.48:smtp ESTABLISHED

services.exe:676 TCP ibañez:3623 65.125.161.246:smtp ESTABLISHED

services.exe:676 TCP ibañez:3624 196.15.171.154:smtp ESTABLISHED

services.exe:676 TCP ibañez:3625 202.96.159.232:smtp ESTABLISHED

services.exe:676 TCP ibañez:3626 62.149.128.65:smtp SYN_SENT

services.exe:676 TCP ibañez:3627 mail.global.frontbridge.com:smtp SYN_SENT

services.exe:676 TCP ibañez:3628 83.222.10.132:smtp SYN_SENT

svchost.exe:1060 UDP ibañez:1046 *:*

svchost.exe:1060 UDP ibañez:1058 *:*

svchost.exe:1060 UDP ibañez:1059 *:*

svchost.exe:1060 UDP ibañez:1060 *:*

svchost.exe:1060 UDP ibañez:1061 *:*

svchost.exe:1060 UDP ibañez:1062 *:*

svchost.exe:1060 UDP ibañez:1063 *:*

svchost.exe:1060 UDP ibañez:1064 *:*

svchost.exe:1060 UDP ibañez:1065 *:*

svchost.exe:1060 UDP ibañez:1066 *:*

svchost.exe:1156 UDP ibañez:1900 *:*

svchost.exe:1156 UDP ibaÑez:1900 *:*

svchost.exe:900 TCP ibañez:epmap ibañez:0 LISTENING

svchost.exe:976 UDP ibañez:ntp *:*

svchost.exe:976 UDP ibaÑez:ntp *:*

svchost.exe:976 UDP ibañez:ntp *:*

System:4 TCP ibañez:microsoft-ds ibañez:0 LISTENING

System:4 TCP ibaÑez:netbios-ssn ibañez:0 LISTENING

System:4 UDP ibañez:microsoft-ds *:*

System:4 UDP ibaÑez:netbios-ns *:*

System:4 UDP ibaÑez:netbios-dgm *:*
[/quote]


la muestra de services.exe no la envié porque aparece sin nada sospechoso en ninguna revision pero si quiere de todas maneras la envio despues de todo sera eso hasta el 27 asi que habria tiempo

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 09 Ago 2007, 09:53

Pues no veo otra cosa que el posible intento de intrusion por falta de algun parche.



Lanza un windowsupdate:





WINDOWSUPDATE:



http://update.microsoft.com









saludos



ms, 9-08-2007

Avatar de Usuario
maxibanez77
Mensajes: 18
Registrado: 02 Mar 2007, 00:00

Estoy contento de mi..se podria decir

Mensaje por maxibanez77 » 09 Ago 2007, 21:39

Sres. [b]PROBLEMA SOLUCIONADO[/b] o eso es hasta ahora jeje:



les paso a contar cual fue la solucion porque nos dio trabajo a todos y su colaboracion es invalorable como siempre digo ... pero se nos habian escapado (porque somos humanos) algunas posibilidades.



cuando me dijo de los updates de windows, alli fui y realice el update que dio negativo pues mi maquina esta actualizada.



entonces descubri pq sinceramente no lo conocia, el "windows live one care" que tiene un revision de virus y spywares y hete aqui que detecto 1 problema, pasa que este servicio no indica donde ni cual solo que lo tienes y que "supuestamente lo solucionó



nop me quede conforme con eso, asi que instale la version de prueba de Kaspersky 7.0.0.125 y comenzo mi carrera pq detecto un "Mass-mailer software" que para los que no saben, es "Riskware" y genera la salida de spam por todos los puertos posibles. Fue entonces que me avoque exclusivamente a ese punto, y paso a contarles. el Kaspersky lo detecta, pero no lo puede poner en cuarentena ni eliminarlo y este Riskware instala rootkit asi que todo vuelve a 0 cada vez que se reinicia el sistema (este habilitado o no el Restaurar windows, puesto que crea puntos de restore por si mismo o algo asi segun lei), descubri un soft (y digo descubri pq "yo" no lo conocia) que se llama "ComboFix" del cual INTENTE ATACHAR copia junto con sus respectivos logs, para que si es necesario o interesante y no lo han hecho lo estudien u observen pero el foro no permite extensiones ".rar" asi que lo envio por mail con el asunto del post. el proceso del ComboFix lleva aproximadamente 20 minutos entre reinicio y esas cosas y veran que el antivirus detecta las actividades de este pq arregla claves de registro. no se le debe clickear la ventana por ningun motivo salvo que el programa lo pida pq sino se cuelga el sistema. en fin despues de scanear y arreglar reinicia y crea 2 logs que les adjunto en el mismo ".rar" que envio por mail y entonces se arreglo el problema.... era eso.... un riskware con rootkit que es mass-mailer y por eso generaba salidas por todos los puerto pidiendo servicio al services.exe (el cual no se infecta sino que tiene modificaciones que arregla el combofix, y por eso todos los test dan sano) e iban a parar los paquetes a puertos smtp de otras direcciones de red.



Bueno espero que el dato sea importante y les sirva. si quieren muestras de archivos pidanmelas sin problemas se las enviare. y mi direccion de e-mail esta disponible para uds cuando quieran



MUY AGRADECIDO POR SUS ATENCIONES (INCLUSIVE EN VACACIONES) Y SUERTE EN LAGO NESS (ALLI ME DIJISTE QUE IBAS VERDAD?) ;)

Avatar de Usuario
lucl
Mensajes: 6324
Registrado: 17 Ene 2006, 18:09
Ubicación: España
Contactar:

Mensaje por lucl » 10 Ago 2007, 08:22

pues si ya esta solucionado nos alegramos, creo que msc ya estara camino del lago ness asi que hasta su vuelta no podra decirte nada, cualquier cosa ya sabes, vuelve cuando quieras, saludos



otro para cerrar admin :D

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 03 Sep 2007, 12:24

Analizada la muestra enviada COMBOFIX resulta ser una utilidad que puede servir para eliminar alguna malware, sin ser propiamente un virus, por lo cual se deja estar



Y ya habiendo indicado que estaba solucionado el Tema, procedemos a cerrarlo



Si nos necesita de nuevo, ya sabe donde estamos



saludos



ms, 3-08-2007

Cerrado

Volver a “Foro Virus - Cuentanos tu problema”