esta compu tenia el NOD32, el primer sintoma de problema es que en un momento se perdio la conexion de adsl, luego empezaron varios otros problemas, como que a veces no termina de cargar todo y hay que reiniciar, o que sale una ventanita diciendo q se va a cerrar el sistema, a veces x el archivo services.exe o tambien x el lsass.exe
desinstale el nod32, instale el avast, lo pase, instale y pase el bitdefender y el avira (el que esta ahora corriendo), instale el spybot, adaware, malwarebytes, ahora tambien tengo activo el SUPERAntispyware que cada tanto me avisa q se quiere cambiar la pagina de inicio, todos encuentran alguna cosa, limpian pero despues vuelve a aparecer
no pude hacer correr el scan online de symantec, el de panda, dps de avisarme q estaba infectado no consegui ver los detalles
tambien ya pase el ccleaner
algunos de los procesos los he realizado desde modo a prueba de fallos, pero sin mejor resultado aparente
y la verdad q ya no se bien que mas puedo hacer.....
espero ayuda
desde ya muchisimas gracias
ahora pego el log del hijackthis y el de avira, y por supuesto, me van diciendo que puedo hacer para avanzar en el diagnostico y luego en la solucion
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:08:23, on 30/11/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Archivos de programa\Lavasoft\Ad-Aware\aawservice.exe
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINNT\system32\svchost.exe
C:\Archivos de programa\LogMeIn\x86\RaMaint.exe
C:\Archivos de programa\LogMeIn\x86\LogMeIn.exe
C:\Archivos de programa\LogMeIn\x86\LMIGuardian.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Archivos de programa\WinPoET\WrOS.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Archivos de programa\LogMeIn\x86\LogMeInSystray.exe
C:\Archivos de programa\LogMeIn\x86\LMIGuardian.exe
C:\Archivos de programa\Archivos comunes\Logitech\QCDriver2\LVCOMS.EXE
C:\Archivos de programa\WinPoET\winpppoverethernet.exe
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Archivos de programa\Skype\Phone\Skype.exe
C:\Program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Archivos de programa\JustVoip.com\JustVoip\JustVoip.exe
C:\Program files\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O4 - HKLM\..\Run: [LVCOMS] C:\Archivos de programa\Archivos comunes\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Archivos de programa\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Archivos de programa\WinPoET\winpppoverethernet.exe"
O4 - HKLM\..\Run: [z-WrDialer] C:\Archivos de programa\WinPoET\WrDialer.exe
O4 - HKLM\..\Run: [avgnt] "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Networking Monitoring] C:\WINNT\system32\mdm.exe
O4 - HKLM\..\Run: [mmsass] msv.exe
O4 - HKLM\..\RunServices: [mmsass] msv.exe
O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Windows Networking Monitoring] C:\WINNT\system32\mdm.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Windows Networking Monitoring] C:\WINNT\system32\mdm.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_03\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\CAD\Autodesk Architectural Desktop 3\AcDcToday.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\CAD\Autodesk Architectural Desktop 3\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{63BBBCAD-F240-46AF-990B-0A8E9B6B77E0}: NameServer = 200.40.220.245 200.40.30.245
O20 - Winlogon Notify: !SASWinLogon - C:\Program files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Archivos de programa\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: JFWService - Freedom Scientific BLV Group, LLC - C:\JAWS451\jfw.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\x86\LogMeIn.exe
O23 - Service: Windows Host Services (SVCHOSTS32) - Unknown owner - C:\WINNT\system\svchost.exe (file missing)
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Archivos de programa\WinPoET\WrOS.EXE
--
End of file - 5654 bytes
Avira AntiVir Personal
Report file date: domingo, 30 de noviembre de 2008 12:22
Scanning for 1059587 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows 2000
Windows version: (Service Pack 4) [5.0.2195]
Boot mode: Normally booted
Username: SYSTEM
Computer name: STEVIE
Version information:
BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 12:21:28
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 11:56:42
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 16:44:20
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 11:58:54
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 15:30:38
ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 20:57:14
ANTIVIR2.VDF : 7.1.0.124 376832 Bytes 23/11/2008 14:48:46
ANTIVIR3.VDF : 7.1.0.159 206848 Bytes 29/11/2008 14:48:54
Engineversion : 8.2.0.36
AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 14:05:58
AESCRIPT.DLL : 8.1.1.15 332156 Bytes 11/11/2008 18:00:08
AESCN.DLL : 8.1.1.5 123251 Bytes 07/11/2008 19:06:42
AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 17:58:40
AEPACK.DLL : 8.1.3.4 393591 Bytes 11/11/2008 13:41:40
AEOFFICE.DLL : 8.1.0.30 196986 Bytes 07/11/2008 19:06:42
AEHEUR.DLL : 8.1.0.71 1487222 Bytes 07/11/2008 19:06:42
AEHELP.DLL : 8.1.2.0 119159 Bytes 30/11/2008 14:49:04
AEGEN.DLL : 8.1.1.6 323955 Bytes 30/11/2008 14:49:02
AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 14:05:58
AECORE.DLL : 8.1.5.2 172405 Bytes 30/11/2008 14:48:56
AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 14:05:58
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 12:40:06
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 13:28:02
AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 16:02:16
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 15:26:42
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 12:29:24
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 16:27:50
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 21:28:04
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 16:49:42
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 16:05:12
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 17:48:08
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 17:34:38
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\archivos de programa\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: domingo, 30 de noviembre de 2008 12:22
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'LMIGuardian.exe' - '1' Module(s) have been scanned
Scan process 'LogMeIn.exe' - '1' Module(s) have been scanned
Scan process 'LMIGuardian.exe' - '1' Module(s) have been scanned
Scan process 'Skype.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'winpppoverether' - '1' Module(s) have been scanned
Scan process 'LogMeInSystray.' - '1' Module(s) have been scanned
Scan process 'LVCOMS.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
Scan process 'WrOS.EXE' - '1' Module(s) have been scanned
Scan process 'WinMgmt.exe' - '1' Module(s) have been scanned
Scan process 'MSTask.exe' - '1' Module(s) have been scanned
Scan process 'LMIGuardian.exe' - '1' Module(s) have been scanned
Scan process 'LogMeIn.exe' - '1' Module(s) have been scanned
Scan process 'RaMaint.exe' - '1' Module(s) have been scanned
Scan process 'jfw.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '0' Module(s) have been scanned
Scan process 'sched.exe' - '0' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <C>
C:\Documents and Settings\Default User\Configuración local\Archivos temporales de Internet\Content.IE5\SAV86YQM\t[1].txt
[DETECTION] Is the TR/Crypt.ULPM.Gen Trojan
[NOTE] The file was deleted!
Begin scan in 'D:\' <DISCO LOCAL>
D:\pagefile.sys
[WARNING] The file could not be opened!
End of the scan: domingo, 30 de noviembre de 2008 13:13
Used time: 51:05 Minute(s)
The scan has been done completely.
3374 Scanning directories
170127 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
1 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
170125 Files not concerned
3533 Archives were scanned
1 Warnings
1 Notes