Serios Problemas "Project 1", agrego el hijacklist

Responder
marlboromen
Mensajes: 2
Registrado: 12 Oct 2006, 06:48

Serios Problemas "Project 1", agrego el hijacklist

Mensaje por marlboromen » 12 Oct 2006, 07:03

Saludos primero que nada..



La verdad es que nunca me habia pasado nada igual, la cosa va asi.



Cuando prendo el ordenador, me abre un error de un dll, un run time error, posteriormente se tratan de abrir paginas de internet o mas bien dicho se abre la ventana en la cual me pregunta si es que quiero conectarme a internet o trabajar offline.



Otro de los problemas es que cuando quiero meterme en el panel de control, en un principio si me dejaba pero ahora que estoy escribiendo estas lineas, no me deja y es como si se reiniciara el "explorer.exe", no me deja trabajar con el "iexplore.exe"



Ahora estoy escribiendo desde firefox mozilla, al estar buscando informacion acerca de esto de vez en vez me aparecen pop ups suponiendo antivirus y cosas asi...



he usado el Ad aware, he corrido el norton antivirus, y al parecer si se han eliminado muchas cosas pero ya lo he hecho varias veces y no me deja trabajar adecuadamente.



Cuando reinicio la maquina me aparecen en el task manager dos aplicaciones con el nombre de "Project 1"..



Agradezco de antemano la lectura de mi post y espero exista una pronta solucion a mi problema.



MUCHAS GRACIAS





Logfile of HijackThis v1.99.1

Scan saved at 11:27:23 PM, on 10/11/2006

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\Program Files\Norton Internet Security\NISUM.EXE

C:\Program Files\Norton Internet Security\ccPxySvc.exe

C:\Program Files\sony\giga pocket\shwserv.exe

C:\Program Files\Norton AntiVirus\navapsvc.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

C:\Program Files\Sony\giga pocket\RM_SV.exe

C:\WINDOWS\system32\winlogon.exe

C:\Program Files\Apoint\Apoint.exe

C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe

C:\WINDOWS\System32\ICO.EXE

C:\Program Files\Sony\HotKey Utility\HKserv.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\System32\ezSP_Px.exe

C:\program files\support.com\client\bin\tgcmd.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

C:\WINDOWS\elitepop06.exe

C:\Program Files\Apoint\Apntex.exe

C:\Program Files\Sony\HotKey Utility\HKWnd.exe

C:\WINDOWS\System32\SSTEM~1\rundll32.exe

C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

C:\Program Files\PowerPanel\Program\PcfMgr.exe

C:\Program Files\Sony\USBSircs\usbsircs.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\Program Files\Common Files\Symantec Shared\NMain.exe

C:\PROGRA~1\NORTON~1\navw32.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Hijackthis\HijackThis.exe



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

R3 - URLSearchHook: (no name) - _{A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)

R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)

R3 - URLSearchHook: (no name) - {BF169783-5B1D-27BF-41F0-75E29F007294} - C:\WINDOWS\System32\wkib.dll

F2 - REG:system.ini: UserInit=userinit.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\S Vaughn\Application Data\Mozilla\Profiles\default\y559b0ao.slt\prefs.js)

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\C-Major Audio\stacmon.exe

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

O4 - HKLM\..\Run: [otj64643] RUNDLL32.EXE wb3c7fd9.dll,n 0056463e00000012b3c7fd9

O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe

O4 - HKLM\..\Run: [rbzwxkzA] C:\WINDOWS\rbzwxkzA.exe

O4 - HKLM\..\Run: [sys0158343466-] C:\WINDOWS\sys0158343466-.exe

O4 - HKLM\..\Run: [newname] C:\\nwnmff_e26.exe

O4 - HKLM\..\Run: [defender] C:\\dfndrff_e26.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e26.exe

O4 - HKLM\..\Run: [xload] "C:\WINDOWS\xload.exe"

O4 - HKLM\..\Run: [1pop06apelt2] C:\WINDOWS\elitepop06.exe

O4 - HKLM\..\Run: [sys028343466-5] C:\WINDOWS\sys028343466-5.exe

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKCU\..\Run: [Iinl] "C:\WINDOWS\System32\SSTEM~1\rundll32.exe" -vt tzt

O4 - HKCU\..\Run: [Rqchomh] C:\Documents and Settings\S Vaughn\Application Data\??crosoft\w?crtupd.exe

O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"

O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe

O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: PowerPanel.lnk = ?

O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe

O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE

O4 - Global Startup: Remocon Driver.lnk = ?

O4 - Global Startup: Timer Recording Manager.lnk = C:\Program Files\Sony\giga pocket\ReserveModule.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)

O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

O15 - Trusted Zone: *.adgate.info

O15 - Trusted Zone: *.adsextend.net

O15 - Trusted Zone: *.dollarrevenue.com

O15 - Trusted Zone: *.elitemediagroup.net

O15 - Trusted Zone: *.imagesrvr.com

O15 - Trusted Zone: *.matcash.com

O15 - Trusted Zone: *.media-motor.com

O15 - Trusted Zone: *.mediatickets.net

O15 - Trusted Zone: *.mmohsix.com

O15 - Trusted Zone: *.snipernet.biz

O15 - Trusted Zone: *.sxload.com

O15 - Trusted Zone: *.systemdoctor.com

O15 - Trusted Zone: *.winantivirus.com

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe

O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\sony\giga pocket\shwserv.exe

O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)

O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\giga pocket\halsv.exe

O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\giga pocket\RM_SV.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)

O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)

O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe

O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)

O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)

O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)

O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 12 Oct 2006, 10:16

De entrada debe actualizarlos parches de microsoft. Le faltan todos los del SP2 y posteriores. Lance un windowsupdate !!!





Tras ello lance el ELISTARA para eliminar las O15:





ELISTARA:

http://www.zonavirus.com/descargas/elistara.asp





Y elimine estas claves:



R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)



R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)



O4 - HKLM\..\Run: [otj64643] RUNDLL32.EXE wb3c7fd9.dll,n 0056463e00000012b3c7fd9



O4 - HKLM\..\Run: [newname] C:\\nwnmff_e26.exe



O4 - HKLM\..\Run: [defender] C:\\dfndrff_e26.exe



O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e26.exe



O4 - HKLM\..\Run: [xload] "C:\WINDOWS\xload.exe"



O4 - HKCU\..\Run: [Rqchomh] C:\Documents and Settings\S Vaughn\Application Data\??crosoft\w?crtupd.exe



O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"



O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\c"



O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"



O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe



O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)



O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)



O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)



O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)



O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)



O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)



O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)





y estas, si aun persisten (y comprobar su eliminacion !!!)





O15 - Trusted Zone: *.adgate.info



O15 - Trusted Zone: *.adsextend.net



O15 - Trusted Zone: *.dollarrevenue.com



O15 - Trusted Zone: *.elitemediagroup.net



O15 - Trusted Zone: *.imagesrvr.com



O15 - Trusted Zone: *.matcash.com



O15 - Trusted Zone: *.media-motor.com



O15 - Trusted Zone: *.mediatickets.net



O15 - Trusted Zone: *.mmohsix.com



O15 - Trusted Zone: *.snipernet.biz



O15 - Trusted Zone: *.sxload.com



O15 - Trusted Zone: *.systemdoctor.com



O15 - Trusted Zone: *.winantivirus.com









y diganos si conoce estas utilidades que tiene instaladas:









C:\WINDOWS\elitepop06.exe ???



C:\WINDOWS\System32\wkib.dll ???





O4 - HKLM\..\Run: [rbzwxkzA] C:\WINDOWS\rbzwxkzA.exe ???



O4 - HKLM\..\Run: [sys0158343466-] C:\WINDOWS\sys0158343466-.exe ???



O4 - HKLM\..\Run: [sys028343466-5] C:\WINDOWS\sys028343466-5.exe ???



O4 - HKCU\..\Run: [Iinl] "C:\WINDOWS\System32\SSTEM~1\rundll32.exe" -vt tzt ???









saludos



ms, 12-10-2006
Última edición por msc hotline sat el 13 Oct 2006, 08:20, editado 1 vez en total.

marlboromen
Mensajes: 2
Registrado: 12 Oct 2006, 06:48

Mensaje por marlboromen » 13 Oct 2006, 02:17

Gracias por su pronta respuesta, llegando a mi casa hago lo que me suguieres posteriormente te paso el log, de lo que me muestre.



Gracias.



Saludos.

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 13 Oct 2006, 08:27

Añadida la eliminacion de una clave, revisa mi post anterior:



O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe



saludos



13-10-2006

Responder

Volver a “Foro HijackThis - copia y pega tu log”