smart-search.biz como pagina de inicio

Responder
DEBORA
Mensajes: 1
Registrado: 02 May 2005, 16:27

smart-search.biz como pagina de inicio

Mensaje por DEBORA » 02 May 2005, 16:33

Necesito saber como eliminar smart-search.biz y paginas que se agregaron a la carpeta favoritos y aunque las elimine vuelven...aqui les copié mi log. Desde ya muchas gracias!

Débora









Logfile of HijackThis v1.98.2

Scan saved at 11:24:55 a.m., on 02/05/2005

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)



Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Documents and Settings\user\Local Settings\Temp\Temporary Directory 2 for HijackThis.zip\HijackThis 1.98.2.exe



R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.smart-search.biz

R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.smart-search.biz

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hotmail.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.smart-search.biz

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.smart-search.biz

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.smart-search.biz

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.smart-search.biz

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.smart-search.biz

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.55.208:80

O1 - Hosts: auto.search.msn.com 127.0.0.1

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll

O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\System & Internet Washer\pkext.dll

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\es-la\msntb.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O2 - BHO: MIME Type Support Dll - {ED045E50-1DD5-4FA1-B468-E624CC585D3A} - C:\WINDOWS\System32\mimtcore.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\es-la\msnappau.exe"

O4 - HKLM\..\Run: [fb7w3N] C:\WINDOWS\abbhd.exe

O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\CA-80U\ADSL\CnxDslTb.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\RunOnce: [uuetype] C:\WINDOWS\System32\uuetype.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Waat] C:\WINDOWS\System32\noao.exe

O4 - Startup: System & Internet Washer.lnk = C:\Program Files\System & Internet Washer\cseraser.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra button: System & Internet Washer - {4A0EF50C-6A4A-4b30-84D8-53D5BC95C043} - C:\Program Files\System & Internet Washer\cseraser.exe (HKCU)

O10 - Hijacked Internet access by New.Net

O13 - DefaultPrefix: http://www.smart-search.biz/best.php?url=

O13 - WWW Prefix: http://www.smart-search.biz/best.php?url=

O13 - Home Prefix: http://www.smart-search.biz/best.php?url=

O13 - Mosaic Prefix: http://www.smart-search.biz/best.php?url=

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1114458578820

O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab



[/b]

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Mensaje por msc hotline sat » 02 May 2005, 16:41

Ha seguido las instrucciones del primer Tema de este apartado?



https://foros.zonavirus.com/viewtopic.php?t=5148



Ha lanzado el ELISTARA.EXE???



http://www.zonavirus.com/descargas/elistara.asp



So tras ello persisten los problemas, postee su log, pero hagalo con la version actual del HJT, la 1.99.1, gracias



saludos



ms, 2-05-2005

Responder

Volver a “Foro HijackThis - copia y pega tu log”