Weird upload issue! help been 2 years with this
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
Weird upload issue! help been 2 years with this
my problem is that i got 1mbps/128kbps connection and my upload speed goes from 0 to 5kbps from the 128 kbps i should be getting , my downloads are fine and also i get like 200 ping and i cant navigate fast through sites! plz help im 100% sure i dont have viruses i have scanned reformated and done everything , called my isp and they say everything is ok with the connection i got 2 computers a laptop and other a desktop computer i have been with the laptop on cousins house with same internet and everything is ok on the upload also when i connect my laptop to his internet
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
my problem is that i got 1mbps/128kbps connection and my upload speed goes from 0 to 5kbps from the 128 kbps i should be getting , my downloads are fine and also i get like 200 ping and i cant navigate fast through sites! plz help im 100% sure i dont have viruses i have scanned reformated and done everything , called my isp and they say everything is ok with the connection i got 2 computers a laptop and other a desktop computer i have been with the laptop on cousins house with same internet and everything is ok on the upload also when i connect my laptop to his internet. also i cant upload anything cos the transfer fails. plz help
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
The 2wire 1701-HG is a modem with a built-in router. What do you mean that you have 2 modems? Do you mean you have a router connected to the 2wire?PatoZambrano wrote:Country mexico , i have been 3 years with this connection and 2 years with the problem kind of connection PPPoE my modem is a 2wire 1701-HG well i have 2 modems and they work same with upload and i cant do tcp analyzer right now maybe tomorrow cos im not on my house right now.
:P
Do a tracert to http://www.yahoo.com and post.
To do a tracert, click 'Start' and then 'Run'. Type "cmd" into the box and click 'ok'.
A DOS black screen will appear. Type after the C:\>
tracert http://www.yahoo.com
and press enter key
When test is completed, move mouse cursor to the DOS black screen, click right and choose 'select all'.
Move mouse cursor to the Quick Reply box of this forum, click right and 'paste'.
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
The 2wire 1701-HG is a modem with a built-in router. What do you mean that you have 2 modems? Do you mean you have a router connected to the 2wire?
no i mean i used to have a diferent one it was speedstream but now i have the 2wire one and it is same as the other one.
1 2 ms 3 ms 3 ms home [192.168.1.254]
2 27 ms 25 ms 22 ms dsl-servicio-l200.uninet.net.mx [200.38.193.226]
3 26 ms 25 ms * bb-nvl-mayo-10-POS-9-2.uninet.net.mx [201.125.74
.42]
4 56 ms 56 ms 55 ms vpn-nvl-triara-10-g5-2.uninet.net.mx [200.38.193
.9]
5 94 ms 205 ms 65 ms ge-3-3-0.ar3.LAX1.gblx.net [208.50.86.65]
6 64 ms 64 ms 66 ms yahoo-2.ar2.SJC2.gblx.net [64.208.110.166]
7 103 ms 102 ms 164 ms so-0-0-0.pat1.da3.yahoo.com [216.115.101.137]
8 103 ms 103 ms 101 ms ge-0-1-0-p130.msr2.mud.yahoo.com [216.115.104.85
]
9 100 ms 101 ms 100 ms te-9-1.bas-c1.mud.yahoo.com [68.142.193.9]
10 103 ms 104 ms 104 ms f1.http://www.vip.mud.yahoo.com [209.191.93.52]
no i mean i used to have a diferent one it was speedstream but now i have the 2wire one and it is same as the other one.
1 2 ms 3 ms 3 ms home [192.168.1.254]
2 27 ms 25 ms 22 ms dsl-servicio-l200.uninet.net.mx [200.38.193.226]
3 26 ms 25 ms * bb-nvl-mayo-10-POS-9-2.uninet.net.mx [201.125.74
.42]
4 56 ms 56 ms 55 ms vpn-nvl-triara-10-g5-2.uninet.net.mx [200.38.193
.9]
5 94 ms 205 ms 65 ms ge-3-3-0.ar3.LAX1.gblx.net [208.50.86.65]
6 64 ms 64 ms 66 ms yahoo-2.ar2.SJC2.gblx.net [64.208.110.166]
7 103 ms 102 ms 164 ms so-0-0-0.pat1.da3.yahoo.com [216.115.101.137]
8 103 ms 103 ms 101 ms ge-0-1-0-p130.msr2.mud.yahoo.com [216.115.104.85
]
9 100 ms 101 ms 100 ms te-9-1.bas-c1.mud.yahoo.com [68.142.193.9]
10 103 ms 104 ms 104 ms f1.http://www.vip.mud.yahoo.com [209.191.93.52]
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
Reducing the mtu won't help neither would formating scanning for viruses ,and spyware as far as the upload is concearned.
It could be line trouble distance factor from your house to the central office make sure you are allowing icmp traffic/ping to go though on the routers ,and software firewall. Make sure on the router the mtu is enabled.
With a 128 you are only suppose to get 15kbs a second usually with upload trouble thogh it's more of physical promblem wire issues something on pole atleast what I noticed.
It could be line trouble distance factor from your house to the central office make sure you are allowing icmp traffic/ping to go though on the routers ,and software firewall. Make sure on the router the mtu is enabled.
With a 128 you are only suppose to get 15kbs a second usually with upload trouble thogh it's more of physical promblem wire issues something on pole atleast what I noticed.
Comptia a+ n+
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
With a 128 you are only suppose to get 15kbs a second usually with upload trouble thogh it's more of physical promblem wire issues something on pole atleast what I noticed.
__________________ yeah i only get 0-1 kbs when uploading but how do i check if wires are bad or :S also the central is not so far maybe 1 km or less i got a friend with same connection near my house and he has his connection fine
__________________ yeah i only get 0-1 kbs when uploading but how do i check if wires are bad or :S also the central is not so far maybe 1 km or less i got a friend with same connection near my house and he has his connection fine
You call the phone company ,and isp to sweep the lines outside of the house for any promblems if that comes out nothing. You might want to make sure you have good wirring on the inside.
Move the dsl modem away from any electirical applicanes keep it isolated call the isp ,and have them run some test.
Move the dsl modem away from any electirical applicanes keep it isolated call the isp ,and have them run some test.
Comptia a+ n+
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
This is the results of TCP analyzer for trogers
« SpeedGuide.net TCP Analyzer Results »
Tested on: 07.26.2007 01:10
IP address: 189.154.xx.xxx
TCP options string: 020405ac0103030001010402
MSS: 1452
MTU: 1492
TCP Window: 30492 (multiple of MSS)
RWIN Scaling: 0
Unscaled RWIN : 30492
Reccomended RWINs: 63888, 127776, 255552, 511104
BDP limit (200ms): 1220kbps (152KBytes/s)
BDP limit (500ms): 488kbps (61KBytes/s)
MTU Discovery: ON
TTL: 114
Timestamps: OFF
SACKs: ON
IP ToS: 00000000 (0)
« SpeedGuide.net TCP Analyzer Results »
Tested on: 07.26.2007 01:10
IP address: 189.154.xx.xxx
TCP options string: 020405ac0103030001010402
MSS: 1452
MTU: 1492
TCP Window: 30492 (multiple of MSS)
RWIN Scaling: 0
Unscaled RWIN : 30492
Reccomended RWINs: 63888, 127776, 255552, 511104
BDP limit (200ms): 1220kbps (152KBytes/s)
BDP limit (500ms): 488kbps (61KBytes/s)
MTU Discovery: ON
TTL: 114
Timestamps: OFF
SACKs: ON
IP ToS: 00000000 (0)
You have not posted your TCP Analyzer report.
Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.
Do a speed test at this link using the recommended test server and post your results:
http://speedtest.net/
Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.
Do a speed test at this link using the recommended test server and post your results:
http://speedtest.net/
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
You have not posted your TCP Analyzer report.
Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.
Do a speed test at this link using the recommended test server and post your results:
i have already tried that 2 times placing the model without electrical devices close and everything and its still same i get 900 kbps in download and like 0-5 upload if it starts cos sometimes it doesnt
Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.
Do a speed test at this link using the recommended test server and post your results:
i have already tried that 2 times placing the model without electrical devices close and everything and its still same i get 900 kbps in download and like 0-5 upload if it starts cos sometimes it doesnt
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
:::.. testmy.net test results ..:::
Download Connection is:: 869 Kbps about 0.87 Mbps (tested with 748 kB)
Download Speed is:: 106 kB/s
Upload Connection is:: 13 Kbps about 0 Mbps (tested with 97 kB)
Upload Speed is:: 2 kB/s
Tested From:: http://testmy.net (Main)
Test Time:: 2007/07/26 - 12:29am
D-Validation Link:: http://testmy.net/stats/id-J7HFL2GRI
U-Validation Link:: http://testmy.net/stats/id-WZX1L856B
User Agent:: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.5) Gecko/20070713 Firefox/2.0.0.4;MEGAUPLOAD 1.0 [!]
Download Connection is:: 869 Kbps about 0.87 Mbps (tested with 748 kB)
Download Speed is:: 106 kB/s
Upload Connection is:: 13 Kbps about 0 Mbps (tested with 97 kB)
Upload Speed is:: 2 kB/s
Tested From:: http://testmy.net (Main)
Test Time:: 2007/07/26 - 12:29am
D-Validation Link:: http://testmy.net/stats/id-J7HFL2GRI
U-Validation Link:: http://testmy.net/stats/id-WZX1L856B
User Agent:: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.5) Gecko/20070713 Firefox/2.0.0.4;MEGAUPLOAD 1.0 [!]
Try the following with TCP Optimizer:
General Settings tab:
Custom settings - check
Modify All Network Adapters - check
network adapter selection - your NIC
MTU 1492
TTL - 64
TCP Receive Window - 63888
MTU Discovery - Yes
Black Hole Detect - No
Selective Acks - Yes
Max Duplicate ACKs - 2
TCP 1323 Options:
Windows Scaling - uncheck
Timestamps - uncheck
Advanced Settings tab:
Max Connections per Server - 10
Max Connections per 1.0 Server - 20
LocalPriority - 1
Host Priority - 1
DNSPriority - 1
NetbtPriority - 1
Lan Browsing speedup - optimized
QoS: NonBestEffortLimit - 0
ToS: DisableUserTOSSetting - 0
ToS: DefaultTOSValue - 80
MaxNegativeCacheTtl - 0
NetFailureCacheTime - 0
NegativeSOACache Time - 0
LAN Request Buffer Size - 32768
Then select "Apply Changes" and reboot to take effect
Also, scan with these new antispyware:
a-Squared Free
Ad-Aware 2007
General Settings tab:
Custom settings - check
Modify All Network Adapters - check
network adapter selection - your NIC
MTU 1492
TTL - 64
TCP Receive Window - 63888
MTU Discovery - Yes
Black Hole Detect - No
Selective Acks - Yes
Max Duplicate ACKs - 2
TCP 1323 Options:
Windows Scaling - uncheck
Timestamps - uncheck
Advanced Settings tab:
Max Connections per Server - 10
Max Connections per 1.0 Server - 20
LocalPriority - 1
Host Priority - 1
DNSPriority - 1
NetbtPriority - 1
Lan Browsing speedup - optimized
QoS: NonBestEffortLimit - 0
ToS: DisableUserTOSSetting - 0
ToS: DefaultTOSValue - 80
MaxNegativeCacheTtl - 0
NetFailureCacheTime - 0
NegativeSOACache Time - 0
LAN Request Buffer Size - 32768
Then select "Apply Changes" and reboot to take effect
Also, scan with these new antispyware:
a-Squared Free
Ad-Aware 2007
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
well i have tried optimal settings in tcp optimizer and its same , also i have already scanned with Ad-Aware 2007 and nothing :/ i got no spywares also i reformated , bought new hard drive and threw the other to the thrash can , bought new computer and the first thing i did was unplug the other one and plug new to check internet but same.. :/
It could be a line problem as suggested by Mccoffee since the problem is the same with a new comp connected.PatoZambrano wrote:well i have tried optimal settings in tcp optimizer and its same , also i have already scanned with Ad-Aware 2007 and nothing :/ i got no spywares also i reformated , bought new hard drive and threw the other to the thrash can , bought new computer and the first thing i did was unplug the other one and plug new to check internet but same.. :/
Try contacting your ISP again to test the line. Mine charges US$5 for a line check to their switch and US$8 if they have to check the line right to my home.
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
Try this NDT test. Post the report under the 'Statistics' button:PatoZambrano wrote:could you tell me how to check my wires if they are ok or something?
http://miranda.ctd.anl.gov:7123/
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
TCP/Web100 Network Diagnostic Tool v5.3.4e
click START to begin
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client to server) . . . . . Server busy: Please wait 30 seconds for previous test to finish
click START to re-test
it always say its busy :S have tried lots of times
click START to begin
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client to server) . . . . . Server busy: Please wait 30 seconds for previous test to finish
click START to re-test
it always say its busy :S have tried lots of times
If the test server is busy, all you need to do is leave your computer free and wait 30 seconds. When the test server finished testing the person before you, it will automatically test your line thereafter without you doing anything further. This test is not like a speedtest where you must click and see the test run immediately.PatoZambrano wrote:TCP/Web100 Network Diagnostic Tool v5.3.4e
click START to begin
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client to server) . . . . . Server busy: Please wait 30 seconds for previous test to finish
click START to re-test
it always say its busy :S have tried lots of times
Here are two NDT test servers you can choose from:
http://nitro.ucsc.edu/
http://miranda.ctd.anl.gov:7123/
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s
------ Client System Details ------
OS data: Name = Windows XP, Architecture = x86, Version = 5.1
Java data: Vendor = Sun Microsystems Inc., Version = 1.5.0_10
------ Web100 Detailed Analysis ------
Cable modem/DSL/T1 link found.
Link set to Full Duplex mode
No network congestion discovered.
Good network cable(s) found
Normal duplex operation found.
Web100 reports the Round trip time = 541.74 msec; the Packet size = 1452 Bytes; and
No packet loss - but packets arrived out-of-order 2.19% of the time
C2S throughput test: Packet queuing detected: 24.76%
S2C throughput test: Packet queuing detected: 11.46%
This connection is receiver limited 79.82% of the time.
Increasing the the client's receive buffer (29.0 KB) will improve performance
This connection is network limited 20.09% of the time.
Web100 reports TCP negotiated the optional Performance Settings to:
RFC 2018 Selective Acknowledgment: ON
RFC 896 Nagle Algorithm: ON
RFC 3168 Explicit Congestion Notification: OFF
RFC 1323 Time Stamping: OFF
RFC 1323 Window Scaling: OFF
Server 'nitro.ucsc.edu' is not behind a firewall. [Connection to the ephemeral port was successful]
Client is probably behind a firewall. [Connection to the ephemeral port failed]
Information: Network Middlebox is modifying MSS variable
Server IP addresses are preserved End-to-End
Information: Network Address Translation (NAT) box is modifying the Client's IP address
Server says [189.154.70.240] but Client says [192.168.1.65]
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s
------ Client System Details ------
OS data: Name = Windows XP, Architecture = x86, Version = 5.1
Java data: Vendor = Sun Microsystems Inc., Version = 1.5.0_10
------ Web100 Detailed Analysis ------
Cable modem/DSL/T1 link found.
Link set to Full Duplex mode
No network congestion discovered.
Good network cable(s) found
Normal duplex operation found.
Web100 reports the Round trip time = 541.74 msec; the Packet size = 1452 Bytes; and
No packet loss - but packets arrived out-of-order 2.19% of the time
C2S throughput test: Packet queuing detected: 24.76%
S2C throughput test: Packet queuing detected: 11.46%
This connection is receiver limited 79.82% of the time.
Increasing the the client's receive buffer (29.0 KB) will improve performance
This connection is network limited 20.09% of the time.
Web100 reports TCP negotiated the optional Performance Settings to:
RFC 2018 Selective Acknowledgment: ON
RFC 896 Nagle Algorithm: ON
RFC 3168 Explicit Congestion Notification: OFF
RFC 1323 Time Stamping: OFF
RFC 1323 Window Scaling: OFF
Server 'nitro.ucsc.edu' is not behind a firewall. [Connection to the ephemeral port was successful]
Client is probably behind a firewall. [Connection to the ephemeral port failed]
Information: Network Middlebox is modifying MSS variable
Server IP addresses are preserved End-to-End
Information: Network Address Translation (NAT) box is modifying the Client's IP address
Server says [189.154.70.240] but Client says [192.168.1.65]
The test shows your latency (round trip time) at 542ms and your TCP buffer at only 29 KB. If you have done the TCP Optimizer with my settings properly, your TCP buffer would have become 62 KB and thus your line will not have such a high percentage of 'receiver limited'.PatoZambrano wrote:WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s
------ Client System Details ------
OS data: Name = Windows XP, Architecture = x86, Version = 5.1
Java data: Vendor = Sun Microsystems Inc., Version = 1.5.0_10
------ Web100 Detailed Analysis ------
Cable modem/DSL/T1 link found.
Link set to Full Duplex mode
No network congestion discovered.
Good network cable(s) found
Normal duplex operation found.
Web100 reports the Round trip time = 541.74 msec; the Packet size = 1452 Bytes; and
No packet loss - but packets arrived out-of-order 2.19% of the time
C2S throughput test: Packet queuing detected: 24.76%
S2C throughput test: Packet queuing detected: 11.46%
This connection is receiver limited 79.82% of the time.
Increasing the the client's receive buffer (29.0 KB) will improve performance
This connection is network limited 20.09% of the time.
Web100 reports TCP negotiated the optional Performance Settings to:
RFC 2018 Selective Acknowledgment: ON
RFC 896 Nagle Algorithm: ON
RFC 3168 Explicit Congestion Notification: OFF
RFC 1323 Time Stamping: OFF
RFC 1323 Window Scaling: OFF
Server 'nitro.ucsc.edu' is not behind a firewall. [Connection to the ephemeral port was successful]
Client is probably behind a firewall. [Connection to the ephemeral port failed]
Information: Network Middlebox is modifying MSS variable
Server IP addresses are preserved End-to-End
Information: Network Address Translation (NAT) box is modifying the Client's IP address
Server says [189.154.xxx.xxx] but Client says [192.168.1.65]
Rerun the settings I gave and test again.
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
TCP Optimizer only make changes in the Windows registry of the comp. So you have to use TCP Optimizer on each and every comp that runs Windows, except those that is using Vista. TCP Optimizer does not tweak Vista.PatoZambrano wrote:but are will tcp optimizer change settings of my connection or only this comp? cos i got 2 new laptops and this computer and they are same to this on internet
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
This test showed your upload speed is not a problem.PatoZambrano wrote:WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s![]()
It is your download speed that is bad at only 14 kbps. Suggest you increase your TCP buffer by setting TCP Window to 63888.
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
What kind of firewall and antivirus are you using?PatoZambrano wrote:upload is my problem i can just download fine at like 110 kbytes almost all time but i cant even upload a 40kb pic to photobucket or anything
What is the brand and model of your router and modem?
Download and run HijackThis and post the report:
http://www.majorgeeks.com/download3155.html
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
my antivirus right now is nod32 my router is 2wire 1701-HG
And here is the hijackthis report:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 6467 bytes
And here is the hijackthis report:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 6467 bytes
-
PatoZambrano
- Member
- Posts: 57
- Joined: Tue Jul 24, 2007 1:34 am
srry i didnt pasted correct
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:34:16 a.m., on 30/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\svchost.exe
C:\ARCHIV~1\Mozilla Firefox\firefox.exe
C:\Downloads\setups\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 6467 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:34:16 a.m., on 30/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\svchost.exe
C:\ARCHIV~1\Mozilla Firefox\firefox.exe
C:\Downloads\setups\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 6467 bytes