Acá te mando el resultado del "STARTUPLIST", (el log del hijackthis es el que no se como mandar), otra vez gracias.
StartupList report, 15/07/04, 07:05:11 p.m.
StartupList version: 1.52
Started from : C:\MIS DOCUMENTOS\NUEVA CARPETA\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\ARCHIVOS DE PROGRAMA\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\ARCHIVOS DE PROGRAMA\MESSENGER PLUS! 3\MSGPLUS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\CMMPU.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\ARCHIVOS DE PROGRAMA\GRISOFT\AVG6\AVGCC32.EXE
C:\ARCHIVOS DE PROGRAMA\WINDOWJUNKPOKE\BALL LOUD.EXE
C:\ARCHIVOS DE PROGRAMA\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\ARCHIVOS DE PROGRAMA\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\ARCHIVOS DE PROGRAMA\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
C:\ARCHIVOS DE PROGRAMA\MSN MESSENGER\MSNMSGR.EXE
C:\MIS DOCUMENTOS\NUEVA CARPETA\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Menú Inicio\Programas\Inicio]
Inicio de Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
LoadQM = loadqm.exe
AVG_CC = C:\ARCHIVOS DE PROGRAMA\GRISOFT\AVG6\avgcc32.exe /startup
QuickTime Task = "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
Greylove = C:\ARCHIV~1\WINDOW~3\Ball Loud.exe
Zone Labs Client = "C:\Archivos de programa\Zone Labs\ZoneAlarm\zlclient.exe"
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
winmodem = WINMODEM.101\wmexe.exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
Avgserv9.exe = C:\ARCHIV~1\GRISOFT\AVG6\Avgserv9.exe
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
MessengerPlus3 = "C:\Archivos de programa\Messenger Plus! 3\MsgPlus.exe"
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo! Pager = C:\ARCHIV~1\YAHOO!\MESSEN~1\ypager.exe -quiet
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=
run=C:\WINDOWS\SYSTEM\cmmpu.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 27/6/2004, 21:59:24)
[rename]
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE
C:\WINDOWS\SYSTEM\VSXML.DLL=C:\WINDOWS\SYSTEM\~GLH0020.TMP
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
C:\ARCHIV~1\GRISOFT\AVG6\bootup.exe
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
keyb la,,C:\WINDOWS\COMMAND\keyboard.sys
C:\WINDOWS\SYSTEM\setaudio /S
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\ARCHIVOS DE PROGRAMA\YAHOO!\COMMON\YCOMP5_2_3_0.DLL - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\ARCHIVOS DE PROGRAMA\COOLLOGOSTART\CITYBIAS.DLL - {22B6B2ED-3525-93E9-F3A7-3CDE89C48D38}
(no name) - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE =
http://v4.windowsupdate.microsoft.com/CAB/...7990.4044907407
[iPIX Media Send Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\IPIX-IMAGEWELL-IPIX.DLL
CODEBASE =
http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE =
http://download.yahoo.com/dl/installs/yinst0309.cab
[YahooYMailTo Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YMMAPI.DLL
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
[PremiumHTML Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\IBEROD~1.DLL
CODEBASE = http://213.254.243.5/data/dialercab/IberoDialerHTML.cab
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE =
http://www.apple.com/qtactivex/qtplugin.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 6.428 bytes
Report generated in 4,470 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list versión history only