Nokia_Multimedia_Common_Components_2.5-Installshield Wizard Tema Solucionado

Foro referente al sistema operativo Windows Vista (Longhorn)
mecmora
Usuario linuxero
Usuario linuxero
Mensajes: 10
Registrado: 02 Ene 2012, 23:18
Contactar:

Nokia_Multimedia_Common_Components_2.5-Installshield Wizard

Mensajepor mecmora » 02 Ene 2012, 23:43

Hola! Paz para todos! Feliz Año!

El mensaje de error es "Nokia_Multimedia_Common_2.5-Installsheld wizard: El componente común multimedia de Nokia no puede desinstalarse porque se requiere para OVI Player". Yo no quiero desinstalarlo, pero continuamente se intenta desinstalar, para después darme una ventana de aviso "Detección del cuadro de diálogo de servicios interactivos" dentro de la cual da el mensaje de error mencionado.

Adjunto información conseguida con "Hijackthis",

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:55:22, on 02/01/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\WebProxy.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Program Files\DUE\DUESysTrayCD.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\ApVxdWin.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Vid HD\Vid.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Siemens\Card API\bin\siecacst.exe
C:\Program Files\TEXTware\HotKey\Twalink.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\lexibase.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\PROGRA~1\COMMON~1\Nokia\MPLATF~1\NOKIAM~1.EXE
C:\Program Files\Panda Security\Panda Global Protection 2012\PavBckPT.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Windows\system32\ntvdm.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conime.exe
C:\Program Files\Panda USB Vaccine\USBVaccine.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://es.yappr.com/welcome/Welcome2.action
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
R3 - URLSearchHook: Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RTP - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Ziepod One-Click IE Helper - {57A30D1E-08B9-4EF4-B273-AAEA1C234A5B} - C:\Windows\system32\ZiepodOneClicker.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: (no name) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - (no file)
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O3 - Toolbar: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [recinfo471] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [DUESystray] C:\Program Files\DUE\DUESystrayCD.exe
O4 - HKLM\..\Run: [RestartNeroSetup] "C:\Users\MANUEL~1\AppData\Local\Temp\Nero Web\SetupXu.exe" MODE="update" STARTMODE="2" USERSEL="3" FAMILYNAME="Nero 7" RUNSETUPXU="1" UPGRADE="1"
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [RegistrarUsrDNIeCertStoreDLL] "C:\Program Files\DNIe\udcs.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2012\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2012\Inicio.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [9DBF38FFBBFF11D1ED54B9C758C5C565B3CBBBB5._service_run] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: bDule.appref-ms
O4 - Global Startup: HiPath SIcurity Card API.lnk = ?
O4 - Global Startup: HotKey.lnk = C:\Program Files\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lexibase Express.lnk = C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra 'Tools' menuitem: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Portafolios de HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Selección inteligente de HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: ClickPotato - {B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} - C:\Program Files\ClickPotatoLite\bin\10.0.622.0\ClickPotatoLiteSABHO.dll
O9 - Extra button: (no name) - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O9 - Extra 'Tools' menuitem: Xmarks for IE... - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - http://dl.google.com/dl/desktop/nv/Goog ... nIEWin.cab
O16 - DPF: {8A177687-28EB-48DB-9CCB-5C5254D10568} - http://es.yappr.com/practice/core/EduSpeakX.cab
O16 - DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - https://www5.aeat.es/es13/h/cactivex.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Administrador de Google Desktop 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c986365bb6fea8) (gupdate1c986365bb6fea8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\pavsrvx86.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Panda Host Service (PSHost) - Panda Security International - c:\program files\panda security\panda global protection 2012\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PskSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\TPSrv.exe
O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

--
End of file - 17953 bytes

¿Puede alguien decirme como este continuo reintento de ejecutar un programa de forma automática por el sistema?
saludos

Avatar de Usuario
helheim
Usuario Bill Gates
Usuario Bill Gates
Mensajes: 5001
Registrado: 20 Abr 2008, 11:38
Agradecido : 24 veces
Agradecimiento recibido: 169 veces
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor helheim » 03 Ene 2012, 13:02

El log indica una serie de entradas sospechosas. Realiza los siguientes pasos:

En primer lugar ejecuta de nuevo HijackThis (con todos los programas cerrados y como Administrador; para eso pulsa con el botón derecho del raton sobre el programa y elige "Ejecutar como Administrador"), pulsa sobre "Do a system scan only", marca las siguientes entradas y pulsa "Fix Checked":

O2 - BHO: (no name) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - (no file)
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray



Vete a Inicio/Panel de Control/Desinstalar un programa y en la lista que te sale busca algo relacionado con los siguientes nombres (o algo parecido):

Ask Toolbar
Spigot
Softissimo
ConduitEngine
Vuze Remote Toolbar
FreeRIP Toolbar


Desinstala esos elementos, pasa CCLEANER y limpia tanto Archivos Temporales como Registro (pásalo las veces que sean necesarias hasta que no te aparezca nada).

Después, vuelve a ejecutar Hijackthis como Administrador (sin tener nada abierto salvo Hijackthis)y péganos el log de nuevo.

Un saludo.
La experiencia es una llama que alumbra quemando (Benito Pérez Galdós)

mecmora
Usuario linuxero
Usuario linuxero
Mensajes: 10
Registrado: 02 Ene 2012, 23:18
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor mecmora » 03 Ene 2012, 22:47

no he podido quitar:
-Ask toolbar, ni freeRIP Toolbar, dan el mensaje:"Se está instalando otro programa. espere hasta que dicha instalación se complete y después intente instalar este software de nuevo"
-Vuze remote Toolbar, da el mensaje:"Could not open INSTALL.LOG file"

aparentemente ha desaparecido el problema de reinicio del Installer



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:31:07, on 03/01/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\WebProxy.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Program Files\DUE\DUESysTrayCD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\ApVxdWin.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Vid HD\Vid.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Program Files\Siemens\Card API\bin\siecacst.exe
C:\Program Files\TEXTware\HotKey\Twalink.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\lexibase.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\PavBckPT.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://es.yappr.com/welcome/Welcome2.action
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
R3 - URLSearchHook: Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RTP - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O2 - BHO: Ziepod One-Click IE Helper - {57A30D1E-08B9-4EF4-B273-AAEA1C234A5B} - C:\Windows\system32\ZiepodOneClicker.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O3 - Toolbar: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [recinfo471] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [DUESystray] C:\Program Files\DUE\DUESystrayCD.exe
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [RegistrarUsrDNIeCertStoreDLL] "C:\Program Files\DNIe\udcs.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2012\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2012\Inicio.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [9DBF38FFBBFF11D1ED54B9C758C5C565B3CBBBB5._service_run] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: bDule.appref-ms
O4 - Global Startup: HiPath SIcurity Card API.lnk = ?
O4 - Global Startup: HotKey.lnk = C:\Program Files\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lexibase Express.lnk = C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra 'Tools' menuitem: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Portafolios de HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Selección inteligente de HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: ClickPotato - {B58926D6-CFB0-45d2-9C28-4B5A0F0368AE} - C:\Program Files\ClickPotatoLite\bin\10.0.622.0\ClickPotatoLiteSABHO.dll
O9 - Extra button: (no name) - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O9 - Extra 'Tools' menuitem: Xmarks for IE... - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - http://dl.google.com/dl/desktop/nv/Goog ... nIEWin.cab
O16 - DPF: {8A177687-28EB-48DB-9CCB-5C5254D10568} - http://es.yappr.com/practice/core/EduSpeakX.cab
O16 - DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - https://www5.aeat.es/es13/h/cactivex.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Administrador de Google Desktop 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c986365bb6fea8) (gupdate1c986365bb6fea8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\pavsrvx86.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Panda Host Service (PSHost) - Panda Security International - c:\program files\panda security\panda global protection 2012\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PskSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\TPSrv.exe
O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

--
End of file - 16045 bytes

Avatar de Usuario
helheim
Usuario Bill Gates
Usuario Bill Gates
Mensajes: 5001
Registrado: 20 Abr 2008, 11:38
Agradecido : 24 veces
Agradecimiento recibido: 169 veces
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor helheim » 04 Ene 2012, 13:47

Vuelve a intentar desinstalar los programas y barras que te dije. No mencionas nada de:

Softissimo
Spigot
ConduitEngine


Independientemente de eso, realiza lo siguiente:

1) Ten a mano un Punto de Restauración (En Windows Vista)

2) Descarga y ejecuta Toolbar-S&D. Selecciona el idioma español y elige "Eliminar". Guarda el log y pégalo aquí en tu próximo mensaje.

MANUAL DE TOOLBAR-S&D.

3) Reinicia en " Modo Seguro" (Pulsando varias veces F8 al iniciar o reinicar el ordenador hasta que te aparezca la ventana de inicio avanzado).

4) Pasa Malwarebytes Anti-Malware (MANUAL) (ANÁLISIS COMPLETO).

Tras eso reinicia y vuelve a ejecutar Hijackthis para ver como quedó (péganos el log).

Un saludo.
La experiencia es una llama que alumbra quemando (Benito Pérez Galdós)

mecmora
Usuario linuxero
Usuario linuxero
Mensajes: 10
Registrado: 02 Ene 2012, 23:18
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor mecmora » 05 Ene 2012, 23:21

He intentado de nuevo las desinstalaciones de los programas que mencionas con el resultado ya conocido:
ConduitEngine...............Desinstalado sin problemas.
Softissimo.....................No lo he localizado.
Spigot.........................Estaba relacionado con el programa FreeRIP, quedando este desinstalado sin problemas.
Ask Toolbar..................No se puede desinstalar. Mensaje:"se está instalando otro programa. Espere hasta que dicha instalación se complete y después intente instalar este software de nuevo".
FreeRIP Toolbar.............Idem anterior.
Vuze remote Toolbar......No se puede desinstalar. Mensaje:"Could not open INSTALL.LOG file.

Una vez ejecutadas las herramientas que me aconsejas ( te adjunto los logs al final), se abre el cuadro de diálogo siguiente:
"Detección del cuadro de diálogo de servicios interactivos.
Programa o dispositivo que necesitan atención:
Titulo: Nokia_Multimedia_Common_Components_2_5- InstallShield Wizard.
Ruta de acceso del programa: C:\Windows\System32\MsiExec.exe
Este problema se debe a una incompatibilidad parcial con Windows.
Póngase en contacto con el fabricante del programa o dispositivo para obtener más información".

saludos,

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Report de Toolbar ED:


-----------\\ ToolBar S&D 1.2.9 XP/Vista


"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( 05/01/2012|20:34 )

[ UAC => 1 ]

-----------\\ ELIMINAR

í Borrado ! - C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\ShopperReports
í Borrado ! - C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65

-----------\\ Deteccion de archivos y carpetas ToolBar ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://es.yappr.com/welcome/Welcome2.action"
"Start Page Restore"="http://www.cincodias.com/"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"


--------------------\\ Deteccion de otras infecciones

C:\Program Files\Live-Player
C:\Program Files\Live-Player\data
C:\Program Files\Live-Player\img
C:\Program Files\Live-Player\live-player.log
C:\Program Files\Live-Player\SkinCrafterDll.dll
C:\Program Files\Live-Player\skins
C:\Program Files\Live-Player\sqlite3.dll
C:\Users\MANUEL~1\AppData\Roaming\live-player
C:\Users\MANUEL~1\AppData\Roaming\live-player\liveplayer.s3db
C:\Users\MANUEL~1\AppData\Roaming\live-player\flv.swf
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Confidencialidad.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Desinstalar.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Live-Player.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\T‚rminos y condiciones.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Live-Player\Website.url
C:\Program Files\WebMediaPlayer
C:\Program Files\WebMediaPlayer\resources
C:\Program Files\WebMediaPlayer\skins
C:\Program Files\WebMediaPlayer\sqlite3.dll
C:\Program Files\WebMediaPlayer\updates
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Confidencialidad.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Desinstalar.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\T‚rminos y condiciones.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\WebMediaPlayer.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Website.url
==> EGDACCESS <==

--------------------\\ Cracks & Keygens ..

C:\Users\MANUEL~1\Documents\FrostWire\Shared\guitarra [crack][fixed].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\guitarra [WinAll.ZeDoZa.Crack].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\idiomatic expression crack and keygen (100% good).zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\musica celta [crack][fixed].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\the no. 1 laides detcetive ag [crack][fixed].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\the no. 1 laides detcetive ag [crack][SaCaVb].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\the no. 1 ldaies deetctive ag [crack][fixed].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\[CRACK].[musica celta].[by FFF].zip
C:\Users\MANUEL~1\Documents\FrostWire\Shared\[tested 100% working] idiomatic expression crack by EMBRACE.zip


[ UAC => 1 ]


1 - "C:\ToolBar SD\TB_1.txt" - 05/01/2012|20:35 - Option : [2]

-----------\\ Analisis terminado a 20:35:41,10

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Report Malwarebyte

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Versión de la Base de Datos: v2012.01.05.03

Windows Vista Service Pack 2 x86 NTFS (modo seguro)
Internet Explorer 9.0.8112.16421
MANUEL CAMACHO :: MANUELCAMACHO1 [administrador]

05/01/2012 20:45:32
mbam-log-2012-01-05 (20-45-32).txt

Tipos de Análisis: Análisis Completo
Opciones de análisis activado: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opciones de análisis desactivados: P2P
Objetos examinados: 558140
Tiempo transcurrido: 1 hora(s), 20 minuto(s), 48 segundo(s)

Procesos en Memoria Detectados: 0
(No se han detectado elementos maliciosos)

Módulos de Memoria Detectados: 0
(No se han detectado elementos maliciosos)

Claves del Registro Detectados: 72
HKCR\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\{11C27351-716B-4052-9361-E3B0A3F8221C} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\{A89256AD-EC17-4a83-BEF5-4B8BC4F39306} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{1602F07D-8BF3-4c08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\TypeLib\{C55CA95C-324B-451C-B2D2-6E895AA75FEC} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\ClickPotatoLiteAX.Info.1 (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\ClickPotatoLiteAX.Info (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{2721A8E5-BFDB-4562-9912-9E0531CA616C} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\TypeLib\{5FE0CEAE-CB69-40AF-A323-40F94257DACB} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{65A16874-2ED0-460E-A547-5FE2EC3A13A7} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.MozillaPSExecuter.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.MozillaPSExecuter (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{396CFC12-932D-496b-A0A8-5D7201E105E1} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\TypeLib\{573F4ABB-A1A2-44ED-9BA9-A8DAD40AAC46} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{71E02280-5212-45C3-B174-4D5A35DA254F} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.MozillaNvgtnTrpr.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.MozillaNvgtnTrpr (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{60DA826C-B1C6-4358-BDEC-4837CED45470} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.KOPFF.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.KOPFF (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{74C22317-5B90-471f-9AD2-FEC049870A16} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.Scopes.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.Scopes (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{7A3D6D17-9DD5-4C60-8076-D1784DABAF8C} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\TypeLib\{814BAA91-DC22-4350-87D6-0C86E93F7F08} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\MenuButtonIE.ButtonIE.1 (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\MenuButtonIE.ButtonIE (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\ClickPotatoLiteAX.UserProfiles.1 (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\ClickPotatoLiteAX.UserProfiles (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{C1089F63-7AFC-4538-B0EB-BEA0F4225A57} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.Stock.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.Stock (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{CC7BD6F1-565C-47ce-A5BB-9C935E77B59D} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\TypeLib\{02AED140-2B62-4B49-8B3B-179020CC39B9} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{17BF1E05-C0E8-413C-BD1F-A481EEA3B8E9} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.CntntDic.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.CntntDic (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{CFC16189-8A92-4a29-A940-60248385F426} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.CntntDisp.1 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\ShopperReports.CntntDisp (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\CLSID\{DEE758B4-C3FB-4a5b-9939-848B9C77A2FB} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\Typelib\{ACC62306-9A63-4864-BD2F-C8825D2D7EA6} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\Interface\{21BA420E-161C-413A-B21E-4E42AE1F4226} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100EB1FD-D03E-47FD-81F3-EE91287F9465} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7CDDCDC-BEEB-4685-A062-978F5E07CEEE} (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperReportsSA (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCR\AppID\BRNstIE.DLL (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\CmndFF.DLL (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\MenuButtonIE.DLL (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\mozillaps.dll (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCR\AppID\Pltfrm.DLL (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\fcn (Rogue.Residue) -> En cuarentena y eliminado con éxito.
HKCU\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKCU\Software\clickpotatolitesa (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\ClickPotatoLite (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\ShopperReports3 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\WebMediaPlayer (Rogue.WebMedia) -> En cuarentena y eliminado con éxito.

Valores del Registro Detectados: 4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|ShopperReports 3.0.517.0 (Adware.HotBar) -> datos: -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|SRS_IT_E8790477B1765B5A36A999 (Malware.Trace) -> datos: -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Mozilla\Firefox\extensions|ShopperReports@ShopperReports.com (ShopperReports) -> datos: C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions -> En cuarentena y eliminado con éxito.
HKLM\SOFTWARE\Mozilla\Firefox\extensions|ClickPotatoLite@ClickPotatoLite.com (Adware.ClickPotato) -> datos: C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox\extensions -> En cuarentena y eliminado con éxito.

Elementos de Datos del Registro Detectados: 2
HKCR\scrfile\shell\open\command| (Broken.OpenCommand) -> Malo: (NOTEPAD.EXE %1) Bueno: ("%1" /S) -> En cuarentena y reparado con éxito.
HKCR\regfile\shell\open\command| (Broken.OpenCommand) -> Malo: (NOTEPAD.EXE %1) Bueno: (regedit.exe "%1") -> En cuarentena y reparado con éxito.

Carpetas Detectadas: 22
C:\ProgramData\ClickPotatoLiteSA (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Users\MANUEL CAMACHO\AppData\Roaming\ClickPotatoLite (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Users\MANUEL CAMACHO\AppData\Roaming\ShopperReports3 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0 (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox\extensions (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox\extensions\plugins (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0 (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\chrome (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\components (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\resources (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\skins (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\updates (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.

Archivos Detectados: 32
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\ClickPotatoLiteSAAX.dll (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\mozillaps.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\CmndFF.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\ClickPotatoLiteSABHO.dll (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\CntntCntr.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\BRNstIE.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\LaunchHelp.dll (Adware.Seekmo) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox\extensions\plugins\npclntax_ClickPotatoLiteSA.dll (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\Mozilla Firefox\plugins\npclntax_ClickPotatoLiteSA.dll (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\ShopperReports.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\ShopperReportsUninstaller.exe (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
H:\DATAACER_D\MIS DATOS\MIS CARPETAS\software\DIV X\XvidSetup.exe (Adware.Hotbar) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA.dat (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAAbout.mht (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAau.dat (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSAEULA.mht (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA_hpk.dat (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\ClickPotatoLiteSA\ClickPotatoLiteSA_kyf.dat (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ClickPotatoLite\bin\10.0.622.0\firefox\extensions\install.rdf (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\LaunchHelp.dll (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\link.ico (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\chrome.manifest (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\install.rdf (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\chrome\firefoxtoolbar.jar (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.xpt (Adware.ShopperReports) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\sqlite3.dll (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\resources\wmp_translation_file.xml (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\Program Files\WebMediaPlayer\skins\classic.skn (Adware.EGDAccess) -> En cuarentena y eliminado con éxito.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\About Us.lnk (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Customer Support.lnk (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato\ClickPotato Uninstall Instructions.lnk (Adware.ClickPotato) -> En cuarentena y eliminado con éxito.

fin)

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Report de HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:44:34, on 05/01/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\WebProxy.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\Explorer.EXE
C:\Program Files\WTouch\WTouchUser.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DUE\DUESysTrayCD.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\ApVxdWin.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Vid HD\Vid.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Siemens\Card API\bin\siecacst.exe
C:\Program Files\TEXTware\HotKey\Twalink.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\Softissimo\Lexibase Standard\exe\lexibase.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\PavBckPT.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://es.yappr.com/welcome/Welcome2.action
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
R3 - URLSearchHook: Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RTP - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O2 - BHO: Ziepod One-Click IE Helper - {57A30D1E-08B9-4EF4-B273-AAEA1C234A5B} - C:\Windows\system32\ZiepodOneClicker.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O3 - Toolbar: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [recinfo471] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [DUESystray] C:\Program Files\DUE\DUESystrayCD.exe
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [RegistrarUsrDNIeCertStoreDLL] "C:\Program Files\DNIe\udcs.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2012\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2012\Inicio.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [9DBF38FFBBFF11D1ED54B9C758C5C565B3CBBBB5._service_run] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: bDule.appref-ms
O4 - Global Startup: HiPath SIcurity Card API.lnk = ?
O4 - Global Startup: HotKey.lnk = C:\Program Files\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lexibase Express.lnk = C:\Program Files\Softissimo\Lexibase Standard\exe\L-Express.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra 'Tools' menuitem: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Portafolios de HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Selección inteligente de HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O9 - Extra button: (no name) - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O9 - Extra 'Tools' menuitem: Xmarks for IE... - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - http://dl.google.com/dl/desktop/nv/Goog ... nIEWin.cab
O16 - DPF: {8A177687-28EB-48DB-9CCB-5C5254D10568} - http://es.yappr.com/practice/core/EduSpeakX.cab
O16 - DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - https://www5.aeat.es/es13/h/cactivex.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Administrador de Google Desktop 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c986365bb6fea8) (gupdate1c986365bb6fea8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\pavsrvx86.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Panda Host Service (PSHost) - Panda Security International - c:\program files\panda security\panda global protection 2012\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PskSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\TPSrv.exe
O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

--
End of file - 15604 bytes

Avatar de Usuario
helheim
Usuario Bill Gates
Usuario Bill Gates
Mensajes: 5001
Registrado: 20 Abr 2008, 11:38
Agradecido : 24 veces
Agradecimiento recibido: 169 veces
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor helheim » 07 Ene 2012, 14:14

Ejecuta de nuevo HijackThis (con todos los programas cerrados y como Administrador; para eso pulsa con el botón derecho del raton sobre el programa y elige "Ejecutar como Administrador"), pulsa sobre "Do a system scan only", marca las siguientes entradas y pulsa "Fix Checked":

R3 - URLSearchHook: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
R3 - URLSearchHook: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll
O2 - BHO: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O3 - Toolbar: FreeRIP Toolbar - {E634228A-03CF-4BC8-B0AB-668257F1FD8C} - C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
O4 - Startup: bDule.appref-ms
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe


Busca (en las rutas que te pongo ahora) y borra también los siguientes archivos (solo los archivos que te pongo en azul):

C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll
C:\Program Files\Application Updater\ApplicationUpdater.exe

Una vez hecho eso, pasa CCLEANER y limpia tanto Archivos Temporales como el Registro (pásalo tantas veces como sea necesario hasta no encontrar nada).

-----------------


Aunque Malwarebytes te ha quitado mucha porquería, tanto la toolbar de Ask como la de Softissimo (Lexibase Standard) siguen ahí.

Para desinstalar la de Softissimo, busca por Lexibase Standard a ver si encuentras algo.

Para la barra de Ask, inicia en Modo Seguro y trata de desinstalarla desde allí si no, probaríamos otra cosa.

NOTA: Cuando vayas a desinstalar las toolbars, no tengas abierto nada (ni navegadores ni nada)

Un saludo.
La experiencia es una llama que alumbra quemando (Benito Pérez Galdós)

mecmora
Usuario linuxero
Usuario linuxero
Mensajes: 10
Registrado: 02 Ene 2012, 23:18
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor mecmora » 09 Ene 2012, 23:02

he ejecutado todo lo que recomiendas:
Hijackthis.............Desapareció todo lo apuntado en tu escrito.

C:\Program Files\FreeRIP Toolbar\IE\4.7\freeripToolbarIE.dll .......................borrado
C:\Program Files\Application Updater\ApplicationUpdater.exe ......................borrado

CCLEANER ............. pasado varias veces hasta que solo quedo: "google chrome-cache de internet 0 KB 0Archivos"

Lexibase Standard ......................Desinstalado.

Para la barra de Ask, iniciado en Modo Seguro, no se desinstala. Mensaje: "No tiene acceso al servicio de Wndows Instaler. esto puede suceder si Windows Instaler no está correctamente instalado. Pongase en contacto con el personal de soporte técnico para obtener ayuda"

Adjunto el log de HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:58:28, on 09/01/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES\PANDA SECURITY\PANDA GLOBAL PROTECTION 2012\WebProxy.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\Explorer.EXE
C:\Program Files\WTouch\WTouchUser.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\opwareSE2.exe
C:\Program Files\DUE\DUESysTrayCD.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\ApVxdWin.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\Vid HD\Vid.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Xmarks\IE Extension\xmarkssync.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Siemens\Card API\bin\siecacst.exe
C:\Program Files\TEXTware\HotKey\Twalink.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Panda Security\Panda Global Protection 2012\PavBckPT.exe
C:\Windows\system32\conime.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://es.yappr.com/welcome/Welcome2.action
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Toolbar Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RTP - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O2 - BHO: Ziepod One-Click IE Helper - {57A30D1E-08B9-4EF4-B273-AAEA1C234A5B} - C:\Windows\system32\ZiepodOneClicker.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: RTP Toolbar - {26f55586-8cf9-49f1-9206-6017be1dfd57} - C:\Program Files\RTP\prxtbRT2.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [recinfo471] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [DUESystray] C:\Program Files\DUE\DUESystrayCD.exe
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [RegistrarUsrDNIeCertStoreDLL] "C:\Program Files\DNIe\udcs.exe"
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 6\vspdfprsrv.exe --background
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Global Protection 2012\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Global Protection 2012\Inicio.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe -q
O4 - HKCU\..\Run: [9DBF38FFBBFF11D1ED54B9C758C5C565B3CBBBB5._service_run] "C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: HiPath SIcurity Card API.lnk = ?
O4 - Global Startup: HotKey.lnk = C:\Program Files\TEXTware\HotKey\Twalink.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra 'Tools' menuitem: FLiP Spell - {0A222F6E-5513-4478-A435-E09E9E253842} - C:\Program Files\Priberam\FLiP\FLiPIE.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Portafolios de HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Selección inteligente de HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O9 - Extra 'Tools' menuitem: Xmarks for IE... - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - http://dl.google.com/dl/desktop/nv/Goog ... nIEWin.cab
O16 - DPF: {8A177687-28EB-48DB-9CCB-5C5254D10568} - http://es.yappr.com/practice/core/EduSpeakX.cab
O16 - DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - https://www5.aeat.es/es13/h/cactivex.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{0D197AB6-3C84-4B6A-AF30-97EC2CCDD5FC}: NameServer = 80.58.61.250,80.58.61.254
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Administrador de Google Desktop 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c986365bb6fea8) (gupdate1c986365bb6fea8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Security, S.L. - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\pavsrvx86.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Panda Host Service (PSHost) - Panda Security International - c:\program files\panda security\panda global protection 2012\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PsImSvc.exe
O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\PskSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Global Protection 2012\TPSrv.exe
O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

--
End of file - 16023 bytes

un saludo

Avatar de Usuario
helheim
Usuario Bill Gates
Usuario Bill Gates
Mensajes: 5001
Registrado: 20 Abr 2008, 11:38
Agradecido : 24 veces
Agradecimiento recibido: 169 veces
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor helheim » 10 Ene 2012, 16:42

Bueno, solo nos queda la toolbar de Ask que se resiste. Vamos a probar con una herramienta que se llama AdwCleaner.

Realiza los pasos que se indican en ESTE POST para ejecutar la herramienta y péganos el log que te genere.

Un saludo.
La experiencia es una llama que alumbra quemando (Benito Pérez Galdós)

mecmora
Usuario linuxero
Usuario linuxero
Mensajes: 10
Registrado: 02 Ene 2012, 23:18
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor mecmora » 11 Ene 2012, 00:01

he pasado HijackThis, "Do system scan only", y no he encontrado las siguientes líneas:

O4 - HKCU\..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msirni32.dll,tUsscfzR

O20 - AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll

por tanto he pasado al paso 2), bajar AdwCleaner ejecutarlo como administrador y elegir Delete. Se ha reiniciado el ordenador (acompaño el log ).

Al reinicio se sigue queriendo ejecutar el Wndows Instaler, el mensaje que da :

"Detección del cuadro de diálogo de servicios interactivos.
Programa o dispositivo que necesitan atención:
Titulo: Nokia_Multimedia_Common_Components_2_5- InstallShield Wizard.
Ruta de acceso del programa: C:\Windows\System32\MsiExec.exe
Este problema se debe a una incompatibilidad parcial con Windows.
Póngase en contacto con el fabricante del programa o dispositivo para obtener más información".

log @@@@@@@@@@@@@@@@@@@@@@@
# AdwCleaner v1.406 - Logfile created 01/10/2012 at 23:30:23
# Updated 09/01/2012 by Xplode
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# User : MANUEL CAMACHO - MANUELCAMACHO1 (Administrator)
# Running from : C:\Users\MANUEL CAMACHO\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\ProgramData\Winamp Toolbar
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-

13a3a9e97384}
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\Local\Conduit
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\Local\Winamp Toolbar
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\MANUEL CAMACHO\AppData\LocalLow\Search Settings
Folder Deleted : C:\Program Files\Application Updater
Folder Deleted : C:\Program Files\Ask.com
Folder Deleted : C:\Program Files\AutocompletePro
Folder Deleted : C:\Program Files\Winamp Toolbar
Folder Deleted : C:\Program Files\Common Files\Software Update Utility
Folder Deleted : C:\Program Files\Common Files\spigot
Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\Conduit
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\ConduitCommon
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\ConduitEngine
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\winampToolbarData
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\extensions\{75623d5d-4683-402a-b610

-ac4bab767c86}
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\extensions\{0b38152b-1b20-484d-a11f

-5e04a9b0661f}
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\extensions\engine@conduit.com
Folder Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\extensions\toolbar@ask.com
File Deleted : C:\Program Files\Mozilla Firefox\extensions\wtxpcom@mybrowserbar.com
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.xpt
File Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\searchplugins\aol-web-search.xml
File Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\searchplugins\Conduit.xml
File Deleted : C:\Users\MANUEL

CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\searchplugins\Surf-canyon.xml

***** [Registry] *****

[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT669574
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\AutocompletePro
Key Deleted : HKCU\Software\AutocompleteProBHO
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Winamp Toolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Deleted : HKLM\SOFTWARE\Application Updater
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Software
Key Deleted : HKLM\SOFTWARE\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO
Key Deleted : HKLM\SOFTWARE\Classes\SuggestMeYes.SuggestMeYesBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLTBSearch.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.AOLToolBand.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.Downloader.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarInfo.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams
Key Deleted : HKLM\SOFTWARE\Classes\WinampTb.ToolbarParams.1
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\WinampTbServer.AolToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\AutocompletePro.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\SoftwareUpdate.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\winamptbServer.exe
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B27D9527-3762-4d71-963D-FB7A94FDD678}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EF4E91D-DDD5-4478-BCA7-DA04435934C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B38D6EDE-390B-4620-8365-29E16459EBDA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F20F11FD-203E-45a9-B7BB-AFC1B4FEA7A6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE178B09-C8AA-4734-804D-1849BCCA0C29}
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18

\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted :

HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20E

EE4
Key Deleted :

HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8

212
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{453DB0C5-F41C-4D97-8DD6-CC72ECD5F699}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4AFC07D0-59BB-46B8-B097-1A46E88EEF71}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6511CE4C-4722-40D0-AD3D-4AFA2F50978A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BEC9B38-BF39-4899-806E-A1C5DFEB60A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B86D82BF-D39F-439A-A07C-43EDDC6F6EA6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DA6305B9-0869-4235-8C1D-533A65E639E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E6961C59-CFCE-4CCD-B794-BC78DB98413A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0F54B66A-21CF-4548-AE59-A6B83EE6676F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{51A971CA-D36E-4D13-A799-2CF0A491D04D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56FBEA9F-EF93-4318-B75F-A96FC7C7BD7B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66DD22B9-6521-4B05-97DB-0EBC00B1DA5D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{78B3C85E-44FF-4DC8-B3AD-156F39DC75E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{841FD004-57A2-4B49-BBDB-5897394619DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E19FDA06-5BDF-43C2-B794-BCD8A4C2051F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FAB076F5-E4DD-4EA4-AFEE-F18BF972B057}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{507591C2-2F4E-46A7-92D6-E6CFF82E5F26}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{538CD77C-BFDD-49B0-9562-77419CAB89D1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-

442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-

CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-

F5D7BAF2DB0C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-

185a7020515b}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-

4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8856F961-340A-11D0-A96B-

00C04FD705A2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-

4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1

-8156E22C1D96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-

96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutocompletePro2_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winamp Toolbar
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45a2-B558-

1755C3F6253B}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{57BCA5FA-5DBB-45a2-B558-

1755C3F6253B}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-

A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-

4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EBF2BA02-9094-4c5a-858B-

BB198F3D8DE2}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [support@predictad.com]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v8.0.1 (es-ES)

Profile : 5w9yo0s4.default
File : C:\Users\MANUEL CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\prefs.js

C:\Users\MANUEL CAMACHO\AppData\Roaming\Mozilla\Firefox\Profiles\5w9yo0s4.default\user.js ... Deleted

!

Deleted : user_pref("CT2396205..clientLogIsEnabled", true);
Deleted : user_pref("CT2396205..clientLogServiceUrl",

"hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2396205..uninstallLogServiceUrl",

"hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2396205.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2396205.CTID", "CT2396205");
Deleted : user_pref("CT2396205.Chat.Meebo.ServerLastCheckTime", "Mon Dec 14 2009 01:31:27 GMT+0100");
Deleted : user_pref("CT2396205.Chat.Meebo.ServerLastResponseTime", "Mon Dec 14 2009 01:31:28

GMT+0100");
Deleted : user_pref("CT2396205.Chat.Meebo.rooms.interspeakerscommunitychatf5b95713", 0);
Deleted : user_pref("CT2396205.Chat.ServerLastCheckTime", "Mon Dec 14 2009 01:31:27 GMT+0100");
Deleted : user_pref("CT2396205.CommunitiesChangesLastCheckTime", "0");
Deleted : user_pref("CT2396205.CurrentServerDate", "6-7-2011");
Deleted : user_pref("CT2396205.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2396205.DialogsGetterLastCheckTime", "Wed Jul 06 2011 21:25:09 GMT+0200 (Hora

de verano[...]
Deleted : user_pref("CT2396205.DownloadReferralCookieData", "");
Deleted : user_pref("CT2396205.EMailNotifierPollDate", "Wed Jul 06 2011 21:25:07 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2396205.ExternalComponentPollDate1446273582604929597", "Wed Jul 06 2011

21:25:07 GMT+02[...]
Deleted : user_pref("CT2396205.FeedPollDate12564526", "Wed Jul 06 2011 21:25:07 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2396205.FeedPollDatehxxp://radioclube.clix.pt/p ... index.aspx", "Wed Jul 06

2011 21:[...]
Deleted : user_pref("CT2396205.FirstServerDate", "7-12-2009");
Deleted : user_pref("CT2396205.FirstTime", true);
Deleted : user_pref("CT2396205.FirstTimeFF3", true);
Deleted : user_pref("CT2396205.GroupingInvalidateCache", false);
Deleted : user_pref("CT2396205.GroupingLastCheckTime", "0");
Deleted : user_pref("CT2396205.GroupingLastServerUpdateTime", "0");
Deleted : user_pref("CT2396205.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2396205.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2396205.HasUserGlobalKeys", true);
Deleted : user_pref("CT2396205.Initialize", true);
Deleted : user_pref("CT2396205.InitializeCommonPrefs", true);
Deleted : user_pref("CT2396205.InstallationAndCookieDataSentCount", 1);
Deleted : user_pref("CT2396205.InstalledDate", "Mon Dec 07 2009 20:58:44 GMT+0100");
Deleted : user_pref("CT2396205.InvalidateCache", false);
Deleted : user_pref("CT2396205.IsAlertDBUpdated", true);
Deleted : user_pref("CT2396205.IsGrouping", false);
Deleted : user_pref("CT2396205.IsMulticommunity", false);
Deleted : user_pref("CT2396205.IsOpenThankYouPage", true);
Deleted : user_pref("CT2396205.IsOpenUninstallPage", true);
Deleted : user_pref("CT2396205.LanguagePackLastCheckTime", "Wed Jul 06 2011 21:25:08 GMT+0200 (Hora de

verano [...]
Deleted : user_pref("CT2396205.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2396205.LanguagePackServiceUrl",

"hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2396205.LastLogin_2.5.1.9", "Thu Feb 04 2010 20:19:51 GMT+0100");
Deleted : user_pref("CT2396205.LastLogin_2.5.6.0", "Mon Apr 19 2010 14:01:34 GMT+0200 (Hora de verano

romance)[...]
Deleted : user_pref("CT2396205.LastLogin_3.5.0.12", "Wed Jul 06 2011 21:25:09 GMT+0200 (Hora de verano

romance[...]
Deleted : user_pref("CT2396205.LatestVersion", "3.3.3.2");
Deleted : user_pref("CT2396205.Locale", "en");
Deleted : user_pref("CT2396205.LoginCache", 4);
Deleted : user_pref("CT2396205.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2396205.MCDetectTooltipShow", false);
Deleted : user_pref("CT2396205.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?

version=1");
Deleted : user_pref("CT2396205.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2396205.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2396205.RadioIsPodcast", false);
Deleted : user_pref("CT2396205.RadioLastCheckTime", "Wed Jul 06 2011 21:25:07 GMT+0200 (Hora de verano

romance[...]
Deleted : user_pref("CT2396205.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT2396205.RadioLastUpdateServer", "128970923883970000");
Deleted : user_pref("CT2396205.RadioMediaID", "12564495");
Deleted : user_pref("CT2396205.RadioMediaType", "Media Player");
Deleted : user_pref("CT2396205.RadioMenuSelectedID", "EBRadioMenu_CT2396205_RECENT12564495");
Deleted : user_pref("CT2396205.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT2396205.RadioStationName", "Radio%20Australia");
Deleted : user_pref("CT2396205.RadioStationURL", "hxxp://bataani.com/gadgets/radio.php?

url=hxxp://www.abc.net.[...]
Deleted : user_pref("CT2396205.RadioVolume", "100");
Deleted : user_pref("CT2396205.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2396205.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?

q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2396205.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2396205.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?

ctid=CT239[...]
Deleted : user_pref("CT2396205.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2396205.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2396205.SearchInNewTabLastCheckTime", "Wed Jul 06 2011 21:25:09 GMT+0200 (Hora

de veran[...]
Deleted : user_pref("CT2396205.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?

ctid=EB_T[...]
Deleted : user_pref("CT2396205.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-

services.com/UsageServic[...]
Deleted : user_pref("CT2396205.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2396205.ServiceMapLastCheckTime", "Wed Jul 06 2011 21:25:06 GMT+0200 (Hora de

verano ro[...]
Deleted : user_pref("CT2396205.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2396205.SettingsLastCheckTime", "Wed Jul 06 2011 21:25:07 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2396205.SettingsLastUpdate", "1306530423");
Deleted : user_pref("CT2396205.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2396205.ThirdPartyComponentsLastCheck", "Wed Jul 06 2011 21:25:06 GMT+0200

(Hora de ver[...]
Deleted : user_pref("CT2396205.ThirdPartyComponentsLastUpdate", "1269761980");
Deleted : user_pref("CT2396205.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2396205");
Deleted : user_pref("CT2396205.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-

services.com,OurTo[...]
Deleted : user_pref("CT2396205.UserID", "UN05427930505609624");
Deleted : user_pref("CT2396205.ValidationData_Search", 0);
Deleted : user_pref("CT2396205.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2396205.WeatherNetwork", "");
Deleted : user_pref("CT2396205.WeatherPollDate", "Wed Jul 06 2011 21:25:08 GMT+0200 (Hora de verano

romance)")[...]
Deleted : user_pref("CT2396205.WeatherUnit", "C");
Deleted : user_pref("CT2396205.alertChannelId", "790888");
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.firsttime", "747[...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.messages_mostrec[...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.numofeventinvite[...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.numoffirendreque[...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.numofgroupinvite[...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.numofmessages", [...]
Deleted : user_pref("CT2396205.backendstorage.hxxp://conduit-fb-

toolbar_conduit_com/fbtoolbar.numofpokes", "30[...]
Deleted : user_pref("CT2396205.clientLogIsEnabled", true);
Deleted : user_pref("CT2396205.clientLogServiceUrl",

"hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2396205.components.1000034", true);
Deleted : user_pref("CT2396205.components.1000234", true);
Deleted : user_pref("CT2396205.components.129044925492369160", false);
Deleted : user_pref("CT2396205.components.524624752343668066", false);
Deleted : user_pref("CT2396205.generalConfigFromLogin",

"{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
Deleted : user_pref("CT2396205.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 21:25:09 GMT+0200

(Hora de [...]
Deleted : user_pref("CT2396205.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2396205.initDone", true);
Deleted : user_pref("CT2396205.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2396205.isFirstRadioInstallation", false);
Deleted : user_pref("CT2396205.myStuffEnabled", true);
Deleted : user_pref("CT2396205.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2396205.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?

q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2396205.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2396205.myStuffServiceUrl", "hxxp://mystuff.conduit-

services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2396205.oldAppsList",

"128970832284050893,128970832285300894,111,1000082,12897083813373[...]
Deleted : user_pref("CT2396205.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2396205.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2396205.testingCtid", "");
Deleted : user_pref("CT2396205.toolbarAppMetaDataLastCheckTime", "Wed Jul 06 2011 21:25:08 GMT+0200

(Hora de v[...]
Deleted : user_pref("CT2396205.toolbarContextMenuLastCheckTime", "Wed Jul 06 2011 21:25:08 GMT+0200

(Hora de v[...]
Deleted : user_pref("CT2396205.uninstallLogServiceUrl",

"hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2504091.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2504091.CTID", "CT2504091");
Deleted : user_pref("CT2504091.CurrentServerDate", "13-10-2010");
Deleted : user_pref("CT2504091.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2504091.DownloadReferralCookieData", "");
Deleted : user_pref("CT2504091.EMailNotifierPollDate", "Wed Oct 13 2010 21:00:39 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2504091.FeedLastCount129079840422964131", 10);
Deleted : user_pref("CT2504091.FeedPollDate128891351169457140", "Wed Oct 13 2010 20:25:40 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2504091.FeedPollDate129079840422964131", "Wed Oct 13 2010 19:25:11 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2504091.FirstServerDate", "13-10-2010");
Deleted : user_pref("CT2504091.FirstTime", true);
Deleted : user_pref("CT2504091.FirstTimeFF3", true);
Deleted : user_pref("CT2504091.FirstTimeSettingsDone", true);
Deleted : user_pref("CT2504091.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2504091.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2504091.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2504091.Initialize", true);
Deleted : user_pref("CT2504091.InitializeCommonPrefs", true);
Deleted : user_pref("CT2504091.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2504091.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2504091.InstalledDate", "Tue Oct 12 2010 23:35:16 GMT+0200 (Hora de verano

romance)");
Deleted : user_pref("CT2504091.IsGrouping", false);
Deleted : user_pref("CT2504091.IsMulticommunity", false);
Deleted : user_pref("CT2504091.IsOpenThankYouPage", false);
Deleted : user_pref("CT2504091.IsOpenUninstallPage", false);
Deleted : user_pref("CT2504091.LanguagePackLastCheckTime", "Tue Oct 12 2010 23:36:08 GMT+0200 (Hora de

verano [...]
Deleted : user_pref("CT2504091.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2504091.LanguagePackServiceUrl",

"hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2504091.LastLogin_2.7.2.0", "Wed Oct 13 2010 17:58:03 GMT+0200 (Hora de verano

romance)[...]
Deleted : user_pref("CT2504091.LatestVersion", "2.6.0.14");
Deleted : user_pref("CT2504091.Locale", "en-us");
Deleted : user_pref("CT2504091.LoginCache", 4);
Deleted : user_pref("CT2504091.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2504091.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?

version=1");
Deleted : user_pref("CT2504091.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2504091.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2504091.SearchEngine", "Search||hxxp://search.conduit.com/Results.aspx?

q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2504091.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2504091.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?

ctid=CT250[...]
Deleted : user_pref("CT2504091.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2504091.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2504091.SearchInNewTabLastCheckTime", "Tue Oct 12 2010 23:36:11 GMT+0200 (Hora

de veran[...]
Deleted : user_pref("CT2504091.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?

ctid=EB_T[...]
Deleted : user_pref("CT2504091.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-

services.com/UsageServic[...]
Deleted : user_pref("CT2504091.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2504091.SettingsLastCheckTime", "Wed Oct 13 2010 17:25:10 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2504091.SettingsLastUpdate", "1286395440");
Deleted : user_pref("CT2504091.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2504091.ThirdPartyComponentsLastCheck", "Tue Oct 12 2010 23:34:55 GMT+0200

(Hora de ver[...]
Deleted : user_pref("CT2504091.ThirdPartyComponentsLastUpdate", "1246790578");
Deleted : user_pref("CT2504091.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?

page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2504091.UserID", "UN04402299892389094");
Deleted : user_pref("CT2504091.ValidationData_Toolbar", 0);
Deleted : user_pref("CT2504091.alertChannelId", "897164");
Deleted : user_pref("CT2504091.clientLogIsEnabled", true);
Deleted : user_pref("CT2504091.clientLogServiceUrl",

"hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2504091.myStuffEnabled", true);
Deleted : user_pref("CT2504091.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2504091.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?

q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2504091.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2504091.myStuffServiceUrl", "hxxp://mystuff.conduit-

services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2504091.uninstallLogServiceUrl",

"hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CT2537298.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2537298.CTID", "CT2537298");
Deleted : user_pref("CT2537298.CurrentServerDate", "31-3-2010");
Deleted : user_pref("CT2537298.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2537298.EMailNotifierPollDate", "Wed Mar 31 2010 23:35:43 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2537298.FeedLastCount129108046520931263", 0);
Deleted : user_pref("CT2537298.FeedLastCount129108048746093442", 0);
Deleted : user_pref("CT2537298.FeedLastCount129108165294995264", 263);
Deleted : user_pref("CT2537298.FeedPollDate129108046520931263", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108048746093442", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401547", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401548", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401549", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401550", "Wed Mar 31 2010 23:30:41 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401551", "Wed Mar 31 2010 22:50:42 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate129108165296401552", "Wed Mar 31 2010 22:50:42 GMT+0200

(Hora de ve[...]
Deleted : user_pref("CT2537298.FeedPollDate20042297", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042303", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042311", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042312", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042313", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042314", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042315", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042316", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042317", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042318", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042319", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042320", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042321", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042322", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042323", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042324", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042325", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042326", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042327", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20042328", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedPollDate20266901", "Thu Apr 01 2010 00:00:41 GMT+0200 (Hora de

verano roman[...]
Deleted : user_pref("CT2537298.FeedTTL129108046520931263", 60);
Deleted : user_pref("CT2537298.FeedTTL129108048746093442", 60);
Deleted : user_pref("CT2537298.FeedTTL129108165296401547", 40);
Deleted : user_pref("CT2537298.FeedTTL129108165296401548", 40);
Deleted : user_pref("CT2537298.FeedTTL129108165296401549", 40);
Deleted : user_pref("CT2537298.FeedTTL129108165296401550", 40);
Deleted : user_pref("CT2537298.FeedTTL129108165296401551", 40);
Deleted : user_pref("CT2537298.FeedTTL129108165296401552", 40);
Deleted : user_pref("CT2537298.FirstServerDate", "23-2-2010");
Deleted : user_pref("CT2537298.FirstTime", true);
Deleted : user_pref("CT2537298.FirstTimeFF3", true);
Deleted : user_pref("CT2537298.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2537298.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2537298.Initialize", true);
Deleted : user_pref("CT2537298.InitializeCommonPrefs", true);
Deleted : user_pref("CT2537298.InstalledDate", "Tue Feb 23 2010 20:51:47 GMT+0100");
Deleted : user_pref("CT2537298.InvalidateCache", false);
Deleted : user_pref("CT2537298.IsGrouping", false);
Deleted : user_pref("CT2537298.IsMulticommunity", false);
Deleted : user_pref("CT2537298.IsOpenThankYouPage", true);
Deleted : user_pref("CT2537298.IsOpenUninstallPage", true);
Deleted : user_pref("CT2537298.LanguagePackLastCheckTime", "Wed Mar 31 2010 21:20:04 GMT+0200 (Hora de

verano [...]
Deleted : user_pref("CT2537298.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2537298.LanguagePackServiceUrl",

"hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2537298.LastLogin_2.5.6.0", "Wed Mar 31 2010 21:20:01 GMT+0200 (Hora de verano

romance)[...]
Deleted : user_pref("CT2537298.LatestVersion", "2.1.0.18");
Deleted : user_pref("CT2537298.Locale", "es");
Deleted : user_pref("CT2537298.LoginCache", 4);
Deleted : user_pref("CT2537298.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2537298.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?

version=1");
Deleted : user_pref("CT2537298.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2537298.RadioIsPodcast", true);
Deleted : user_pref("CT2537298.RadioLastCheckTime", "Wed Mar 31 2010 21:19:40 GMT+0200 (Hora de verano

romance[...]
Deleted : user_pref("CT2537298.RadioLastUpdateIPServer", "3");
Deleted : user_pref("CT2537298.RadioLastUpdateServer", "129137605980330000");
Deleted : user_pref("CT2537298.RadioMediaID", "20042297");
Deleted : user_pref("CT2537298.RadioMediaType", "Media Player");
Deleted : user_pref("CT2537298.RadioMenuSelectedID", "EBRadioPodcastPreffix20042297-0");
Deleted : user_pref("CT2537298.RadioStationName", "Lo%20mejor%20de%20'Hoy%20por%20Hoy'%20(22%2F02%

2F10)");
Deleted : user_pref("CT2537298.RadioStationURL",

"hxxp://www.cadenaser.com/cadenaser/podcast/audios/cadenaser_[...]
Deleted : user_pref("CT2537298.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2537298.SearchEngine", "Buscar||hxxp://search.conduit.com/Results.aspx?

q=UCM_SEARCH_TER[...]
Deleted : user_pref("CT2537298.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2537298.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?

ctid=CT253[...]
Deleted : user_pref("CT2537298.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2537298.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2537298.SearchInNewTabLastCheckTime", "Wed Mar 31 2010 21:19:40 GMT+0200 (Hora

de veran[...]
Deleted : user_pref("CT2537298.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?

ctid=EB_T[...]
Deleted : user_pref("CT2537298.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-

services.com/UsageServic[...]
Deleted : user_pref("CT2537298.SettingsCheckIntervalMin", 120);
Deleted : user_pref("CT2537298.SettingsLastCheckTime", "Wed Mar 31 2010 21:19:40 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("CT2537298.SettingsLastUpdate", "1269279798");
Deleted : user_pref("CT2537298.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2537298.ThirdPartyComponentsLastCheck", "Wed Mar 17 2010 00:50:42 GMT+0100");
Deleted : user_pref("CT2537298.ThirdPartyComponentsLastUpdate", "1267170260");
Deleted : user_pref("CT2537298.TrusteLinkUrl", "hxxp://www.truste.org/pvr.php?

page=validate&softwareProgramId=[...]
Deleted : user_pref("CT2537298.UserID", "UN76263744586405043");
Deleted : user_pref("CT2537298.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2537298.WeatherNetwork", "");
Deleted : user_pref("CT2537298.WeatherPollDate", "Wed Mar 31 2010 23:19:43 GMT+0200 (Hora de verano

romance)")[...]
Deleted : user_pref("CT2537298.WeatherUnit", "C");
Deleted : user_pref("CT2537298.alertChannelId", "930301");
Deleted : user_pref("CT2537298.clientLogIsEnabled", false);
Deleted : user_pref("CT2537298.clientLogServiceUrl",

"hxxp://clientlog.users.conduit.com/ClientDiagnostics.asm[...]
Deleted : user_pref("CT2537298.components.1000034", true);
Deleted : user_pref("CT2537298.components.1000234", true);
Deleted : user_pref("CT2537298.myStuffEnabled", true);
Deleted : user_pref("CT2537298.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2537298.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?

q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2537298.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2537298.myStuffServiceUrl", "hxxp://mystuff.conduit-

services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2537298.uninstallLogServiceUrl",

"hxxp://uninstall.users.conduit.com/Uninstall.asmx/Reg[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root ... /786710/ES",

"\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root ... /905414/ES",

"\"0\"")[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?

ctid=CT2396205", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-

services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.engine.conduit-se ... om/DLG.pkg?

ver=3.3.3[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-

services.com/DLG.pkg?ver=3.5.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?

ownerId=CT2396205",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?

browser=FF&lut=0", "63[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.engine.conduit-services.com/?

browser=FF&lut=3/13/20[...]
Deleted : user_pref

("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit. ... /CT2396205[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?

locale=en", "\"634[...]
Deleted : user_pref("CommunityToolbar.EngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.EngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.EngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.IsEngineShown", true);
Deleted : user_pref("CommunityToolbar.IsMyStuffImportedToEngine", true);
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\MANUEL

CAMACHO\\AppData\\Roaming\\M[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.5.0.12");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.

hxxp://storage.conduit.com/gadgets/LiveTV.html?[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.

hxxp://storage.conduit.com/gadgets/LiveTV.html?[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.

hxxp://storage.conduit.com/gadgets/LiveTV.html?[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.

hxxp://storage.conduit.com/gadgets/LiveTV.html?[...]
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.

hxxp://storage.conduit.com/gadgets/LiveTV.html?[...]
Deleted : user_pref

("CommunityToolbar.MiniIPageGadgetPosition.hxxp://www.labpixies.com/campaigns/youtube/youtu[...]
Deleted : user_pref

("CommunityToolbar.MiniIPageGadgetSize.hxxp://www.labpixies.com/campaigns/youtube/youtube.h[...]
Deleted : user_pref("CommunityToolbar.OriginalEngineOwner", "ConduitEngine");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "engine@conduit.com");
Deleted : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "conduitengine");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl",

"hxxp://search.live.com/results.aspx?FORM[...]
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2396205,CT2537298,CT2504091,ConduitEngine");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2396205,CT2537298,CT2504091");
Deleted : user_pref("CommunityToolbar.alert.alertDialogsGetterLastCheckTime", "Sat Apr 02 2011

13:13:41 GMT+02[...]
Deleted : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Sun May 22 2011 23:23:28

GMT+0200 (Hora [...]
Deleted : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.locale", "en");
Deleted : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Wed Jul 06 2011 20:24:09 GMT+0200

(Hora de v[...]
Deleted : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.alert.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.alert.userId", "dbfbf381-6c42-4308-8f59-37ff19617348");
Deleted : user_pref("CommunityToolbar.globalUserId", "c54bc369-9f93-440f-ac67-9e41fd486cb3");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2504091");
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jul 06 2011

21:25:0[...]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 60);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Jul 06 2011 21:25:17

GMT+020[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl",

"hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jul 06 2011 21:25:06

GMT+0200 (H[...]
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1305622559");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl",

"hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "aab5eaf0-1073-4377-a7bc-ea1e597a1ee8");
Deleted : user_pref("CommunityToolbar.twitter.user_14814402.LastCheckTime", "Wed Mar 31 2010 21:19:40

GMT+0200[...]
Deleted : user_pref("ConduitEngine.AppTrackingLastCheckTime", "Sat Apr 30 2011 20:46:05 GMT+0200 (Hora

de vera[...]
Deleted : user_pref("ConduitEngine.CTID", "ConduitEngine");
Deleted : user_pref("ConduitEngine.DialogsGetterLastCheckTime", "Wed Jul 06 2011 20:24:10 GMT+0200

(Hora de ve[...]
Deleted : user_pref("ConduitEngine.FirstServerDate", "04/02/2011 14");
Deleted : user_pref("ConduitEngine.FirstTime", true);
Deleted : user_pref("ConduitEngine.FirstTimeFF3", true);
Deleted : user_pref("ConduitEngine.HasUserGlobalKeys", true);
Deleted : user_pref("ConduitEngine.Initialize", true);
Deleted : user_pref("ConduitEngine.InitializeCommonPrefs", true);
Deleted : user_pref("ConduitEngine.InstalledDate", "Sat Apr 02 2011 13:13:41 GMT+0200 (Hora de verano

romance)[...]
Deleted : user_pref("ConduitEngine.IsMulticommunity", false);
Deleted : user_pref("ConduitEngine.IsOpenThankYouPage", false);
Deleted : user_pref("ConduitEngine.IsOpenUninstallPage", true);
Deleted : user_pref("ConduitEngine.LanguagePackLastCheckTime", "Wed Jul 06 2011 20:24:10 GMT+0200

(Hora de ver[...]
Deleted : user_pref("ConduitEngine.LastLogin_3.3.3.2", "Wed Jul 06 2011 20:24:10 GMT+0200 (Hora de

verano roma[...]
Deleted : user_pref("ConduitEngine.SearchFromAddressBarIsInit", true);
Deleted : user_pref("ConduitEngine.SettingsLastCheckTime", "Wed Jul 06 2011 20:24:10 GMT+0200 (Hora de

verano [...]
Deleted : user_pref("ConduitEngine.UserID", "UN76485085630002986");
Deleted : user_pref("ConduitEngine.componentAlertEnabled", true);
Deleted : user_pref("ConduitEngine.engineLocale", "es-ES");
Deleted : user_pref("ConduitEngine.enngineContextMenuLastCheckTime", "Wed Jul 06 2011 20:24:10

GMT+0200 (Hora [...]
Deleted : user_pref("ConduitEngine.globalFirstTimeInfoLastCheckTime", "Wed Jul 06 2011 20:24:10

GMT+0200 (Hora[...]
Deleted : user_pref("ConduitEngine.initDone", true);
Deleted : user_pref("ConduitEngine.isAppTrackingManagerOn", true);
Deleted : user_pref("ConduitEngine.usagesFlag", 1);
Deleted : user_pref("aol_toolbar.surf.date", "7");
Deleted : user_pref("aol_toolbar.surf.lastDate", "8");
Deleted : user_pref("aol_toolbar.surf.lastMonth", "11");
Deleted : user_pref("aol_toolbar.surf.lastYear", "2011");
Deleted : user_pref("aol_toolbar.surf.month", "7");
Deleted : user_pref("aol_toolbar.surf.prevMonth", "13");
Deleted : user_pref("aol_toolbar.surf.total", "1068");
Deleted : user_pref("aol_toolbar.surf.week", "7");
Deleted : user_pref("aol_toolbar.surf.year", "1032");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.winamp.com/search/search?query=

{searchTerms}&i[...]
Deleted : user_pref("extensions.asktb.cbid", "B5");
Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o=

{o}&l={l}[...]
Deleted : user_pref("extensions.asktb.first-launch-url", "hxxp://em.pc-on-internet.com/eas?

cu=1562&login=67212[...]
Deleted : user_pref("extensions.asktb.fresh-install", false);
Deleted : user_pref("extensions.asktb.l", "dis");
Deleted : user_pref("extensions.asktb.last-config-req", "1241088547380");
Deleted : user_pref("extensions.asktb.locale", "en_US");
Deleted : user_pref("extensions.asktb.o", "101720");
Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Deleted : user_pref("extensions.asktb.qsrc", "2871");
Deleted : user_pref("extensions.asktb.r", "4");
Deleted : user_pref("surfcanyon.added_to_searchbar", true);
Deleted : user_pref("surfcanyon.checked_domains", "");
Deleted : user_pref("surfcanyon.daily_code", "scIsOnSearchEngineDomain = function() {\nreturn

contains(scCurre[...]
Deleted : user_pref("surfcanyon.daily_code_timestamp", "1323380681432");
Deleted : user_pref("surfcanyon.disabled", false);
Deleted : user_pref("surfcanyon.disliked_domains", "");
Deleted : user_pref("surfcanyon.google_search_button_click_query", "granada");
Deleted : user_pref("surfcanyon.google_search_button_click_ts", "1295899436767");
Deleted : user_pref("surfcanyon.hourly_code", "scHourlyCodeRevision = '336f';\nscGetDocument =

function() {\nr[...]
Deleted : user_pref("surfcanyon.hourly_code2", "scEnableGoogle_hourly = function() {\nvar args =

window.locati[...]
Deleted : user_pref("surfcanyon.hourly_code_timestamp", "1324932411171");
Deleted : user_pref("surfcanyon.inst_id", "MZ93308731127199485379898479715521");
Deleted : user_pref("surfcanyon.inst_timestamp", "1236340839850");
Deleted : user_pref("surfcanyon.last_notification_displayed", 1);
Deleted : user_pref("surfcanyon.last_seen_splash", "336");
Deleted : user_pref("surfcanyon.num_recs_clicked", "11");
Deleted : user_pref("surfcanyon.num_results_clicked", "227");
Deleted : user_pref("surfcanyon.num_results_clicked_when_recs_available", "48");
Deleted : user_pref("surfcanyon.num_searches", "287");
Deleted : user_pref("surfcanyon.partner_code", "MZ");
Deleted : user_pref("surfcanyon.preferred_domains", "");
Deleted : user_pref("surfcanyon.refinements_cache", "^ruralvia/^voddler/^paco tejada/^sexo en

lepe/^acuario/^m[...]
Deleted : user_pref("surfcanyon.retailer_domain", "");
Deleted : user_pref("surfcanyon.retailer_id", "");
Deleted : user_pref("surfcanyon.retailer_url", "");
Deleted : user_pref("winamp_toolbar.buttons.layout",

"shoutcast_30026;mobile/android_33522;post_to_twitter_335[...]
Deleted : user_pref("winamp_toolbar.firsttime.showwindow", false);
Deleted : user_pref("winamp_toolbar.guid", "{6D13172D-2B31-BFBA-2937-9DBF032F345D}");
Deleted : user_pref("winamp_toolbar.install.lastTbVersion", "5.6.14.1");
Deleted : user_pref("winamp_toolbar.metrics.activestampdate", "8");
Deleted : user_pref("winamp_toolbar.metrics.activestampmonth", "11");
Deleted : user_pref("winamp_toolbar.metrics.activestampyear", "2011");
Deleted : user_pref("winamp_toolbar.metrics.originalDate", "21");
Deleted : user_pref("winamp_toolbar.metrics.originalHours", "21");
Deleted : user_pref("winamp_toolbar.metrics.originalMinutes", "34");
Deleted : user_pref("winamp_toolbar.metrics.originalMonth", "10");
Deleted : user_pref("winamp_toolbar.metrics.originalSeconds", "58");
Deleted : user_pref("winamp_toolbar.metrics.originalYear", "2010");
Deleted : user_pref("winamp_toolbar.remote.publish.xml", "1323380673979");
Deleted : user_pref("winamp_toolbar.search.cid", "08-12-2011");
Deleted : user_pref("winamp_toolbar.search.instd", "20110501093140213");
Deleted : user_pref("winamp_toolbar.search.oid", "21-10-2010");
Deleted : user_pref("winamp_toolbar.search.populateoncomplete", false);
Deleted : user_pref("winamp_toolbar.search.searchtype", "web");
Deleted : user_pref("winamp_toolbar.search.source", "tb50-ff-winamp");
Deleted : user_pref("winamp_toolbar.skin.custom", true);
Deleted : user_pref("winamp_toolbar.strbundle.msg", "Winamp Toolbar");
Deleted : user_pref("winamp_toolbar.upgrade.showwindow", false);
Deleted : user_pref("winamp_toolbar.winamp.appversion", "1");
Deleted : user_pref("winamp_toolbar.winamp.artist", "");
Deleted : user_pref("winamp_toolbar.winamp.button.focus", true);
Deleted : user_pref("winamp_toolbar.winamp.button.forward", true);
Deleted : user_pref("winamp_toolbar.winamp.button.open", true);
Deleted : user_pref("winamp_toolbar.winamp.button.pause", true);
Deleted : user_pref("winamp_toolbar.winamp.button.play", true);
Deleted : user_pref("winamp_toolbar.winamp.button.rewind", true);
Deleted : user_pref("winamp_toolbar.winamp.button.stop", false);
Deleted : user_pref("winamp_toolbar.winamp.button.volume", true);
Deleted : user_pref("winamp_toolbar.winamp.info.url", "hxxp://music.aol.com/artist/{artist}");
Deleted : user_pref("winamp_toolbar.winamp.ticker.show", true);
Deleted : user_pref("winamp_toolbar.winamp.title", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracklength", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.tracktime", "-999999");
Deleted : user_pref("winamp_toolbar.winamp.volume", "206");

-\\ Google Chrome v16.0.912.75

File : C:\Users\MANUEL CAMACHO\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [50532 octets] - [10/01/2012 23:29:55]
AdwCleaner[S1].txt - [51665 octets] - [10/01/2012 23:30:23]

*************************

Temporary folder : : 7 folder(s) and 6 file(s) deleted

########## EOF - C:\AdwCleaner[S1].txt - [51882 octets] ##########

Avatar de Usuario
helheim
Usuario Bill Gates
Usuario Bill Gates
Mensajes: 5001
Registrado: 20 Abr 2008, 11:38
Agradecido : 24 veces
Agradecimiento recibido: 169 veces
Contactar:

Re: Nokia_Multimedia_Common_Components_2.5-Installshield Wiz

Mensajepor helheim » 11 Ene 2012, 14:37

Hay dos cosas que no me cuadran:

1)
mecmora escribió:he pasado HijackThis, "Do system scan only", y no he encontrado las siguientes líneas:

O4 - HKCU\..\Run: [MSIDLL] C:\Windows\SysWOW64\rundll32.exe msirni32.dll,tUsscfzR

O20 - AppInit_DLLs: C:\PROGRA~2\WI3C8A~1\Datamngr\datamngr.dll C:\PROGRA~2\WI3C8A~1\Datamngr\IEBHO.dll
Esas dos líneas no han aparecido en ningún log de los que has pegado aquí y por lo tanto es lógico que no las encuentres.

2)
mecmora escribió:Al reinicio se sigue queriendo ejecutar el Wndows Instaler
Creo recordar un mensaje anterior tuyo donde decías que ese mensaje no te aparecía ya.

mecmora escribió:aparentemente ha desaparecido el problema de reinicio del Installer


Pasa de nuevo Hijackthis para ver si ya no aparece nada.

Un saludo.
La experiencia es una llama que alumbra quemando (Benito Pérez Galdós)


Volver a “Windows Vista”

¿Quién está conectado?

Usuarios navegando por este Foro: No hay usuarios registrados visitando el Foro y 3 invitados