Hola , gracias por el interes , ya baje el hijackthis, y le quite y le di arreglar en HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
y ya me deja entrar al registro, tambien le di en algo de whatsfind.com y ahora la pagina de inicio es about:blank, pero no se deja modificar.
lo que me pediste es esto:
StartupList report, 18/04/04, 10:59:48 p.m.
StartupList version: 1.52
Started from : C:\HIJACKTHIS.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v5.00 (5.00.2614.3500)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\ARCHIVOS DE PROGRAMA\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPCC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\ARCHIVOS DE PROGRAMA\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPCC.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\ptsnoop.exe
C:\WINDOWS\AGRSMMSG.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\ARCHIVOS DE PROGRAMA\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\AVPM.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\ARCHIVOS DE PROGRAMA\WINAMP\WINAMP.EXE
C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
C:\ARCHIVOS DE PROGRAMA\DAP\DAP.EXE
C:\HIJACKTHIS.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Menú Inicio\Programas\Inicio]
Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
Webshots.lnk = C:\Archivos de programa\Webshots\Launcher.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SoundMan = SOUNDMAN.EXE
AVPCC = "C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe" /wait
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
LoadQM = loadqm.exe
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
CountrySelection = pctptt.exe
PTSNOOP = ptsnoop.exe
IntelSMAPL = IntelCdx.exe
agrsmMSG = agrsmMSG.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = C:\WINDOWS\SYSTEM\mstask.exe
AVPCC Service = "C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe" /service
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\SYSTEM\NVMCTRAY.DLL,NvTaskbarInit
NVIEW = rundll32.exe nview.dll,nViewLoadHook
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 11/4/2004, 9:37:52)
[Rename]
NUL=c:\system volume information\_restore{2945fa56-a5d4-4538-a34c-6777bc685650}\rp50\a0017659.dll
NUL=c:\system volume information\_restore{2945fa56-a5d4-4538-a34c-6777bc685650}\rp50\a0017658.dll
NUL=c:\windows\cookies\
[email protected][1].txt
NUL=c:\windows\cookies\
[email protected][1].txt
NUL=c:\windows\cookies\gustavo@sexlist[2].txt
NUL=c:\windows\cookies\gustavo@paycounter[2].txt
NUL=c:\windows\cookies\gustavo@sextracker[1].txt
NUL=c:\windows\cookies\
[email protected][1].txt
NUL=c:\windows\cookies\
[email protected][2].txt
NUL=c:\windows\cookies\gustavo@hitbox[1].txt
NUL=c:\windows\cookies\
[email protected][1].txt
NUL=c:\windows\application data\msnt\msnt.dll
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
keyb sp,,C:\WINDOWS\COMMAND\keyboard.sys
PATH D:\BITWARE\
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\ARCHIVOS DE PROGRAMA\DAP\DAPIEBAR.DLL - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Optimización del inicio de aplicaciones.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 5.579 bytes
Report generated in 0,080 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
El Spybot y el Ad-Aware si los tengo actualizados y ya lo ejecute a prueba de fallos.
saludos