Pues resulta que en el curro se me a instalado un poquito de spyware, que me crea carpetas de favoritos en el IE, el Ad-Aware SE lo elimina momentaneamente, pero en el reinicio vuelve a aparecer, a ver si podis decirme como me libro de ello.

Ad-Aware SE Build 1.05
Logfile Created on:martes, 14 de diciembre de 2004 10:21:54
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R22 13.12.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
SCBAR(TAC index:3):15 total references
Tracking Cookie(TAC index:3):4 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
14-12-2004 10:21:54 - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 380
ThreadCreationTime : 14-12-2004 7:11:10
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 648
ThreadCreationTime : 14-12-2004 7:11:12
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\SYSTEM32\
ProcessID : 672
ThreadCreationTime : 14-12-2004 7:11:13
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 724
ThreadCreationTime : 14-12-2004 7:11:13
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Aplicación de servicios y controlador
InternalName : services.exe
LegalCopyright : Copyright (C) Microsoft Corporation. Reservados todos los derechos.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 736
ThreadCreationTime : 14-12-2004 7:11:13
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 904
ThreadCreationTime : 14-12-2004 7:11:14
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 996
ThreadCreationTime : 14-12-2004 7:11:14
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1128
ThreadCreationTime : 14-12-2004 7:11:14
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1144
ThreadCreationTime : 14-12-2004 7:11:14
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1332
ThreadCreationTime : 14-12-2004 7:11:15
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:11 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1580
ThreadCreationTime : 14-12-2004 7:11:19
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorador de Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Reservados todos los derechos.
OriginalFilename : EXPLORER.EXE
#:12 [igfxtray.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1708
ThreadCreationTime : 14-12-2004 7:11:19
BasePriority : Normal
FileVersion : 3,0,0,1773
ProductVersion : 7,0,0,1773
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
#:13 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1716
ThreadCreationTime : 14-12-2004 7:11:19
BasePriority : Normal
FileVersion : 3,0,0,1773
ProductVersion : 7,0,0,1773
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : HKCMD.EXE
#:14 [clshield.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 1756
ThreadCreationTime : 14-12-2004 7:11:20
BasePriority : Normal
FileVersion : 4.07.09
ProductVersion : 2.00.00
ProductName : Panda ClientShield
CompanyName : Panda Software International
FileDescription : ClShield
InternalName : ClShield.exe
LegalCopyright : © Panda Software 2004
OriginalFilename : ClShield.exe
#:15 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1800
ThreadCreationTime : 14-12-2004 7:11:20
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:16 [osa.exe]
FilePath : C:\Archivos de programa\Microsoft Office\Office\
ProcessID : 1824
ThreadCreationTime : 14-12-2004 7:11:20
BasePriority : Normal
#:17 [findfast.exe]
FilePath : C:\Archivos de programa\Microsoft Office\Office\
ProcessID : 1832
ThreadCreationTime : 14-12-2004 7:11:20
BasePriority : Normal
FileVersion : 8.0
ProductVersion : 8.0
ProductName : Búsqueda rápida de Microsoft®
CompanyName : Microsoft Corporation
FileDescription : Búsqueda rápida de Microsoft Office
InternalName : FINDFAST
LegalCopyright : Copyright © Microsoft Corp. 1995-1997
OriginalFilename : FINDFAST.EXE
#:18 [passrv.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 1956
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : Normal
#:19 [pagent.exe]
FilePath : C:\Archivos de programa\Panda Software\Panda Administrator 3\Pav_Agent\
ProcessID : 1988
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : Normal
FileVersion : 3, 0, 0, 0
ProductVersion : 3, 0, 0, 0
ProductName : pagent
CompanyName : Panda Software
FileDescription : Panda AdminSecure © communication service
InternalName : pagent
LegalCopyright : © Panda Software 2003
OriginalFilename : pagent.exe
Comments : Panda AdminSecure © communication service
#:20 [pavsched.exe]
FilePath : C:\Archivos de programa\Panda Software\Panda Administrator 3\Scheduler\
ProcessID : 2016
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : Normal
FileVersion : 3, 0, 0, 0
ProductVersion : 3, 0, 0, 0
ProductName : Panda AdminSecure
CompanyName : Panda Software
FileDescription : Panda AdminSecure Scheduler
InternalName : PavSched
LegalCopyright : © Panda Software 2003
OriginalFilename : PavSched.exe
Comments : Panda AdminSecure Scheduler
#:21 [pagentwd.exe]
FilePath : C:\Archivos de programa\Panda Software\Panda Administrator 3\Pav_Agent\
ProcessID : 2028
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : Normal
#:22 [pavsrv51.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 2040
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : High
FileVersion : 1, 3, 144, 11
ProductVersion : 1.3.144.0
ProductName : Panda Antivirus for Windows NT/2000/XP/2003
CompanyName : Panda Software
FileDescription : On-Access Antivirus Scanner Service.
InternalName : pavsrv.exe
LegalCopyright : © Panda Software 2004.
OriginalFilename : pavsrv.exe
#:23 [psimsvc.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 168
ThreadCreationTime : 14-12-2004 7:11:21
BasePriority : Normal
FileVersion : 1, 3, 2, 0
ProductVersion : 1, 3, 2, 0
ProductName : Panda Antivirus
CompanyName : Panda Software Internacional
FileDescription : Common Interface Manager
InternalName : PsImSvc
LegalCopyright : © Panda Software 2004.
OriginalFilename : PsImSvc.exe
#:24 [avengine.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 432
ThreadCreationTime : 14-12-2004 7:11:22
BasePriority : Normal
FileVersion : 1, 3, 144, 2
ProductVersion : 1.3.144.0
ProductName : Panda Antivirus for Windows NT/2000/XP/2003
CompanyName : Panda Software
FileDescription : Enhanced On-Access Antivirus Scanner Process.
InternalName : avengine.exe
LegalCopyright : © Panda Software 2004.
OriginalFilename : avengine.exe
#:25 [webproxy.exe]
FilePath : C:\Archivos de programa\Panda Software\AVTC\
ProcessID : 1644
ThreadCreationTime : 14-12-2004 7:11:37
BasePriority : Normal
FileVersion : 4, 6, 9, 6
ProductVersion : 2, 1, 0, 0
ProductName : Internet Resident
CompanyName : Panda Software
FileDescription : WebProxy
InternalName : WebProxy
LegalCopyright : © Panda Software 2004
OriginalFilename : WebProxy.exe
#:26 [iexplore.exe]
FilePath : C:\Archivos de programa\Internet Explorer\
ProcessID : 1788
ThreadCreationTime : 14-12-2004 7:15:42
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Reservados todos los derechos.
OriginalFilename : IEXPLORE.EXE
#:27 [acrord32.exe]
FilePath : C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\
ProcessID : 1576
ThreadCreationTime : 14-12-2004 7:20:51
BasePriority : Normal
FileVersion : 5.0.5.2001092400
ProductVersion : 5.0.5.0
ProductName : Adobe Acrobat Reader
CompanyName : Adobe Systems Incorporated
FileDescription : Acrobat Reader 5.0
LegalCopyright : Copyright 1984-2001 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroRd32.exe
#:28 [icqlite.exe]
FilePath : C:\Archivos de programa\ICQLite\
ProcessID : 1168
ThreadCreationTime : 14-12-2004 8:11:07
BasePriority : Normal
FileVersion : 555
ProductVersion : 1, 0, 0
ProductName : ICQLite
CompanyName : ICQ Ltd.
FileDescription : ICQLite
InternalName : ICQ Lite
LegalCopyright : Copyright (C) 2002
OriginalFilename : ICQLite.exe
#:29 [msaccess.exe]
FilePath : C:\Archivos de programa\Microsoft Office\Office\
ProcessID : 1380
ThreadCreationTime : 14-12-2004 8:19:49
BasePriority : Normal
#:30 [ad-aware.exe]
FilePath : C:\Archivos de programa\Lavasoft\Ad-Aware SE Personal\
ProcessID : 1668
ThreadCreationTime : 14-12-2004 9:10:28
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:31 [iexplore.exe]
FilePath : C:\Archivos de programa\Internet Explorer\
ProcessID : 1424
ThreadCreationTime : 14-12-2004 9:19:37
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Sistema operativo Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Reservados todos los derechos.
OriginalFilename : IEXPLORE.EXE
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
SCBAR Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{00041a26-7033-432c-94c7-6371de343822}
SCBAR Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{9368D063-44BE-49B9-BD14-BB9663FD38FC}"
Rootkey : HKEY_USERS
Object : S-1-5-21-357967339-4264649163-3499916212-1004\software\microsoft\internet explorer\urlsearchhooks
Value : {9368D063-44BE-49B9-BD14-BB9663FD38FC}
SCBAR Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{9368D063-44BE-49B9-BD14-BB9663FD38FC}"
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\urlsearchhooks
Value : {9368D063-44BE-49B9-BD14-BB9663FD38FC}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 3
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : educu093@tribalfusion[2].txt
Category : Data Miner
Comment : Hits:3
Value : Cookie:
[email protected]/
Expires : 01-01-2038 1:00:00
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : educu093@fastclick[1].txt
Category : Data Miner
Comment : Hits:5
Value : Cookie:
[email protected]/
Expires : 03-12-2006 12:37:52
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : educu093@mediaplex[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:
[email protected]/
Expires : 22-06-2009 1:00:00
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : educu093@casalemedia[1].txt
Category : Data Miner
Comment : Hits:9
Value : Cookie:
[email protected]/
Expires : 04-12-2005 7:52:14
LastSync : Hits:9
UseCount : 0
Hits : 9
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 4
Objects found so far: 7
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
2 entries scanned.
New critical objects:0
Objects found so far: 7
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
SCBAR Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\restore
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Autos-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Computers and Internet-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Music-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Communications-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Health and Fitness-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Travel-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Sports-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Shopping-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Entertainment-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Games-
SCBAR Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\Documents and Settings\Educu093\Favoritos\-Business Directory-
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 12
Objects found so far: 19
10:24:07 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:02:12.281
Objects scanned:81045
Objects identified:19
Objects ignored:0
New critical objects:19