Hey SpySentinel!
Thank you so much for helping me!
Ok, first of all, before you replied to my topic I read the guide in the forum to remove malware and used some of the tools there. This had no sucess, however found a few infections which I removed. I had used MBAM on August 10th, but I will post both MBAM logs; the one from today and the one from the 10th, since they both found some problem.
Second, my OS language is spanish

(I work in the Dominican Republic), and I noticed that on Extra.txt log there are some errors which are in spanish. I hope there will be no problem with this since it's easy to understand the context. If you need translation just post it here and I'll tell you!

Ok, here we go:
OTL LOG:
OTL logfile created on: 12/08/2009 07:50:02 a.m. - Run 1
OTL by OldTimer - Version 3.0.10.6 Folder = C:\Documents and Settings\Felipe\Escritorio\ñema
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00002C0A | Country: Argentina | Language: ESS | Date Format: dd/MM/yyyy
958.36 Mb Total Physical Memory | 179.09 Mb Available Physical Memory | 18.69% Memory free
2.85 Gb Paging File | 2.16 Gb Available in Paging File | 75.64% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 37.99 Gb Total Space | 23.09 Gb Free Space | 60.79% Space Free | Partition Type: NTFS
Drive D: | 36.53 Gb Total Space | 19.13 Gb Free Space | 52.36% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC
Current User Name: Felipe
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\System32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - c:\archivos de programa\archivos comunes\logitech\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Archivos de programa\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Archivos de programa\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Archivos de programa\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Archivos de programa\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Archivos de programa\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Archivos de programa\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\System32\S3trayp.exe (S3 Graphics Co., Ltd.)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Archivos de programa\Archivos comunes\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.)
PRC - C:\Archivos de programa\Logitech\QuickCam10\QuickCam10.exe ()
PRC - C:\Archivos de programa\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Archivos de programa\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Archivos de programa\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
PRC - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)
PRC - C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Archivos de programa\Archivos comunes\Logitech\LComMgr\LVComSX.exe (Logitech Inc.)
PRC - C:\Archivos de programa\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Archivos de programa\Logitech\QuickCam10\COCIManager.exe (Logitech Inc.)
PRC - C:\Archivos de programa\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Felipe\Escritorio\ñema\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\System32\msfeedssync.exe (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) -- C:\Archivos de programa\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Archivos de programa\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Archivos de programa\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (fsssvc [Auto | Running]) -- C:\Archivos de programa\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Archivos de programa\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Archivos de programa\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) -- C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\System32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (LVPrcSrv [Auto | Running]) -- c:\archivos de programa\archivos comunes\logitech\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) -- C:\Archivos de programa\Archivos comunes\Logitech\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (MDM [Auto | Running]) -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (FETNDISB [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\fetnd5b.sys (VIA Technologies, Inc. )
DRV - (fssfltr [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LVcKap [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LVcKap.sys (Logitech Inc.)
DRV - (LVMVDrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\lvusbsta.sys (Logitech Inc.)
DRV - (PID_0928 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\LV561AV.SYS (Logitech Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (S3GIGP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\S3gIGPm.sys (S3 Graphics Co., Ltd.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tap0801 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\tap0801.sys (The OpenVPN Project)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (videX32 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (xfilt [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\xfilt.sys (VIA Technologies,Inc)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Archivos de programa\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.co...-8&oe=UTF-8&q="FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems:
[email protected]:1.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:1.2
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Archivos de programa\AVG\AVG8\Firefox [2009/07/01 08:26:46 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Archivos de programa\AVG\AVG8\Toolbar\Firefox\
[email protected] [2009/07/01 08:26:05 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ff [2008/10/30 15:26:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/12 03:11:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2009/08/04 08:48:37 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins [2009/08/04 08:48:38 | 00,000,000 | ---D | M]
[2009/01/09 17:53:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Extensions
[2009/01/09 17:53:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/12 07:36:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Firefox\Profiles\7esjtkhz.default\extensions
[2009/01/07 17:00:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Firefox\Profiles\7esjtkhz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/07/23 16:36:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Firefox\Profiles\7esjtkhz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/07/01 17:17:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Firefox\Profiles\7esjtkhz.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2009/02/18 20:30:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\mozilla\Firefox\Profiles\7esjtkhz.default\extensions\
[email protected][2008/11/06 14:31:49 | 00,002,109 | ---- | M] () -- C:\Documents and Settings\Felipe\Datos de programa\Mozilla\FireFox\Profiles\7esjtkhz.default\searchplugins\youtube-video-search.xml
[2009/08/12 07:36:42 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions
[2008/06/16 22:45:04 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/08/04 08:48:37 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/10/30 15:26:56 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/04 00:24:42 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/02 12:44:26 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/08/06 09:42:32 | 00,000,000 | ---D | M] -- C:\Archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/08/04 08:48:31 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\browserdirprovider.dll
[2009/08/04 08:48:31 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\brwsrcmp.dll
[2009/07/25 05:23:01 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npdeploytk.dll
[2008/06/10 20:03:12 | 01,335,600 | ---- | M] (DivX,Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npdivx32.dll
[2009/08/04 08:48:32 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Archivos de programa\mozilla firefox\plugins\npnul32.dll
[2007/03/22 21:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- C:\Archivos de programa\mozilla firefox\plugins\NPOFFICE.DLL
[2008/10/14 21:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\nppdf32.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin2.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin3.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin4.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin5.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin6.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin7.dll
[2009/07/08 15:30:58 | 00,143,360 | ---- | M] (Apple Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npqtplugin8.dll
[2009/01/09 17:53:40 | 00,001,394 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/09 17:53:40 | 00,002,193 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\answers.xml
[2009/07/01 14:15:14 | 00,001,489 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\avg_igeared.xml
[2009/01/09 17:53:40 | 00,001,534 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/09 17:53:40 | 00,002,343 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\eBay.xml
[2009/01/09 17:53:40 | 00,001,706 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\google.xml
[2009/01/09 17:53:40 | 00,001,178 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/09 17:53:40 | 00,000,792 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (318491 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10922 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Archivos de programa\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Archivos de programa\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Click-to-Call BHO) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Archivos de programa\Windows Live\Messenger\wlchtc.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Archivos de programa\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Archivos de programa\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Archivos de programa\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Archivos de programa\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Archivos de programa\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Archivos de programa\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Archivos de programa\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Archivos de programa\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Archivos de programa\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Archivos de programa\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [fssui] C:\Archivos de programa\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Archivos de programa\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Archivos de programa\Archivos comunes\Logitech\LComMgr\Communications_Helper.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Archivos de programa\Logitech\QuickCam10\QuickCam10.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [QuickTime Task] C:\Archivos de programa\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [S3Trayp] C:\WINDOWS\System32\S3trayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe File not found
O4 - HKCU..\Run: [ares] C:\Archivos de programa\Ares\Ares.exe File not found
O4 - HKCU..\Run: [LDM] C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech)
O4 - HKCU..\Run: [MsnMsgr] C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\Logitech Desktop Messenger.lnk = C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O8 - Extra context menu item: E&xportar a Microsoft Excel - C:\Archivos de programa\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Archivos de programa\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Archivos de programa\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1 196.3.81.5 200.88.127.22
O18 - Protocol\Handler\bw+0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw+0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw-0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw00 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw00s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw-0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw10 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw10s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw20 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw20s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw30 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw30s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw40 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw40s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw50 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw50s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw60 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw60s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw70 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw70s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw80 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw80s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw90 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bw90s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwa0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwa0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwb0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwb0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwc0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwc0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwd0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwd0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwe0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwe0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwf0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwf0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwg0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwg0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwh0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwh0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwi0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwi0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwj0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwj0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwk0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwk0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwl0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwl0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwm0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwm0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwn0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwn0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwo0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwo0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwp0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwp0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwq0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwq0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwr0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwr0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bws0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bws0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwt0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwt0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwu0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwu0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwv0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwv0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bww0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bww0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwx0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwx0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwy0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwy0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwz0 {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\bwz0s {45042735-6a39-4b23-a480-adad6fcb8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Archivos de programa\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {45042735-6A39-4B23-A480-ADAD6FCB8976} - C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (Logitech)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Archivos de programa\Archivos comunes\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Archivos de programa\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Archivos de programa\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (C:\RECYCLER\S-1-5-21-7116568769-7389958157-042186739-2252\nissan.exe) - C:\RECYCLER\S-1-5-21-7116568769-7389958157-042186739-2252\nissan.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/05/19 23:30:50 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{f837f514-30e8-11de-8d60-0019dbabc147}\Shell\AutoRun\command - "" = F:\BORO\kawasaki.exe -- File not found
O33 - MountPoints2\{f837f514-30e8-11de-8d60-0019dbabc147}\Shell\explore\command - "" = F:\.\\BORO\\\kawasaki.exe -- File not found
O33 - MountPoints2\{f837f514-30e8-11de-8d60-0019dbabc147}\Shell\open\command - "" = F:\BORO\\\\\kawasaki.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ========== [2009/08/12 05:55:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/08/12 03:08:38 | 00,000,000 | ---D | C] -- C:\8bd9f25ee2e36cf8576b9732
[2009/08/12 03:01:16 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/08/10 17:25:57 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/08/10 17:15:15 | 00,000,500 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/10 17:14:56 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/08/10 17:13:49 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Datos de programa\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/08/10 17:13:48 | 00,000,916 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Ad-Aware.lnk
[2009/08/10 17:13:33 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Lavasoft
[2009/08/10 17:13:33 | 00,000,000 | ---D | C] -- C:\Archivos de programa\Lavasoft
[2009/08/10 17:00:42 | 60,857,536 | ---- | C] (Lavasoft ) -- C:\Documents and Settings\Felipe\Escritorio\Ad-AwareAE.exe
[2009/08/10 16:57:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Felipe\Datos de programa\Malwarebytes
[2009/08/10 16:57:05 | 00,000,731 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Malwarebytes' Anti-Malware.lnk
[2009/08/10 16:57:02 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/10 16:57:01 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/10 16:57:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Malwarebytes
[2009/08/10 16:57:01 | 00,000,000 | ---D | C] -- C:\Archivos de programa\Malwarebytes' Anti-Malware
[2009/08/10 16:55:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/08/10 16:54:45 | 00,000,646 | ---- | C] () -- C:\Documents and Settings\Felipe\Escritorio\NTREGOPT.lnk
[2009/08/10 16:54:44 | 00,000,627 | ---- | C] () -- C:\Documents and Settings\Felipe\Escritorio\ERUNT.lnk
[2009/08/10 16:54:40 | 00,000,000 | ---D | C] -- C:\Archivos de programa\ERUNT
[2009/08/10 16:51:09 | 00,000,000 | ---D | C] -- C:\Archivos de programa\MSBuild
[2009/08/10 16:47:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/08/10 16:46:58 | 00,000,000 | ---D | C] -- C:\Archivos de programa\Reference Assemblies
[2009/08/10 16:46:25 | 00,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2009/08/10 16:31:02 | 00,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2009/08/10 16:31:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2009/08/10 16:30:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\URTTemp
[2009/08/10 16:14:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Felipe\Escritorio\ñema
[2009/08/06 09:42:30 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/08/06 09:42:30 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/08/06 09:42:30 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2009/08/03 08:11:21 | 00,001,797 | ---- | C] () -- C:\Documents and Settings\Felipe\Escritorio\HijackThis.lnk
[2009/08/03 08:11:19 | 00,000,000 | ---D | C] -- C:\Archivos de programa\Trend Micro
[2009/08/03 07:12:38 | 00,000,982 | ---- | C] () -- C:\Documents and Settings\Felipe\Escritorio\Spybot - Search & Destroy.lnk
[2009/08/03 07:12:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy
[2009/08/03 07:12:28 | 00,000,000 | ---D | C] -- C:\Archivos de programa\Spybot - Search & Destroy
[2009/07/31 02:20:39 | 00,000,839 | ---- | C] () -- C:\Documents and Settings\Felipe\Escritorio\Reproductor de Windows Media.lnk
[2009/06/29 17:45:17 | 00,000,023 | ---- | C] () -- C:\WINDOWS\SWFDecompiler.INI
[2009/06/29 16:19:29 | 01,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2009/06/14 17:39:41 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\ssresources.dll
[2009/06/14 17:39:41 | 00,020,481 | ---- | C] () -- C:\WINDOWS\System32\SystemsHook.dll
[2009/06/10 03:01:59 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2009/03/04 12:22:48 | 00,000,434 | ---- | C] () -- C:\WINDOWS\LEXSTAT.INI
[2009/02/27 03:37:47 | 04,762,112 | ---- | C] () -- C:\WINDOWS\System32\NCMedia.dll
[2008/11/08 14:02:12 | 00,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/10/11 20:00:04 | 00,000,031 | ---- | C] () -- C:\WINDOWS\System32\winnsdows2.dll
[2008/10/10 01:38:32 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/10/10 01:38:32 | 00,383,238 | ---- | C] () -- C:\WINDOWS\System32\libmp3lame-0.dll
[2008/05/24 19:03:45 | 00,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/10/12 03:11:58 | 00,022,334 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2006/06/26 10:33:40 | 00,023,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2003/04/11 12:14:14 | 00,005,827 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/24 06:00:00 | 00,000,647 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/24 06:00:00 | 00,000,263 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ========== [2009/08/12 07:50:24 | 00,000,490 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{1D1F8161-9D7D-4E01-AC74-37A2BC799E8B}.job
[2009/08/12 07:47:24 | 00,069,656 | ---- | M] () -- C:\Documents and Settings\Felipe\Configuración local\Datos de programa\GDIPFONTCACHEV1.DAT
[2009/08/12 03:25:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/08/12 03:25:00 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/08/12 03:24:58 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/08/12 03:24:55 | 00,269,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/12 03:16:12 | 01,078,316 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/12 03:16:12 | 00,505,318 | ---- | M] () -- C:\WINDOWS\System32\perfh00A.dat
[2009/08/12 03:16:12 | 00,441,574 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/08/12 03:16:12 | 00,090,948 | ---- | M] () -- C:\WINDOWS\System32\perfc00A.dat
[2009/08/12 03:16:12 | 00,071,510 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/08/11 10:18:02 | 00,000,434 | ---- | M] () -- C:\WINDOWS\LEXSTAT.INI
[2009/08/11 10:15:00 | 00,078,507 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\Envio Datos.mht
[2009/08/11 08:58:28 | 39,735,262 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/11 08:58:28 | 00,060,374 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/10 17:15:15 | 00,000,500 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/10 17:13:48 | 00,000,916 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Ad-Aware.lnk
[2009/08/10 17:08:32 | 60,857,536 | ---- | M] (Lavasoft ) -- C:\Documents and Settings\Felipe\Escritorio\Ad-AwareAE.exe
[2009/08/10 16:57:05 | 00,000,731 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Malwarebytes' Anti-Malware.lnk
[2009/08/10 16:54:45 | 00,000,646 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\NTREGOPT.lnk
[2009/08/10 16:54:44 | 00,000,627 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\ERUNT.lnk
[2009/08/09 23:27:15 | 00,068,608 | ---- | M] () -- C:\Documents and Settings\Felipe\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/06 14:16:34 | 00,318,491 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/03 13:36:28 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/03 08:11:21 | 00,001,797 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\HijackThis.lnk
[2009/08/03 07:12:38 | 00,000,982 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\Spybot - Search & Destroy.lnk
[2009/07/31 23:03:10 | 00,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/07/31 02:20:39 | 00,000,839 | ---- | M] () -- C:\Documents and Settings\Felipe\Escritorio\Reproductor de Windows Media.lnk
[2009/07/29 03:01:47 | 00,000,584 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/07/25 05:23:07 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/07/25 05:23:07 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/07/25 05:23:05 | 00,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2009/07/25 05:23:00 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2009/07/25 03:00:33 | 00,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2009/07/24 08:56:35 | 00,335,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/19 09:28:27 | 03,597,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009/07/19 09:28:27 | 03,597,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/07/19 09:28:25 | 06,067,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieframe.dll
[2009/07/19 09:28:25 | 06,067,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/13 17:10:44 | 00,000,647 | ---- | M] () -- C:\WINDOWS\win.ini
========== LOP Check ========== [2009/08/10 17:13:33 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Datos de programa
[2009/04/13 17:23:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/10 17:13:49 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\{EF63305C-BAD7-4144-9208-D65528260864}
[2009/07/01 17:22:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\AVG Security Toolbar
[2009/02/25 13:00:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Azureus
[2008/09/18 12:34:17 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\CanonBJ
[2008/12/28 08:24:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\OrbNetworks
[2009/07/01 17:20:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\TEMP
[2009/08/10 16:57:08 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Felipe\Datos de programa
[2008/10/30 16:19:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\Ahead
[2008/09/10 15:05:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\AVGTOOLBAR
[2009/02/25 13:10:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\Azureus
[2008/10/30 16:04:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\FinalBurner MP3
[2009/02/24 09:26:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\GetRight
[2009/04/15 22:58:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\U3
[2009/03/01 21:33:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\uTorrent
[2009/06/19 12:55:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Felipe\Datos de programa\YoudaGames
[2009/08/10 17:15:15 | 00,000,500 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2001/08/24 06:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/08/12 03:25:04 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/08/12 07:50:24 | 00,000,490 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{1D1F8161-9D7D-4E01-AC74-37A2BC799E8B}.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Datos de programa\TEMP:0C1EFF69
< End of report >
ROOTREPEAL LOG:ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/12 07:51
Program Version: Version 1.3.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF55B8000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B2B000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEFB65000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "Lbd.sys" at address 0xf75c187e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "Lbd.sys" at address 0xf75c1bfe
==EOF==
MBAM LOG(S):(2009-08-10):
Malwarebytes' Anti-Malware 1.40
Database version: 2594
Windows 5.1.2600 Service Pack 3
10/08/2009 05:04:36 p.m.
mbam-log-2009-08-10 (17-04-36).txt
Scan type: Quick Scan
Objects scanned: 92115
Time elapsed: 6 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
(2009-08-12):
Malwarebytes' Anti-Malware 1.40
Database version: 2594
Windows 5.1.2600 Service Pack 3
12/08/2009 08:14:04 a.m.
mbam-log-2009-08-12 (08-14-04).txt
Scan type: Quick Scan
Objects scanned: 92415
Time elapsed: 6 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Thanks in advance!
-Joseph