I don't know the name of the infection, but I do know there is one... some programs are not running, like mbam, i reintaled it before i could run it... so,...logs:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
2010-07-20 13:48:14
mbam-log-2010-07-20 (13-48-14).txt
Scan type: Quick scan
Objects scanned: 127643
Time elapsed: 6 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Jesica\Escritorio\PotMaker.exe (Trojan.Downloader) -> No action taken.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-20 13:37:38
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Jesica\CONFIG~1\Temp\pwtdypog.sys
---- System - GMER 1.0.15 ----
SSDT B87E2756 ZwCreateKey
SSDT B87E274C ZwCreateThread
SSDT B87E275B ZwDeleteKey
SSDT B87E2765 ZwDeleteValueKey
SSDT spjn.sys ZwEnumerateKey [0xB7EC5CA4]
SSDT spjn.sys ZwEnumerateValueKey [0xB7EC6032]
SSDT B87E276A ZwLoadKey
SSDT spjn.sys ZwOpenKey [0xB7EA70C0]
SSDT B87E2738 ZwOpenProcess
SSDT B87E273D ZwOpenThread
SSDT spjn.sys ZwQueryKey [0xB7EC610A]
SSDT spjn.sys ZwQueryValueKey [0xB7EC5F8A]
SSDT B87E2774 ZwReplaceKey
SSDT B87E276F ZwRestoreKey
SSDT B87E2760 ZwSetValueKey
SSDT B87E2747 ZwTerminateProcess
INT 0x62 ? 8ABD0BF8
INT 0x73 ? 8A9A5F00
INT 0x83 ? 8AB61BF8
INT 0xB4 ? 8A9A5F00
---- Kernel code sections - GMER 1.0.15 ----
? spjn.sys El sistema no puede hallar el archivo especificado. !
.text USBPORT.SYS!DllUnload B73B162C 5 Bytes JMP 8A9A54E0
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6A7E360, 0x3D46A5, 0xE8000020]
.text a5v88i9q.SYS B6A32386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a5v88i9q.SYS B6A323AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a5v88i9q.SYS B6A323C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text a5v88i9q.SYS B6A323C9 1 Byte [30]
.text a5v88i9q.SYS B6A323C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
init C:\Archivos de programa\TFE\npkcusb.sys entry point in "init" section [0xB828F0F7]
---- User code sections - GMER 1.0.15 ----
.text C:\Archivos de programa\Mozilla Firefox\firefox.exe[1124] ntdll.dll!LdrLoadDll 7C925CBB 5 Bytes JMP 004013F0 C:\Archivos de programa\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Archivos de programa\Mozilla Firefox\plugin-container.exe[1676] USER32.dll!TrackPopupMenu 7E3E50EE 5 Bytes JMP 104505FE C:\Archivos de programa\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!LoadResource 7C809FC5 7 Bytes JMP 28001E30 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceExW 7C80AC98 7 Bytes JMP 28001C70 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceW 7C80BBDE 7 Bytes JMP 28001BF0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!SizeofResource 7C80BC79 7 Bytes JMP 28001EF0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceA 7C80BE99 7 Bytes JMP 28001D00 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!LockResource 7C80CCA7 5 Bytes JMP 28001F60 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!CreateEventA 7C8308C9 5 Bytes JMP 28001850 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] kernel32.dll!FindResourceExA 7C835FC0 7 Bytes JMP 28001D90 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] ADVAPI32.dll!CryptDeriveKey 77DBA1A5 7 Bytes JMP 28001000 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] ADVAPI32.dll!CryptDecrypt 77DBA2D1 7 Bytes JMP 28001060 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!GetWindowLongW 7E3988A6 7 Bytes JMP 28006AF0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!PeekMessageW 7E39929B 5 Bytes JMP 280046B0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!CreateWindowExW 7E39FC25 5 Bytes JMP 28003CE0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!SetWindowRgn 7E39FFB2 7 Bytes JMP 28005FD0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!LoadIconW 7E3A0894 5 Bytes JMP 28006950 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!LoadImageW 7E3A2CFE 5 Bytes JMP 28006760 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!CreateDialogParamW 7E3A7D4F 5 Bytes JMP 28006110 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!SetWindowPlacement 7E3AD84C 5 Bytes JMP 28005E90 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!MessageBoxIndirectW 7E3E62AB 5 Bytes JMP 28006300 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] USER32.dll!TrackPopupMenuEx 7E3ECD28 5 Bytes JMP 28004F90 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] SHELL32.dll!Shell_NotifyIconW 7E701BEA 5 Bytes JMP 28003430 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] ole32.dll!CoInitializeEx 774CEF6B 5 Bytes JMP 28002270 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] ole32.dll!CoCreateInstance 774CFAC3 5 Bytes JMP 28002610 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] ole32.dll!CoRegisterClassObject 774E8720 5 Bytes JMP 28002370 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] WININET.dll!InternetReadFile 3FA1654B 5 Bytes JMP 2800A0E0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] WININET.dll!InternetCloseHandle 3FA19088 5 Bytes JMP 2800A290 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] WININET.dll!HttpOpenRequestA 3FA1D508 5 Bytes JMP 28009F50 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe[2856] WININET.dll!HttpSendRequestA 3FA2EE89 5 Bytes JMP 2800A1C0 C:\Archivos de programa\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8AB601F8
Device \FileSystem\Fastfat \FatCdrom 8A8A9500
Device \FileSystem\Udfs \UdfsCdRom 8A4ED500
Device \FileSystem\Udfs \UdfsDisk 8A4ED500
Device \Driver\sptd \Device\2428629562 spjn.sys
Device \Driver\usbohci \Device\USBPDO-0 8A9A31F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AB621F8
Device \Driver\dmio \Device\DmControl\DmConfig 8AB621F8
Device \Driver\dmio \Device\DmControl\DmPnP 8AB621F8
Device \Driver\dmio \Device\DmControl\DmInfo 8AB621F8
Device \Driver\usbehci \Device\USBPDO-1 8A99F1F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8ABD11F8
Device \Driver\Cdrom \Device\CdRom0 8A8DE1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{405C5288-3744-4F4D-B927-6FF856E5AFAF} 8A9724D8
Device \Driver\Cdrom \Device\CdRom1 8A8DE1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 8ABD01F8
Device \Driver\atapi \Device\Ide\IdePort0 8ABD01F8
Device \Driver\atapi \Device\Ide\IdePort1 8ABD01F8
Device \Driver\Cdrom \Device\CdRom2 8A8DE1F8
Device \Driver\Cdrom \Device\CdRom3 8A8DE1F8
Device \Driver\Cdrom \Device\CdRom4 8A8DE1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A9724D8
Device \Driver\NetBT \Device\NetbiosSmb 8A9724D8
Device \Driver\PCI_PNP4562 \Device\0000004c spjn.sys
Device \Driver\usbohci \Device\USBFDO-0 8A9A31F8
Device \Driver\usbehci \Device\USBFDO-1 8A99F1F8
Device \Driver\nvata \Device\NvAta0 8AB611F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A71E500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A71E500
Device \Driver\nvata \Device\0000006f 8AB611F8
Device \Driver\Ftdisk \Device\FtControl 8ABD11F8
Device \Driver\a5v88i9q \Device\Scsi\a5v88i9q1Port3Path0Target0Lun0 8A97C1F8
Device \Driver\a5v88i9q \Device\Scsi\a5v88i9q1 8A97C1F8
Device \Driver\a5v88i9q \Device\Scsi\a5v88i9q1Port3Path0Target2Lun0 8A97C1F8
Device \Driver\a5v88i9q \Device\Scsi\a5v88i9q1Port3Path0Target3Lun0 8A97C1F8
Device \Driver\a5v88i9q \Device\Scsi\a5v88i9q1Port3Path0Target1Lun0 8A97C1F8
Device \FileSystem\Fastfat \Fat 8A8A9500
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs 8A665500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\[email protected] C:\Archivos de programa\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\[email protected] 0x52 0xD2 0xFB 0x52 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xD8 0xD3 0xC7 0xFE ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x81 0x01 0xBA 0xD7 ...
Reg HKLM\SYSTEM\ControlSet001\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet001\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet001\Services\[email protected] \systemroot\system32\drivers\TDSSserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\[email protected] 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] C:\Archivos de programa\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0x12 0x9A 0x72 0xB3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\0[email protected] 0x6F 0xF4 0x19 0xAC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x0B 0x9D 0xA3 0xAB ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0xAB 0x4A 0xB2 0xF2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x55 0x27 0x27 0xCD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x4C 0x9D 0x27 0x94 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\[email protected] 0x8F 0xA8 0xEC 0x93 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xD8 0xD3 0xC7 0xFE ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x1E 0x5D 0xC1 0x29 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x1F 0x6F 0x58 0xE9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF0 0x95 0x7A 0x3A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] C:\Archivos de programa\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0x12 0x9A 0x72 0xB3 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\0[email protected] 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\0[email protected] 0x6F 0xF4 0x19 0xAC ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x0B 0x9D 0xA3 0xAB ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0xAB 0x4A 0xB2 0xF2 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x55 0x27 0x27 0xCD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\[email protected] 0x4C 0x9D 0x27 0x94 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\[email protected] 0x8F 0xA8 0xEC 0x93 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\0[email protected] 0xD8 0xD3 0xC7 0xFE ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x1E 0x5D 0xC1 0x29 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0x1F 0x6F 0x58 0xE9 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0[email protected] 0xF0 0x95 0x7A 0x3A ...
---- EOF - GMER 1.0.15 ----
OTL logfile created on: 2010-07-20 13:38:47 - Run 4
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Jesica\Escritorio
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00002C0A | Country: Argentina | Language: ESS | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 298.09 Gb Total Space | 70.78 Gb Free Space | 23.75% Space Free | Partition Type: NTFS
Drive D: | 4.37 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JESICA
Current User Name: Jesica
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010-07-20 13:36:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jesica\Escritorio\OTL.exe
PRC - [2010-06-27 21:08:28 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Archivos de programa\Mozilla Firefox\plugin-container.exe
PRC - [2010-06-27 21:08:27 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Archivos de programa\Mozilla Firefox\firefox.exe
PRC - [2010-04-16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Archivos de programa\Windows Live\Contacts\wlcomm.exe
PRC - [2010-02-18 11:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
PRC - [2010-02-18 01:59:45 | 000,470,785 | ---- | M] (Avira GmbH) -- c:\Archivos de programa\Avira\AntiVir Desktop\avcenter.exe
PRC - [2009-07-21 13:40:24 | 000,404,737 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\update.exe
PRC - [2009-05-13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe
PRC - [2009-03-02 12:08:47 | 000,209,153 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe
PRC - [2007-06-13 10:22:28 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006-05-24 15:31:39 | 001,372,160 | ---- | M] () -- C:\Archivos de programa\TGTSoft\StyleXP\StyleXP.exe
PRC - [2003-06-19 23:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
========== Modules (SafeList) ==========
MOD - [2010-07-20 13:36:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jesica\Escritorio\OTL.exe
MOD - [2006-08-25 12:46:26 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004-08-03 18:01:18 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Archivos de programa\TGTSoft\StyleXP\StyleXPService.exe -- (StyleXPService)
SRV - File not found [Auto | Stopped] -- -- (BackWeb Plug-in - 4476822)
SRV - [2009-07-21 13:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Stopped] -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009-05-13 15:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2008-12-13 14:12:42 | 000,413,696 | ---- | M] (Ares Development Group) [On_Demand | Stopped] -- C:\Archivos de programa\Ares\chatServer.exe -- (AresChatServer)
SRV - [2008-09-15 00:34:33 | 000,072,704 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2007-10-25 15:27:54 | 000,266,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc)
SRV - [2007-03-26 13:06:24 | 000,292,864 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2005-04-04 00:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003-07-28 20:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2003-06-19 23:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\alppfium.sys -- (vack)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\philcam2.sys -- (phil2vid)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\hheausq.sys -- (kgznaszq)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\InCDRm.sys -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\InCDPass.sys -- (InCDPass)
DRV - File not found [File_System | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\InCDFs.sys -- (InCDFs)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\asyncmac.sys -- (AsyncMac)
DRV - [2010-02-18 02:00:07 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009-10-13 05:50:00 | 000,133,632 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2kfNT.sys -- (Mkd2kfNt)
DRV - [2009-07-13 05:37:00 | 000,079,360 | ---- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mkd2Nadr.sys -- (Mkd2Nadr)
DRV - [2009-06-29 16:32:58 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009-06-10 18:33:00 | 008,087,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009-05-11 09:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009-03-30 09:33:07 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009-02-13 11:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2008-09-22 09:04:02 | 000,019,712 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Archivos de programa\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2008-09-22 09:04:02 | 000,018,304 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Archivos de programa\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2007-10-10 17:41:50 | 000,042,112 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motodrv.sys -- (MotDev)
DRV - [2007-06-18 15:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\motmodem.sys -- (motmodem)
DRV - [2007-03-01 06:27:00 | 004,484,608 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006-10-19 02:12:16 | 000,012,664 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2006-10-17 21:31:38 | 000,105,472 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006-09-27 04:04:16 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006-09-27 04:04:12 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006-07-01 22:43:02 | 000,043,520 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005-10-31 18:44:39 | 000,010,880 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Running] -- C:\Archivos de programa\TGTSoft\StyleXP\StyleXPHelper.exe -- (StyleXPHelper)
DRV - [2005-10-19 13:00:00 | 000,011,264 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\EIO.sys -- (EIO)
DRV - [2005-04-06 11:30:16 | 000,026,752 | ---- | M] (ENCORE ELECTRONICS, INC. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ipfnd51.sys -- (ip100xp)
DRV - [2005-02-01 18:55:40 | 000,037,009 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Archivos de programa\TFE\npkcusb.sys -- (npkcusb)
DRV - [2005-02-01 18:55:40 | 000,021,442 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Archivos de programa\TFE\npkcrypt.sys -- (npkcrypt)
DRV - [2005-01-07 17:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004-08-11 13:00:00 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2004-08-03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Controlador de Windows NT del adaptador Fast Ethernet PCI basado en Realtek RTL8139(A/B/C)
DRV - [2004-08-03 22:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) Controlador de audio USB (WDM)
DRV - [2004-05-05 22:46:16 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001-11-07 01:00:00 | 000,166,504 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\webc3vid.sys -- (CTL511Plus) Video Blaster WebCam 3/WebCam Plus (WDM)
DRV - [2001-09-18 11:00:00 | 000,167,816 | ---- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\omcamvid.sys -- (OVT511Plus)
DRV - [2000-10-25 09:27:24 | 000,003,000 | R--- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\SetupNT.sys -- (SetupNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.co...es&source=iglk"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.8.86
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2010-06-27 21:08:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins [2010-07-05 15:49:39 | 000,000,000 | ---D | M]
[2009-01-12 17:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Extensions
[2010-07-20 13:38:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Firefox\Profiles\4l29m2nj.default\extensions
[2009-09-14 22:00:51 | 000,000,000 | ---D | M] (NoScript) -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Firefox\Profiles\4l29m2nj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009-09-06 17:29:46 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Firefox\Profiles\4l29m2nj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009-01-12 21:29:21 | 000,001,504 | ---- | M] () -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Firefox\Profiles\4l29m2nj.default\searchplugins\imdb.xml
[2009-01-12 21:36:10 | 000,000,887 | ---- | M] () -- C:\Documents and Settings\Jesica\Datos de programa\Mozilla\Firefox\Profiles\4l29m2nj.default\searchplugins\mininova.xml
[2010-07-20 13:38:30 | 000,000,000 | ---D | M] -- C:\Archivos de programa\Mozilla Firefox\extensions
[2010-06-27 21:29:03 | 000,000,000 | ---D | M] (Java Console) -- C:\Archivos de programa\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-06-27 21:28:50 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2008-11-10 22:33:25 | 000,000,687 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [STYLEXP] C:\Archivos de programa\TGTSoft\StyleXP\StyleXP.exe ()
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky...can_unicode.cab (Reg Error: Key error.)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewi...oOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zon...S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zon...wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1229647118765 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1229647086796 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 200.115.192.29 200.115.192.30 200.115.192.28
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Archivos de programa\Archivos comunes\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Jesica\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jesica\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-09-08 19:23:59 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1a3828e4-8234-11dd-95bf-0018e727858b}\Shell\AutoRun\command - "" = J:\svchost.exe -- File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\WINDOWS\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010-07-20 13:36:20 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jesica\Escritorio\OTL.exe
[2010-07-20 13:33:10 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010-07-20 13:33:10 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010-07-20 13:33:09 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Malwarebytes' Anti-Malware
[2010-07-20 13:20:11 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2010-07-18 17:09:43 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Personal Internet Movil
[2010-07-15 15:59:53 | 000,000,000 | -HSD | C] -- C:\found.009
[2010-07-05 16:16:57 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Jesica\Mis documentos\My Web Sites
[2010-07-05 15:49:34 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\L&H
[2010-07-05 15:49:22 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Microsoft Works
[2010-07-05 15:49:19 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Microsoft Visual Studio
[2010-07-05 15:49:19 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Microsoft ActiveSync
[2010-07-03 22:16:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesica\Escritorio\Nueva carpeta (3)
[2010-06-27 21:29:19 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Java
[2010-06-27 21:29:03 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010-06-27 21:29:03 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010-06-27 21:29:03 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010-06-27 21:29:03 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010-06-27 21:29:03 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010-06-27 17:52:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesica\Escritorio\emblemas
[2010-06-23 01:32:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesica\Datos de programa\Mumble
[2010-06-23 01:32:09 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Mumble
[2010-06-22 18:29:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jesica\Mis documentos\My Received Files
[2010-06-20 20:51:44 | 000,720,896 | ---- | C] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002ev.exe
[2010-06-20 20:51:44 | 000,000,000 | ---D | C] -- C:\Archivos de programa\TegNet1.3.5
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Jesica\*.tmp files -> C:\Documents and Settings\Jesica\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010-07-20 13:36:26 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jesica\Escritorio\OTL.exe
[2010-07-20 13:34:20 | 010,223,616 | ---- | M] () -- C:\Documents and Settings\Jesica\ntuser.dat
[2010-07-20 13:23:19 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{08F50F74-2844-4602-B4B5-E00A36606543}.job
[2010-07-20 13:22:20 | 000,081,531 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010-07-20 13:21:54 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010-07-20 13:21:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010-07-20 13:21:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010-07-20 13:06:00 | 004,238,448 | -H-- | M] () -- C:\Documents and Settings\Jesica\Configuración local\Datos de programa\IconCache.db
[2010-07-20 02:13:31 | 000,000,126 | ---- | M] () -- C:\Documents and Settings\Jesica\default.pls
[2010-07-18 17:12:16 | 000,452,990 | ---- | M] () -- C:\WINDOWS\System32\perfh00A.dat
[2010-07-18 17:12:16 | 000,392,296 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010-07-18 17:12:16 | 000,076,352 | ---- | M] () -- C:\WINDOWS\System32\perfc00A.dat
[2010-07-18 17:12:16 | 000,058,596 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010-07-15 21:25:55 | 000,000,000 | RHS- | M] () -- C:\Documents and Settings\All Users\Documentos\khw
[2010-07-13 00:48:52 | 000,000,000 | RHS- | M] () -- C:\Documents and Settings\All Users\Documentos\khq
[2010-07-11 01:35:58 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010-07-10 21:27:22 | 000,000,000 | RHS- | M] () -- C:\Documents and Settings\All Users\Documentos\khx
[2010-07-10 20:52:56 | 000,023,040 | ---- | M] () -- C:\Documents and Settings\Jesica\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-07-08 19:27:40 | 000,000,192 | -HS- | M] () -- C:\Documents and Settings\Jesica\ntuser.ini
[2010-07-07 09:31:42 | 000,514,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-07-05 16:16:50 | 000,143,192 | ---- | M] () -- C:\Documents and Settings\Jesica\Configuración local\Datos de programa\GDIPFONTCACHEV1.DAT
[2010-07-05 15:50:13 | 000,000,379 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010-07-01 23:59:04 | 000,104,569 | ---- | M] () -- C:\Documents and Settings\Jesica\Escritorio\2do_parcial.rar
[2010-06-27 21:32:08 | 000,001,695 | ---- | M] () -- C:\Documents and Settings\Jesica\Escritorio\Update Checker.lnk
[2010-06-27 21:28:50 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2010-06-27 21:28:50 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010-06-27 21:28:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010-06-27 21:28:50 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010-06-27 21:28:50 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010-06-23 01:36:51 | 000,002,385 | ---- | M] () -- C:\Documents and Settings\Jesica\Mis documentos\MumbleAutomaticCertificateBackup.p12
[2010-06-23 01:32:21 | 000,000,703 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Mumble.lnk
[2010-06-22 17:27:13 | 000,000,934 | ---- | M] () -- C:\Documents and Settings\Jesica\Mis documentos\Mis carpetas para compartir.lnk
[2010-06-20 20:51:46 | 000,001,740 | ---- | M] () -- C:\Documents and Settings\Jesica\Escritorio\TegNet.lnk
[2010-06-20 20:51:25 | 000,720,896 | ---- | M] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002ev.exe
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Jesica\*.tmp files -> C:\Documents and Settings\Jesica\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010-07-20 13:34:07 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Jesica\Escritorio\gmer.exe
[2010-07-15 21:25:55 | 000,000,000 | RHS- | C] () -- C:\Documents and Settings\All Users\Documentos\khw
[2010-07-13 00:48:52 | 000,000,000 | RHS- | C] () -- C:\Documents and Settings\All Users\Documentos\khq
[2010-07-11 09:02:13 | 010,223,616 | ---- | C] () -- C:\Documents and Settings\Jesica\ntuser.dat
[2010-07-10 21:27:22 | 000,000,000 | RHS- | C] () -- C:\Documents and Settings\All Users\Documentos\khx
[2010-07-10 21:26:57 | 000,601,116 | ---- | C] () -- C:\Documents and Settings\All Users\Documentos\qndzrs.exe
[2010-07-01 23:59:03 | 000,104,569 | ---- | C] () -- C:\Documents and Settings\Jesica\Escritorio\2do_parcial.rar
[2010-06-23 01:36:51 | 000,002,385 | ---- | C] () -- C:\Documents and Settings\Jesica\Mis documentos\MumbleAutomaticCertificateBackup.p12
[2010-06-23 01:32:21 | 000,000,703 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Mumble.lnk
[2010-06-20 20:51:46 | 000,001,740 | ---- | C] () -- C:\Documents and Settings\Jesica\Escritorio\TegNet.lnk
[2010-05-27 16:44:17 | 000,000,172 | ---- | C] () -- C:\WINDOWS\7THLEVEL.INI
[2010-04-30 20:28:41 | 000,000,210 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010-04-22 22:12:21 | 000,000,024 | ---- | C] () -- C:\WINDOWS\sysdat.dll
[2010-03-18 20:48:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Mapper.INI
[2009-12-22 17:31:08 | 000,000,031 | ---- | C] () -- C:\WINDOWS\warhead.ini
[2009-11-21 05:06:59 | 001,216,512 | ---- | C] () -- C:\WINDOWS\System32\cfgmig32.dll
[2009-11-21 05:06:59 | 001,155,072 | ---- | C] () -- C:\WINDOWS\System32\winsflt.dll
[2009-11-20 17:21:05 | 000,000,176 | ---- | C] () -- C:\WINDOWS\ImageExplorer.INI
[2009-11-20 17:11:38 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WinPM.INI
[2009-11-20 16:33:29 | 003,870,720 | ---- | C] () -- C:\WINDOWS\System32\qt-mt323.dll
[2009-10-11 01:23:17 | 000,000,030 | ---- | C] () -- C:\WINDOWS\Monitor.INI
[2009-10-06 14:59:07 | 001,970,176 | ---- | C] () -- C:\WINDOWS\System32\d3dx9.dll
[2009-08-06 00:16:00 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2009-08-06 00:16:00 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2009-08-06 00:16:00 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2009-08-06 00:16:00 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2009-06-10 08:29:34 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009-06-10 08:29:34 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009-06-10 08:29:34 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009-06-10 08:29:32 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009-04-08 20:03:34 | 000,002,925 | ---- | C] () -- C:\WINDOWS\SubCreator.INI
[2009-03-04 18:28:24 | 000,014,211 | ---- | C] () -- C:\WINDOWS\twacker.ini
[2008-12-30 16:02:28 | 000,000,050 | ---- | C] () -- C:\WINDOWS\MegaManager.INI
[2008-12-28 17:22:48 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2008-12-28 17:22:46 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2008-12-09 23:08:21 | 000,000,230 | ---- | C] () -- C:\WINDOWS\EntPack.ini
[2008-11-23 16:14:29 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\AsIO.dll
[2008-11-23 16:14:29 | 000,012,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsIO.sys
[2008-11-23 16:14:26 | 000,012,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2008-11-23 16:14:26 | 000,010,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2008-10-10 21:39:14 | 000,002,245 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008-10-10 20:38:09 | 000,000,104 | ---- | C] () -- C:\WINDOWS\System32\ProxySettings.ini
[2008-10-10 20:38:08 | 000,000,124 | ---- | C] () -- C:\WINDOWS\System32\SDEarlyDelete.ini
[2008-09-09 03:14:37 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008-09-09 02:27:06 | 000,721,904 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008-09-09 01:06:49 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008-09-09 01:06:49 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008-09-09 01:06:49 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008-09-09 01:06:48 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008-09-09 01:06:48 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008-09-09 00:40:23 | 000,003,000 | R--- | C] () -- C:\WINDOWS\System32\SetupNT.sys
[2008-09-08 23:42:39 | 000,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008-09-08 19:30:10 | 000,014,731 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2008-09-08 19:29:51 | 000,014,693 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008-09-08 19:29:51 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2008-09-08 19:29:43 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2006-10-30 19:35:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006-10-30 19:35:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2001-09-18 11:00:00 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\bmpproc.dll
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008-09-08 19:23:59 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2008-10-10 21:57:01 | 000,000,223 | ---- | M] () -- C:\Boot.bak
[2009-12-22 12:19:36 | 000,000,293 | RHS- | M] () -- C:\boot.ini
[2001-08-24 08:00:00 | 000,004,952 | RHS- | M] () -- C:\Bootfont.bin
[2004-08-03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2009-12-23 20:42:57 | 000,012,878 | ---- | M] () -- C:\ComboFix.txt
[2008-09-08 19:23:59 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008-09-08 19:23:59 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010-07-20 13:34:41 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2008-09-08 19:23:59 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004-08-03 17:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2004-08-03 17:59:42 | 000,250,640 | RHS- | M] () -- C:\ntldr
[2010-07-20 13:21:26 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2008-09-08 19:38:02 | 000,000,582 | ---- | M] () -- C:\RHDSetup.log
[2009-03-20 22:46:27 | 000,002,993 | ---- | M] () -- C:\Rooter.txt
[2009-03-28 19:15:04 | 000,001,572 | ---- | M] () -- C:\TCleaner.txt
[2009-12-22 18:36:10 | 000,000,045 | ---- | M] () -- C:\TEST.XML
< %systemroot%\system32\*.wt >
< %systemroot%\system32\*.ruy >
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008-09-08 19:23:31 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003-06-19 01:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2008-11-05 22:03:26 | 000,001,506 | -H-- | M] () -- C:\Documents and Settings\Jesica\Datos de programa\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2009-08-11 00:48:26 | 000,000,728 | ---- | M] () -- C:\Archivos de programa\injsf.txt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008-09-08 16:11:04 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008-09-08 16:11:04 | 000,667,648 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008-09-08 16:11:04 | 000,471,040 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\user32.dll /md5 >
[2007-03-08 12:36:30 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=FED9881C07A301271F52B51389A028C9 -- C:\WINDOWS\system32\user32.dll
< %systemroot%\system32\ws2_32.dll /md5 >
[2004-08-19 10:42:32 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=B4A90738BA4355F187BD26D6C112082B -- C:\WINDOWS\system32\ws2_32.dll
< %systemroot%\system32\ws2help.dll /md5 >
[2004-08-19 10:42:32 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=0EDF3501370A14BEFB27526CD06FACEE -- C:\WINDOWS\system32\ws2help.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-05-29 00:22:50
========== Alternate Data Streams ==========
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Datos de programa\TEMP:D1E22E44
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Datos de programa\TEMP:931BB48A
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Datos de programa\TEMP:CB0AACC9
< End of report >