Many thanks for the response. Here are the files you requested:
(1)aswMBR.txt
aswMBR version 0.9.7.753 Copyright© 2011 AVAST Software
Run date: 2011-07-16 21:35:23
-----------------------------
21:35:23.328 OS Version: Windows 5.1.2600 Service Pack 3
21:35:23.328 Number of processors: 2 586 0x1C02
21:35:23.359 ComputerName: ACER-074AC68100 UserName: User
21:35:25.078 Initialize success
21:38:25.890 AVAST engine defs: 11071601
21:38:36.484 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
21:38:36.500 Disk 0 Vendor: WDC_WD16 11.0 Size: 152627MB BusType: 3
21:38:36.515 Disk 0 MBR read successfully
21:38:36.531 Disk 0 MBR scan
21:38:37.062 Disk 0 MBR:Alureon-I [Rtk]
21:38:37.078 Disk 0 TDL4@MBR code has been found
21:38:37.078 Disk 0 MBR hidden
21:38:37.093 Disk 0 MBR [TDL4] **ROOTKIT**
21:38:37.093 Disk 0 trace - called modules:
21:38:37.109 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8733de7a]<<
21:38:37.109 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8737a030]
21:38:37.125 3 CLASSPNP.SYS[f783dfd7] -> nt!IofCallDriver -> \Device\0000006a[0x8731b910]
21:38:37.125 5 ACPI.sys[f77b3620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8737b030]
21:38:37.171 \Driver\iaStor[0x8737eb90] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8733de7a
21:38:38.296 AVAST engine scan C:\WINDOWS
22:07:57.015 AVAST engine scan C:\Documents and Settings\User
22:30:58.250 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Escritorio\MBR.dat"
22:30:58.265 The log file has been saved successfully to "C:\Documents and Settings\User\Escritorio\aswMBR.txt"
aswMBR version 0.9.7.753 Copyright© 2011 AVAST Software
Run date: 2011-07-16 22:35:29
-----------------------------
22:35:29.546 OS Version: Windows 5.1.2600 Service Pack 3
22:35:29.546 Number of processors: 2 586 0x1C02
22:35:29.546 ComputerName: ACER-074AC68100 UserName: User
22:35:30.343 Initialize success
22:35:39.953 AVAST engine defs: 11071601
22:35:43.250 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
22:35:43.250 Disk 0 Vendor: WDC_WD16 11.0 Size: 152627MB BusType: 3
22:35:43.328 Disk 0 MBR read successfully
22:35:43.328 Disk 0 MBR scan
22:35:43.625 Disk 0 MBR:Alureon-I [Rtk]
22:35:43.640 Disk 0 TDL4@MBR code has been found
22:35:43.640 Disk 0 MBR hidden
22:35:43.656 Disk 0 MBR [TDL4] **ROOTKIT**
22:35:43.656 Disk 0 trace - called modules:
22:35:43.671 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8733de7a]<<
22:35:43.671 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8737a030]
22:35:43.687 3 CLASSPNP.SYS[f783dfd7] -> nt!IofCallDriver -> \Device\0000006a[0x8731b910]
22:35:43.687 5 ACPI.sys[f77b3620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8737b030]
22:35:43.703 \Driver\iaStor[0x8737eb90] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8733de7a
22:35:44.468 AVAST engine scan C:\WINDOWS
23:05:01.578 AVAST engine scan C:\Documents and Settings\User
23:47:54.890 AVAST engine scan C:\Documents and Settings\All Users
23:48:11.750 Scan finished successfully
23:49:41.953 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Escritorio\MBR.dat"
23:49:42.015 The log file has been saved successfully to "C:\Documents and Settings\User\Escritorio\aswMBR.txt"
(2)OTL.txt
OTL logfile created on: 17/07/2011 00:19:10 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\User\Escritorio
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: Reino Unido | Language: ENG | Date Format: dd/MM/yyyy
1013.88 Mb Total Physical Memory | 426.76 Mb Available Physical Memory | 42.09% Memory free
2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.71% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 142.05 Gb Total Space | 35.17 Gb Free Space | 24.76% Space Free | Partition Type: NTFS
Computer Name: ACER-074AC68100 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/07/16 23:50:23 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Escritorio\OTL.scr
PRC - [2011/07/14 01:39:13 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Archivos de programa\Mozilla Firefox\firefox.exe
PRC - [2011/03/28 16:15:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 16:15:29 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/02/02 02:55:06 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Archivos de programa\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 02:55:04 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Archivos de programa\OpenOffice.org 3\program\soffice.exe
PRC - [2009/02/11 15:46:28 | 000,565,248 | ---- | M] (Acer Incorporated) -- C:\Archivos de programa\Acer\Acer VCM\AcerVCM.exe
PRC - [2009/02/05 08:14:56 | 000,237,568 | ---- | M] (Acer Incorporated) -- C:\Archivos de programa\Acer\Acer VCM\RS_Service.exe
PRC - [2008/12/30 08:09:54 | 000,875,016 | ---- | M] (Dritek System Inc.) -- C:\Archivos de programa\Launch Manager\LManager.exe
PRC - [2008/07/03 14:58:22 | 000,094,208 | ---- | M] (sonix) -- C:\WINDOWS\PLFSetL.exe
PRC - [2008/04/15 17:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Archivos de programa\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 17:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Archivos de programa\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 13:00:00 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 13:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dwwin.exe
========== Modules (SafeList) ========== MOD - [2011/07/16 23:50:23 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Escritorio\OTL.scr
MOD - [2010/08/23 17:12:00 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/07/14 01:39:13 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2009/02/05 08:14:56 | 000,237,568 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Archivos de programa\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2008/11/04 05:06:28 | 000,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/04/15 17:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Archivos de programa\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2007/11/06 21:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Archivos de programa\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ========== DRV - [2011/07/14 01:39:14 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/07/14 01:39:14 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 15:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Archivos de programa\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009/05/06 17:15:38 | 001,759,744 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2009/03/02 06:03:46 | 000,038,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
DRV - [2009/02/25 19:17:52 | 001,344,224 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\athw.sys -- (AR5416)
DRV - [2009/02/24 09:49:44 | 005,032,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/02/03 07:42:30 | 000,162,816 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2008/08/05 13:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/14 13:00:00 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/11/06 21:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2006/11/02 14:27:36 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Archivos de programa\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2006/01/04 08:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer...09&m=aspire_oneIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer...09&m=aspire_one IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer...09&m=aspire_oneIE - HKU\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://google.co.uk/IE - HKU\S-1-5-21-572454927-955046455-3802400216-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Archivos de programa\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Archivos de programa\Real\RealPlayer\Netscape6\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Archivos de programa\Real\RealPlayer\Netscape6\nprjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Archivos de programa\Real\RealPlayer\Netscape6\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Archivos de programa\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2011/06/24 22:27:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\FireFox\Extensions\\
[email protected]: C:\Archivos de programa\SaveTubeVideo.com\SaveTubeVideo\FF
[2011/06/09 23:27:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Datos de programa\Mozilla\Extensions
[2011/06/08 13:57:00 | 000,000,000 | ---D | M] (No name found) -- C:\Archivos de programa\Mozilla Firefox\extensions
File not found (No name found) --
[2010/04/02 13:55:18 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\ARCHIVOS DE PROGRAMA\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/09/30 11:48:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/06/24 22:27:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,001,538 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 09:00:00 | 000,002,252 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml
[2010/01/01 09:00:00 | 000,000,947 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 09:00:00 | 000,001,180 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 09:00:00 | 000,001,135 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2008/04/14 13:00:00 | 000,000,792 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Archivos de programa\Archivos comunes\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Archivos de programa\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [AzMixerSel] C:\Archivos de programa\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Archivos de programa\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Archivos de programa\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.dll ( )
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKLM..\Run: [TkBellExe] File not found
O4 - Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\Acer VCM.lnk = C:\Archivos de programa\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\Adobe Gamma Loader.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Menú Inicio\Programas\Inicio\OpenOffice.org 3.2.lnk = C:\Archivos de programa\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_18)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Archivos de programa\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\User\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O32 - Unable to read "AutoRun" value or value not present!
O32 - AutoRun File - [2009/03/12 12:49:35 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2011/07/16 23:50:21 | 000,579,584 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Escritorio\OTL.scr
[2011/07/16 22:34:14 | 001,906,176 | ---- | C] (AVAST Software) -- C:\Documents and Settings\User\Escritorio\aswMBR.exe
[2011/07/16 02:11:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Escritorio\Confessionals from medicine ... and Scrabble_files
[2011/07/15 01:01:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Escritorio\dualcitizen_files
[2011/07/15 00:53:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Escritorio\39449_files
[2011/07/14 16:09:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Escritorio\RECENT STUFF
[2011/07/12 00:33:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Escritorio\QUACKLED GAMES
[2011/07/12 00:30:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\Stuff off desktop
[2011/07/12 00:28:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\STUFF
[2011/07/12 00:26:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\Stuff off old memory stick
[2011/07/12 00:12:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\NEWER STUFF
[2011/07/11 23:50:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\APPLICATIONS
[2011/07/11 23:34:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\Lake District stuff
[2011/07/11 23:33:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\User\Escritorio\SCRABBLE
[2011/07/11 23:15:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\sbmiso
[2011/07/11 22:13:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\Susana Spears video
[2011/07/11 22:12:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Mis documentos\My documents
[2011/06/19 02:08:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Configuración local\Datos de programa\PCHealth
[2011/06/18 15:47:00 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/18 15:46:30 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011/06/18 15:36:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\TEMP
[2011/06/18 15:36:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\SpywareBlaster
[2011/06/18 15:36:43 | 000,000,000 | ---D | C] -- C:\Archivos de programa\SpywareBlaster
[2011/06/17 21:07:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Zyzzyva 2.1.4
[2009/07/05 19:37:06 | 000,196,608 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2uvc.dll
[2009/07/05 19:37:03 | 000,225,280 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2uvc.dll
[2009/03/12 05:34:20 | 000,049,152 | ---- | C] ( ) -- C:\WINDOWS\Interop.IWshRuntimeLibrary.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Configuración local\Datos de programa\*.tmp files -> C:\Documents and Settings\User\Configuración local\Datos de programa\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/07/17 00:27:01 | 000,001,098 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/07/17 00:17:02 | 000,001,094 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/17 00:17:00 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-572454927-955046455-3802400216-1005.job
[2011/07/17 00:16:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/07/16 23:50:23 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Escritorio\OTL.scr
[2011/07/16 23:49:41 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\MBR.dat
[2011/07/16 22:35:02 | 001,906,176 | ---- | M] (AVAST Software) -- C:\Documents and Settings\User\Escritorio\aswMBR.exe
[2011/07/16 19:32:50 | 000,000,015 | ---- | M] () -- C:\WINDOWS\System32\package.lst
[2011/07/16 18:29:30 | 000,000,937 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\d to 500.lxp
[2011/07/16 13:47:45 | 000,006,242 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\current bonus.lxp
[2011/07/16 03:25:16 | 000,061,440 | ---- | M] () -- C:\Documents and Settings\User\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/16 02:12:00 | 000,094,051 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\Confessionals from medicine ... and Scrabble.htm
[2011/07/15 01:01:16 | 000,106,442 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\dualcitizen.html
[2011/07/15 00:53:30 | 000,146,607 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\39449.htm
[2011/07/14 16:24:39 | 000,000,765 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\zyzzyva.lnk
[2011/07/14 03:18:41 | 000,000,851 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\anaHack2025.lnk
[2011/07/14 01:39:14 | 000,138,192 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/07/14 01:39:14 | 000,066,616 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/07/13 22:04:00 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-572454927-955046455-3802400216-1005.job
[2011/07/13 19:07:23 | 000,279,744 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/13 18:52:15 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/07/13 17:33:32 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\User\Escritorio\Quackle.lnk
[2011/07/10 18:02:59 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/06/20 22:36:10 | 000,499,736 | ---- | M] () -- C:\WINDOWS\System32\perfh00A.dat
[2011/06/20 22:36:10 | 000,436,044 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/06/20 22:36:10 | 000,088,282 | ---- | M] () -- C:\WINDOWS\System32\perfc00A.dat
[2011/06/20 22:36:10 | 000,069,754 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\User\Configuración local\Datos de programa\*.tmp files -> C:\Documents and Settings\User\Configuración local\Datos de programa\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/07/16 23:49:41 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\MBR.dat
[2011/07/16 13:48:54 | 000,000,937 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\d to 500.lxp
[2011/07/16 02:11:57 | 000,094,051 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\Confessionals from medicine ... and Scrabble.htm
[2011/07/15 01:01:15 | 000,106,442 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\dualcitizen.html
[2011/07/15 00:53:20 | 000,146,607 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\39449.htm
[2011/07/14 16:24:13 | 000,000,765 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\zyzzyva.lnk
[2011/07/14 03:18:24 | 000,000,851 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\anaHack2025.lnk
[2011/07/13 17:32:45 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\Quackle.lnk
[2011/07/13 01:19:24 | 000,006,242 | ---- | C] () -- C:\Documents and Settings\User\Escritorio\current bonus.lxp
[2011/06/08 13:57:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2011/06/03 23:47:44 | 000,000,152 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\~16703268r
[2011/06/03 23:47:44 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\~16703268
[2011/06/03 23:47:36 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\16703268
[2010/06/12 04:48:44 | 000,070,009 | ---- | C] () -- C:\Documents and Settings\User\Datos de programa\QD info.ini
[2010/04/12 01:13:22 | 000,018,432 | ---- | C] () -- C:\WINDOWS\ss3unstl.exe
[2010/03/27 00:24:49 | 000,000,007 | ---- | C] () -- C:\WINDOWS\treeskp.sys
[2010/03/11 05:29:18 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/11/23 04:26:45 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\ztvunacev2.dll
[2009/11/23 04:26:44 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\7-zip32.dll
[2009/11/23 04:26:44 | 000,156,160 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar3.dll
[2009/10/01 02:43:59 | 000,061,440 | ---- | C] () -- C:\Documents and Settings\User\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/30 04:08:31 | 000,000,007 | ---- | C] () -- C:\WINDOWS\sbacknt.bin
[2009/09/29 06:02:29 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2009/07/05 19:37:06 | 001,759,744 | ---- | C] () -- C:\WINDOWS\System32\drivers\snp2uvc.sys
[2009/07/05 19:37:06 | 000,028,544 | ---- | C] () -- C:\WINDOWS\System32\drivers\sncduvc.sys
[2009/07/05 19:37:06 | 000,000,323 | ---- | C] () -- C:\WINDOWS\PidList.ini
[2009/03/12 14:31:01 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/03/12 13:40:21 | 000,090,772 | ---- | C] () -- C:\WINDOWS\System32\drivers\RtConvEQ.DAT
[2009/03/12 13:40:21 | 000,000,536 | ---- | C] () -- C:\WINDOWS\System32\drivers\RtHdatEx.dat
[2009/03/12 13:40:21 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTEQEX2.dat
[2009/03/12 13:40:21 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTEQEX1.dat
[2009/03/12 13:40:21 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTEQEX0.dat
[2009/03/12 13:40:21 | 000,000,164 | ---- | C] () -- C:\WINDOWS\System32\drivers\SamSfPa.dat
[2009/03/12 13:40:21 | 000,000,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\rtkhdaud.dat
[2009/03/12 13:39:25 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/03/12 12:52:30 | 000,032,768 | ---- | C] () -- C:\WINDOWS\AMove.exe
[2009/03/12 12:52:30 | 000,006,782 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2009/03/12 12:51:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/03/12 12:47:46 | 000,021,900 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/03/12 12:47:00 | 000,003,656 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2009/03/12 12:44:52 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/03/12 12:44:10 | 000,279,744 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/12 05:34:20 | 000,020,480 | ---- | C] () -- C:\WINDOWS\LauncheRyDiscCalc.exe
[2009/03/12 05:34:12 | 000,499,736 | ---- | C] () -- C:\WINDOWS\System32\perfh00A.dat
[2009/03/12 05:34:12 | 000,317,534 | ---- | C] () -- C:\WINDOWS\System32\perfi00A.dat
[2009/03/12 05:34:12 | 000,088,282 | ---- | C] () -- C:\WINDOWS\System32\perfc00A.dat
[2009/03/12 05:34:12 | 000,036,284 | ---- | C] () -- C:\WINDOWS\System32\perfd00A.dat
[2009/03/12 05:34:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2009/03/12 05:33:58 | 000,436,044 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/12 05:33:58 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2009/03/12 05:33:58 | 000,069,754 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/12 05:33:58 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2009/03/12 05:33:57 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2009/03/12 05:33:57 | 000,004,524 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2009/03/12 05:33:56 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2009/03/12 05:33:53 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2009/03/12 05:33:53 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2009/03/12 05:33:47 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2009/03/12 05:33:45 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/11/06 21:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
========== LOP Check ========== [2009/03/12 14:16:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Datos de programa\Acer
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Datos de programa\Acer GameZone Console
[2009/03/12 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Datos de programa\Super-Cow
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Acer GameZone Console
[2009/03/12 14:15:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\eSobi
[2011/06/08 17:08:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Hitman Pro
[2011/06/18 15:36:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\TEMP
[2011/06/09 23:27:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Transparent
[2011/06/09 23:35:18 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\{7D4B3D1D-104E-4507-9123-568BC721B7E2}
[2009/03/12 14:16:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Datos de programa\Acer
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Datos de programa\Acer GameZone Console
[2009/03/12 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Datos de programa\Super-Cow
[2009/03/12 14:16:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Invitado\Datos de programa\Acer
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Invitado\Datos de programa\Acer GameZone Console
[2010/03/11 12:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Invitado\Datos de programa\Search Settings
[2009/03/12 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Invitado\Datos de programa\Super-Cow
[2010/03/11 12:48:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Invitado\Datos de programa\YouTube Downloader
[2009/03/12 14:16:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Limited\Datos de programa\Acer
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Limited\Datos de programa\Acer GameZone Console
[2009/03/12 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Limited\Datos de programa\Super-Cow
[2009/09/29 06:47:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Datos de programa\SACore
[2009/10/02 22:01:01 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\User\Datos de programa\.#
[2009/03/12 14:16:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\Acer
[2009/07/05 19:38:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\Acer GameZone Console
[2011/03/14 19:46:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\Azureus
[2009/10/05 04:38:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\eSobi
[2010/05/21 01:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\OpenOffice.org
[2009/03/12 14:12:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\Super-Cow
[2009/09/30 04:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Datos de programa\vghd
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2008/04/14 13:00:00 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\explorer.exe
[2008/04/14 13:00:00 | 001,036,288 | ---- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF -- C:\WINDOWS\system32\dllcache\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX10\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX11\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX12\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX13\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX14\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX15\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX16\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX17\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX18\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX19\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX2\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX20\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX21\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX22\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX23\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX24\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX25\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX26\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX27\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX28\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX29\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX3\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX30\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX31\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX32\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX33\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX34\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX35\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX36\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX37\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX38\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX39\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX4\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX40\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX41\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX42\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX43\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX44\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX45\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX46\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX47\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX5\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX6\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX7\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX8\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | ---- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX9\h\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/04/14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=4F2340F0BD5B6365C38E74DD391919A8 -- C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=4F2340F0BD5B6365C38E74DD391919A8 -- C:\WINDOWS\system32\svchost.exe
< MD5 for: USERINIT.EXE >[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX10\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX11\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX12\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX13\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX14\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX15\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX16\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX17\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX18\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX19\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX2\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX20\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX21\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX22\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX23\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX24\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX25\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX26\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX27\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX28\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX29\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX3\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX30\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX31\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX32\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX33\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX34\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX35\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX36\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX37\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX38\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX39\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX4\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX40\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX41\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX42\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX43\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX44\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX45\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX5\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX6\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX7\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX8\userinit.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX9\userinit.exe
[2008/04/14 13:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 13:00:00 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=F5B8745B9A90EAF17E30C0574E049AA3 -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >[2008/04/14 13:00:00 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 13:00:00 | 000,510,976 | ---- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C -- C:\WINDOWS\system32\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX10\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX11\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX12\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX13\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX14\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX15\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX16\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX17\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX18\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX19\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX2\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX20\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX21\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX22\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX23\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX24\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX25\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX26\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX27\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX28\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX29\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX3\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX30\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX31\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX32\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX33\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX34\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX35\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX36\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX37\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX38\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX39\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX4\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX40\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX41\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX42\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX43\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX44\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX45\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX5\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX6\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX7\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX8\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | ---- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F -- C:\Documents and Settings\User\Configuración local\Temp\RarSFX9\winlogon.exe
< %systemroot%\*. /mp /s > < hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Archivos de programa\Mozilla Firefox\firefox.exe [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -preferences [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Archivos de programa\Internet Explorer\iexplore.exe [2011/04/21 11:58:25 | 000,634,648 | ---- | M] (Microsoft Corporation)
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011/06/24 22:26:58 | 000,712,976 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Archivos de programa\Mozilla Firefox\firefox.exe [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -preferences [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Archivos de programa\Mozilla Firefox\firefox.exe" -safe-mode [2011/06/24 22:27:01 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\system32\ie4uinit.exe" -reinstall [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -hide [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\system32\ie4uinit.exe" -show [2011/04/25 13:00:32 | 000,070,656 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Archivos de programa\Internet Explorer\iexplore.exe [2011/04/21 11:58:25 | 000,634,648 | ---- | M] (Microsoft Corporation)
< End of report >
(3)Extras.txt
OTL Extras logfile created on: 17/07/2011 00:19:10 - Run 1
OTL by OldTimer - Version 3.2.26.1 Folder = C:\Documents and Settings\User\Escritorio
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: Reino Unido | Language: ENG | Date Format: dd/MM/yyyy
1013.88 Mb Total Physical Memory | 426.76 Mb Available Physical Memory | 42.09% Memory free
2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.71% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 142.05 Gb Total Space | 35.17 Gb Free Space | 24.76% Space Free | Partition Type: NTFS
Computer Name: ACER-074AC68100 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_USERS\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Archivos de programa\Acer\Acer VCM\VC.exe" = C:\Archivos de programa\Acer\Acer VCM\VC.exe:*:Disabled:Acer Video Quality Enhancement -- (Acer Incoporated)
"C:\Archivos de programa\Google\Google Earth\plugin\geplugin.exe" = C:\Archivos de programa\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth
"C:\Archivos de programa\Vuze\Azureus.exe" = C:\Archivos de programa\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java 6 Update 20
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C9C0A-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38BB21D5-B0D1-41DA-A0B0-1EFB5EF4AAC2}" = Microsoft Works
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = WebCam
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51F026FA-5146-4232-A8BA-1364740BD053}" = Acer Crystal Eye webcam
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{7148F0A8-6813-11D6-A77B-00B0D0142180}" = Java 2 Runtime Environment, SE v1.4.2_18
"{71C2828F-2678-4675-BDEC-895424861262}_is1" = C:\Archivos de programa\Acer GameZone\GameConsole
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11109097}" = Luxor - Amun Rising
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111940693}" = Bookworm Adventures
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11198580}" = Fizzball
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113297350}" = Cake Mania 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113644907}" = Gold Miner Vegas
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113938743}" = Supercow
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115329757}" = Jewelleria
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{90120000-0010-0C0A-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Spanish) 12
"{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
"{90120000-0016-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
"{90120000-0018-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
"{90120000-001B-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_HOMESTUDENTR_{4B47C31E-46B0-462B-BEE4-DC383B6A1F2A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_HOMESTUDENTR_{75EBE365-7FC5-4720-A7D3-804BF550D1BC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0C0A-0000-0000000FF1CE}" = Paquete de compatibilidad para 2007 Office system
"{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{6113C11D-BACA-4D8E-8002-03C8D06FD5E6}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2007
"{90120000-00A1-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (Spanish)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = USB2.0 Card Reader Software
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D2B0720-4787-437E-A949-97D01BF64BAE}_is1" = C:\Archivos de programa\Acer GameZone\GameConsole
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A62892A7-9D90-4A58-8FFF-78FC5A2BC3C5}" = OpenOffice.org 3.2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1034-7B44-A94000000001}" = Adobe Reader 9.4.5 - Español
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD9E03B5-AEEA-4D59-B512-6CE4AA0281D4}" = Byki
"Acer Screensaver" = Acer ScreenSaver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Byki Express" = Byki Express
"CDisplay_is1" = CDisplay 1.8
"Google Desktop" = Google Desktop
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"Internet Scrabble Club_is1" = WordBiz version 1.8
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.7.5 (Basic)
"LeXpert 3.2" = LeXpert 3.2
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 5.0 (x86 en-GB)" = Mozilla Firefox 5.0 (x86 en-GB)
"MP4 Player_is1" = MP4 Player 3.5
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Quackle_is1" = Quackle 0.96 [Beta]
"RAR File Open Knife - Free Opener" = RAR File Open Knife - Free Opener
"RealPlayer 12.0" = RealPlayer
"SpywareBlaster_is1" = SpywareBlaster 4.4
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"vghd" = VirtuaGirl
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Reproductor de Windows Media 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Zyzzyva 2.0.5" = Zyzzyva
"Zyzzyva 2.1.4" = Zyzzyva
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-572454927-955046455-3802400216-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 16/07/2011 19:06:43 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:18 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:23 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:26 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:45 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:55 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:57 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: drwtsn32.exe, versión: 5.1.2600.0, módulo
con error: dbghelp.dll, versión 5.1.2600.5512, dirección de error 0x0001295d.
Error - 16/07/2011 19:07:59 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:17:01 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: explorer.exe, versión: 6.0.2900.5512, módulo
con error: unknown, versión 0.0.0.0, dirección de error 0x00d62ca7.
Error - 16/07/2011 19:19:49 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: svchost.exe, versión: 5.1.2600.5512, módulo
con error: unknown, versión 0.0.0.0, dirección de error 0x007f1b14.
[ Application Events ]
Error - 16/07/2011 19:06:43 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:18 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:23 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:26 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:45 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:55 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:07:57 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: drwtsn32.exe, versión: 5.1.2600.0, módulo
con error: dbghelp.dll, versión 5.1.2600.5512, dirección de error 0x0001295d.
Error - 16/07/2011 19:07:59 | Computer Name = ACER-074AC68100 | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.scr, versión 3.2.26.1, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.
Error - 16/07/2011 19:17:01 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: explorer.exe, versión: 6.0.2900.5512, módulo
con error: unknown, versión 0.0.0.0, dirección de error 0x00d62ca7.
Error - 16/07/2011 19:19:49 | Computer Name = ACER-074AC68100 | Source = Application Error | ID = 1000
Description = Aplicación con errores: svchost.exe, versión: 5.1.2600.5512, módulo
con error: unknown, versión 0.0.0.0, dirección de error 0x007f1b14.
[ System Events ]
Error - 15/07/2011 22:17:17 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7034
Description = El servicio Servicios de Terminal Server se terminó de manera inesperada.
Esto ha sucedido 1 veces.
Error - 16/07/2011 07:53:26 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7031
Description = El servicio Iniciador de procesos de servidor DCOM terminó inesperadamente.
Lo ha hecho 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos:
Reiniciar el servicio.
Error - 16/07/2011 07:53:26 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7034
Description = El servicio Servicios de Terminal Server se terminó de manera inesperada.
Esto ha sucedido 1 veces.
Error - 16/07/2011 13:27:19 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7031
Description = El servicio Iniciador de procesos de servidor DCOM terminó inesperadamente.
Lo ha hecho 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos:
Reiniciar el servicio.
Error - 16/07/2011 13:27:19 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7034
Description = El servicio Servicios de Terminal Server se terminó de manera inesperada.
Esto ha sucedido 1 veces.
Error - 16/07/2011 14:27:57 | Computer Name = ACER-074AC68100 | Source = System Error | ID = 1003
Description = Código de error 1000007e, parámetro 1 c0000005, parámetro 2 8736a669,
parámetro 3 f7cb0cbc, parámetro 4 f7cb09b8.
Error - 16/07/2011 14:30:25 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7031
Description = El servicio Iniciador de procesos de servidor DCOM terminó inesperadamente.
Lo ha hecho 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos:
Reiniciar el servicio.
Error - 16/07/2011 14:30:25 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7034
Description = El servicio Servicios de Terminal Server se terminó de manera inesperada.
Esto ha sucedido 1 veces.
Error - 16/07/2011 19:24:52 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7031
Description = El servicio Iniciador de procesos de servidor DCOM terminó inesperadamente.
Lo ha hecho 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos:
Reiniciar el servicio.
Error - 16/07/2011 19:24:52 | Computer Name = ACER-074AC68100 | Source = Service Control Manager | ID = 7034
Description = El servicio Servicios de Terminal Server se terminó de manera inesperada.
Esto ha sucedido 1 veces.
< End of report >
I am sorry that my initial description was not quite accurate with the names of error messages etc. due to working from memory. I am doing my best to be systematic now.