Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Google redirected geekstogo to 95p.com [Closed]


  • This topic is locked This topic is locked

#1
u200002

u200002

    New Member

  • Member
  • Pip
  • 1 posts
Hello, I'm a new member here.
Some days ago my PC goes slow, and when I use Google some pages like geekstogo are redirected to 95p.com
Also begin to appear twice a window "Missing Virus Definitions: VPTRAY.exe No se encuentra el Ordinal 1109 en la biblioteca de vinculos dinámicos WSOCK32.dll"

I unintall the Symantec Antivirus, and try to install again but appear the error 1920, and can't install it.

Regards and happy new year.
Chema

This is the OTL output:

OTL logfile created on: 04/01/2012 19:38:18 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = H:\Virus
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040A | Country: España | Language: ESP | Date Format: dd/MM/yyyy

1,49 Gb Total Physical Memory | 0,43 Gb Available Physical Memory | 28,89% Memory free
2,08 Gb Paging File | 1,13 Gb Available in Paging File | 54,50% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 69,77 Gb Total Space | 31,91 Gb Free Space | 45,73% Space Free | Partition Type: NTFS
Drive H: | 14,89 Gb Total Space | 7,03 Gb Free Space | 47,22% Space Free | Partition Type: FAT32

Computer Name: CHEMA | User Name: Chema Alvarez | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/04 19:36:18 | 000,584,192 | ---- | M] (OldTimer Tools) -- H:\Virus\OTL.exe
PRC - [2012/01/02 08:15:57 | 000,483,328 | ---- | M] (Intel Corporation) -- C:\Archivos de programa\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2012/01/01 20:55:28 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/01/01 20:04:37 | 000,028,672 | ---- | M] (IBM Corporation) -- C:\WINDOWS\system32\drivers\ldlcserv.exe
PRC - [2011/12/29 22:37:18 | 000,167,936 | ---- | M] (Lenovo ) -- C:\Archivos de programa\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
PRC - [2011/12/29 22:37:17 | 000,015,360 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPApp.exe
PRC - [2011/12/29 22:37:15 | 000,057,344 | ---- | M] (Lenovo) -- C:\WINDOWS\system32\PMSveH.exe
PRC - [2011/12/29 22:22:17 | 000,230,760 | ---- | M] (Lenovo ) -- C:\Archivos de programa\ThinkPad\ConnectUtilities\AcSvc.exe
PRC - [2011/12/29 22:07:55 | 000,134,144 | ---- | M] (Nokia) -- C:\Archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe
PRC - [2011/12/29 22:07:52 | 000,659,456 | ---- | M] (Nokia) -- C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe
PRC - [2011/12/29 22:07:48 | 001,126,400 | ---- | M] (Lenovo Group Limited) -- C:\Archivos de programa\Archivos comunes\Lenovo\Scheduler\tvtsched.exe
PRC - [2011/12/29 22:07:46 | 001,384,448 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
PRC - [2011/12/29 22:07:43 | 000,644,408 | ---- | M] (Lenovo Group Limited) -- C:\Archivos de programa\Archivos comunes\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2011/12/29 22:07:43 | 000,092,592 | ---- | M] (TomTom) -- C:\Archivos de programa\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011/12/29 22:07:41 | 000,195,584 | ---- | M] (Telefónica I+D) -- C:\Archivos de programa\movistar\Escritorio movistar Latam\ImpWiFiSvc.exe
PRC - [2011/12/29 22:07:38 | 000,935,208 | ---- | M] (Nero AG) -- C:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
PRC - [2011/12/29 22:07:38 | 000,036,864 | ---- | M] (Softex Inc.) -- C:\Program Files\Softex\OmniPass\OmniServ.exe
PRC - [2011/12/29 22:07:35 | 000,200,704 | ---- | M] (OptionNV) -- C:\Archivos de programa\Option\GlobeTrotter Connect\GtDetectSc.exe
PRC - [2011/12/29 22:07:34 | 000,532,480 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcxcoms.exe
PRC - [2011/12/29 22:07:34 | 000,054,560 | ---- | M] (Lenovo.) -- C:\Archivos de programa\Lenovo\HOTKEY\FnF5svc.exe
PRC - [2011/12/29 22:07:31 | 001,520,688 | ---- | M] (Cisco Systems, Inc.) -- C:\Archivos de programa\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2011/12/29 22:07:28 | 000,270,336 | ---- | M] (Broadcom Corporation.) -- C:\Archivos de programa\Lenovo\Bluetooth Software\bin\btwdins.exe
PRC - [2011/12/29 22:07:25 | 000,103,784 | ---- | M] (Lenovo ) -- C:\Archivos de programa\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
PRC - [2011/12/29 22:07:25 | 000,040,960 | ---- | M] (IBM Corporation) -- C:\Archivos de programa\IBM\Personal Communications\PCS_AGNT.EXE
PRC - [2011/12/29 22:07:24 | 000,028,672 | ---- | M] (IBM Corporation) -- C:\WINDOWS\system32\drivers\trcboot.exe
PRC - [2011/12/29 22:07:23 | 000,611,664 | ---- | M] (Lavasoft) -- C:\Archivos de programa\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/11/26 11:46:42 | 000,399,512 | ---- | M] (Mozilla Messaging) -- C:\Archivos de programa\Mozilla Thunderbird\thunderbird.exe
PRC - [2011/11/12 18:18:53 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Archivos de programa\Mozilla Firefox\firefox.exe
PRC - [2011/07/04 14:29:24 | 000,025,472 | ---- | M] (Uniblue Systems Limited) -- C:\Archivos de programa\Uniblue\RegistryBooster\rbmonitor.exe
PRC - [2009/12/10 22:34:16 | 000,181,608 | ---- | M] (Lenovo ) -- C:\Archivos de programa\ThinkPad\ConnectUtilities\ACWLIcon.exe
PRC - [2009/12/10 22:34:14 | 000,431,464 | ---- | M] (Lenovo ) -- C:\Archivos de programa\ThinkPad\ConnectUtilities\ACTray.exe
PRC - [2009/11/11 10:57:36 | 001,451,520 | ---- | M] (Nokia) -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe
PRC - [2009/10/29 13:03:34 | 000,159,744 | ---- | M] (Nokia) -- C:\Archivos de programa\PC Connectivity Solution\Transports\NclBCBTSrv.exe
PRC - [2009/10/27 09:14:22 | 000,128,000 | ---- | M] (Nokia) -- C:\Archivos de programa\PC Connectivity Solution\Transports\NclMSBTSrv.exe
PRC - [2009/07/01 23:12:46 | 000,623,960 | ---- | M] (Research In Motion Limited) -- C:\Archivos de programa\Archivos comunes\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/03/09 04:19:11 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Archivos de programa\Java\jre6\bin\java.exe
PRC - [2008/04/14 03:18:57 | 001,036,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 03:18:52 | 000,403,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2008/03/11 13:33:02 | 000,054,560 | ---- | M] (Lenovo Group Limited) -- C:\Archivos de programa\Lenovo\HOTKEY\TpWAudAp.exe
PRC - [2007/03/01 02:02:00 | 000,120,368 | ---- | M] (Lenovo Group Limited) -- C:\Archivos de programa\Lenovo\LenovoCare\LPMGR.EXE
PRC - [2006/05/20 08:28:32 | 000,024,576 | ---- | M] (Lenovo) -- C:\WINDOWS\system32\PMHandler.exe
PRC - [2006/02/27 23:20:44 | 002,076,672 | ---- | M] () -- C:\Program Files\Softex\OmniPass\scureapp.exe
PRC - [2005/12/21 17:08:06 | 001,988,144 | ---- | M] (Lenovo Group Limited) -- C:\Archivos de programa\IBM ThinkVantage\Client Security Solution\cssauthe.exe
PRC - [2004/10/08 02:10:22 | 000,009,728 | ---- | M] (IBM Corporation) -- C:\lotus\123\123w.exe


========== Modules (No Company Name) ==========

MOD - [2011/12/29 22:37:17 | 000,015,360 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPApp.exe
MOD - [2011/12/29 22:07:46 | 001,384,448 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
MOD - [2011/12/08 15:04:23 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/26 11:46:49 | 001,988,760 | ---- | M] () -- C:\Archivos de programa\Mozilla Thunderbird\mozjs.dll
MOD - [2011/11/26 11:46:49 | 000,161,944 | ---- | M] () -- C:\Archivos de programa\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2011/11/26 11:46:49 | 000,021,656 | ---- | M] () -- C:\Archivos de programa\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2011/11/12 18:18:52 | 001,989,592 | ---- | M] () -- C:\Archivos de programa\Mozilla Firefox\mozjs.dll
MOD - [2009/12/10 22:53:34 | 000,047,616 | ---- | M] () -- C:\Archivos de programa\ThinkPad\ConnectUtilities\Res\SP\GUIHlprRes.dll
MOD - [2009/12/10 22:53:24 | 000,229,376 | ---- | M] () -- C:\Archivos de programa\ThinkPad\ConnectUtilities\Res\SP\IconRes.dll
MOD - [2009/12/10 22:53:06 | 000,077,824 | ---- | M] () -- C:\Archivos de programa\ThinkPad\ConnectUtilities\Res\SP\SvcHlprRes.dll
MOD - [2009/12/10 21:58:52 | 000,006,656 | ---- | M] () -- C:\Archivos de programa\ThinkPad\ConnectUtilities\ACNewBiosHelper.dll
MOD - [2009/03/09 04:18:50 | 000,008,192 | ---- | M] () -- C:\Archivos de programa\Java\jre6\bin\jp2native.dll
MOD - [2008/08/12 10:16:16 | 002,023,424 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\QtCore4.dll
MOD - [2008/07/29 13:47:56 | 000,016,384 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\imageformats\qsvg4.dll
MOD - [2008/07/29 13:47:38 | 000,135,168 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\imageformats\qjpeg4.dll
MOD - [2008/07/29 13:11:18 | 000,253,952 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\QtSvg4.dll
MOD - [2008/07/29 13:01:12 | 007,331,840 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\QtGUI4.dll
MOD - [2008/07/29 12:50:26 | 000,364,544 | ---- | M] () -- C:\Archivos de programa\Nokia\Nokia PC Suite 7\QtXml4.dll
MOD - [2008/06/20 17:03:30 | 000,248,320 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2007/03/01 02:02:00 | 000,063,024 | ---- | M] () -- C:\Archivos de programa\Lenovo\LenovoCare\SP\LPRESMGR.DLL
MOD - [2006/10/20 08:16:16 | 000,151,552 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcxprpr.dll
MOD - [2006/10/20 06:34:34 | 000,115,200 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcxdrui.dll
MOD - [2006/10/20 06:33:26 | 000,117,760 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcxdrpp.dll
MOD - [2006/10/20 06:32:58 | 000,162,304 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcxdr.dll
MOD - [2006/10/06 13:24:28 | 000,016,384 | ---- | M] () -- C:\Archivos de programa\Dell PC Fax\dlctrstr.dll
MOD - [2006/10/06 13:06:16 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\DLPRMON.DLL
MOD - [2006/10/06 13:04:20 | 000,032,768 | ---- | M] () -- C:\Archivos de programa\Dell PC Fax\ipcmt.dll
MOD - [2006/09/06 11:13:14 | 000,073,728 | ---- | M] () -- C:\WINDOWS\system32\spool\drivers\w32x86\3\dlcxcfg.dll
MOD - [2006/08/02 00:26:20 | 000,118,784 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\iWMSProv.dll
MOD - [2006/08/02 00:24:54 | 000,348,160 | ---- | M] () -- C:\Archivos de programa\Intel\Wireless\Bin\IntStngs.dll
MOD - [2006/05/20 09:42:18 | 000,032,768 | ---- | M] () -- C:\WINDOWS\system32\PMEBLib.dll
MOD - [2006/04/20 07:34:38 | 000,197,680 | ---- | M] () -- C:\WINDOWS\system32\vpnapi.dll
MOD - [2006/02/27 23:21:50 | 000,025,024 | ---- | M] () -- C:\Program Files\Softex\OmniPass\hdddrv.dll
MOD - [2006/02/27 23:21:08 | 000,049,152 | ---- | M] () -- C:\Program Files\Softex\OmniPass\OPXPGina.dll
MOD - [2006/02/27 23:20:44 | 002,076,672 | ---- | M] () -- C:\Program Files\Softex\OmniPass\scureapp.exe
MOD - [2006/02/27 23:19:40 | 000,122,880 | ---- | M] () -- C:\Program Files\Softex\OmniPass\ginastub.dll
MOD - [2006/02/27 23:15:26 | 000,053,248 | ---- | M] () -- C:\Program Files\Softex\OmniPass\scuredll.dll
MOD - [2006/02/27 23:14:56 | 000,327,680 | ---- | M] () -- C:\Program Files\Softex\OmniPass\userdata.dll
MOD - [2006/02/27 23:14:46 | 000,061,440 | ---- | M] () -- C:\Program Files\Softex\OmniPass\opfsdll.dll
MOD - [2006/02/27 23:14:40 | 000,790,528 | ---- | M] () -- C:\Program Files\Softex\OmniPass\autheng.dll
MOD - [2006/02/27 23:14:30 | 000,012,288 | ---- | M] () -- C:\Program Files\Softex\OmniPass\cryptodll.dll
MOD - [2006/02/27 23:14:28 | 000,434,176 | ---- | M] () -- C:\Program Files\Softex\OmniPass\storeng.dll
MOD - [2006/02/27 23:14:12 | 000,010,752 | ---- | M] () -- C:\Program Files\Softex\OmniPass\SSPLogon.dll
MOD - [2006/02/27 23:10:46 | 002,179,504 | ---- | M] () -- C:\Program Files\Softex\OmniPass\sftxtgp.dll
MOD - [2006/02/08 08:42:14 | 000,024,576 | ---- | M] () -- C:\WINDOWS\system32\PMHlerIO.dll
MOD - [2006/01/12 20:26:24 | 001,265,664 | ---- | M] () -- C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\adistres.ESP
MOD - [2005/12/21 17:23:06 | 000,139,264 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\CDRecord.dll
MOD - [2005/12/21 17:19:10 | 000,155,648 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\ui.dll
MOD - [2005/12/21 17:19:02 | 000,069,632 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\zlib.dll
MOD - [2005/12/21 17:15:14 | 000,671,744 | ---- | M] () -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\rr_res.dll
MOD - [2005/10/07 14:05:32 | 000,125,440 | ---- | M] () -- C:\Archivos de programa\WinRAR\RarExt.dll
MOD - [2004/08/18 13:27:40 | 000,311,340 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\ipspgp.dll
MOD - [2004/08/18 13:25:50 | 000,069,678 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\wsfirscr.dll
MOD - [2004/08/18 13:25:36 | 000,147,502 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\wsftplib.dll
MOD - [2004/08/18 13:24:38 | 000,049,197 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\wshosts.dll
MOD - [2004/05/25 07:50:36 | 000,839,680 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\libeay32.dll
MOD - [2004/05/25 07:50:36 | 000,159,744 | ---- | M] () -- C:\Archivos de programa\Ipswitch\WS_FTP Pro\ssleay32.dll
MOD - [2003/08/11 10:07:32 | 000,485,376 | ---- | M] () -- C:\Archivos de programa\IBM\Personal Communications\OOCSVCS2.DLL
MOD - [2002/08/12 15:35:04 | 000,009,216 | ---- | M] () -- C:\lotus\123\winshell.dll
MOD - [2002/08/12 15:34:48 | 000,008,704 | ---- | M] () -- C:\lotus\123\special.dll
MOD - [2002/04/12 10:34:54 | 000,094,208 | ---- | M] () -- C:\lotus\Notes\vim32.dll
MOD - [2002/04/12 10:34:52 | 000,036,864 | ---- | M] () -- C:\lotus\Notes\nxrtf.dll
MOD - [2002/04/12 10:34:48 | 000,045,056 | ---- | M] () -- C:\lotus\Notes\nirtf.dll
MOD - [2002/03/22 23:58:00 | 007,589,888 | ---- | M] () -- C:\lotus\Notes\nnotes.dll
MOD - [2002/03/12 03:13:48 | 000,241,664 | ---- | M] () -- C:\lotus\Notes\nlsccstr.dll
MOD - [2002/03/12 03:02:06 | 000,327,680 | ---- | M] () -- C:\lotus\Notes\js32.dll
MOD - [2000/12/05 07:00:00 | 000,022,016 | ---- | M] () -- C:\Archivos de programa\UltraEdit\ue32ctmn.dll
MOD - [2000/03/27 16:19:02 | 000,229,376 | ---- | M] () -- C:\lotus\compnent\lticnc90.dll
MOD - [1999/01/28 15:30:20 | 000,033,280 | ---- | M] () -- C:\lotus\compnent\ltsbc70.dll
MOD - [1998/08/07 10:08:00 | 000,035,840 | ---- | M] () -- C:\lotus\compnent\ltss98.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (clr_optimization_v2.0.50727_32)
SRV - [2012/01/01 20:55:28 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/01/01 20:04:37 | 000,028,672 | ---- | M] (IBM Corporation) [Auto | Running] -- C:\WINDOWS\system32\drivers\ldlcserv.exe -- (ldlcserv)
SRV - [2012/01/01 20:04:35 | 000,069,632 | ---- | M] (HP) [Unknown | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
SRV - [2011/12/29 22:37:15 | 000,057,344 | ---- | M] (Lenovo) [Auto | Running] -- C:\WINDOWS\system32\PMSveH.exe -- (PMSveH)
SRV - [2011/12/29 22:22:17 | 000,230,760 | ---- | M] (Lenovo ) [Auto | Running] -- C:\Archivos de programa\ThinkPad\ConnectUtilities\AcSvc.exe -- (AcSvc)
SRV - [2011/12/29 22:07:52 | 000,659,456 | ---- | M] (Nokia) [On_Demand | Running] -- C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/12/29 22:07:48 | 001,126,400 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Archivos de programa\Archivos comunes\Lenovo\Scheduler\tvtsched.exe -- (TVT Scheduler)
SRV - [2011/12/29 22:07:46 | 001,384,448 | ---- | M] () [Auto | Running] -- C:\Archivos de programa\IBM ThinkVantage\Rescue and Recovery\rrservice.exe -- (TVT Backup Service)
SRV - [2011/12/29 22:07:43 | 000,644,408 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Archivos de programa\Archivos comunes\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2011/12/29 22:07:43 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Archivos de programa\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2011/12/29 22:07:41 | 000,195,584 | ---- | M] (Telefónica I+D) [Auto | Running] -- C:\Archivos de programa\movistar\Escritorio movistar Latam\ImpWiFiSvc.exe -- (TGCM_ImportWiFiSvc)
SRV - [2011/12/29 22:07:38 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2011/12/29 22:07:38 | 000,036,864 | ---- | M] (Softex Inc.) [Auto | Running] -- C:\Program Files\Softex\OmniPass\OmniServ.exe -- (omniserv)
SRV - [2011/12/29 22:07:35 | 000,200,704 | ---- | M] (OptionNV) [Auto | Running] -- C:\Archivos de programa\Option\GlobeTrotter Connect\GtDetectSc.exe -- (GtDetectSc)
SRV - [2011/12/29 22:07:34 | 000,532,480 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\System32\dlcxcoms.exe -- (dlcx_device)
SRV - [2011/12/29 22:07:34 | 000,054,560 | ---- | M] (Lenovo.) [Auto | Running] -- C:\Archivos de programa\Lenovo\HOTKEY\FnF5svc.exe -- (FNF5SVC)
SRV - [2011/12/29 22:07:33 | 000,626,688 | ---- | M] (Diskeeper Corporation) [Auto | Stopped] -- C:\Archivos de programa\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2011/12/29 22:07:31 | 001,520,688 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Archivos de programa\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2011/12/29 22:07:28 | 000,270,336 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Archivos de programa\Lenovo\Bluetooth Software\bin\btwdins.exe -- (btwdins)
SRV - [2011/12/29 22:07:25 | 000,103,784 | ---- | M] (Lenovo ) [Auto | Running] -- C:\Archivos de programa\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2011/12/29 22:07:24 | 000,028,672 | ---- | M] (IBM Corporation) [Auto | Running] -- C:\WINDOWS\system32\drivers\trcboot.exe -- (TrcBoot)
SRV - [2011/12/29 22:07:23 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Archivos de programa\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2011/12/29 22:07:22 | 001,160,848 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe -- (SPBBCSvc)
SRV - [2006/09/02 16:36:33 | 002,528,960 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Symantec\LiveUpdate\LuComServer_3_1.EXE -- (LiveUpdate)
SRV - [2006/06/13 14:59:06 | 000,032,256 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\psasrv.exe -- (PsaSrv)
SRV - [2005/11/14 00:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2003/08/11 10:07:32 | 000,032,768 | ---- | M] (IBM Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\appnnode.exe -- (AppnNode)
SRV - [2003/07/28 19:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Disabled | Running] -- -- (SYMTDI)
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/03/03 15:41:34 | 000,019,200 | ---- | M] (Telefónica I+D) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tidnet.sys -- (tidnet)
DRV - [2010/02/22 17:26:36 | 000,014,336 | ---- | M] (ZTE) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbccid.sys -- (USBZTECCID)
DRV - [2010/02/22 16:33:48 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2010/02/22 16:33:48 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2010/02/22 16:33:48 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2010/02/22 16:33:48 | 000,105,856 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmeaext2.sys -- (ZTEusbMB)
DRV - [2010/02/04 23:01:36 | 000,030,144 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2009/12/28 14:52:40 | 000,010,240 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter.sys -- (massfilter)
DRV - [2009/12/28 14:03:40 | 000,114,688 | ---- | M] (ZTE Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnet.sys -- (ZTEusbnet)
DRV - [2009/12/07 12:53:12 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/11/17 19:02:46 | 000,004,224 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\IBMBLDID.sys -- (IBMTPCHK)
DRV - [2009/11/17 19:02:44 | 000,011,520 | ---- | M] (IBM Corp.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ANC.sys -- (ANC)
DRV - [2009/10/12 08:21:54 | 000,100,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/10/06 11:56:34 | 000,136,704 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2009/10/06 11:52:50 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2009/10/06 11:52:34 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2009/10/06 11:52:34 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2009/10/06 11:52:34 | 000,007,936 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2009/06/17 17:56:16 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/06/17 17:56:06 | 000,035,472 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/02/03 15:56:22 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\massfilter_hs.sys -- (massfilter_hs)
DRV - [2008/12/01 21:28:49 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/08/08 21:13:04 | 000,024,448 | ---- | M] (Huawei Tech. Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewdcsc.sys -- (Huawei)
DRV - [2006/08/02 01:27:48 | 000,012,544 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2006/04/20 07:33:40 | 000,303,740 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2006/03/28 11:48:38 | 000,032,000 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtf32bus.sys -- (GTF32BUS)
DRV - [2006/03/28 11:48:38 | 000,018,944 | ---- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtscser.sys -- (GTSCSER)
DRV - [2006/03/28 11:48:38 | 000,007,936 | R--- | M] (Option N.V.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gtptser.sys -- (GTPTSER)
DRV - [2006/02/27 04:46:20 | 000,081,408 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006/01/17 09:21:52 | 000,328,061 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2006/01/17 09:18:22 | 000,850,474 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2006/01/17 09:15:36 | 000,030,459 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2006/01/17 09:15:26 | 000,030,285 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2006/01/17 09:14:52 | 000,065,688 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2006/01/17 09:11:56 | 000,148,900 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2006/01/11 01:42:00 | 000,007,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\TSMAPIP.SYS -- (TSMAPIP)
DRV - [2005/12/21 16:14:58 | 000,012,544 | ---- | M] (IBM) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ibmfilter.sys -- (ibmfilter)
DRV - [2005/12/21 13:09:50 | 000,010,240 | ---- | M] (Lenovo ) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PMHler.sys -- (PMHler)
DRV - [2005/12/12 15:08:44 | 001,124,097 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2005/12/04 23:55:30 | 001,428,096 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\w39n51.sys -- (w39n51) Intel®
DRV - [2005/12/01 06:20:00 | 000,027,264 | ---- | M] (Tatara Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tsclient.sys -- (TSClient)
DRV - [2005/11/16 19:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/11/01 17:08:00 | 000,308,992 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/11/01 16:54:50 | 000,051,584 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/08/18 18:22:30 | 000,110,080 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2005/05/17 03:51:34 | 000,005,315 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2005/03/29 17:02:22 | 000,116,594 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATSwpDrv.sys -- (ATSWPDRV) AuthenTec TruePrint USB Driver (AES2500)
DRV - [2005/01/26 05:22:20 | 000,280,344 | ---- | M] (Zone Labs LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2005/01/07 16:07:16 | 000,145,920 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Hdaudio.sys -- (HdAudAddService)
DRV - [2003/08/11 10:07:32 | 001,278,912 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\appn.sys -- (Appn)
DRV - [2003/08/11 10:07:32 | 000,194,688 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\AppnBase.sys -- (AppnBase)
DRV - [2003/08/11 10:07:32 | 000,160,288 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlncfwk.sys -- (pdlncfwk)
DRV - [2003/08/11 10:07:32 | 000,119,104 | ---- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\appnapi.sys -- (AppnApi)
DRV - [2003/08/11 10:07:32 | 000,101,408 | ---- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\llc2.sys -- (IBM_LLC2)
DRV - [2003/08/11 10:07:32 | 000,074,992 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnacom.sys -- (pdlnacom)
DRV - [2003/08/11 10:07:32 | 000,070,144 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndlpb.sys -- (pdlndlpb)
DRV - [2003/08/11 10:07:32 | 000,067,184 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnemap.sys -- (pdlnemap)
DRV - [2003/08/11 10:07:32 | 000,067,072 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndsdl.sys -- (pdlndsdl)
DRV - [2003/08/11 10:07:32 | 000,059,504 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnshay.sys -- (pdlnshay)
DRV - [2003/08/11 10:07:32 | 000,059,392 | ---- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\pdlndldl.sys -- (pdlndldl) IBM Enterprise Extender (HPR/IP)
DRV - [2003/08/11 10:07:32 | 000,058,432 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnsx25.sys -- (pdlnsx25)
DRV - [2003/08/11 10:07:32 | 000,054,416 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnsv25.sys -- (pdlnsv25)
DRV - [2003/08/11 10:07:32 | 000,053,248 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndqll.sys -- (pdlndqll)
DRV - [2003/08/11 10:07:32 | 000,051,712 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndtdl.sys -- (pdlndtdl)
DRV - [2003/08/11 10:07:32 | 000,050,336 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnecfg.sys -- (pdlnecfg)
DRV - [2003/08/11 10:07:32 | 000,038,236 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\anydlc.sys -- (Anydlc)
DRV - [2003/08/11 10:07:32 | 000,036,048 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnafac.sys -- (pdlnafac)
DRV - [2003/08/11 10:07:32 | 000,024,588 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\klognt.sys -- (KLOGNT)
DRV - [2003/08/11 10:07:32 | 000,022,384 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnslea.sys -- (pdlnslea)
DRV - [2003/08/11 10:07:32 | 000,020,480 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnatcm.sys -- (pdlnatcm)
DRV - [2003/08/11 10:07:32 | 000,019,984 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnepkt.sys -- (pdlnepkt)
DRV - [2003/08/11 10:07:32 | 000,018,944 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndoem.sys -- (pdlndoem)
DRV - [2003/08/11 10:07:32 | 000,018,432 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnatdl.sys -- (pdlnatdl)
DRV - [2003/08/11 10:07:32 | 000,012,800 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlndint.sys -- (pdlndint)
DRV - [2003/08/11 10:07:32 | 000,012,768 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnemsg.sys -- (pdlnemsg)
DRV - [2003/08/11 10:07:32 | 000,012,288 | ---- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\pdlnctdl.sys -- (pdlnctdl)
DRV - [2003/08/11 10:07:32 | 000,012,028 | ---- | M] (IBM Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\nstrcnt.sys -- (NsTrcNT)
DRV - [2003/08/11 10:07:32 | 000,008,608 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlnebas.sys -- (pdlnebas)
DRV - [2003/08/11 10:07:32 | 000,006,784 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\pdlncbas.sys -- (pdlncbas)
DRV - [2002/08/30 16:07:14 | 000,006,207 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dvbcamd.sys -- (DVBCAM)
DRV - [2001/08/17 21:53:32 | 000,003,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\qv2kux.sys -- (QV2KUX)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;;;;;;;;;;;;;;;;;*.local;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;<local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http://172.23.200.28:8080

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.co...-8&oe=UTF-8&q="
FF - prefs.js..browser.startup.homepage: "http://www.google.es"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..network.proxy.autoconfig_url: "htpps:www.ibm.com"
FF - prefs.js..network.proxy.backup.ftp: "helesponto1"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "helesponto1"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "helesponto1"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "helesponto1"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "helesponto1"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "helesponto1"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "helesponto1"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "helesponto1"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "helesponto1"
FF - prefs.js..network.proxy.ssl_port: 8080


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Archivos de programa\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Archivos de programa\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Archivos de programa\Picasa2\npPicasa2.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Archivos de programa\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Archivos de programa\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Archivos de programa\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[email protected]: C:\Archivos de programa\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/11/22 20:41:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2011/11/12 18:18:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins [2011/05/09 23:08:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Archivos de programa\Mozilla Thunderbird\components [2011/11/26 11:46:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Archivos de programa\Mozilla Thunderbird\plugins [2009/12/09 21:04:17 | 000,000,000 | ---D | M]

[2010/09/05 11:35:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Extensions
[2010/09/05 11:35:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2008/10/27 17:40:21 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Extensions\[email protected]
[2011/10/09 04:53:11 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Firefox\Profiles\c4nkwdk2.default\extensions
[2010/05/02 20:55:12 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Firefox\Profiles\c4nkwdk2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/17 20:55:30 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Firefox\Profiles\c4nkwdk2.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2006/09/08 07:53:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Profiles\Netscape\NSB\Profiles\wbloravd.default\extensions
[2006/09/08 07:59:25 | 000,000,000 | ---D | M] (Netscape - Winscape) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Profiles\Netscape\NSB\Profiles\wbloravd.default\extensions\{8803789A-23EB-44b4-BD48-6762FD320242}
[2006/09/08 07:59:25 | 000,000,000 | ---D | M] (Netscape - Fusion) -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Mozilla\Profiles\Netscape\NSB\Profiles\wbloravd.default\extensions\{f799a0d0-641d-11d9-9669-0800200c9a66}
[2011/11/12 18:19:20 | 000,000,000 | ---D | M] (No name found) -- C:\Archivos de programa\Mozilla Firefox\extensions
[2006/09/03 14:18:58 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Archivos de programa\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/09/09 17:30:21 | 000,000,000 | ---D | M] (Click to call with Skype) -- C:\Archivos de programa\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/12 18:18:53 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Archivos de programa\mozilla firefox\components\browsercomps.dll
[2008/09/04 01:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Archivos de programa\mozilla firefox\plugins\npbittorrent.dll
[2009/11/18 19:59:20 | 000,002,206 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\babylon.xml
[2011/09/15 22:35:11 | 000,002,252 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml
[2011/11/12 18:18:54 | 000,002,040 | ---- | M] () -- C:\Archivos de programa\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/01/02 17:15:12 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (WsftpBrowserHelper Class) - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Archivos de programa\Ipswitch\WS_FTP Pro\wsbho2k0.dll (Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington, MA 02421)
O2 - BHO: (Windows Live Aplicación auxiliar de inicio de sesión) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - Reg Error: Value error. File not found
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acceso directo a la página de propiedades de High Definition Audio] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [ACTray] C:\Archivos de programa\ThinkPad\ConnectUtilities\ACTray.exe (Lenovo )
O4 - HKLM..\Run: [ACWLIcon] C:\Archivos de programa\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo )
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Archivos de programa\Archivos comunes\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [cssauthe] C:\Archivos de programa\IBM ThinkVantage\Client Security Solution\cssauthe.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [DLCXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL ()
O4 - HKLM..\Run: [LPManager] C:\Archivos de programa\Lenovo\LenovoCare\LPMGR.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe ()
O4 - HKLM..\Run: [PMHandler] C:\WINDOWS\system32\PMHandler.exe (Lenovo)
O4 - HKLM..\Run: [TPWAUDAP] C:\Archivos de programa\Lenovo\HOTKEY\TpWAudAp.exe (Lenovo Group Limited)
O4 - HKCU..\Run: [PC Suite Tray] C:\Archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)
O4 - HKCU..\Run: [updateMgr] C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk = C:\WINDOWS\Installer\{AC76BA86-1034-4700-BA7E-100000000002}\SC_Acrobat.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Archivos de programa\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Archivos de programa\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O9 - Extra Button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Archivos de programa\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Archivos de programa\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Archivos de programa\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Archivos de programa\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ntent/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} http://www-307.ibm.c...rt/IbmEgath.cab (IBM Access Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/...all-142-win.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 87.216.1.65 87.216.1.66
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2D8F0A8-E926-40E1-9410-5722904D2DD2}: DhcpNameServer = 87.216.1.65 87.216.1.66
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - (C:\Program Files\Softex\OmniPass\opxpgina.dll) - C:\Program Files\Softex\OmniPass\OPXPGina.dll ()
O20 - Winlogon\Notify\pcsinst: DllName - (pcsinst.dll) - C:\WINDOWS\System32\pcsinst.dll (IBM)
O20 - Winlogon\Notify\tphotkey: DllName - (C:\Archivos de programa\Lenovo\HOTKEY\tphklock.dll) - C:\Archivos de programa\Lenovo\HOTKEY\tphklock.dll (Lenovo Group Limited)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/29 15:02:42 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\AutoRun\command - "" = E:\hgu.bat
O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\explore\Command - "" = E:\hgu.bat
O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\open\Command - "" = E:\hgu.bat
O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\AutoRun\command - "" = E:\hgu.bat
O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\explore\Command - "" = E:\hgu.bat
O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\open\Command - "" = E:\hgu.bat
O33 - MountPoints2\{3382fd74-c4e1-11df-84c2-000fb0c96c99}\Shell - "" = AutoRun
O33 - MountPoints2\{3382fd74-c4e1-11df-84c2-000fb0c96c99}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WIN31.dll.vbs
O33 - MountPoints2\{3382fd83-c4e1-11df-84c2-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{3382fd83-c4e1-11df-84c2-00a0c6000000}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\AutoRun\command - "" = ybj8df.exe
O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\explore\Command - "" = ybj8df.exe
O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\open\Command - "" = ybj8df.exe
O33 - MountPoints2\{a2a5832f-c1de-11dc-8c77-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{c5f54ae7-82e1-11df-84b7-000fb0c96c99}\Shell - "" = AutoRun
O33 - MountPoints2\{c5f54ae7-82e1-11df-84b7-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{c5f8be5e-a552-11df-84b9-000fb0c96c99}\Shell\AutoRun\command - "" = RECYCLE\D-0-060-0000000000-1111111-2222222\windm.exe
O33 - MountPoints2\{c5f8be5e-a552-11df-84b9-000fb0c96c99}\Shell\open\command - "" = RECYCLE\D-0-060-0000000000-1111111-2222222\windm.exe
O33 - MountPoints2\{c5f8be61-a552-11df-84b9-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{c965ec18-77c8-11df-84b4-000fb0c96c99}\Shell - "" = AutoRun
O33 - MountPoints2\{c965ec18-77c8-11df-84b4-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{c965ec1b-77c8-11df-84b4-000fb0c96c99}\Shell - "" = AutoRun
O33 - MountPoints2\{c965ec1b-77c8-11df-84b4-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{c965ec1d-77c8-11df-84b4-00130252ca97}\Shell - "" = AutoRun
O33 - MountPoints2\{c965ec1d-77c8-11df-84b4-00130252ca97}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{c965ec22-77c8-11df-84b4-00130252ca97}\Shell - "" = AutoRun
O33 - MountPoints2\{c965ec22-77c8-11df-84b4-00130252ca97}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{d17c587b-9d6a-11de-8d0c-000fb0c96c99}\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
O33 - MountPoints2\{d17c587d-9d6a-11de-8d0c-000fb0c96c99}\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
O33 - MountPoints2\{db3f364d-6f1d-11de-8cfd-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{db3f3652-6f1d-11de-8cfd-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
O33 - MountPoints2\{dfde2ec4-9196-11df-84b8-000fb0c96c99}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\WINDOWS\System32\drivers\
File not found -- C:\WINDOWS\System32\
[2012/01/03 21:00:18 | 001,578,288 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Chema Alvarez\Escritorio\TDSSKiller.exe
[2012/01/02 20:38:58 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/01/02 20:08:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Datos de programa\Adobe
[2012/01/02 19:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Norton
[2012/01/02 19:15:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\NortonInstaller
[2012/01/02 17:02:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/01/02 17:02:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/01/02 17:02:18 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/01/02 17:02:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/01/02 17:01:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/01/02 17:01:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/02 16:43:37 | 004,353,794 | R--- | C] (Swearware) -- C:\Documents and Settings\Chema Alvarez\Escritorio\ComboFix.exe
[2012/01/02 16:39:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/01/02 16:39:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\setup.pss
[2012/01/02 16:38:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\setupupd
[2012/01/02 15:59:06 | 000,000,000 | ---D | C] -- C:\7a34f181bf5f4afdd8eb46
[2011/12/30 18:24:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Hewlett-Packard Company
[2011/12/30 18:24:34 | 000,000,000 | ---D | C] -- C:\DriveKey
[2011/12/30 17:47:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\HDD Capacity Restore
[2011/12/30 17:47:41 | 000,000,000 | ---D | C] -- C:\Archivos de programa\HDD Capacity Restore
[2011/12/30 15:54:09 | 000,000,000 | ---D | C] -- C:\Archivos de programa\HDDGURU FreeWipe Tool
[2011/12/30 15:54:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\HDD Wipe Tool
[2011/12/29 23:36:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Datos de programa\Sun
[2011/12/29 22:08:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Datos de programa\Adobe
[2011/12/27 22:16:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Blackberry Desktop
[2011/12/27 21:40:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Research In Motion
[2011/12/27 21:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Datos de programa\Research In Motion
[2011/12/27 21:37:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menú Inicio\Programas\BlackBerry
[2011/12/27 21:37:14 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Roxio Shared
[2011/12/27 21:36:25 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Research In Motion
[2011/12/27 21:36:20 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Research In Motion
[2011/12/20 21:59:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Chema Alvarez\Escritorio\TomTom-Cfg
[2007/07/29 13:01:36 | 000,323,584 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxhcp.dll
[2007/07/29 13:01:35 | 000,413,696 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxinpa.dll
[2007/07/29 13:01:35 | 000,397,312 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxiesc.dll
[2007/07/29 13:01:34 | 000,991,232 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxusb1.dll
[2007/07/29 13:01:33 | 001,224,704 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxserv.dll
[2007/07/29 13:01:33 | 000,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxprox.dll
[2007/07/29 13:01:32 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxpmui.dll
[2007/07/29 13:01:32 | 000,585,728 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxlmpm.dll
[2007/07/29 13:01:32 | 000,094,208 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxpplc.dll
[2007/07/29 13:01:30 | 000,696,320 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxhbn3.dll
[2007/07/29 13:01:30 | 000,380,928 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxih.exe
[2007/07/29 13:01:28 | 000,532,480 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcoms.exe
[2007/07/29 13:01:27 | 000,684,032 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcomc.dll
[2007/07/29 13:01:27 | 000,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcomm.dll
[2007/07/29 13:01:26 | 000,381,832 | ---- | C] ( ) -- C:\WINDOWS\System32\dlcxcfg.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\WINDOWS\System32\drivers\
File not found -- C:\WINDOWS\System32\
[2012/01/04 19:01:00 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/04 16:01:03 | 000,001,098 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/03 20:34:45 | 000,007,639 | ---- | M] () -- C:\WINDOWS\UEDIT32.INI
[2012/01/03 20:23:19 | 000,002,363 | ---- | M] () -- C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk
[2012/01/03 20:22:24 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/03 20:22:17 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
[2012/01/03 20:22:04 | 000,000,374 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2012/01/03 20:21:49 | 000,158,088 | ---- | M] () -- C:\wts.dbg
[2012/01/03 20:21:39 | 1600,311,296 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/03 20:21:39 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/03 18:09:52 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\iExplore.exe
[2012/01/03 12:45:34 | 000,920,384 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\Norton_Removal_Tool.exe
[2012/01/03 04:12:59 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/03 04:08:10 | 000,068,096 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/02 17:15:12 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/02 16:40:21 | 000,000,278 | RHS- | M] () -- C:\boot.ini
[2012/01/02 15:53:07 | 000,527,264 | ---- | M] () -- C:\WINDOWS\System32\perfh00A.dat
[2012/01/02 15:53:07 | 000,460,456 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/02 15:53:07 | 000,101,158 | ---- | M] () -- C:\WINDOWS\System32\perfc00A.dat
[2012/01/02 15:53:07 | 000,079,078 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/01/02 12:03:56 | 004,353,794 | R--- | M] (Swearware) -- C:\Documents and Settings\Chema Alvarez\Escritorio\ComboFix.exe
[2012/01/01 20:22:14 | 000,000,256 | ---- | M] () -- C:\WINDOWS\System32\pool.bin
[2011/12/30 18:24:34 | 000,000,325 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\HP USB Disk Storage Format Tool.lnk
[2011/12/30 18:18:04 | 005,166,988 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\Install_RMPrepUSB_MultiLingualInstaller.exe
[2011/12/30 17:47:42 | 000,000,771 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\HDD Capacity Restore.lnk
[2011/12/29 22:07:34 | 000,532,480 | ---- | M] ( ) -- C:\WINDOWS\System32\dlcxcoms.exe
[2011/12/27 21:43:32 | 002,841,119 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\LoaderBackup-(2011-12-27).ipd
[2011/12/27 21:37:31 | 000,001,775 | ---- | M] () -- C:\Documents and Settings\All Users\Escritorio\Desktop Manager.lnk
[2011/12/26 18:42:37 | 000,079,086 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\47lw980s Factura.pdf
[2011/12/26 18:40:37 | 030,108,726 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\47lw980s.BMP
[2011/12/24 13:39:00 | 000,001,020 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011/12/23 14:52:26 | 001,578,288 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Chema Alvarez\Escritorio\TDSSKiller.exe
[2011/12/23 12:28:37 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/12/19 16:19:12 | 000,516,094 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\parte valdecilla.pdf
[2011/12/19 16:17:41 | 027,108,918 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\parte valdecilla.bmp
[2011/12/19 00:41:26 | 000,029,299 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\pagoFinanet;jsessionid=0000JN2RZ3vyNR5hCiehdlYcbOb_15denq2kv.pdf
[2011/12/17 12:04:06 | 000,227,208 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/16 12:16:58 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/12/09 21:48:32 | 000,270,564 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\larguero.pdf
[2011/12/09 21:32:47 | 022,133,550 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\larguero.bmp
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/03 18:12:39 | 001,008,141 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\iExplore.exe
[2012/01/03 15:31:58 | 000,920,384 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\Norton_Removal_Tool.exe
[2012/01/02 18:04:06 | 1600,311,296 | -HS- | C] () -- C:\hiberfil.sys
[2012/01/02 17:02:18 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/01/02 17:02:18 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/01/02 17:02:18 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/01/02 17:02:18 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/01/02 17:02:18 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/01/02 16:40:20 | 000,000,194 | -HS- | C] () -- C:\BOOT.BAK
[2012/01/02 16:40:15 | 000,261,904 | RHS- | C] () -- C:\cmldr
[2011/12/30 19:17:03 | 031,661,561 | ---- | C] () -- C:\3DGuy-Open-Side-by-Side-Full.avi
[2011/12/30 18:24:34 | 000,000,325 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\HP USB Disk Storage Format Tool.lnk
[2011/12/30 18:17:55 | 005,166,988 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\Install_RMPrepUSB_MultiLingualInstaller.exe
[2011/12/30 17:47:42 | 000,000,771 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\HDD Capacity Restore.lnk
[2011/12/27 21:43:31 | 002,841,119 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\LoaderBackup-(2011-12-27).ipd
[2011/12/27 21:40:18 | 000,000,256 | ---- | C] () -- C:\WINDOWS\System32\pool.bin
[2011/12/27 21:37:30 | 000,001,775 | ---- | C] () -- C:\Documents and Settings\All Users\Escritorio\Desktop Manager.lnk
[2011/12/26 18:42:36 | 000,079,086 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\47lw980s Factura.pdf
[2011/12/26 18:40:29 | 030,108,726 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Mis documentos\47lw980s.BMP
[2011/12/20 16:36:36 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/19 16:19:11 | 000,516,094 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\parte valdecilla.pdf
[2011/12/19 16:17:37 | 027,108,918 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\parte valdecilla.bmp
[2011/12/19 00:41:26 | 000,029,299 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\pagoFinanet;jsessionid=0000JN2RZ3vyNR5hCiehdlYcbOb_15denq2kv.pdf
[2011/12/09 21:48:32 | 000,270,564 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\larguero.pdf
[2011/12/09 21:32:43 | 022,133,550 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\larguero.bmp
[2011/05/09 13:41:00 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Configuración local\Datos de programa\{938E9E19-D923-44BA-8C0B-A594F0564D74}
[2011/02/09 17:33:39 | 000,135,295 | ---- | C] () -- C:\WINDOWS\HPHins12.dat
[2011/02/09 17:33:39 | 000,014,916 | ---- | C] () -- C:\WINDOWS\hphmdl12.dat
[2011/02/09 17:33:28 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2010/06/24 11:26:00 | 000,196,808 | ---- | C] () -- C:\Documents and Settings\LocalService\Configuración local\Datos de programa\FontCache3.0.0.0.dat
[2010/05/31 16:25:49 | 000,000,043 | ---- | C] () -- C:\WINDOWS\MezzmoMediaServer.INI
[2010/02/18 21:35:43 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/12/23 18:11:47 | 000,000,225 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Datos de programa\default.rss
[2009/09/08 15:31:35 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Datos de programa\$_hpcst$.hpc
[2009/08/24 21:28:10 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Datos de programa\QTSBandwidthCache
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/09 18:09:38 | 000,241,664 | ---- | C] () -- C:\WINDOWS\NwtGatewayDLL.dll
[2009/06/09 18:09:38 | 000,001,110 | ---- | C] () -- C:\WINDOWS\NwtGatewayConfig.ini
[2009/06/09 15:09:09 | 000,241,664 | ---- | C] () -- C:\WINDOWS\VMC9SavedNwtGatewayDLL.dll
[2009/06/09 15:09:09 | 000,001,110 | ---- | C] () -- C:\WINDOWS\VMC9SavedNwtGatewayConfig.ini
[2009/06/07 13:54:55 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/05/12 17:21:53 | 000,000,407 | ---- | C] () -- C:\WINDOWS\nwcvegas.ini
[2009/05/09 19:21:17 | 000,000,334 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2008/12/10 19:21:37 | 000,004,767 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2008/08/18 18:31:45 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2008/05/16 11:58:04 | 000,012,632 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2008/03/05 19:18:10 | 000,691,545 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2008/03/05 19:18:10 | 000,002,550 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2007/07/29 19:01:03 | 000,006,580 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2007/07/29 19:01:03 | 000,000,104 | RHS- | C] () -- C:\WINDOWS\System32\554BF46618.sys
[2007/07/29 13:12:40 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlcxvs.dll
[2007/07/29 13:12:33 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\dlcxcoin.dll
[2007/07/29 13:11:50 | 000,692,224 | ---- | C] () -- C:\WINDOWS\System32\dlcxdrs.dll
[2007/07/29 13:11:50 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dlcxcaps.dll
[2007/07/29 13:11:50 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\dlcxcnv4.dll
[2007/07/29 13:05:49 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\DLPRMON.DLL
[2007/07/29 13:05:49 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\DLPMONUI.DLL
[2007/07/29 13:01:37 | 000,274,432 | ---- | C] () -- C:\WINDOWS\System32\dlcxinst.dll
[2007/07/29 13:01:34 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\dlcxutil.dll
[2007/07/29 13:01:31 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcxinsb.dll
[2007/07/29 13:01:31 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\dlcxins.dll
[2007/07/29 13:01:31 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\dlcxjswr.dll
[2007/07/29 13:01:31 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\dlcxinsr.dll
[2007/07/29 13:01:29 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\dlcxgrd.dll
[2007/07/29 13:01:28 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\dlcxcub.dll
[2007/07/29 13:01:28 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\dlcxcu.dll
[2007/07/29 13:01:28 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\dlcxcur.dll
[2007/07/29 13:01:25 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\DLCXcfg.dll
[2007/05/30 10:43:45 | 000,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI
[2007/03/22 21:47:35 | 000,046,344 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2007/02/21 19:56:37 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006/12/22 16:46:37 | 000,000,006 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Datos de programa\dm.ini
[2006/11/26 00:20:32 | 000,000,143 | ---- | C] () -- C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\fusioncache.dat
[2006/10/10 23:42:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2006/09/12 11:48:17 | 000,458,752 | ---- | C] () -- C:\WINDOWS\System32\TLS704D.DLL
[2006/09/12 11:48:16 | 000,036,911 | ---- | C] () -- C:\WINDOWS\System32\PCIMSG.DLL
[2006/09/12 11:33:02 | 000,000,044 | ---- | C] () -- C:\WINDOWS\lotus.ini
[2006/09/09 19:22:19 | 000,000,379 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/09/09 19:03:21 | 000,007,639 | ---- | C] () -- C:\WINDOWS\UEDIT32.INI
[2006/09/08 10:27:37 | 000,068,096 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 08:03:43 | 000,105,168 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2006/09/08 07:26:29 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcsmig.INI
[2006/09/03 14:19:03 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2006/09/03 14:18:41 | 000,018,385 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2006/08/29 15:02:38 | 000,000,142 | ---- | C] () -- C:\Documents and Settings\Chema Alvarez\Configuración local\Datos de programa\fusioncache.dat
[2006/06/13 15:05:02 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/06/13 15:04:14 | 000,004,224 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2006/06/13 14:59:30 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\psasrv.exe
[2006/06/13 14:47:46 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2006/06/13 14:47:46 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2006/06/13 14:47:46 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2006/06/13 14:47:46 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2006/06/13 14:47:46 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2006/06/13 14:47:46 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2006/06/13 14:47:18 | 000,114,688 | ---- | C] () -- C:\WINDOWS\desktopset.exe
[2006/06/13 14:47:08 | 000,028,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBkey.sys
[2006/06/13 14:45:12 | 000,000,256 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2006/06/13 14:18:54 | 000,002,954 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/05/20 09:42:18 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\PMEBLib.dll
[2006/04/20 07:34:38 | 000,197,680 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2006/04/20 07:34:24 | 000,193,584 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2006/02/08 08:42:14 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\PMHlerIO.dll
[2006/01/19 11:46:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2006/01/17 09:31:30 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005/05/23 07:22:24 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2005/05/23 07:22:24 | 000,004,547 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/09/01 12:54:54 | 000,000,834 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/09/01 12:46:14 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2004/09/01 12:37:27 | 000,021,900 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/09/01 12:32:20 | 000,004,370 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/09/01 12:31:33 | 000,227,208 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/11 10:07:32 | 000,000,251 | ---- | C] () -- C:\WINDOWS\System32\drivers\hlldrvr.com
[2003/04/11 12:14:14 | 000,005,827 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/30 16:07:14 | 000,006,207 | ---- | C] () -- C:\WINDOWS\System32\drivers\dvbcamd.sys
[2001/11/14 11:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[1999/03/10 01:23:00 | 000,222,928 | ---- | C] () -- C:\WINDOWS\System32\lobas09.dll
[1998/04/27 01:23:00 | 006,150,961 | ---- | C] () -- C:\WINDOWS\System32\jre116.exe
[1998/01/13 13:52:30 | 000,047,104 | ---- | C] () -- C:\WINDOWS\System32\lotrn13.dll
[1997/11/14 01:23:00 | 000,031,008 | ---- | C] () -- C:\WINDOWS\System32\ivtrn09.dll
[1997/02/02 01:23:00 | 000,000,058 | ---- | C] () -- C:\WINDOWS\loss613.ini
[1997/02/02 01:23:00 | 000,000,058 | ---- | C] () -- C:\WINDOWS\loss09.ini
[1996/07/09 01:23:00 | 000,000,038 | ---- | C] () -- C:\WINDOWS\loidp13.ini
[1994/07/25 01:23:00 | 000,014,928 | ---- | C] () -- C:\WINDOWS\System32\wingen.drv
[1994/04/07 01:23:00 | 000,000,462 | ---- | C] () -- C:\WINDOWS\lodbf13.ini
[1979/12/31 23:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[1979/12/31 23:00:00 | 000,527,264 | ---- | C] () -- C:\WINDOWS\System32\perfh00A.dat
[1979/12/31 23:00:00 | 000,460,456 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[1979/12/31 23:00:00 | 000,317,534 | ---- | C] () -- C:\WINDOWS\System32\perfi00A.dat
[1979/12/31 23:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[1979/12/31 23:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[1979/12/31 23:00:00 | 000,101,158 | ---- | C] () -- C:\WINDOWS\System32\perfc00A.dat
[1979/12/31 23:00:00 | 000,079,078 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[1979/12/31 23:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[1979/12/31 23:00:00 | 000,036,284 | ---- | C] () -- C:\WINDOWS\System32\perfd00A.dat
[1979/12/31 23:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[1979/12/31 23:00:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[1979/12/31 23:00:00 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock(3).dll
[1979/12/31 23:00:00 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[1979/12/31 23:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[1979/12/31 23:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[1979/12/31 23:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2010/01/07 11:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Babylon
[2006/09/08 07:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\IBM
[2009/11/22 20:33:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Installations
[2010/02/04 23:02:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Lenovo
[2007/05/30 11:26:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\PC Suite
[2011/12/27 21:39:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\Research In Motion
[2006/08/29 15:03:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\ThinkVantage
[2010/05/17 18:58:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\TomTom
[2011/07/27 18:11:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Datos de programa\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2009/12/09 21:07:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/24 21:46:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Datos de programa\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/02/06 11:09:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Avaya
[2009/02/13 21:04:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\BitTorrent
[2011/12/27 22:16:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Blackberry Desktop
[2007/01/25 19:31:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\DataLayer
[2010/09/04 19:27:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\DNA
[2010/02/04 23:01:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Downloaded Installations
[2006/09/08 07:18:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\IBM
[2009/06/09 15:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\ICS
[2010/08/23 18:23:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\ImgBurn
[2006/09/03 23:04:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\InterVideo
[2006/10/14 20:43:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Leadertech
[2006/09/08 10:48:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Lenovo
[2010/06/28 18:37:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Netscape
[2008/10/02 20:06:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Nokia
[2011/07/06 17:40:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\PC Suite
[2011/12/27 21:40:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Research In Motion
[2010/10/01 17:23:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Telefónica
[2009/12/04 20:06:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Telefónica Móviles
[2006/08/29 15:03:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\ThinkVantage
[2010/09/05 11:35:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Thunderbird
[2009/05/29 17:36:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\TomTom
[2011/06/09 17:46:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Uniblue
[2009/06/09 17:23:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Vodafone
[2009/06/09 16:16:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Vodafone Mobile Connect
[2008/07/02 19:47:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\Vodafone Net
[2011/09/07 14:49:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chema Alvarez\Datos de programa\VoipBuster
[2012/01/03 20:22:17 | 000,000,294 | ---- | M] () -- C:\WINDOWS\Tasks\RegistryBooster.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Hello and welcome to Geekstogo!

We apologize for the delay in responding to your request for help.
If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below.

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;;;;;;;;;;;;;;;;;*.local;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;<local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http://172.23.200.28:8080
    O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\AutoRun\command - "" = E:\hgu.bat
    O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\explore\Command - "" = E:\hgu.bat
    O33 - MountPoints2\{008b8296-490b-11dd-8ca8-000fb0c96c99}\Shell\open\Command - "" = E:\hgu.bat
    O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\AutoRun\command - "" = E:\hgu.bat
    O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\explore\Command - "" = E:\hgu.bat
    O33 - MountPoints2\{01241d65-5171-11dd-8cad-000fb0c96c99}\Shell\open\Command - "" = E:\hgu.bat
    O33 - MountPoints2\{3382fd74-c4e1-11df-84c2-000fb0c96c99}\Shell - "" = AutoRun
    O33 - MountPoints2\{3382fd74-c4e1-11df-84c2-000fb0c96c99}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WIN31.dll.vbs
    O33 - MountPoints2\{3382fd83-c4e1-11df-84c2-00a0c6000000}\Shell - "" = AutoRun
    O33 - MountPoints2\{3382fd83-c4e1-11df-84c2-00a0c6000000}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\AutoRun\command - "" = ybj8df.exe
    O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\explore\Command - "" = ybj8df.exe
    O33 - MountPoints2\{8fed7d3e-9495-11de-8d07-000fb0c96c99}\Shell\open\Command - "" = ybj8df.exe
    O33 - MountPoints2\{a2a5832f-c1de-11dc-8c77-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
    O33 - MountPoints2\{c5f54ae7-82e1-11df-84b7-000fb0c96c99}\Shell - "" = AutoRun
    O33 - MountPoints2\{c5f54ae7-82e1-11df-84b7-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{c5f8be5e-a552-11df-84b9-000fb0c96c99}\Shell\AutoRun\command - "" = RECYCLE\D-0-060-0000000000-1111111-2222222\windm.exe
    O33 - MountPoints2\{c5f8be5e-a552-11df-84b9-000fb0c96c99}\Shell\open\command - "" = RECYCLE\D-0-060-0000000000-1111111-2222222\windm.exe
    O33 - MountPoints2\{c5f8be61-a552-11df-84b9-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
    O33 - MountPoints2\{c965ec18-77c8-11df-84b4-000fb0c96c99}\Shell - "" = AutoRun
    O33 - MountPoints2\{c965ec18-77c8-11df-84b4-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{c965ec1b-77c8-11df-84b4-000fb0c96c99}\Shell - "" = AutoRun
    O33 - MountPoints2\{c965ec1b-77c8-11df-84b4-000fb0c96c99}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{c965ec1d-77c8-11df-84b4-00130252ca97}\Shell - "" = AutoRun
    O33 - MountPoints2\{c965ec1d-77c8-11df-84b4-00130252ca97}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{c965ec22-77c8-11df-84b4-00130252ca97}\Shell - "" = AutoRun
    O33 - MountPoints2\{c965ec22-77c8-11df-84b4-00130252ca97}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{d17c587b-9d6a-11de-8d0c-000fb0c96c99}\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
    O33 - MountPoints2\{d17c587d-9d6a-11de-8d0c-000fb0c96c99}\Shell\AutoRun\command - "" = WD_Windows_Tools\Setup.exe
    O33 - MountPoints2\{db3f364d-6f1d-11de-8cfd-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
    O33 - MountPoints2\{db3f3652-6f1d-11de-8cfd-000fb0c96c99}\Shell\AutoRun\command - "" = E:\InstallTomTomHOME.exe
    O33 - MountPoints2\{dfde2ec4-9196-11df-84b8-000fb0c96c99}\Shell\AutoRun\command - "" = F:\InstallTomTomHOME.exe
    [2012/01/03 18:09:52 | 001,008,141 | ---- | M] () -- C:\Documents and Settings\Chema Alvarez\Escritorio\iExplore.exe
    [5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    C:\hgu.bat
    D:\hgu.bat
    E:\hgu.bat
    F:\hgu.bat
    G:\hgu.bat
    H:\hgu.bat
    I:\hgu.bat
    C:\ybj8df.exe
    D:\ybj8df.exe
    E:\ybj8df.exe
    F:\ybj8df.exe
    G:\ybj8df.exe
    H:\ybj8df.exe
    I:\ybj8df.exe
    C:\RECYCLE
    D:\RECYCLE
    E:\RECYCLE
    F:\RECYCLE
    G:\RECYCLE
    H:\RECYCLE
    I:\RECYCLE
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
    [reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done


Download and Install Combofix

Download ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop *

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
  • 0

#3
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP