This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Hi, I have problems with DVD burner.

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I have problems with my DVD & CD Burn, copy does not complete the CD and sends me an error message and then I damage the CD.
I Scan the Malwarebytes and detected a few infected files.
I wanted you to help me properly disinfected my PC and see if we get out of this problem.
I speak Spanish and Italian but little English.
Thanks


This is the LOG file:
________________________________________________
11Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 06:54:16 p.m., on 03/06/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
L:\WINDOWS\System32\smss.exe
L:\WINDOWS\system32\winlogon.exe
L:\WINDOWS\system32\services.exe
L:\WINDOWS\system32\lsass.exe
L:\WINDOWS\system32\Ati2evxx.exe
L:\WINDOWS\system32\svchost.exe
L:\WINDOWS\System32\svchost.exe
L:\WINDOWS\system32\svchost.exe
L:\WINDOWS\system32\Ati2evxx.exe
L:\WINDOWS\system32\spoolsv.exe
L:\Archivos de programa\Archivos comunes\LogiShrd\LVMVFM\LVPrcSrv.exe
L:\Archivos de programa\Creative\Shared Files\CTAudSvc.exe
L:\WINDOWS\system32\CTsvcCDA.EXE
L:\Archivos de programa\Archivos comunes\LogiShrd\LVCOMSER\LVComSer.exe
L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe
L:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
L:\WINDOWS\system32\HPZipm12.exe
L:\Archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
L:\Archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
L:\WINDOWS\Explorer.EXE
L:\WINDOWS\RTHDCPL.EXE
L:\Archivos de programa\Unlocker\UnlockerAssistant.exe
L:\Archivos de programa\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
L:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
L:\Archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe
L:\WINDOWS\system32\CTHELPER.EXE
L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe
L:\Archivos de programa\ATI Multimedia\main\launchpd.exe
L:\Archivos de programa\ATI Multimedia\main\ATIDtct.EXE
L:\Archivos de programa\ATI Multimedia\RemCtrl\ATIRW.exe
L:\Archivos de programa\DAEMON Tools Lite\DTLite.exe
L:\Archivos de programa\Creative\Shared Files\CTSched.exe
L:\WINDOWS\system32\ctfmon.exe
L:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
L:\Archivos de programa\Logitech\SetPoint\SetPoint.exe
L:\WINDOWS\system32\rundll32.exe
L:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
L:\Archivos de programa\Archivos comunes\Logishrd\KHAL2\KHALMNPR.EXE
L:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
L:\Archivos de programa\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
L:\Archivos de programa\Mozilla Firefox\firefox.exe
L:\Archivos de programa\Java\jre6\bin\java.exe
L:\WINDOWS\System32\svchost.exe
L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
L:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
L:\WINDOWS\system32\svchost.exe
I:\Programs\nu2menu\nu2menu.exe
I:\Programs\nu2menu\nu2menu.exe
L:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
L:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.ve/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 60.190.218.24 www.kavkiskey.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - L:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - L:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - L:\Archivos de programa\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - L:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - L:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - L:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - L:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - L:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [UnlockerAssistant] "L:\Archivos de programa\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [StartCCC] "L:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVP] "L:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [CTSysVol] L:\Archivos de programa\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "L:\Archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "L:\Archivos de programa\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [QuickTime Task] "L:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ATI Launchpad] "L:\Archivos de programa\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] "L:\Archivos de programa\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKCU\..\Run: [ATI Remote Control] "L:\Archivos de programa\ATI Multimedia\RemCtrl\ATIRW.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "L:\Archivos de programa\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RCSystem] "L:\Archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem *
O4 - HKCU\..\Run: [CreativeTaskScheduler] "L:\Archivos de programa\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [ctfmon.exe] L:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] L:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = L:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Inicio rápido de Adobe Acrobat.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = L:\Archivos de programa\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Anexar a PDF existente - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir a Adobe PDF - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir destino de vínculo a PDF existente - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir destino de vínculo en archivo Adobe PDF - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir selección a Adobe PDF - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir selección a archivo PDF existente - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir vínculos seleccionados a Adobe PDF - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir vínculos seleccionados a PDF existente - res://L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://L:\ARCHIV~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Estadísticas de protección del tráfico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - L:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - L:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - L:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - L:\Archivos de programa\ATI Multimedia\dtv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - L:\ARCHIV~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - L:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - L:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - L:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - L:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15111/CTPID.cab
O20 - AppInit_DLLs: L:\ARCHIV~1\KASPER~1\KASPER~1\mzvkbd3.dll
O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - L:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - L:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - L:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - L:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - L:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - L:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - L:\Archivos de programa\Archivos comunes\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - L:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - L:\Archivos de programa\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Unknown owner - L:\WINDOWS\System32\dmadmin.exe
O23 - Service: Registro de sucesos (Eventlog) - Unknown owner - L:\WINDOWS\system32\services.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - L:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Servicio COM de grabación de CD de IMAPI (ImapiService) - Unknown owner - L:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - L:\Archivos de programa\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - L:\Archivos de programa\Archivos comunes\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - L:\Archivos de programa\Archivos comunes\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - L:\Archivos de programa\Archivos comunes\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - L:\Archivos de programa\Archivos comunes\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MBAMService - Malwarebytes Corporation - L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Escritorio remoto compartido de NetMeeting (mnmsrvc) - Unknown owner - L:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - L:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - L:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - L:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Administrador de sesión de Ayuda de escritorio remoto (RDSessMgr) - Unknown owner - L:\WINDOWS\system32\sessmgr.exe
O23 - Service: Tarjeta inteligente (SCardSvr) - Unknown owner - L:\WINDOWS\System32\SCardSvr.exe
O23 - Service: ServiceLayer - Nokia - L:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Registros y alertas de rendimiento (SysmonLog) - Unknown owner - L:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - L:\Archivos de programa\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - L:\Archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: Instantáneas de volumen (VSS) - Unknown owner - L:\WINDOWS\System32\vssvc.exe
O23 - Service: Adaptador de rendimiento de WMI (WmiApSrv) - Unknown owner - L:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Servicio de uso compartido de red del Reproductor de Windows Media (WMPNetworkSvc) - Unknown owner - L:\Archivos de programa\Windows Media Player\WMPNetwk.exe

–
End of file - 14421 bytes


=================================================================


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:08:23,74 on 03/06/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.3071.2106 [GMT -4,5:30]

AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

L:\WINDOWS\system32\Ati2evxx.exe
L:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
L:\WINDOWS\System32\svchost.exe -k netsvcs
L:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
L:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
L:\WINDOWS\system32\spoolsv.exe
L:\Archivos de programa\Archivos comunes\LogiShrd\LVMVFM\LVPrcSrv.exe
L:\Archivos de programa\Creative\Shared Files\CTAudSvc.exe
L:\WINDOWS\system32\CTsvcCDA.EXE
L:\Archivos de programa\Archivos comunes\LogiShrd\LVCOMSER\LVComSer.exe
L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe
L:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
L:\WINDOWS\system32\HPZipm12.exe
L:\Archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
L:\Archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
L:\WINDOWS\Explorer.EXE
L:\WINDOWS\RTHDCPL.EXE
L:\Archivos de programa\Unlocker\UnlockerAssistant.exe
L:\Archivos de programa\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
L:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
L:\Archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe
L:\WINDOWS\system32\CTHELPER.EXE
L:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe
L:\Archivos de programa\ATI Multimedia\main\launchpd.exe
L:\Archivos de programa\ATI Multimedia\main\ATIDtct.EXE
L:\Archivos de programa\ATI Multimedia\RemCtrl\ATIRW.exe
L:\Archivos de programa\DAEMON Tools Lite\DTLite.exe
L:\Archivos de programa\Creative\Shared Files\CTSched.exe
L:\WINDOWS\system32\ctfmon.exe
L:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
L:\Archivos de programa\Logitech\SetPoint\SetPoint.exe
L:\WINDOWS\system32\rundll32.exe
L:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
L:\Archivos de programa\Archivos comunes\Logishrd\KHAL2\KHALMNPR.EXE
L:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
L:\Archivos de programa\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
L:\Archivos de programa\Mozilla Firefox\firefox.exe
L:\Archivos de programa\Java\jre6\bin\java.exe
L:\WINDOWS\System32\svchost.exe -k HTTPFilter
L:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
L:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
L:\WINDOWS\system32\svchost.exe -k imgsvc
I:\Programs\nu2menu\nu2menu.exe
I:\Programs\nu2menu\nu2menu.exe
L:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
L:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe
L:\WINDOWS\system32\NOTEPAD.EXE
L:\Documents and Settings\Gabriel_Ch\Escritorio\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.ve/
uInternet Settings,ProxyOverride = localhost
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - l:\archivos de programa\archivos

comunes\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - l:\archivos de programa\kaspersky lab\kaspersky anti-virus 2009\ievkbd.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - l:\archivos de programa\microsoft\search enhancement pack\search

helper\SEPsearchhelperie.dll
BHO: Windows Live Aplicación auxiliar de inicio de sesión: {9030d464-4c02-4abf-8ecc-5164760863c6} - l:\archivos de programa\archivos

comunes\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - l:\archivos de programa\adobe\acrobat

8.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - l:\archivos de programa\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - l:\archivos de programa\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - l:\archivos de

programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - l:\archivos de programa\windows live\toolbar\wltcore.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: []
uRun: [ATI Launchpad] "l:\archivos de programa\ati multimedia\main\launchpd.exe"
uRun: [ATI DeviceDetect] "l:\archivos de programa\ati multimedia\main\ATIDtct.EXE"
uRun: [ATI Remote Control] "l:\archivos de programa\ati multimedia\remctrl\ATIRW.exe"
uRun: [DAEMON Tools Lite] "l:\archivos de programa\daemon tools lite\DTLite.exe" -autorun
uRun: [RCSystem] "l:\archivos de programa\creative\shared files\module loader\DLLML.exe" RCSystem *
uRun: [CreativeTaskScheduler] "l:\archivos de programa\creative\shared files\CTSched.exe" /logon
uRun: [ctfmon.exe] l:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [UnlockerAssistant] "l:\archivos de programa\unlocker\UnlockerAssistant.exe" -H
mRun: [StartCCC] "l:\archivos de programa\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [AVP] "l:\archivos de programa\kaspersky lab\kaspersky anti-virus 2009\avp.exe"
mRun: [CTSysVol] l:\archivos de programa\creative\sbaudigy4\surround mixer\CTSysVol.exe /r
mRun: []
mRun: [AudioDrvEmulator] "l:\archivos de programa\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "l:\archivos de

programa\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTHelper] CTHELPER.EXE
mRun: [Malwarebytes' Anti-Malware] "l:\archivos de programa\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [QuickTime Task] "l:\archivos de programa\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] l:\windows\system32\CTFMON.EXE
StartupFolder: l:\docume~1\alluse~1\menini~1\progra~1\inicio\hpdigi~1.lnk - l:\archivos de programa\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: l:\docume~1\alluse~1\menini~1\progra~1\inicio\inicio~1.lnk -

l:\windows\installer\{ac76ba86-1040-7d00-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: l:\docume~1\alluse~1\menini~1\progra~1\inicio\logite~1.lnk - l:\archivos de programa\logitech\setpoint\SetPoint.exe
IE: Anexar a PDF existente - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir a Adobe PDF - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir destino de vínculo a PDF existente - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo Adobe PDF - l:\archivos de programa\adobe\acrobat

8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a Adobe PDF - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - l:\archivos de programa\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir vínculos seleccionados a Adobe PDF - l:\archivos de programa\adobe\acrobat

8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - l:\archivos de programa\adobe\acrobat

8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar a Microsoft Excel - l:\archiv~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - l:\archivos de programa\messenger\msmsgs.exe
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - l:\archivos de programa\kaspersky lab\kaspersky

anti-virus 2009\SCIEPlgn.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - l:\archivos de programa\windows

live\writer\WriterBrowserExtension.dll
IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} - l:\archivos de programa\ati multimedia\dtv\EXPLBAR.DLL
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - l:\archiv~1\mi1933~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - l:\windows\system32\klogon.dll
Notify: LBTWlgn - l:\archivos de programa\archivos comunes\logitech\bluetooth\LBTWlgn.dll
AppInit_DLLs: l:\archiv~1\kasper~1\kasper~1\mzvkbd3.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - l:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - l:\docume~1\gabrie~1\datosd~1\mozilla\firefox\profiles\lv1c8r3y.default\
FF - prefs.js: browser.startup.homepage - www.google.com.ve/
FF - component: l:\documents and settings\gabriel_ch\datos de

programa\mozilla\firefox\profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: l:\documents and settings\gabriel_ch\datos de

programa\mozilla\firefox\profiles\lv1c8r3y.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc_

fireftp.dll
FF - component: l:\documents and settings\gabriel_ch\datos de

programa\mozilla\firefox\profiles\lv1c8r3y.default\extensions\[removed]\components\firetorrent.dll
FF - plugin: l:\archivos de programa\quicktime\plugins\npqtplugin8.dll
FF - plugin: l:\archivos de programa\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} -

l:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - l:\archivos de programa\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - l:\archivos de programa\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
l:\archivos de programa\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js -

pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
l:\archivos de programa\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now

unused
l:\archivos de programa\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name",

"chrome://browser/locale/browser.properties");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description",

"chrome://browser/locale/browser.properties");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
l:\archivos de programa\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 kl1;Kl1;l:\windows\system32\drivers\kl1.sys [2008-7-21 121872]
R0 klbg;Kaspersky Lab Boot Guard Driver;l:\windows\system32\drivers\klbg.sys [2008-1-29 33808]
R1 KLIF;Kaspersky Lab Driver;l:\windows\system32\drivers\klif.sys [2010-2-22 226832]
R2 acedrv11;acedrv11;l:\windows\system32\drivers\ACEDRV11.sys [2008-1-23 501560]
R2 AVP;Kaspersky Anti-Virus;l:\archivos de programa\kaspersky lab\kaspersky anti-virus 2009\avp.exe [2008-11-11 208616]
R2 MBAMService;MBAMService;l:\archivos de programa\malwarebytes' anti-malware\mbamservice.exe [2010-3-8 304464]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;l:\archivos de programa\archivos comunes\nero\nero backitup 4\NBService.exe

[2009-9-23 935208]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;l:\archivos de programa\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2010-4-19

1050440]
R3 COMMONFX.SYS;COMMONFX.SYS;l:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;l:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;l:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;l:\windows\system32\drivers\klim5.sys [2008-4-30 24592]
R3 MBAMProtector;MBAMProtector;l:\windows\system32\drivers\mbam.sys [2010-3-8 20952]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;l:\archivos de programa\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2010-2-24 10064]
S2 SeaPort;SeaPort;l:\archivos de programa\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
S3 COMMONFX;COMMONFX;l:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;l:\archivos de programa\archivos comunes\creative labs

shared\service\CTAELicensing.exe [2010-5-24 79360]
S3 CTAUDFX;CTAUDFX;l:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;l:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTERFXFX;CTERFXFX;l:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTSBLFX;CTSBLFX;l:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
S3 GarenaPEngine;GarenaPEngine;l:\docume~1\gabrie~1\config~1\temp\OXR3B9.tmp [2010-6-3 25616]

=============== Created Last 30 ================

2010-06-03 18:48 –d—– l:\archivos de programa\Trend Micro
2010-06-03 00:24 27,829 a——- l:\windows\system32\winlob32.rar
2010-06-02 18:06 298,496 a——- l:\windows\uninst.exe
2010-06-01 23:36 –d—– l:\docume~1\alluse~1\datosd~1\CrystalIdea Software
2010-06-01 22:43 66 a——- l:\windows\cdplayer.ini
2010-06-01 11:35 –d—– l:\docume~1\alluse~1\datosd~1\AVS4YOU
2010-06-01 11:35 –d—– l:\docume~1\gabrie~1\datosd~1\AVS4YOU
2010-06-01 11:33 –d—– l:\archivos de programa\archivos comunes\AVSMedia
2010-06-01 11:33 24,576 a——- l:\windows\system32\msxml3a.dll
2010-05-31 23:31 245,408 a——- l:\windows\system32\unicows.dll
2010-05-31 23:30 –d—– l:\archivos de programa\Codec Pack de ELISOFT
2010-05-30 10:48 24 a——- l:\windows\system32\asfsdpc.dll
2010-05-29 16:31 –d—– l:\archivos de programa\archivos comunes\Apple
2010-05-29 16:08 –d—– l:\archivos de programa\archivos comunes\DigiDesign
2010-05-29 15:44 –d—– l:\archivos de programa\Audio Effect
2010-05-29 12:36 24 a——- l:\windows\system32\kadmdc.dll
2010-05-28 08:51 24 a——- l:\windows\system32\ipxrwmgr.dll
2010-05-27 20:35 0 a——- l:\windows\WinHDM.INI
2010-05-27 09:38 –d—– l:\docume~1\gabrie~1\datosd~1\GetRightToGo
2010-05-26 23:34 30,536 a——- l:\windows\system32\TURegOpt.exe
2010-05-26 23:34 30,024 a——- l:\windows\system32\uxtuneup.dll
2010-05-26 15:55 24 a——- l:\windows\system32\crpt32.dll
2010-05-26 00:42 1,080 a——- l:\windows\system32\settingsbkup.sfm
2010-05-26 00:42 1,080 a——- l:\windows\system32\settings.sfm
2010-05-25 21:38 32 a——- l:\windows\system32\w3data.vss
2010-05-25 21:38 32 a——- l:\windows\system32\msvcsv60.dll
2010-05-25 21:38 32 a——- l:\windows\msocreg32.dat
2010-05-25 21:24 –d—– l:\archivos de programa\Audio Plugins
2010-05-25 21:02 –d—– l:\documents and settings\gabriel_ch\dwhelper
2010-05-25 01:27 24 a——- l:\windows\system32\cnptcfg.dll
2010-05-25 01:20 –d—– l:\archivos de programa\archivos comunes\Adobe Systems Shared
2010-05-25 01:00 86 a——- l:\windows\CTWave32.ini
2010-05-24 20:51 42 a——- l:\windows\MixBUda.INI
2010-05-24 19:10 24 a——- l:\windows\system32\atmqvcno.dll
2010-05-24 19:07 30,168 a——- l:\windows\system32\BMXCtrlState-{00000001-00000000-00000001-00001102-00000004-20071102}.rfx
2010-05-24 19:07 30,168 a——-

l:\windows\system32\BMXBkpCtrlState-{00000001-00000000-00000001-00001102-00000004-20071102}.rfx
2010-05-24 19:07 11,564 a——- l:\windows\system32\DVCState-{00000001-00000000-00000001-00001102-00000004-20071102}.rfx
2010-05-24 19:07 4,932,917 ——– l:\windows\{00000001-00000000-00000001-00001102-00000004-20071102}.BAK
2010-05-24 19:07 4,932,917 a——- l:\windows\{00000001-00000000-00000001-00001102-00000004-20071102}.CDF
2010-05-24 19:06 –d—– l:\archivos de programa\archivos comunes\Creative Labs Shared
2010-05-24 18:31 65,536 ——– l:\windows\system32\ctdvda32.dll
2010-05-24 16:53 –d—– l:\docume~1\gabrie~1\datosd~1\Smart Recorder
2010-05-20 10:28 24 a——- l:\windows\system32\ifbutil.dll
2010-05-19 21:31 45,056 a——- l:\windows\system32\WNASPI32.DLL
2010-05-19 21:31 16,512 a——- l:\windows\system32\drivers\ASPI32.SYS
2010-05-19 21:31 –d—– l:\archivos de programa\ImTOO
2010-05-19 21:23 87,608 a——- l:\docume~1\gabrie~1\datosd~1\inst.exe
2010-05-19 21:23 47,360 a——- l:\windows\system32\drivers\pcouffin.sys
2010-05-19 21:23 47,360 a——- l:\docume~1\gabrie~1\datosd~1\pcouffin.sys
2010-05-19 21:22 217,127 a——- l:\windows\system32\drv43260.dll
2010-05-19 21:22 208,935 a——- l:\windows\system32\drv33260.dll
2010-05-19 21:22 176,165 a——- l:\windows\system32\drv23260.dll
2010-05-19 21:22 102,439 a——- l:\windows\system32\sipr3260.dll
2010-05-19 21:22 65,602 a——- l:\windows\system32\cook3260.dll
2010-05-19 21:22 1,184,984 a——- l:\windows\system32\wvc1dmod.dll
2010-05-19 21:22 626,688 a——- l:\windows\system32\vp7vfw.dll
2010-05-19 21:22 –d—– l:\archivos de programa\VSO
2010-05-19 20:11 152,576 a——- l:\windows\system32\IWUninstall.exe
2010-05-19 20:10 385,100 a——- l:\windows\system32\MSVCRTD.DLL
2010-05-19 20:10 94,285 a——- l:\windows\system32\MSVCIRTD.DLL
2010-05-19 20:10 54,784 a——- l:\windows\system32\Inetwh32.dll
2010-05-19 20:10 610,816 a——- l:\windows\system32\vobhw.dll
2010-05-19 20:10 19,456 a——- l:\windows\system32\asapi.dll
2010-05-19 20:10 10,240 a——- l:\windows\system32\drivers\asapiw2k.sys
2010-05-19 20:10 10,240 a——- l:\windows\system32\drivers\asapi.sys
2010-05-19 20:10 –d—– l:\archivos de programa\InstantCD+DVD
2010-05-19 20:09 327,168 a——- l:\windows\IsUn040a.exe
2010-05-19 19:48 –d—– l:\archivos de programa\MediaInfo
2010-05-17 15:13 691,696 a——- l:\windows\system32\drivers\sptd.sys
2010-05-17 15:13 –d—– l:\archivos de programa\DAEMON Tools Lite
2010-05-17 15:12 –d—– l:\docume~1\gabrie~1\datosd~1\DAEMON Tools Lite
2010-05-17 15:12 –d—– l:\docume~1\alluse~1\datosd~1\DAEMON Tools Lite
2010-05-16 08:45 32,656 a——- l:\windows\system32\msonpmon.dll
2010-05-14 22:15 –d—– l:\archivos de programa\Yursoft
2010-05-14 20:54 –d—– l:\archivos de programa\GetData
2010-05-14 00:40 –d—– l:\archivos de programa\Compaq
2010-05-14 00:40 –d—– L:\CPQSYSTEM
2010-05-13 23:34 12,928 a——- l:\windows\system32\drivers\filedisk.sys
2010-05-13 23:34 –d—– l:\archivos de programa\WinImage
2010-05-13 23:19 –d—– l:\archivos de programa\XLS Regenerator
2010-05-13 23:17 –d—– l:\archivos de programa\DOC Regenerator
2010-05-13 22:10 –d—– l:\archivos de programa\HDD Regenerator
2010-05-12 21:40 12 a——- l:\windows\flpass.dll
2010-05-11 01:54 –d—– l:\archivos de programa\VirtualDub-1.8.8
2010-05-11 01:53 –d—– l:\docume~1\gabrie~1\datosd~1\VideoReDo-TVSuite
2010-05-11 01:52 –d—– l:\archivos de programa\VideoReDoTVSuite
2010-05-11 01:50 –d—– l:\archivos de programa\Ultra Tag Editor
2010-05-11 01:48 –d—– l:\archivos de programa\Total Video Converter
2010-05-11 01:34 –d—– l:\archivos de programa\Stellar Phoenix
2010-05-11 01:34 –d—– l:\archivos de programa\File Scavenger V3.2
2010-05-11 01:31 –d—– l:\archivos de programa\FixPasbr SYMANTEC w32
2010-05-11 01:30 –d—– l:\archivos de programa\DivFix 1.10
2010-05-11 01:25 –d—– l:\archivos de programa\Craagle 3.0
2010-05-11 01:25 –d—– l:\archivos de programa\All Video Fixer
2010-05-11 01:25 –d—– l:\archivos de programa\All Media Fixer 2008
2010-05-11 01:21 –d—– l:\docume~1\gabrie~1\datosd~1\Axialis
2010-05-11 01:20 –d—– l:\docume~1\gabrie~1\datosd~1\IndigoRose

==================== Find3M ====================

2010-06-03 18:47 1,310,752 a–sh— l:\windows\system32\drivers\fidbox2.dat
2010-06-03 18:47 16,040 a–sh— l:\windows\system32\drivers\fidbox2.idx
2010-06-03 18:02 22,460,960 a–sh— l:\windows\system32\drivers\fidbox.dat
2010-06-03 18:02 196,468 a–sh— l:\windows\system32\drivers\fidbox.idx
2010-05-24 19:06 445,016 a——- l:\windows\system32\wrap_oal.dll
2010-05-24 19:06 109,144 a——- l:\windows\system32\OpenAL32.dll
2010-05-18 21:13 505,016 a——- l:\windows\system32\perfh00A.dat
2010-05-18 21:13 90,614 a——- l:\windows\system32\perfc00A.dat
2010-05-05 03:16 113,933 a——- l:\windows\system32\drivers\klin.dat
2010-05-05 03:16 97,549 a——- l:\windows\system32\drivers\klick.dat
2010-04-29 15:39 38,224 a——- l:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 15:39 20,952 a——- l:\windows\system32\drivers\mbam.sys
2010-04-08 19:35 122,330 a——- l:\windows\War3Unin.dat
2010-04-07 13:30 0 a—h— l:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-04-07 13:30 0 a—h— l:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-04-07 13:29 0 a—h— l:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-04-07 13:29 0 a—h— l:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-03-18 19:19 43,520 a——- l:\windows\system32\CTBurst.dll
2010-03-18 19:19 11,776 a——- l:\windows\system32\inres.dll
2010-03-18 19:19 182,272 a——- l:\windows\system32\ctdvinst.dll
2010-03-18 19:19 86,528 a——- l:\windows\system32\ctcoinst.dll
2010-03-18 19:18 10,752 a——- l:\windows\system32\a3d.dll
2010-03-18 19:18 11,776 a——- l:\windows\system32\ac3api.dll
2010-03-18 19:07 386,852 a——- l:\windows\system32\ctdnlstr.dat
2010-03-18 19:07 51,787 a——- l:\windows\system32\ctdlang.dat
2010-03-18 19:07 196,096 a——- l:\windows\system32\ctemupia.dll
2010-03-18 19:04 176,128 a——- l:\windows\system32\ct_oal.dll
2010-03-18 19:04 46,592 a——- l:\windows\system32\ctasio.dll
2010-03-18 19:04 49,152 a——- l:\windows\system32\ctdproxy.dll
2010-03-18 19:03 69,632 a——- l:\windows\system32\ctosuser.dll
2010-03-18 19:03 6,144 a——- l:\windows\system32\sfman32.dll
2010-03-18 19:03 125,952 a——- l:\windows\system32\sfms32.dll
2010-03-18 19:03 13,312 a——- l:\windows\system32\regplib.exe
2010-03-18 19:03 64,512 a——- l:\windows\system32\piaproxy.dll
2010-03-18 19:02 149,838 a——- l:\windows\system32\ctbas2w.dat
2010-03-18 19:00 274,587 a——- l:\windows\system32\ctsbas2w.dat
2010-03-18 19:00 241,084 a——- l:\windows\system32\CTSBASW.DAT
2010-03-18 19:00 115,166 a——- l:\windows\system32\CTBASICW.DAT
2010-03-18 18:59 313,207 a——- l:\windows\system32\ctstatic.dat
2010-03-18 18:59 53,932 a——- l:\windows\system32\ctdaught.dat
2010-03-18 18:59 5,120 a——- l:\windows\system32\enlocstr.exe
2010-03-18 18:59 10,240 a——- l:\windows\system32\killapps.exe
2010-03-18 18:59 28,672 a——- l:\windows\system32\MIDIDEF.EXE
2010-03-18 18:59 33,792 a——- l:\windows\system32\devreg.dll
2010-03-17 15:14 737,280 a——- l:\windows\iun6002.exe
2010-03-12 14:55 17,772,264 a——- l:\windows\system32\AppSetup.exe
2010-03-10 01:46 420,352 a——- l:\windows\system32\vbscript.dll
2010-03-08 20:17 139,264 a——- l:\windows\War3Unin.exe
2010-03-08 20:17 2,829 a——- l:\windows\War3Unin.pif
2010-02-23 10:01 4 —shr– l:\docume~1\alluse~1\datosd~1\sysqcl1129139270.dat

============= FINISH: 19:09:20,85 ===============
Hi,

I would be very happy to try and help you, but all my instructions would be in English.

I know of an excellent Spanish speaking forum, who will give you the same expert guidance and help that you would recive here at WhattheTech, but you may feel more comfortable there as their instructions will be Spanish:

http://www.forospyware.com/

Please let me know if you wish to proceed here, or join the Spanish speaking forum?

Thank-you

~CB




Google Translation:

¡Hola!

Yo sería muy feliz para tratar de ayudarle, pero todos mis instrucciones estaría en Inglés.

Yo sé de un foro de habla española excelente, que le dará la misma orientación de expertos y la ayuda que usted recive de aquí en WhattheTech, pero puede que se sienta más cómodo allí como sus instrucciones serán el español:

http://www.forospyware.com/

Por favor, hágamelo saber si usted desea continuar aquí, o participar en el foro de habla española?

De agradecimiento

Let's try, I speak some English do not worry, I do not understand what Translates :) Check if what you post on the forum have any suspicious software please. Thenks.
OK,

Please do the following:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I commented, I did what I stated, but the "gmer.exe" when it has 60% have scanned my Windows PC freezes, my mouse moves in intervals of 2 sec, imposibol to move, I have to force shutdown of the PC. Try to pass a fail-safe mode and does the same. It may be a virus that attacks the memory? I really do not know how to scan the PC with your program gmer.exe ", closed the Kaspersky and Malwarebytes' Anti-Malware when you activate the gmer.exe but did the same. I can enter Windows without any problems and my PC is not slow, just something strange when using the burners. I followed all the steps OK
OK

Please run this program instead:

Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".

Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.

Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.

Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.

Finally, please open this report with Notepad, and post it here.
JAJAJA. Definitely this PC not want to be scanned by anything or anyone. See when you scan everything but at the end and ask for the report, sends me this error message. ____________________________________________ ROOTREPEAL CRASH REPORT ————————- Windows Version: Windows XP SP3 Exception Code: 0xc0000005 Exception Address: 0x7c921909 Attempt to read from address: 0xfffffff0 ____________________________________________ This program is not compatible with Windows SP3? I commented, anti virus detected me like a virus, disable the two order not to create problems before to scan, OK Damm.
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Ok, that if you owned the PC and does not throw any error message. Microsoft Console installed and then reboot suddenly, I realize 50 process, and record the TXT file.
Now what remains is to try and wait to see if the problem was resolved.
I'd like to answer a few questions:

1. ComboFix.exe file I have to leave it on the desktop for another time?
2. I created two folders in L: \
a ) ComboFix
b ) Qoobox (this seems to have files and records in Quarantine for restoration. I donn´t not)

I can delete these folders or do I leave them for a lifetime?
3. According to the report can tell me if I had some virus that affected me the burners?
4. I have to go back to run the other two programs to send me before?

We are in contact, I went on a big help.

Thanks for your time. :D



LOGFILE:
___________________________________________________________________________

ComboFix 10-06-10.03 - Gabriel_Ch 10/06/2010 22:12:30.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.3071.2530 [GMT -4,5:30]
Running from: l:\documents and settings\[removed]\Escritorio\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\resycled
l:\documents and settings\Gabriel_Ch\Datos de programa\inst.exe
l:\windows\flpass.dll
l:\windows\system32\asfsdpc.dll
l:\windows\system32\atmqvcno.dll
l:\windows\system32\cnptcfg.dll
l:\windows\system32\crpt32.dll
l:\windows\system32\ifbutil.dll
l:\windows\system32\ipxrwmgr.dll
l:\windows\system32\kadmdc.dll
l:\windows\system32\msvcsv60.dll

.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.

2010-06-10 22:41 . 2010-06-10 22:41 ——– d—–w- l:\archivos de programa\Zeallsoft
2010-06-10 21:16 . 2010-06-10 21:16 ——– d—–w- l:\archivos de programa\Alwil Software
2010-06-10 18:50 . 2010-06-11 02:35 ——– d—–w- l:\archivos de programa\7-Zip
2010-06-10 18:44 . 2010-06-10 18:45 ——– d—–w- l:\archivos de programa\neuronshell
2010-06-10 18:24 . 2010-06-10 18:24 ——– d—–w- l:\archivos de programa\neuronpedisassembler
2010-06-10 14:26 . 2010-06-10 20:40 ——– d—–w- l:\archivos de programa\JDownloader
2010-06-09 22:01 . 2010-06-09 22:01 ——– d—–w- l:\documents and settings\Administrador.OFICINA-TALLER\Datos de programa\Malwarebytes
2010-06-09 21:41 . 2010-06-09 21:41 ——– d-sh–w- l:\documents and settings\Administrador.OFICINA-TALLER\PrivacIE
2010-06-09 21:21 . 2010-06-09 21:41 ——– d—–w- l:\documents and settings\Administrador.OFICINA-TALLER
2010-06-09 18:48 . 2010-06-09 18:48 98304 —-a-w- l:\windows\system32\CmdLineExt.dll
2010-06-08 18:07 . 2007-01-11 08:32 113664 —-a-w- l:\documents and settings\All Users\Datos de programa\EPSON\EPW!3 SSRP\E_S40RP7.EXE
2010-06-08 18:07 . 2010-06-08 18:07 ——– d—–w- l:\documents and settings\All Users\Datos de programa\EPSON
2010-06-07 00:52 . 2010-05-07 14:53 30024 —-a-w- l:\windows\system32\uxtuneup.dll
2010-06-04 20:03 . 2010-06-04 20:03 160704 —-a-w- l:\windows\system32\drivers\afcdp.sys
2010-06-04 20:03 . 2010-06-04 20:03 911680 —-a-w- l:\windows\system32\drivers\tdrpm258.sys
2010-06-04 20:03 . 2010-06-04 20:03 581984 —-a-w- l:\windows\system32\drivers\timntr.sys
2010-06-04 20:03 . 2010-06-04 20:03 166272 —-a-w- l:\windows\system32\drivers\snapman.sys
2010-06-04 20:03 . 2010-06-04 20:03 ——– d—–w- l:\archivos de programa\Archivos comunes\Acronis
2010-06-04 20:03 . 2010-06-04 20:03 ——– d—–w- l:\archivos de programa\Acronis
2010-06-04 01:34 . 2010-06-04 01:34 ——– d—–w- l:\archivos de programa\AoaoWatermark
2010-06-04 00:41 . 2010-06-04 00:42 ——– d—–w- l:\archivos de programa\Acez All Audio Converter
2010-06-03 23:18 . 2010-06-03 23:18 ——– d—–w- l:\archivos de programa\Trend Micro
2010-06-03 00:58 . 2010-05-23 22:20 73216 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
2010-06-03 00:58 . 2010-04-18 19:03 307200 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
2010-06-03 00:58 . 2010-04-18 19:03 172032 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
2010-06-02 22:36 . 1996-10-15 22:31 298496 —-a-w- l:\windows\uninst.exe
2010-06-02 04:06 . 2010-06-02 04:06 ——– d—–w- l:\documents and settings\All Users\Datos de programa\CrystalIdea Software
2010-06-01 16:05 . 2010-06-01 16:05 ——– d—–w- l:\documents and settings\All Users\Datos de programa\AVS4YOU
2010-06-01 16:05 . 2010-06-01 16:44 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\AVS4YOU
2010-06-01 16:03 . 2010-06-02 02:51 ——– d—–w- l:\archivos de programa\Archivos comunes\AVSMedia
2010-06-01 16:03 . 2003-05-21 18:20 24576 —-a-w- l:\windows\system32\msxml3a.dll
2010-06-01 04:01 . 2003-04-21 13:09 245408 —-a-w- l:\windows\system32\unicows.dll
2010-06-01 04:00 . 2010-06-01 04:03 ——– d—–w- l:\archivos de programa\Codec Pack de ELISOFT
2010-05-29 21:08 . 2010-05-29 21:08 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Apple Computer
2010-05-29 21:01 . 2010-05-29 21:01 ——– d—–w- l:\archivos de programa\Archivos comunes\Apple
2010-05-29 21:01 . 2010-05-29 21:01 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Apple
2010-05-29 20:38 . 2010-05-29 20:38 ——– d—–w- l:\archivos de programa\Archivos comunes\DigiDesign
2010-05-29 20:14 . 2010-05-29 22:53 ——– d—–w- l:\archivos de programa\Audio Effect
2010-05-27 14:08 . 2010-05-27 14:08 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\GetRightToGo
2010-05-27 04:04 . 2010-05-07 14:59 30536 —-a-w- l:\windows\system32\TURegOpt.exe
2010-05-26 02:08 . 2010-05-29 23:18 32 —-a-w- l:\windows\msocreg32.dat
2010-05-26 01:54 . 2010-05-29 22:13 ——– d—–w- l:\archivos de programa\Audio Plugins
2010-05-26 01:32 . 2010-05-26 01:32 ——– d—–w- l:\documents and settings\Gabriel_Ch\dwhelper
2010-05-25 06:12 . 2010-05-25 06:12 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Apple Computer
2010-05-25 05:51 . 2010-05-25 05:51 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Adobe Systems
2010-05-25 05:50 . 2010-05-25 05:50 ——– d—–w- l:\archivos de programa\Archivos comunes\Adobe Systems Shared
2010-05-25 03:55 . 2008-04-14 12:00 621344 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Mswstr10.dll
2010-05-25 03:55 . 2008-04-14 12:00 60192 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjter40.dll
2010-05-25 03:55 . 2008-04-14 12:00 57344 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msadrh15.dll
2010-05-25 03:55 . 2008-04-14 12:00 536576 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msado15.dll
2010-05-25 03:55 . 2008-04-14 12:00 380445 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Expsrv.dll
2010-05-25 03:55 . 2008-04-14 12:00 355112 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjetoledb40.dll
2010-05-25 03:55 . 2008-04-14 12:00 30749 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\vbajet32.dll
2010-05-25 03:55 . 2008-04-14 12:00 248608 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjtes40.dll
2010-05-25 03:55 . 2008-04-14 12:00 200704 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msadox.dll
2010-05-25 03:55 . 2008-04-14 12:00 187168 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjint40.dll
2010-05-25 03:55 . 2008-04-14 12:00 1516568 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjet40.dll
2010-05-25 03:55 . 2008-04-14 12:00 102400 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative\Media Database\JetFileBackup\Msjro.dll
2010-05-24 23:36 . 2010-05-24 23:36 ——– d—–w- l:\archivos de programa\Archivos comunes\Creative Labs Shared
2010-05-24 23:01 . 2008-06-13 15:43 65536 ——w- l:\windows\system32\ctdvda32.dll
2010-05-24 21:23 . 2010-05-24 21:23 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Smart Recorder
2010-05-20 02:18 . 2010-05-20 02:18 2227712 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\[removed]\components\firetorrent.dll
2010-05-20 02:01 . 2010-05-13 08:02 45056 —-a-w- l:\windows\system32\WNASPI32.DLL
2010-05-20 02:01 . 2010-05-13 08:02 16512 —-a-w- l:\windows\system32\drivers\ASPI32.SYS
2010-05-20 02:01 . 2010-06-02 04:48 ——– d—–w- l:\archivos de programa\ImTOO
2010-05-20 02:01 . 2010-06-04 16:20 ——– d—–w- l:\archivos de programa\QuickTime
2010-05-20 01:53 . 2010-06-02 04:41 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Vso
2010-05-20 01:53 . 2010-05-20 01:53 47360 —-a-w- l:\windows\system32\drivers\pcouffin.sys
2010-05-20 01:53 . 2010-05-20 01:53 47360 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\pcouffin.sys
2010-05-20 01:52 . 2010-02-09 20:07 65602 —-a-w- l:\windows\system32\cook3260.dll
2010-05-20 01:52 . 2010-02-09 20:07 217127 —-a-w- l:\windows\system32\drv43260.dll
2010-05-20 01:52 . 2010-02-09 20:07 208935 —-a-w- l:\windows\system32\drv33260.dll
2010-05-20 01:52 . 2010-02-09 20:07 176165 —-a-w- l:\windows\system32\drv23260.dll
2010-05-20 01:52 . 2010-02-09 20:07 102439 —-a-w- l:\windows\system32\sipr3260.dll
2010-05-20 01:52 . 2010-02-09 20:07 626688 —-a-w- l:\windows\system32\vp7vfw.dll
2010-05-20 01:52 . 2010-02-09 20:07 1184984 —-a-w- l:\windows\system32\wvc1dmod.dll
2010-05-20 01:52 . 2010-05-20 01:52 ——– d—–w- l:\archivos de programa\VSO
2010-05-20 00:41 . 2002-07-23 14:41 152576 —-a-w- l:\windows\system32\IWUninstall.exe
2010-05-20 00:40 . 1998-10-20 20:35 54784 —-a-w- l:\windows\system32\Inetwh32.dll
2010-05-20 00:40 . 1998-06-17 13:30 94285 —-a-w- l:\windows\system32\MSVCIRTD.DLL
2010-05-20 00:40 . 1998-06-17 13:30 385100 —-a-w- l:\windows\system32\MSVCRTD.DLL
2010-05-20 00:40 . 2002-08-12 19:23 610816 —-a-w- l:\windows\system32\vobhw.dll
2010-05-20 00:40 . 2000-04-27 17:01 19456 —-a-w- l:\windows\system32\asapi.dll
2010-05-20 00:40 . 2000-01-08 13:52 10240 —-a-w- l:\windows\system32\drivers\asapiw2k.sys
2010-05-20 00:40 . 2000-01-08 13:52 10240 —-a-w- l:\windows\system32\drivers\asapi.sys
2010-05-20 00:40 . 2010-06-02 04:38 ——– d—–w- l:\archivos de programa\InstantCD+DVD
2010-05-20 00:39 . 1998-10-06 23:04 327168 —-a-w- l:\windows\IsUn040a.exe
2010-05-20 00:18 . 2010-05-20 00:18 ——– d—–w- l:\archivos de programa\MediaInfo
2010-05-17 19:43 . 2010-05-17 19:43 691696 —-a-w- l:\windows\system32\drivers\sptd.sys
2010-05-17 19:43 . 2010-05-17 19:43 ——– d—–w- l:\archivos de programa\DAEMON Tools Lite
2010-05-17 19:42 . 2010-05-18 00:18 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\DAEMON Tools Lite
2010-05-17 19:42 . 2010-05-17 19:42 ——– d—–w- l:\documents and settings\All Users\Datos de programa\DAEMON Tools Lite
2010-05-16 13:15 . 2008-11-10 16:11 32656 —-a-w- l:\windows\system32\msonpmon.dll
2010-05-16 13:15 . 2006-10-27 00:26 33104 —-a-w- l:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-05-15 02:45 . 2010-05-15 02:45 ——– d—–w- l:\archivos de programa\Yursoft
2010-05-15 01:24 . 2010-05-15 01:24 ——– d—–w- l:\archivos de programa\GetData
2010-05-14 05:10 . 2010-05-14 05:10 ——– d—–w- l:\archivos de programa\Compaq
2010-05-14 05:10 . 2010-05-14 05:10 ——– d—–w- L:\CPQSYSTEM
2010-05-14 04:04 . 2010-05-14 04:04 12928 —-a-w- l:\windows\system32\drivers\filedisk.sys
2010-05-14 04:04 . 2010-05-14 04:04 ——– d—–w- l:\archivos de programa\WinImage
2010-05-14 03:49 . 2010-05-14 04:12 ——– d—–w- l:\archivos de programa\XLS Regenerator
2010-05-14 03:47 . 2010-05-14 03:47 ——– d—–w- l:\archivos de programa\DOC Regenerator
2010-05-14 02:40 . 2010-05-14 05:35 ——– d—–w- l:\archivos de programa\HDD Regenerator

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-11 02:51 . 2010-02-22 05:48 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Kaspersky Lab
2010-06-11 02:47 . 2010-02-22 05:48 23758368 –sha-w- l:\windows\system32\drivers\fidbox.dat
2010-06-11 02:47 . 2010-02-22 05:48 206604 –sha-w- l:\windows\system32\drivers\fidbox.idx
2010-06-11 02:47 . 2010-02-22 05:48 16236 –sha-w- l:\windows\system32\drivers\fidbox2.idx
2010-06-11 02:47 . 2010-02-22 05:48 1368096 –sha-w- l:\windows\system32\drivers\fidbox2.dat
2010-06-10 15:58 . 2010-02-19 18:00 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Image Zone Express
2010-06-09 18:34 . 2010-02-19 18:07 ——– d–h–w- l:\archivos de programa\InstallShield Installation Information
2010-06-09 05:58 . 2010-03-09 01:23 ——– d—–w- l:\archivos de programa\Garena
2010-06-08 18:44 . 2008-04-14 12:00 90614 —-a-w- l:\windows\system32\perfc00A.dat
2010-06-08 18:44 . 2008-04-14 12:00 505016 —-a-w- l:\windows\system32\perfh00A.dat
2010-06-07 22:05 . 2010-03-10 19:00 188152 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\FlashGot.exe
2010-06-07 00:56 . 2010-02-21 17:05 ——– d—–w- l:\archivos de programa\TuneUp Utilities 2010
2010-06-04 13:07 . 2010-02-20 03:20 ——– d—–w- l:\archivos de programa\Microsoft Silverlight
2010-06-03 22:35 . 2010-05-11 05:55 ——– d—–w- l:\archivos de programa\Craagle 3.0
2010-06-03 15:02 . 2010-04-07 17:58 ——– d—–w- l:\archivos de programa\Archivos comunes\Nokia
2010-06-03 00:00 . 2010-03-09 00:32 ——– d—–w- l:\archivos de programa\Malwarebytes' Anti-Malware
2010-06-02 04:17 . 2010-03-02 06:22 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Nero
2010-05-27 04:04 . 2010-02-21 17:05 ——– d—–w- l:\documents and settings\All Users\Datos de programa\TuneUp Software
2010-05-25 05:50 . 2010-02-19 21:29 ——– d—–w- l:\archivos de programa\Archivos comunes\Adobe
2010-05-24 23:36 . 2010-03-01 20:21 445016 —-a-w- l:\windows\system32\wrap_oal.dll
2010-05-24 23:36 . 2010-03-01 20:21 109144 —-a-w- l:\windows\system32\OpenAL32.dll
2010-05-24 23:13 . 2010-02-28 20:10 ——– d—–w- l:\archivos de programa\Creative
2010-05-24 21:14 . 2010-03-02 06:01 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Nero
2010-05-18 01:04 . 2010-02-20 04:08 ——– d—–w- l:\documents and settings\All Users\Datos de programa\Microsoft Help
2010-05-15 15:11 . 2010-02-22 04:04 ——– d—–w- l:\documents and settings\All Users\Datos de programa\ATI MMC
2010-05-15 01:26 . 2010-05-11 06:03 ——– d—a-w- l:\documents and settings\All Users\Datos de programa\TEMP
2010-05-13 02:09 . 2010-02-19 20:44 ——– d—–w- l:\archivos de programa\Hide My Files
2010-05-11 06:24 . 2010-05-11 06:24 ——– d—–w- l:\archivos de programa\VirtualDub-1.8.8
2010-05-11 06:23 . 2010-05-11 06:23 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\VideoReDo-TVSuite
2010-05-11 06:23 . 2010-05-11 06:22 ——– d—–w- l:\archivos de programa\VideoReDoTVSuite
2010-05-11 06:20 . 2010-05-11 06:20 ——– d—–w- l:\archivos de programa\Ultra Tag Editor
2010-05-11 06:18 . 2010-05-11 06:18 ——– d—–w- l:\archivos de programa\Total Video Converter
2010-05-11 06:16 . 2010-05-11 06:04 ——– d—–w- l:\archivos de programa\Stellar Phoenix
2010-05-11 06:14 . 2010-02-19 21:03 ——– d—–w- l:\archivos de programa\Unlocker
2010-05-11 06:04 . 2010-05-11 06:04 ——– d—–w- l:\archivos de programa\File Scavenger V3.2
2010-05-11 06:01 . 2010-05-11 06:01 ——– d—–w- l:\archivos de programa\FixPasbr SYMANTEC w32
2010-05-11 06:00 . 2010-05-11 06:00 ——– d—–w- l:\archivos de programa\DivFix 1.10
2010-05-11 05:55 . 2010-05-11 05:55 ——– d—–w- l:\archivos de programa\All Video Fixer
2010-05-11 05:55 . 2010-05-11 05:55 ——– d—–w- l:\archivos de programa\All Media Fixer 2008
2010-05-11 05:51 . 2010-05-11 05:51 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Axialis
2010-05-11 05:50 . 2010-05-11 05:50 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\IndigoRose
2010-05-05 07:46 . 2010-02-22 05:48 97549 —-a-w- l:\windows\system32\drivers\klick.dat
2010-05-05 07:46 . 2010-02-22 05:48 113933 —-a-w- l:\windows\system32\drivers\klin.dat
2010-04-29 20:09 . 2010-03-09 00:32 38224 —-a-w- l:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:09 . 2010-03-09 00:32 20952 —-a-w- l:\windows\system32\drivers\mbam.sys
2010-04-21 05:02 . 2010-04-21 05:02 43008 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-04-21 05:02 . 2010-04-21 05:02 346112 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-04-21 05:02 . 2010-04-21 05:02 339456 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-04-21 05:02 . 2010-04-21 05:02 1496064 —-a-w- l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-04-18 14:40 . 2010-03-01 18:58 ——– d—–w- l:\documents and settings\Gabriel_Ch\Datos de programa\Creative
2010-04-09 00:05 . 2010-03-09 00:32 122330 —-a-w- l:\windows\War3Unin.dat
2010-04-07 17:57 . 2010-04-07 17:57 95232 —-a-w- l:\documents and settings\All Users\Datos de programa\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-07 17:57 . 2010-04-07 17:57 8192 —-a-w- l:\documents and settings\All Users\Datos de programa\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-07 17:57 . 2010-04-07 17:57 61440 —-a-w- l:\documents and settings\All Users\Datos de programa\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-07 17:57 . 2010-04-07 17:57 10240 —-a-w- l:\documents and settings\All Users\Datos de programa\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-03-30 01:04 . 2010-04-07 17:57 34554168 —-a-w- l:\documents and settings\All Users\Datos de programa\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_spa_co_web.exe
2010-03-19 01:20 . 2010-03-19 01:20 15960 —-a-w- l:\windows\system32\drivers\pfmodnt.sys
2010-03-19 01:20 . 2010-03-19 01:20 189528 —-a-w- l:\windows\system32\drivers\haP17v2k.sys
2010-03-19 01:20 . 2010-03-19 01:20 162904 —-a-w- l:\windows\system32\drivers\haP16v2k.sys
2010-03-19 01:19 . 2010-03-19 01:19 798808 —-a-w- l:\windows\system32\drivers\ha10kx2k.sys
2010-03-19 01:15 . 2010-03-19 01:15 92760 —-a-w- l:\windows\system32\drivers\emupia2k.sys
2010-03-19 01:15 . 2010-03-19 01:15 157272 —-a-w- l:\windows\system32\drivers\ctsfm2k.sys
2010-03-19 01:15 . 2010-03-19 01:15 14424 —-a-w- l:\windows\system32\drivers\ctprxy2k.sys
2010-03-19 01:15 . 2010-03-19 01:15 127576 —-a-w- l:\windows\system32\drivers\ctoss2k.sys
2010-03-19 01:11 . 2010-03-19 01:11 1372888 —-a-w- l:\windows\system32\drivers\CTMMFILT.SYS
2010-03-19 01:10 . 2010-03-19 01:10 18904 —-a-w- l:\windows\system32\drivers\CTGAME.SYS
2010-03-19 01:10 . 2010-03-19 01:10 347144 —-a-w- l:\windows\system32\drivers\ctdvda2k.sys
2010-03-19 01:10 . 2010-03-19 01:10 528472 —-a-w- l:\windows\system32\drivers\ctaud2k.sys
2010-03-19 01:10 . 2010-03-19 01:10 511064 —-a-w- l:\windows\system32\drivers\ctac32k.sys
2010-03-19 01:10 . 2010-03-19 01:10 1366488 —-a-w- l:\windows\system32\drivers\CT0531FL.SYS
2010-03-19 01:09 . 2010-03-19 01:09 100952 —-a-w- l:\windows\system32\drivers\CTERFXFX.sys
2010-03-19 01:09 . 2010-03-19 01:09 566360 —-a-w- l:\windows\system32\drivers\CTSBLFX.sys
2010-03-19 01:09 . 2010-03-19 01:09 555096 —-a-w- l:\windows\system32\drivers\CTAUDFX.sys
2010-03-19 01:09 . 2010-03-19 01:09 99416 —-a-w- l:\windows\system32\drivers\COMMONFX.sys
2010-03-18 23:49 . 2010-03-18 23:49 43520 —-a-w- l:\windows\system32\CTBurst.dll
2010-03-18 23:49 . 2010-03-18 23:49 11776 —-a-w- l:\windows\system32\inres.dll
2010-03-18 23:49 . 2004-09-23 03:31 182272 —-a-w- l:\windows\system32\ctdvinst.dll
2010-03-18 23:49 . 2004-09-23 03:31 86528 —-a-w- l:\windows\system32\ctcoinst.dll
2010-03-18 23:48 . 2010-03-18 23:48 10752 —-a-w- l:\windows\system32\a3d.dll
2010-03-18 23:48 . 2010-03-18 23:48 11776 —-a-w- l:\windows\system32\ac3api.dll
2010-03-18 23:37 . 2010-03-18 23:37 51787 —-a-w- l:\windows\system32\ctdlang.dat
2010-03-18 23:37 . 2010-03-18 23:37 386852 —-a-w- l:\windows\system32\ctdnlstr.dat
2010-03-18 23:37 . 2010-03-18 23:37 196096 —-a-w- l:\windows\system32\ctemupia.dll
2010-03-18 23:34 . 2010-03-18 23:34 176128 —-a-w- l:\windows\system32\ct_oal.dll
2010-03-18 23:34 . 2010-03-18 23:34 46592 —-a-w- l:\windows\system32\ctasio.dll
2010-03-18 23:34 . 2010-03-18 23:34 49152 —-a-w- l:\windows\system32\ctdproxy.dll
2010-03-18 23:33 . 2010-03-18 23:33 69632 —-a-w- l:\windows\system32\ctosuser.dll
2010-03-18 23:33 . 2010-03-18 23:33 6144 —-a-w- l:\windows\system32\sfman32.dll
2010-03-18 23:33 . 2010-03-18 23:33 125952 —-a-w- l:\windows\system32\sfms32.dll
2010-03-18 23:33 . 2010-03-18 23:33 13312 —-a-w- l:\windows\system32\regplib.exe
2010-03-18 23:33 . 2010-03-18 23:33 64512 —-a-w- l:\windows\system32\piaproxy.dll
2010-03-18 23:32 . 2010-03-18 23:32 149838 —-a-w- l:\windows\system32\ctbas2w.dat
2010-03-18 23:30 . 2010-03-18 23:30 274587 —-a-w- l:\windows\system32\ctsbas2w.dat
2010-03-18 23:30 . 2010-03-18 23:30 241084 —-a-w- l:\windows\system32\CTSBASW.DAT
2010-03-18 23:30 . 2010-03-18 23:30 115166 —-a-w- l:\windows\system32\CTBASICW.DAT
2010-03-18 23:29 . 2010-03-18 23:29 53932 —-a-w- l:\windows\system32\ctdaught.dat
2010-03-18 23:29 . 2010-03-18 23:29 313207 —-a-w- l:\windows\system32\ctstatic.dat
2010-03-18 23:29 . 2010-03-18 23:29 5120 —-a-w- l:\windows\system32\enlocstr.exe
2010-03-18 23:29 . 2010-03-18 23:29 10240 —-a-w- l:\windows\system32\killapps.exe
2010-03-18 23:29 . 2010-03-18 23:29 28672 —-a-w- l:\windows\system32\MIDIDEF.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="l:\archivos de programa\ATI Multimedia\main\launchpd.exe" [2006-11-01 102400]
"ATI DeviceDetect"="l:\archivos de programa\ATI Multimedia\main\ATIDtct.EXE" [2006-11-01 57344]
"ATI Remote Control"="l:\archivos de programa\ATI Multimedia\RemCtrl\ATIRW.exe" [2006-04-06 1622016]
"DAEMON Tools Lite"="l:\archivos de programa\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"RCSystem"="l:\archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe" [2004-12-10 45056]
"CreativeTaskScheduler"="l:\archivos de programa\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"ctfmon.exe"="l:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-13 14156800]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UnlockerAssistant"="l:\archivos de programa\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"StartCCC"="l:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"AVP"="l:\archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2010-02-22 208616]
"CTSysVol"="l:\archivos de programa\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"AudioDrvEmulator"="l:\archivos de programa\Creative\Shared Files\Module Loader\DLLML.exe" [2004-12-10 45056]
"CTHelper"="CTHELPER.EXE" [2010-03-18 19456]
"Malwarebytes' Anti-Malware"="l:\archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"QuickTime Task"="l:\archivos de programa\QuickTime\qttask.exe" [2010-03-18 421888]
"TrueImageMonitor.exe"="l:\archivos de programa\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232]
"Acronis Scheduler2 Service"="l:\archivos de programa\Archivos comunes\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232]
"Super Screen Capture"="l:\archivos de programa\Zeallsoft\Super Screen Capture\SSCapture.exe" [2007-03-09 3025920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="l:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

l:\documents and settings\All Users\Men£ Inicio\Programas\Inicio\
HP Digital Imaging Monitor.lnk - l:\archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
Inicio r pido de Adobe Acrobat.lnk - l:\windows\Installer\{AC76BA86-1040-7D00-7760-000000000003}\_SC_Acrobat.exe [2010-3-20 295606]
Logitech SetPoint.lnk - l:\archivos de programa\Logitech\SetPoint\SetPoint.exe [2010-2-19 813584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 16:28 72208 —-a-w- l:\archivos de programa\Archivos comunes\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=l:\windows\system32\ctfmon.exe
"PC Suite Tray"="l:\archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"Creative Detector"="l:\archivos de programa\Creative\MediaSource\Detector\CTDetect.exe" /R

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="l:\archivos de programa\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="l:\archivos de programa\Archivos comunes\Adobe\ARM\1.0\AdobeARM.exe"
"Launch Ai Booster"="l:\archivos de programa\ASUS\Ai Booster\OverClk.exe"
"SunJavaUpdateSched"="l:\archivos de programa\Java\jre6\bin\jusched.exe"
"LogitechQuickCamRibbon"="l:\archivos de programa\Logitech\QuickCam\Quickcam.exe" /hide
"HP Software Update"=l:\archivos de programa\HP\HP Software Update\HPWuSchd2.exe
"HPWQTOOLBOX"=l:\archivos de programa\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe "-i"
"UpdReg"=l:\windows\UpdReg.EXE
"Ulead AutoDetector v2"=l:\archivos de programa\Archivos comunes\Ulead Systems\AutoDetector\monitor.exe
"Acrobat Assistant 8.0"="l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"CTDVDDET"="l:\archivos de programa\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
"LogitechCommunicationsManager"="l:\archivos de programa\Archivos comunes\LogiShrd\LComMgr\Communications_Helper.exe"
"QuickTime Task"="l:\archivos de programa\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"l:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"l:\\Archivos de programa\\Windows Live\\Messenger\\wlcsdk.exe"=
"l:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"l:\\Archivos de programa\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"l:\\Archivos de programa\\Ventrilo\\Ventrilo.exe"=
"l:\\Archivos de programa\\Garena\\Garena.exe"=
"l:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"l:\\Archivos de programa\\Mozilla Firefox\\firefox.exe"=
"g:\\Worms 4 Mayhem Setup\\WORMS 4 MAYHEM.EXE"=
"l:\\Archivos de programa\\Java\\jre6\\bin\\javaw.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;l:\windows\system32\drivers\klbg.sys [29/01/2008 04:59 p.m. 33808]
R0 sptd;sptd;l:\windows\system32\drivers\sptd.sys [17/05/2010 03:13 p.m. 691696]
R0 tdrpman258;Acronis Try&Decide; and Restore Points filter (build 258);l:\windows\system32\drivers\tdrpm258.sys [04/06/2010 03:33 p.m. 911680]
R2 acedrv11;acedrv11;l:\windows\system32\drivers\ACEDRV11.sys [23/01/2008 03:49 a.m. 501560]
R2 afcdpsrv;Acronis Nonstop Backup service;l:\archivos de programa\Archivos comunes\Acronis\CDP\afcdpsrv.exe [04/06/2010 03:33 p.m. 2480048]
R2 MBAMService;MBAMService;l:\archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe [08/03/2010 08:02 p.m. 304464]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;l:\archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [07/05/2010 10:26 a.m. 1051976]
R3 afcdp;afcdp;l:\windows\system32\drivers\afcdp.sys [04/06/2010 03:33 p.m. 160704]
R3 COMMONFX.SYS;COMMONFX.SYS;l:\windows\system32\drivers\COMMONFX.sys [18/03/2010 08:39 p.m. 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;l:\windows\system32\drivers\CTAUDFX.sys [18/03/2010 08:39 p.m. 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;l:\windows\system32\drivers\CTSBLFX.sys [18/03/2010 08:39 p.m. 566360]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;l:\windows\system32\drivers\klim5.sys [30/04/2008 04:36 p.m. 24592]
R3 MBAMProtector;MBAMProtector;l:\windows\system32\drivers\mbam.sys [08/03/2010 08:02 p.m. 20952]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;l:\archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [24/02/2010 02:41 p.m. 10064]
S3 COMMONFX;COMMONFX;l:\windows\system32\drivers\COMMONFX.sys [18/03/2010 08:39 p.m. 99416]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;l:\archivos de programa\Archivos comunes\Creative Labs Shared\Service\CTAELicensing.exe [24/05/2010 07:06 p.m. 79360]
S3 CTAUDFX;CTAUDFX;l:\windows\system32\drivers\CTAUDFX.sys [18/03/2010 08:39 p.m. 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;l:\windows\system32\drivers\CTERFXFX.sys [18/03/2010 08:39 p.m. 100952]
S3 CTERFXFX;CTERFXFX;l:\windows\system32\drivers\CTERFXFX.sys [18/03/2010 08:39 p.m. 100952]
S3 CTSBLFX;CTSBLFX;l:\windows\system32\drivers\CTSBLFX.sys [18/03/2010 08:39 p.m. 566360]
S3 GarenaPEngine;GarenaPEngine;\??\l:\docume~1\GABRIE~1\CONFIG~1\Temp\SWX52.tmp –> l:\docume~1\GABRIE~1\CONFIG~1\Temp\SWX52.tmp [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-06-10 l:\windows\Tasks\User_Feed_Synchronization-{03C3B1A6-4937-4591-9B98-EDB0D3D92916}.job
- l:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.ve/
uInternet Settings,ProxyOverride = localhost
IE: Anexar a PDF existente - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir a Adobe PDF - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir destino de vínculo a PDF existente - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo Adobe PDF - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a Adobe PDF - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir vínculos seleccionados a Adobe PDF - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar; a Microsoft Excel - l:\archiv~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\
FF - prefs.js: browser.startup.homepage - www.google.com.ve/
FF - component: l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
FF - component: l:\documents and settings\Gabriel_Ch\Datos de programa\Mozilla\Firefox\Profiles\lv1c8r3y.default\extensions\[removed]\components\firetorrent.dll
FF - plugin: l:\archivos de programa\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: l:\archivos de programa\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: l:\archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - l:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
l:\archivos de programa\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
l:\archivos de programa\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
l:\archivos de programa\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
l:\archivos de programa\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
l:\archivos de programa\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
l:\archivos de programa\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
l:\archivos de programa\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
l:\archivos de programa\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
l:\archivos de programa\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
l:\archivos de programa\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************
scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GarenaPEngine]
"ImagePath"="\??\l:\docume~1\GABRIEL~1\CONFIG~1\Temp\SWX52.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1482476501-1644491937-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{16965A75-6A10-FDAC-7833-1B07071FA0CC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaifjbcpcapjpldbmoin"=hex:62,61,6d,68,00,2d
"jaifjbcpcapjpldbmoeo"=hex:62,61,66,68,00,2d
"iaigfjjbpgcdmhodal"=hex:6b,61,6e,68,6b,6a,70,6c,65,65,62,70,69,66,63,63,70,67,
6e,68,70,6d,00,7c
"hamfnanhlfcdghmk"=hex:6f,61,6d,67,67,67,66,6c,69,70,67,6c,64,63,6a,6a,69,6c,
63,65,66,68,65,68,6d,65,6a,6e,6d,66,00,00
"jalfgajkakpmgfddgfof"=hex:64,62,67,68,6f,6e,68,62,67,6c,6b,68,63,6a,70,6c,70,
64,61,67,65,6c,66,67,6b,65,68,6a,69,67,6f,63,6d,6f,65,66,6f,61,6b,6d,00,00
"hacehfggeepccjmm"=hex:6b,61,6e,68,6b,6a,70,6c,65,65,62,70,69,66,69,66,62,68,
6f,6c,68,67,00,7c

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(600)
l:\windows\system32\Ati2evxx.dll
l:\archivos de programa\archivos comunes\logitech\bluetooth\LBTWlgn.dll
l:\archivos de programa\archivos comunes\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(7048)
l:\windows\system32\WININET.dll
l:\archivos de programa\Archivos comunes\Logishrd\LVMVFM\LVPrcInj.dll
l:\archivos de programa\Unlocker\UnlockerHook.dll
l:\archivos de programa\Logitech\SetPoint\lgscroll.dll
l:\windows\system32\ctagent.dll
l:\archiv~1\WINDOW~2\wmpband.dll
l:\windows\system32\webcheck.dll
l:\windows\system32\WPDShServiceObj.dll
l:\archivos de programa\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
l:\archivos de programa\Nokia\Nokia PC Suite 7\NGSCM.DLL
l:\archivos de programa\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_spa-co.nlr
l:\archivos de programa\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
l:\windows\system32\PortableDeviceTypes.dll
l:\windows\system32\PortableDeviceApi.dll
l:\archivos de programa\Archivos comunes\Nero\SMC\NeroDigitalExt.dll
l:\archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\PDFShell.dll
l:\archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\PDFShell.ESP
.
———————— Other Running Processes ————————
.
l:\windows\system32\Ati2evxx.exe
l:\windows\system32\Ati2evxx.exe
l:\archivos de programa\Archivos comunes\LogiShrd\LVMVFM\LVPrcSrv.exe
l:\archivos de programa\Creative\Shared Files\CTAudSvc.exe
l:\archivos de programa\Archivos comunes\Acronis\Schedule2\schedul2.exe
l:\windows\system32\CTsvcCDA.EXE
l:\archivos de programa\Java\jre6\bin\jqs.exe
l:\archivos de programa\Archivos comunes\LogiShrd\LVCOMSER\LVComSer.exe
l:\archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
l:\windows\system32\HPZipm12.exe
l:\archivos de programa\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
l:\windows\RTHDCPL.EXE
l:\windows\system32\wbem\wmiapsrv.exe
l:\archivos de programa\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
l:\windows\system32\wscntfy.exe
l:\archivos de programa\Archivos comunes\LogiShrd\LVCOMSER\LVComSer.exe
l:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
l:\windows\system32\CTHELPER.EXE
l:\windows\system32\rundll32.exe
l:\archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrobat_sl.exe
l:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
l:\archivos de programa\Archivos comunes\Logishrd\KHAL2\KHALMNPR.EXE
l:\archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
l:\archivos de programa\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2010-06-10 22:25:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-11 02:55

Pre-Run: 106.152.267.776 bytes libres
Post-Run: 109.208.608.768 bytes libres

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT

- - End Of File - - 5C14C7ADD028BEFFD107155E053D5B25

==========================================00====================================
=====


MBR.TXT:
____________________________________________________________________________

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf765bf28
\Driver\ACPI -> ACPI.sys @ 0xf74a2cb8
\Driver\atapi -> atapi.sys @ 0xf7833b40
IoDeviceObjectType -> SecurityProcedure -> ntoskrnl.exe @ 0x805df529
\Device\Harddisk0\DR0 -> SecurityProcedure -> ntoskrnl.exe @ 0x805df529
NDIS: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xba65fbb0
PacketIndicateHandler -> NDIS.sys @ 0xba66ca21
SendHandler -> NDIS.sys @ 0xba64a87b
user & kernel MBR OK

End
__________________________________________________________________
we have lots more work to do I will tell you when you are clean I need some time to look over the log I'll get back to you with more instructions tomorrow (it's very late here)
Hi

Don't worry about the tools and the logs, we will clean those up when we are done.

How is your computer running at the moment?

Are there any outstanding issues?

Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT




Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Good morning. Ok, scan everything as I said, here I leave the reports. Malwarebytes log and the ESET Online. ——————————————————————————– Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Versión de la Base de Datos: 4189 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/06/2010 10:54:25 a.m. mbam-log-2010-06-11 (10-54-25).txt Tipos de Análisis: Análisis Rápido Objetos examinados: 137582 Tiempo transcurrido: 5 minuto(s), 59 segundo(s) Procesos en Memoria Infectados: 0 Módulos de Memoria Infectados: 0 Claves del Registro Infectadas: 0 Valores del Registro Infectados: 0 Elementos de Datos del Registro Infectados: 0 Carpetas Infectadas: 0 Archivos Infectados: 0 Procesos en Memoria Infectados: (No se han detectado elementos maliciosos) Módulos de Memoria Infectados: (No se han detectado elementos maliciosos) Claves del Registro Infectadas: (No se han detectado elementos maliciosos) Valores del Registro Infectados: (No se han detectado elementos maliciosos) Elementos de Datos del Registro Infectados: (No se han detectado elementos maliciosos) Carpetas Infectadas: (No se han detectado elementos maliciosos) Archivos Infectados: (No se han detectado elementos maliciosos) ================================================================== ESETSmartInstaller@High as downloader log: all ok # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=f105fec3f6d69e4c9973bf01fe177abb # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-06-11 03:45:24 # local_time=2010-06-11 11:15:24 (-04-30, Hora estándar de Venezuela) # country="Venezuela" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 575769 575769 0 0 # compatibility_mode=768 16777215 100 0 0 0 0 0 # compatibility_mode=1280 16777175 100 0 8533571 8533571 0 0 # compatibility_mode=5376 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=1277 # found=0 # cleaned=0 # scan_time=68 esets_scanner_update returned -1 esets_gle=53251 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=f105fec3f6d69e4c9973bf01fe177abb # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-06-11 05:34:12 # local_time=2010-06-11 01:04:12 (-04-30, Hora estándar de Venezuela) # country="Venezuela" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 575920 575920 0 0 # compatibility_mode=768 16777215 100 0 0 0 0 0 # compatibility_mode=1280 16777175 100 0 8533722 8533722 0 0 # compatibility_mode=5376 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=109287 # found=5 # cleaned=0 # scan_time=6444 L:\Archivos de programa\Codec Pack de ELISOFT\divx511\fsg_4104.exe Win32/Adware.Gator.A application 00000000000000000000000000000000 I L:\Archivos de programa\Craagle 3.0\Craagle v3.0.exe Win32/Adware.Craagle application 00000000000000000000000000000000 I L:\Archivos de programa\Mozilla Firefox\Optimizers\Fuo\Firefox Ultimate Optimizer.exe MSIL/FireOptimizer application 00000000000000000000000000000000 I L:\Archivos de programa\NirSoft\MessenPass\mspass.exe a variant of Win32/MPass.A application 00000000000000000000000000000000 I L:\Archivos de programa\Stellar Phoenix\Stellar Phoenix Excel Recovery\ser.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
I do not understand your question, what equipment I running?. What do you think, the see good or bad? It is a very good Computer, but still I have not the last (I7) :(, but I'd like to have him here with the problem of this president and the dollar is impossible to buy something. If that question is like working my computer, I just burn a CD to see if I rejected the recording and did not give any error, I suspect that it is possible to fix the problem, continue to test. :) If you ask what equipment I have is a Game Shark for the Termaltake, MB ASUS P5WD2 Premium, Dual Core 3.40 GHz and 4GB PQI low memory latency. I use the PC for the technical work, editing Video-Audio also collects programs, such as hobbies and testing. By the way, I have a sister who lives in Canada and already has residence there, lives with her husband in Montreal, I think you also is from Canada! I hope that you indicate me which is the following step, Thanks..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI